YungBinary's profile picture. Malware Research @eSentire

YungBinary

@YungBinary

Malware Research @eSentire

Fixado

New blog on #ChaosBot! A novel Rust-based backdoor that uses Discord for C2 and supports commands like shell (execute powershell commands), scr (screenshot), download (download files to victim device), and upload (exfiltrate files from victim device). esentire.com/blog/new-rust-…

YungBinary's tweet image. New blog on #ChaosBot! A novel Rust-based backdoor that uses Discord for C2 and supports commands like shell (execute powershell commands), scr (screenshot), download (download files to victim device), and upload (exfiltrate files from victim device).

esentire.com/blog/new-rust-…

New malware analysis blog on #DarkCloud, an infostealer written in VB6 + a config extractor and string decryption tool for IDA Pro! esentire.com/blog/eye-of-th…

YungBinary's tweet image. New malware analysis blog on #DarkCloud, an infostealer written in VB6 + a config extractor and string decryption tool for IDA Pro!

esentire.com/blog/eye-of-th…
YungBinary's tweet image. New malware analysis blog on #DarkCloud, an infostealer written in VB6 + a config extractor and string decryption tool for IDA Pro!

esentire.com/blog/eye-of-th…

YungBinary repostou

Check out the latest @recordedfuture report from @JulianVoeg , Marius, and me on TAG-150, where we break down CastleLoader and CastleRAT (Python + C variants). Recent TTP: C2 deaddrops on Steam Community pages, marking a new infrastructure tactic 🔗recordedfuture.com/research/from-…

_whoisnt's tweet image. Check out the latest @recordedfuture report from @JulianVoeg , Marius, and me on TAG-150, where we break down CastleLoader and CastleRAT (Python + C variants). 

Recent TTP: C2 deaddrops on Steam Community pages, marking a new infrastructure tactic 

🔗recordedfuture.com/research/from-…

New blog is out on #NightshadeC2! Newly discovered botnet with capabilities like reverse shell, password/cookie theft, remote control, and more. Loader relies on UAC Prompt Bombing to force victims into excluding payload in Windows Defender! esentire.com/blog/new-botne…

YungBinary's tweet image. New blog is out on #NightshadeC2!

Newly discovered botnet with capabilities like reverse shell, password/cookie theft, remote control, and more. Loader relies on UAC Prompt Bombing to force victims into excluding payload in Windows Defender!

esentire.com/blog/new-botne…
YungBinary's tweet image. New blog is out on #NightshadeC2!

Newly discovered botnet with capabilities like reverse shell, password/cookie theft, remote control, and more. Loader relies on UAC Prompt Bombing to force victims into excluding payload in Windows Defender!

esentire.com/blog/new-botne…

New blog on #Sinobi ransomware! They used an MSP's compromised SonicWall SSL VPN creds for initial access. Decryption is impossible w/o the attacker's private key, unless of course you hooked CryptGenRandom😜 esentire.com/blog/threat-ac…

YungBinary's tweet image. New blog on #Sinobi ransomware! They used an MSP's compromised SonicWall SSL VPN creds for initial access. Decryption is impossible w/o the attacker's private key, unless of course you hooked CryptGenRandom😜

esentire.com/blog/threat-ac…

United States Tendências

Loading...

Something went wrong.


Something went wrong.