
Cybercrime Security Research
SpyCloud Labs is a focused cybercrime research group dedicated to uncovering and analyzing the most intricate patterns from the criminal underground. We nerd out on all things breach, malware, phishing, and threat actor-related – and are hellbent on making the internet a safer place for all. This is a space for our experts to share our latest research findings as well as best practices and solutions for organizations to better their defenses.
Latest security research
Dig in with us as we analyze digital underground collections, reverse-engineer malware, and identify threat actor patterns.

Exposed Credentials & Ransomware Operations: Using LLMs to Digest 200K Messages from the Black Basta Chats
We analyzed the nearly 200K leaked Black Basta chats and this is what we learned about their use of exposed credentials for ransomware operations.

Residential Proxies, North Korean IT Workers & Smishing
A deep dive into March’s cybercrime trends, including GhostSocks, North Korean IT workers, and pesky smishing campaigns.

On the Hunt for Ghost(Socks)
LummaC2’s link to GhostSocks reveals stealthy proxy access, long-term persistence, and advanced evasion—posing a serious threat to enterprise defenses.
Webinars and videos
Tune in to hear new and interesting research insights from our experts, first-hand.

Minding the Malware Gap – Identity Threat Protection Beyond The Endpoint
This webinar explores the latest malware trends uncovered by our SpyCloud Labs team, and how these insights help security teams enable proactive measures to secure corporate access.

Journey to the Underground: Insights Into What’s Fueling Ransomware in 2024
This webinar breaks down the most important findings from The SpyCloud 2024 Malware and Ransomware Defense Report and what your organization can do to get ahead of emerging cyber threats.

The Illicit Chinese “Pantsless Data” Trade
Hear from SpyCloud Labs researchers how Chinese cybercriminals are accessing, exfiltrating, and trading vast amounts of PII, with international impact.
SpyCloud Labs in the news
Insights and research from the team making headlines.
2025 Cybersecurity Excellence Awards “Cybersecurity Team of the Year”
Meet the research team
Trevor Hilligoss
Wallis Romzek, PhD
Kyla Cardona
Joe Roosen
Aurora Johnson
Mike Dausin
Jakob S.
James
Yashar H.
Daniel
Paul S.
Keegan Keplinger
Andy Culler
Meet the research team
Trevor Hilligoss
Wallis Romzek, PhD
James
Kyla Cardona
Joe Roosen
Aurora Johnson
Mike Dausin
Jakob S.
Yashar H.
Daniel
Paul S.
Keegan Keplinger
Andy Culler
Meet the research team
Trevor Hilligoss
Wallis Romzek, PhD
James
Kyla Cardona
Joe Roosen
Aurora Johnson
Mike Dausin
Yashar H.
Daniel
Jakob S.
Paul S.
Keegan Keplinger
Andy Culler
Driven by SpyCloud Cybercrime Analytics
The purpose of SpyCloud Labs is to relentlessly analyze the active tactics we’re seeing among cybercriminals and look ahead in the evolution of these practices. We use Cybercrime Analytics to illuminate exposures relating to employee and customer credentials, cookies, PII, and other stolen assets so you can protect your organization.
Assets

Breaches


Malware
Families
