Deobfuscating .NET function names manually
Deobfuscating .NET function names manually 🙌 .NET malware loves packers, obfuscation (of names, CFG, and other things), and multi-stage reflective image loading…
Deobfuscating .NET function names manually 🙌 .NET malware loves packers, obfuscation (of names, CFG, and other things), and multi-stage reflective image loading…
APT31. Striking Panda Attacks 🐼 From 2024 to 2025, Russian IT companies operating as contractors and solution integrators for government agencies faced a series…
PT ESC Cyber Intelligence Group Presents Q3 2025 Cyberattack Overview ✍️ The report examines hacker attacks on the infrastructure of Russian organizations and t…
Long, weird, but it works 🍊🍊🍊🍊🍊🍊🍊🍊🍊🍊🍊 Not everything we investigate turns out to be complex attacks by serious groups. Sometimes attacks only appear complex. We…
Malware flies, malware runs, malware sits in the sandbox ⏳ In mid-August, we reported on a new large-scale campaign by the PhantomCore group, detected by the Th…
APT31 Grouping Tool. CloudyLoader 🌩 In one of the incidents, the PT ESC IR team encountered an interesting malicious file that loads a payload in several stages…
Generating a COM vtable in IDA 🐍 While analyzing one of the Snake Keylogger variants, we needed to figure out which managed methods the native module calls thro…
Operation Tartaria — VTDoor 🚪 We have already covered Operation Tartaria in several posts — part 1 and part 2. In one of the cases, the PT ESC IR team discovere…
Fortune Telling on Goffee Grounds: Current Tools and Grouping Features of Goffee in Attacks on Russia ☕️ Throughout 2024-2025, experts from the TI department ha…
From Phantom Payments to Confidential Data 🫰 In June, we published an article about discovered Exchange keyloggers. At that time, nine victim companies were ide…
PT ESC cyber intelligence group presents a review of cyberattacks for Q2 2025 ✍️ The report examines the most notable attacks on the IT infrastructure of Russia…
Operation Tartaria Part 2 In addition to the passive backdoor PlugX, we managed to discover another version of it that mimicked the launch of Yandex Browser. {&…