July 14, 2022 13 min read North Korean threat actor targets small and midsize businesses with H0lyGh0st ransomware A group of actors originating from North Korea that MSTIC tracks as DEV-0530 has been developing and using ransomware in attacks since June 2021.
January 28, 2021 19 min read ZINC attacks against security researchers In recent months, Microsoft has detected cyberattacks targeting security researchers by an actor we track as ZINC.
February 4, 2020 5 min read Ghost in the shell: Investigating web shell attacks Web shell attacks allow adversaries to run commands and steal data from an Internet-facing server or use the server as launch pad for further attacks against the affected organization.