GOFFEE continues to attack organizations in Russia ​

GOFFEE continues to attack organizations in Russia ​

Read More  GOFFEE is a threat actor that first came to our attention in early 2022. Since then, we have observed malicious activities targeting exclusively entities located in the Russian Federation, leveraging spear phishing emails with a malicious attachment....
How ToddyCat tried to hide behind AV software ​

How ToddyCat tried to hide behind AV software ​

Read More  To hide their activity in infected systems, APT groups resort to various techniques to bypass defenses. Most of these techniques are well known and detectable by both EPP solutions and EDR threat-monitoring and response tools. For example, to hide their...
TookPS: DeepSeek isn’t the only game in town ​

TookPS: DeepSeek isn’t the only game in town ​

Read More  In early March, we published a study detailing several malicious campaigns that exploited the popular DeepSeek LLM as a lure. Subsequent telemetry analysis indicated that the TookPS downloader, a malware strain detailed in the article, was not limited to...