Phantom pains
Phantom pains 👻 In May, the Threat Intelligence department of the Positive Technologies Expert Security Center (PT ESC TI) discovered a new large-scale cyber es…
Phantom pains 👻 In May, the Threat Intelligence department of the Positive Technologies Expert Security Center (PT ESC TI) discovered a new large-scale cyber es…
From Phantom Payments to Confidential Data 🫰 In June, we published an article about discovered Exchange keyloggers. At that time, nine victim companies were ide…
PT ESC cyber intelligence group presents a review of cyberattacks for Q2 2025 ✍️ The report examines the most notable attacks on the IT infrastructure of Russia…
Operation Tartaria Part 2 In addition to the passive backdoor PlugX, we managed to discover another version of it that mimicked the launch of Yandex Browser. {&…
Operation Tartaria — PlugX 🤝 DevTunnels At the end of May, PHDays Fest wrapped up, during which, on the Defense track, the 4RAYS team discussed the specifics of…
Node JS. Malicious activity at the installation stage As part of researching the actions of attackers in npm (Node Package Manager, the main repository of JS co…
The Return of the Bloody Wolf 🐺 Since early May, the PT ESC cyber intelligence team has discovered a new wave of attacks by the Bloody Wolf group against organi…
Drama around PyPI: 🪰⮕🐘? Last week, CNews published a news item: "Russians driven out of the Python community. Only the chosen ones for now, but the selection cr…
Jade Metal: the not-so-new Telemanmilconfav group attacks military organizations? 🪖 In March, researchers from F6 published a report on the Telemancon group, wh…
Exchange Mutation. How We Caught Anomalies in Outlook Pages 😮 Continuing our series of incident investigation stories (you can read about them here, here, and p…
IoCs-detox: protecting TI from false indicators ✋ Imagine this: your SOC team receives a fresh feed of compromise indicators. The list contains hundreds of new…
DarkGaboon. The venom of a cyber viper in the digital veins of Russian companies 🐍 In January of this year, the cyber intelligence group of the TI department at…