How we found the ITW exploit for CVE-2024-38178
🔦 How We Found the ITW Exploit for CVE-2024-38178 As part of our monthly review of freshly patched vulnerabilities, our team in ESC-VR pays close attention to v…
[ FEED // CHRONO // 267 ITEMS ]
🔦 How We Found the ITW Exploit for CVE-2024-38178 As part of our monthly review of freshly patched vulnerabilities, our team in ESC-VR pays close attention to v…
!!р^д**н**c 🤔 A characteristic example of how threat actors use current events to distribute malicious programs is a malicious document we discovered. It contai…
Where to look for network indicators of compromise on Windows? For example, in the DNS cache 💡 The DNS cache is a mechanism for caching records that map domain…
☝️ In addition to Windows logs, another interesting artifact provided by a popular antivirus protection tool helped us in investigating the activity described i…
ℹ️ Exfiltration using PowerShell/C# During an incident investigation, while analyzing Windows event logs on one of the compromised hosts, we discovered that a P…
⛩ Attackers are looking for new ways to "open the gates" We recently discovered an unusual attack scheme. The attackers first establish contact with the victim…
Exfiltration on an industrial scale 😐 The APT group Cloud Atlas has been attacking Russian companies since 2019, engaging in espionage and theft of confidential…
🫡 Hellhounds remains one of the most advanced groups attacking companies in Russia We have already covered Hellhounds' activity in the articles "Operation Lahat…
In early 2024, our team identified the use of the Cobint malware in customers' infrastructures 🥷 This malware is actively used by the (Ex)Cobalt group in attack…
🤨 Adding bookmarks to open-source repositories? Young man, come with us. As part of threat intelligence, in addition to researching "traditional" malware, we al…
🔎 Quick-and-dirty network research, or How to find a new, previously undiscovered activity of a known group in 15 minutes While analyzing external expertise on…
DPAPI — a popular vector for attacks on Windows-family OS 💻 Wi-Fi keys, certificates, credentials, browser cookies, DropBox, Skype — and that's only part of the…