New variant of #Emmenhtal loader actively distributed since early December and leading to #Lumma#DarkGate and/or #SectopRAT.
🚩#Emmenhtalv2 adopts new obfuscation features and is currently not well detected by AV solutions.
Initial access: fake CAPTCHA, #ClickFix, phishing.
Our CTI analysts @Mar_Pich and @Lexsek_ just released their investigation into #Emmenhtal 🪼🧀, a loader which has been distributing +10 different infostealers since early 2024. This research is based on real-life incidents from our #CyberSOC.
🔗https://t.co/R7qwuSnyr0
Nous recrutons dans notre équipe. Si vous avez des compétences en RE, souhaitez travailler au profit de la Gendarmerie en tant qu'expert judiciaire et manager une équipe de passionnés : https://t.co/60oviiU04V
(rt apprécié)
Look what I just received 😊. Thanks a lot @DarkCoderSc@fr0gger_ for the kind message and this beautiful coin, really appreciate the gesture. Does the Ronflex Pokemon's card mean I need to take some rest and sleep more ? 😅
Let's explore the link between #Rhadamanthys stealer and #HiddenBee coin miner!
In our latest blog, @hasherezade walks you through the custom executable formats, evolution, and features of this interesting, multilayer malware toolkit.
https://t.co/DcKLK5e7kw
The slides https://t.co/c77SpAoCDO and video https://t.co/8WpHENc1Og of my #Botconf talk about #IronTiger TTPs are online. I discuss recent infection vectors (supply chain attack), the evolution of their malware toolkit and targeting, and our attribution methodology #APT#APT27
So far I've written 559 pages to help the security community:
1. https://t.co/CqJcmTzygA
2. https://t.co/49XWAoYgb9
3. https://t.co/eVgSSSzBhQ
4. https://t.co/5b3zrZMZXk
5. https://t.co/JMqvn2wK67
6. https://t.co/7WKSDijTIb
7. https://t.co/V3rw0gSZfu
8. https://t.co/2Hv0XLMuqU
New release: #TinyTracer v2.3 : https://t.co/Ajq09c2TUQ - with improved syscalls tracing support - now syscalls are automatically mapped to corresponding functions names
🧵Thread: 10 underestimated resources about malware techniques.
This is a list of various resources to learn more about malware techniques, how to analyse them and how to improve your detection! 🤓 #infosec#malware#threatintel#malwareanalysis#cybersecurity
For a reverse engineer, the ability to directly call a function from the analyzed binary can be a shortcut that bypasses a lot of grief. In this article, we explore and compare 3 ways of invoking functions: IDA Appcall, Dumpulator, and Unicorn Engine.
https://t.co/QO4yUGx6Eg
At the crossroads between pentest and incident response, we wondered what traces attackers really leave when they lateralize. Our latest blogpost tries to answer the question on Windows systems.
https://t.co/PnuZiWwkJz #DFIR