Rare fixation techniques. Part 2
Rare persistence techniques. Part 2 Also read about: Zabbix Agent, TimeProvider. 3️⃣ COM Hijacking For persistence in the infrastructure, the attackers used a r…
Rare persistence techniques. Part 2 Also read about: Zabbix Agent, TimeProvider. 3️⃣ COM Hijacking For persistence in the infrastructure, the attackers used a r…
Rare persistence techniques In the first six months of 2026, the PT ESC IR team recorded a number of rare persistence techniques on compromised hosts, which we…
The diamond is barely visible 💎 During the analysis of PT ESC IR dumps, we periodically encounter new malware families that are not detected by known indicators…
🫣 Hiding in plain sight: how PhantomCore masks its activity using legitimate tools The PT ESC IR team has presented a new study dedicated to the activities of t…
Time to update ⚠️ In early December we already reported how hackers infiltrate infrastructure through unpatched vulnerabilities in the TrueConf server that admi…
consumerWiper: architecture and mechanism of operation. Part 2 ❗️ Conclusions Analysis of this malware demonstrates a rational approach by the attackers. Since…
consumerWiper: architecture and operating mechanism. Part 1 ☹️ During the investigation of one of the incidents, the PT ESC response team discovered the consume…
Operation CyberPosi 🤔 The PT ESC IR team, together with the Threat Intelligence team, is observing a new campaign by the APT group PhantomCore, in which the att…
He may not, as unvalued persons do, Carve for himself (W. Shakespeare) When investigating an infrastructure that has been subjected to encryption, there is regu…
We would very much like to give you an overview of "tomato gose," but on Friday you voted for a new analysis of (Ex)Cobalt... 🙄 This is one of the most active a…
How the Hammer of Thunder Disrupted the Claws of Silence 🦀 During an incident investigation, the Incident Response team, with support from the Threat Intelligen…
A New Connection to Old Techniques 📡 During incident investigations, the PT ESC IR team discovered a reverse shell developed in .NET and observed since 2023. It…