Citizen, update yourself 🫵
Citizen, update yourself 🫵 Recently, a sample mir-pay.apk flew into our sandbox. At first glance, nothing unusual: just another variation of the well-known Mamo…
Citizen, update yourself 🫵 Recently, a sample mir-pay.apk flew into our sandbox. At first glance, nothing unusual: just another variation of the well-known Mamo…
Dirty Frag 🐧💥 A week after the widely discussed Copy.Fail, researcher v4bel disclosed a new privilege escalation technique in the Linux kernel — Dirty Frag. As…
Shove your claims into... PT Sandbox! 🫵 At the end of January, we discovered a malicious campaign distributing the PureRat (PureHVNC) malware to Russian organiz…
Dissecting network traffic with ML in search of new malware 📖 🧪 We — the network expertise department team of the ESC antivirus laboratory and the machine learn…
A fresh batch of soup 🍜 Back in summer 2025, our foreign colleagues already wrote about the SoupDealer trojan — an attack tailored specifically to users in Turk…
PDQ-Masters 🧙♂️ The main attack vector using malware is phishing campaigns via email. The ideal phishing email with malware differs from a legitimate email onl…
A New Window in Dark Mode 🫣 During the monitoring of new network threats in the network expertise department, suspicious traffic was noticed that was generated…
And we have big news!😡 At PT ESC, the Antivirus Laboratory has opened: we have combined the expertise of "VIRUSBLOCKADA" with our own, analyzing numerous sample…
.NET Reactor: The Evolution of Protection from 6.7 to 7.0 and Methods for Removing Obfuscation 🔄 .NET Reactor is a powerful tool for protecting executables writ…
Do you automate debugging? 🧐 The PT Sandbox expert team often has to debug various Windows kernel components in their work, and a kernel debugger is indispensab…