Join us at Gartner SEC London and discover how LevelBlue can help you secure what’s next. Learn More

SpiderLabs Blog

Explore the latest threats, critical vulnerability disclosures, cutting-edge research, and intelligence from our elite global threat experts.

circleradial-blogs

The Godfather of Ransomware? Inside DragonForce’s Cartel Ambitions

February 03, 2026 | Mark Tsipershtein and Evgeny Ananin

Hunter

Stay Informed

Sign up to receive the latest security news and trends straight to your inbox from LevelBlue.

LevelBlue SpiderLabs: SQL Injection in Orkes Conductor: CVE-2025-66387

December 18, 2025 | Tim Stamopoulos

LevelBlue SpiderLabs has discovered a vulnerability in the Orkes Conductor ...

Sha1-Hulud: The Second Coming of The New npm GitHub Worm

December 03, 2025 | Karl Sigler

Sha1-Hulud is back with a new evolution of its supply-chain attack that targets ...

The Cat's Out of the Bag: A 'Meow Attack' Data Corruption Campaign Simulation via MAD-CAT

November 07, 2025 | Karl Biron

In 2024, I published Feline Hackers Among Us? (A Deep Dive and Simulation of ...

Scattered LAPSUS$ Hunters: Anatomy of a Federated Cybercriminal Brand

November 04, 2025 | Serhii Melnyk

Trustwave SpiderLabs’ Cyber Threat Intelligence team is tracking the emergence ...

Data in the Dark: The Public Sector on the Dark Web

October 15, 2025

The dark web serves as a refuge for threat actors to gather intel, trade ...

Babuk2 Bjorka: The Evolution of Ransomware for ‘Data Commoditization’

April 01, 2025 | John Basmayor

An investigation that started with a tip from one of our threat intel sources ...

Lessons from a Honeypot with US Citizens’ Data

November 13, 2024 | Radoslaw Zdonczyk and Nikita Kazymirskyi

Prior to last week’s US Presidential Election, the Trustwave SpiderLabs team ...

Why Do Criminals Love Phishing-as-a-Service Platforms?

September 23, 2024 | Rodel Mendrez

Phishing-as-a-Service (PaaS) platforms have become the go-to tool for ...

Bypassing EDR through Retrosigned Drivers and System Time Manipulation

September 13, 2024 | Zachary Reichert

The Retrosigned Driver EDR Bypass is a novel modification of a technique ...

Unveiling "sedexp": A Stealthy Linux Malware Exploiting udev Rules

August 19, 2024 | Zachary Reichert

Stroz Friedberg identified a stealthy malware, dubbed “sedexp,” utilizing Linux ...

Deep Dive and Simulation of a MariaDB RCE Attack: CVE-2021-27928

August 16, 2024 | Karl Biron

In early 2021, a new vulnerability, identified as CVE-2021-27928, was ...

Atlas Oil: The Consequences of a Ransomware Attack

June 25, 2024 | Arthur Erzberger

Overview Atlas Oil, a major player in the oil and fuel distribution industry, ...

See ya in S3!

November 14, 2020 | Mary Braden Murphy

Stroz Friedberg has unique insight on how attackers attempt to cover their ...

Into Defray

October 08, 2020 | Daniel Spicer

Stroz Friedberg provides a look into the techniques and patterns of the ...

Close, but no Ragnar

August 19, 2020 | Daniel Spicer and Partha Alwar

Stroz Friedberg Incident Response Services has observed Ragnar Locker use ...