Lots of people YOLO their claude usage. We should probably stop doing that.
I've developed claude-guard (beta). Claude Code inside a full sandbox, behind a firewall, watched by an escalation monitor that can STOP the agent and push-notify you when something weird happens
🚨BREAKING: Israel assassinated Mohamed Al-Wahidi, Director of Public Relations at the Egyptian Committee in Gaza.
The assassination comes one day after Hamas dissolved its governing body to clear the way for civilian technocratic rule.
Together with @bzvr_, @2igosha and Anton Kargin, we identified that the DAEMON Tools software has been compromised in a complex supply chain attack since April 8. We see thousands of infections across 100+ countries. If you use DAEMON Tools, run a malware scan immediately! [1/7]
A country that has nuclear weapons is threatening to use its nuclear weapons on the country it won’t allow to have nuclear weapons because if they had nuclear weapons they would ‘use them.’
🚨Alert: Evolution of EtherHiding in ArechClient2
🔬Report: https://t.co/6YAc3dIb12
ArechClient2 has been using the Binance Smart Chain (BSC) to fetch C2 servers (a technique known as EtherHiding) since at least June 2025, but we observed a change in the technique in a more recent sample. In the past, a single API endpoint hxxps[:]//bsc-dataseed1[.]binance[.]org was used for this, but in this new sample we see requests to 10 different API (sub)domains. While it is currently unclear why the sample queries the same smart contract on 10 different API endpoints, it is likely an attempt to circumvent blocking, or a first step into diversification of API endpoints used to access the smart contracts. Either way, due a limited number of possible API endpoints, this still is a great detection opportunity to detect malware (for example ArechClient2, SharkStealer) that uses EtherHiding.
🔎In a nutshell:
- ArechClient2 contains one hardcoded C2, fetches second C2 server from Binance Smart Chain via RPC call (eth_call)
- Smart contract returns base64 encoded tuple (with “START” and “FINISH” markers) consisting of IV and encrypted C2 IP
- Executable uses embedded hardcoded key plus IV to decrypt C2 channel (AES)
- We identified samples communicating with three different smart contracts, one of them being updated very frequently
- 10 different BSC API endpoints queried in recent sample
🔐Find the full decryption procedure here: https://t.co/xLNE4kvT4d
🧬IoCs:
- 79326544757d48a9f0fc0cfd9628df712a92271fa85e1194c5132fa465896e72
- Contract: 0xbd75e2f339d4aebf72ff13f3af4c27096f709a4d
- AES Key: VOqkXCYMgproaIQIj50Z2tsBru1ULFzXeKKKg19WMTs=
- C2:138[.]226[.]238[.]96:443
🌐BSC API endpoints
- hxxps[:]//bsc-dataseed1[.]binance[.]org
- hxxps[:]//bsc-dataseed2[.]binance[.]org
- hxxps[:]//bsc-dataseed3[.]binance[.]org
- hxxps[:]//bsc-dataseed4[.]binance[.]org
- hxxps[:]//bsc-dataseed1[.]ninicoin[.]io
- hxxps[:]//bsc-dataseed2[.]ninicoin[.]io
- hxxps[:]//bsc-dataseed1[.]defibit[.]io
- hxxps[:]//bsc-dataseed2[.]defibit[.]io
- hxxps[:]//bsc-dataseed3[.]defibit[.]io
- hxxps[:]//bsc-dataseed4[.]defibit[.]io
Israel's conviction rate of Palestinians (in military courts) is 99.74%
Israel's conviction rate of reported settler attacks on Palestinians is 1.8%
Israel's death sentence will only apply against Palestinians not Israeli Jews
It's not complicated. It's Apartheid!
The recording of my first Binary Cartography webinar is now public:
Agentic Reverse Engineering: How AI Agents Are Changing Binary Analysis
Topics: keygenning, cracking & anti-tamper removal
Recording: https://t.co/dheTSRkJqP
Slides/code/samples: https://t.co/nAqtcqVs7i
Stop asking LLMs to “find vulns.” Start using them to understand code.
@Sw4mp_f0x walks through using Claude Code as a force multiplier in app assessments - faster analysis, fewer false positives, better outcomes.
Check it out: https://t.co/BpMnOGBMv7
I may have found a way to get an uncensored PDF invitation to an “exclusive event” out of the Epstein files… but I need help and fresh suggestions! Link below.
