[ << ALL_FEED ]

PT ESC cyber intelligence group presented an overview of cyberattacks for Q4 2025 ✍️

More in General

PT ESC cyber intelligence group presents an overview of cyberattacks for Q4 2025 ✍️

The report analyzes the activity of hacker groups targeting Russian organizations — from the public sector and military-industrial complex to industry, finance, and telecommunications.

It describes the activity of APT31, ExCobalt, QuietCrabs, Rare Werewolf, PseudoGamaredon, as well as financially motivated Werewolves, NetMedved, Silver Fox, and Hive0117.

✉️ Primary initial access vectors:

• Targeted phishing using business correspondence pretexts, notifications from government agencies, and procurement documentation;
• Password-protected archives containing LNK, SCR, EXE loaders and decoy documents;
• Exploitation of fresh RCE vulnerabilities with mass scanning of external services;
• Compromise of contractors and exposed RDP services.

🔧 Key trends and techniques:

• Continuous evolution of tooling;
• Active use of legitimate services and clouds for stealthy command and control;
• New persistence methods;
• Steganography and multi-stage chains;
• Rapid exploitation of zero-day and n-day vulnerabilities.

You can read the report on our blog.

#TI #APT #Malware #Phishing
@ptescalator

More from ti_author

More from ti_author

More in General