We continue reproducing the attack from the post above 🔼
Continuing to reproduce the attack from the post above 🔼 3️⃣ Creating a public API Gateway trigger (screenshot 1) At the end, we need to expose the function to…
Continuing to reproduce the attack from the post above 🔼 3️⃣ Creating a public API Gateway trigger (screenshot 1) At the end, we need to expose the function to…
☁️ AWS backdoor as a service: persistence in the cloud via Lambda The cloud threat landscape is constantly evolving, and attackers are increasingly abusing legi…
How to create rules for network traffic to address a future threat 🤨 This was discussed this week in China during the third cybersecurity summit, which included…
APT31 Grouping Tool. CloudyLoader 🌩 In one of the incidents, the PT ESC IR team encountered an interesting malicious file that loads a payload in several stages…
Operation Tartaria — VTDoor 🚪 We have already covered Operation Tartaria in several posts — part 1 and part 2. In one of the cases, the PT ESC IR team discovere…
Fortune Telling on Goffee Grounds: Current Tools and Grouping Features of Goffee in Attacks on Russia ☕️ Throughout 2024-2025, experts from the TI department ha…
Operation Tartaria Part 2 In addition to the passive backdoor PlugX, we managed to discover another version of it that mimicked the launch of Yandex Browser. {&…
Operation Tartaria — PlugX 🤝 DevTunnels At the end of May, PHDays Fest wrapped up, during which, on the Defense track, the 4RAYS team discussed the specifics of…
All Hackers Go To Cloud ☁️💻 During the investigation of an incident in a fully encrypted infrastructure, we identified an autonomous web server hosting the clie…
HTML attachments as a phishing tool 🤑 Delivery of HTML-like email attachments containing various techniques for opening third-party web content, interacting wit…
Interview → iPhone software from the "employer" → you no longer have a smartphone 👋 The old-new scheme for locking an iPhone via "Lost Mode" is back in circulat…
Malware in SYSVOL: finding the source 😐 Let's say we're investigating a ransomware incident. The attackers used a Group Policy to launch the ransomware (for exa…