🚨 Alert: Previously undocumented Tornado v51 variant from Prince of Persia (Infy) APT
🔬 Report:
https://t.co/eQK6y1yCwA
We have recently spotted an infostealer sample, which shows code similarities to previous Foudre/Tonnerre malware variants from the Prince of Persia/Infy APT groups, but the infostealer seems to call itself Tornado with a v051 version marker. This would align well with previously discovered variants like the last Foudre v50 variant and how Tornado seems to be a continuation of that.
Prince of Persia, also known as Infy, is an Iranian state-sponsored APT group active since at least 2007, targeting dissidents, civil society, journalists, diplomats, and critical infrastructure primarily in Iran and Europe through espionage-focused malware like Foudre and Tonnerre.
Previously SafeBreach Labs' research revealed the group never truly went dormant after 2022.
-----
Key takeaways:
🧬 New Foudre-like v051 variant (Tornado?)
PE timestamp: 2012-06-09 13:19:49, but only uploaded to VT on 2025-12-15 22:01:45
🌪️ Places a mutex named TornadoInstaller
🧾 Exfiltrates browser cookies, saved credentials
🕵️♂️ Checks whether ESET/NOD32 AV is installed
🛡️ Enumerates AntiVirusProduct, BIOS, CPU, BaseBoard information, and more
📋 Collects list of installed programs, copies clipboard content
📡 Sends all previous listed information to the C2
🤖 Capability to send the report to Telegram bot
🔀 Utilizes DGA and uses a set of 4 hardcoded TLDs (.ix[.]tc, .site, .space, .hbmc[.]net)
⛓️ Potentially use blockchain for C2 domains (BTC: 1HLoD9E4SDFFPDiYfNYnkBLQ85Y51J3Zb1)
-----
IoCs (SHA256):
44fc9e306763774b50b61fc7487aa1d219aa288aefa201119c7bc278e17600a8
5db4ed7d07ab028ab6ceba8efec5f667d86a419020d2a8c86e90a3125aa31bb9
8db20544f280955ed3ef3c42dc8423e3000e244fc7c8f0e3a7567fa48f7a15d9
a05c2c042dc4f54daf69b1b1441aa938b0ffc6fe979c413bd9fcae95b0bf7542
b937024b7484b26d09ba8130cc4ab04600dc18c976bb0c7724a063f1fc6f0d77
ba16a2dddbae458d85e663a773bff2f6eeb8704b6111b0c748564f48424538e8
🔥 Brazil WhatsApp spam reloaded: multi-layer obfuscation with HTA and PowerShellWe've recently spotted an attack chain that demonstrates a uniquely layered obfuscation scheme that resembles previous WhatsApp spam bot operations seen in Brazilian phishing campaigns similar to STAC3150, known for distributing payloads such as the infostealer Astaroth through hijacked web sessions and social engineering.
The attack begins with a malicious HTA carrier embedding a VBScript payload that’s both Base64-encoded and XOR-encrypted. Through five decryption rounds, each using a different XOR key, the final VBScript emerges and connects to the C2, retrieving a ZIP archive containing a next-stage PS1 loader and a MSI installer. The PowerShell component automates sending messages and payloads to WhatsApp Web using Selenium, Chrome, and the WPPConnect WA-JS library, while communicating with a remote PHP backend for configuration and telemetry.
Key takeaways:
- Initial HTA carrier contains Base64-obfuscated and XOR-encrypted (5 rounds) VBScript
- Final VBScript pulls a ZIP archive from the C2, with embedded PS1 downloader and MSI installer
- PowerShell loader drops wppconnect-wa.js, ChromeDriver and SeleniumModule for automating headless WhatsApp spam bot (whatsapp_automation_v6_robust.ps1)
- PowerShell also pulls PDF with prefix "Orcamento-2025" (Budget-2025), mimicking legitimate invoice attachments for phishing
- MSI installer deploys ConnectWise ScreenConnect RMM
- Operation resembles previous Brazil WhatsApp spam ops without the Astaroth/Guildma payload
الافضل من انك تبقى ذكي و ألمعي .. انك تحاول تقلل الحماقة و القرارت الاندفاعية و العصبية اللي بتعملها
اللي نجحوا في الدنيا مكانوش اذكى ناس.. بس ناس عندهم متانة نفسية تخليهم ياخدوا قرارات أقل غباءا و اندفاعا من غيرهم
ووارن بافيت له جملة بتتقال في الاستثمار بس هي صالحة للحياة كلها:
“سوق الأسهم آلة بتنقل الفلوس من اللي مستعجل للي صبور.”
