#Sshdinjector
-Five Eyes releases guide on securing edge devices
-SmokeLoader abuses 7-Zip zero-day
-Malware reports on ValleyRAT, FleshStealer, FlexibleFerret, Sshdinjector
-AMD Zen vulnerability impacts the cloud
-Unpatched Sysinternals vulns
-Supply chain attack via S3 buckets
-BSides London and Belfast videos
February 5, 2025 at 10:44 AM
Analyzing ELF/Sshdinjector (IoT bot) with r2ai.

Really helpful and time save to use AI (with r2ai) for analysis *but* use it with a non-AI decompiler side by side:

1. To direct the AI
2. To spot more easily hallucinations or extrapolations.

www.fortinet.com/blog/threat-...

#r2ai #IoT #botnet #AI
Analyzing ELF/Sshdinjector.A!tr with a Human and Artificial Analyst | FortiGuard Labs
FortiGuard Labs reverse engineers a malware’s binaries to look into what the malware is actually doing.…
www.fortinet.com
February 6, 2025 at 8:34 AM
#Sshdinjector is a #backdoor which injects itself into the SSH daemon, & is used by the #Daggerfly #APT group for espionage purposes. Don't become a victim, deploy our public #YARArules: github.com/reversinglab...

#Malware #Cybersecurity
GitHub - reversinglabs/reversinglabs-yara-rules: ReversingLabs YARA Rules
ReversingLabs YARA Rules. Contribute to reversinglabs/reversinglabs-yara-rules development by creating an account on GitHub.
github.com
March 28, 2025 at 6:41 PM