Shadow HVNC and Shadow Loader: The Kit That Protects Its License Better Than Its Customers
Ransomware gets the headlines because it's loud: it kicks the door wide open, encrypts everything, and leaves a "love" note, and the bill for the week or...
Thoughts, tutorials, and deep dives on software development, systems, and everything in between.
Ransomware gets the headlines because it's loud: it kicks the door wide open, encrypts everything, and leaves a "love" note, and the bill for the week or...
A teardown of Weyhro C2, a new command-and-control framework advertised on a cybercrime forum as an "advanced pentesting toolkit."
StealC is one of the well-known stealers written in C++ that has been active since 2022. In April 2025 after the release of the StealC v2 version, the...
First promoted as the “Triple Culture” Team and later rebranded as the Wagmi Team, this traffer group has been operating since at least, early 2023. One...
LegionLoader is a downloader malware written in C/C++ that first appeared in the wild in 2019. It is also known by other names, including Satacom and...
This blog was written in collaboration with @g0njxa ❤ Together, we will explore the CryptoLove traffer’s team and look into their methods of operation.
The SMOKEDHAM backdoor has been active since 2019 and has been observed being distributed by the threat actor Mandiant identifies as UNC2465. This...
Looking into the abuse of ITarian RMM and introducing Dolphin Loader
GlorySprout malware analysis
Technical Analysis of Atomic Stealer
MetaStealer Part 2 Malware Analysis
Pure Logs Stealer malware analysis
MetaStealer malware analysis
WhiteSnake Stealer malware analysis
Meduza Stealer malware analysis
No posts match this filter.
New malware breakdowns, threat research, and IOCs. No fluff, just the analysis.
→ Zero spam. Unsubscribe anytime.
By subscribing you agree that we process your data to send you our newsletter. No third parties, no ads. Ever.