MuddyWater: When Your Build System Becomes an IOC – “Jacob”
by Robin Dost Subscribe Newsletter EDIT 2026-01-18: I published a follow-up article analyzing the evolution and version history of the...
by Robin Dost Subscribe Newsletter EDIT 2026-01-18: I published a follow-up article analyzing the evolution and version history of the...
by Robin Dost Subscribe Newsletter EDIT: If you're interested in how I efficiently track threat actors such as Gamaredon, feel...
by Robin Dost Subscribe Newsletter In malware analysis, it is tempting to describe change as innovation.New tricks, new tooling, new...
by Robin Dost Subscribe Newsletter After my recent blog posts covering Gamaredon’s ongoing PterodoGraph campaign targeting Ukraine, and following almost...
by Robin Dost Subscribe Newsletter UPDATE 22.12.2025: Gamaredon updated it's payload delivery infrastructure. You can find more information here.UPDATE 08.01.2026:...
by Robin Dost Subscribe Newsletter If you're interested in reading more about Gamaredon check out my other articles.If you're interested...
by Robin Dost Subscribe Newsletter I recently discovered a sample attributed to the threat actor APT36 ("Transparent Tribe") on MalwareBazaar....
APT44 (Sandworm Team) – Quick Facts Type: Advanced Persistent Threat (APT) Aliases: Sandworm, Sandworm Team, Seashell Blizzard, Iron Viking, Telebots, Voodoo Bear, Iridium, FrozenBarents...
In the past few days I found something fairly interesting in my sandbox. An attacker attempted to install malware, and...