Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group targeting at least oil and gas companies and the financial sector. D…
At the end of June, the PT ESC team, during incident investigations, discovered a new group targeting at least oil and gas companies and the financial sector. D…
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center has discovered a new group that we have named DENOmina…
We will croc you 👻 PhantomCore continues to actively exploit misconfigurations in 1C to attack Russian organizations. We previously wrote about attacks on 1C us…
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at Positive Technologies' Expert Security Center has discovered a camp…
⚡Fake news — B U L L S H I T PT ESC specialists discovered an interconnected network of news sites, email domains, and social media accounts that were used to s…
PT ESC Cyber Intelligence Group presented an overview of cyberattacks for Q2 2026 ✍️ The report analyzes the activity of hacker groups targeting Russian organiz…
CloudAtlas: a new wave of cyberattacks on organizations in Russia and Iraq using chains of legitimate web resources In May 2026, the Threat Intelligence departm…
NetMedved: Summer Campaign Against Russian Organizations 🐻👍 The PT ESC cyber intelligence group has recorded a new wave of activity by the NetMedved hacking gro…
PT ESC Cyber Intelligence Group presented an overview of cyberattacks for Q1 2026 ✍️ The report analyzes the activity of hacker groups targeting Russian organiz…
CHM snap-in, alarms, CIB of the Russian Ministry of Defense, and bitcoin eggs 🤖 At the end of December last year, the Threat Intelligence team of the Positive T…
Friday Newsletter 🐽 Imagine: you're an employee of a Russian organization, and on Friday someone named Nadezhda Arturovna 😌 sends you an email (screenshot 1) as…
Where does one group end and another begin? 🧩 In a new study, we examined a case that clearly demonstrates how the MaaS model complicates attack attribution. Th…