PT ESC cyber intelligence group presented an overview of cyberattacks for Q4 2025 ✍️

More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…
PT ESC cyber intelligence group presents an overview of cyberattacks for Q4 2025 ✍️
The report analyzes the activity of hacker groups targeting Russian organizations — from the public sector and military-industrial complex to industry, finance, and telecommunications.
It describes the activity of APT31, ExCobalt, QuietCrabs, Rare Werewolf, PseudoGamaredon, as well as financially motivated Werewolves, NetMedved, Silver Fox, and Hive0117.
✉️ Primary initial access vectors:
• Targeted phishing using business correspondence pretexts, notifications from government agencies, and procurement documentation;
• Password-protected archives containing LNK, SCR, EXE loaders and decoy documents;
• Exploitation of fresh RCE vulnerabilities with mass scanning of external services;
• Compromise of contractors and exposed RDP services.
🔧 Key trends and techniques:
• Continuous evolution of tooling;
• Active use of legitimate services and clouds for stealthy command and control;
• New persistence methods;
• Steganography and multi-stage chains;
• Rapid exploitation of zero-day and n-day vulnerabilities.
You can read the report on our blog.
#TI #APT #Malware #Phishing
@ptescalator
More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…



