Bad magic: new APT found in the area of Russo-Ukrainian conflict

In October 2022, we identified an active infection of government, agriculture and transportation organizations located in the Donetsk, Lugansk, and Crimea regions. Continue reading Bad magic: new APT found in the area of Russo-Ukrainian conflict

How to find the process that is running PowerShell commands that appear in Windows Defender

On one of our Windows Datacenter 2016, there’s an alert that a trojan is trying to install :

The following PowerShell commands are trying to execute at seemingly random hours of the day (always during working hours, one to two times a day… Continue reading How to find the process that is running PowerShell commands that appear in Windows Defender