reib3n1's profile picture. Malware Researcher at ESET LATAM

reib3n

@reib3n1

Malware Researcher at ESET LATAM

reib3n reposted

#ESETresearch has discovered #HybridPetya ransomware on VirusTotal: a UEFI-compatible copycat of the infamous Petya/NotPetya malware. HybridPetya is capable of bypassing UEFI Secure Boot on outdated systems. @smolar_m welivesecurity.com/en/eset-resear… 1/8


reib3n reposted

#ESETresearch uncovers GhostRedirector, a threat actor compromising Windows servers with a C++ Backdoor named Rungan and Gamshen, a native IIS malware welivesecurity.com/en/eset-resear… 1/6


reib3n reposted

The embargo (12:00 UTC 2025-06-10) is over, let's start a thread on Hydroph0bia (CVE-2025-4275), a trivial SecureBoot and FW updater signature bypass in almost any Insyde H2O-based UEFI firmware used since 2012 and still in use today. English writeup: coderush.me/hydroph0bia-pa…


reib3n reposted

#ESETresearch analyzed a campaign deployed by BladedFeline, an 🇮🇷-aligned threat actor with likely ties to #OilRig. We discovered the campaign, which targeted Kurdish and 🇮🇶 government officials, in 2024. welivesecurity.com/en/eset-resear… 1/6


reib3n reposted

Another pointless weekend project - a playable version of the old 3DMaze screensaver from Windows 9x. I reverse-engineered the original screensaver binary and added user-input functionality for the controls (and fixed some other minor issues!) github.com/x86matthew/Pla…


reib3n reposted

Spotted another "Living off the..." project in the wild - LOTTunnels lottunnels.github.io


reib3n reposted

🚨NEW from Binarly: "LogoFAIL Exploited to Deploy Bootkitty, the first UEFI bootkit for Linux". We found a direct connection between the newly discovered #Bootkitty Linux bootkit and in-the-wild weaponized exploitation of the #LogoFAIL vulnerability. binarly.io/blog/logofail-…

binarly_io's tweet image. 🚨NEW from Binarly: "LogoFAIL Exploited to Deploy Bootkitty, the first UEFI bootkit for Linux".  

We found a direct connection between the newly discovered #Bootkitty Linux bootkit and in-the-wild weaponized exploitation of the #LogoFAIL vulnerability.

binarly.io/blog/logofail-…

reib3n reposted

#ESETresearch reveals the first Linux UEFI bootkit, Bootkitty. It disables kernel signature verification and preloads two ELFs unknown during our analysis. Also discovered, a possibly related unsigned LKM – both were uploaded to VT early this month. welivesecurity.com/en/eset-resear… 1/5


reib3n reposted

#ESETresearch discovered an #exploit targeting Firefox and Windows zero days, used in the wild by Russia-aligned #RomCom. Browsing a specially crafted web page runs arbitrary code with the privileges of the user, compromising the PC. @dmnsch & R.Dumont welivesecurity.com/en/eset-resear… 1/7

ESETresearch's tweet image. #ESETresearch discovered an #exploit targeting Firefox and Windows zero days, used in the wild by Russia-aligned #RomCom. Browsing a specially crafted web page runs arbitrary code with the privileges of the user, compromising the PC. @dmnsch & R.Dumont welivesecurity.com/en/eset-resear… 1/7

reib3n reposted

#ESET research has identified #Linux malware samples, one of which we named #WolfsBane and attribute with high confidence to #Gelsemium. This 🇨🇳 China-aligned APT group , active since 2014, has not previously been publicly reported to use Linux malware. welivesecurity.com/en/eset-resear…


reib3n reposted

#ESETresearch investigated two previously undocumented toolsets used by the #GoldenJackal APT group, both of which target air-gapped systems. welivesecurity.com/en/eset-resear… 1/6


reib3n reposted

ESETresearch discovered a zero-day exploit of #Telegram for Android allowing attackers to share malicious payloads that appear as video files via chat. We named the vulnerability being exploited #EvilVideo. welivesecurity.com/en/eset-resear… @lukasstefanko 1/4

ESETresearch's tweet image. ESETresearch discovered a zero-day exploit of #Telegram for Android allowing attackers to share malicious payloads that appear as video files via chat. We named the vulnerability being exploited #EvilVideo. welivesecurity.com/en/eset-resear… @lukasstefanko 1/4

reib3n reposted

CrowdStrike has performed the largest ransomware attack in history. Accidentally.


Loading...

Something went wrong.


Something went wrong.