// Threats

This is Siemens...

Recently, our colleagues from the Positive Industrial Expertise Center discovered a curious Windows sample on MalwareBazaar. Here is its SHA-256: e014dadf6d93b3…

// Threats

Anti-antivirus

Recently, we came across an APK with an intriguing and trust-inspiring name: «Антивирус ФСБ.apk». After installing it, we discovered that upon launch, the user…

[ FEED // CHRONO // 267 ITEMS ]

ALL MATERIALS

// Threats

Operation Chewbacca

At the end of June, the PT ESC team, during incident investigations, discovered a new group targeting at least oil and gas companies and the financial sector. D…

oUth0R
// Threats

Your Zimbra server is at risk

Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail servers using the vulnerability CVE-2026-73570 and the TargetZimbra en…

oUth0R
// Threats

Ding, ding — who's there?

Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center has discovered a new group that we have named DENOmina…

ti_author
// Threats

He's not your gsocket

He's not gsocket to you 😑 During the investigation of one of the incidents, PT ESC IR specialists came across a rather curious tool called hsocket (not to be co…

oUth0R
// Threats

We will croc you

We will croc you 👻 PhantomCore continues to actively exploit misconfigurations in 1C to attack Russian organizations. We previously wrote about attacks on 1C us…

oUth0R
// Threats

⚡Fake news — THAT'S ALL

⚡Fake news — B U L L S H I T PT ESC specialists discovered an interconnected network of news sites, email domains, and social media accounts that were used to s…

ti_author