Curing a problem
Curing a problem 🔧 Recently, researchers from ARMO presented a paper and PoC for the Curing malware, which uses the io_uring interface to bypass monitoring of f…
Curing a problem 🔧 Recently, researchers from ARMO presented a paper and PoC for the Curing malware, which uses the io_uring interface to bypass monitoring of f…
⚠️ PT ESC experts have detected attempts to exploit the CVE-2025-24071 vulnerability The vulnerability CVE-2025-24071, affecting a wide range of Windows operati…
Graphics with a Surprise: When Vectors Hide Malicious Code 🤨 In this post, we will examine an example of a phishing email in which malicious content was deliver…
A fool and his money are soon parted, APK is not a video 🦣 In late 2024 — early 2025, information about the spread of the Mamont virus in Telegram was actively…
📲 Cloud services from the "MeHaFon" operator News from the field: the PT ESC team is observing a new campaign by the Cloud Atlas group targeting government orga…
APT-C-60, aka DarkHotel 💿 We once talked about the use of VHDX files in attacks and why it is convenient (no, this is not a call to action). You can find that p…
🟥 ⚔️ 💿 Virtual Disk as the Start of an Attack In early September, experts from the TI cyberintelligence group of the PT ESC department discovered an interesting…
We, ESC-VR, have successfully reproduced the exploit for CVE-2024-30085 😎 The vulnerability was featured at the recent Pwn2Own 2024 in Vancouver, where Team The…
!!р^д**н**c 🤔 A characteristic example of how threat actors use current events to distribute malicious programs is a malicious document we discovered. It contai…