## ABOUT US

Check Point Research provides leading cyber threat intelligence to Check Point Software customers and the greater intelligence community. The research team collects and analyzes global cyber attack data stored on [ThreatCloud](https://www.checkpoint.com/infinity/threatcloud/) to keep hackers at bay, while ensuring all Check Point products are updated with the latest protections. From the moment a breach is initiated, [ThreatCloud](https://www.checkpoint.com/infinity/threatcloud/) begins sharing data across the entire network, providing researchers with the intelligence they need to deeply analyze and report on attacks. Check Point Research publications and intelligence sharing fuel the discovery of new cyber threats and the development of the international threat intelligence community to keep you secure.

## LEADING THE THREAT INTELLIGENCE COMMUNITY

The research team consists of over 200 analysts and researchers cooperating with other security vendors, law enforcement and various CERTs. Their data sources includes open sources, the [ThreatCloud](https://www.checkpoint.com/infinity/threatcloud/) network and dark web intelligence. Internally, the team has developed their own machine learning modules, anomaly detection, reverse engineering and campaign hunting techniques that all assist in staying ahead of hackers and the latest cyber threats. You can follow all our latest research on [Twitter](https://twitter.com/_CPResearch_).

If you would like to collaborate or hear more about our research we would love to hear from you. Please feel free to contact us through [Twitter](https://twitter.com/_CPResearch_) or our [Contact Page](https://research.checkpoint.com/contact/).

## NOTABLE RESEARCH PUBLICATIONS BY CHECK POINT RESEARCH

- [2020-2022](https://research.checkpoint.com/about-us/#2020-2022)
- [2019-2020](https://research.checkpoint.com/about-us/#2019-2020)
- [2018](https://research.checkpoint.com/about-us/#2018)
- [2017](https://research.checkpoint.com/about-us/#2017)
- [2016](https://research.checkpoint.com/about-us/#2016)

- [Threat Actors Migrating to the Cloud](https://research.checkpoint.com/2020/threat-actors-migrating-to-the-cloud/)
- [Ransomware Evolved: Double Extortion](https://research.checkpoint.com/2020/ransomware-evolved-double-extortion/)
- [E-Learning Platforms Getting Schooled – Multiple Vulnerabilities in WordPress’ Most Popular Learning Management System Plugins](https://research.checkpoint.com/2020/e-learning-platforms-getting-schooled-multiple-vulnerabilities-in-wordpress-most-popular-learning-management-system-plugins/)
- [First seen in the wild – Malware uses Corporate MDM as attack vector](https://research.checkpoint.com/2020/mobile-as-attack-vector-using-mdm/)
- [SIGRed – Resolving Your Way into Domain Admin: Exploiting a 17 Year-old Bug in Windows DNS Servers](https://research.checkpoint.com/2020/sigred-hijacking-microsoft-windows-server/)
- [Hacker, 22, seeks LTR with your data: vulnerabilities found on popular OkCupid dating app](https://research.checkpoint.com/2020/hacker-22-seeks-ltr-with-your-data-vulnerabilities-found-on-popular-okcupid-dating-app/)
- [Don’t be silly – it’s only a lightbulb](https://research.checkpoint.com/2020/dont-be-silly-its-only-a-lightbulb/)
- [Keeping the gate locked on your IoT devices: Vulnerabilities found on Amazon’s Alexa](https://research.checkpoint.com/2020/amazons-alexa-hacked/)
- [Rampant Kitten – An Iranian Espionage Campaign](https://research.checkpoint.com/2020/rampant-kitten-an-iranian-espionage-campaign/)
- [Ransomware Alert: Pay2Key](https://research.checkpoint.com/2020/ransomware-alert-pay2key/)
- [The Story of Jian – How APT31 Stole and Used an Unknown Equation Group 0-Day](https://research.checkpoint.com/2021/the-story-of-jian/)
- [Pwn2Own Qualcomm DSP](https://research.checkpoint.com/2021/pwn2own-qualcomm-dsp/)
- [Indra — Hackers Behind Recent Attacks on Iran](https://research.checkpoint.com/2021/indra-hackers-behind-recent-attacks-on-iran/)
- [Looking for vulnerabilities in MediaTek audio DSP](https://research.checkpoint.com/2021/looking-for-vulnerabilities-in-mediatek-audio-dsp/)
- [APT35 exploits Log4j vulnerability to distribute new modular PowerShell toolkit](https://research.checkpoint.com/2022/apt35-exploits-log4j-vulnerability-to-distribute-new-modular-powershell-toolkit/)
- [Leaks of Conti Ransomware Group Paint Picture of a Surprisingly Normal Tech Start-Up… Sort Of](https://research.checkpoint.com/2022/leaks-of-conti-ransomware-group-paint-picture-of-a-surprisingly-normal-tech-start-up-sort-of/)
- [AirDrop process of ApeCoin cryptocurrency found vulnerable, led to theft of millions of dollars in NFTs](https://research.checkpoint.com/2022/airdrop-process-of-apecoin-cryptocurrency-found-vulnerable-led-to-theft-of-millions-of-dollars-in-nfts/)
- [Check Point Research detects vulnerability in the Everscale blockchain wallet, preventing cryptocurrency theft](https://research.checkpoint.com/2022/check-point-research-detects-vulnerability-in-the-everscale-blockchain-wallet-preventing-cryptocurrency-theft/)
- [#ALHACK: One codec to hack the whole world](https://research.checkpoint.com/2022/bad-alac-one-codec-to-hack-the-whole-world/)
- [State-sponsored Attack Groups Capitalise on Russia-Ukraine War for Cyber Espionage](https://research.checkpoint.com/2022/state-sponsored-attack-groups-capitalise-on-russia-ukraine-war-for-cyber-espionage/)
- [Twisted Panda: Chinese APT espionage operation against Russian’s state-owned defense institutes](https://research.checkpoint.com/2022/twisted-panda-chinese-apt-espionage-operation-against-russians-state-owned-defense-institutes/)
- [The New Era of Hacktivism – State-Mobilized Hacktivism Proliferates to the West and Beyond](https://research.checkpoint.com/2022/the-new-era-of-hacktivism/)

