DarkGaboon. The venom of a cyber-viper in the digital veins of Russian companies
DarkGaboon. The venom of a cyber viper in the digital veins of Russian companies 🐍 In January of this year, the cyber intelligence group of the TI department at…
[ FEED // CHRONO // 267 ITEMS ]
DarkGaboon. The venom of a cyber viper in the digital veins of Russian companies 🐍 In January of this year, the cyber intelligence group of the TI department at…
No Longer Rezet, or New Rare Wolf Attacks 🐺 The PT ESC cyber intelligence group continues to record attacks by the Rare Wolf group: for example, in late May, th…
One on One with Rust ☹️ Recently, the complex threat research group of Positive Technologies' TI department has been increasingly encountering malware written i…
We will protect your money… Just give it to us 😏 At the beginning of the year, specialists from the cyber intelligence group of the TI department at the Positiv…
New PhaseShifters campaign 👽 Throughout May, the PT ESC cyberthreat intelligence team has been tracking a wave of activity by the PhaseShifters hacking group, w…
🛡 Puma: how a rootkit provides covert SSH access through stealthy key substitution Continuing our story about the activities of the ExCobalt group and its new t…
Trust but verify, or How to choose TI sources wisely 😏 In the life of the vast majority of SOC centers, there comes a time when you need to supplement your tool…
Yara-Yara-Yara! 🐧 Now that we've sorted out strings, we can move on to generating byte signatures. Usually people try to make them as rarely as possible, since…
Yara Yara Daze Anyone involved in malware analysis is certainly familiar with a tool like YARA 😉. With its help, many companies 🔴 build sets of signature rules…
PT ESC cyber intelligence team has prepared a report on the results of the first quarter of 2025 ✍️ It compiles the most notable attacks by hacker groups on the…
How did CaT entangle several groups at once? 🧶 In the fall of 2024, our attention was drawn to an interesting tool discovered while studying the activity of the…
(Ex)Cobalt == (Ex)Carbanak 🤔 Since the beginning of 2025, the PT ESC team has observed a rise in the number of attacks using the SshDoor backdoor. Russian gover…