TaxOff: it seems you have… a backdoor
📑 TaxOff: looks like you have… a backdoor In the third quarter, specialists from the TI department of the Positive Technologies Expert Security Center (PT Exper…
📑 TaxOff: looks like you have… a backdoor In the third quarter, specialists from the TI department of the Positive Technologies Expert Security Center (PT Exper…
What exactly is wrong with this AES? ❔ Attackers often use encryption to obfuscate parts of malware samples that may be of greatest interest during research. Wh…
Through the blockchain to the data ⭐️ Researchers from Socket and Checkmarx have reported on an interesting malicious campaign in NPM. The attackers mimicked pl…
Over, over, can you hear us? 😲 Despite the fact that hackers have recently gotten lazy and increasingly don't develop anything of their own, original attack ide…
📲 Cloud services from the "MeHaFon" operator News from the field: the PT ESC team is observing a new campaign by the Cloud Atlas group targeting government orga…
APT-C-60, aka DarkHotel 💿 We once talked about the use of VHDX files in attacks and why it is convenient (no, this is not a call to action). You can find that p…
Come again, I can't see it well 😳 Recently, the PT ESC cyber intelligence team discovered an example of a multi-stage phishing attack in which the attackers fir…
Learning to Recover VMProtect Imports ⚙️ VMProtect is one of the most widely used malware protectors. At the same time, attackers are often lazy and use only si…
😲 Who the heck are these PhaseShifters of yours? In early June 2024, specialists from the Threat Intelligence department identified a new PhaseShifters attack c…
Gapucino* — is GOFFEE ☕️ Today we are covering one of the most active campaigns currently underway in Russia. Other researchers call it GOFFEE. As the initial v…
Catching bug hunters again 💀 In one of our previous posts we wrote about traces of bug bounty activity targeting "Yandex". History repeated itself, but this tim…
🛠 Reverse Engineering Delphi without IDR When you're actively involved in reverse engineering, sooner or later you encounter an executable file written in Delph…