πŸ‡ΊπŸ‡¦ Xorhex πŸ‡ΊπŸ‡¦'s Avatar

πŸ‡ΊπŸ‡¦ Xorhex πŸ‡ΊπŸ‡¦

@xorhex.bsky.social

230 Followers  |  564 Following  |  71 Posts  |  Joined: 11.11.2024  |  1.8809

Latest posts by xorhex.bsky.social on Bluesky

Preview
China-nexus APT Targets the Tibetan Community | ThreatLabz China-nexus APT campaign leverages DLL sideloading, multi-stage infection chains, and low-level APIs to deploy Ghost RAT and PhantomNet backdoors against Tibetan targets.

Illusory Wishes: China-nexus APT Targets the Tibetan Community | www.zscaler.com/blogs/securi... @zscalerinc.bsky.social

24.07.2025 12:07 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Preview
How China’s Patriotic β€˜Honkers’ Became the Nation’s Elite Cyber Spies A new report traces the history of the early wave of Chinese hackers who became the backbone of the state's espionage apparatus.

How did China's top APT hackers come to be? Many were early "Honkers" - patriotic hackers who in late 90s launched low-skill cyberattacks against nations deemed disrespectful to China. But once Honkers developed their skills, PLA/MSS came calling. Based on great research by bsky.app/profile/eube...

18.07.2025 15:48 β€” πŸ‘ 58    πŸ” 30    πŸ’¬ 0    πŸ“Œ 1
Advanced Ghidra Scripting & Automation Register on Humanitix - Advanced Ghidra Scripting & Automation hosted by DEF CON Workshops. DEF CON Workshops . Saturday August 9th 2025. Find event information.

The workshop tickets for my Advanced Ghidra Scripting & Automation workshop at @defcon.bsky.social are live now: events.humanitix.com/dc33ws-n260-...

16.07.2025 11:48 β€” πŸ‘ 0    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

Signed up! The inaugural conference was great - looking forward to the next one πŸ˜€

14.07.2025 16:48 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Malspace | Multiple Actors, One Breach - Rethinking Threat Models in 2025 In this episode, Julien sits down with Chi En (Ashley) Shen, a distinguished threat researcher at Cisco Talos. Ashley shares her fascinating journey from hacking forums in Taiwan to leading threat ...

Had a great time on the @malspace.bsky.social podcast with Julien talking about my PIVOTcon presentation from tracking compartmentalized attacks to thoughts on attribution. Fun convo (and I loved the theme song at the end!). 🎢 Thanks for having me!

malspace.com/episodes/mul...

10.07.2025 13:05 β€” πŸ‘ 4    πŸ” 3    πŸ’¬ 0    πŸ“Œ 0
Time Travel Debugging in Binary Ninja with Xusheng Li
YouTube video by Invoke RE Time Travel Debugging in Binary Ninja with Xusheng Li

We've uploaded our Time Travel Debugging in Binary Ninja stream with Xusheng Li from Vector 35
where we unpacked malware and analyzed anti-analysis capabilities with TTD traces. Enjoy! youtu.be/2v7DRyXb8_c

30.06.2025 13:29 β€” πŸ‘ 3    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0
A side by side comparison of the original output by Ghidra, and the LLM enriched output.

A side by side comparison of the original output by Ghidra, and the LLM enriched output.

Ghidra, scripting, LLM, automagic automation. That should grab the attention for this thread. If you want to read the complete blog, you can do so here: www.trellix.com/blogs/resear...
1/n

01.07.2025 12:35 β€” πŸ‘ 8    πŸ” 5    πŸ’¬ 1    πŸ“Œ 0
2025-06-29 - Supper is served - Humpty's RE Blog 2025-06-29 - Supper is served - Humpty's RE Blog

In case you missed it, check out the β€œSupper is served” technical blog by cyberj3rry on the Supper backdoor c-b.io/2025-06-29+-... it’s well written and provides a great overview of its functionality!

06.07.2025 13:36 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Preview
Release v3.4.5 Β· xorhex/mlget Fix to get Malware Bazaar's new auth requirement working. Plus some additional test cases. https://bazaar.abuse.ch/api/#auth_key

#mlget has been updated to work with Malware Bazaar’s new Auth requirement!

github.com/xorhex/mlget...

03.07.2025 20:21 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

The slides from our @reconmtl.bsky.social talk, "Breaking Mixed Boolean-Arithmetic Obfuscation in Real-World Applications" (CC @nicolo.dev ), are now online!

Slides: synthesis.to/presentation...

