WithSecure Labs.
Most up-to-date information regarding WithSecure
Article
Stolen creds and stinging loaders: An initial access campaign via SEO poisoning
Blog post
GREYVIBE: A Russia-nexus group leveraging AI across state-aligned operations
Article
The ‘vice’ in tech advice: ClickFix-style commands disguised as tech tips across social media platforms and beyond
Article
Ivanti EPMM Exploitation: Hit-and-Run
This blogpost, written by WithSecure’s STINGR Group, presents the analysis of a security incident that happened in February 2026 and was investigated by the WithSecure Incident Response team.
Article
The Changing Economics of Cybercrime-as-a-Service: What Defenders Need to Know
Back in 2023, when we last wrote about Cybercrime-as-a-Service, we described cybercrime as an economy that had figured out how to scale
Publications
To the past and beyond: Andariel’s latest arsenal and cyberattacks
WithSecure proactively identified and notified a European customer belonging to the public/legal sector of a breach attributed with high confidence to the Andariel group, a state-sponsored cyber group linked to the Reconnaissance General Bureau (RGB) 3rd bureau of Democratic People’s Republic of Korea (DPRK).
Article
TangleCrypt: a sophisticated but buggy malware packer
WithSecure's STINGR Group is releasing a detailed technical analysis of TangleCrypt, a previously undocumented packer for Windows malware.
Article
WEBJACK: Evolving IIS Hijacking Campaign Abuses SEO for Fraud and Monetization
WithSecure’s STINGR has been investigating a malware campaign, tracked as WEBJACK, which compromises Microsoft IIS servers
Article
TamperedChef: Malvertising to Credential Theft
TamperedChef is a sophisticated malware campaign that leveraged a convincing advertising campaign strategy and a fully functional decoy application to target European organizations.
Article
Email-Delivered RMM: Abusing PDFs for Silent Initial Access
Since November 2024, WithSecure has been tracking a slight uptick of targeted activities leveraging Remote Monitoring and Management (RMM) tools embedded within PDF documents.
Article
Active exploitation of on-premise SharePoint Server vulnerabilities “ToolShell”
On July 19th 2025, Microsoft reported on a set of vulnerabilities being actively exploited in-the-wild targeting on-premise SharePoint Servers,
Publications
WEEVILPROXY
WithSecure™ has uncovered a highly sophisticated and evasive malware campaign that has flown under the radar since March 2024.
Not Found
No results found, please try something else!