APT ANALYSIS
1.76K subscribers
171 photos
2 videos
6 files
176 links
Анализ APT с фокусом на моделирование, обнаружение и управление сложными атаками. Предоставление точных данных и решений для прогнозирования угроз с реальным опытом в области безопасности.
https://t.me/addlist/7MAZa-vnZclhYzAx
Download Telegram
Please open Telegram to view this post
VIEW IN TELEGRAM
♣️Salty 2FA: Undetected PhaaS from Storm-1575 Hitting US and EU Industries
👁‍🗨Blog : https://any.run/cybersecurity-blog/salty2fa-technical-analysis/
♣️Crypto24 Ransomware Group Blends Legitimate Tools with Custom Malware for Stealth Attacks
👁‍🗨Blog : https://www.trendmicro.com/en_no/research/25/h/crypto24-ransomware-stealth-attacks.html
⭐️@APTANALYSIS
Please open Telegram to view this post
VIEW IN TELEGRAM
Bring your own vulnerable driver’ attack technique is becoming popular among threat actors
https://cybernews.com/security/bring-your-own-vulnerable-driver-attack/

To practice Bring Your Own Vulnerable Driver (BYOVD) techniques from the CETP course, I set out to develop a toolkit leveraging a kernel-level read/write primitive to bypass security mechanisms such as LSASS’s RunasPPL protection and to enumerate and remove EDR telemetry via kernel callback manipulation. For the vulnerable driver, I used the well-known RTCore64.sys from MSI Afterburner.


⭐️@APTANALYSIS
♣️Warlock: From SharePoint Vulnerability Exploit to Enterprise Ransomware
🌟Blog : https://www.trendmicro.com/en_us/research/25/h/warlock-ransomware.html
♣️Investigation Report: APT36 Malware Campaign Using Desktop Entry Files and Google Drive Payload Delivery
🌟Blog : https://www.cloudsek.com/blog/investigation-report-apt36-malware-campaign-using-desktop-entry-files-and-google-drive-payload-delivery
♣️APT MuddyWater Deploys Multi-Stage Phishing to Target CFOs
🌟Blog : https://hunt.io/blog/apt-muddywater-deploys-multi-stage-phishing-to-target-cfos
♣️Phantom Pains: A Massive Cyber Espionage Campaign and Possible Split of the PhantomCore APT Group
🌟Blog : https://www.ptsecurity.com/ru-ru/research/pt-esc-threat-intelligence/phantom-pains-a-large-scale-cyber-espionage-campaign-and-a-possible-split-of-the-apt-group-phantomcore/#id1
♣️Think before you Click(Fix): Analyzing the ClickFix social engineering technique
🌟Blog : https://www.microsoft.com/en-us/security/blog/2025/08/21/think-before-you-clickfix-analyzing-the-clickfix-social-engineering-technique/
♣️A Cereal Offender: Analyzing the CORNFLAKE.V3 Backdoor
🌟Blog : https://cloud.google.com/blog/topics/threat-intelligence/analyzing-cornflake-v3-backdoor/
♣️Examining the tactics of BQTLOCK Ransomware & its variants
🌟Blog : https://labs.k7computing.com/index.php/examining-the-tactics-of-bqtlock-ransomware-its-variants/
⭐️@APTANALYSIS
Please open Telegram to view this post
VIEW IN TELEGRAM
♣️Operating Outside the Box: NTLM Relaying Low-Privilege HTTP Auth to LDAP
Blog : https://specterops.io/blog/2025/08/22/operating-outside-the-box-ntlm-relaying-low-privilege-http-auth-to-ldap
⭐️@APTANALYSIS
Please open Telegram to view this post
VIEW IN TELEGRAM
Machine Account Takeover with LsaStorePrivateData()
Blog: https://pentest.party/posts/2025/ksetup-machine-password/
⭐️@APTANALYSIS
AppSuite PDF Editor Backdoor: A Detailed Technical Analysis
Blog: https://www.gdatasoftware.com/blog/2025/08/38257-appsuite-pdf-editor-backdoor-analysis
⭐️@APTANALYSIS
The One-Man APT, Part I: A Picture That Can Execute Code on the Target
Blog:https://hackers-arise.com/the-one-man-apt-part-i-a-picture-that-can-execute-code-on-the-target/
⭐️@APTANALYSIS
♣️Blurring the Lines: Intrusion Shows Connection With Three Major Ransomware Gangs
Blog :https://thedfirreport.com/2025/09/08/blurring-the-lines-intrusion-shows-connection-with-three-major-ransomware-gangs/
⭐️@APTANALYSIS
Please open Telegram to view this post
VIEW IN TELEGRAM
An analysis of the Gentlemen ransomware group, which employs advanced, adaptive tactics, techniques, and procedure to target critical industries worldwide.
Blog: https://www.trendmicro.com/en_us/research/25/i/unmasking-the-gentlemen-ransomware.html
⭐️@APTANALYSIS
♣️Threat Intelligence Report: APT35 Internal Leak of Hacking Campaigns Against Lebanon, Kuwait, Turkey, Saudi Arabia, Korea, and Domestic Iranian Targets
🐈‍⬛Blog : https://dti.domaintools.com/threat-intelligence-report-apt35-internal-leak-of-hacking-campaigns-against-lebanon-kuwait-turkey-saudi-arabia-korea-and-domestic-iranian-targets
⭐️@APTANALYSIS
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
♣️MongoDB Unauthenticated Attacker Sensitive Memory Leak
Blog : https://www.ox.security/blog/attackers-could-exploit-zlib-to-exfiltrate-data-cve-2025-14847/
⭐️@APTANALYSIS
Please open Telegram to view this post
VIEW IN TELEGRAM
♣️Attackers exploit vulnerability CVE-2005–55182 in attacks on Russian companies
🌐Blog : https://bi.zone/expertise/blog/zloumyshlenniki-ekspluatiruyut-uyazvimost-cve-2025-55182-v-atakakh-na-rossiyskie-kompanii
♣️MongoBleed: CVE-2025-14847 Memory Corruption in MongoDB. Your Database Talks Back
🌐Blog : https://phoenix.security/mongobleed-vulnerability-cve-2025-14847
♣️The Story of a Perfect Exploit Chain: Six Bugs That Looked Harmless Until They Became Pre-Auth RCE in a Security Appliance
🌐Blog : https://mehmetince.net/the-story-of-a-perfect-exploit-chain-six-bugs-that-looked-harmless-until-they-became-pre-auth-rce-in-a-security-appliance
♣️Livewire: remote command execution through unmarshaling
🌐Blog : https://www.synacktiv.com/en/publications/livewire-remote-command-execution-through-unmarshalinghttps://www.synacktiv.com/en/publications/livewire-remote-command-execution-through-unmarshaling
⭐️@APTANALYSIS
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
♣️Deep Dive into New XWorm Campaign Utilizing Multiple-Themed Phishing Emails
👮‍♀Blog : https://www.fortinet.com/blog/threat-research/deep-dive-into-new-xworm-campaign-utilizing-multiple-themed-phishing-emails
⭐️@APTANALYSIS
Please open Telegram to view this post
VIEW IN TELEGRAM