
Cybercrime Security Research
SpyCloud Labs is a focused cybercrime research group dedicated to uncovering and analyzing the most intricate patterns from the criminal underground. We nerd out on all things breach, malware, phishing, and threat actor-related โ and are hellbent on making the internet a safer place for all. This is a space for our experts to share our latest research findings as well as best practices and solutions for organizations to better their defenses.
Latest security research
Dig in with us as we analyze digital underground collections, reverse-engineer malware, and identify threat actor patterns.

The LummaC2 Takedown, Attack Trends & Forum War Fighting
From the LummaC2 takedown to the BreachForums void, our May cybercrime update breaks down the biggest cyber threats & news.

Freshly Stolen: The New Age of Combolists
ULP combolists often contain fresh infostealer data. Hereโs what to know about ULP combolists, including how to defend your organization from credential theft & attacks.

April Cybercrime Update: BreachForums Down, A Big Twitter Leak & Atomic Stealer Infection Trends
From the Twitter/X breach to Atomic macOS Stealer infection trends, our April cybercrime update breaks down the biggest cyber threats and news.
Webinars and videos
Tune in to hear new and interesting research insights from our experts, first-hand.

Minding the Malware Gap โ Identity Threat Protection Beyond The Endpoint
This webinar explores the latest malware trends uncovered by our SpyCloud Labs team, and how these insights help security teams enable proactive measures to secure corporate access.

Journey to the Underground: Insights Into What’s Fueling Ransomware in 2024
This webinar breaks down the most important findings from The SpyCloud 2024 Malware and Ransomware Defense Report and what your organization can do to get ahead of emerging cyber threats.

The Illicit Chinese “Pantsless Data” Trade
Hear from SpyCloud Labs researchers how Chinese cybercriminals are accessing, exfiltrating, and trading vast amounts of PII, with international impact.
SpyCloud Labs in the news
Insights and research from the team making headlines.
2025 Cybersecurity Excellence Awards “Cybersecurity Team of the Year”
Meet the research team
Trevor Hilligoss
Wallis Romzek, PhD
Kyla Cardona
Joe Roosen
Aurora Johnson
Mike Dausin
Jakob S.
James
Yashar H.
Daniel
Paul S.
Andy Culler
Keegan Keplinger
Zoe Neale
Aaron Coffey
Meet the research team
Trevor Hilligoss
Wallis Romzek, PhD
James
Kyla Cardona
Joe Roosen
Aurora Johnson
Mike Dausin
Jakob S.
Yashar H.
Daniel
Paul S.
Keegan Keplinger
Andy Culler
Zoe Neale
Aaron Coffey
Meet the research team
Trevor Hilligoss
Wallis Romzek, PhD
James
Kyla Cardona
Joe Roosen
Aurora Johnson
Mike Dausin
Yashar H.
Daniel
Jakob S.
Paul S.
Keegan Keplinger
Andy Culler
Zoe Neale
Aaron Coffey
Driven by SpyCloud Cybercrime Analytics
The purpose of SpyCloud Labs is to relentlessly analyze the active tactics weโre seeing among cybercriminals and look ahead in the evolution of these practices. We use Cybercrime Analytics to illuminate exposures relating to employee and customer credentials, cookies, PII, and other stolen assets so you can protect your organization.
Assets

Breaches


Malware
Families
