ViPNet as transport for malware 📦
PT ESC specialists have recorded signs of attackers carrying out an attack through the standard functionality of the ViPNet MFTP service. As of the publication…
[ FEED // CHRONO // 267 ITEMS ]
PT ESC specialists have recorded signs of attackers carrying out an attack through the standard functionality of the ViPNet MFTP service. As of the publication…
CloudAtlas: a new wave of cyberattacks on organizations in Russia and Iraq using chains of legitimate web resources In May 2026, the Threat Intelligence departm…
Citizen, update yourself 🫵 Recently, a sample mir-pay.apk flew into our sandbox. At first glance, nothing unusual: just another variation of the well-known Mamo…
Our colleagues at Censys published a breakdown of the AsyncRAT family, describing an entire genealogical tree: AsyncRAT → DCRAT (DarkCrystal RAT) → VenomRAT → d…
In 2026, a tool called VMkatz was published. In terms of functionality, it resembles the widely known Mimikatz tool, but unlike it, VMkatz's goal is to extract…
Someone said sandbox? 👀 Once again we're watching threat actors conduct unethical research. Given: Security researcher Nicholas Curran He published packages wit…
NetMedved: Summer Campaign Against Russian Organizations 🐻👍 The PT ESC cyber intelligence group has recorded a new wave of activity by the NetMedved hacking gro…
AI-95 with a malicious additive ⛽️ In mid-June, the Threat Intelligence team discovered several resources at once using a "fuel" theme for malicious purposes. 0…
Looking inside ESE 🫣 During incident investigations, we at PT ESC IR regularly encounter the need to analyze databases in the ESE (Extensible Storage Engine) fo…
::%16777216 — so what exactly are you? It is known that during attacks, adversaries can use tunneling. For example, to punch a reverse tunnel from a compromised…
Rare persistence techniques. Part 4 Also read about: Zabbix Agent, TimeProvider, COM Hijacking, WMICLNT. 5️⃣ Systemd Generator A Systemd Generator is an executa…
Rare persistence techniques. Part 3 Also read about: Zabbix Agent, TimeProvider, COM Hijacking. 4️⃣ WMICLNT This persistence technique is based on hijacking a D…