Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group targeting at least oil and gas companies and the financial sector. D…
[ SECTION // THREATS // 193 ITEMS ]
6 groups across 33 tags
At the end of June, the PT ESC team, during incident investigations, discovered a new group targeting at least oil and gas companies and the financial sector. D…
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center has discovered a new group that we have named DENOmina…
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to add "Enterprise-grade" obfuscation We discovere…
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at Positive Technologies' Expert Security Center has discovered a camp…
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring, PT ESC specialists discovered a previously unknown APK file uploaded f…
⚡Fake news — B U L L S H I T PT ESC specialists discovered an interconnected network of news sites, email domains, and social media accounts that were used to s…
We will croc you 👻 PhantomCore continues to actively exploit misconfigurations in 1C to attack Russian organizations. We previously wrote about attacks on 1C us…
PT ESC Cyber Intelligence Group presented an overview of cyberattacks for Q2 2026 ✍️ The report analyzes the activity of hacker groups targeting Russian organiz…
CloudAtlas: a new wave of cyberattacks on organizations in Russia and Iraq using chains of legitimate web resources In May 2026, the Threat Intelligence departm…
NetMedved: Summer Campaign Against Russian Organizations 🐻👍 The PT ESC cyber intelligence group has recorded a new wave of activity by the NetMedved hacking gro…
PT ESC Cyber Intelligence Group presented an overview of cyberattacks for Q1 2026 ✍️ The report analyzes the activity of hacker groups targeting Russian organiz…
CHM snap-in, alarms, CIB of the Russian Ministry of Defense, and bitcoin eggs 🤖 At the end of December last year, the Threat Intelligence team of the Positive T…
Recently, our colleagues from the Positive Industrial Expertise Center discovered a curious Windows sample on MalwareBazaar. Here is its SHA-256: e014dadf6d93b3…
Recently, we came across an APK with an intriguing and trust-inspiring name: «Антивирус ФСБ.apk». After installing it, we discovered that upon launch, the user…
.exe .docm .xlsm Malicious files with these extensions are most often found in corporate network traffic. Let's take a basic look at why. 🖥 .exe — the classic e…
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail servers using the vulnerability CVE-2026-73570 and the TargetZimbra en…
He's not gsocket to you 😑 During the investigation of one of the incidents, PT ESC IR specialists came across a rather curious tool called hsocket (not to be co…
Recently, the Department for Comprehensive Response to Cyberthreats (PT ESC IR) received a number of samples of an Android banking trojan with remote control ca…
Citizen, update yourself 🫵 Recently, a sample mir-pay.apk flew into our sandbox. At first glance, nothing unusual: just another variation of the well-known Mamo…
AI-95 with a malicious additive ⛽️ In mid-June, the Threat Intelligence team discovered several resources at once using a "fuel" theme for malicious purposes. 0…
Dirty Frag 🐧💥 A week after the widely discussed Copy.Fail, researcher v4bel disclosed a new privilege escalation technique in the Linux kernel — Dirty Frag. As…
👨💻 Do you use email for work? Keep in mind that… ...up to 80% of phishing attacks on organizations are carried out through it. Positive Technologies specialist…
Infect a state and earn 3 rubles 🪙 In late February and early March, specialists from the PT ESC threat research department identified attacks on various organi…
Breaching the office through Office 👨💻 The PT ESC cyber intelligence team has recorded the first phishing campaign exploiting CVE-2026-21509, targeting Russian…
Our colleagues at Censys published a breakdown of the AsyncRAT family, describing an entire genealogical tree: AsyncRAT → DCRAT (DarkCrystal RAT) → VenomRAT → d…
Shove your claims into... PT Sandbox! 🫵 At the end of January, we discovered a malicious campaign distributing the PureRat (PureHVNC) malware to Russian organiz…
A fresh batch of soup 🍜 Back in summer 2025, our foreign colleagues already wrote about the SoupDealer trojan — an attack tailored specifically to users in Turk…
Work order for malware operation ✍️ In mid-January, the cyber intelligence group recorded a campaign by the hacker group XDSpy targeting organizations in Russia…
consumerWiper: architecture and mechanism of operation. Part 2 ❗️ Conclusions Analysis of this malware demonstrates a rational approach by the attackers. Since…
A New Window in Dark Mode 🫣 During the monitoring of new network threats in the network expertise department, suspicious traffic was noticed that was generated…
Over the past couple of months, the attacker has been distributing trojans from several npm accounts: alex05255, mdrafiqulislamrabby, b.w1001, abdev8773, and mo…
Someone said sandbox? 👀 Once again we're watching threat actors conduct unethical research. Given: Security researcher Nicholas Curran He published packages wit…
Hello! The Supply Chain Security group is here 🩷 We scan open source in real time for malicious code. We are also responsible at ESCalator for publications abou…
Attacker publishes .bash_history watch without registration and SMS 😱 The Supply Chain Security team sent a report to the npm registry administration about an a…
A logging library and an infostealer to boot? No thanks 👋 A lot has happened recently. For example, someone decided to play patron of the arts and published 30…
Unusual obfuscation is always beautiful... 🥰 ... it's just a shame that you have to see it in trojanized open-source packages, and not only at Capture The Flag…