PrevedNetMedved

More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…
PrevedNetMedved 🐻
In October 2025, our cyber intelligence team detected ongoing phishing activity by a hacker group we have designated as NetMedved. The attacks targeted Russian organizations: victims received ZIP archives containing a set of decoy documents mimicking the document flow of Russian companies, as well as disguised LNK files that initiated the download of the next stage and deployment of NetSupportRAT on victims’ devices.
The malware operators used multiple attack vectors — ranging from more classic chains involving PowerShell scripts and HTA files to a significantly rarer technique: delivering malicious code via the Finger protocol and subsequently executing it in the command line.
After analyzing the activity and network infrastructure of NetMedved, we observed consistent overlaps with the December 2024 campaign against Russian companies, which we previously covered in a post titled “PrevedMedved 👋 — It’s Lumma Stealer Again.”
Details of the attack, analysis of the TTPs used, and the rationale behind the group’s naming — in our blog on Habr.
#TI #APT #Phishing
@ptescalator
More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…



