Rare fixation techniques. Part 3
Rare persistence techniques. Part 3 Also read about: Zabbix Agent, TimeProvider, COM Hijacking. 4️⃣ WMICLNT This persistence technique is based on hijacking a D…
Rare persistence techniques. Part 3 Also read about: Zabbix Agent, TimeProvider, COM Hijacking. 4️⃣ WMICLNT This persistence technique is based on hijacking a D…
Rare persistence techniques. Part 2 Also read about: Zabbix Agent, TimeProvider. 3️⃣ COM Hijacking For persistence in the infrastructure, the attackers used a r…
Rare persistence techniques In the first six months of 2026, the PT ESC IR team recorded a number of rare persistence techniques on compromised hosts, which we…
⚠️ Turned on Wi-Fi debugging — got Mamont In early May, a vulnerability CVE-2026-0073 was discovered on Android devices that allows remote execution of commands…
The diamond is barely visible 💎 During the analysis of PT ESC IR dumps, we periodically encounter new malware families that are not detected by known indicators…
🫣 Hiding in plain sight: how PhantomCore masks its activity using legitimate tools The PT ESC IR team has presented a new study dedicated to the activities of t…
Lately, we are increasingly encountering devices that have received a compromise notification from Apple 📲 If you receive a message on your device in iMessage f…
Time to update ⚠️ In early December we already reported how hackers infiltrate infrastructure through unpatched vulnerabilities in the TrueConf server that admi…
consumerWiper: architecture and mechanism of operation. Part 2 ❗️ Conclusions Analysis of this malware demonstrates a rational approach by the attackers. Since…
consumerWiper: architecture and operating mechanism. Part 1 ☹️ During the investigation of one of the incidents, the PT ESC response team discovered the consume…
Using IoC in a Non-Standard Way. Part 2. Threat Landscape 🧘♀️ Earlier, we discussed how to use indicators of compromise for Threat Hunting. This time, we’ll ta…
🤑 I'll help you donate Recently, we received a sample of a malicious app for research that is used to steal money from Android users (screenshot 1). In 2015, st…