Research Archive
Research
27 reports documenting adversary operations, malware, infrastructure and tradecraft.
Threat Research
Three exposed operator workspaces reveal confirmed access to Russian and Kyrgyz government systems, a Syrian Customs C2 inventory, stolen data and wider targeting of Russian sta...
Sep 13, 2026
·
34 min read
Threat Research
Tracing The Gentlemen ransomware group's origins, infrastructure, OPSEC failures, organisational structure, and alleged leader.
Jul 24, 2026
·
23 min read
Threat Research
Exposed operator tooling shows an INC affiliate using likely LLM-generated scripts to enumerate, pivot, and deploy ransomware against network storage
Jul 22, 2026
·
22 min read
Threat Research
OSINT analysis of Denis Obrezko & the Void Blizzard threat group
Jul 14, 2026
·
12 min read
Threat Research
Open-directories exposes mass exploitation of web-applications globally
Jun 22, 2026
·
25 min read
Threat Research
Check whether a domain or IP address appeared in locally recovered mass-exploitation target lists, scanner results, or confirmed web-shell evidence.
Jun 22, 2026
·
1 min read
Threat Research
Exposed C2 server highlights opportunistic exploitation of CVE-2026-41940 and novel exploitation chains against South-East Asian military & hosting providers
May 2, 2026
·
14 min read
Threat Research
Sucessive OPSEC failures expose a Qilin affiliate targeting network appliances for initial access
May 1, 2026
·
26 min read
Threat Research
How an exposed C2 exposed the back-end of a cybercrime operation, including threat actors beefing. TGI Fridays was one of the many victims.
Apr 22, 2026
·
14 min read
Threat Research
A full technical teardown of FUD Crypt (Cryptor-as-a-Service) and surrounding activity performed by this threat actor
Apr 19, 2026
·
53 min read
Threat Research
Linking TP-Link and ASUS exploitation to a March supply-chain attack, and examining possible overlap with TeamPCP.
Apr 10, 2026
·
21 min read
Threat Research
Reconstructing the complete kill-chain of the BuddyBoss Attack
Apr 3, 2026
·
23 min read
Threat Research
How Claude infiltrated the supply-chain, compromising 200+ websites for fraud
Apr 3, 2026
·
15 min read
Threat Research
Analysis of a fully-featured AiTM phishing platform with a collective intelligence & licensing system
Mar 30, 2026
·
23 min read
Threat Research
FancyBear's OPSEC failure gives Ctrl-Alt-Intel rare visibility inside Russian espionage operations
Mar 16, 2026
·
46 min read
Threat Research
MuddyWater espionage campaign exposed
Mar 4, 2026
·
28 min read
Threat Research
A suspected DPRK-associated actor compromises crypto orgs, pillaging cloud environments, stealing proprietary exchange software and source code.
Mar 2, 2026
·
23 min read
Threat Research
OSINT analysis of entities potentially linked to the 'Global Profit' PHaaS platform
Feb 23, 2026
·
16 min read
Threat Research
Our attempt at reversing Aeternum Loader to extract contract addresses and reveal functionality.
Feb 16, 2026
·
19 min read
Threat Research
An exposed operator panel revealed how Aeternum Loader abuses Polygon smart contracts for C2, allowing us to view all C2 commands ever sent.
Feb 16, 2026
·
22 min read
Threat Research
Investigating vulnerabilities in the ErrTraffic panel
Jan 28, 2026
·
17 min read
Threat Research
Suspected state-affiliated actor targets Afghan and Kazakh entities
Jan 21, 2026
·
21 min read
Threat Research
Threat actor deploys Sliver C2 to FortiWeb appliances
Dec 31, 2025
·
10 min read
Threat Research
Lessons in OPSEC from a sloppy RaaS
Dec 16, 2025
·
17 min read
Threat Research
Scanning CVE-2025-55182 for the greater good
Dec 8, 2025
·
5 min read
Threat Research
An analysis of the threats surrounding exploitation of CVE-2025-55182
Dec 8, 2025
·
22 min read
Threat Research
Chinese threat actor targets Vietnemse universities in extensive campaign.
Aug 20, 2025
·
55 min read
No research matched those filters. Clear the search or choose different tags.