A practitioner’s tutorial for assembling a working threat-actor profile from public sources: MITRE ATT&CK for TTPs, Mandiant and CrowdStrike for attribution context, Malpedia for malware lineage, plus a clean note-taking template.
A 2026 tutorial for tracking individual ransomware affiliates across operator rebrands using VirusTotal Intelligence, abuse.ch’s MalwareBazaar, and YARA rules. Code reuse, builder fingerprints, and TTP continuity reveal the same crews under new names.
A practitioner’s tutorial for checking whether your email, your domain, or your employees show up in fresh infostealer logs, using Hudson Rock’s free tools, IntelX, Have I Been Pwned, and a couple of paid options worth the spend.
A 2026 tutorial on building a layered defence against infostealers: endpoint EDR settings that catch stealer behaviour, browser hardening that protects cookie stores, and the user-side training that closes the actual gap.
Stolen credentials are only half the package. The other half is the browser fingerprint that lets an attacker impersonate the victim’s session believably. A 2026 look at how fingerprint markets work.
A practitioner’s look inside the “cloud of logs” subscription model: what attackers pay, what they get, and the operational mechanics that turn raw infostealer output into a productised threat.
Stealing your password used to be the goal. In 2026 it’s the consolation prize: modern infostealers go for session cookies, which let attackers impersonate authenticated users without needing to defeat MFA. Here’s how the model works.
A 2026 comparative profile of the three dominant infostealer families: capabilities, distribution channels, market share by observed infections, and where each is heading after the 2024 takedown actions.
Three mid-tier ransomware operators have built sustained victim claim counts in 2025-2026. Profiles of Qilin, Medusa, and Embargo: what’s distinctive about each, and what the rise of the mid-tier means for defenders.
Persistent rumors point to a Lapsus$ revival operating under new branding in 2026. Sorting the credible signal from the Telegram noise, and what defenders should make of it.