Threat Intelligence
Community feed · IR

Incident Response Reports

The latest threat research aggregated from Incident Response Reports — browse the feed inside NivX, click through to read the full article on the source site.

Article previews are curated from Incident Response Reports. We show the title, cover image and a short snippet here; clicking any card opens the full article on the source site so the original authors get proper credit.
Threat Research

From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira

Key Takeaways This case was first reported to customers in a threat brief released in July 2025 and in a public flash alert in August 2025 in partnership with Swisscom B2B CSIRT, which observed anothe…

Jun 29, 2026
Read on IR
Threat Research

Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware

The EtherRAT malware family was first reported by Sysdig back in December 2025. At that time, the initial access vector was exploitation of CVE-2025-55182 (React2Shell) targeting Linux servers. In Mar…

May 11, 2026
Read on IR
Threat Research

Bissa Scanner Exposed: AI-Assisted Mass Exploitation and Credential Harvesting

Key Takeaways We identified an exposed server that provided unusual visibility into a large-scale, multi-victim exploitation and collection operation. Artifacts on the host showed that Claude Code and…

Apr 22, 2026
Read on IR
Threat Research

Apache ActiveMQ Exploit Leads to LockBit Ransomware

Key Takeaways An audio version of this report can be found on Spotify, Apple, YouTube, Audible, & Amazon.  This intrusion began in mid-February 2024 after a threat ac…

Feb 23, 2026
Read on IR
Threat Research

Cat’s Got Your Files: Lynx Ransomware

Key Takeaways The DFIR Report Services Contact us today for pricing or a demo! The intrusion began in early March 2025 with a single successful Remote Desktop Protocol (RDP) logon to an internet-expos…

Dec 17, 2025
Read on IR
Threat Research

From a Single Click: How Lunar Spider Enabled a Near Two-Month Intrusion

Key Takeaways Private Threat Briefs: 20+ private DFIR reports annually.   Contact us today for pricing or a demo!   Table of Contents: Case Summary Analysts Initial Access Execution Persiste…

Sep 29, 2025
Read on IR
Threat Research

Blurring the Lines: Intrusion Shows Connection With Three Major Ransomware Gangs

Key Takeaways Private Threat Briefs: 20+ private DFIR reports annually. Contact us today for pricing or a demo! Table of Contents: Case Summary Analysts Initial Access Execution Persistence Privilege…

Sep 8, 2025
Read on IR
Threat Research

Flash Alert: From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira

Overview Bumblebee malware has been an initial access tool used by threat actors since late 2021. In 2023 the malware was first reported as using SEO poisoning as a delivery mechanism. Recently in May…

Aug 5, 2025
Read on IR
Threat Research

KongTuke FileFix Leads to New Interlock RAT Variant

Researchers from The DFIR Report, in partnership with Proofpoint, have identified a new and resilient variant of the Interlock ransomware group's remote access trojan (RAT). This new malware, a shift…

Jul 14, 2025
Read on IR
Threat Research

Hide Your RDP: Password Spray Leads to RansomHub Deployment

Key Takeaways Case Summary This intrusion began in November 2024 with a password spray attack targeting an internet-facing RDP server. Over the course of several hours, the threat actor attempted logi…

Jun 30, 2025
Read on IR

Made with Emergent