
Latrodectus: The Black Widow Loader Quietly Replacing IcedID
Named after the black widow spider, Latrodectus is a lightweight but potent loader built by the people behind IcedID.
Resources
Adversary infrastructure, malware teardowns and copy-ready IOCs.

Named after the black widow spider, Latrodectus is a lightweight but potent loader built by the people behind IcedID.

UNC2891 cabled a 4G Raspberry Pi straight into a bank’s ATM network switch, hid its backdoor from forensic triage with a novel Linux bind-mount trick, and aimed…

Symantec found the Daxin kernel rootkit still operational on a Taiwan manufacturing subsidiary in 2026, alongside a previously undocumented backdoor, Stupig, that runs SYSTEM commands from the Windows logon screen before anyone signs in.

Medusa is a ransomware-as-a-service operation that has hit 300+ organisations across healthcare, education, manufacturing and other critical sectors.

GodDamn is a fresh rebrand of the Beast/Monster ransomware lineage that switches off endpoint defenses before it encrypts.

SPECTRALVIPER is a heavily obfuscated x64 Windows backdoor used against large, strategically important Vietnamese companies.

MirrorFace, a China-aligned espionage group inside the APT10 umbrella (also tracked as Earth Kasha), spent years quietly targeting Japan’s government, politicians, think tanks and defence-adjacent industry.

The crew that stopped robbing bank customers and learned to rob the bank itself.

MirrorBlast hits financial-services organisations with an Excel document so lightweight it is nearly undetectable on VirusTotal.

Most Linux runtime security watches system calls. A growing class of stealth techniques, eBPF abuse and the io_uring asynchronous-I/O interface, does its work without the syscalls those tools hook.

China-aligned FishMonger (Earth Lusca) has ported its SprySOCKS backdoor to Windows and bolted on a kernel driver, RawWNPF, that hides processes, files, connections and registry keys, and turns any open TCP port into a hidden door and erases itself from every tool you’d use to find it.

PoisonX: A Signed Kernel Driver That Turns Your EDR Into a Target A Microsoft-signed BYOVD driver used to kill CrowdStrike Falcon and other security tooling from Ring 0.

A new post-exploitation implant abuses the Linux authentication stack (PAM) to harvest plaintext SSH credentials from every user who logs in, and hands the operator a covert, persistent backdoor.

Threat AdvisoryTLP:CLEAR Threat ReportsInfostealer Trash Panda as a Service: Raccoon Stealer Steals Cookies, Crypto, and More A $75-a-week stealer-as-a-service that harvests browser passwords, cookies and autofill, hijacks crypto transactions with a bundled…

Threat AdvisoryTLP:AMBER RansomwareMalware Bugs & Betrayal: VECT Ransomware by Design, Wiper by Accident Analysis of the VECT ransomware family suggests implementation flaws can undermine the operator’s own monetization objectives.

Threat AdvisoryTLP:AMBER LinuxRootkit Sneaky Umbreon Linux Rootkit Targets x86 Systems with Stealth-Focused Persistence A recently disclosed Linux rootkit known as Sneaky Umbreon demonstrates a renewed focus on kernel-level stealth for x86 environments.

Threat Hunt Intelligence FIN7 Infrastructure Hunt, 26 Attributed Hosts C2 Panel · Malware · Loader · 26 attributed · 48 ambient commodity · 74 surfaced Hunt #45Scope C2 Panel · Malware · LoaderAttributed 26Ambient 48Generated 2026-07-07 19:08 UTC This report…

Threat AdvisoryTLP:AMBER HacktivismGov Web Disruption Indian Cyber Force Targets Government Sites Amid Diplomatic Flashpoint A recurring pattern of opportunistic hacktivism and low-sophistication distributed attacks has been observed against public-sector web…

Threat AdvisoryTLP:AMBER HacktivismDDoS Threat Intel Cyber Islamic Resistance and NoName057(16) Signal Intent for Coordinated Cyber Pressure Campaign Against France Intelligence indicators suggest overlapping messaging and tasking narratives between Cyber…

Threat AdvisoryTLP:CLEAR Supply ChainLinux Security 400+ Arch Linux Packages Hijacked to Install Rootkit-Like Malware A large-scale compromise impacting hundreds of Arch Linux packages demonstrates how software supply-chain attacks can transform trusted…

QLNX is an advanced Linux rootkit engineered for kernel-level stealth, privilege concealment and long-term covert access – hiding processes, tampering with telemetry, and evading detection across servers, cloud workloads and internet-facing systems.

