LevelBlue (formerly Trustwave) SpiderLabs
trustwave-spiderlabs · B · active
https://www.levelblue.com/blogs/spiderlabs-blog
Trustwave SpiderLabs was rebranded to LevelBlue in 2025. URL CORRECTED 2026-05-08: legacy https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog 301-redirects to www.levelblue.com/blogs/spiderlabs-blog. 2026-05-08 audit: WebFetch returned 5 dated 2026 posts latest 2026-05-07 (Vidar/AutoIt, LevelBlue TTP Briefing, Vect ransomware). | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → webfetch https://www.levelblue.com/blogs/spiderlabs-blog (listing) then webfetch the per-post www.levelblue.com/blogs/spiderlabs-blog/<slug> for full malware/TTP analysis. AVOID: Don't use the legacy trustwave.com URL, it 301s to levelblue.com (already corrected in the source). WebFetch works directly, no bridge.. | 2026-07-05 admiralty audit: B, reputable vendor threat-research lab, original malware/TTP analysis; levelblue.com URL (post-rebrand) resolves cleanly via WebFetch. No status change.
Cited in 6 entries
Citation cadence
Citation days per ISO week (9 weeks of coverage span, total 6).
- Chaotic Eclipse turns its zero-day drops on third-party security products: local privilege escalation in CrowdStrike Falcon and Avast, with working proof-of-concept code public; all three vendors have since remediated2026-09-06
- CNCMachineRMS, an undocumented remote-access trojan delivered through a four-stage BabaDeda loader chain that smuggles shellcode via a benign Windows date-formatting API2026-08-28
- ShieldBreak, a public proof-of-concept defeats Microsoft's July fix for the RoguePlanet Defender flaw, claims 100% reliability where the original was a coin flip, and now covers Windows Server 20252026-08-12
- A ScreenConnect distribution campaign fronts fake Microsoft Store and App Store update dialogs, and binds each installer to its operator's relay with an embedded key2026-08-08
- LegacyHive: a public Windows technique that redirects a profile's Local AppData into the NT Object Manager namespace via offline hive edits, reproduced on fully patched systems2026-07-29
- CrySome RAT freight-phishing chain: AMSI bypass, ICMLuaUtil UAC bypass and an open-source Defender-disruption tool2026-07-08