Quick post about a stealer masquerading as DocuSign shared by @malwrhunterteam: 6d979466596978ffcb633a0b8c47adedd0778555c0e513fc3d3c84bcef6f036b (macho - 6 VT hits) and uses simple XOR for strings.
🧵
Security leaders are often trapped in endless assessments and opinion-giving without driving actual change. Staying busy with spreadsheets, dashboards, and emails doesn't move the organization forward.
Here's how we can break out of the "Chief Opinion Officer" mode: https://t.co/wTAOwHOzsM
My new site for learning macOS malware reverse engineering:
https://t.co/kzeSDjFqWp
I got my start in RE by using @patrickwardle's awesome blog. I would download samples and follow along. So I created this to complement that with dives into specific code from recent samples.
We're looking for a Principal Threat Intel Incident Commander here at @HuntressLabs ! Do you love to:
🔍 Conduct #DFIR analysis?
👀 Track threat actors?
🕸️ Work with others across different departments?
✍️ Write about your findings?
👩💼 Present your work?
👇
We've uploaded our stream from last Thursday where we analyzed the Avalon Linux bot with IDA Pro. Throughout this stream we reversed its persistence, C2 functionality, encryption and command dispatcher. Enjoy!
For those who missed it, our founder Joshua Reynolds featured the Binja Lattice MCP server on Prompt||GTFO here: https://t.co/Bxya7QGOv5 where he highlighted reverse engineering malware with AI!
Just posted my @defcon slides (talk #2): "Binary Facades"
Mac malware may be compiled Mach-Os but can contain embedded scripts. Learn to spot these 'faux' binaries + the techniques to extract their scripts ...skipping the disassembler entirely! 🍎🐛
https://t.co/yWhas0x2ro
Now at #DFIRSummit: Aaron Sparling @OSINTlabworks@Walmarttech walks through forensic techniques for analyzing #TAILs—an OS built for anonymity. From RAM imaging to artifact recovery, this session tackles how to investigate what’s designed to disappear. #MemoryForensics#DFIR
We are excited to announce FTSCon 2025 on October 20, 2025, in Arlington VA! Registration is now OPEN + we have a Call for Speakers.
Following FTSCon will be a 4-day Malware & Memory Forensics Training course with Volatility 3.
See the full details here: https://t.co/ygqxNhZyW2
We are very excited to announce that Volatility 3 has reached parity with Volatility 2! With this achievement, Volatility 2 is now deprecated. See the full details in our blog post: https://t.co/Vd8cGVe6ap
We are VERY excited to announce that Volatility 3 has now reached feature parity with Volatility 2! With this parity release, Volatility 2 is now deprecated. Full details in the blog post linked below.
You asked, we delivered: Binary Ninja 5.0 brings major iOS reversing upgrades! DYLD Shared Cache is now a first-class feature, with up to 18x faster performance and way smarter analysis across the board. https://t.co/QP0cWYib1I
.@HeatherMahalik is back with another #TipTuesday - answering a topic that came up during our #C2CUserSummit.
Understanding how to properly keyword search in your tool is a required skill. Today she clarifies questions you may have when searching for multiple words.