Cloud services from the operator "MeHaFon"
📲 Cloud services from the "MeHaFon" operator News from the field: the PT ESC team is observing a new campaign by the Cloud Atlas group targeting government orga…
📲 Cloud services from the "MeHaFon" operator News from the field: the PT ESC team is observing a new campaign by the Cloud Atlas group targeting government orga…
Stealer infection: a new USB strain 👾 Today we're going to talk about an unusual modification of the WorldWind stealer that we discovered. It is a real, bona fi…
Ngrok. Finding and understanding it 🔍 In the process of investigating numerous incidents, we repeatedly encounter a tool such as ngrok. It is a convenient legit…
SSH-IT. Guide to detecting a popular tool 🔭 In the course of investigating numerous incidents involving the compromise of Linux nodes, we sometimes discover var…
⚠️ OWOWAsome module, or IIS kOWOWAren Researchers reported on the malicious IIS module Owowa, designed to intercept user credentials, back in 2021. And in 2022…
Gapucino* — is GOFFEE ☕️ Today we are covering one of the most active campaigns currently underway in Russia. Other researchers call it GOFFEE. As the initial v…
🤔 Remember, in a couple of previous posts we described simple and slightly more complex approaches to detecting malware using the example of an email that lande…
A word about the obfuscated batch file... We're publishing this post as a follow-up to the recent one about the EXE hidden under a hex dump in a Base64 request…
📫 X-Filtering of User Data In the process of analyzing email traffic, we periodically encounter the implementation of unusual malicious techniques. Today we wan…
Slam screen locker. What are you? ☹️ Next up is fast malware analysis, conducted on one Sunday evening. An interesting sample flew into our networks, generating…
How to get to the internet 🚶♂️ What do hackers do when the network segment they're interested in has no internet access, but they really want to connect to C2?…
Gsocket: how to find one of the most popular tools 🙂 In the course of investigating numerous incidents involving the compromise of Linux nodes, we often discove…