The PT ESC cyber intelligence group has presented an overview of cyberattacks for Q2 2025 ✍️

More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…
PT ESC cyber intelligence group presents a review of cyberattacks for Q2 2025 ✍️
The report examines the most notable attacks on the IT infrastructure of Russian government organizations and private companies.
🦉 During this period, activity from Team46, TA Tolik, Black Owl, and others was recorded.
📩 Phishing campaigns ran continuously, impersonating government agencies and regulators. The following techniques were used:
• Archives with malicious payloads, whose names and subjects matched the email content;
• Documents with embedded exploits targeting known vulnerabilities in office suites and EDM systems;
• Links to cloud storage and file-sharing services to bypass email filters.
In several cases, a “delayed delivery” model was employed, where the payload was deployed after establishing correspondence (spear-phishing + social engineering), along with imitation of business communication to pressure recipients into opening attachments.
💥 Key trends:
1. Destructive use of ransomware. Black Owl uses encryption and wiper techniques to maximally disrupt infrastructure operations.
2. Monetization through extortion. Werewolves and DarkGaboon deploy ransomware as part of ransom schemes, often following prior reconnaissance and data theft (double extortion).
3. Espionage with a focus on stealth. Cloud Atlas and PhantomCore aim for long-term presence, collecting internal documents and credentials; they use multi-stage loaders and living-off-the-land techniques to reduce visibility.
Full report — on our blog ⬅️
#TI #APT #Malware #Phishing
@ptescalator
More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…



