Found 35775 bookmarks
Newest
OysterLoader Unmasked: The Multi-Stage Evasion Loader
OysterLoader Unmasked: The Multi-Stage Evasion Loader
Unmasking OysterLoader's evasion: from API hammering to custom LZMA. Explore the 4-stage infection chain and its ties to Rhysida ransomware.
·sekoia.com·
OysterLoader Unmasked: The Multi-Stage Evasion Loader
Shadow IT: The Initial Access You Didn’t Log
Shadow IT: The Initial Access You Didn’t Log
Shadow IT isn’t just governance debt, it’s an attacker’s beachhead. This post explores real intrusions where forgotten assets, rogue tenants, exposed cloud storage, and abandoned domains enabled initial access, and why closing visibility gaps is now a core SOC capability.
·sekoia.com·
Shadow IT: The Initial Access You Didn’t Log
Silver Fox: The only Tax Audit Where Fine Print Installs Malware
Silver Fox: The only Tax Audit Where Fine Print Installs Malware
Track the 2025-2026 shift of China-based Silver Fox from financial crime to APT espionage. Discover how they exploit tax-themed phishing and RMM tools to target South Asian entities.
·sekoia.com·
Silver Fox: The only Tax Audit Where Fine Print Installs Malware
UEBA vs. Stealth Intrusions: Catching Identity & Credential Abuse
UEBA vs. Stealth Intrusions: Catching Identity & Credential Abuse
Traditional SOC rules miss attacks using valid accounts and MFA fatigue. Learn real-world cases where UEBA detects stealthy lateral movement, OAuth abuse, and cloud console misuse.
·sekoia.com·
UEBA vs. Stealth Intrusions: Catching Identity & Credential Abuse
From APT28 to RePythonNET: automating .NET malware analysis
From APT28 to RePythonNET: automating .NET malware analysis
This blogpost covers the tooling and methodology we use at TDR to reverse engineer .NET malware. In our daily work, we encounter a wide range of malware, sophisticated or not, and a significant portion of it is written in .NET.
·sekoia.com·
From APT28 to RePythonNET: automating .NET malware analysis
Strategic Autonomy in Cybersecurity: Where you Get to Choose
Strategic Autonomy in Cybersecurity: Where you Get to Choose
Stop being locked into "black box" ecosystems. Discover how Sekoia’s vendor-agnostic platform ensures data sovereignty, GDPR compliance, and technological independence.
·sekoia.com·
Strategic Autonomy in Cybersecurity: Where you Get to Choose
FSB’s matryoshka #1/3: Inside Gamaredon Cyber Operations
FSB’s matryoshka #1/3: Inside Gamaredon Cyber Operations
Part 1 of our FSB Matryoshka series. Discover the context behind Gamaredon's cyberespionage campaigns, introducing GammaPhish and GammaWorm operations.
·sekoia.com·
FSB’s matryoshka #1/3: Inside Gamaredon Cyber Operations
FSB’s matryoshka #2/3: Gamaredon's Gammaload Malware
FSB’s matryoshka #2/3: Gamaredon's Gammaload Malware
In part 2 of our FSB Matryoshka series, we analyze Gamaredon's Gammaload malware variant, dissecting its technical updates and deployment mechanisms.
·sekoia.com·
FSB’s matryoshka #2/3: Gamaredon's Gammaload Malware
FSB’s matryoshka #3/3: Gamaredon's Gammasteel Infostealer
FSB’s matryoshka #3/3: Gamaredon's Gammasteel Infostealer
Discover part 3 of our FSB Matryoshka investigation. We deep dive into Gamaredon's Gammasteel info-stealer, its data exfiltration TTPs, and indicators.
·sekoia.com·
FSB’s matryoshka #3/3: Gamaredon's Gammasteel Infostealer
APT28: An Evolution of Tradecraft from X-Agent to LLM Malware
APT28: An Evolution of Tradecraft from X-Agent to LLM Malware
Sekoia TDR looks back at how APT28's arsenal has evolved over two decades, from its signature X-Agent implants to disposable modules, edge-device infrastructure and the first LLM-driven malware.
·sekoia.com·
APT28: An Evolution of Tradecraft from X-Agent to LLM Malware
Sekoia’s New Identity: Designed for Clarity
Sekoia’s New Identity: Designed for Clarity
Sekoia has partnered with branding agency Bruno to develop a new brand identity and digital experience that reflects who we really are.
·sekoia.com·
Sekoia’s New Identity: Designed for Clarity
Don't Eat the ChocoPoCs: Trojanised PoCs Hit Researchers
Don't Eat the ChocoPoCs: Trojanised PoCs Hit Researchers
This article details a campaign targeting vulnerability researchers with "ChocoPoC" malware embedded inside trojanised Python dependencies. Exploiting the pressure to quickly test new vulnerabilities, threat actors distribute a persistent Remote Access Trojan (RAT) that exfiltrates data and harvests credentials from compromised developer environments.
·sekoia.com·
Don't Eat the ChocoPoCs: Trojanised PoCs Hit Researchers
6 AI SOC Integrations Actually Worth Connecting
6 AI SOC Integrations Actually Worth Connecting
Explore six AI SOC integrations that bring identity, cloud, vulnerability, phishing, incident and network context into one investigation workflow.
·sekoia.com·
6 AI SOC Integrations Actually Worth Connecting
Here's Why Every Detection Needs a Runbook
Here's Why Every Detection Needs a Runbook
A detection can raise the alarm and still leave the analyst with the hardest work. Runbooks put the investigation path beside the alert.
·sekoia.com·
Here's Why Every Detection Needs a Runbook
AI SOC Security: All About Sekoia’s AI Trust Architecture
AI SOC Security: All About Sekoia’s AI Trust Architecture
Security teams are being asked to trust AI with work that used to belong to experienced analysts. So how can they decide if it’s earned its place there?
·sekoia.com·
AI SOC Security: All About Sekoia’s AI Trust Architecture
Why AI SOC Agents Need Context to Investigate Alerts
Why AI SOC Agents Need Context to Investigate Alerts
AI SOC agents need more than an alert to investigate threats. See how telemetry, asset data, identities and threat intelligence help explain each verdict.
·sekoia.com·
Why AI SOC Agents Need Context to Investigate Alerts
Why One SOC Agent Isn’t Enough for Every Customer
Why One SOC Agent Isn’t Enough for Every Customer
One SOC can protect dozens of customers, but every customer works differently. See how multi-level agents give security teams one shared way to investigate alerts, while keeping the local context needed to make the right call.
·sekoia.com·
Why One SOC Agent Isn’t Enough for Every Customer
Exvicy: A Copycat of the ErrTraffic Malware Distribution Framework
Exvicy: A Copycat of the ErrTraffic Malware Distribution Framework
This article details how TDR pivoted from a forum advertisement to identify confirmed operator infrastructure, analyzes the Exvicy infection chain, and provides code evidence establishing that this emerging MaaS is a direct copycat of the adopted ErrTraffic framework.
·sekoia.com·
Exvicy: A Copycat of the ErrTraffic Malware Distribution Framework
AI in the SOC: EU AI Act and Technology Sovereignty
AI in the SOC: EU AI Act and Technology Sovereignty
An analysis of how Europe’s emerging AI and cybersecurity framework is shaping trust, control and technology sovereignty in the SOC.
·sekoia.com·
AI in the SOC: EU AI Act and Technology Sovereignty