Who even are these PhaseShifters of yours?
😲 Who the heck are these PhaseShifters of yours? In early June 2024, specialists from the Threat Intelligence department identified a new PhaseShifters attack c…
😲 Who the heck are these PhaseShifters of yours? In early June 2024, specialists from the Threat Intelligence department identified a new PhaseShifters attack c…
Slam screen locker. What are you? ☹️ Next up is fast malware analysis, conducted on one Sunday evening. An interesting sample flew into our networks, generating…
Methods for Masking a Virtual Environment 😷 During malware analysis, you may encounter samples that will not function fully in a virtual environment. This is be…
TLS on the network: what to do 🤷♂️ You are a powerful network traffic analysis engine. You work for the benefit of the information security system, grinding th…
Open source passions: part two Infostealers 🧋 No one is surprised by them anymore, since this is a popular class of malware, often mentioned in the news. Most t…
By the way, about Offzone 🙂 We promised to publish the latest version of the presentation from the talk about ExCobalt's maneuvers in the channel — here it is 🤝…
!!р^д**н**c 🤔 A characteristic example of how threat actors use current events to distribute malicious programs is a malicious document we discovered. It contai…
⛩ Attackers are looking for new ways to "open the gates" We recently discovered an unusual attack scheme. The attackers first establish contact with the victim…
In early 2024, our team identified the use of the Cobint malware in customers' infrastructures 🥷 This malware is actively used by the (Ex)Cobalt group in attack…
🤨 Adding bookmarks to open-source repositories? Young man, come with us. As part of threat intelligence, in addition to researching "traditional" malware, we al…
🔎 Quick-and-dirty network research, or How to find a new, previously undiscovered activity of a known group in 15 minutes While analyzing external expertise on…
👏 One-two — and done. Generating FLIRT signatures And we do this to avoid wasting time on recognizing the library code of PureBasic, in which the COM-DLL-Droppe…