Let’s talk reporting with the NSA and the FBI and friends
TA488 used CVE-2025-66376 for 5 months as a zero day, and for a few months after, to target education, gov, and nuclear entities in the US and Ukraine.
reports here:
https://t.co/8Bp9h1e2f5
https://t.co/AEFlv1qlLG
During my first red team operation, i got access to a guy’s mailbox. I still remember his Friday schedule where he had to take one of his kids to a swimming class. Feels nostalgic
The CEO called a town hall to announce our transition to a modern digital workspace.
He wants to replace our entire fleet of 2020 Dell laptops with brand new equipment.
He framed it as an investment in employee productivity.
I immediately recognized it as an existential threat to my peace and quiet.
Deploying 400 new machines means dealing with 400 unique human beings.
It means migrating local files for people who save all their passwords on a sticky note.
I scheduled an emergency closed-door meeting with the executive board.
I told them a hardware refresh right now would be corporate suicide.
The CFO asked why giving people faster computers is a bad idea.
I told him we are currently operating in a state of chronological hardware obfuscation.
I explained that modern ransomware is explicitly designed to exploit the silicon architecture of modern processors.
By keeping our workforce on hardware that is 6 years old, we are technically invisible to threat actors.
I said the laptops are so bogged down with legacy cache files that a virus physically cannot execute its payload in time.
Our inefficiency is our greatest defense mechanism.
The CEO looked deeply concerned and asked if upgrading would expose our intellectual property.
I nodded and whispered the phrase "silicon-level perimeter degradation."
They immediately canceled the hardware order.
They thanked me for prioritizing our data sovereignty over flashy aesthetics.
I spent the rest of the day in the server room watching a 3 part documentary on the history of the vending machine.
Sometimes doing absolutely nothing is the highest form of cybersecurity.
Our insurance provider forced us to undergo a third-party cybersecurity audit.
They sent a guy named Kevin who carried a clipboard and spoke entirely in compliance frameworks.
Kevin spent his first morning asking for our active directory topology.
I do not have an active directory topology.
My active directory is a chaotic swamp of deprecated user profiles from 2017.
I told Kevin that mapping the network creates a comprehensive blueprint for state-sponsored threat actors.
I explained that we utilize a Schrödinger network philosophy.
I told him the infrastructure exists in a state of quantum superposition where it is both perfectly secure and completely undocumented.
By refusing to map the network, we ensure that if we are ever breached, the hackers will be just as confused as we are.
Kevin looked at his clipboard and asked how we handle routine patch management.
I leaned over my desk and told him we employ a strategy of Darwinian software evolution.
I said we let the applications fight it out, and only the strongest legacy code survives.
He asked if I was joking.
I asked him if he was prepared to accept liability for interrupting an organic security ecosystem.
He crossed something off on his clipboard and moved on to physical security.
I took him to the data center and showed him an empty rack cabinet.
I told him it was an air-gapped honeypot designed to trap localized radio frequency interference.
He just nodded, completely broken, and went back to his car.
We passed the audit with a conditional green light.
If you come into my dojo I'm going to confuse you with buzzwords and fake urgency until you leave.
Missed BSides Pyongyang 2025? Every talk is now on YouTube. Over two weeks we'll spotlight each session — DPRK malware, crypto laundering, counterintel & attribution. Start here: https://t.co/XVCfYN1xSV
#BSidesPyongyang#BSPY25
@Octoberfest73@0xBoku Have used it . Even the registery edit works for persistence . I sometimes faced the issue you are mentioning. Most of the times it was due to the xll itself
@simplylurking2 Ship the least minimal capability . The one that makes you talk to your c2 and load other capabilities. While you do so, make it look like a legitimate app.
During an engagement, and in an effort to bypass Crowdstrike, I figured out a new method to locally privilege escalate when having code execution as a Microsoft Virtual account using only a LoLbin(certreq) and some AD-CS magic.
I was successfully able to compromise the target with Crowdstrike present without needing to use potatoe class exploits. I wrote a blog about it here! https://t.co/zywdv2ZQzN