This is Siemens...
Recently, our colleagues from the Positive Industrial Expertise Center discovered a curious Windows sample on MalwareBazaar. Here is its SHA-256: e014dadf6d93b3…
Recently, our colleagues from the Positive Industrial Expertise Center discovered a curious Windows sample on MalwareBazaar. Here is its SHA-256: e014dadf6d93b3…
At the end of June, the PT ESC team, during incident investigations, discovered a new group targeting at least oil and gas companies and the financial sector. D…
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail servers using the vulnerability CVE-2026-73570 and the TargetZimbra en…
He's not gsocket to you 😑 During the investigation of one of the incidents, PT ESC IR specialists came across a rather curious tool called hsocket (not to be co…
AI-95 with a malicious additive ⛽️ In mid-June, the Threat Intelligence team discovered several resources at once using a "fuel" theme for malicious purposes. 0…
Breaching the office through Office 👨💻 The PT ESC cyber intelligence team has recorded the first phishing campaign exploiting CVE-2026-21509, targeting Russian…
Shove your claims into... PT Sandbox! 🫵 At the end of January, we discovered a malicious campaign distributing the PureRat (PureHVNC) malware to Russian organiz…
A fresh batch of soup 🍜 Back in summer 2025, our foreign colleagues already wrote about the SoupDealer trojan — an attack tailored specifically to users in Turk…
Work order for malware operation ✍️ In mid-January, the cyber intelligence group recorded a campaign by the hacker group XDSpy targeting organizations in Russia…
consumerWiper: architecture and mechanism of operation. Part 2 ❗️ Conclusions Analysis of this malware demonstrates a rational approach by the attackers. Since…
Using IoC in a Non-Standard Way. Part 2. Threat Landscape 🧘♀️ Earlier, we discussed how to use indicators of compromise for Threat Hunting. This time, we’ll ta…
Operation CyberPosi 🤔 The PT ESC IR team, together with the Threat Intelligence team, is observing a new campaign by the APT group PhantomCore, in which the att…