[ GROUP // INDICATORS & C2 // 48 ITEMS ]

INDICATORS & C2

> in section Threats

// Threats

This is Siemens...

Recently, our colleagues from the Positive Industrial Expertise Center discovered a curious Windows sample on MalwareBazaar. Here is its SHA-256: e014dadf6d93b3…

global_author
// Threats

Operation Chewbacca

At the end of June, the PT ESC team, during incident investigations, discovered a new group targeting at least oil and gas companies and the financial sector. D…

oUth0R
// Threats

Your Zimbra server is at risk

Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail servers using the vulnerability CVE-2026-73570 and the TargetZimbra en…

oUth0R
// Threats

He's not your gsocket

He's not gsocket to you 😑 During the investigation of one of the incidents, PT ESC IR specialists came across a rather curious tool called hsocket (not to be co…

oUth0R
// Threats

A new batch of soup

A fresh batch of soup 🍜 Back in summer 2025, our foreign colleagues already wrote about the SoupDealer trojan — an attack tailored specifically to users in Turk…

ti_author
// Threats

New window in dark mode

A New Window in Dark Mode 🫣 During the monitoring of new network threats in the network expertise department, suspicious traffic was noticed that was generated…

global_author