[ << ALL_FEED ]

The PT ESC cyber intelligence group has presented an overview of cyberattacks for the third quarter of 2025 ✍️

More in General

PT ESC Cyber Intelligence Group Presents Q3 2025 Cyberattack Overview ✍️

The report examines hacker attacks on the infrastructure of Russian organizations and typical group attack chains — from initial access to persistence.

🙅‍♂️ During the period, activity was noted from groups such as PseudoGamaredon, TA Tolik, XDSpy, PhantomCore, Rare Werewolf, Goffee, IAmTheKing, Telemancon, DarkWatchman, and Black Owl.

✉️ Phishing campaigns ran continuously, masquerading as business correspondence. The following were used:

• Password-protected archives containing LNK, SCR, and COM loaders along with decoy documents; fake CAPTCHA triggering PowerShell.

• RMM and remote access tools (UltraVNC, AnyDesk), REST-C2, and multi-stage loaders.

• Redirect logic: if the check is passed — the payload is downloaded; if not — the user is redirected to a legitimate service decoy page.

• Zero-day vulnerabilities: exploitation of CVE-2025-8088 by the Goffee group.

Full report — on our website.

#TI #APT #Malware #Phishing
@ptescalator

More from ti_author

More from ti_author

More in General