I took a look at the #rekoobe#linux backdoor and wrote a blog post about how to recover the C2 details from the sample. I also wrote a config extractor to automate the process: https://t.co/eYeJmAmW5S
#malware#radare2
With some guidance from @DebugPrivilege I've found a way to easily dump clear text implants even while they sleep. Bad day for sleep obfuscation 💤
https://t.co/GpNQS6yMjl
Ok I think this is REALLY cool, I've now got Event Tracing for Windows: Threat Intelligence working with my EDR (not implemented yet into the main EDR) BUT you can see it catching remote memory allocations https://t.co/89X8HHoGJS
#malware#blueteam#redteam#infosec#cyber#rust
Check out my new blog post on declawing PUMAKIT, a sneaky #LKM#rootkit targeting Linux systems. Find out how it hides, escalates privileges, and stays under the radar. Don’t miss the deep-dive! https://t.co/PPkDQ3h4EU #cybersecurity#malwareanalysis#linux
I took a look at the #rekoobe#linux backdoor and wrote a blog post about how to recover the C2 details from the sample. I also wrote a config extractor to automate the process: https://t.co/eYeJmAmW5S
#malware#radare2
A threat actor testing an AV/EDR bypass tool on rogue virtual machines inadvertently exposed their methods. This allowed us a deep dive into their operational strategies and multiple toolkits, including tracing their steps to cybercrime forums. Read now: https://t.co/QiR8jM3zv8
Read our latest blog post and get an inside look at Warmcookie’s updated C2 infrastructure linked to its latest update. 📡
We reveal insights into newly identified servers that can assist defenders in identifying related servers
https://t.co/EKYVXcKXUk
Had fun presenting #WARMCOOKIE research at #VB2024. The malware was recently updated with new handlers. Our team wrote some tooling to simulate the C2 server to help organizations build better detections.
Tooling: https://t.co/GTeVTLDAaU
I took a look at a #warmcookie infection, and wrote an investigation walk-through using a #PCAP from @malware_traffic, check it out: https://t.co/lUPWJxB2sb
The Return of OceanLotus?
During routine threat hunting here at @HuntressLabs analysts @CyberRaiju & @bumbucha identified a sophisticated campaign with hallmark TTPs of APT32 aka BISMUTH, Ocean Buffalo, & Canvas Cyclone targeting human rights activists
https://t.co/25KSyDgUnA
.@Volexity shares #threatintel on how #StormBamboo compromised an ISP to conduct DNS poisoning attacks on targeted organizations & abuse insecure HTTP software updates, delivering custom malware on both macOS + Windows.
Read the full analysis: https://t.co/iqAH1PgVVz
#dfir
Exec at Ferrari gets a call from "CEO" asking about acquisitions. Exec realizes that this could be a voice clone & asks the "CEO" which book they just talked about, catching the attacker!
Thanks @FortuneMagazine for talking with me about AI voice clones.
https://t.co/oxKnS6ZXvi
Here is a little Linux detection telemetry tool I released as part of my Black Hat Arsenal presentation 'ELFieScanner: Advanced process memory threat detection on Linux' #BlackHat:
https://t.co/3FrHxjq4Jp
Happy Friday! I have gotten a lot of questions around ETW Patching as of late. I decided to write a blog on understanding ETW Patching, check it out!
https://t.co/s8DJhI7zTH
Not sure who needs to hear this, but I was today years old when I realized how effective conditional breakpoints in x64dbg are.. I had a need to break conditionally on all VirtualAlloc calls with a size parameter > 0x3000000. Here is how to do this.😎
@malware_traffic Part 3 looking into #icedid#malware - https://t.co/tPpokyh4j9
In this post I go through the unpacking routine to reveal an injected PE file.
The extracted shellcode and the final PE file available to download, find links in the blog post.
I finally wrote my first blog post. Carving up an #icedid PCAP from @malware_traffic Diving into tshark, pivoting and enriching my way through, hope you enjoy. https://t.co/6jDJG76V3u
@malware_traffic Part 2 of my adventures carving the #icedid: https://t.co/pQtuss7025
Massively delayed due to the research for part 3 taking quite a while, it's in progress...until then, I hope you enjoy this instalment.
🕵️♂️ The silent torrent of VileRAT
Get an in-depth, technical look at #VileRAT, a sophisticated Python-based malware believed to be the work of the #Evilnum threat group.
Read our latest #threatresearch report here: https://t.co/gLU4ULkzPD