Hunting RATs by their own certificates 🕵️
Our colleagues at Censys published a breakdown of the AsyncRAT family, describing an entire genealogical tree: AsyncRAT → DCRAT (DarkCrystal RAT) → VenomRAT → d…
Our colleagues at Censys published a breakdown of the AsyncRAT family, describing an entire genealogical tree: AsyncRAT → DCRAT (DarkCrystal RAT) → VenomRAT → d…
Click trap: not only for users, but also for link analyzers 🐭 When manually analyzing links, we typically ask ourselves only one question — “is it safe?” ✔️❌ Tr…
In addition to the previous post we are looking at additional tools for decrypting network traffic. Let's look at an alternative to PolarProxy that is no…
MITM attack is a fairly popular feature of various sandboxes and application analysis systems. Typically, tools that enable MITM attacks are a proxy serv…
🦈 Looking Under the Hood of Secure Connections in Wireshark. Part 1: TLS Our network experts often need to decrypt TLS connection traffic and analyze protected…
😐 “Why aren't you answering?”, or The Story of How to Steal a Telegram Account Without Registration or SMS Recently we published an article about the most popul…
Are you using cryptography correctly? 🔓 The Advanced Threat Research Group of the Threat Intelligence department often has to solve interesting tasks in the pro…
An endless chain of redirects ♾️ Quite often, when sending phishing links via email, attackers do not attach them explicitly to the email but use various redire…
Phishing Legitimacy 😂 During an analysis of one phishing email, we noticed how attackers attempted to place phishing content on a page of the telegra․ph domain…
Do you see the authorization form? No. Neither do I. But it's there 🤔 During a recent investigation of one of the incidents, we encountered exploitation by atta…