Plugin: github.com/mrphrazer/ob...

27.06.2025 20:28 β€” πŸ‘ 12    πŸ” 5    πŸ’¬ 0    πŸ“Œ 1
Post image

Announcing RE//verse 2026! Website is updated with info for sponsors, trainers, speakers, and more importantly, attendees! Are you ready for another year of high quality reverse engineering talks and networking? Join us the first week of March, 2026!

re-verse.io

28.06.2025 15:01 β€” πŸ‘ 8    πŸ” 7    πŸ’¬ 0    πŸ“Œ 0

I know I've been slacking on contributing to YARA-X, but I've been busy elsewhere. I do run a small keybase group where developers and users hang out. Ideas, features and bugs are discussed there. If you think you would benefit from being part of the discussion just hit me up for an invite.

26.06.2025 14:01 β€” πŸ‘ 4    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Preview
10 Things I Hate About Attribution: RomCom vs. TransferLoader | Proofpoint US Threat Research would like to acknowledge and thank the Paranoids, Spur, and Pim Trouerbach for their collaboration to identify, track, and disrupt this activity.Β  Key takeaways

Fun crossover blog about TA829 (RomCom) & TransferLoader with my ecrime pals @selenalarson.bsky.social it’s got it all:

πŸ›°οΈ Popped routers for sending phish

πŸ“Š ACH on attribution

πŸ‘Ύ custom protocols

πŸ‘½ cool malware

πŸ•΅οΈ crime

🎯 espionage

❔many unanswered questions

www.proofpoint.com/us/blog/thre...

30.06.2025 10:04 β€” πŸ‘ 17    πŸ” 12    πŸ’¬ 0    πŸ“Œ 2
Preview
Webinar: What is ICS Malware & How We Detect It?Β  Define what ICS-specific threats are, how they differ from IT threats, and what detection is required to uncover threats targeting industrial control systems.Β Register now β†’

Matt Pahl and I are doing a webinar on defining ICS Malware, its distinction from IT threats, and how we search for it using different OT detection strategies. It's a follow-up to the ICS Malware definition work. Hope to see you there!

Registration link:
hub.dragos.com/webin...

23.06.2025 15:00 β€” πŸ‘ 1    πŸ” 2    πŸ’¬ 1    πŸ“Œ 0
Post image

Busy Week!

Grateful to SANS ICS for hosting my talk on ICS Malware. It was a great experience.

We released our whitepaper on the subject ( www.dragos.com/resou... ).

We also got word that my talk with Sam Hanson on assessing ICS threats was accepted at Defcon ICS village. Hope to see you there!

20.06.2025 19:51 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Post image Post image

Suspicious domains awsonlineserch[.]com and azuronlineserch[.]com were co-registered through Njalla on 6/19/25. Currently resolving to 34.204.12[.]191 and 20.83.167[.]25, respectively.

20.06.2025 17:58 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0
Preview
Inside the BlueNoroff Web3 macOS Intrusion Analysis | Huntress Learn how DPRK's BlueNoroff group executed a Web3 macOS intrusion. Explore the attack chain, malware, and techniques in our detailed technical report.

excited bc today @huntress.com is releasing our analysis of a gnarly intrusion into a web3 company by the DPRK's BlueNoroff!! 🀠

we've observed 8 new pieces of macOS malware from implants to infostealers! and they're actually good (for once)!

www.huntress.com/blog/inside-...

18.06.2025 20:53 β€” πŸ‘ 29    πŸ” 19    πŸ’¬ 1    πŸ“Œ 2
Senior Threat Intelligence Analyst (Iran APT Focus) Arlington, VA, Boston, MA

There are currently two roles open at Insikt Group, one Senior Analyst focused on Iran and one Analyst focused on Rest of the World. Reach out if you have questions:

job-boards.greenhouse.io/recordedfutu...

job-boards.greenhouse.io/recordedfutu...

18.06.2025 16:11 β€” πŸ‘ 3    πŸ” 4    πŸ’¬ 0    πŸ“Œ 0
Preview
Understanding ICS Malware: Defining a Credible Threat to Industrial Infrastructure | Dragos Learn to distinguish ICS malware from IT threats with Dragos's evidence-based framework. Analyze real attacks like TRISIS & FrostyGoop to defend infrastructure.

We've been working on this one for a while, so I'm excited to finally share our whitepaper on defining ICS Malware. In it, we describe how Dragos identifies and differentiates ICS Malware using three properties: ICS-capability, Malicious Intent, and Adverse Effects.

http://www.dragos.co...

