// Threats

Long, strange, but working

Long, weird, but it works 🍊🍊🍊🍊🍊🍊🍊🍊🍊🍊🍊 Not everything we investigate turns out to be complex attacks by serious groups. Sometimes attacks only appear complex. We…

ti_author
// Threats

APT31 grouping tool. CloudyLoader

APT31 Grouping Tool. CloudyLoader 🌩 In one of the incidents, the PT ESC IR team encountered an interesting malicious file that loads a payload in several stages…

oUth0R
// Threats

Operation Tartaria — VTDoor

Operation Tartaria — VTDoor 🚪 We have already covered Operation Tartaria in several posts — part 1 and part 2. In one of the cases, the PT ESC IR team discovere…

oUth0R
// Threats

Divination by Goffee grounds

Fortune Telling on Goffee Grounds: Current Tools and Grouping Features of Goffee in Attacks on Russia ☕️ Throughout 2024-2025, experts from the TI department ha…

oUth0R
// Threats

Operation Tartaria Part 2

Operation Tartaria Part 2 In addition to the passive backdoor PlugX, we managed to discover another version of it that mimicked the launch of Yandex Browser. {&…

oUth0R