HTML attachments as a phishing tool
HTML attachments as a phishing tool 🤑 Delivery of HTML-like email attachments containing various techniques for opening third-party web content, interacting wit…
[ FEED // CHRONO // 267 ITEMS ]
HTML attachments as a phishing tool 🤑 Delivery of HTML-like email attachments containing various techniques for opening third-party web content, interacting wit…
Interview → iPhone software from the "employer" → you no longer have a smartphone 👋 The old-new scheme for locking an iPhone via "Lost Mode" is back in circulat…
Jade Metal: the not-so-new Telemanmilconfav group attacks military organizations? 🪖 In March, researchers from F6 published a report on the Telemancon group, wh…
Malware in SYSVOL: finding the source 😐 Let's say we're investigating a ransomware incident. The attackers used a Group Policy to launch the ransomware (for exa…
And we have big news!😡 At PT ESC, the Antivirus Laboratory has opened: we have combined the expertise of "VIRUSBLOCKADA" with our own, analyzing numerous sample…
Continuing previous publications, we explain how to detect the CVE-2025-33073 vulnerability 🕵️♂️ 1️⃣ Monitor DNS queries with a Marshalled suffix In Reflection…
🧤 Now about the exploitation of the vulnerability CVE-2025-33073: • A domain account with the most ordinary privileges. • SMB signing is not enforced on the tar…
Reflection Relay. It never happened before, and now it's happening again (CVE-2025-33073) 😐 One of the most popular techniques for privilege escalation in an Ac…
In addition to the previous post, we want to talk about some other potential ways of detecting the execution of malicious code in the "1C" system 😳 • First, if…
Following the 1C_Shell trail. Investigating attacks using the event log 🐾 In one of our previous posts, we wrote about detecting attacks on the 1C system in whi…
Exchange Mutation. How We Caught Anomalies in Outlook Pages 😮 Continuing our series of incident investigation stories (you can read about them here, here, and p…
IoCs-detox: protecting TI from false indicators ✋ Imagine this: your SOC team receives a fresh feed of compromise indicators. The list contains hundreds of new…