Phantom in the flesh
Phantom in the Flesh 👻 In the summer of 2025, the Threat Intelligence team of the Positive Technologies cybersecurity expert center analyzed Operation Phantom E…
[ ARCHIVE ]
Phantom in the Flesh 👻 In the summer of 2025, the Threat Intelligence team of the Positive Technologies cybersecurity expert center analyzed Operation Phantom E…
Hush, hush: a new campaign against CIS countries 🤫 In the second half of 2025, we discovered a new series of attacks by the SweetSpecter group targeting CIS cou…
In addition to the post 👆 Disabling Defender / MpPreference Set-MpPreference -DisableRealtimeMonitoring $true Set-MpPreference -DisableBehaviorMonitoring $true…
Using DefendNot in XWorm Attacks 🪱 A cyber intelligence group has recorded phishing activity aimed at data theft followed by monetary extortion (screenshot 1)…
Deobfuscating .NET function names manually 🙌 .NET malware loves packers, obfuscation (of names, CFG, and other things), and multi-stage reflective image loading…
PrevedNetMedved 🐻 In October 2025, our cyber intelligence team detected ongoing phishing activity by a hacker group we have designated as NetMedved. The attacks…
A lone wolf is no companion for you 🐺 The cyber intelligence team has recorded another phishing campaign by the Lone Wolf group: the attackers use steganography…
PT ESC Cyber Intelligence Group Presents Q3 2025 Cyberattack Overview ✍️ The report examines hacker attacks on the infrastructure of Russian organizations and t…
Searching for Phishing Infrastructure at the Preparation Stage 🧱 In protecting an organization from phishing threats, it is useful not to limit yourself to simp…
"I will *** your fish" 🐟 In mid-October, a cyber intelligence group detected phishing activity targeting HR departments in the construction sector. The attacker…
Long, weird, but it works 🍊🍊🍊🍊🍊🍊🍊🍊🍊🍊🍊 Not everything we investigate turns out to be complex attacks by serious groups. Sometimes attacks only appear complex. We…
Malware flies, malware runs, malware sits in the sandbox ⏳ In mid-August, we reported on a new large-scale campaign by the PhantomCore group, detected by the Th…