[ << ALL_FEED ]

The PT ESC cyber intelligence team has prepared a report on the results of the first quarter of 2025.

More in General

PT ESC cyber intelligence team has prepared a report on the results of the first quarter of 2025 ✍️

It compiles the most notable attacks by hacker groups on the infrastructure of Russian government organizations and private companies.

🐍 Activity was observed from groups such as PseudoGamaredon, Cloud Atlas, DarkGaboon, and others. The main objectives are data theft and gaining access to internal systems for espionage.

📩 Throughout the quarter, phishing campaigns were detected impersonating various government agencies. The mailings included both archives containing malware, whose names mimicked the email subject, and documents with exploits for known vulnerabilities.

📑 Alongside this, attackers also distributed files that appeared harmless at first glance, such as fake inspection orders styled in an official manner but containing no malicious payload. This allowed the emails to successfully pass antivirus checks, after which social engineering tactics were employed — the attackers attempted to establish a dialogue and gain access to the company’s internal network.

😏 You can view the report on the Positive Technologies website.

#TI #APT #malware #ioc
@ptescalator

More from ti_author

More from ti_author

More in General