A malicious email linked to proxy nodes, a processor, and mining coins

Tofsee Botnet: Proxying and Mining

Investigating the proxying, spam, and cryptocurrency-mining activity of the modular Tofsee botnet.

Research article · March 28, 2023
A loader distributing different payloads through branching connections

Tracking PrivateLoader: Malware Distribution Service

Tracking PrivateLoader delivery chains and identifying 30 malware families in the collected payloads.

Research article · August 31, 2022
SMS-linked phones beside a map highlighting Europe and Australia

FluBot Persists: Infecting Europe and Australia

A historical investigation of FluBot distribution, infection telemetry, and its domain-generation algorithm.

Research article · February 4, 2022
A phone with a hidden malicious chip beside factory-packaged connected devices

Backdoors Pre-Installed on Cheap Android Devices

Sinkhole observations of pre-installed Android threats and insecure device-update mechanisms.

Research article · April 28, 2020
Phone applications linked through an embedded chip to advertisements and many devices

Fraudulent Ads SDK Installed on 15 Million Android Devices

An Android advertising SDK investigation, with a historical appendix of sample hashes, package names, and domains.

Research article · March 8, 2019