Loading the current evidence view. Navigation and account controls remain available.
Indicator investigation
Loading the current evidence view. Navigation and account controls remain available.
Loading verdict, provenance, relationships and sightings.
Indicator
Type domain · source intel_report_ingest
Shared non-noise tags (narrow join).
tags: report:checkpoint_research
tags: report:checkpoint_research
tags: report:checkpoint_research
tags: report:checkpoint_research
tags: report:checkpoint_research
tags: report:checkpoint_research
tags: report:checkpoint_research
tags: report:checkpoint_research
High-signal pivots without leaving the thread you started in search.
Structured pivots from local graph context.
Full investigation canvas with neighbor expansion.
Title/body text match only.
Photo ZIP campaign targeting hospitality industry delivers Node.js implant for persistent access Microsoft Threat Intelligence identified an active multi-stage intrusion campaign targeting hospitality organizations in Europe and Asia. The campaign uses photo-themed ZIP archives
Killing me gently: Inside Gentlemen’s EDR killer framework ESET Research shares the results of a months-long investigation into the suite of EDR killers maintained by the RaaS gang Gentlemen Killing me gently: Inside Gentlemen’s EDR killer framework Award-winning news, views, a
How We Added WebAuthn to a Browser-Based RDP Client A look inside the reverse-engineering journey of building the first RDP client outside of Windows to support WebAuthn redirection. The post How We Added WebAuthn to a Browser-Based RDP Client appeared first on Unit 42 . How We
Proactive Preparation and Hardening Against Destructive Attacks: 2026 Edition Written by: Matthew McWhirt, Bhavesh Dhake, Emilio Oropeza, Gautam Krishnan, Stuart Carrera, Greg Blaum, Michael Rudden UPDATE (March 13): Added guidance around abuse or misuse of endpoint / MDM platfo
VECT: Ransomware by design, Wiper by accident Key Takeaways Background VECT Ransomware is a Ransomware-as-a-Service (RaaS) program that made its first appearance in December 2025 on a Russian-language cybercrime forum. After claiming their first two victims in January 2026, the
Inside SHADOW-WATER-063’s Banana RAT: From Build Server to Banking Fraud In this blog entry, researchers from the TrendAI™ MDR team discuss how they mapped the full end-to-end operation of SHADOW-WATER-063’s Banana RAT banking malware by analyzing server-side artifacts and victi
Deduped connector weight from graph context.