Stealer infection: a new USB strain
Stealer infection: a new USB strain 👾 Today we're going to talk about an unusual modification of the WorldWind stealer that we discovered. It is a real, bona fi…
[ FEED // CHRONO // 267 ITEMS ]
Stealer infection: a new USB strain 👾 Today we're going to talk about an unusual modification of the WorldWind stealer that we discovered. It is a real, bona fi…
Ngrok. Finding and understanding it 🔍 In the process of investigating numerous incidents, we repeatedly encounter a tool such as ngrok. It is a convenient legit…
Come again, I can't see it well 😳 Recently, the PT ESC cyber intelligence team discovered an example of a multi-stage phishing attack in which the attackers fir…
Learning to Recover VMProtect Imports ⚙️ VMProtect is one of the most widely used malware protectors. At the same time, attackers are often lazy and use only si…
SSH-IT. Guide to detecting a popular tool 🔭 In the course of investigating numerous incidents involving the compromise of Linux nodes, we sometimes discover var…
😲 Who the heck are these PhaseShifters of yours? In early June 2024, specialists from the Threat Intelligence department identified a new PhaseShifters attack c…
⚠️ OWOWAsome module, or IIS kOWOWAren Researchers reported on the malicious IIS module Owowa, designed to intercept user credentials, back in 2021. And in 2022…
Gapucino* — is GOFFEE ☕️ Today we are covering one of the most active campaigns currently underway in Russia. Other researchers call it GOFFEE. As the initial v…
An endless chain of redirects ♾️ Quite often, when sending phishing links via email, attackers do not attach them explicitly to the email but use various redire…
How to fix CFG 🔧 In the process of reverse engineering malware, we encounter cases where obfuscation hinders understanding the overall algorithm. One example is…
🤔 Remember, in a couple of previous posts we described simple and slightly more complex approaches to detecting malware using the example of an email that lande…
Catching bug hunters again 💀 In one of our previous posts we wrote about traces of bug bounty activity targeting "Yandex". History repeated itself, but this tim…