Skip to content

Research & Reports

Long-form threat intelligence reports, adversary analysis, and technical deep-dives from the Threxar research team.

01
Ransomware Ecosystem Report: Q3 2026
A comprehensive analysis of ransomware group activity, victim sector distribution, average dwell times, and emerging double-extortion tactics observed in Q3 2026. Covers 8 active groups with confirmed victims.
15 September 2026ransomwarequarterly-reportthreat-landscapeRead Research Article →
02
Initial Access Broker Markets: A Structural Analysis
Deep-dive into how Initial Access Broker (IAB) markets operate, how they interface with ransomware affiliates, and what access types are most commonly traded. Includes pricing benchmarks from monitored listings.
28 August 2026IABdark-webransomwareaccess-marketsRead Research Article →
03
StealCraft Loader Technical Deep-Dive
Full reverse engineering report on the StealCraft loader: unpacking mechanism, second-stage injection, C2 protocol analysis, and persistence techniques. Includes YARA rules.
24 September 2026malwarereverse-engineeringloaderYARARead Research Article →
04
Credential Stuffing at Scale: Tactics and Automation
How threat actors automate credential stuffing operations using commercially available tools and residential proxy networks. Includes defensive recommendations for authentication systems.
10 August 2026credential-stuffingautomationauthenticationdefenceRead Research Article →
05
Linux & VMware Hypervisor Ransomware Vulnerabilities
Technical investigation into hypervisor-specific ransomware variants (Rust/Go) designed to target ESXi datastores directly.
1 August 2026vmwareesxiransomwarehypervisorRead Research Article →
06
Underground Data Leak Forum Telemetry Report
Quarterly statistical overview of leak portal traffic, breach database post frequency, and threat actor monetization channels.
22 July 2026dark-webbreach-datatelemetryRead Research Article →
07
Zero-Day Exploitation Trends in Perimeter Gateways
Empirical review of zero-day vulnerabilities targeted in SSL-VPN, firewalls, and edge infrastructure throughout 2026.
11 July 2026cvezero-dayvpnperimeterRead Research Article →
08
Supply Chain Compromises in Open-Source Ecosystems
Examining malicious NPM and PyPI package publishing campaigns used to deliver stealthy infostealer payloads.
29 June 2026supply-chainnpmpypiinfostealerRead Research Article →
09
APT Espionage Operations Targeting Defense Contractors
Comprehensive dossier on long-term stealth campaigns abusing custom DLL side-loading and encrypted TLS tunnels.
15 June 2026aptespionagedefensedll-sideloadingRead Research Article →
10
Automated Ransomware Dwell Time Reduction Metrics
Statistical analysis of time elapsed between initial access broker handoff and ransomware payload deployment.
30 May 2026ransomwaredwell-timeincident-responseRead Research Article →
Commission a Report

Need a tailored threat intelligence report for your sector, technology stack, or geographic region? Get in touch via the contact form.

Get in touch →