[ ARCHIVE ]

Author: ti_author

// Threats

Your hash, please… Thank you!

Your hash, please… Thank you! 🙏 In early January, we discovered a file that drew attention for its content and structure. An examination of the document's metad…

ti_author
// Threats

One lazy driver

🚘 One lazy driver Recently, the PT ESC cyber intelligence group discovered an executable file with an "unusual" name, reinforced by a distinctive PDF file icon…

ti_author
// Threats

Another Python stealer?!

Another stealer in Python?! 🫣 Since the beginning of September, we have been tracking attacks that at first glance could be attributed to the activity of the La…

ti_author
// Threats

What is wrong with this AES?

What exactly is wrong with this AES? ❔ Attackers often use encryption to obfuscate parts of malware samples that may be of greatest interest during research. Wh…

ti_author
// Threats

Through blockchain to data

Through the blockchain to the data ⭐️ Researchers from Socket and Checkmarx have reported on an interesting malicious campaign in NPM. The attackers mimicked pl…

ti_author
// Threats

Copy, copy, can you hear us?

Over, over, can you hear us? 😲 Despite the fact that hackers have recently gotten lazy and increasingly don't develop anything of their own, original attack ide…

ti_author
// Threats

APT-C-60, or DarkHotel

APT-C-60, aka DarkHotel 💿 We once talked about the use of VHDX files in attacks and why it is convenient (no, this is not a call to action). You can find that p…

ti_author
// Threats

Repeat, it's hard to see

Come again, I can't see it well 😳 Recently, the PT ESC cyber intelligence team discovered an example of a multi-stage phishing attack in which the attackers fir…

ti_author