APT ANALYSIS
1.77K subscribers
171 photos
2 videos
6 files
176 links
Анализ APT с фокусом на моделирование, обнаружение и управление сложными атаками. Предоставление точных данных и решений для прогнозирования угроз с реальным опытом в области безопасности.
Download Telegram
♣️The Bitter End: Unraveling Eight Years of Espionage Antics—Part One
🩸Blog : https://www.proofpoint.com/us/blog/threat-insight/bitter-end-unraveling-eight-years-espionage-antics-part-one
♣️DuplexSpy RAT: Stealthy Windows Malware Enabling Full Remote Control and Surveillance
🐍Blog : https://www.cyfirma.com/research/duplexspy-rat-stealthy-windows-malware-enabling-full-remote-control-and-surveillance/
♣️TTPs of Cyber Partisans activity aimed at espionage and disruption
😈Blog : https://ics-cert.kaspersky.com/publications/reports/2025/06/05/ttps-of-cyber-partisans-activity-aimed-at-espionage-and-disruption/
♣️Operation Phantom Enigma
👁Blog : https://global.ptsecurity.com/analytics/pt-esc-threat-intelligence/operation-phantom-enigma
♣️BladedFeline: Whispering in the dark
🐈‍⬛Blog : https://www.welivesecurity.com/en/eset-research/bladedfeline-whispering-dark
♣️A SoraAI clickbait
📺Blog : https://labs.k7computing.com/index.php/a-soraai-clickbait
♣️Operation DRAGONCLONE: Chinese Telecommunication industry targeted via VELETRIX & VShell malware.
🚬Blog : https://www.seqrite.com/blog/operation-dragonclone-chinese-telecom-veletrix-vshell-malware
♣️Blitz Malware: A Tale of Game Cheats and Code Repositories
🔪Blog : https://unit42.paloaltonetworks.com/blitz-malware-2025
⭐️@APTANALYSIS
Please open Telegram to view this post
VIEW IN TELEGRAM
CyberCX___WP_Engine_Report.pdf
2.1 MB
♣️DarkEngine: CyberCX Uncovers Highly Orchestrated WordPress Phishing Campaign
⭐️@APTANALYSIS
Please open Telegram to view this post
VIEW IN TELEGRAM
♣️CVE-2025-33053, Stealth Falcon and Horus: A Saga of Middle Eastern Cyber Espionage
🎩Blog : https://research.checkpoint.com/2025/stealth-falcon-zero-day
⭐️@APTANALYSIS
Please open Telegram to view this post
VIEW IN TELEGRAM
♣️FortMajeure: Authentication Bypass in FortiWeb (CVE-2025-52970)
😈Blog : https://pwner.gg/blog/2025-08-13-fortiweb-cve-2025-52970
⭐️@APTANALYSIS
Please open Telegram to view this post
VIEW IN TELEGRAM
♣️CVE-2025-50154 : Zero Click, One NTLM: Microsoft Security Patch Bypass
🐱Blog : https://cymulate.com/blog/zero-click-one-ntlm-microsoft-security-patch-bypass-cve-2025-50154/
⭐️@APTANALYSIS
Please open Telegram to view this post
VIEW IN TELEGRAM
♣️Turning Camera Surveillance on its Axis
🌟Blog : https://claroty.com/team82/research/turning-camera-surveillance-on-its-axis
⭐️@APTANALYSIS
Please open Telegram to view this post
VIEW IN TELEGRAM
♣️AlphabeticalPolyShellGen: Generate an Alphabetical Polymorphic Shellcode
😈Repo : https://github.com/Maldev-Academy/AlphabeticalPolyShellGen
⭐️@APTANALYSIS
Please open Telegram to view this post
VIEW IN TELEGRAM
APT-C-36 (Blind Eagle) group escalates its tactics in new attack campaigns

[1]https://mp.weixin.qq.com/s/wLDUwr3WVuO37eAOrXs8ag

[2]https://mp.weixin.qq.com/s/DDCCjhBjUTa7Ia4Hggsa1A

⭐️@APTANALYSIS
CVE-2025–32713: Windows Common Log File System Driver Local Privilege Escalation Vulnerability
https://hackyboiz.github.io/2025/08/13/ogu123/cve-2025%E2%80%9332713/
⭐️@APTANALYSIS
Please open Telegram to view this post
VIEW IN TELEGRAM
Netexec Workshop Active Directory Lab Writeup
Blog: https://blog.anh4ckin.ch/posts/netexec-workshop2k25/
⭐️@APTANALYSIS
CrossC2 framework
generate CobaltStrike's cross-platform payload:
https://github.com/gloxec/CrossC2.git

Hackers Found Using CrossC2 to Expand Cobalt Strike Beacon's Reach to Linux and macOS
https://thehackernews.com/2025/08/researchers-warn-crossc2-expands-cobalt.html?m=1
⭐️@APTANALYSIS
Please open Telegram to view this post
VIEW IN TELEGRAM
♣️Salty 2FA: Undetected PhaaS from Storm-1575 Hitting US and EU Industries
👁‍🗨Blog : https://any.run/cybersecurity-blog/salty2fa-technical-analysis/
♣️Crypto24 Ransomware Group Blends Legitimate Tools with Custom Malware for Stealth Attacks
👁‍🗨Blog : https://www.trendmicro.com/en_no/research/25/h/crypto24-ransomware-stealth-attacks.html
⭐️@APTANALYSIS
Please open Telegram to view this post
VIEW IN TELEGRAM
Bring your own vulnerable driver’ attack technique is becoming popular among threat actors
https://cybernews.com/security/bring-your-own-vulnerable-driver-attack/

To practice Bring Your Own Vulnerable Driver (BYOVD) techniques from the CETP course, I set out to develop a toolkit leveraging a kernel-level read/write primitive to bypass security mechanisms such as LSASS’s RunasPPL protection and to enumerate and remove EDR telemetry via kernel callback manipulation. For the vulnerable driver, I used the well-known RTCore64.sys from MSI Afterburner.


⭐️@APTANALYSIS