Like a hammer of thunder disrupted the claws of silence.

More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…
How the Hammer of Thunder Disrupted the Claws of Silence 🦀
During an incident investigation, the Incident Response team, with support from the Threat Intelligence department, discovered traces of the KrustyLoader malware.
This malware was first described in January 2024 by experts from Volexity and Mandiant: they found it being used in attacks targeting the exploitation of zero-day RCE vulnerabilities in Ivanti Connect Secure. At that time, it was noted that KrustyLoader was written for Linux, but later versions for Windows appeared. Notably, at the time of the research, the loader was used by only one group, which we call QuietCrabs.
Further investigation revealed the activity of another group within the victim’s infrastructure. Interestingly, the actions of the second group likely disrupted QuietCrabs’ ability to carry out the attack and were the reason this attack drew attention.
We believe the second group is Thor. Based on an analysis of the attackers’ network infrastructure and telemetry data, we concluded that they were conducting mass attacks against Russian companies. To gain initial access to the infrastructure, the group exploited a number of RCE (Remote Code Execution) vulnerabilities, such as CVE-2025-53770 and CVE-2021-27065.
😠 In the article, we will show the attack chains we discovered during the investigation and discuss the tools used by the attackers. Read the material in our blog.
#IR #TI #APT
@ptescalator
More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…






