threat-intelligence
Know who's behind the attack before it reaches you.
Profiles, TTPs, and IOCs on the threat actor groups and ransomware operations our analysts track in the wild — updated as campaigns evolve.
RabbitHole: the RaaS operation built to blind your EDR first
RabbitHole's affiliate toolkit now ships with a framework targeting 400 distinct security and monitoring processes before payload execution.
QueenOfHearts infrastructure dismantled in multinational takedown
Operation Looking Glass disrupted command-and-control servers across three countries and cleaned 14,971 compromised WordPress sites.
CheshireCat phishing kit now sold as a subscription on dark web forums
A breakdown of the templates, hosting infrastructure, and evasion tricks behind one of the most-cloned phishing kits this quarter.
TeaParty Loader resurfaces in three compromised npm packages
A known credential-stealing loader has reappeared inside typosquatted packages downloaded over 40,000 times before takedown.
WhiteRabbit collective claims responsibility for regional outages
Claims remain unverified, but DDoS patterns match infrastructure previously linked to the group's earlier campaigns.
Inside an insider-threat case study: what the access logs actually showed
A walkthrough of how anomalous access patterns surfaced weeks before the exfiltration attempt — and what caught it in time.