Recent Posts
FireScam Android Malware
Jan 10, 2025 1:36:56 PM / by The Hivemind posted in Threat Bulletin, Android, Stealer, Spyware, FireScam
2024 Recap - Malware Hall of Fame
Dec 30, 2024 12:05:01 PM / by The Hivemind posted in Threat Bulletin, Malware, 2024 Recap
Executive Summary
In this report, PolySwarm analysts chose fifteen standout malware families for the 2024 Malware Hall of Fame. A small selection of IOCs of our most recent samples of each family are provided as well.
2024 Recap - Russian Threat Actor Activity
Dec 19, 2024 12:38:53 PM / by The Hivemind posted in Russia, Threat Bulletin, Europe, 2024, Recap
Executive Summary
This Threat Bulletin is part of PolySwarm’s 2024 Recap series. This report provides highlights of activity perpetrated by Russia-based threat actors in 2024.
2024 Recap - Iranian Threat Actor Activity
Dec 16, 2024 1:42:43 PM / by The Hivemind posted in Threat Bulletin, Middle East, Iran, MENA, 2024, Recap
Executive Summary
This Threat Bulletin is part of PolySwarm’s 2024 Recap series. This report provides highlights of activity perpetrated by Iran-based threat actors in 2024.
2024 Recap - North Korean Threat Actor Activity
Dec 13, 2024 2:20:52 PM / by The Hivemind posted in Threat Bulletin, North Korea, Asia, APAC, 2024, Recap
Executive Summary
This Threat Bulletin is part of PolySwarm’s 2024 Recap series. This report highlights the activity perpetrated by North Korea-based threat actors in 2024.
Black Basta Evolves
Dec 9, 2024 12:32:54 PM / by The Hivemind posted in Threat Bulletin, Ransomware, Black Basta, Emerging Threat, Evolving Threat
Verticals Targeted: Manufacturing, Finance, Transportation, Legal Services, Healthcare, Defense, Business Services
Executive Summary
Black Basta is a ransomware group that rose in the aftermath of the dissolution of Conti ransomware in 2022. In recent months, Black Basta has begun using tactics that are reminiscent of nation-state threat actor tactics and has shifted from opportunistic targeting to more refined, strategic targeting.
Salt Typhoon Targets Telecoms With GhostSpider
Dec 6, 2024 1:33:32 PM / by The Hivemind posted in Threat Bulletin, APT, China, Emerging Threat, Salt Typhoon, GhostSpider
Related Families: Demodex
Verticals Targeted: Telecommunications
Executive Summary
Salt Typhoon, a China nexus APT group, was recently observed using GhostSpider backdoor to target telecommunications companies.
BabbleLoader
Nov 29, 2024 12:54:44 PM / by The Hivemind posted in Threat Bulletin, Loader, BabbleLoader, Meduza, WhiteSnake, Donut Loader
Related Families: WhiteSnake, Meduza
Verticals Targeted: Finance, Business Administration