The city celebrates, the mafia wakes up
The city celebrates, the mafia wakes up 🥰 Between January 1 and 11, approximately 180 malicious packages were removed from the NPM ecosystem, and 16 from PyPI…
The city celebrates, the mafia wakes up 🥰 Between January 1 and 11, approximately 180 malicious packages were removed from the NPM ecosystem, and 16 from PyPI…
"Tax Audit" from East Asia 🚪 At the beginning of the investigation, the PT ESC Threat Intelligence team discovered attacks on several Russian banks. All observe…
Phantom in the Flesh 👻 In the summer of 2025, the Threat Intelligence team of the Positive Technologies cybersecurity expert center analyzed Operation Phantom E…
Hush, hush: a new campaign against CIS countries 🤫 In the second half of 2025, we discovered a new series of attacks by the SweetSpecter group targeting CIS cou…
Operation CyberPosi 🤔 The PT ESC IR team, together with the Threat Intelligence team, is observing a new campaign by the APT group PhantomCore, in which the att…
In addition to the post 👆 Disabling Defender / MpPreference Set-MpPreference -DisableRealtimeMonitoring $true Set-MpPreference -DisableBehaviorMonitoring $true…
Using DefendNot in XWorm Attacks 🪱 A cyber intelligence group has recorded phishing activity aimed at data theft followed by monetary extortion (screenshot 1)…
We would very much like to give you an overview of "tomato gose," but on Friday you voted for a new analysis of (Ex)Cobalt... 🙄 This is one of the most active a…
How the Hammer of Thunder Disrupted the Claws of Silence 🦀 During an incident investigation, the Incident Response team, with support from the Threat Intelligen…
A New Connection to Old Techniques 📡 During incident investigations, the PT ESC IR team discovered a reverse shell developed in .NET and observed since 2023. It…
Deobfuscating .NET function names manually 🙌 .NET malware loves packers, obfuscation (of names, CFG, and other things), and multi-stage reflective image loading…
PrevedNetMedved 🐻 In October 2025, our cyber intelligence team detected ongoing phishing activity by a hacker group we have designated as NetMedved. The attacks…