// Threats

This is Siemens...

Recently, our colleagues from the Positive Industrial Expertise Center discovered a curious Windows sample on MalwareBazaar. Here is its SHA-256: e014dadf6d93b3…

global_author
// Threats

Anti-antivirus

Recently, we came across an APK with an intriguing and trust-inspiring name: «Антивирус ФСБ.apk». After installing it, we discovered that upon launch, the user…

global_author
// Threats

.exe .docm .xlsm

.exe .docm .xlsm Malicious files with these extensions are most often found in corporate network traffic. Let's take a basic look at why. 🖥 .exe — the classic e…

global_author
// Threats

Operation Chewbacca

At the end of June, the PT ESC team, during incident investigations, discovered a new group targeting at least oil and gas companies and the financial sector. D…

oUth0R
// Threats

Your Zimbra server is at risk

Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail servers using the vulnerability CVE-2026-73570 and the TargetZimbra en…

oUth0R
// Threats

Ding, ding — who's there?

Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center has discovered a new group that we have named DENOmina…

ti_author
// Threats

He's not your gsocket

He's not gsocket to you 😑 During the investigation of one of the incidents, PT ESC IR specialists came across a rather curious tool called hsocket (not to be co…

oUth0R