ThreatBook Research Team

The ThreatBook Research and Response Team leads the forefront of cybersecurity analysis and security operations. Its core research focuses on automated threat intelligence, advanced APT tracking, cybercrime industry monitoring, malware and automated analysis technologies, and major incident response. Composed of seasoned experts in malware analysis, forensic investigation, web attack technologies, attribution, big data, AI, and other advanced security disciplines, the team leverages proprietary systems — including automated intelligence production, cloud sandbox, hacker profiling, threat hunting, tracking and tracing, threat perception, and big data correlation knowledge graphs—to analyze and correlate millions of new malware samples, tens of millions of URLs, PDNS, and Whois records added daily to ThreatBook. Since its inception, the team has consistently been among the first to detect and monitor sophisticated APT groups targeting critical infrastructure and industries such as finance, energy, government, and high-tech. They have supported hundreds of clients worldwide in responding to high-impact global incidents — including the WannaCry ransomware outbreak — and in managing persistent, targeted attacks such as OceanLotus on maritime, high-tech, and financial sectors, and Patchwork campaigns affecting governments, diplomatic entities, universities, and research institutions.

3 min read

Singapore's Cyber Threat Landscape: Inside the 2025 Data

The Threat Landscape An Open Economy, an Outsized Target Singapore's unique geographic position and economic standing have made it a frontline battleground for both regional cybercrime networks and state-sponsored cyber forces. Its advanced...

Read More

2 min read

Hong Kong's Cyber Threat Landscape: Inside the 2025 Data

The Threat Landscape A City Built on Commerce — and Cross-Border Risk Hong Kong's cyberattack landscape reflects the city's unique position. Unlike...

Read More

3 min read

Suspected North Korea-Linked Hackers Conduct Targeted Attack Campaign Against Uzbekistan

Overview In November 2025, ThreatBook Research Team identified two suspected targeted attack campaigns against targets within Uzbekistan. We...

Read More

4 min read

Unknown Group Leverages Novel In-Memory Backdoor in Targeted Attacks Against Central Asia and China

Overview In November 2025, the ThreatBook Research Team captured a cluster of cyber espionage activity operating within Kyrgyzstan and China, using...

Read More

11 min read

SilverFox: Not an Organization, But a Tool - Uncovering the Underground Ecosystem

Executive Summary For months, the cybersecurity community tracked what appeared to be a sophisticated cybercrime organization dubbed "SilverFox"....

Read More