en
Feedback
APT

APT

Open in Telegram

This channel discusses: — Offensive Security — RedTeam — Malware Research — OSINT — etc Disclaimer: t.me/APT_Notes/6 Chat Link: t.me/APT_Notes_PublicChat

Show more

📈 Analytical overview of Telegram channel APT

Channel APT (@apt_notes) in the English language segment is an active participant. Currently, the community unites 16 275 subscribers, ranking 7 794 in the Technologies & Applications category and 40 535 in the Russia region.

📊 Audience metrics and dynamics

Since its creation on невідомо, the project has demonstrated rapid growth, gathering an audience of 16 275 subscribers.

According to the latest data from 01 September, 2026, the channel demonstrates stable activity. Although there has been a change in the number of participants by 547 over the last 30 days and by 18 over the last 24 hours, overall reach remains high.

  • Verification status: Not verified
  • Engagement rate (ER): The average audience engagement rate is 44.29%. Within the first 24 hours after publication, content typically collects 18.04% reactions from the total number of subscribers.
  • Post reach: On average, each post receives 7 204 views. Within the first day, a publication typically gains 2 934 views.
  • Reactions and interaction: The audience actively supports content: the average number of reactions per post is 26.

📝 Description and content policy

The author describes the resource as a platform for expressing subjective opinions:
This channel discusses: — Offensive Security — RedTeam — Malware Research — OSINT — etc Disclaimer: t.me/APT_Notes/6 Chat Link: t.me/APT_Notes_PublicChat

Thanks to the high frequency of updates (latest data received on 02 September, 2026), the channel maintains relevance and a high level of publication reach. Analytics show that the audience actively interacts with content, making it an important point of influence in the Technologies & Applications category.

16 275
Subscribers
+1824 hours
+827 days
+54730 days
Posts Archive
APT
16 275
Repost from Offensive Xwitter
😈 [ _Kudaes_, Kurosh Dabbagh ] I've found that fibers may be something to look at when it comes to execute local in-memory code. This is a simple PoC of how you can leverage fibers to execute in-memory code without spawning threads and hiding suspicious thread stacks among others. https://t.co/kjIPOunGun 🔗 https://github.com/Kudaes/Fiber 🐥 [ tweet ]

APT
16 275
🕳 Ngrok: SSH Reverse Tunnel Agent Did you know that you can run ngrok without even installing ngrok? You can start tunnels v
🕳 Ngrok: SSH Reverse Tunnel Agent Did you know that you can run ngrok without even installing ngrok? You can start tunnels via SSH without downloading an ngrok agent by running an SSH reverse tunnel command: ssh -i ~/.ssh/id_ed25519 -R 80:localhost:80 v2@tunnel.us.ngrok.com http Source: https://ngrok.com/docs/secure-tunnels/tunnels/ssh-reverse-tunnel-agent/ #ngrok #ssh #reverse #tunnel

APT
16 275
Запись нашего стрима про пентест и redteam с крутыми ребятами: * @clevergod – вице-капитан команды Codeby с колоссальным опытом в ред тим проектах; * @Riocool – создатель Telegram канала RedTeam Brazzers, участник команды True0xA3; * @Acrono – создатель Telegram канала APT и автор нескольких CVE; * @puni1337 - ведущий стримов Codeby. https://www.youtube.com/live/ITtiyhA0rwU?feature=share Интересно пообщались, не без смешных историй)) #stream #video

APT
16 275
Repost from Offensive Xwitter
😈 [ elkement, elkement ] Hi Active Directory / ADCS hackers, I've published something! You can add the new SID extension manually if certificate templates allow for custom names: https://t.co/SndcHH3Kz7 🔗 https://elkement.blog/2023/03/30/lord-of-the-sid-how-to-add-the-objectsid-attribute-to-a-certificate-manually/ 🐥 [ tweet ]

