The Solana blockchain at the service of hackers
Solana blockchain at the service of hackers🪙 In January, specialists from the cyber intelligence group of the Threat Intelligence department at the PT Expert Se…
Solana blockchain at the service of hackers🪙 In January, specialists from the cyber intelligence group of the Threat Intelligence department at the PT Expert Se…
UnsolicitedBooker: this uninvited boxer with 1 report will go down 🥊 In the fall of 2025, the Threat Intelligence team of the Positive Technologies cybersecurit…
Shove your claims into... PT Sandbox! 🫵 At the end of January, we discovered a malicious campaign distributing the PureRat (PureHVNC) malware to Russian organiz…
PT ESC cyber intelligence group presents an overview of cyberattacks for Q4 2025 ✍️ The report analyzes the activity of hacker groups targeting Russian organiza…
PDQ-Masters 🧙♂️ The main attack vector using malware is phishing campaigns via email. The ideal phishing email with malware differs from a legitimate email onl…
consumerWiper: architecture and mechanism of operation. Part 2 ❗️ Conclusions Analysis of this malware demonstrates a rational approach by the attackers. Since…
consumerWiper: architecture and operating mechanism. Part 1 ☹️ During the investigation of one of the incidents, the PT ESC response team discovered the consume…
Hush, hush: a new campaign against CIS countries 🤫 In the second half of 2025, we discovered a new series of attacks by the SweetSpecter group targeting CIS cou…
In addition to the post 👆 Disabling Defender / MpPreference Set-MpPreference -DisableRealtimeMonitoring $true Set-MpPreference -DisableBehaviorMonitoring $true…
Using DefendNot in XWorm Attacks 🪱 A cyber intelligence group has recorded phishing activity aimed at data theft followed by monetary extortion (screenshot 1)…
We would very much like to give you an overview of "tomato gose," but on Friday you voted for a new analysis of (Ex)Cobalt... 🙄 This is one of the most active a…
Deobfuscating .NET function names manually 🙌 .NET malware loves packers, obfuscation (of names, CFG, and other things), and multi-stage reflective image loading…