www.proofpoint.com/us/blog/thre...
www.proofpoint.com/us/blog/thre...
➡️ compiled V8
➡️ we write a reusable hook script
➡️ we overcome basic anti-hooking
#MalwareAnalysisForHedgehogs #V8 #JavaScript
www.youtube.com/watch?v=Y8_A...
➡️ compiled V8
➡️ we write a reusable hook script
➡️ we overcome basic anti-hooking
#MalwareAnalysisForHedgehogs #V8 #JavaScript
www.youtube.com/watch?v=Y8_A...
If you ever heard or said "visiting websites can't infect you", "PDFs aren't malicious" or "exploits are rare and always targeted" this article might be for you.
blog.gdatasoftware.com/2026/07/3846...
#GDATATechBlog #GDATA
If you ever heard or said "visiting websites can't infect you", "PDFs aren't malicious" or "exploits are rare and always targeted" this article might be for you.
blog.gdatasoftware.com/2026/07/3846...
#GDATATechBlog #GDATA
➡️ V8 compilation pipeline
➡️ bytecode caching
➡️ how bytenode abuses caching for protection
www.youtube.com/watch?v=YSSC...
#MalwareAnalysisForHedgehogs #JavaScript #V8
➡️ V8 compilation pipeline
➡️ bytecode caching
➡️ how bytenode abuses caching for protection
www.youtube.com/watch?v=YSSC...
#MalwareAnalysisForHedgehogs #JavaScript #V8
FBI arrested the threat actor
www.techspot.com/news/113163-...
FBI arrested the threat actor
www.techspot.com/news/113163-...
I got a warning for cyber abuse with threats to shut down my account o.O
I got a warning for cyber abuse with threats to shut down my account o.O
AI notice: It's vibe-coded.
I manually analyzed ~20 drivers to verify and improve the output and tested with a corpus of ~100 drivers.
github.com/struppigel/h...
AI notice: It's vibe-coded.
I manually analyzed ~20 drivers to verify and improve the output and tested with a corpus of ~100 drivers.
github.com/struppigel/h...
Backdoor, obfuscated Python bytecode.
0/60 on Virustotal, which means it's still fresh.
www.virustotal.com/gui/file/4ad...
samplepedia.cc/sample/4ada6...
Backdoor, obfuscated Python bytecode.
0/60 on Virustotal, which means it's still fresh.
www.virustotal.com/gui/file/4ad...
samplepedia.cc/sample/4ada6...
➡️ kernel mode driver theory
➡️ Ghidra markup
➡️ basic string deobfuscation
#MalwareAnalysisForHedgehogs
www.youtube.com/watch?v=yx6A...
➡️ kernel mode driver theory
➡️ Ghidra markup
➡️ basic string deobfuscation
#MalwareAnalysisForHedgehogs
www.youtube.com/watch?v=yx6A...
PoisonX rootkit.
Video solution follows the next days.
samplepedia.cc/sample/db5d2...
PoisonX rootkit.
Video solution follows the next days.
samplepedia.cc/sample/db5d2...
The generated test files rely on real threat actor infrastructure to download or exfiltrate.
hxxps://github.com/DataDog/guarddog/blob/main/tests
The generated test files rely on real threat actor infrastructure to download or exfiltrate.
hxxps://github.com/DataDog/guarddog/blob/main/tests
www.virustotal.com/gui/file/e3b...
www.virustotal.com/gui/file/e3b...
➡️ AI debugs and unpacks with x64dbg
➡️ AI can access powershell terminal
www.youtube.com/watch?v=QrWz...
➡️ AI debugs and unpacks with x64dbg
➡️ AI can access powershell terminal
www.youtube.com/watch?v=QrWz...
malwareanalysis-for-hedgehogs.learnworlds.com/courses
malwareanalysis-for-hedgehogs.learnworlds.com/courses
After a brief contact to the threat actor, we talked to two victims and followed the trail.
Analysis in collaboration with @rifteyy
#GDATATechblog #GDATA
blog.gdatasoftware.com/2026/03/3839...
After a brief contact to the threat actor, we talked to two victims and followed the trail.
Analysis in collaboration with @rifteyy
#GDATATechblog #GDATA
blog.gdatasoftware.com/2026/03/3839...
➡️ old system, 16 GB RAM
➡️ using Remnux
#MalwareAnalysisForHedgehogs #LLM
www.youtube.com/watch?v=YOdu...
➡️ old system, 16 GB RAM
➡️ using Remnux
#MalwareAnalysisForHedgehogs #LLM
www.youtube.com/watch?v=YOdu...
➡️ #MythJs stealer sample
➡️ pkg VFS exploration tool
➡️ js-confuser
#MalwareAnalysisForHedgehogs
www.youtube.com/watch?v=gtLq...
➡️ #MythJs stealer sample
➡️ pkg VFS exploration tool
➡️ js-confuser
#MalwareAnalysisForHedgehogs
www.youtube.com/watch?v=gtLq...
💡Tips for building an autonomous AI analysis lab on a 12 yo laptop and getting stuff done faster without loss of accuracy.
blog.gdatasoftware.com/2026/03/3838...
💡Tips for building an autonomous AI analysis lab on a 12 yo laptop and getting stuff done faster without loss of accuracy.
blog.gdatasoftware.com/2026/03/3838...
#kurdishmyth stealer, NodeJS
➡️Infects discord_desktop_core\index.js
➡️Steals various browser and discord data.
➡️Exfiltrates via discord webhook.
The code references kurdishmyth and mythprivate
www.virustotal.com/gui/file/496...
#kurdishmyth stealer, NodeJS
➡️Infects discord_desktop_core\index.js
➡️Steals various browser and discord data.
➡️Exfiltrates via discord webhook.
The code references kurdishmyth and mythprivate
www.virustotal.com/gui/file/496...
It provides some tools for HijackLoader too.
blog.gdatasoftware.com/2026/02/3837...
It provides some tools for HijackLoader too.
blog.gdatasoftware.com/2026/02/3837...
You have now a new "My articles" overview (see profile dropdown menu), which allows you to add article drafts and manage articles.
You can decide to publish such a draft as a solution later.
You have now a new "My articles" overview (see profile dropdown menu), which allows you to add article drafts and manage articles.
You can decide to publish such a draft as a solution later.
The LLM complied and generated malicious test files...
github.com/Cobenian/sha...
The LLM complied and generated malicious test files...
github.com/Cobenian/sha...
Script (modified pyinstxtractor-ng): github.com/struppigel/h...
Article: samplepedia.cc/sample/8c9d9...
Script (modified pyinstxtractor-ng): github.com/struppigel/h...
Article: samplepedia.cc/sample/8c9d9...