Resources / Threat intelligence

Threat signals.Operational context.

Cyber Struggle Delta

Evidence before assumptions.

Each report turns collected artifacts and observed behavior into a structured record of targeting, tradecraft, technical execution and defensive relevance.

01 / REPORT

TLP: AMBER

06 May 202020CTI212PDF · 15 pages

Leery Turtle Threat Report

An intelligence and forensic assessment of a persistent threat group targeting cryptocurrency exchanges worldwide through reconnaissance, spear-phishing and custom malware.

  • Cryptocurrency exchanges
  • Spear-phishing
  • Custom malware
  • Global activity
02 / REPORT

UNCLASSIFIED

17 January 2019CSDELTA / TITA0013PDF · 11 pages

APT37 New Year Attack

Malware analysis of a campaign targeting the South Korean Unification Ministry, covering information collection, suspected remote command execution and anti-analysis behavior.

  • APT37
  • Espionage
  • Information collection
  • Anti-analysis
03 / REPORT

TECHNICAL ANALYSIS

05 January 2019CVE-2018-4878Web analysis

Bankshot Dropper Analysis

Technical analysis of a malicious Word document used against financial organizations and cryptocurrency exchanges to exploit Adobe Flash and deliver a second-stage implant.

  • Bankshot
  • Lazarus Group
  • Adobe Flash
  • Second-stage malware

From artifact to action

Intelligence becomes valuable when it changes a decision.

The archive preserves technical findings and operational context so defenders can recognize patterns, test assumptions and improve future readiness.