17.06.2025 15:55 β€” πŸ‘ 4    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0
Post image

I'm thrilled to be speaking at #VB2025 this September in Berlin! My talk will focus on TAG-124, a widespread traffic distribution system, and its role in the cybercriminal ecosystem, with a particular emphasis on its link to ransomware operations! πŸ‘‰ tinyurl.com/3hurr52m

16.06.2025 07:14 β€” πŸ‘ 20    πŸ” 5    πŸ’¬ 0    πŸ“Œ 0
Preview
GrayAlpha Unmasked: New FIN7-Linked Infrastructure, PowerNet Loader, and Fake Update Attacks Insikt Group exposes GrayAlpha’s evolving infrastructure and infection methodsβ€”including PowerNet and MaskBat loaders, fake 7-Zip sites, and the undocumented TAG-124 networkβ€”linking the group to FIN7’...

Today we are releasing a report on new infrastructure and tooling linked to GrayAlpha, a financially motivated threat actor overlapping with FIN7 🧡
www.recordedfuture.com/research/gra...

13.06.2025 14:34 β€” πŸ‘ 13    πŸ” 13    πŸ’¬ 1    πŸ“Œ 3
Post image

Forgot to mention this the other week - capa v9.2.0/v9.2.1 has been released! This version includes the rules I wrote for detecting COM-based assembly loading and donut shellcode/relevant feature detection.
github.com/mandiant/cap...

13.06.2025 06:12 β€” πŸ‘ 3    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Preview
Predator Spyware Resurgence: Insikt Group Exposes New Global Infrastructure Despite sanctions and global scrutiny, Predator spyware operations persist. Insikt Group reveals new infrastructure links in Mozambique, Africa, and Europe, highlighting ongoing threats to civil socie...

Today we’re publishing new findings on Predator spyware, still active despite global sanctions, now with a new client and ties to a Czech entity. Here’s what we found 🧡

www.recordedfuture.com/research/pre...

12.06.2025 14:22 β€” πŸ‘ 21    πŸ” 14    πŸ’¬ 1    πŸ“Œ 3

Hi, I’m the author of mlget (bsky.app/profile/xorh...) - is it possible to DM you? I’ve a question about the API response when a file is returned versus when it’s not found.

12.06.2025 15:20 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

VxShare’s API is currently returning a 500

12.06.2025 00:03 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Latest test run: For the ones that failed, I either don’t have a current API key to test with or an instance of the service to test against.  

If folks can test and let me know, I’d be very grateful!   Please submit an issue in GitHub if it’s broken. Thanks! πŸ˜€

Latest test run: For the ones that failed, I either don’t have a current API key to test with or an instance of the service to test against. If folks can test and let me know, I’d be very grateful! Please submit an issue in GitHub if it’s broken. Thanks! πŸ˜€

#mlget has been updated - your 1 stop shop for finding malware across different services!

Grab an updated copy at github.com/xorhex/mlget...

Happy to add additional services if folks know of more!

Some services I no longer have access to for testing - see the Alt text for more info.

11.06.2025 23:40 β€” πŸ‘ 6    πŸ” 4    πŸ’¬ 2    πŸ“Œ 1
Post image

Was great presenting with @milenkowski.bsky.social at @haguetix.bsky.social yesterday. Big thank you for hosting this incredible event. Looking forward to next year!

11.06.2025 16:53 β€” πŸ‘ 8    πŸ” 3    πŸ’¬ 0    πŸ“Œ 0
Post image

New #TinyTracer (v3.0) is out - with many cool features: github.com/hasherezade/... - check them out!

06.06.2025 19:11 β€” πŸ‘ 15    πŸ” 6    πŸ’¬ 1    πŸ“Œ 0

Apparently my lightning talk at @cyberwarcon.bsky.social last year was released. Go watch it for a quick overview. COLDRIVER is still active, and still evolving to this day.

The critical question is do I want to use emojis when I post about them?

05.06.2025 23:50 β€” πŸ‘ 7    πŸ” 4    πŸ’¬ 0    πŸ“Œ 0
picture

picture

Really excited to see this research go live. We found 400 web based HMIs for US Water facilities open on Censys. With the EPA, we helped reduced that exposure by over 94%.

https://censys.com/blog/turning-off-the-information-flow-working-with-the-epa-to-secure-hundreds-of-exposed-water-hmis

05.06.2025 15:56 β€” πŸ‘ 37    πŸ” 13    πŸ’¬ 3    πŸ“Œ 2

@xorhex is following 20 prominent accounts