Archives
- 18 May StudioSecGhost: A Browser-Piggyback hVNC Agent That Skips the Hidden Desktop
- 07 May PoolParty in the Wild (2026): Reversing Three Samples and Building Cross-Variant Detection
- 03 May GuLoader Through the NSIS Lens: Word-Salad Obfuscation, System.dll Plugin Abuse, and Decoy Padding
- 03 May Destover: The Sony-Signed Backdoor That Walked Through The Front Door
- 02 May Amadey cred64.dll: Reversing the v5.78 Credential-Stealer Plugin (botnet 54e64e)
- 26 Apr VerShadow / FUD Crypt: A MinGW VERSION.dll Carrier With A Catbox Fallback And A Live Test Payload
- 23 Apr A Gafgyt Variant Branded 'YakuzaBotnet': Walking Through an assailant.x86 ELF
- 22 Apr IRoveroll: A Telegram-Exfiltrating Infostealer Hiding Behind svchost
- 20 Apr Discord RAT 2.0: When Your C2 is a Chat Server
- 16 Apr Pony/Fareit: Inside the Credential Machine That Targeted 60+ FTP Clients
- 14 Apr ZyreC2: The Game-Obsessed Mirai Fork That Left Its Homework Out
- 13 Apr NanoCore RAT v1.2.2.0: Dissecting a Persistent Commercial Trojan
- 12 Apr Dissecting a Chaos/Ares Go Botnet: 12 DDoS Vectors, DNS C2, and 11 Linux Persistence Mechanisms
- 11 Apr Reversing a Custom Cipher to Extract Quasar RAT: From Raw Disassembly to Decrypted C2 Config
- 10 Apr DcRAT in 48KB: Cracking the Config, Mapping the Plugin Loader, and Why the Stub IS the Malware
- 09 Apr Cracking a .NET Crypter to Extract a Weaponized XWorm: Bootkit, Rootkit, and a Zero-Day UAC Bypass
- 08 Apr Backdoor.Win64.Gsb: A Go Implant Hiding Behind Nuclear Reactor Simulations
- 07 Apr njRAT v0.7d 'HacKed' Campaign: Config Extraction, C2 Protocol, and Full Capability Mapping
- 06 Apr Pulsar RAT .NET Reversing: C2 Protocol Recovery, Costura Extraction, and DPAPI Credential Theft Pipeline
- 06 Mar Kaiji-Like Linux ELF Reversing: Persistence, C2 Token Recovery, and Ares Module Mapping
- 25 Feb Mirai-like ELF Reversing, Part I: Stage1 Trust Gate, Command Dispatch, and Killer Loop
- 23 Feb Stage1 (22.exe) Loader Reversing, Part I: Stage Decryption, Evasion, and Attribution
- 20 Feb From log.dll To A Decrypted Chrysalis Main Module