Gapucino* is GOFFEE
Gapucino* — is GOFFEE ☕️ Today we are covering one of the most active campaigns currently underway in Russia. Other researchers call it GOFFEE. As the initial v…
Gapucino* — is GOFFEE ☕️ Today we are covering one of the most active campaigns currently underway in Russia. Other researchers call it GOFFEE. As the initial v…
How to get to the internet 🚶♂️ What do hackers do when the network segment they're interested in has no internet access, but they really want to connect to C2?…
Gsocket: how to find one of the most popular tools 🙂 In the course of investigating numerous incidents involving the compromise of Linux nodes, we often discove…
Proxying WebSocket nginx — payload detection 👀 Checking configurations of various services sometimes helps find unknown malware that is not detected by antiviru…
😈 Exfiltration Gone Wrong When investigating incidents, we periodically encounter threat actors exfiltrating data before encrypting infrastructure. One of the e…
Where to look for network indicators of compromise on Windows? For example, in the DNS cache 💡 The DNS cache is a mechanism for caching records that map domain…
☝️ In addition to Windows logs, another interesting artifact provided by a popular antivirus protection tool helped us in investigating the activity described i…
ℹ️ Exfiltration using PowerShell/C# During an incident investigation, while analyzing Windows event logs on one of the compromised hosts, we discovered that a P…
Exfiltration on an industrial scale 😐 The APT group Cloud Atlas has been attacking Russian companies since 2019, engaging in espionage and theft of confidential…
🫡 Hellhounds remains one of the most advanced groups attacking companies in Russia We have already covered Hellhounds' activity in the articles "Operation Lahat…
In early 2024, our team identified the use of the Cobint malware in customers' infrastructures 🥷 This malware is actively used by the (Ex)Cobalt group in attack…
Do you see the authorization form? No. Neither do I. But it's there 🤔 During a recent investigation of one of the incidents, we encountered exploitation by atta…