APT-C-60, or DarkHotel
APT-C-60, aka DarkHotel 💿 We once talked about the use of VHDX files in attacks and why it is convenient (no, this is not a call to action). You can find that p…
APT-C-60, aka DarkHotel 💿 We once talked about the use of VHDX files in attacks and why it is convenient (no, this is not a call to action). You can find that p…
Come again, I can't see it well 😳 Recently, the PT ESC cyber intelligence team discovered an example of a multi-stage phishing attack in which the attackers fir…
Learning to Recover VMProtect Imports ⚙️ VMProtect is one of the most widely used malware protectors. At the same time, attackers are often lazy and use only si…
😲 Who the heck are these PhaseShifters of yours? In early June 2024, specialists from the Threat Intelligence department identified a new PhaseShifters attack c…
Gapucino* — is GOFFEE ☕️ Today we are covering one of the most active campaigns currently underway in Russia. Other researchers call it GOFFEE. As the initial v…
Catching bug hunters again 💀 In one of our previous posts we wrote about traces of bug bounty activity targeting "Yandex". History repeated itself, but this tim…
🛠 Reverse Engineering Delphi without IDR When you're actively involved in reverse engineering, sooner or later you encounter an executable file written in Delph…
🟥 ⚔️ 💿 Virtual Disk as the Start of an Attack In early September, experts from the TI cyberintelligence group of the PT ESC department discovered an interesting…
Colonels write first! (🔞) The collection of malicious mass mailings sent in the name of law enforcement agencies has a new addition. In September, several recip…
Phishing Legitimacy 😂 During an analysis of one phishing email, we noticed how attackers attempted to place phishing content on a page of the telegra․ph domain…
СHavocают Recently, a phishing email fell into our hands. The email subject is in the best traditions of phone spam calls, when someone calls you from the FSB a…
🗂 Useful Data Sources: MISP Warning Lists Information security analysts deal with massive volumes of threat data on a daily basis. To extract the most relevant…