Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group targeting at least oil and gas companies and the financial sector. D…
At the end of June, the PT ESC team, during incident investigations, discovered a new group targeting at least oil and gas companies and the financial sector. D…
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center has discovered a new group that we have named DENOmina…
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to add "Enterprise-grade" obfuscation We discovere…
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at Positive Technologies' Expert Security Center has discovered a camp…
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring, PT ESC specialists discovered a previously unknown APK file uploaded f…
⚡Fake news — B U L L S H I T PT ESC specialists discovered an interconnected network of news sites, email domains, and social media accounts that were used to s…
PT ESC Cyber Intelligence Group presented an overview of cyberattacks for Q2 2026 ✍️ The report analyzes the activity of hacker groups targeting Russian organiz…
PT ESC specialists have recorded signs of attackers carrying out an attack through the standard functionality of the ViPNet MFTP service. As of the publication…
CloudAtlas: a new wave of cyberattacks on organizations in Russia and Iraq using chains of legitimate web resources In May 2026, the Threat Intelligence departm…
Citizen, update yourself 🫵 Recently, a sample mir-pay.apk flew into our sandbox. At first glance, nothing unusual: just another variation of the well-known Mamo…
Our colleagues at Censys published a breakdown of the AsyncRAT family, describing an entire genealogical tree: AsyncRAT → DCRAT (DarkCrystal RAT) → VenomRAT → d…
Someone said sandbox? 👀 Once again we're watching threat actors conduct unethical research. Given: Security researcher Nicholas Curran He published packages wit…