بدّل “سوق الأسهم” بـ “الفرص/الشغل/العلاقات”… وهتفهم إن الصبر مش فضيلة دينية بس… ده ميزة تنافسية
أولاً: الأفضل من إنك تبقى عبقري؟ إنك تبقى هادي.
كتير من اللي “كسبوا اللعبة” مش كانوا أذكى ناس في القاعة… كانوا بس ناس عندها متانة نفسية تخليها تعمل حاجتين صعبين
ثانيا انت محتاج تفتضل تتعلم لو عايز تخليك في الgame.. عشان في ثانية هيجي واحد نص عمرك بنص خبرتك بيعمل الحاجة احسن مش عشان عنده خبرة بس عشان مواكب التطور و فاهم الجديد what got you here won’t get you there
ألف باء اي استثمار هو (الصبر) و (العلاقات)
الصبر بتحصله بهدوء اعصابك و عدم اندفاعك و انك متبقاش خفيف قدام المصايب و الايام الصعبة و تروحش تهد كل اللي انت بنيته بقرار متسرع
العلاقات في الشغل بتيجي كل ما نسبة الاعتمادية عليك تزيد..
يعني من الاخر تكون راجل او ست. صاحب مبدأ و كلمتك سيف و لو خيشت منك توضح ده من غير لوع..
السوق بيحب الناس السالكة و بيعلم عالملاوعين و العالم المقرفة و اللي بتلعب من تحت و فوق الترابيزة و يلبسواتوب مش بتاعهم
ثالثا لو فضلت اقنع نفسك ان مفيش فايدة و ان القطر فاتك. هيفوتك فعلا.. لان الولولة و السلبية بتشد لتحت .. و تخليك تبوظ اي فوصة نضيفة تجيلك عشان تثبت لنفسك قد ايه العالم شرير و انت ضحية و كلهم شمال و انت اللي مغدور بيك
فكك في العبث ده و فوق لنفسك و swallow your pride و روح شوف تطلع نفسك من المشاكل اللي انت واقع فيها ازاي .. استرجل يعني و بطل ولولة و خليك ايجابي عشان الفرص عمرها ما بتخلص
رابعا.. الفرص عمرها ما بتخلص.. بس الفكرة انك لازم تكون مجمع معاها استعدادية و هجوم مباشر (متدنجلش - انجز) و ابني قدرتك على اتخاذ قرارات حاسمة و متلعبش دايما السهلة و تاخد الاختيار الrisk free لانه بيبقى أمان مزيف
و ربنا يطورنا كلنا
@AhmedSoliman ما ده زي التغيير اللي حصل لما الmoocs ابتدت تنتشر و معدش حد عايز يقرأ كتب و ابحاث مع ان فيها حاجات مفيش كورسات بتغطيها.
اللي عنده استعداد يخرج بره الرفاهية هو اللي بيرسم الطريق عكس حد محتاج حد يديله الاكل مضروب فالخلاط و ميعرفش يعمل حاجة متعملتش قبل كده
I actually did an experiment on this using fully autonomous Claude on FlareOn 12
TL;DR: had to step in as human on every challenge, though it did speed up some phases
🔥 We uncovered notable shifts in how threat actors stage payload delivery, including emerging combinations of preferred loader, dropper and payload pairings.
We think these insights reveal interesting patterns that were previously not shared, and provide a view of the ecosystem’s strategic changes through VMRay's own telemetry.
💡 Few takeaways:
- Amadey seems to take the first entry of point quite often in multi-stage loader scenarios (3+)
- Lumma to take an intermediate position in between loaders and final dropped families
- StealCv2 and Vidar almost exclusively dropped as a final payload
- Combination of Netwire and Warzone is the leading contributor to 2-stage delivery chains
- Rhadamanthys solely deploys XMRig and StealCv2 as final payload
🔍 Check out VMRay's Dynamic Analysis report to get insights on behavior and detections others have missed: https://t.co/tXsPMtjVHo