INTEL_REPORT
ESET WeLiveSecurity · published 3/10/2026, 9:58:00 AM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
Sednit reloaded: Back in the trenches The resurgence of one of Russia’s most notorious APT groups Sednit reloaded: Back in the trenches Award-winning news, views, and insight from the ESET security community English Español Deutsch Português Français TIPS & ADVICE BUSINESS SECURITY ESET RESEARCH About ESET Research Blogposts Podcasts White papers Threat reports WeLiveScience FEATURED Ukraine crisis – Digital security resource center WeLiveProgress COVID-19 Resources Vid…
https://www.welivesecurity.com/en/eset-research/sednit-reloaded-back-trenches
sha256:58fcfe5c8ca5a695565d28845c3b75fdfa522c1bb84baa41c4704dca0c00b7c5
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| tcpiphlpsvc.dll |
| Open → |
| domain | taskhost.exe | Open → |
| domain | taskhostw.exe | Open → |
| sha1 | d0db619a7a160949528d46d20fc0151bf9775c32 | Open → |
| sha1 | 99b454262dc26b081600e844371982a49d334e5e | Open → |
| cve | CVE-2026-21509 | Open → |