MetaStealer Part 2, Google Cookie Refresher Madness and Stealer Drama
MetaStealer Part 2 Malware Analysis
Browse posts by topic.
All posts tagged with Malware Analysis.
All posts tagged with Reverse Engineering.
All posts tagged with Threat Intelligence.
MetaStealer Part 2 Malware Analysis
WhiteSnake Stealer malware analysis
Looking into the abuse of ITarian RMM and introducing Dolphin Loader
Meduza Stealer malware analysis
First promoted as the “Triple Culture” Team and later rebranded as the Wagmi Team, this traffer group has been operating since at least, early 2023. One...
Ransomware gets the headlines because it's loud: it kicks the door wide open, encrypts everything, and leaves a "love" note, and the bill for the week or...
A teardown of Weyhro C2, a new command-and-control framework advertised on a cybercrime forum as an "advanced pentesting toolkit."
First promoted as the “Triple Culture” Team and later rebranded as the Wagmi Team, this traffer group has been operating since at least, early 2023. One...
This blog was written in collaboration with @g0njxa ❤ Together, we will explore the CryptoLove traffer’s team and look into their methods of operation.
The SMOKEDHAM backdoor has been active since 2019 and has been observed being distributed by the threat actor Mandiant identifies as UNC2465. This...
A teardown of Weyhro C2, a new command-and-control framework advertised on a cybercrime forum as an "advanced pentesting toolkit."
StealC is one of the well-known stealers written in C++ that has been active since 2022. In April 2025 after the release of the StealC v2 version, the...
LegionLoader is a downloader malware written in C/C++ that first appeared in the wild in 2019. It is also known by other names, including Satacom and...
This blog was written in collaboration with @g0njxa ❤ Together, we will explore the CryptoLove traffer’s team and look into their methods of operation.
The SMOKEDHAM backdoor has been active since 2019 and has been observed being distributed by the threat actor Mandiant identifies as UNC2465. This...
Looking into the abuse of ITarian RMM and introducing Dolphin Loader
Ransomware gets the headlines because it's loud: it kicks the door wide open, encrypts everything, and leaves a "love" note, and the bill for the week or...
Looking into the abuse of ITarian RMM and introducing Dolphin Loader
Ransomware gets the headlines because it's loud: it kicks the door wide open, encrypts everything, and leaves a "love" note, and the bill for the week or...
A teardown of Weyhro C2, a new command-and-control framework advertised on a cybercrime forum as an "advanced pentesting toolkit."
StealC is one of the well-known stealers written in C++ that has been active since 2022. In April 2025 after the release of the StealC v2 version, the...
First promoted as the “Triple Culture” Team and later rebranded as the Wagmi Team, this traffer group has been operating since at least, early 2023. One...
LegionLoader is a downloader malware written in C/C++ that first appeared in the wild in 2019. It is also known by other names, including Satacom and...
This blog was written in collaboration with @g0njxa ❤ Together, we will explore the CryptoLove traffer’s team and look into their methods of operation.
The SMOKEDHAM backdoor has been active since 2019 and has been observed being distributed by the threat actor Mandiant identifies as UNC2465. This...
Ransomware gets the headlines because it's loud: it kicks the door wide open, encrypts everything, and leaves a "love" note, and the bill for the week or...
LegionLoader is a downloader malware written in C/C++ that first appeared in the wild in 2019. It is also known by other names, including Satacom and...
This blog was written in collaboration with @g0njxa ❤ Together, we will explore the CryptoLove traffer’s team and look into their methods of operation.
The SMOKEDHAM backdoor has been active since 2019 and has been observed being distributed by the threat actor Mandiant identifies as UNC2465. This...
Looking into the abuse of ITarian RMM and introducing Dolphin Loader
MetaStealer Part 2 Malware Analysis
WhiteSnake Stealer malware analysis
Meduza Stealer malware analysis
Meduza Stealer malware analysis
MetaStealer Part 2 Malware Analysis
StealC is one of the well-known stealers written in C++ that has been active since 2022. In April 2025 after the release of the StealC v2 version, the...
LegionLoader is a downloader malware written in C/C++ that first appeared in the wild in 2019. It is also known by other names, including Satacom and...
First promoted as the “Triple Culture” Team and later rebranded as the Wagmi Team, this traffer group has been operating since at least, early 2023. One...
StealC is one of the well-known stealers written in C++ that has been active since 2022. In April 2025 after the release of the StealC v2 version, the...
MetaStealer Part 2 Malware Analysis
WhiteSnake Stealer malware analysis
Meduza Stealer malware analysis
Ransomware gets the headlines because it's loud: it kicks the door wide open, encrypts everything, and leaves a "love" note, and the bill for the week or...
A teardown of Weyhro C2, a new command-and-control framework advertised on a cybercrime forum as an "advanced pentesting toolkit."
WhiteSnake Stealer malware analysis
New malware breakdowns, threat research, and IOCs. No fluff, just the analysis.
→ Zero spam. Unsubscribe anytime.
By subscribing you agree that we process your data to send you our newsletter. No third parties, no ads. Ever.