C2 hunting: part 2.
C2 hunting: part 2. Hunting for hacker servers by external signs 😁 In the previous part, we talked about how to expand knowledge about hackers' infrastructure u…
C2 hunting: part 2. Hunting for hacker servers by external signs 😁 In the previous part, we talked about how to expand knowledge about hackers' infrastructure u…
"Attaching the data in the attachment" 💌 Today we have as our guest a small, but no less interesting and experimental reverse shell for Linux. Although it's har…
(Ex)Cobalt in a Container 🛂 During the response to a computer incident, the PT ESC IR team established the fact that attackers had gained a foothold in Docker c…
Your hash, please… Thank you! 🙏 In early January, we discovered a file that drew attention for its content and structure. An examination of the document's metad…
Lok'tar ogar! 👺 In today's world, attacks aimed at gaining initial access have become more sophisticated. Threat actors use multi-stage payloads, which allows t…
🚘 One lazy driver Recently, the PT ESC cyber intelligence group discovered an executable file with an "unusual" name, reinforced by a distinctive PDF file icon…
🥸 Can Stalin control your computer? Probably not. But PowerStalin definitely can. Recently, we came across a malicious PowerShell script that its author affecti…
PrevedMedved 👋 — it's Lumma Stealer again In mid-November, the PT ESC cyber threat intelligence team recorded a campaign distributing the malware Lumma Stealer…
📑 TaxOff: looks like you have… a backdoor In the third quarter, specialists from the TI department of the Positive Technologies Expert Security Center (PT Exper…
Over, over, can you hear us? 😲 Despite the fact that hackers have recently gotten lazy and increasingly don't develop anything of their own, original attack ide…
📲 Cloud services from the "MeHaFon" operator News from the field: the PT ESC team is observing a new campaign by the Cloud Atlas group targeting government orga…
Stealer infection: a new USB strain 👾 Today we're going to talk about an unusual modification of the WorldWind stealer that we discovered. It is a real, bona fi…