Research & Reports
Long-form threat intelligence reports, adversary analysis, and technical deep-dives from the Threxar research team.
01
Ransomware Ecosystem Report: Q3 2026
A comprehensive analysis of ransomware group activity, victim sector distribution, average dwell times, and emerging double-extortion tactics observed in Q3 2026. Covers 8 active groups with confirmed victims.
ransomwarequarterly-reportthreat-landscapeRead Research Article →
02
Initial Access Broker Markets: A Structural Analysis
Deep-dive into how Initial Access Broker (IAB) markets operate, how they interface with ransomware affiliates, and what access types are most commonly traded. Includes pricing benchmarks from monitored listings.
IABdark-webransomwareaccess-marketsRead Research Article →
03
StealCraft Loader Technical Deep-Dive
Full reverse engineering report on the StealCraft loader: unpacking mechanism, second-stage injection, C2 protocol analysis, and persistence techniques. Includes YARA rules.
malwarereverse-engineeringloaderYARARead Research Article →
04
Credential Stuffing at Scale: Tactics and Automation
How threat actors automate credential stuffing operations using commercially available tools and residential proxy networks. Includes defensive recommendations for authentication systems.
credential-stuffingautomationauthenticationdefenceRead Research Article →
05
Linux & VMware Hypervisor Ransomware Vulnerabilities
Technical investigation into hypervisor-specific ransomware variants (Rust/Go) designed to target ESXi datastores directly.
vmwareesxiransomwarehypervisorRead Research Article →
06
Underground Data Leak Forum Telemetry Report
Quarterly statistical overview of leak portal traffic, breach database post frequency, and threat actor monetization channels.
dark-webbreach-datatelemetryRead Research Article →
07
Zero-Day Exploitation Trends in Perimeter Gateways
Empirical review of zero-day vulnerabilities targeted in SSL-VPN, firewalls, and edge infrastructure throughout 2026.
cvezero-dayvpnperimeterRead Research Article →
08
Supply Chain Compromises in Open-Source Ecosystems
Examining malicious NPM and PyPI package publishing campaigns used to deliver stealthy infostealer payloads.
supply-chainnpmpypiinfostealerRead Research Article →
09
APT Espionage Operations Targeting Defense Contractors
Comprehensive dossier on long-term stealth campaigns abusing custom DLL side-loading and encrypted TLS tunnels.
aptespionagedefensedll-sideloadingRead Research Article →
10
Automated Ransomware Dwell Time Reduction Metrics
Statistical analysis of time elapsed between initial access broker handoff and ransomware payload deployment.
ransomwaredwell-timeincident-responseRead Research Article →
Commission a Report
Need a tailored threat intelligence report for your sector, technology stack, or geographic region? Get in touch via the contact form.
Get in touch →