A sucker is not a mammoth, an APK is not a video.
A fool and his money are soon parted, APK is not a video 🦣 In late 2024 — early 2025, information about the spread of the Mamont virus in Telegram was actively…
A fool and his money are soon parted, APK is not a video 🦣 In late 2024 — early 2025, information about the spread of the Mamont virus in Telegram was actively…
"Attaching the data in the attachment" 💌 Today we have as our guest a small, but no less interesting and experimental reverse shell for Linux. Although it's har…
Attacker published malicious packages deepseeek and deepseekai on the Python Package Index 🐳 The Supply Chain Security team of the Threat Intelligence departmen…
Rare Wolf is preparing to hunt 🐺 The PT ESC cyberthreat intelligence team consistently tracks down new command-and-control servers used by threat groups, as wel…
Tools for Working with Python 😦 Attackers are not shy about using Python for their purposes. LazyStealer, packaged with PyInstaller, the Python backdoor in Shad…
Viper Style 🐍 Can an attacker use well-known tools and remain undetected for over a year and a half? Our answer is yes. In mid-October 2024, the cyber intellige…
Your hash, please… Thank you! 🙏 In early January, we discovered a file that drew attention for its content and structure. An examination of the document's metad…
🚘 One lazy driver Recently, the PT ESC cyber intelligence group discovered an executable file with an "unusual" name, reinforced by a distinctive PDF file icon…
First steps on the hacking path 🐱 Open source is an interesting environment for observing how projects evolve. It's fascinating to study the implementation of t…
🥸 Can Stalin control your computer? Probably not. But PowerStalin definitely can. Recently, we came across a malicious PowerShell script that its author affecti…
PrevedMedved 👋 — it's Lumma Stealer again In mid-November, the PT ESC cyber threat intelligence team recorded a campaign distributing the malware Lumma Stealer…
Another stealer in Python?! 🫣 Since the beginning of September, we have been tracking attacks that at first glance could be attributed to the activity of the La…