Deep dive into imports: continuing to explore static resolution methods
Deep Dive into Imports: Continuing to Explore Static Resolution Techniques 🕵️♂️ Earlier we discussed how static import resolution can be implemented. However…
Deep Dive into Imports: Continuing to Explore Static Resolution Techniques 🕵️♂️ Earlier we discussed how static import resolution can be implemented. However…
Jade Metal: the not-so-new Telemanmilconfav group attacks military organizations? 🪖 In March, researchers from F6 published a report on the Telemancon group, wh…
In addition to the previous post, we want to talk about some other potential ways of detecting the execution of malicious code in the "1C" system 😳 • First, if…
Following the 1C_Shell trail. Investigating attacks using the event log 🐾 In one of our previous posts, we wrote about detecting attacks on the 1C system in whi…
Exchange Mutation. How We Caught Anomalies in Outlook Pages 😮 Continuing our series of incident investigation stories (you can read about them here, here, and p…
DarkGaboon. The venom of a cyber viper in the digital veins of Russian companies 🐍 In January of this year, the cyber intelligence group of the TI department at…
No Longer Rezet, or New Rare Wolf Attacks 🐺 The PT ESC cyber intelligence group continues to record attacks by the Rare Wolf group: for example, in late May, th…
One on One with Rust ☹️ Recently, the complex threat research group of Positive Technologies' TI department has been increasingly encountering malware written i…
We will protect your money… Just give it to us 😏 At the beginning of the year, specialists from the cyber intelligence group of the TI department at the Positiv…
🛡 Puma: how a rootkit provides covert SSH access through stealthy key substitution Continuing our story about the activities of the ExCobalt group and its new t…
Yara-Yara-Yara! 🐧 Now that we've sorted out strings, we can move on to generating byte signatures. Usually people try to make them as rarely as possible, since…
Yara Yara Daze Anyone involved in malware analysis is certainly familiar with a tool like YARA 😉. With its help, many companies 🔴 build sets of signature rules…