Drew's Avatar

Drew

@bugfire.io.bsky.social

malware detection and analysis, hunting and gathering, threat research

113 Followers  |  151 Following  |  273 Posts  |  Joined: 01.07.2023  |  2.1885

Latest posts by bugfire.io on Bluesky

No pun intended

08.08.2025 15:49 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

I would say that phishing is also social engineering, but agree this new โ€œhelp deskโ€ style social engineering is the next level and so very effective!

06.08.2025 00:55 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Bing is still giving search results for opmanager[.]pro ...sigh...

05.08.2025 18:03 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Another day, another loader becoming a full-on ransomware dropper ๐Ÿ™ƒ

๐Ÿ“ข First public attribution of Bumblebee โžก๏ธ Akira ransomware
โžก๏ธ ๐๐ฎ๐ฆ๐›๐ฅ๐ž๐›๐ž๐ž โ†’ ๐€๐๐š๐ฉ๐ญ๐— ๐‚2 โ†’ ๐€๐ค๐ข๐ซ๐š ๐ซ๐š๐ง๐ฌ๐จ๐ฆ๐ฐ๐š๐ซ๐ž

- Starts with Bing malvertising
โ†ช๏ธ Moves through custom loader (AdaptX)
โ†ช๏ธ Ends in Akira Ransomware
1/2

05.08.2025 16:50 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 0

Heading into the week the right way!

04.08.2025 01:18 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Late night, thanks for sharing

02.08.2025 02:42 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

2025-08-01 (Friday): Some info on a #LummaStealer example I found today:

github.com/malware-traf...

#Lumma

02.08.2025 02:30 โ€” ๐Ÿ‘ 1    ๐Ÿ” 2    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

The least they can do

31.07.2025 21:59 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Reversing Mac Malware with L0Psec: Live ARM64 Analysis & Latest Trends Ready to reverse Mac Malware? Today's guest is L0Psec, who joins the stream to talk about reversing the latest mac malware, discuss some current trends and s...

๐Ÿ”ฅ Live stream starts in an hour - we're reversing Mac malware with L0psec!

Join us on YouTube ๐Ÿ‘‰ youtube.com/live/w3ifC_U...

31.07.2025 20:02 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Ahh but that runs counter to you wanting to do IR 24/7

31.07.2025 19:59 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Dynamic Malware Analysis: Tools & Workflow (Amadey Malware)
YouTube video by Anuj Soni Dynamic Malware Analysis: Tools & Workflow (Amadey Malware)

New video from @anujsoni.bsky.social on dynamic analysis workflow is up! youtu.be/_loQ63eGQLM?...

31.07.2025 13:02 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Very cool!

31.07.2025 04:33 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

๐Ÿคฃ

31.07.2025 04:32 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

This is quite interesting having 2 instances of Remcos for redundancy

31.07.2025 03:50 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Hey there dahlia!

31.07.2025 02:10 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

It is Wednesday so feels right

30.07.2025 23:12 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

That's the kind of audience you want, already paranoid!

29.07.2025 21:26 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
ARM64 Malware & Exploits Unraveled with Saumil Shah Join us for a captivating live stream with Saumil Shah, cybersecurity legend and founder of Net-Square, as we dive into the world of ARM64 malware and exploi...

๐Ÿ”ฅ Live stream with Saumil Shah starts in an hour - we'll be discussing ARM64, exploits and whole lot more!

Join us on YouTube ๐Ÿ‘‰ youtube.com/live/o0-rMG0...

29.07.2025 15:02 โ€” ๐Ÿ‘ 3    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Need to go full Scattered Bajiri on them

27.07.2025 03:34 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

๐Ÿš€ Live stream double-header next week!

July 29 @ 11am CDT - Saumil Shah joins the stream to talk ARM, exploits and more!
๐Ÿ‘‰ youtube.com/live/o0-rMG0...

July 31 @ 4pm CDT - L0psec returns to do some live mac malware reversing!
๐Ÿ‘‰ youtube.com/live/w3ifC_U...

26.07.2025 19:20 โ€” ๐Ÿ‘ 3    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Hey there Delilahโ€ฆerr dahlia

25.07.2025 03:45 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Agree, we all need to get off our RaaS and start spending quality time getting things moving with it.

22.07.2025 20:32 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Pay this man!

22.07.2025 02:07 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Nice work, thanks for sharing

21.07.2025 22:39 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

You bet your RaaS they are!

21.07.2025 19:55 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Lol

21.07.2025 18:02 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Tap in to the stream this week for some YARA fun, highlighting some crazy rules, how I think about learning yara (or anything) as a mid-career professional, and more!

21.07.2025 17:06 โ€” ๐Ÿ‘ 14    ๐Ÿ” 6    ๐Ÿ’ฌ 3    ๐Ÿ“Œ 0

Iโ€™m thinking karaoke possiblyโ€ฆ

21.07.2025 18:00 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
Learn and test SPF, DKIM and DMARC Visualize, analyze and improve your email authentication setup

Ohhhโ€ฆon this weekโ€™s @smashingsecurity.com podcast @grahamcluley.com recommended a service called Learn DMARC for testing DMARC configuration and it is excellent.

20.07.2025 11:15 โ€” ๐Ÿ‘ 16    ๐Ÿ” 3    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

I really appreciated both yours and Mattโ€™s Q/A answers as being very thoughtful and complete. Looking forward to getting the recording soon as well.

17.07.2025 19:33 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

@bugfire.io is following 20 prominent accounts