Sandworm Uses SSH-over-Tor Tunnels for Stealthy Long-Term Persistence Sandworm – the Russian state-sponsored actor linked to GRU Unit 74455 – leveraged SSH-over-Tor tunneling to establish covert, resilient, long-term access inside compromised environments…

Katana is a Mirai-derived botnet built to compromise vulnerable IoT devices at scale through credential abuse, remote code execution and aggressive propagation – delivering stealth persistence…

Kazuar Backdoor: Inside Turla’s .NET Espionage Implant Indicators and behavioral telemetry align with Kazuar – a sophisticated espionage backdoor associated with Turla, the Russian state-sponsored APT known for stealth operations against government…

ABYSSWORKER: The EDR-Killer Driver Behind MEDUSA Ransomware ABYSSWORKER is a malicious signed Windows kernel driver used in the MEDUSA ransomware attack chain to blind and disable endpoint detection and response tools – masquerading as a CrowdStrike Falcon…

OrBit: The Linux Rootkit That Hijacks the Dynamic Linker OrBit is a stealthy Linux userland rootkit that abuses the dynamic linker (ld.so) to load itself into every new process – hooking dozens of libc functions to hide files, processes and network sockets from standard tooling on the host.

Mercenary Surveillance: Hack-for-Hire Group Targets Android and iCloud Backups A commercial hack-for-hire operation runs a cross-platform surveillance model – deploying Android spyware on some targets while phishing Apple ID credentials to siphon entire…

Operation NoVoice: The Android Rootkit That Survives a Factory Reset NoVoice is a mobile-espionage campaign that hid in 50+ Google Play apps (2.3M+ downloads), chained 22 legacy Android exploits to gain root, and planted a Zygote-level rootkit that hooks the…

Profile of 2025’s Most Active Extortion Operation Qilin (formerly Agenda) is a Rust-based ransomware-as-a-service operation that became the most active extortion brand of 2025 – absorbing displaced affiliates after RansomHub’s collapse, running double…

RegPhantom Watch: A Suspicious Hash With Agreement SHA-256 703dfb12…e7c4 draws consensus from two trusted reputation feeds and possible RegPhantom rootkit ties, but no behavioural detonation confirms intent.

VGOD Ransomware: Anatomy of a Backup-Killing Windows Extortion Strain VGOD is a Windows ransomware first seen in February 2025 that encrypts files, deletes Volume Shadow Copies to block recovery, and runs double extortion behind a ‘Decryption…

DYNOWIPER: Anatomy of the Wiper That Struck Poland’s Energy Grid The ‘critical, unattributed PE’ from automated triage is DYNOWIPER, a deliberately simple data-destruction wiper used on 29 December 2025 against 30+ Polish renewable sites and a major CHP…

Beyond the Binary: How Luca Stealer Uses the Rust Runtime to Slip Past Detection A 4.6 MB Rust PE scored 100/100 with heavy anti-analysis and a Telegram exfiltration channel, behaviour that lines up with Luca Stealer, the leaked Rust infostealer.

Luke Ransomware: A Critical-Severity Encryptor That Also Steals A small (~558 KB) Windows PE flagged critical (90/100) is Luke, a ransomware sample that is also an information-stealer.

The Qilin Surge: How Agenda’s Rust Rewrite Became the Most Active Ransomware of 2025 Qilin published more than 1,000 victims in 2025 and now names 40-plus organisations a month on its leak site.

Under the Hood of klingpremium.xyz: an Obfuscated Batch Loader Your ML Model Rated 0% Malicious A 314 KB Windows .bat flagged critical (90/100) is a multi-stage loader that geofences, then uses PowerShell to pull a next-stage payload from klingpremium.xyz and…

GoAskBobby.exe: The ‘AI Helper’ That’s Really JustAskJacky Malware An automated scan shrugged this 20 MB signed installer off as UNKNOWN with zero indicators.

Blocking the Breach: Inside the indeanapolice.cc PowerShell Dropper A tiny, heavily obfuscated PowerShell script flagged in triage turns out to be the download-cradle stage of the indeanapolice.cc dropper, a recently-registered, low-reputation campaign that…

Malware Analysis Report FredyStealer: The Silent Thief in Your System Published March 26, 2026 · Threat Intelligence Team · A critical-severity script sample was processed by the malware analysis suite.

