Home Framework Threat Intel APT Encyclopedia Blog

Security Research
& Insights

Deep dives into adversary emulation, threat intelligence, and the philosophy behind building offensive security tools.

Threat Intel Sep 3, 2026 20 min read

From Job Offer to Ring 0: Lazarus, CVE-2026-68820 and FudModule 3.1

Lazarus burned a Windows kernel zero-day on a fake recruiter email. Full technical breakdown of the revived Operation Dream Job: the SEO-poisoned lure, the trojanized MuPDF viewer, the MISTPEN downloader riding the Graph API, the AFD.sys use-after-free, and a rootkit that blinds 94 ETW providers and switches off Smart App Control, plus the honest question of what stays detectable once the attacker owns ring 0.

Lazarus Zero-Day Kernel Rootkit DLL Sideloading Purple Team
Read full analysis
Threat Intel Jul 15, 2026 12 min read

No Malware Required: Inside Scattered Spider's Identity-First Playbook

Scattered Spider (UNC3944 / Octo Tempest) breaks into hardened enterprises through the help desk: MFA fatigue, SIM swaps and valid accounts, with no implant to catch. Why malware-centric detection misses the whole kill chain, the full ATT&CK mapping, and how to validate whether you'd actually catch it with Cyllex.

Scattered Spider Identity MFA Fatigue Purple Team
Read full analysis
Threat Intel Jan 7, 2026 25 min read

Judgment Panda: When China Spies on its "Ally" Russia

APT31 vs Russia - A deep dive into the Chinese state-sponsored campaign targeting Russian IT contractors (2022-2025). Analysis of VtChatter's VirusTotal C2 channel, CloudyLoader's evasion techniques, and the geopolitical implications of allies spying on allies.

APT31 China Russia Cloud C2
Read full analysis
Framework Dec 21, 2025 12 min read

Introducing Cyllex: Why I Built an APT Emulation Framework

As an adversarial engineer, I've spent years studying how threat actors operate. From nation-state APTs to financially motivated groups, understanding their TTPs is only half the battle.

APT Emulation Purple Team MITRE ATT&CK
Read full article