// Threats

(Ex)Cobalt in container

(Ex)Cobalt in a Container 🛂 During the response to a computer incident, the PT ESC IR team established the fact that attackers had gained a foothold in Docker c…

oUth0R
// Threats

Viper style

Viper Style 🐍 Can an attacker use well-known tools and remain undetected for over a year and a half? Our answer is yes. In mid-October 2024, the cyber intellige…

ti_author
// Threats

One lazy driver

🚘 One lazy driver Recently, the PT ESC cyber intelligence group discovered an executable file with an "unusual" name, reinforced by a distinctive PDF file icon…

ti_author
// Threats

Another Python stealer?!

Another stealer in Python?! 🫣 Since the beginning of September, we have been tracking attacks that at first glance could be attributed to the activity of the La…

ti_author
// Threats

What is wrong with this AES?

What exactly is wrong with this AES? ❔ Attackers often use encryption to obfuscate parts of malware samples that may be of greatest interest during research. Wh…

ti_author