BiBi Wiper: What the Malware Really Does, and Why This Sample Does Not Confirm It BiBi is a destructive wiper used against Israeli organisations in 2023 that shreds files and appends a .BiBi extension.

Signed Is Not Safe: How Vulnerable Kernel Drivers Are Weaponised to Kill EDR Kernel drivers run in Ring 0, below your endpoint protection.

A rootkit hides inside normal operations and hands an attacker persistent, trusted access without tripping an alarm. A predictable transport route does the same thing to a supply chain.

In the cybersecurity world, we often talk about “defense in depth.” But what happens when the very vault meant to protect your secrets becomes the front door for an intruder?

APT29 a notorious Russian cyber espionage group has recently targeted European diplomats using GRAPELOADER malware.

In a sophisticated cyberattack that rocked WideOpenWest (WoW), the Arkana Ransomware Group used a subtle yet dangerous strategy that started with an infostealer infection.

Imagine your server starts behaving erratically. You suspect a breach, but your monitoring tools are silent.

In January 2026, researchers at Check Point Research published what may be the first clearly documented case of advanced AI-generated malware at scale: VoidLink.

In today’s cybersecurity landscape, advanced persistent threats (APTs) like the Interlock RAT are becoming increasingly sophisticated.

It is the notification no administrator wants to see: not a firewall alert, but a Microsoft Teams message from an intruder already sitting inside the tenant.

When geopolitical tensions boil over, the first shots aren’t always fired on the battlefield they’re fired in the browser.

The “SiameseKitten” APT (also known as Lyceum) represents one of the most persistent and calculated threat actors operating out of Iran.

In the world of targeted espionage, what you don’t see isn’t just a blind spot it’s an open door.

In the rapidly shifting ecosystem of cybercrime, new actors often emerge from the shadows of fallen giants.

Tax season is stressful enough without an Advanced Persistent Threat (APT) group living in your network.

The digital underground just lost one of its most notorious meeting spots.

The digital battlefield just got a lot bigger. For years, Western organizations viewed South Asian hacking collectives as a localized threat nuisances confined to their own backyard.

We’ve all seen te tech tips: create a folder, paste a string of code, and boom you have “God Mode,” a one-stop shop for every Windows setting imaginable.

Executive Summary A sophisticated phishing campaign dubbed “I Paid Twice” is actively targeting Booking.com hotels and their customers, abusing brand trust to deliver malware and remote access tooling.

The digital landscape is currently haunted by one of the most sophisticated and relentless state-sponsored threats in history: APT-41 (also known as Winnti, BARIUM, or Double Dragon).

Akira Ransomware is a formidable threat, known for its sophisticated tactics and ability to bypass even robust security measures.

(ASA) In mid-2024, a joint advisory from the U.S. Department of Treasury, and the Israel National Cyber Directorate sounded a critical alarm.

In the evolving world of cyber threats, ransomware campaigns like MedusaLocker are becoming more sophisticated and difficult to combat.

Cracking the GodRat Campaign: Unmasking Its Infrastructure & How to Block It The GodRat Trojan is believed to be operated by the Chinese threat group Winnti (APT41), known for targeting financial institutions, including trading and brokerage firms.

The LinkPro Rootkit is a highly sophisticated malware that continues to make waves in the cybersecurity landscape.

In the modern threat landscape, stealth is the ultimate weapon.

Advanced Persistent Threats (APTs) are expanding their offensive footprint into mobile ecosystems and organizations in South Asia remain prime targets.

Donot Team (also known as APTC35, Viceroy Tiger, or Mint Tempest) is a highly organized Advanced Persistent Threat group strongly suspected to operate with ties to the Indian state.

A Wake-Up Call for Corporate Security A major cybersecurity and legal battle concluded this week, resulting in a landmark settlement that underscores the growing threat of corporate espionage and “hack-for-hire” schemes.

The world of cybersecurity is constantly evolving, and so are the tactics used by advanced persistent threats (APTs).

In the ever evolving world of cybersecurity, advanced persistent threat (APT) groups continue to develop increasingly sophisticated tactics to breach highly sensitive sectors.