APT
16 275
Repost from Codeby
👩‍💻 За кулисами Red Team. Интересные ситуации в проектах. Друзья, рады вам сообщить, что уже в эту субботу, 1 апреля, мы пр
👩‍💻 За кулисами Red Team. Интересные ситуации в проектах. Друзья, рады вам сообщить, что уже в эту субботу, 1 апреля, мы проведём наш первый стрим в этом году! Мы пригласили экспертов информационной безопасности, которые поделятся опытом работы в Red Team и расскажут о самых интересных и необычных ситуациях, с которыми они сталкивались в проектах по тестированию на проникновение. Вы узнаете, как они решают проблемы и справляются с непредсказуемыми ситуациями в процессе работы. 🌟 У нас в гостях: 🔹 @T3m3t_N0sc3 – гуру инфраструктурных пентестов и автор множества статей по Red Team; 🔹 @clevergod – вице-капитан команды Кодебай с колоссальным опытом в ред тим проектах; 🔹 @Riocool – основатель группы единомышленников RedTeam Brazzers, участник команды True0xA3; 🔹 @Acrono – создатель группы Telegram APT и автор нескольких CVE для Windows. 🎤 И, конечно же, ваш незаменимый ведущий – @puni1337! ⏰ Мы ждем вас 1 апреля в 17:00 по московскому времени! 🌐 Смотрите стрим в нашем Youtube канале #pentest #redteam #stream

APT
16 275
🔄 CertSync New technique in order to dump NTDS remotely, but without DRSUAPI it uses golden certificate and UnPAC the hash.
🔄 CertSync New technique in order to dump NTDS remotely, but without DRSUAPI it uses golden certificate and UnPAC the hash. It does not require to use a Domain Administrator, it only require a CA Administrator. It works in several steps: — Dump user list, CA informations and CRL from LDAP; — Dump CA certificate and private key; — Forge offline a certificate for every user; — UnPAC the hash for every user in order to get NT and LM hashes. https://github.com/zblurx/certsync #ad #adcs #drsuapi #ntds #cert #redteam

APT
16 275
⚙️ Joomla < 4.2.8 — Unauthenticated Information Disclosure (CVE-2023-23752) Research: https://vulncheck.com/blog/joomla-fo
⚙️ Joomla < 4.2.8 — Unauthenticated Information Disclosure (CVE-2023-23752) Research: https://vulncheck.com/blog/joomla-for-rce Exploit: https://github.com/Acceis/exploit-CVE-2023-23752 #joomla #information #disclosure #cve

APT
16 275
👾 HeapCrypt Encypting the Heap while sleeping by hooking and modifying Sleep with our own sleep that encrypts the heap. http
👾 HeapCrypt Encypting the Heap while sleeping by hooking and modifying Sleep with our own sleep that encrypts the heap. https://github.com/TheD1rkMtr/HeapCrypt #maldev #heap #encypt #sleep #cpp

APT
16 275
Veeam Backup and Replication (CVE-2023-27532) Vulnerability in Veeam Backup & Replication component allows encrypted credenti
Veeam Backup and Replication (CVE-2023-27532) Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained. This may lead to gaining access to the backup infrastructure hosts. Research: https://www.horizon3.ai/veeam-backup-and-replication-cve-2023-27532-deep-dive/ Exploit: https://github.com/horizon3ai/CVE-2023-27532 #veeam #credentials #rce #cve

APT
16 275
Repost from Offensive Xwitter
😈 [ fr0gger_, Thomas Roccia 🤘 ] New EDR/AV evasion technique added to the #UnprotectProject by @Praetorian_GRD "Unloading M
😈 [ fr0gger_, Thomas Roccia 🤘 ] New EDR/AV evasion technique added to the #UnprotectProject by @Praetorian_GRD "Unloading Module Using FreeLibrary". Check out the detailed description, code snippet and CAPA rule👇 #cybersecurity #malware #infosec cf: @DarkCoderSc https://t.co/Td7ogFwVcZ 🔗 https://unprotect.it/technique/unloading-module-with-freelibrary/ 🐥 [ tweet ]

