Ghostly Gist
Ghostly Gist 😏 In March, PT ESC cyber intelligence specialists recorded activity from the Rare Werewolf group (Rezet, Librarian Ghouls). This time, an archive d…
Ghostly Gist 😏 In March, PT ESC cyber intelligence specialists recorded activity from the Rare Werewolf group (Rezet, Librarian Ghouls). This time, an archive d…
Keeping a finger on the Pulse: cyberattacks by the Mythic Likho group on Russia's critical information infrastructure 🔮 The Threat Intelligence Department of Po…
Breaching the office through Office 👨💻 The PT ESC cyber intelligence team has recorded the first phishing campaign exploiting CVE-2026-21509, targeting Russian…
UnsolicitedBooker: this uninvited boxer with 1 report will go down 🥊 In the fall of 2025, the Threat Intelligence team of the Positive Technologies cybersecurit…
PT ESC cyber intelligence group presents an overview of cyberattacks for Q4 2025 ✍️ The report analyzes the activity of hacker groups targeting Russian organiza…
Punishing Owl attacks Russia🦉 A new owl in the hacktivist forest 🎄 On the eve of the New Year, a number of Russian institutions received an unpleasant gift — a…
Work order for malware operation ✍️ In mid-January, the cyber intelligence group recorded a campaign by the hacker group XDSpy targeting organizations in Russia…
"Tax Audit" from East Asia 🚪 At the beginning of the investigation, the PT ESC Threat Intelligence team discovered attacks on several Russian banks. All observe…
Phantom in the Flesh 👻 In the summer of 2025, the Threat Intelligence team of the Positive Technologies cybersecurity expert center analyzed Operation Phantom E…
Operation CyberPosi 🤔 The PT ESC IR team, together with the Threat Intelligence team, is observing a new campaign by the APT group PhantomCore, in which the att…
How the Hammer of Thunder Disrupted the Claws of Silence 🦀 During an incident investigation, the Incident Response team, with support from the Threat Intelligen…
PrevedNetMedved 🐻 In October 2025, our cyber intelligence team detected ongoing phishing activity by a hacker group we have designated as NetMedved. The attacks…