The cybersecurity landscape is constantly evolving, and the rise of Advanced Persistent Threats (APTs) remains one of the most dangerous challenges for businesses globally.

In the vast and often unseen world of cyber threats, there exists a particularly nasty breed of hackers that thrive in the shadows: the Sandworm hackers.

In the world of cybersecurity, new and increasingly sophisticated threats emerge daily.

For years, the stealthy FruitFly remote access trojan (RAT) quietly operated beneath the radar, targeting macOS systems with an unusual blend of simplicity and persistence.

In the world of cyber threats, ransomware continues to be one of the most destructive forces, and Metadatabin is no exception.

KongTuke is a recent, aggressive campaign that delivers a modified Interlock RAT (PHP variant) via a PyInstaller packed payload.

In 2019, a sophisticated cyber threat group known as Rancor made headlines with an innovative and devastating phishing campaign.

Advanced Persistent Threat (APT) groups are known for their sophisticated, long term campaigns that target high value organizations, governments, and industries.

Cyber threats continue to evolve, becoming more sophisticated and harder to detect. One of the most insidious techniques used by the notorious Andariel APT (Advanced Persistent Threat) group is RID Hijacking.

In the ever evolving landscape of cybersecurity, threat actors are continuously adapting and refining their tactics to bypass traditional defenses.

In the ever evolving world of cyber threats, staying ahead of sophisticated attackers is crucial. One such group Laundry Bear (also known as Void Blizzard) has been making headlines for its advanced cyber espionage tactics.

) In today’s cybersecurity landscape, being proactive is your best defense against evolving threats. Cybercriminals no longer rely on random attacks they carefully target critical sectors, using advanced techniques to infiltrate networks.

Summary: A stealthy, targeted campaign we’ll call “Mysterious Elephant” is actively exploiting government targets in Asia.

The notorious Fancy Bear, also known as APT28, has once again surfaced with a new wave of attacks targeting high-value targets across various sectors.

In the ever-evolving world of cybersecurity, advanced threats like rootkits remain among the most dangerous. One such example is the R77 Rootkit, a highly sophisticated malware that stealthily infiltrates systems and provides backdoor access to cybercriminals.

Malvertisements promising AI tools and “instant video/article editing” are a lucrative bait for attackers.

The threat landscape is constantly evolving, and as adversaries grow more sophisticated, defenders must stay one step ahead. One of the more persistent and damaging threats we’ve recently encountered is the Klingon RAT (Remote Access Trojan).

FuRootkit is not a single binary, it’s an infrastructure. Our Graphing FuRootkit Infrastructure service builds an actionable map of how this rootkit’s campaign is assembled (drop points → loaders → kernel hooks → C2/beacons → persistence), so defenders can see choke points, prioritize takedowns, and automate containment without calling out any mapping product names.

Malicious campaigns like IndigoDrop are no longer single files or lone command-and-control servers. They behave like distributed, evolving infrastructures.

The APT-C-24 (also known as SideWinder) hacker group has been actively employing LNK file phishing techniques in their recent attacks, posing significant risks to organizations worldwide.

Blocking Critical IP and Domain IOCs In the world of cyber threats, attribution is key to understanding and mitigating attacks.

Summary: A targeted campaign dubbed Operation Zero Disco has been observed exploiting a Cisco SNMP vulnerability to gain footholds and deploy rootkits on compromised systems.

Cybercrime-as-a-service is no longer science fiction it’s here.

Mysterious Elephant, a persistent threat group long associated with espionage operations in South Asia, is showing signs of evolution, moving beyond reusing old malware.

Fraudsters are luring users with convincing fake banking apps on Google Play and third‑party stores to harvest login credentials, OTPs, and other sensitive data.

Financial institutions remain top targets for cybercriminal groups focused on high-reward operations.

APT27, also known as Emissary Panda, is a well-documented threat group associated with cyber-espionage campaigns targeting government, defense, technology, and financial institutions worldwide.

Overview NoName057(16) is a pro‑Russian hacktivist group that has publicly targeted NATO‑aligned entities using the DDosia DDoS toolkit and related tooling (and overlaps observed with Bobik infrastructure).

Overview Kematian is an info‑stealer that targets credentials, cookies, and local artifacts to support espionage and fraud.

