Open source passions: mafia, stealers, and bug bounty hunting of Yandex projects
Open Source Drama: Mafia, Stealers, and Bug Hunting of Yandex Projects 🐱 Over the past two weeks, a lot of interesting things have happened in the Python Packag…
[ ARCHIVE ]
Open Source Drama: Mafia, Stealers, and Bug Hunting of Yandex Projects 🐱 Over the past two weeks, a lot of interesting things have happened in the Python Packag…
!!р^д**н**c 🤔 A characteristic example of how threat actors use current events to distribute malicious programs is a malicious document we discovered. It contai…
⛩ Attackers are looking for new ways to "open the gates" We recently discovered an unusual attack scheme. The attackers first establish contact with the victim…
🤨 Adding bookmarks to open-source repositories? Young man, come with us. As part of threat intelligence, in addition to researching "traditional" malware, we al…
DPAPI — a popular vector for attacks on Windows-family OS 💻 Wi-Fi keys, certificates, credentials, browser cookies, DropBox, Skype — and that's only part of the…
📬 How attackers are changing their approach to writing phishing emails Recently, we came across an email with a malicious attachment sent by the group Hive0117…
✈️ In our last post, we explained that Telegram is becoming more popular among hackers in the C2 as a service paradigm Exfiltration of victim data to attackers'…
👏 One-two — and done. Generating FLIRT signatures And we do this to avoid wasting time on recognizing the library code of PureBasic, in which the COM-DLL-Droppe…
Proactive Hunting for C2 Servers 👨💻 In the process of hunting for C2 servers, an important question arises — which artifacts to use for better effectiveness an…
Rapid decryption of data from an NSIS script 🗄 When there's no time to identify the encryption algorithm and implement a decryption algorithm, a debugger comes…