Loading the current evidence view. Navigation and account controls remain available.
Indicator investigation
Loading the current evidence view. Navigation and account controls remain available.
Loading verdict, provenance, relationships and sightings.
Indicator
Type domain · source intel_report_ingest
Shared non-noise tags (narrow join).
tags: report:mandiant, report:microsoft_mstic, report:talos, report:trend_micro
tags: report:mandiant, report:microsoft_mstic, report:talos, report:trend_micro
tags: report:microsoft_mstic, report:talos, report:trend_micro
tags: report:mandiant, report:microsoft_mstic, report:talos
tags: report:talos, report:trend_micro
tags: report:microsoft_mstic, report:trend_micro
tags: report:mandiant, report:talos
tags: report:microsoft_mstic, report:trend_micro
High-signal pivots without leaving the thread you started in search.
Structured pivots from local graph context.
Full investigation canvas with neighbor expansion.
Title/body text match only.
Inside Shadow-Earth-053: A China-Aligned Cyberespionage Campaign Against Government and Defense Sectors in Asia A China-aligned threat group is exploiting unpatched Microsoft Exchange vulnerabilities to conduct cyberespionage against government and critical infrastructure target
STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus Written by: Jordan Jones Introduction Google Threat Intelligence Group (GTIG) has conducted an in-depth analysis of a .NET backdoor, tracked as STOCKSTAY, that has been continually developed a
Ransomware Under Pressure: Tactics, Techniques, and Procedures in a Shifting Threat Landscape Written by: Bavi Sadayappan, Zach Riddle, Ioana Teaca, Kimberly Goody, Genevieve Stark Introduction Since 2018, when many financially motivated threat actors began shifting their moneti
Killing me gently: Inside Gentlemen’s EDR killer framework ESET Research shares the results of a months-long investigation into the suite of EDR killers maintained by the RaaS gang Gentlemen Killing me gently: Inside Gentlemen’s EDR killer framework Award-winning news, views, a
UAT-8302 and its box full of malware Cisco Talos is disclosing UAT-8302, a sophisticated, China-nexus advanced persistent threat (APT) group targeting government entities in South America since at least late 2024 and government agencies in southeastern Europe in 2025. Cisco Tal
When prompts become shells: RCE vulnerabilities in AI agent frameworks New research exposes how prompt injection in AI agent frameworks can lead to remote code execution. Learn how these vulnerabilities work, what’s impacted, and how to secure your agents. The post When prompts
Deduped connector weight from graph context.