Malware in open source!
Mmaallwwaarree iinn ooppeennssoouurrccee! A notable campaign by a single researcher is unfolding online. The following packages belong to him: User lastbright…
Mmaallwwaarree iinn ooppeennssoouurrccee! A notable campaign by a single researcher is unfolding online. The following packages belong to him: User lastbright…
😆Spy is back in action A cyber intelligence team has recorded a new campaign by the hacker group XDSpy aimed at compromising the IT infrastructure of government…
What is the steganographic mafia hiding from us? 👤 In November 2024, we told you about the PhaseShifters group and also mentioned the subscription-based crypter…
Are you using cryptography correctly? 🔓 The Advanced Threat Research Group of the Threat Intelligence department often has to solve interesting tasks in the pro…
Desert Dexter — a group targeting residents of Arab states👽 Specialists from the cyber intelligence group of the PT ESC TI department have discovered a maliciou…
Evolution of Dark Caracal Tools 🐱 In the first quarter of 2024, a malicious sample came to the attention of the Threat Intelligence department at the Positive T…
Radio enthusiasts, get ready 📻 The internal systems of the cyber intelligence group have discovered a hack of a website for radio enthusiasts. The site has exis…
C2 hunting: part 2. Hunting for hacker servers by external signs 😁 In the previous part, we talked about how to expand knowledge about hackers' infrastructure u…
Move like water. Be still like a mirror. Respond like an echo... 🪞 In this post, we will discuss a discovered instance of a phishing page. It is notable for emp…
"Attaching the data in the attachment" 💌 Today we have as our guest a small, but no less interesting and experimental reverse shell for Linux. Although it's har…
Attacker published malicious packages deepseeek and deepseekai on the Python Package Index 🐳 The Supply Chain Security team of the Threat Intelligence departmen…
Rare Wolf is preparing to hunt 🐺 The PT ESC cyberthreat intelligence team consistently tracks down new command-and-control servers used by threat groups, as wel…