⚠️ Enabled Wi-Fi debugging — got Mamont
⚠️ Turned on Wi-Fi debugging — got Mamont In early May, a vulnerability CVE-2026-0073 was discovered on Android devices that allows remote execution of commands…
⚠️ Turned on Wi-Fi debugging — got Mamont In early May, a vulnerability CVE-2026-0073 was discovered on Android devices that allows remote execution of commands…
🫣 Hiding in plain sight: how PhantomCore masks its activity using legitimate tools The PT ESC IR team has presented a new study dedicated to the activities of t…
Lately, we are increasingly encountering devices that have received a compromise notification from Apple 📲 If you receive a message on your device in iMessage f…
consumerWiper: architecture and mechanism of operation. Part 2 ❗️ Conclusions Analysis of this malware demonstrates a rational approach by the attackers. Since…
consumerWiper: architecture and operating mechanism. Part 1 ☹️ During the investigation of one of the incidents, the PT ESC response team discovered the consume…
🤑 I'll help you donate Recently, we received a sample of a malicious app for research that is used to steal money from Android users (screenshot 1). In 2015, st…
Operation CyberPosi 🤔 The PT ESC IR team, together with the Threat Intelligence team, is observing a new campaign by the APT group PhantomCore, in which the att…
He may not, as unvalued persons do, Carve for himself (W. Shakespeare) When investigating an infrastructure that has been subjected to encryption, there is regu…
We would very much like to give you an overview of "tomato gose," but on Friday you voted for a new analysis of (Ex)Cobalt... 🙄 This is one of the most active a…
A New Connection to Old Techniques 📡 During incident investigations, the PT ESC IR team discovered a reverse shell developed in .NET and observed since 2023. It…
APT31. Striking Panda Attacks 🐼 From 2024 to 2025, Russian IT companies operating as contractors and solution integrators for government agencies faced a series…
In addition to the previous post we are looking at additional tools for decrypting network traffic. Let's look at an alternative to PolarProxy that is no…