"I'm attaching the data in the attachment" 💌
"Attaching the data in the attachment" 💌 Today we have as our guest a small, but no less interesting and experimental reverse shell for Linux. Although it's har…
"Attaching the data in the attachment" 💌 Today we have as our guest a small, but no less interesting and experimental reverse shell for Linux. Although it's har…
(Ex)Cobalt in a Container 🛂 During the response to a computer incident, the PT ESC IR team established the fact that attackers had gained a foothold in Docker c…
Rare Wolf is preparing to hunt 🐺 The PT ESC cyberthreat intelligence team consistently tracks down new command-and-control servers used by threat groups, as wel…
Viper Style 🐍 Can an attacker use well-known tools and remain undetected for over a year and a half? Our answer is yes. In mid-October 2024, the cyber intellige…
🚘 One lazy driver Recently, the PT ESC cyber intelligence group discovered an executable file with an "unusual" name, reinforced by a distinctive PDF file icon…
😏 Useful tools: Mandiant capa Imagine the situation: you are a malware analyst or an incident response specialist and you need to analyze a large volume of bina…
🥸 Can Stalin control your computer? Probably not. But PowerStalin definitely can. Recently, we came across a malicious PowerShell script that its author affecti…
PrevedMedved 👋 — it's Lumma Stealer again In mid-November, the PT ESC cyber threat intelligence team recorded a campaign distributing the malware Lumma Stealer…
Another stealer in Python?! 🫣 Since the beginning of September, we have been tracking attacks that at first glance could be attributed to the activity of the La…
What exactly is wrong with this AES? ❔ Attackers often use encryption to obfuscate parts of malware samples that may be of greatest interest during research. Wh…
Stealer infection: a new USB strain 👾 Today we're going to talk about an unusual modification of the WorldWind stealer that we discovered. It is a real, bona fi…
Learning to Recover VMProtect Imports ⚙️ VMProtect is one of the most widely used malware protectors. At the same time, attackers are often lazy and use only si…