APT31. Attacks of the Striking Panda
APT31. Striking Panda Attacks 🐼 From 2024 to 2025, Russian IT companies operating as contractors and solution integrators for government agencies faced a series…
APT31. Striking Panda Attacks 🐼 From 2024 to 2025, Russian IT companies operating as contractors and solution integrators for government agencies faced a series…
A lone wolf is no companion for you 🐺 The cyber intelligence team has recorded another phishing campaign by the Lone Wolf group: the attackers use steganography…
PT ESC Cyber Intelligence Group Presents Q3 2025 Cyberattack Overview ✍️ The report examines hacker attacks on the infrastructure of Russian organizations and t…
Malware flies, malware runs, malware sits in the sandbox ⏳ In mid-August, we reported on a new large-scale campaign by the PhantomCore group, detected by the Th…
APT31 Grouping Tool. CloudyLoader 🌩 In one of the incidents, the PT ESC IR team encountered an interesting malicious file that loads a payload in several stages…
Operation Tartaria — VTDoor 🚪 We have already covered Operation Tartaria in several posts — part 1 and part 2. In one of the cases, the PT ESC IR team discovere…
The Lost Goffee Bean 🤨 Literally a couple of days after our research into the activity of the Goffee group, another attack was carried out, which we will now te…
Fortune Telling on Goffee Grounds: Current Tools and Grouping Features of Goffee in Attacks on Russia ☕️ Throughout 2024-2025, experts from the TI department ha…
Phantom pains 👻 In May, the Threat Intelligence department of the Positive Technologies Expert Security Center (PT ESC TI) discovered a new large-scale cyber es…
From Phantom Payments to Confidential Data 🫰 In June, we published an article about discovered Exchange keyloggers. At that time, nine victim companies were ide…
PT ESC cyber intelligence group presents a review of cyberattacks for Q2 2025 ✍️ The report examines the most notable attacks on the IT infrastructure of Russia…
Operation Tartaria Part 2 In addition to the passive backdoor PlugX, we managed to discover another version of it that mimicked the launch of Yandex Browser. {&…