The PT ESC cyber intelligence group has presented an overview of cyberattacks for the third quarter of 2025 ✍️

More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…
PT ESC Cyber Intelligence Group Presents Q3 2025 Cyberattack Overview ✍️
The report examines hacker attacks on the infrastructure of Russian organizations and typical group attack chains — from initial access to persistence.
🙅♂️ During the period, activity was noted from groups such as PseudoGamaredon, TA Tolik, XDSpy, PhantomCore, Rare Werewolf, Goffee, IAmTheKing, Telemancon, DarkWatchman, and Black Owl.
✉️ Phishing campaigns ran continuously, masquerading as business correspondence. The following were used:
• Password-protected archives containing LNK, SCR, and COM loaders along with decoy documents; fake CAPTCHA triggering PowerShell.
• RMM and remote access tools (UltraVNC, AnyDesk), REST-C2, and multi-stage loaders.
• Redirect logic: if the check is passed — the payload is downloaded; if not — the user is redirected to a legitimate service decoy page.
• Zero-day vulnerabilities: exploitation of CVE-2025-8088 by the Goffee group.
Full report — on our website.
#TI #APT #Malware #Phishing
@ptescalator
More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…



