The attacker publishes .bash_history view without registration and SMS
Attacker publishes .bash_history watch without registration and SMS 😱 The Supply Chain Security team sent a report to the npm registry administration about an a…
[ ARCHIVE ]
Attacker publishes .bash_history watch without registration and SMS 😱 The Supply Chain Security team sent a report to the npm registry administration about an a…
PT ESC Cyber Intelligence Group presented an overview of cyberattacks for Q1 2026 ✍️ The report analyzes the activity of hacker groups targeting Russian organiz…
CHM snap-in, alarms, CIB of the Russian Ministry of Defense, and bitcoin eggs 🤖 At the end of December last year, the Threat Intelligence team of the Positive T…
A logging library and an infostealer to boot? No thanks 👋 A lot has happened recently. For example, someone decided to play patron of the arts and published 30…
Friday Newsletter 🐽 Imagine: you're an employee of a Russian organization, and on Friday someone named Nadezhda Arturovna 😌 sends you an email (screenshot 1) as…
Where does one group end and another begin? 🧩 In a new study, we examined a case that clearly demonstrates how the MaaS model complicates attack attribution. Th…
Ghostly Gist 😏 In March, PT ESC cyber intelligence specialists recorded activity from the Rare Werewolf group (Rezet, Librarian Ghouls). This time, an archive d…
Unusual obfuscation is always beautiful... 🥰 ... it's just a shame that you have to see it in trojanized open-source packages, and not only at Capture The Flag…
Cyber Intelligence Basics 👍 This week we are holding the fifth episode of the webinar "Better Call PT ESC," where we break down practical scenarios for working…
Infect a state and earn 3 rubles 🪙 In late February and early March, specialists from the PT ESC threat research department identified attacks on various organi…
Keeping a finger on the Pulse: cyberattacks by the Mythic Likho group on Russia's critical information infrastructure 🔮 The Threat Intelligence Department of Po…
Breaching the office through Office 👨💻 The PT ESC cyber intelligence team has recorded the first phishing campaign exploiting CVE-2026-21509, targeting Russian…