The description of the new hacking campaign itself does not yet show whether its traces remain within a particular corporate network. Positive Technologies has updated PT Fusion and added to the portal closed cyber intelligence reports together with YARA rules based on the analysis of current threats and incident investigation.
The main change was a separate section with the materials of the expert security center Positive Technologies. Customers with a premium subscription level will have access to closed analytics. The reports deal with the detected hacker campaigns, the tools used by the attackers, signs of attacks and compromising indicators, such as malicious IP addresses, domains, links and file hashes.
Some of the materials are not planned to be published for a wide audience. Some studies will later become publicly available, but users of the portal with the appropriate level of access will be able to get acquainted with the analytics before the public release. As a result, the closed section actually complements the open threat library with more recent materials designed for the practical work of IS specialists.
Along with the reports, the YARA rules appeared in PT Fusion. YARA allows you to search and classify files by characteristic text and binary sequences, structure and other features. The rule describes a set of features and matching conditions, after which a compatible tool can check files or other data for the presence of a given template.
Positive Technologies forms new rules based on the information that specialists receive during cyber intelligence and investigations. Such a set will be useful when analysts already know what features have a specific malware, bootloader or attacking tool, and it is necessary to check a large number of files for matches with the found signs.
The developers involve the use of YARA rules in the response and investigation of incidents, as well as during the threat of hunting, that is, proactive search for traces of intruders who could not cause the operation of standard means of protection. The very coincidence with the YARA rule does not always mean confirmed infection: the result usually requires verification along with other signs of the attack and the context of the incident.
The rules can be transferred to protective products that support the YARA format. Among the examples, Positive Technologies names EDR, systems for detecting and investigating malicious activity on workstations and servers, and sandboxes where suspicious files run in an isolated environment and observe behavior.
PT Fusion appeared in late 2025 as a cloud portal for SOC analysts, cyber intelligence specialists and response teams. The service combined the verification of malicious files, the search for compromise indicators, information about hacker groups and malware families, Passive DNS data and vulnerability information. In March 2026, version 1.5 received Threat Intelligence Feeds streams, full-text search by threat library, and advanced API.
The next notable extension appeared in version 1.7: in May, Positive Technologies added data on malicious, protest and remote releases of open source projects. The current update continues to develop the portal in a different direction: closed-end campaign analytics and ready-made rules for finding related files are added to the arrays of technical indicators.
Positive Technologies links the release to the need to close the gap between getting information about the new threat and checking corporate infrastructure. Instead of one report describing the campaign, specialists will be able to get technical features and YARA rules, but the final effectiveness of the search will depend on the completeness of the collected data, the quality of the rules themselves and the capabilities of the security systems where the rules are loaded.
The main change was a separate section with the materials of the expert security center Positive Technologies. Customers with a premium subscription level will have access to closed analytics. The reports deal with the detected hacker campaigns, the tools used by the attackers, signs of attacks and compromising indicators, such as malicious IP addresses, domains, links and file hashes.
Some of the materials are not planned to be published for a wide audience. Some studies will later become publicly available, but users of the portal with the appropriate level of access will be able to get acquainted with the analytics before the public release. As a result, the closed section actually complements the open threat library with more recent materials designed for the practical work of IS specialists.
Along with the reports, the YARA rules appeared in PT Fusion. YARA allows you to search and classify files by characteristic text and binary sequences, structure and other features. The rule describes a set of features and matching conditions, after which a compatible tool can check files or other data for the presence of a given template.
Positive Technologies forms new rules based on the information that specialists receive during cyber intelligence and investigations. Such a set will be useful when analysts already know what features have a specific malware, bootloader or attacking tool, and it is necessary to check a large number of files for matches with the found signs.
The developers involve the use of YARA rules in the response and investigation of incidents, as well as during the threat of hunting, that is, proactive search for traces of intruders who could not cause the operation of standard means of protection. The very coincidence with the YARA rule does not always mean confirmed infection: the result usually requires verification along with other signs of the attack and the context of the incident.
The rules can be transferred to protective products that support the YARA format. Among the examples, Positive Technologies names EDR, systems for detecting and investigating malicious activity on workstations and servers, and sandboxes where suspicious files run in an isolated environment and observe behavior.
PT Fusion appeared in late 2025 as a cloud portal for SOC analysts, cyber intelligence specialists and response teams. The service combined the verification of malicious files, the search for compromise indicators, information about hacker groups and malware families, Passive DNS data and vulnerability information. In March 2026, version 1.5 received Threat Intelligence Feeds streams, full-text search by threat library, and advanced API.
The next notable extension appeared in version 1.7: in May, Positive Technologies added data on malicious, protest and remote releases of open source projects. The current update continues to develop the portal in a different direction: closed-end campaign analytics and ready-made rules for finding related files are added to the arrays of technical indicators.
Positive Technologies links the release to the need to close the gap between getting information about the new threat and checking corporate infrastructure. Instead of one report describing the campaign, specialists will be able to get technical features and YARA rules, but the final effectiveness of the search will depend on the completeness of the collected data, the quality of the rules themselves and the capabilities of the security systems where the rules are loaded.