Everything we've published.
Every report, in one place methodology and indicators included, not just findings.
Inside PlayCrypt: Deconstructing the Amadey → Cobalt Strike → Play Multi-Stage Ransomware Chain
One file hash. A few pivots. That's all it took to walk straight into Play ransomware's back office: a Cobalt Strike server on Tencent loaded with exploit and credential-theft scripts, a live Sliver C2 host, and a team server actively churning out evasive Windows payloads, all sitting in open directories, no victim network required. A misconfigured leak site handed over Play's negotiation timelines for free. And one intrusion traced back to a single binary carrying Amadey, Cobalt Strike, Elex, and the Play encryptor together, proof that if you're only watching the network, you're already too late.
Scattered Spider: Many Names, One Syndicate
A financially motivated collective that weaponises social engineering over malware, mapped through domain impersonation, JARM pivoting and IOC clustering.
Operation Black Mirror: ClickFix Campaign Analysis
Multi-campaign analysis of ClickFix operations run by both APT actors and crimeware crews, focused on Win+R lures and infrastructure-level hunting.
When the Bazaar Burned From Within: The Silent Breach of Nobitex
How a cryptocurrency exchange was taken apart from the inside, and what its internal architecture revealed once the attackers published it.
No reports match your search.
