Resources / Threat intelligence

Threat signals.Operational context.

Evidence-led intelligence and technical analysis created to clarify adversary behavior, attack paths and the defensive decisions that follow.

Cyber Struggle Delta

Evidence before assumptions.

Each report turns collected artifacts and observed behavior into a structured record of targeting, tradecraft, technical execution and defensive relevance.

01 / REPORT

TLP: AMBER

06 May 202020CTI212PDF · 15 pages

Leery Turtle Threat Report

An intelligence and forensic assessment of a persistent threat group targeting cryptocurrency exchanges worldwide through reconnaissance, spear-phishing and custom malware.

  • Cryptocurrency exchanges
  • Spear-phishing
  • Custom malware
  • Global activity
02 / REPORT

UNCLASSIFIED

17 January 2019CSDELTA / TITA0013PDF · 11 pages

APT37 New Year Attack

Malware analysis of a campaign targeting the South Korean Unification Ministry, covering information collection, suspected remote command execution and anti-analysis behavior.

  • APT37
  • Espionage
  • Information collection
  • Anti-analysis
03 / REPORT

TECHNICAL ANALYSIS

05 January 2019CVE-2018-4878Web analysis

Bankshot Dropper Analysis

Technical analysis of a malicious Word document used against financial organizations and cryptocurrency exchanges to exploit Adobe Flash and deliver a second-stage implant.

  • Bankshot
  • Lazarus Group
  • Adobe Flash
  • Second-stage malware

From artifact to action

Intelligence becomes valuable when it changes a decision.

The archive preserves technical findings and operational context so defenders can recognize patterns, test assumptions and improve future readiness.