- [Hacking Fortnite Accounts](https://research.checkpoint.com/2019/hacking-fortnite/)
- [Reverse RDP attacks: Code Execution on RDP Clients](https://research.checkpoint.com/2019/reverse-rdp-attack-code-execution-on-rdp-clients/)
- [Operation Tripoli](https://research.checkpoint.com/2019/operation-tripoli/)
- [EA Games Vulnerability](https://research.checkpoint.com/2019/ea-games-vulnerability/)
- [Microsoft Management Console (MMC) Vulnerabilities](https://research.checkpoint.com/2019/microsoft-management-console-mmc-vulnerabilities/)
- [We Decide What You See: Remote Code Execution on a Major IPTV Platform](https://research.checkpoint.com/2019/we-decide-what-you-see-remote-code-execution-on-a-major-iptv-platform/)
- [UPSynergy: Chinese-American Spy vs. Spy Story](https://research.checkpoint.com/2019/upsynergy/)
- [Say Cheese: Ransomware-ing a DSLR Camera](https://research.checkpoint.com/2019/say-cheese-ransomware-ing-a-dslr-camera/)
- [Agent Smith: A new Species of Mobile Malware](https://research.checkpoint.com/2019/agent-smith-a-new-species-of-mobile-malware/)
- [The Eye on the Nile](https://research.checkpoint.com/2019/the-eye-on-the-nile/)
- [Mappint the connections inside Russia’s APT Ecosystem](https://research.checkpoint.com/2019/russianaptecosystem/)
- [Zoom-Zoom: We Are Watching You](https://research.checkpoint.com/2020/zoom-zoom-we-are-watching-you/)
- [The 2020 Cyber Security Report](https://research.checkpoint.com/2020/the-2020-cyber-security-report/)
- [Tik or Tok? Is TikTok secure enough?](https://research.checkpoint.com/2020/tik-or-tok-is-tiktok-secure-enough/)
- [Remote Cloud Execution – Critical Vulnerabilities in Azure Cloud Infrastructure](https://research.checkpoint.com/2020/remote-cloud-execution-critical-vulnerabilities-in-azure-cloud-infrastructure-part-ii/)
- [Vicious Panda: The COVID Campaign](https://research.checkpoint.com/2020/vicious-panda-the-covid-campaign/)

- [Domestic Kitten: An Iranian Surveillance Operation](https://research.checkpoint.com/domestic-kitten-an-iranian-surveillance-operation/)
- [Interactive Map of APT-C-23](https://research.checkpoint.com/interactive-mapping-of-apt-c-23/)
- [Ryuk Ransomware: A Targeted Campaign Breakdown](https://research.checkpoint.com/ryuk-ransomware-targeted-campaign-break/)
- [Faxploit: Hacking Fax Machines to Enter an IT Network](https://research.checkpoint.com/sending-fax-back-to-the-dark-ages/)
- [Man-In-The-Disk Android Vulnerabilities](https://research.checkpoint.com/androids-man-in-the-disk/)
- [FakesApp: Vulnerabilities in WhatsApp](https://research.checkpoint.com/fakesapp-a-vulnerability-in-whatsapp/)
- [Ramnit’s Network of Proxy Servers](https://research.checkpoint.com/ramnits-network-proxy-servers/)
- [Malvertising Campaign of Secrets and Lies](https://research.checkpoint.com/malvertising-campaign-based-secrets-lies/)
- [GlanceLove: Under the Cover of the World Cup](https://research.checkpoint.com/glancelove-spying-cover-world-cup/)
- [Cyber Trends Mid-Year Report](https://research.checkpoint.com/cyber-attack-trends-2018-mid-year-report/)
- [Remote Code Execution on LG Phones](https://research.checkpoint.com/lg-keyboard-vulnerabilities/)
- [SiliVaccine: Inside North Korea’s Anti-Virus](https://research.checkpoint.com/silivaccine-a-look-inside-north-koreas-anti-virus/)
- [CryptoMining Operation Unmasked](https://research.checkpoint.com/de-anonymizing-monero-mining-operation/)
- [NTLM Credentials Theft via PDF Files](https://research.checkpoint.com/ntlm-credentials-theft-via-pdf-files/)
- [A New Phishing Kit on the Dark Net](https://research.checkpoint.com/a-phishing-kit-investigative-report/)
- [Uncovering Drupalgeddon 2](https://research.checkpoint.com/uncovering-drupalgeddon-2/)
- [RottenSys: Not a Secure Wifi Service At All](https://research.checkpoint.com/rottensys-not-secure-wi-fi-service/)
- [The GandCrab Ransomware Mindset](https://research.checkpoint.com/gandcrab-ransomware-mindset/)
- [Jenkins Miner](https://research.checkpoint.com/jenkins-miner-one-biggest-mining-operations-ever-discovered/)
- [AdultSwine: Malware Displaying Porn on Kids Mobile Apps](https://research.checkpoint.com/malware-displaying-porn-ads-discovered-in-game-apps-on-google-play/)

