Resources

Access the latest resources including White Papers, Case Studies, Product Descriptions, Analysts Reports, and more, covering the topic of Cyber Threat Intelligence. Experts share their insights for Threat Analysts, Security Analysts, Managers of Threat Intelligence / SOC / CERT, and CISOs.

Threat Intelligence Report

EclecticIQ Fusion Center Report: ScrapedIn LinkedIn Scraper Released on GitHub English

A Red Team Engineer posted a new tool on GitHub, ScrapedIn, that can scrape LinkedIn profiles and put the results into an Excel Spreadsheet. 

Download report and STIX entities

Threat Intelligence Report

Report - EclecticIQ Hypotheses: Infection Vector for German Government Breach English

On 28th February the German Interior Ministry confirmed that it identified an attack against its servers in December 2017. In this report EclecticIQ Fusion Center analysts will summarize what is known to date and will provide a set of hypotheses about the infection vector. 

Download report and STIX entities

Threat Intelligence Report

Large Lokibot Malspam Campaign Hitting The UK English

Malware: LokiBot malware is actively being distributed via a spam email campaign in the UK. 

Download report and STIX entities

Threat Intelligence Report

EclecticIQ Analysis: Trend in Android Trojans Targeting the Middle East English

There have been numerous instances of Android Trojans being used for espionage purposes targeting users in the Middle East in recent months. The highest profile of these include; FrozenCell, GnatSpy, AnubisSpy, Pallas and Tempting Cedar. 

Download report and STIX entities

Threat Intelligence Report

EclecticIQ Fusion Center Report: ComboJack Malware Alters Clipboards to Steal Cryptocurrency English

Unit 42 researchers discovered a new currency stealer dubbed "ComboJack", which targets cryptocurrencies and online wallets.

Download report and STIX entities

Threat Intelligence Report

EclecticIQ Fusion Center Report: Malware Steals Data Directly from the Device to Hack Facebook Accounts English

A new Android malware named Malware: Android.Fakeapp extracts user credentials directly from the victim's devices, most of which have been found to be located in the Asia-Pacific region. 

Download report and STIX entities

Threat Intelligence Report

EclecticIQ Fusion Center Report: DDoS Attack Stemming from Memcached Servers Hits GitHub English

Earlier this week Cloudflare and various security researchers were reporting on an obscure amplification attack vector using the memcached protocol, coming from UDP port 11211. On Wednesday. GitHub experienced a DDoS attack stemming from memcached servers. 

Download report and STIX entities

Threat Intelligence Report

EclecticIQ Fusion Center Report: Annabelle Ransomware (Update) English

Security researchers have identified a new ransomware, named after the horror movie "Annabelle", which showcases a number of traditional ransomware features. This report details the observations seen by EclecticIQ Fusion Center analysts. 

Download report and STIX entities

Threat Intelligence Report

EclecticIQ Fusion Center Report: Thanatos Ransomware First Ransomware to Ask for Payment in Bitcoin Cash English

Researchers identified a new ransomware, Thanatos, that still appears to contain a lot of bugs but is the first ransomware seen to ask for payment to be made in Bitcoin Cash (BCH).

Download report and STIX entities

Threat Intelligence Report

EclecticIQ Fusion Center Report: Hacker Group Makes $3 Million by Installing Monero Miners on Jenkins Servers English

A group of actors hacked into Jenkins servers and installed a malware that mines for Monero. This operation resulted in the theft of approximately $3 million (USD). 

Download report and STIX entities

Threat Intelligence Report

EclecticIQ Fusion Center Report: Olympic Destroyer - Various Firms Attempt to Attribute English

Talos reported about Malware: Olympic Destroyer samples. Researchers noted that of the analyzedsamples, it appeared to perform only destructive functionality. From previous attacks, inclusion of destructive capabilities may add additional meaning, in terms of targeting, campaign goals, and attribution. 

Download report and STIX entities

Threat Intelligence Report

EclecticIQ Fusion Center Report: Russian Hacking Group Fancy Bear Prepares to Attack Winter Olympics, U.S. Senate English

The hacking group Threat Actor: Fancy Bears Hack Team, which is heavily linked to the Russian government, appears to be preparing to disrupt the 2018 Winter Olympics in South Korea.

Download report and STIX entities

Threat Intelligence Report

EclecticIQ Fusion Center Report: Pyeongchang 2018: Summary of Cyber and Physical Threats English

In preparation for the 2018 Olympic Winter Games travelers are reminded to be aware of cybersecurity and physical security risks. Cyber criminals may attempt to steal PII or harvest credentials for financial gain.

Download report and STIX entities