// Threats

The diamond is barely visible

The diamond is barely visible 💎 During the analysis of PT ESC IR dumps, we periodically encounter new malware families that are not detected by known indicators…

oUth0R
// Threats

Friday newsletter

Friday Newsletter 🐽 Imagine: you're an employee of a Russian organization, and on Friday someone named Nadezhda Arturovna 😌 sends you an email (screenshot 1) as…

ti_author
// Threats

Ghostly Gist

Ghostly Gist 😏 In March, PT ESC cyber intelligence specialists recorded activity from the Rare Werewolf group (Rezet, Librarian Ghouls). This time, an archive d…

ti_author
// Threats

Again CFG

CFG again 👋 A common task when extracting malware configurations at scale is obtaining function boundaries and references. The most typical example is string de…

global_author