Shove your complaints into... PT Sandbox!
Shove your claims into... PT Sandbox! 🫵 At the end of January, we discovered a malicious campaign distributing the PureRat (PureHVNC) malware to Russian organiz…
Shove your claims into... PT Sandbox! 🫵 At the end of January, we discovered a malicious campaign distributing the PureRat (PureHVNC) malware to Russian organiz…
Dissecting network traffic with ML in search of new malware 📖 🧪 We — the network expertise department team of the ESC antivirus laboratory and the machine learn…
A fresh batch of soup 🍜 Back in summer 2025, our foreign colleagues already wrote about the SoupDealer trojan — an attack tailored specifically to users in Turk…
PT ESC cyber intelligence group presents an overview of cyberattacks for Q4 2025 ✍️ The report analyzes the activity of hacker groups targeting Russian organiza…
PDQ-Masters 🧙♂️ The main attack vector using malware is phishing campaigns via email. The ideal phishing email with malware differs from a legitimate email onl…
"Tax Audit" from East Asia 🚪 At the beginning of the investigation, the PT ESC Threat Intelligence team discovered attacks on several Russian banks. All observe…
A New Window in Dark Mode 🫣 During the monitoring of new network threats in the network expertise department, suspicious traffic was noticed that was generated…
Hush, hush: a new campaign against CIS countries 🤫 In the second half of 2025, we discovered a new series of attacks by the SweetSpecter group targeting CIS cou…
In addition to the post 👆 Disabling Defender / MpPreference Set-MpPreference -DisableRealtimeMonitoring $true Set-MpPreference -DisableBehaviorMonitoring $true…
Using DefendNot in XWorm Attacks 🪱 A cyber intelligence group has recorded phishing activity aimed at data theft followed by monetary extortion (screenshot 1)…
PrevedNetMedved 🐻 In October 2025, our cyber intelligence team detected ongoing phishing activity by a hacker group we have designated as NetMedved. The attacks…
A lone wolf is no companion for you 🐺 The cyber intelligence team has recorded another phishing campaign by the Lone Wolf group: the attackers use steganography…