Your Zimbra server is at risk
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail servers using the vulnerability CVE-2026-73570 and the TargetZimbra en…
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail servers using the vulnerability CVE-2026-73570 and the TargetZimbra en…
He's not gsocket to you 😑 During the investigation of one of the incidents, PT ESC IR specialists came across a rather curious tool called hsocket (not to be co…
We will croc you 👻 PhantomCore continues to actively exploit misconfigurations in 1C to attack Russian organizations. We previously wrote about attacks on 1C us…
Our colleagues at Censys published a breakdown of the AsyncRAT family, describing an entire genealogical tree: AsyncRAT → DCRAT (DarkCrystal RAT) → VenomRAT → d…
Using IoC in a Non-Standard Way. Part 2. Threat Landscape 🧘♀️ Earlier, we discussed how to use indicators of compromise for Threat Hunting. This time, we’ll ta…
Operation CyberPosi 🤔 The PT ESC IR team, together with the Threat Intelligence team, is observing a new campaign by the APT group PhantomCore, in which the att…
A New Connection to Old Techniques 📡 During incident investigations, the PT ESC IR team discovered a reverse shell developed in .NET and observed since 2023. It…
Using IoC in a non-standard way. Part 1. Threat hunting 🧐 When we talk about indicators of compromise, we usually mean a reactive approach to defense: a securit…
Idea for a SIEM correlation rule 💡 Although tracking the entire attack chain described in the posts above provides a complete picture, the strongest and simples…
Continuing to reproduce the attack from the post above 🔼 3️⃣ Creating a public API Gateway trigger (screenshot 1) At the end, we need to expose the function to…
☁️ AWS backdoor as a service: persistence in the cloud via Lambda The cloud threat landscape is constantly evolving, and attackers are increasingly abusing legi…
How to create rules for network traffic to address a future threat 🤨 This was discussed this week in China during the third cybersecurity summit, which included…