The Return of the Blood Wolf
The Return of the Bloody Wolf 🐺 Since early May, the PT ESC cyber intelligence team has discovered a new wave of attacks by the Bloody Wolf group against organi…
The Return of the Bloody Wolf 🐺 Since early May, the PT ESC cyber intelligence team has discovered a new wave of attacks by the Bloody Wolf group against organi…
HTML attachments as a phishing tool 🤑 Delivery of HTML-like email attachments containing various techniques for opening third-party web content, interacting wit…
No Longer Rezet, or New Rare Wolf Attacks 🐺 The PT ESC cyber intelligence group continues to record attacks by the Rare Wolf group: for example, in late May, th…
We will protect your money… Just give it to us 😏 At the beginning of the year, specialists from the cyber intelligence group of the TI department at the Positiv…
New PhaseShifters campaign 👽 Throughout May, the PT ESC cyberthreat intelligence team has been tracking a wave of activity by the PhaseShifters hacking group, w…
Big Browser is watching you 👹 The cyber intelligence group has recorded a new campaign using an updated stealer Unicorn, which began in mid-February and continu…
😆Spy is back in action A cyber intelligence team has recorded a new campaign by the hacker group XDSpy aimed at compromising the IT infrastructure of government…
Graphics with a Surprise: When Vectors Hide Malicious Code 🤨 In this post, we will examine an example of a phishing email in which malicious content was deliver…
Move like water. Be still like a mirror. Respond like an echo... 🪞 In this post, we will discuss a discovered instance of a phishing page. It is notable for emp…
How long has it been since you reversed JavaScript? 😲 Continuing the phishing theme (we previously looked at targeted suspicious documents leading to initial ac…
Your hash, please… Thank you! 🙏 In early January, we discovered a file that drew attention for its content and structure. An examination of the document's metad…
Lok'tar ogar! 👺 In today's world, attacks aimed at gaining initial access have become more sophisticated. Threat actors use multi-stage payloads, which allows t…