Operation Tartaria — PlugX 🤝 DevTunnels
Operation Tartaria — PlugX 🤝 DevTunnels At the end of May, PHDays Fest wrapped up, during which, on the Defense track, the 4RAYS team discussed the specifics of…
[ ARCHIVE ]
Operation Tartaria — PlugX 🤝 DevTunnels At the end of May, PHDays Fest wrapped up, during which, on the Defense track, the 4RAYS team discussed the specifics of…
All Hackers Go To Cloud ☁️💻 During the investigation of an incident in a fully encrypted infrastructure, we identified an autonomous web server hosting the clie…
Interview → iPhone software from the "employer" → you no longer have a smartphone 👋 The old-new scheme for locking an iPhone via "Lost Mode" is back in circulat…
Malware in SYSVOL: finding the source 😐 Let's say we're investigating a ransomware incident. The attackers used a Group Policy to launch the ransomware (for exa…
In addition to the previous post, we want to talk about some other potential ways of detecting the execution of malicious code in the "1C" system 😳 • First, if…
Following the 1C_Shell trail. Investigating attacks using the event log 🐾 In one of our previous posts, we wrote about detecting attacks on the 1C system in whi…
Exchange Mutation. How We Caught Anomalies in Outlook Pages 😮 Continuing our series of incident investigation stories (you can read about them here, here, and p…
(Ex)Cobalt == (Ex)Carbanak 🤔 Since the beginning of 2025, the PT ESC team has observed a rise in the number of attacks using the SshDoor backdoor. Russian gover…
A complex password won't help 📮 The practice of the PT ESC IR information security incident response team shows that attackers, upon gaining access to companies…
😐 “Why aren't you answering?”, or The Story of How to Steal a Telegram Account Without Registration or SMS Recently we published an article about the most popul…
1C_shell for "1C" 🦞 Sometimes situations arise when, during an information security incident investigation, the traditionally used OS artifacts contain extremel…
Net group "babyk" /add During the investigation of one of the incidents, we discovered the exploitation of the CVE-2024-37085 vulnerability. It allows…