A lone wolf is no companion for you
A lone wolf is no companion for you 🐺 The cyber intelligence team has recorded another phishing campaign by the Lone Wolf group: the attackers use steganography…
[ FEED // CHRONO // 267 ITEMS ]
A lone wolf is no companion for you 🐺 The cyber intelligence team has recorded another phishing campaign by the Lone Wolf group: the attackers use steganography…
PT ESC Cyber Intelligence Group Presents Q3 2025 Cyberattack Overview ✍️ The report examines hacker attacks on the infrastructure of Russian organizations and t…
Searching for Phishing Infrastructure at the Preparation Stage 🧱 In protecting an organization from phishing threats, it is useful not to limit yourself to simp…
"I will *** your fish" 🐟 In mid-October, a cyber intelligence group detected phishing activity targeting HR departments in the construction sector. The attacker…
In addition to the previous post we are looking at additional tools for decrypting network traffic. Let's look at an alternative to PolarProxy that is no…
MITM attack is a fairly popular feature of various sandboxes and application analysis systems. Typically, tools that enable MITM attacks are a proxy serv…
In the first part, we examined the decryption of TLS connections, which are often used on the internet. But if we move inside a corporate environment, other pro…
🦈 Looking Under the Hood of Secure Connections in Wireshark. Part 1: TLS Our network experts often need to decrypt TLS connection traffic and analyze protected…
Using IoC in a non-standard way. Part 1. Threat hunting 🧐 When we talk about indicators of compromise, we usually mean a reactive approach to defense: a securit…
Idea for a SIEM correlation rule 💡 Although tracking the entire attack chain described in the posts above provides a complete picture, the strongest and simples…
Continuing to reproduce the attack from the post above 🔼 3️⃣ Creating a public API Gateway trigger (screenshot 1) At the end, we need to expose the function to…
☁️ AWS backdoor as a service: persistence in the cloud via Lambda The cloud threat landscape is constantly evolving, and attackers are increasingly abusing legi…