Team46 group attacks
Team46 Attacks 😎 Yesterday, September 4, researchers from Doctor Web released an interesting report about a failed attack on a Russian freight rail operator. We…
Team46 Attacks 😎 Yesterday, September 4, researchers from Doctor Web released an interesting report about a failed attack on a Russian freight rail operator. We…
By the way, about Offzone 🙂 We promised to publish the latest version of the presentation from the talk about ExCobalt's maneuvers in the channel — here it is 🤝…
Exfiltration on an industrial scale 😐 The APT group Cloud Atlas has been attacking Russian companies since 2019, engaging in espionage and theft of confidential…
🫡 Hellhounds remains one of the most advanced groups attacking companies in Russia We have already covered Hellhounds' activity in the articles "Operation Lahat…
In early 2024, our team identified the use of the Cobint malware in customers' infrastructures 🥷 This malware is actively used by the (Ex)Cobalt group in attack…
🔎 Quick-and-dirty network research, or How to find a new, previously undiscovered activity of a known group in 15 minutes While analyzing external expertise on…
📬 How attackers are changing their approach to writing phishing emails Recently, we came across an email with a malicious attachment sent by the group Hive0117…
👏 One-two — and done. Generating FLIRT signatures And we do this to avoid wasting time on recognizing the library code of PureBasic, in which the COM-DLL-Droppe…
Proactive Hunting for C2 Servers 👨💻 In the process of hunting for C2 servers, an important question arises — which artifacts to use for better effectiveness an…
Rapid decryption of data from an NSIS script 🗄 When there's no time to identify the encryption algorithm and implement a decryption algorithm, a debugger comes…
❕ The ExCobalt group uses a new tool GoRed During incident response at our client, we discovered a file named scrond on one of the Linux nodes, "wrapped" with U…