<feed xmlns="http://www.w3.org/2005/Atom"> <id>https://taogoldi.github.io/reverse-engineer/</id> <title>Reverse Engineer</title> <subtitle>Public malware reversing write-ups, unpacking workflows, and reproducible analysis artifacts.</subtitle> <updated>2026-09-01T19:23:04-04:00</updated> <author> <name>Tao Goldi</name> <uri>https://taogoldi.github.io/reverse-engineer/</uri> </author> <link rel="self" type="application/atom+xml" href="https://taogoldi.github.io/reverse-engineer/feed.xml"/> <link rel="alternate" type="text/html" hreflang="en" href="https://taogoldi.github.io/reverse-engineer/"/> <generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator> <rights> © 2026 Tao Goldi </rights> <icon>/reverse-engineer/assets/img/favicons/favicon.ico</icon> <logo>/reverse-engineer/assets/img/favicons/favicon-96x96.png</logo> <entry> <title>AnimateClipper: A NativeAOT Loader That Hides C# From Every .NET Tool You Own</title> <link href="https://taogoldi.github.io/reverse-engineer/blog/animateclipper-nativeaot-loader/" rel="alternate" type="text/html" title="AnimateClipper: A NativeAOT Loader That Hides C# From Every .NET Tool You Own" /> <published>2026-08-31T20:00:00-04:00</published> <updated>2026-08-31T20:00:00-04:00</updated> <id>https://taogoldi.github.io/reverse-engineer/blog/animateclipper-nativeaot-loader/</id> <content type="text/html" src="https://taogoldi.github.io/reverse-engineer/blog/animateclipper-nativeaot-loader/" /> <author> <name>Tao Goldi</name> </author> <category term="malware-reversing" /> <category term="threat-intel" /> <summary>A NativeAOT stage-1 loader that dnSpy and ILSpy cannot read, taken apart statically: two hand-rolled keystream ciphers over its API name table, a CMSTPLUA elevation-moniker UAC bypass, a self-copy into Startup, and a full manual PE loader that hollows a signed Microsoft binary. Includes the recovered stage-2 cipher, its static 256-bit key and nonce, five YARA rules measured against 2,977 corpus samples, and the retrohunt that pushed the family's first observed build back ten weeks.</summary> </entry> <entry> <title>VioletRAT v6: A WinRAR-Spoofed VB.NET RAT With a 110-Command C2</title> <link href="https://taogoldi.github.io/reverse-engineer/blog/violetrat-v6-winrar-vbnet-rat/" rel="alternate" type="text/html" title="VioletRAT v6: A WinRAR-Spoofed VB.NET RAT With a 110-Command C2" /> <published>2026-06-24T20:00:00-04:00</published> <updated>2026-06-24T20:00:00-04:00</updated> <id>https://taogoldi.github.io/reverse-engineer/blog/violetrat-v6-winrar-vbnet-rat/</id> <content type="text/html" src="https://taogoldi.github.io/reverse-engineer/blog/violetrat-v6-winrar-vbnet-rat/" /> <author> <name>Tao Goldi</name> </author> <category term="malware-reversing" /> <category term="threat-intel" /> <summary>Static teardown of VioletRAT v6 (VioletWorm), a VB.NET commodity RAT misclassified as AsyncRAT. Recovers the Base64+XOR string layer, the AES-128-ECB C2 protocol, embedded C2 195.63.145[.]169:7000, the ~110-command dispatcher, and an in-memory AMSI bypass. Ships an offline decoder, a capture-only C2 client, and four YARA rules.</summary> </entry> <entry> <title>StudioSecGhost: A Browser-Piggyback hVNC Agent That Skips the Hidden Desktop</title> <link href="https://taogoldi.github.io/reverse-engineer/blog/studiosecghost-hvnc-browser-piggyback/" rel="alternate" type="text/html" title="StudioSecGhost: A Browser-Piggyback hVNC Agent That Skips the Hidden Desktop" /> <published>2026-05-18T20:00:00-04:00</published> <updated>2026-05-18T20:00:00-04:00</updated> <id>https://taogoldi.github.io/reverse-engineer/blog/studiosecghost-hvnc-browser-piggyback/</id> <content type="text/html" src="https://taogoldi.github.io/reverse-engineer/blog/studiosecghost-hvnc-browser-piggyback/" /> <author> <name>Tao Goldi</name> </author> <category term="malware-reversing" /> <category term="threat-intel" /> <summary>Full static teardown of StudioSecGhost, a novel native x64 hVNC agent that piggybacks on Chrome/Edge/Firefox via per-window ghost cloaking, skipping CreateDesktopW entirely. C2: 2.26.122[.]211:4444. Pure disassembly, no sandbox required.</summary> </entry> <entry> <title>PoolParty in the Wild (2026): Reversing Three Samples and Building Cross-Variant Detection</title> <link href="https://taogoldi.github.io/reverse-engineer/blog/poolparty-itw-2026/" rel="alternate" type="text/html" title="PoolParty in the Wild (2026): Reversing Three Samples and Building Cross-Variant Detection" /> <published>2026-05-07T20:00:00-04:00</published> <updated>2026-05-07T20:00:00-04:00</updated> <id>https://taogoldi.github.io/reverse-engineer/blog/poolparty-itw-2026/</id> <content type="text/html" src="https://taogoldi.github.io/reverse-engineer/blog/poolparty-itw-2026/" /> <author> <name>Tao Goldi</name> </author> <category term="malware-reversing" /> <category term="threat-intel" /> <summary>Three real-world PoolParty samples reverse-engineered end to end. Sample A is a 50 KB TP_DIRECT dropper that incidentally defeats capa's nursery TP_WORK rule; Sample B is the canonical SafeBreach research build with all eight variants and boost::log phase strings still in the binary; Sample C is a March 2026 ITW campaign artifact whose .text is byte-identical to Sample B after trim, wrapped in a hasherezade pe_to_shellcode reflective loader with a malformed-MZ trampoline. Includes a cross-variant YARA rule with four detection paths, five draft capa nursery candidates for the variants no one has rules for, and a CRC32-IEEE-802.3 API-hash reverser for the wrapper.</summary> </entry> <entry> <title>GuLoader Through the NSIS Lens: Word-Salad Obfuscation, System.dll Plugin Abuse, and Decoy Padding</title> <link href="https://taogoldi.github.io/reverse-engineer/blog/guloader-nsis-shellcode-loader/" rel="alternate" type="text/html" title="GuLoader Through the NSIS Lens: Word-Salad Obfuscation, System.dll Plugin Abuse, and Decoy Padding" /> <published>2026-05-03T20:00:00-04:00</published> <updated>2026-05-03T20:00:00-04:00</updated> <id>https://taogoldi.github.io/reverse-engineer/blog/guloader-nsis-shellcode-loader/</id> <content type="text/html" src="https://taogoldi.github.io/reverse-engineer/blog/guloader-nsis-shellcode-loader/" /> <author> <name>Tao Goldi</name> </author> <category term="malware-reversing" /> <category term="threat-intel" /> <summary>Reversing a 2025 GuLoader (CloudEye) NSIS-3 build that drops 19 files into %TEMP% under 17.6 MB of constant-byte sandbox-bypass padding, builds Windows API names from random Danish nouns to call through the System.dll plugin, decodes a 4-byte-XOR'd shellcode container, hash-resolves 31 APIs, and stages an MPRESS-packed Remcos 7.2.3 Pro from Google Drive that beacons raw TCP to 31.57.184.186:2404.</summary> </entry> </feed>