### 2020-2022

### 2019-2020

### 2018

### 2017

- [Huawei Home Routers in Botnet Recruitment](https://research.checkpoint.com/good-zero-day-skiddie/)
- [Christmas is Coming, The Criminals Await](https://research.checkpoint.com/christmas-coming-criminals-await/)
- [IoT Botnet – Full Investigation](https://research.checkpoint.com/iotroop-botnet-full-investigation/)
- [Bad Rabbit – Full Investigation](https://research.checkpoint.com/bad-rabbit-full-research-investigation/)
- [IoT Botnet Storm Is Coming](https://research.checkpoint.com/new-iot-botnet-storm-coming/)
- [Brazilian Bankingware](https://research.checkpoint.com/perfect-inside-job-banking-malware/)
- [EternalBlue – Everything There Is To Know](https://research.checkpoint.com/eternalblue-everything-know/)
- [ExpensiveWall](https://research.checkpoint.com/expensivewall-dangerous-packed-malware-google-play-will-hit-wallet/)
- [Beware Of The Bashware](https://research.checkpoint.com/beware-bashware-new-method-malware-bypass-security-solutions/)
- [Malware Hiding In Your Resume](https://research.checkpoint.com/is-malware-hiding-in-your-resume-vulnerability-in-linkedin-messenger-would-have-allowed-malicious-file-transfer/)
- [Get Rich or Die Trying](https://research.checkpoint.com/get-rich-or-die-trying-a-case-study-on-the-real-identity-behind-a-wave-of-cyber-attacks-on-energy-mining-and-infrastructure-companies/)
- [JavaScript Lost in Dictionary](https://research.checkpoint.com/javascript-lost-in-the-dictionary/)
- [OSX/DOK](http://blog.checkpoint.com/2017/07/13/osxdok-refuses-go-away-money/)
- [WannaCry Registered Killswitch](http://blog.checkpoint.com/2017/05/15/wannacry-new-kill-switch-new-sinkhole/)
- [Lost in Translation](http://blog.checkpoint.com/2017/05/23/hacked-in-translation/)
- [Fireball](http://blog.checkpoint.com/2017/06/01/fireball-chinese-malware-250-million-infection/) – Led to eventual apprehension of attack perpetrators

### 2016

- [EZCast Vulnerability](http://blog.checkpoint.com/2016/01/07/youre-watching-tv-is-it-also-watching-you/)
- [HummingBad](http://blog.checkpoint.com/2016/02/04/hummingbad-a-persistent-mobile-chain-attack/)
- [Sidestepper](http://blog.checkpoint.com/2016/03/31/sidestepper/)
- [VikingHorde](http://blog.checkpoint.com/2016/05/09/viking-horde-a-new-type-of-android-malware-on-google-play/)
- [QuadRooter](http://blog.checkpoint.com/2016/08/07/quadrooter/)
- [DressCode](http://blog.checkpoint.com/2016/08/31/dresscode-android-malware-discovered-on-google-play/)
- [ImageGate](http://blog.checkpoint.com/2016/11/24/imagegate-check-point-uncovers-new-method-distributing-malware-images/)
- [Gooligan](http://blog.checkpoint.com/2016/11/30/1-million-google-accounts-breached-gooligan/)
- Check Point Research was also the first to reveal the infrastructure and operations behind the [Cerber ransomware](http://blog.checkpoint.com/2016/07/05/check-point-forensic-files-cerber-ransomware-distribution-using-office-dotm-files/) and the [Nuclear Exploit Kit.](http://blog.checkpoint.com/2016/04/20/inside-nuclears-core-analyzing-the-nuclear-exploit-kit-infrastructure/)

**Note:** The subscription and cookie consent sections have been omitted as per cleaning directives.
