[ SECTION // THREATS // 193 ITEMS ]

THREATS

6 groups across 33 tags

General

#ti 134 #news 9 #cybercrime 1 #fakenews 1

// Threats

Operation Chewbacca

At the end of June, the PT ESC team, during incident investigations, discovered a new group targeting at least oil and gas companies and the financial sector. D…

oUth0R
// Threats

Ding, ding — who's there?

Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center has discovered a new group that we have named DENOmina…

ti_author
// Threats

⚡Fake news — THAT'S ALL

⚡Fake news — B U L L S H I T PT ESC specialists discovered an interconnected network of news sites, email domains, and social media accounts that were used to s…

ti_author

> ещё 134 по тегам этой группы

Threat actors

#apt 65 #excobalt 4 #phantomcore 1 #cloudatlas 1 #gored 1 #hellhounds 1 #hive0117 1 #patchwork 1 #xdigo 1

// Threats

We will croc you

We will croc you 👻 PhantomCore continues to actively exploit misconfigurations in 1C to attack Russian organizations. We previously wrote about attacks on 1C us…

oUth0R

> ещё 65 по тегам этой группы

Malware

#malware 92 #stealer 2 #wiper 2 #cobint 1 #comdlldropper 1 #darkgate 1 #rat 1 #spyware 1

// Threats

This is Siemens...

Recently, our colleagues from the Positive Industrial Expertise Center discovered a curious Windows sample on MalwareBazaar. Here is its SHA-256: e014dadf6d93b3…

global_author
// Threats

Anti-antivirus

Recently, we came across an APK with an intriguing and trust-inspiring name: «Антивирус ФСБ.apk». After installing it, we discovered that upon launch, the user…

global_author
// Threats

.exe .docm .xlsm

.exe .docm .xlsm Malicious files with these extensions are most often found in corporate network traffic. Let's take a basic look at why. 🖥 .exe — the classic e…

global_author
// Threats

Your Zimbra server is at risk

Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail servers using the vulnerability CVE-2026-73570 and the TargetZimbra en…

oUth0R
// Threats

He's not your gsocket

He's not gsocket to you 😑 During the investigation of one of the incidents, PT ESC IR specialists came across a rather curious tool called hsocket (not to be co…

oUth0R

> ещё 91 по тегам этой группы

Phishing & sandbox

#phishing 44 #avlab 10 #sandbox 5 #emailsecurity 2 #sandboxteam 2

// Threats

Citizen, update yourself 🫵

Citizen, update yourself 🫵 Recently, a sample mir-pay.apk flew into our sandbox. At first glance, nothing unusual: just another variation of the well-known Mamo…

ti_author
// Threats

Dirty Frag 🐧

Dirty Frag 🐧💥 A week after the widely discussed Copy.Fail, researcher v4bel disclosed a new privilege escalation technique in the Linux kernel — Dirty Frag. As…

global_author
// Threats

Do you use email for work?

👨‍💻 Do you use email for work? Keep in mind that… ...up to 80% of phishing attacks on organizations are carried out through it. Positive Technologies specialist…

global_author

> ещё 45 по тегам этой группы

Indicators & C2

#ioc 41 #c2 12

// Threats

A new batch of soup

A fresh batch of soup 🍜 Back in summer 2025, our foreign colleagues already wrote about the SoupDealer trojan — an attack tailored specifically to users in Turk…

ti_author
// Threats

New window in dark mode

A New Window in Dark Mode 🫣 During the monitoring of new network threats in the network expertise department, suspicious traffic was noticed that was generated…

global_author

> ещё 42 по тегам этой группы

Supply chain

#scs 16 #pyanalysis 14 #pypi 10 #npm 7 #supplychain 1

// Threats

Did someone say sandbox?

Someone said sandbox? 👀 Once again we're watching threat actors conduct unethical research. Given: Security researcher Nicholas Curran He published packages wit…

ti_author

> ещё 15 по тегам этой группы