 
                                TG Soft
@viritexplorer
Italian Software House active in antimalware research and antivirus development since 1992. VirIT eXplorer is the name of our antivirus suite.
ID: 275048774
https://www.tgsoft.it 31-03-2011 14:45:40
2,2K Tweet
2,2K Followers
1,1K Following
 
        #Italy Weekly malspam n.25 from 19 to 25 Jun 2023 We have analyzed 51 campaigns, 6 in italian 🔥 #AgentTesla #FormBook #SnakeLogger #Ave_Maria #Ursnif hits Italy again with theme Pagamenti Total family 8 tgsoft.it/news/news_arch… moto_sato sugimu🐞 JAMESWT_MHT Breabin Radu
 
        #Italy Weekly malspam n.26 from 26 Jun to 2 Jul 2023 We have analyzed 51 campaigns, 15 in italian 🔥 #AgentTesla #FormBook #LokiBot #Rhadamanthys New entry RAT spread via PEC Total family 10 moto_sato JAMESWT_MHT sugimu🐞 Breabin Radu Michele tgsoft.it/news/news_arch…
 
         
         
        A China-linked threat actor called APT17 has been observed targeting Italian companies and government entities using a variant of a known malware referred to as 9002 RAT. thehackernews.com/2024/07/china-… The Hacker News
 
        TG Soft has been monitoring the abuse of MSC files by a Chinese APT that exploited a new diskless shellcode that download the Marte Beacon with Cobalt Strike tgsoft.it/news/news_arch… moto_sato nao_sec AhnLab Security Information Elastic Security Labs StrikeReady Labs Joe Desimone
 
         
        ![TG Soft (@viritexplorer) on Twitter photo Interesting #CobaltStrike from "apt-99" with C2:
pythongo[.]online
LNK -> Silverlight.exe (sideloading coreclr.dll) -> bin.dat -> CS
C:\Users\admin\Desktop\Project\cs4.5(apt-99)\cs4.5 2\external\beacon\Release\beacon.pdb
<a href="/58_158_177_102/">moto_sato</a> <a href="/StrikeReadyLabs/">StrikeReady Labs</a> Interesting #CobaltStrike from "apt-99" with C2:
pythongo[.]online
LNK -> Silverlight.exe (sideloading coreclr.dll) -> bin.dat -> CS
C:\Users\admin\Desktop\Project\cs4.5(apt-99)\cs4.5 2\external\beacon\Release\beacon.pdb
<a href="/58_158_177_102/">moto_sato</a> <a href="/StrikeReadyLabs/">StrikeReady Labs</a>](https://pbs.twimg.com/media/GWtC4khWUAcB4jF.png)