Overview A rapid intruder progression has been observed in which IcedID initial access and loaders lead, within weeks, to Cobalt Strike activity and final Dagon Locker ransomware deployment.

Below is an expanded, technical explanation of how the DDKong plugin campaign operates, what to hunt for in logs and forensic artifacts, and additional detection / mitigation content you can drop directly into tooling.

The pro-Russian advanced persistent threat (APT) group NoName057(16) continues to escalate its cyber operations, targeting entities that support Ukraine.

In the ever-evolving threat landscape, few threats demonstrate the stealth and persistence of BPFDoor, a Linux-based rootkit used by advanced threat actors to backdoor systems while remaining virtually invisible to traditional security controls.

Malicious kernel‑level malware like Darkmegi is one of the highest‑risk threats an enterprise can face: stealthy persistence, ability to tamper with security controls, and the power to hide lateral movement.

Malicious rootkits that inject HTTP iframes into web traffic are a stealthy, high-impact threat to Linux servers and the organizations that rely on them.

In today’s digital age, cyber threats are becoming increasingly sophisticated and widespread, leaving organizations vulnerable to serious data breaches.

APT‑39, also known as “Chafer” or “Remix Kitten”, is a sophisticated Iranian cyber espionage group primarily associated with Iran’s Islamic Revolutionary Guard Corps (IRGC) and its intelligence agencies.

FredMaster, also tracked as Brox, is a modular Android banking trojan family that harvests credentials and performs fraudulent transactions through overlay attacks, accessibility abuse and SMS interception.

Ransomware attacks have become one of the most significant cybersecurity threats in recent years, targeting both individuals and organizations across the globe.

In the ever-evolving landscape of cybersecurity threats, one of the most concerning emerging threats is the DeerStealer Rootkit Stealer Campaign.

In the world of cybersecurity, protecting your network and critical infrastructure from advanced persistent threats (APTs) is paramount.

In the world of cybersecurity, Advanced Persistent Threats (APT) are some of the most sophisticated and dangerous attacks. One such threat is Violin Panda, a Chinese-based APT group also known as theb3g, which has been linked to various espionage campaigns.

Advanced Persistent Threat (APT) actors continue to evolve but so do our methods to uncover and counter them.

As threat actors evolve, so do their methods of staying hidden. Modern botnets no longer rely solely on brute force or noisy traffic they’re stealthy, modular, and highly resilient.

In today’s rapidly evolving threat landscape, adversaries are engineering malware to blend into trusted cloud platforms.

In the ever-evolving cyber threat landscape, advanced persistent threats (APTs) continue to grow in complexity and scale.

Unmasking Advanced Threat Operations Behind the Hash: 9b10685b774a783eabfecdb6119a8aa3 In the evolving world of cyber conflict, few adversaries operate with the consistency and sophistication of Fancy Bear (APT28).

As the cybersecurity landscape evolves, sophisticated banking trojans continue to exploit digital vulnerabilities, putting financial institutions and their clients at constant risk.

How Enterprise Collaboration Tools Became a Gateway for Advanced Ransomware Campaigns The cyber threat landscape has shifted from opportunistic attacks to highly coordinated, multi-stage operations orchestrated by some of the most advanced adversaries in the world.

From Governments to Global Industry The Growing Reach of a Persistent Threat Group Cyber-espionage is no longer confined to state secrets.

With a Surprising Twist: Shared Infrastructure Linked to GandCrab Ransomware Sophisticated, stealthy, and persistent. These are the hallmarks of the latest campaign attributed to the Dropping Elephant (aka Chinastrats) threat group.

Phishing attacks continue to be one of the most effective and damaging methods used by cybercriminals to infiltrate organizations worldwide.

In today’s threat landscape, attackers aren’t just breaking down doors they’re walking right through the front, disguised as trusted tools and workflows.

2025 has seen a dramatic escalation in nation-state cyber threats, with “Dropping Elephant” an India-linked APT group (also known as Patchwork) spearheading a highly targeted campaign against Türkiye’s defense sector.

At Alpha Cyber, our threat intelligence division constantly monitors the evolving threat landscape, analyzing attacker behavior, infrastructure, and payload delivery methods.

How Spoofed Government & Military Interfaces Are Used to Harvest Login Credentials, and How to Shield Against It Recent intelligence has exposed a highly adaptive cyber campaign that targets government and defense institutions by deploying near-authentic fake login portals.

