PT ESC cyber intelligence group presented an overview of cyberattacks for Q2 2026 ✍️

More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…
PT ESC Cyber Intelligence Group presented an overview of cyberattacks for Q2 2026 ✍️
The report analyzes the activity of hacker groups targeting Russian organizations: from the public sector and the defense industry to finance, healthcare, and industry.
It describes the activity of the espionage groups Rare Werewolf, PseudoGamaredon, Tolik, XDSpy, CloudAtlas, BO Team, NetMedved, as well as the financially motivated Hive0117.
✉️ Main initial access vectors:
• Targeted phishing with business, accounting, and government-themed lures.
• Archives with HTA, LNK, and JScript files, RAR archives with BAT scripts, and Office documents with embedded templates.
• Mailings from compromised mailboxes (BEC) to bypass reputation filters.
• Exploitation of CVE-2026-21509 in Microsoft Office.
🔍 Key findings:
• Hive0117 has switched to obtaining the C2 address via the Bitcoin blockchain — the command server address is encoded in the OP_RETURN output of a transaction and is not stored in the sample’s body.
• CloudAtlas hid its infrastructure behind oEmbed chains via legitimate WordPress sites.
You can review the report in our blog 🫲
#TI #APT #Malware #Phishing
@ptescalator
More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…



