C2 hunting: part 1
C2 hunting: part 1. Expanding visibility of hackers' network infrastructure 😜 Often when investigating an attack, performing TI analysis, or DFIR, a specialist…
C2 hunting: part 1. Expanding visibility of hackers' network infrastructure 😜 Often when investigating an attack, performing TI analysis, or DFIR, a specialist…
Team46 Attacks 😎 Yesterday, September 4, researchers from Doctor Web released an interesting report about a failed attack on a Russian freight rail operator. We…
Open source passions: part two Infostealers 🧋 No one is surprised by them anymore, since this is a popular class of malware, often mentioned in the news. Most t…
Open Source Drama: Mafia, Stealers, and Bug Hunting of Yandex Projects 🐱 Over the past two weeks, a lot of interesting things have happened in the Python Packag…
By the way, about Offzone 🙂 We promised to publish the latest version of the presentation from the talk about ExCobalt's maneuvers in the channel — here it is 🤝…
!!р^д**н**c 🤔 A characteristic example of how threat actors use current events to distribute malicious programs is a malicious document we discovered. It contai…
⛩ Attackers are looking for new ways to "open the gates" We recently discovered an unusual attack scheme. The attackers first establish contact with the victim…
🤨 Adding bookmarks to open-source repositories? Young man, come with us. As part of threat intelligence, in addition to researching "traditional" malware, we al…
DPAPI — a popular vector for attacks on Windows-family OS 💻 Wi-Fi keys, certificates, credentials, browser cookies, DropBox, Skype — and that's only part of the…
📬 How attackers are changing their approach to writing phishing emails Recently, we came across an email with a malicious attachment sent by the group Hive0117…
✈️ In our last post, we explained that Telegram is becoming more popular among hackers in the C2 as a service paradigm Exfiltration of victim data to attackers'…
👏 One-two — and done. Generating FLIRT signatures And we do this to avoid wasting time on recognizing the library code of PureBasic, in which the COM-DLL-Droppe…