CATEGORIES

Malware

ReaderUpdate Reforged: Melting Pot of macOS Malware Adds Go to Crystal, Nim and Rust Variants

ReaderUpdate is a macOS malware loader platform that, despite having been in the wild since at least 2020, has passed...

less than 1 minute read

BlueNoroff Hidden Risk: Threat Actor Targets Macs with Fake Crypto News and Novel Persistence

SentinelLabs has observed a suspected DPRK threat actor targeting Crypto-related businesses with novel multi-stage ma...

less than 1 minute read

Gold Pickaxe iOS Technical Analysis: IPA Overview and C2 Communication Start up

In February 2024 Group-IB wrote a blog post about a mobile Trojan developed by a Chinese-speaking cybercrimine group ...

13 minute read

Atomic macOS Stealer (AMOS) Analysis

Hello everybody, this is my first macOS malware analysis, I took a sample from malwarebazaar and tried to reverse it,...

12 minute read

Rustware Part 3: Dynamic API resolution (Windows)

In the previous blog post we have seen how to perform a shellcode process injection by finding a target process PID u...

12 minute read

Rustware Part 2: Process Enumeration Development (Windows)

In the previous blog post we have seen how to develop a Shellcode Process Injection in Rust; the described Process In...

10 minute read

Rustware Part 1: Shellcode Process Injection Development (Windows)

Malware development is essential when performing activities like Red Teaming, Adversary Emulation and Network Penetra...

12 minute read

QAKBOT BB Configuration and C2 IPs List

On September 30, 2022 a friend of mine received a phishing email pretending to be sent by one of his customers, the e...

4 minute read

Emotet Malicious Excel Analysis

Sometime ago a friend of mine sent me a suspicious email containg a zip file with an xls, at the time I didn't focus ...

1 minute read

Back to top ↑

CTF

Back to top ↑

HackTheBox

Back to top ↑

iOS

Back to top ↑

macOS

Back to top ↑

Rustware

Back to top ↑

Windows

Back to top ↑

IoT

Back to top ↑

Binary

Back to top ↑

Vulnerability

Back to top ↑