Emulating the Systematic LokiLocker Ransomware

Emulating the Systematic LokiLocker Ransomware

AttackIQ has released a new attack graph that emulates the behaviors of LokiLocker ransomware, a .NET based strain active since at least mid-August 2021. The malware combines defense evasion and impact techniques, ...
Evergreen Phishing Defense: Automated Weekly Security Validation

Evergreen Phishing Defense: Automated Weekly Security Validation

What if your phishing tests updated themselves every week? Learn how real phishing campaigns are automatically transformed into continuous email and endpoint validation—at scale. The post Evergreen Phishing Defense: Automated Weekly Security ...
25 New Adversary Emulation Packages Covering Ransomware and Advisory-Driven Threats

25 New Adversary Emulation Packages Covering Ransomware and Advisory-Driven Threats

Effective defense depends on understanding how adversaries operate across complete intrusion chains, not just whether individual controls trigger. The post 25 New Adversary Emulation Packages Covering Ransomware and Advisory-Driven Threats appeared first ...
Emulating the Elegant BlackSuit Ransomware

Emulating the Elegant BlackSuit Ransomware

AttackIQ has released a new attack graph that emulates the behaviors exhibited by BlackSuit ransomware, a ransomware strain that has been active since at least May 2023. It represents the evolution of ...

React2Shell (CVE-2025-55182): Critical Remote Code Execution (RCE) in React Server Components

AttackIQ released a new assessment template that compiles the Tactics, Techniques, and Procedures (TTPs) associated with the exploitation of the critical CVE-2025-55182 (React2Shell) Remote Code Execution (RCE) vulnerability affecting React Server Components ...
Ransom Tales: Volume VI — Throwback Edition! Emulating Ryuk, Conti, and BlackCat Ransomware

Ransom Tales: Volume VI — Throwback Edition! Emulating Ryuk, Conti, and BlackCat Ransomware

On July 22, 2025, AttackIQ introduced Ransom Tales, an initiative focused on routinely emulating the Tactics, Techniques, and Procedures (TTPs) associated with the prolific ransomware families currently dominating the threat landscape. Each ...
Revisiting the Versatile Qilin Ransomware

Revisiting the Versatile Qilin Ransomware

AttackIQ has released an updated attack graph in response to emerging threat intelligence associated with the deployment of Qilin ransomware, a ransomware strain that first appeared in July 2022 and remains one ...

Emulating the Destructive Sandworm Adversary

AttackIQ has released a new assessment template designed to emulate the various post-compromise Tactics, Techniques, and Procedures (TTPs) associated with a recent intrusion targeting Ukrainian organizations that aligns with patterns previously associated ...
Emulating the Espionage-Oriented Group SideWinder

Emulating the Espionage-Oriented Group SideWinder

AttackIQ has released a new attack graph that emulates the behaviors exhibited by SideWinder, a threat actor with a long history of cyber espionage dating back to 2012. The group has primarily ...
Emulating the Prominent Global Group Ransomware

Emulating the Prominent Global Group Ransomware

AttackIQ has released a new attack graph that emulates the behaviors exhibited by Global Group ransomware, a threat that first appeared in June 2025 and quickly became notorious across the security landscape ...