The Lost Goffee Bean
The Lost Goffee Bean 🤨 Literally a couple of days after our research into the activity of the Goffee group, another attack was carried out, which we will now te…
[ ARCHIVE ]
The Lost Goffee Bean 🤨 Literally a couple of days after our research into the activity of the Goffee group, another attack was carried out, which we will now te…
Phantom pains 👻 In May, the Threat Intelligence department of the Positive Technologies Expert Security Center (PT ESC TI) discovered a new large-scale cyber es…
From Phantom Payments to Confidential Data 🫰 In June, we published an article about discovered Exchange keyloggers. At that time, nine victim companies were ide…
PT ESC cyber intelligence group presents a review of cyberattacks for Q2 2025 ✍️ The report examines the most notable attacks on the IT infrastructure of Russia…
Node JS. Malicious activity at the installation stage As part of researching the actions of attackers in npm (Node Package Manager, the main repository of JS co…
The Return of the Bloody Wolf 🐺 Since early May, the PT ESC cyber intelligence team has discovered a new wave of attacks by the Bloody Wolf group against organi…
Drama around PyPI: 🪰⮕🐘? Last week, CNews published a news item: "Russians driven out of the Python community. Only the chosen ones for now, but the selection cr…
Jade Metal: the not-so-new Telemanmilconfav group attacks military organizations? 🪖 In March, researchers from F6 published a report on the Telemancon group, wh…
IoCs-detox: protecting TI from false indicators ✋ Imagine this: your SOC team receives a fresh feed of compromise indicators. The list contains hundreds of new…
DarkGaboon. The venom of a cyber viper in the digital veins of Russian companies 🐍 In January of this year, the cyber intelligence group of the TI department at…
No Longer Rezet, or New Rare Wolf Attacks 🐺 The PT ESC cyber intelligence group continues to record attacks by the Rare Wolf group: for example, in late May, th…
One on One with Rust ☹️ Recently, the complex threat research group of Positive Technologies' TI department has been increasingly encountering malware written i…