APT
16 275
Repost from 1N73LL1G3NC3
CVE-2023-23397 Microsoft Office Outlook contains a privilege escalation vulnerability that allows for a NTLM Relay attack against another service to authenticate as the user. PoC: https://github.com/sqrtZeroKnowledge/CVE-2023-23397_EXPLOIT_0DAY https://github.com/api0cradle/CVE-2023-23397-POC-Powershell

APT
16 275
Repost from Offensive Xwitter
photo content
+1

APT
16 275
Repost from Offensive Xwitter
👹 [ snovvcrash, sn🥶vvcr💥sh ] Have been playing around with Domain Fronting via Fastly and discovered that you actually do not need to confirm the domain name ownership (by adding a CNAME) for the traffic to flow towards your IP. A bug or feature? 🤔 🐥 [ tweet ] игрались тут с @Acrono с домен фронтингом и вот такую фичу интересную нашли

APT
16 275
🦛 PetitPotam: Local Privilege Escalation Now PetitPotato can elevate to SYSTEM on the latest windows. My test version is 10.
🦛 PetitPotam: Local Privilege Escalation Now PetitPotato can elevate to SYSTEM on the latest windows. My test version is 10.0.20348.1547 https://github.com/wh0amitz/PetitPotato/ #windows #privesc #rpc #petitpotam

APT
16 275
🌐 External Trusts Are Evil https://exploit.ph/external-trusts-are-evil.html #ad #trust #abuse

APT
16 275
Repost from 1N73LL1G3NC3
LPE exploit for CVE-2023-21768 (Windows Ancillary Function Driver for WinSock Elevation of Privilege) Complete exploit works on vulnerable Windows 11 22H2 systems. Write primitive works on all vulnerable systems.

APT
16 275
🔑 KeePass2: DLL Hijacking and Hooking API This new article about a way to get the Master Password of a KeePass database. htt
🔑 KeePass2: DLL Hijacking and Hooking API This new article about a way to get the Master Password of a KeePass database. https://skr1x.github.io/keepass-dll-hijacking/ #keepass #dll #hijacking #redteam

APT
16 275
🌐 DroppedConnection — Cisco ASA Anyconnect Emulator Fake VPN server that captures credentials and executes code via the Cisc
🌐 DroppedConnection — Cisco ASA Anyconnect Emulator Fake VPN server that captures credentials and executes code via the Cisco AnyConnect client. Source: https://github.com/nccgroup/DroppedConnection Research: https://research.nccgroup.com/2023/03/01/making-new-connections-leveraging-cisco-anyconnect-client-to-drop-and-run-payloads/ #cisco #asa #anyconnect #credentials #redteam

APT
16 275
​​​⚛️ AtomLdr A DLL loader with advanced evasive. Features: • DLL unhooking from \KnwonDlls\ directory, with no RWX sections
​​​⚛️ AtomLdr A DLL loader with advanced evasive. Features: • DLL unhooking from \KnwonDlls\ directory, with no RWX sections • The encrypted payload is saved in the resource section and retrieved via custom code • AES256-CBC Payload encryption using custom no table/data-dependent branches using ctaes; this is one of the best custom AES implementations I've encountered • Indirect syscalls, utilizing HellHall with ROP gadgets • Payload injection using APC calls - alertable thread • Api hashing using two different implementations of the CRC32 string hashing algorithm • The total Size is 17kb https://github.com/NUL0x4C/AtomLdr #loader #dll #edr #evasion #redteam

APT
16 275
📜 Abusing Code Signing Certificates Abusing code signing certificates is not new. In the past few years alone, it has proven
📜 Abusing Code Signing Certificates Abusing code signing certificates is not new. In the past few years alone, it has proven to be an effective method of bypassing certain security controls to allow malicious software to run and look seemingly benign. This article describes code signing methods, as well as tools for copying the signature from legitimate PE files. Source: https://axelarator.github.io/posts/codesigningcerts/ #sign #code #certificate #abuse #redteam