Skip to main content
PPPhishPondPhishing Tradecraft Intelligence

Attack · Detection · Validation

CampaignTradecraftInfrastructureDetectionResearchRadarNewsroomAboutSubscribe
CampaignTradecraftInfrastructureDetectionResearchRadarNewsroomAboutSubscribe

Research Desk

PhishPond

Phishing tradecraft research desk covering campaign analysis, adversary infrastructure, detection engineering, and validation workflows.

High signal for security teams who need tradecraft, not recycled filler.

Navigate

  • Home
  • Newsroom
  • Research
  • Subscribe

Signals

  • editorial@phishpond.dev
  • Research Mission & Ethics
  • Intel Brief
  • RSS Feed
  • Submit Research Tip
© 2026 PhishPond. Authorized security research use only.

Category

Tradecraft Labs

End-to-end technique walkthroughs and operator workflows, with detection and validation.

Tradecraft Labs Archive

7 entries

Field Analysis

Dual UseTradecraft LabsJun 7, 202611 min read

The Step After the Click: Five Persistence Primitives That Survive Your Response

Mailbox rules, OAuth grants, replayed sessions, RMM agents, and downstream account changes are not the aftermath of an intrusion — they are the point. A field guide to the persistence layer most response playbooks still treat as cleanup.

Read more:FBI IC3The Hacker News

By PhishPond Desk

  • #Tradecraft Labs
  • #Persistence
  • #Post-Compromise

Field Analysis

Dual UseTradecraft LabsJun 7, 20268 min read

The Procedure Is the Threat: Why an Intrusion's Shape Outlives Its Toolkit

Runtimes, platforms, and brands rotate every quarter. The six handoffs that move a victim from manufactured urgency to durable persistence have barely changed in five years, and they are what defenders can actually build for.

Read more:FBI IC3Microsoft Security Blog

By PhishPond Desk

  • #Tradecraft Labs
  • #Methodology
  • #Initial Access

Field Analysis

Dual UseTradecraft LabsJun 7, 20267 min read

Silent Ransom Group Walks Into the Office: Help-Desk Impersonation Adds a Physical Step

An FBI flash alert says Silent Ransom Group escalates its IT-impersonation chain by sending an operator to the target's office when the phone-and-email stages fail. Law firms are the named victim set, and the number of leaked firms is rising.

Read more:FBI IC3BleepingComputer

By PhishPond Desk

  • #Tradecraft Labs
  • #Help Desk Impersonation
  • #Silent Ransom Group

Field Analysis

Dual UseTradecraft LabsMay 20, 20269 min read

MuddyWater's Teams Playbook: Screen-Share Credential Theft Behind a False Flag

An Iranian actor opened an intrusion with a Microsoft Teams chat request and a screen-sharing session, harvested credentials live, then staged ransomware as cover for a state-backed operation.

Read more:The Hacker NewsRapid7

By PhishPond Desk

  • #Tradecraft Labs
  • #MuddyWater
  • #Microsoft Teams

Field Analysis

Dual UseTradecraft LabsMay 16, 202610 min read

APT Methods Watch: Geofenced Lures, ClickFix, and Supply Chain Trust

Recent actor reporting points to a practical trend line: adversaries are combining selective delivery, user-driven execution, and trusted developer channels.

Read more:The Hacker NewsDark Reading

By PhishPond Desk

  • #Tradecraft Labs
  • #Initial Access
  • #ClickFix

Field Analysis

Blue TeamTradecraft LabsMay 6, 20268 min read

RMM Phishing Turns the Click Into Remote Access

Recent campaigns using SimpleHelp and ScreenConnect show how phishing can skip credential theft and move straight to persistent endpoint control.

Read more:The Hacker NewsDark Reading

By PhishPond Desk

  • #RMM
  • #Endpoint Security
  • #Initial Access

Field Analysis

Blue TeamTradecraft LabsMay 1, 202611 min read

Device Code Phishing: A Walkthrough and Detection Playbook

Device code phishing turns a legitimate OAuth flow into a credential-free token theft technique. Here is how it runs end-to-end and what defenders can hunt on in Sentinel and Defender XDR.

Read more:Microsoft Security BlogIETF

By PhishPond Desk

  • #Device Code
  • #OAuth
  • #Identity

Explore Other Categories

  • Campaign Analysis
  • Infrastructure Intelligence
  • Detection & Validation
  • Research Reports