
TDR Team
Threat Detection & Research Team
Articles by TDR Team

Securing gold: Assessing cyber threats during Paris 2024
Based on these observations and given the constantly evolving cyber threat landscape, we analysed cyber threats affecting previous editions of the Olympics, as well as the current geopolitical context to understand potential motivations of malicious activity.

CALISTO doxxing: Sekoia findings concurs to Reuters’ investigation on FSB-related Andrey Korinets
Discover activities linking Korinets to CALISTO doxxing in our investigation. Uncover details from emails, domains & servers used to target UK Parliament & Cambridge University.

When a botnet cries: Detecting botnet infection chains
Infection chains used by commodity malware are constantly evolving and use various tricks to bypass security measures and/or user awareness. BumbleBee, QNAPWorm, IcedID and Qakbot are all often used as first-stage malicious code.

Unmasking the latest trends of the financial cyber threat landscape
Financial cyber threat analysis: pinpoint common tactics, techniques & procedures used by intrusion sets to protect the financial system.

Game over: Gaming community at risk with information stealers
This report delves into the gaming industry targeted by infostealer malware, and details a specific campaign spreading via Discord messages.

AridViper, an intrusion set allegedly associated with Hamas
Given the recent events involving the Palestinian politico-military organisation Hamas which conducted on 7 October 2023 a military and terrorist operation in Israel, Sekoia.io took a deeper look into AridViper, an intrusion set suspected to be assoc

ClearFake: A newcomer to the "fake updates" threat landscape
ClearFake is a new malicious JavaScript framework deployed on compromised websites to deliver further malware using the drive-by download technique.

Active Lycantrox infrastructure illumination
Sekoia.io is actively monitoring hundreds of malicious infrastructure clusters to protect its customers. In light of the recent Citizenlab blogspot and in solidarity with the efforts against cyber mercenaries, we have chosen to shed light on one of t

Sekoia mid-2023 ransomware threat landscape
This blog post aims at presenting an overview of the ransomware-related threat evolution in the first half of 2023. The observations and the analysis shared in this blog post focus on ransomware operations mostly impacting corporate networks in lucra


