How did SaT entangle several groups at once in a tangle?
How did CaT entangle several groups at once? 🧶 In the fall of 2024, our attention was drawn to an interesting tool discovered while studying the activity of the…
How did CaT entangle several groups at once? 🧶 In the fall of 2024, our attention was drawn to an interesting tool discovered while studying the activity of the…
Truly subtle interaction 🕊 During reverse engineering of the protocol of one of the Brazilian banking trojans, the use of an interesting network framework was d…
What is the steganographic mafia hiding from us? 👤 In November 2024, we told you about the PhaseShifters group and also mentioned the subscription-based crypter…
Tools for Working with Python 😦 Attackers are not shy about using Python for their purposes. LazyStealer, packaged with PyInstaller, the Python backdoor in Shad…
Lok'tar ogar! 👺 In today's world, attacks aimed at gaining initial access have become more sophisticated. Threat actors use multi-stage payloads, which allows t…
😏 Useful tools: Mandiant capa Imagine the situation: you are a malware analyst or an incident response specialist and you need to analyze a large volume of bina…
Ngrok. Finding and understanding it 🔍 In the process of investigating numerous incidents, we repeatedly encounter a tool such as ngrok. It is a convenient legit…
SSH-IT. Guide to detecting a popular tool 🔭 In the course of investigating numerous incidents involving the compromise of Linux nodes, we sometimes discover var…
Gsocket: how to find one of the most popular tools 🙂 In the course of investigating numerous incidents involving the compromise of Linux nodes, we often discove…
🟥 ⚔️ 💿 Virtual Disk as the Start of an Attack In early September, experts from the TI cyberintelligence group of the PT ESC department discovered an interesting…
🗂 Useful Data Sources: MISP Warning Lists Information security analysts deal with massive volumes of threat data on a daily basis. To extract the most relevant…
😈 Exfiltration Gone Wrong When investigating incidents, we periodically encounter threat actors exfiltrating data before encrypting infrastructure. One of the e…