How to create rules for network traffic for a future threat
How to create rules for network traffic to address a future threat 🤨 This was discussed this week in China during the third cybersecurity summit, which included…
[ FEED // CHRONO // 267 ITEMS ]
How to create rules for network traffic to address a future threat 🤨 This was discussed this week in China during the third cybersecurity summit, which included…
Long, weird, but it works 🍊🍊🍊🍊🍊🍊🍊🍊🍊🍊🍊 Not everything we investigate turns out to be complex attacks by serious groups. Sometimes attacks only appear complex. We…
Malware flies, malware runs, malware sits in the sandbox ⏳ In mid-August, we reported on a new large-scale campaign by the PhantomCore group, detected by the Th…
Useful Friday post 🫥 During threat research, there is often an urgent need to examine a malicious file/URL/domain. In this post, we have gathered the tools we a…
APT31 Grouping Tool. CloudyLoader 🌩 In one of the incidents, the PT ESC IR team encountered an interesting malicious file that loads a payload in several stages…
How to CVE-2025-54916? Low-effort vulnerability research 💻 Hi, ESC-VR here. The Telegram post format is rarely suitable for analyzing complex vulnerabilities, b…
Attackers compromised dozens of NPM packages with ~2 billion downloads 🐾 What happened As part of a phishing campaign, maintainer Josh "Qix" Junon was…
Curing a problem 🔧 Recently, researchers from ARMO presented a paper and PoC for the Curing malware, which uses the io_uring interface to bypass monitoring of f…
Generating a COM vtable in IDA 🐍 While analyzing one of the Snake Keylogger variants, we needed to figure out which managed methods the native module calls thro…
Operation Tartaria — VTDoor 🚪 We have already covered Operation Tartaria in several posts — part 1 and part 2. In one of the cases, the PT ESC IR team discovere…
The Lost Goffee Bean 🤨 Literally a couple of days after our research into the activity of the Goffee group, another attack was carried out, which we will now te…
Fortune Telling on Goffee Grounds: Current Tools and Grouping Features of Goffee in Attacks on Russia ☕️ Throughout 2024-2025, experts from the TI department ha…