APT ANALYSIS
1.76K subscribers
171 photos
2 videos
6 files
176 links
Анализ APT с фокусом на моделирование, обнаружение и управление сложными атаками. Предоставление точных данных и решений для прогнозирования угроз с реальным опытом в области безопасности.
https://t.me/addlist/7MAZa-vnZclhYzAx
Download Telegram
AppSuite PDF Editor Backdoor: A Detailed Technical Analysis
Blog: https://www.gdatasoftware.com/blog/2025/08/38257-appsuite-pdf-editor-backdoor-analysis
⭐️@APTANALYSIS
The One-Man APT, Part I: A Picture That Can Execute Code on the Target
Blog:https://hackers-arise.com/the-one-man-apt-part-i-a-picture-that-can-execute-code-on-the-target/
⭐️@APTANALYSIS
♣️Blurring the Lines: Intrusion Shows Connection With Three Major Ransomware Gangs
Blog :https://thedfirreport.com/2025/09/08/blurring-the-lines-intrusion-shows-connection-with-three-major-ransomware-gangs/
⭐️@APTANALYSIS
Please open Telegram to view this post
VIEW IN TELEGRAM
An analysis of the Gentlemen ransomware group, which employs advanced, adaptive tactics, techniques, and procedure to target critical industries worldwide.
Blog: https://www.trendmicro.com/en_us/research/25/i/unmasking-the-gentlemen-ransomware.html
⭐️@APTANALYSIS
♣️Threat Intelligence Report: APT35 Internal Leak of Hacking Campaigns Against Lebanon, Kuwait, Turkey, Saudi Arabia, Korea, and Domestic Iranian Targets
🐈‍⬛Blog : https://dti.domaintools.com/threat-intelligence-report-apt35-internal-leak-of-hacking-campaigns-against-lebanon-kuwait-turkey-saudi-arabia-korea-and-domestic-iranian-targets
⭐️@APTANALYSIS
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
♣️MongoDB Unauthenticated Attacker Sensitive Memory Leak
Blog : https://www.ox.security/blog/attackers-could-exploit-zlib-to-exfiltrate-data-cve-2025-14847/
⭐️@APTANALYSIS
Please open Telegram to view this post
VIEW IN TELEGRAM
♣️Attackers exploit vulnerability CVE-2005–55182 in attacks on Russian companies
🌐Blog : https://bi.zone/expertise/blog/zloumyshlenniki-ekspluatiruyut-uyazvimost-cve-2025-55182-v-atakakh-na-rossiyskie-kompanii
♣️MongoBleed: CVE-2025-14847 Memory Corruption in MongoDB. Your Database Talks Back
🌐Blog : https://phoenix.security/mongobleed-vulnerability-cve-2025-14847
♣️The Story of a Perfect Exploit Chain: Six Bugs That Looked Harmless Until They Became Pre-Auth RCE in a Security Appliance
🌐Blog : https://mehmetince.net/the-story-of-a-perfect-exploit-chain-six-bugs-that-looked-harmless-until-they-became-pre-auth-rce-in-a-security-appliance
♣️Livewire: remote command execution through unmarshaling
🌐Blog : https://www.synacktiv.com/en/publications/livewire-remote-command-execution-through-unmarshalinghttps://www.synacktiv.com/en/publications/livewire-remote-command-execution-through-unmarshaling
⭐️@APTANALYSIS
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
♣️Deep Dive into New XWorm Campaign Utilizing Multiple-Themed Phishing Emails
👮‍♀Blog : https://www.fortinet.com/blog/threat-research/deep-dive-into-new-xworm-campaign-utilizing-multiple-themed-phishing-emails
⭐️@APTANALYSIS
Please open Telegram to view this post
VIEW IN TELEGRAM
♣️Detecting Russian Threats to Critical Energy Infrastructure
🔬Blog : https://www.truesec.com/hub/blog/detecting-russian-threats-to-critical-energy-infrastructure
⭐️@APTANALYSIS
Please open Telegram to view this post
VIEW IN TELEGRAM
♣️Inside Gunra RaaS: From Affiliate Recruitment on the Dark Web to Full Technical Dissection of their Locker
🍎Blog : https://www.cloudsek.com/blog/inside-gunra-raas-from-affiliate-recruitment-on-the-dark-web-to-full-technical-dissection-of-their-locker
⭐️@APTANALYSIS
Please open Telegram to view this post
VIEW IN TELEGRAM
♣️Tenant from Hell: Prometei's Unauthorized Stay in Your Windows Server
🖥Blog : https://www.esentire.com/blog/tenant-from-hell-prometeis-unauthorized-stay-in-your-windows-server
⭐️@APTANALYSIS
Please open Telegram to view this post
VIEW IN TELEGRAM
💀Hot headlines over the past week
♣️How ClickFix Opens the Door to Stealthy StealC Information Stealer
💿Blog : https://www.levelblue.com/blogs/spiderlabs-blog/how-clickfix-opens-the-door-to-stealthy-stealc-information-stealer
♣️Odyssey Stealer: Inside a macOS Crypto-Stealing Operation
Blog : https://censys.com/blog/odyssey-stealer-macos-crypto-stealing-operation
♣️Lotus Blossom (G0030) and the Notepad++ Supply-Chain Espionage Campaign
🟥Blog : https://dti.domaintools.com/research/lotus-blossom-and-the-notepad-supply-chain-espionage-campaign
♣️LummaStealer Is Getting a Second Life Alongside CastleLoader
🌎Blog : https://www.bitdefender.com/en-us/blog/labs/lummastealer-second-life-castleloader
♣️LockBit strikes with new 5.0 version, targeting Windows, Linux and ESXI systems
🔮Blog : https://www.acronis.com/en/tru/posts/lockbit-strikes-with-new-50-version-targeting-windows-linux-and-esxi-systems
⭐️@APTANALYSIS
Please open Telegram to view this post
VIEW IN TELEGRAM
♣️UAC-0244 / UAC-0247: Malware Targeting FPV drone operators
🖤Blog : https://blog.synapticsystems.de/uac-0247-malware-targeting-fpv-operators
♣️UAC-0184: From HTA to a Signed Network Stack
🖤Blog : https://blog.synapticsystems.de/uac-0184-from-hta-to-a-signed-network-stack
⭐️@APTANALYSIS
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
♣️INJ3CTOR3’s Self-Healing FreePBX Toll Fraud Campaign
👶Blog : https://cyble.com/blog/jomangy-inj3ctor3s-self-healing-freepbx-toll-fraud-campaign
⭐️@APTANALYSIS
Please open Telegram to view this post
VIEW IN TELEGRAM