Shadow IT isn’t just governance debt, it’s an attacker’s beachhead. This post explores real intrusions where forgotten assets, rogue tenants, exposed cloud storage, and abandoned domains enabled initial access, and why closing visibility gaps is now a core SOC capability.
Silver Fox: The only Tax Audit Where Fine Print Installs Malware
Track the 2025-2026 shift of China-based Silver Fox from financial crime to APT espionage. Discover how they exploit tax-themed phishing and RMM tools to target South Asian entities.
UEBA vs. Stealth Intrusions: Catching Identity & Credential Abuse
Traditional SOC rules miss attacks using valid accounts and MFA fatigue. Learn real-world cases where UEBA detects stealthy lateral movement, OAuth abuse, and cloud console misuse.
From APT28 to RePythonNET: automating .NET malware analysis
This blogpost covers the tooling and methodology we use at TDR to reverse engineer .NET malware. In our daily work, we encounter a wide range of malware, sophisticated or not, and a significant portion of it is written in .NET.
Strategic Autonomy in Cybersecurity: Where you Get to Choose
Stop being locked into "black box" ecosystems. Discover how Sekoia’s vendor-agnostic platform ensures data sovereignty, GDPR compliance, and technological independence.
Part 1 of our FSB Matryoshka series. Discover the context behind Gamaredon's cyberespionage campaigns, introducing GammaPhish and GammaWorm operations.
Discover part 3 of our FSB Matryoshka investigation. We deep dive into Gamaredon's Gammasteel info-stealer, its data exfiltration TTPs, and indicators.
APT28: An Evolution of Tradecraft from X-Agent to LLM Malware
Sekoia TDR looks back at how APT28's arsenal has evolved over two decades, from its signature X-Agent implants to disposable modules, edge-device infrastructure and the first LLM-driven malware.
Don't Eat the ChocoPoCs: Trojanised PoCs Hit Researchers
This article details a campaign targeting vulnerability researchers with "ChocoPoC" malware embedded inside trojanised Python dependencies. Exploiting the pressure to quickly test new vulnerabilities, threat actors distribute a persistent Remote Access Trojan (RAT) that exfiltrates data and harvests credentials from compromised developer environments.
AI SOC Security: All About Sekoia’s AI Trust Architecture
Security teams are being asked to trust AI with work that used to belong to experienced analysts. So how can they decide if it’s earned its place there?
Why AI SOC Agents Need Context to Investigate Alerts
AI SOC agents need more than an alert to investigate threats. See how telemetry, asset data, identities and threat intelligence help explain each verdict.
One SOC can protect dozens of customers, but every customer works differently. See how multi-level agents give security teams one shared way to investigate alerts, while keeping the local context needed to make the right call.
Exvicy: A Copycat of the ErrTraffic Malware Distribution Framework
This article details how TDR pivoted from a forum advertisement to identify confirmed operator infrastructure, analyzes the Exvicy infection chain, and provides code evidence establishing that this emerging MaaS is a direct copycat of the adopted ErrTraffic framework.