W/Labs - WithSecure™

WithSecure™ ·

2 min read Original article ↗

Most up-to-date information regarding WithSecure

Overhead view down a wooden staircase of two people working on laptops in a casual seating nook below.

Article

Stolen creds and stinging loaders: An initial access campaign via SEO poisoning

Blog post

GREYVIBE: A Russia-nexus group leveraging AI across state-aligned operations

W/Labs

WithSecure uncovers Russia-nexus threat group using AI to target Ukraine and European organisations

Article

The ‘vice’ in tech advice: ClickFix-style commands disguised as tech tips across social media platforms and beyond

Article

Ivanti EPMM Exploitation: Hit-and-Run

This blogpost, written by WithSecure’s STINGR Group, presents the analysis of a security incident that happened in February 2026 and was investigated by the WithSecure Incident Response team.

Article

The Changing Economics of Cybercrime-as-a-Service: What Defenders Need to Know

Back in 2023, when we last wrote about Cybercrime-as-a-Service, we described cybercrime as an economy that had figured out how to scale

Publications

To the past and beyond: Andariel’s latest arsenal and cyberattacks

WithSecure proactively identified and notified a European customer belonging to the public/legal sector of a breach attributed with high confidence to the Andariel group, a state-sponsored cyber group linked to the Reconnaissance General Bureau (RGB) 3rd bureau of Democratic People’s Republic of Korea (DPRK).

Article

TangleCrypt: a sophisticated but buggy malware packer

WithSecure's STINGR Group is releasing a detailed technical analysis of TangleCrypt, a previously undocumented packer for Windows malware.

Article

WEBJACK: Evolving IIS Hijacking Campaign Abuses SEO for Fraud and Monetization

WithSecure’s STINGR has been investigating a malware campaign, tracked as WEBJACK, which compromises Microsoft IIS servers

Article

TamperedChef: Malvertising to Credential Theft

TamperedChef is a sophisticated malware campaign that leveraged a convincing advertising campaign strategy and a fully functional decoy application to target European organizations.

Article

Email-Delivered RMM: Abusing PDFs for Silent Initial Access

Since November 2024, WithSecure has been tracking a slight uptick of targeted activities leveraging Remote Monitoring and Management (RMM) tools embedded within PDF documents.

Article

Active exploitation of on-premise SharePoint Server vulnerabilities “ToolShell”

On July 19th 2025, Microsoft reported on a set of vulnerabilities being actively exploited in-the-wild targeting on-premise SharePoint Servers,

Not Found

No results found, please try something else!