[ << ALL_FEED ]

PT ESC cyber intelligence group presented an overview of cyberattacks for Q2 2026 ✍️

More in General

PT ESC Cyber Intelligence Group presented an overview of cyberattacks for Q2 2026 ✍️

The report analyzes the activity of hacker groups targeting Russian organizations: from the public sector and the defense industry to finance, healthcare, and industry.

It describes the activity of the espionage groups Rare Werewolf, PseudoGamaredon, Tolik, XDSpy, CloudAtlas, BO Team, NetMedved, as well as the financially motivated Hive0117.

✉️ Main initial access vectors:

• Targeted phishing with business, accounting, and government-themed lures.
• Archives with HTA, LNK, and JScript files, RAR archives with BAT scripts, and Office documents with embedded templates.
• Mailings from compromised mailboxes (BEC) to bypass reputation filters.
• Exploitation of CVE-2026-21509 in Microsoft Office.

🔍 Key findings:

• Hive0117 has switched to obtaining the C2 address via the Bitcoin blockchain — the command server address is encoded in the OP_RETURN output of a transaction and is not stored in the sample’s body.

• CloudAtlas hid its infrastructure behind oEmbed chains via legitimate WordPress sites.

You can review the report in our blog 🫲

#TI #APT #Malware #Phishing
@ptescalator

More from ti_author

More from ti_author

More in General