(Ex)Cobalt == (Ex)Carbanak
(Ex)Cobalt == (Ex)Carbanak 🤔 Since the beginning of 2025, the PT ESC team has observed a rise in the number of attacks using the SshDoor backdoor. Russian gover…
(Ex)Cobalt == (Ex)Carbanak 🤔 Since the beginning of 2025, the PT ESC team has observed a rise in the number of attacks using the SshDoor backdoor. Russian gover…
A complex password won't help 📮 The practice of the PT ESC IR information security incident response team shows that attackers, upon gaining access to companies…
😐 “Why aren't you answering?”, or The Story of How to Steal a Telegram Account Without Registration or SMS Recently we published an article about the most popul…
1C_shell for "1C" 🦞 Sometimes situations arise when, during an information security incident investigation, the traditionally used OS artifacts contain extremel…
Net group "babyk" /add During the investigation of one of the incidents, we discovered the exploitation of the CVE-2024-37085 vulnerability. It allows…
Don't throw away your old iPhone until you read this post (and after, too) 🚮 Recently, our expert Vitaly, who investigates incidents involving mobile devices, r…
Mount point. Pt 2 Hello! We decided to talk about disk mounting again. Today we'll tell you how to work with LVM containers. Here's a short manual so you don't…
😏 You can't just simply extract information from a mobile phone A mobile phone is a portable computer, but in most cases, extracting the data needed for an inve…
Mount Point — pt.1 🙂 Any investigation is an analysis of operating system artifacts. And to obtain them, you often have to work with virtual machine images, suc…
Ngrok. Finding and understanding it 🔍 In the process of investigating numerous incidents, we repeatedly encounter a tool such as ngrok. It is a convenient legit…
SSH-IT. Guide to detecting a popular tool 🔭 In the course of investigating numerous incidents involving the compromise of Linux nodes, we sometimes discover var…
⚠️ OWOWAsome module, or IIS kOWOWAren Researchers reported on the malicious IIS module Owowa, designed to intercept user credentials, back in 2021. And in 2022…