WithSecure Labs
Asiantuntijoidemme uusimmat tutkimukset, päivitykset ja työkalut käyttöösi.
Article
Stolen creds and stinging loaders: An initial access campaign via SEO poisoning
Blog post
GREYVIBE: A Russia-nexus group leveraging AI across state-aligned operations
Article
The ’vice’ in tech advice: ClickFix-style commands disguised as tech tips across social media platforms and beyond
Threat actors constantly look for ways to circumvent traditional security measures to deliver malware to unsuspecting users.
Article
Ivanti EPMM Exploitation: Hit-and-Run
This blogpost, written by WithSecure’s STINGR Group, presents the analysis of a security incident that happened in February 2026 and was investigated by the WithSecure Incident Response team.
Article
The Changing Economics of Cybercrime-as-a-Service: What Defenders Need to Know
Back in 2023, when we last wrote about Cybercrime-as-a-Service, we described cybercrime as an economy that had figured out how to scale
Publications
To the past and beyond: Andariel’s latest arsenal and cyberattacks
WithSecure proactively identified and notified a European customer belonging to the public/legal sector of a breach attributed with high confidence to the Andariel group, a state-sponsored cyber group linked to the Reconnaissance General Bureau (RGB) 3rd bureau of Democratic People’s Republic of Korea (DPRK).
Article
TangleCrypt: a sophisticated but buggy malware packer
WithSecure's STINGR Group is releasing a detailed technical analysis of TangleCrypt, a previously undocumented packer for Windows malware.
Article
WEBJACK: Evolving IIS Hijacking Campaign Abuses SEO for Fraud and Monetization
WithSecure’s STINGR has been investigating a malware campaign, tracked as WEBJACK, which compromises Microsoft IIS servers
Article
TamperedChef: Malvertising to Credential Theft
TamperedChef is a sophisticated malware campaign that leveraged a convincing advertising campaign strategy and a fully functional decoy application to target European organizations.
Article
Email-Delivered RMM: Abusing PDFs for Silent Initial Access
Since November 2024, WithSecure has been tracking a slight uptick of targeted activities leveraging Remote Monitoring and Management (RMM) tools embedded within PDF documents.
Article
Active exploitation of on-premise SharePoint Server vulnerabilities “ToolShell”
On July 19th 2025, Microsoft reported on a set of vulnerabilities being actively exploited in-the-wild targeting on-premise SharePoint Servers,
Reports
Time to next exploit
Organizations are facing an attack surface that is not only expanding at an unprecedented rate but also becoming more difficult to manage using traditional security approaches.
Results not found
Results not found