Home/Intelligence library
Cypho research

Intelligence for the teams behind the defense.

Research, analysis, and practical guidance on the threats, vulnerabilities, and adversaries shaping today's security landscape.

Explore the latest research
Research coverageContinuously updated
01Threat actors
02Dark web
03Attack surface
04Vulnerability research
Latest intelligence

Research you can put to work.

Go beyond headlines with analyst-led context, defensive guidance, and clear takeaways for security teams.

21articles
Free vs. Premium: The Hidden Pricing Model Behind Stolen Credentials
Threat Intel
Aug 19, 2026Cypho Research Team

Free vs. Premium: The Hidden Pricing Model Behind Stolen Credentials

How the stealer log economy splits into free and paid tiers, what actually makes a log valuable, what a single credential can expose inside an organization, and how the 2024 Snowflake breach shows exactly how far that chain can run.

Read analysis
Pequod: A Docker and Redis Botnet Delivering an XMRig Miner and Reverse-Proxy Payload
Threat Intel
Aug 13, 2026Cypho Research Team

Pequod: A Docker and Redis Botnet Delivering an XMRig Miner and Reverse-Proxy Payload

One rented VPS, three payloads — a self-naming dropper, a Docker API scanner, and a Redis module that turns MODULE LOAD into remote code execution — all converging on the same Monero wallet.

Read analysis
Anatomy of a Multi-Architecture IoT Botnet
Threat Intel
Aug 6, 2026Cypho Research Team

Anatomy of a Multi-Architecture IoT Botnet

Inside a three-tier infrastructure of adaptive droppers and fileless C2 — a brute-force stager, an adaptive dropper, and a C2 hiding behind a real web server, tracked tier by tier from honeypot capture to payload teardown.

Read analysis
Closing the Loop on a Redis Worm: From Cron Injection to Self-Propagation
Threat Intel
Jul 25, 2026Cypho Research Team

Closing the Loop on a Redis Worm: From Cron Injection to Self-Propagation

A captured Redis exploit led us from a 1,644-byte cron injection to a self-propagating cryptomining campaign that disables defenses, hides behind shell-script rootkits, and hunts for its next victim.

Read analysis
Beyond IOC Feeds: Building a Modern CTI Platform for Proactive Cyber Defense
Threat Intel
Jul 21, 2026Cypho Research Team

Beyond IOC Feeds: Building a Modern CTI Platform for Proactive Cyber Defense

Why simple Indicator of Compromise lists are losing their edge, how the Pyramid of Pain and MITRE ATT&CK reframe threat intelligence around attacker behavior, and what a modern CTI platform actually looks like in practice.

Read analysis
From Fake Domains to Deepfake Scams: One Target, Two Tools
Brand Protection
Jul 13, 2026Cypho Research Team

From Fake Domains to Deepfake Scams: One Target, Two Tools

Brand impersonation has evolved from typo-squatted domains and fake login pages to cloned executive voices and fabricated videos. A look at why the old brand-monitoring playbook is falling behind, and what a threat-intelligence-driven defense actually looks like.

Read analysis
Move from reading to response

Bring real-time threat intelligence into your workflow.

See how Cypho turns external signals into prioritized action.

Request a demo