New connection to old techniques
A New Connection to Old Techniques 📡 During incident investigations, the PT ESC IR team discovered a reverse shell developed in .NET and observed since 2023. It…
A New Connection to Old Techniques 📡 During incident investigations, the PT ESC IR team discovered a reverse shell developed in .NET and observed since 2023. It…
Using IoC in a non-standard way. Part 1. Threat hunting 🧐 When we talk about indicators of compromise, we usually mean a reactive approach to defense: a securit…
OldGremlin with old tricks OldGremlin is known as a ransomware group 😭. To stop antiviruses (and any programs, for that matter) from running, it loads TinyKille…
Jade Metal: the not-so-new Telemanmilconfav group attacks military organizations? 🪖 In March, researchers from F6 published a report on the Telemancon group, wh…
IoCs-detox: protecting TI from false indicators ✋ Imagine this: your SOC team receives a fresh feed of compromise indicators. The list contains hundreds of new…
No Longer Rezet, or New Rare Wolf Attacks 🐺 The PT ESC cyber intelligence group continues to record attacks by the Rare Wolf group: for example, in late May, th…
PT ESC cyber intelligence team has prepared a report on the results of the first quarter of 2025 ✍️ It compiles the most notable attacks by hacker groups on the…
(Ex)Cobalt == (Ex)Carbanak 🤔 Since the beginning of 2025, the PT ESC team has observed a rise in the number of attacks using the SshDoor backdoor. Russian gover…
⚠️ PT ESC experts have detected attempts to exploit the CVE-2025-24071 vulnerability The vulnerability CVE-2025-24071, affecting a wide range of Windows operati…
Radio enthusiasts, get ready 📻 The internal systems of the cyber intelligence group have discovered a hack of a website for radio enthusiasts. The site has exis…
"Attaching the data in the attachment" 💌 Today we have as our guest a small, but no less interesting and experimental reverse shell for Linux. Although it's har…
(Ex)Cobalt in a Container 🛂 During the response to a computer incident, the PT ESC IR team established the fact that attackers had gained a foothold in Docker c…