AI-95 with a malicious additive ⛽️
AI-95 with a malicious additive ⛽️ In mid-June, the Threat Intelligence team discovered several resources at once using a "fuel" theme for malicious purposes. 0…
AI-95 with a malicious additive ⛽️ In mid-June, the Threat Intelligence team discovered several resources at once using a "fuel" theme for malicious purposes. 0…
The diamond is barely visible 💎 During the analysis of PT ESC IR dumps, we periodically encounter new malware families that are not detected by known indicators…
PT ESC Cyber Intelligence Group presented an overview of cyberattacks for Q1 2026 ✍️ The report analyzes the activity of hacker groups targeting Russian organiz…
🫣 Hiding in plain sight: how PhantomCore masks its activity using legitimate tools The PT ESC IR team has presented a new study dedicated to the activities of t…
CHM snap-in, alarms, CIB of the Russian Ministry of Defense, and bitcoin eggs 🤖 At the end of December last year, the Threat Intelligence team of the Positive T…
Friday Newsletter 🐽 Imagine: you're an employee of a Russian organization, and on Friday someone named Nadezhda Arturovna 😌 sends you an email (screenshot 1) as…
Where does one group end and another begin? 🧩 In a new study, we examined a case that clearly demonstrates how the MaaS model complicates attack attribution. Th…
Ghostly Gist 😏 In March, PT ESC cyber intelligence specialists recorded activity from the Rare Werewolf group (Rezet, Librarian Ghouls). This time, an archive d…
CFG again 👋 A common task when extracting malware configurations at scale is obtaining function boundaries and references. The most typical example is string de…
Infect a state and earn 3 rubles 🪙 In late February and early March, specialists from the PT ESC threat research department identified attacks on various organi…
Keeping a finger on the Pulse: cyberattacks by the Mythic Likho group on Russia's critical information infrastructure 🔮 The Threat Intelligence Department of Po…
Breaching the office through Office 👨💻 The PT ESC cyber intelligence team has recorded the first phishing campaign exploiting CVE-2026-21509, targeting Russian…