A newly observed Remote Access Trojan (RAT) campaign is targeting financial institutions, using stealth and social engineering to penetrate secure environments.

CeidPageLock is a stealthy, kernel-level Chinese rootkit primarily distributed through the RIG exploit kit.

In today’s data-driven world, the privacy and security of user information have become more than just a technical issue, they’re a matter of public trust, legal compliance, and business survival.

How Infrastructure Mapping Can Help Detect and Prevent the Next Breach In the latest wave of targeted ransomware attacks, the Akira ransomware group is now exploiting a previously unknown vulnerability in SonicWall SSLVPN appliances, giving them direct access to corporate networks.

In today’s threat landscape, cybercriminals are no longer relying on single-layer malware. Instead, they’re deploying fully integrated infrastructures to maintain persistence, monetize user data, and avoid detection.

A new wave of coordinated cyberattacks has emerged from a threat actor group known as the Five Families Collective, recently targeting Alpha Automation, a leading industrial automation firm in Brazil.

How Nation-State-Grade Malware is Bypassing Defenses – and What You Can Do About It In today’s rapidly evolving threat landscape, attackers are using increasingly advanced techniques to bypass endpoint security, including digitally-signed rootkits.

Cybercriminals are exploiting legitimate collaboration tools in increasingly sophisticated ways.

In the modern threat landscape, advanced persistent threats (APTs) operate like invisible war machines, strategic, highly coordinated, and capable of maintaining long-term access to their targets.

As geopolitical tensions increasingly manifest online, the Indian Cyber Force (ICF), a politically motivated hacktivist group has emerged as a visible threat through waves of DDoS attacks, website defacements, and alleged data leaks.

Microsoft recently confirmed that China-backed nation-state hackers, including the notorious group known as Violet Typhoon, are actively targeting Microsoft SharePoint servers worldwide.

A highly sophisticated backdoor, SecondDate_CnC, attributed to the elite Equation Group, has resurfaced in targeted infrastructure attacks.

A sophisticated cyber campaign has been discovered targeting SonicWall VPN appliances, embedding a stealthy rootkit backdoor deep in the system, invisible to standard endpoint protection.

A sophisticated campaign attributed to the China-affiliated group Silver Fox (aka Void Arachne) is targeting Chinese‑speaking users via spoofed websites mimicking popular apps like WPS Office, Sogou, and DeepSeek.

Cybercriminals are exploiting the Godot Engine in a new wave of attacks using the GodLoader malware, infecting over 17,000 systems in just three months.

Unveiling the GodLua DNS over HTTPS Malware Infrastructure In today’s rapidly evolving cyber threat landscape, GodLua DNS over HTTPS (DoH) malware stands out as a sophisticated and stealthy adversary.

The Bvp47 backdoor, dubbed the “God of Espionage,” is a top-tier Linux malware platform attributed to the Equation Group, with strong ties to the US NSA.

A new ransomware threat called Bert is targeting organizations across Asia, Europe, and the US, especially in healthcare, technology, and event services.

In the shadowy world of cyber threats, some malware aims not just to steal data, but to disappear.

The Threat:The Sidewinder APT group, believed to be aligned with Indian interests, is actively targeting government, military, and critical infrastructure across South Asia, including Bangladesh, Pakistan, and Sri Lanka.

Two-Factor Authentication (2FA) is vital, but attackers are bypassing it with 2FA Phishing-as-a-Service (PhaaS). These sophisticated platforms, like “Sneaky 2FA,” act as a “reverse proxy,” intercepting real-time credentials and 2FA codes.
Cybersecurity researchers have shed light on an actively maintained remote access trojan called DCRat (aka DarkCrystal RAT) that’s offered on sale for “dirt cheap” prices, making it accessible to professional cybercriminal groups and novice actors alike.
Thanks to cybersecuritynews for this great article Sygnia Incident Response Team found an advanced and persistent threat actor named “Praying Mantis” or “TG2021”, operating completely in memory.
North Korean state-sponsored hackers known as APT37 have been discovered targeting journalists specializing in the DPRK with a novel malware strain.
In April 2017, the hacking collective known as the Shadow Brokers leaked a sophisticated malware framework attributed to the NSA’s Equation Group.
Contact
You speak directly to the people doing the work, wherever in the world you operate.
Or email [email protected]