Hunting RATs by their own certificates 🕵️
Our colleagues at Censys published a breakdown of the AsyncRAT family, describing an entire genealogical tree: AsyncRAT → DCRAT (DarkCrystal RAT) → VenomRAT → d…
Our colleagues at Censys published a breakdown of the AsyncRAT family, describing an entire genealogical tree: AsyncRAT → DCRAT (DarkCrystal RAT) → VenomRAT → d…
Confusion Around WSUS Vulnerabilities: Setting the Record Straight 🕷 One of the most pressing vulnerabilities in Windows Server Update Services (WSUS) is a crit…
He may not, as unvalued persons do, Carve for himself (W. Shakespeare) When investigating an infrastructure that has been subjected to encryption, there is regu…
A New Connection to Old Techniques 📡 During incident investigations, the PT ESC IR team discovered a reverse shell developed in .NET and observed since 2023. It…
Idea for a SIEM correlation rule 💡 Although tracking the entire attack chain described in the posts above provides a complete picture, the strongest and simples…
How to create rules for network traffic to address a future threat 🤨 This was discussed this week in China during the third cybersecurity summit, which included…
Continuing previous publications, we explain how to detect the CVE-2025-33073 vulnerability 🕵️♂️ 1️⃣ Monitor DNS queries with a Marshalled suffix In Reflection…
Yara-Yara-Yara! 🐧 Now that we've sorted out strings, we can move on to generating byte signatures. Usually people try to make them as rarely as possible, since…
Yara Yara Daze Anyone involved in malware analysis is certainly familiar with a tool like YARA 😉. With its help, many companies 🔴 build sets of signature rules…
(Ex)Cobalt == (Ex)Carbanak 🤔 Since the beginning of 2025, the PT ESC team has observed a rise in the number of attacks using the SshDoor backdoor. Russian gover…
A complex password won't help 📮 The practice of the PT ESC IR information security incident response team shows that attackers, upon gaining access to companies…
🔄 Major malware rules update Suricata I hope you remember that we have a public Suricata rules repository (we wrote about launching the resource in another post…