[ GROUP // INDICATORS & C2 // 48 ITEMS ]

INDICATORS & C2

> in section Threats

// Threats

Repeat, it's hard to see

Come again, I can't see it well 😳 Recently, the PT ESC cyber intelligence team discovered an example of a multi-stage phishing attack in which the attackers fir…

ti_author
// Threats

OWOWA

⚠️ OWOWAsome module, or IIS kOWOWAren Researchers reported on the malicious IIS module Owowa, designed to intercept user credentials, back in 2021. And in 2022…

oUth0R
// Threats

Gapucino* is GOFFEE

Gapucino* — is GOFFEE ☕️ Today we are covering one of the most active campaigns currently underway in Russia. Other researchers call it GOFFEE. As the initial v…

oUth0R
// Threats

How to get on the internet

How to get to the internet 🚶‍♂️ What do hackers do when the network segment they're interested in has no internet access, but they really want to connect to C2?…

oUth0R
// Threats

Colonels write first!

Colonels write first! (🔞) The collection of malicious mass mailings sent in the name of law enforcement agencies has a new addition. In September, several recip…

ti_author
// Threats

СHavocают

СHavocают Recently, a phishing email fell into our hands. The email subject is in the best traditions of phone spam calls, when someone calls you from the FSB a…

ti_author
// Threats

C2 hunting: part 1

C2 hunting: part 1. Expanding visibility of hackers' network infrastructure 😜 Often when investigating an attack, performing TI analysis, or DFIR, a specialist…

ti_author
// Threats

Team46 group attacks

Team46 Attacks 😎 Yesterday, September 4, researchers from Doctor Web released an interesting report about a failed attack on a Russian freight rail operator. We…

ti_author
// Threats

Industrial-scale exfiltration

Exfiltration on an industrial scale 😐 The APT group Cloud Atlas has been attacking Russian companies since 2019, engaging in espionage and theft of confidential…

oUth0R
// Threats

Proactive hunting for C2 servers

Proactive Hunting for C2 Servers 👨‍💻 In the process of hunting for C2 servers, an important question arises — which artifacts to use for better effectiveness an…

ti_author