Drew
@bugfire.io
๐ค 143
๐ฅ 164
๐ 399
malware detection and analysis, hunting and gathering, threat research Views are my own.
reposted by
Drew
Lenny Zeltser
1 day ago
Much of our security work is communicating with colleagues throughout the org. 10 habits that sharpen how the technical work gets heard.
https://zeltser.com/strong-communication-skills
loading . . .
10 Communication Tips for Security and IT Professionals
Explaining security and IT work is often harder than the work itself. Ten habits will sharpen how you explain it to specialists, executives, and everyone in between.
https://zeltser.com/strong-communication-skills
0
5
2
reposted by
Drew
Jeremy Kirk
14 days ago
Device-code phishing is surging. One cybercriminal tool can target virtually every Microsoft user. Okta Threat Intelligence digs deep into the OAuth CLI device flow and how to minimize your attack surface.
www.okta.com/blog/threat-...
loading . . .
Device code phishing: itโs phishing with dynamite
Okta Threat Intelligence studies recent abuse of the device code authorization flow in service provider ecosystems, and provides links to detection and remediation strategies for protecting clients cr...
https://www.okta.com/blog/threat-intelligence/device-code-phishing--it-s-phishing-with-dynamite/
0
2
2
I highly recommend this comprehensive blog on EDR internals
0xdbgman.github.io/posts/edr-in...
loading . . .
EDR Tradecraft: Internals, Detection, Evasion & Advanced Researchg
Technical reference on modern EDR architecture, detection mechanisms, evasion techniques, and reverse-engineering methodology. Covers kernel callback APIs, file-system mini-filters, ETW providers, the...
https://0xdbgman.github.io/posts/edr-internals-research-and-bypass/
18 days ago
0
1
0
reposted by
Drew
Squiblydoo
20 days ago
We report certificates for revocation when they sign malware. What about before they sign malware? I've started adding certificates to Cert Graveyard that are being used to "warm" the certificate and improve it's score before being sign malware. 1/4
1
3
1
reposted by
Drew
mthcht
28 days ago
Launching
oauthsentry.github.io
Look up any OAuth app ID and find out what it actually is across thousands of legitimate, risky, and malicious apps (Entra, Google, GitHub). Multiple feeds, API, detection ideas and remediation guidance. Still improving the detections a bit ๐ฆพ
loading . . .
OAuthSentry - OAuth application intelligence for defenders
Search OAuth Application IDs across Microsoft Entra, Google Workspace and more. Three classification feeds for defenders: compliance, risky, and malicious. Includes investigation playbooks, forensic t...
https://oauthsentry.github.io
1
1
3
Great listen!
add a skeleton here at some point
26 days ago
0
3
1
reposted by
Drew
Lenny Zeltser
28 days ago
Out-of-the-box Claude Code is solid for general work. What makes it indispensable is the personalization, hardening, and connectors you layer on top. I mapped my setup into a seven-layer Personal AI Stack, so you can optimize yours.
loading . . .
The Personal AI Stack: A Power User's Guide
An AI tool like Claude Code gives you solid general-purpose capabilities out of the box. To make it truly indispensable, add the layers that teach it who you are, how you work, and what you do.
https://zeltser.com/personal-ai-stack
1
5
2
reposted by
Drew
Ryan Naraine
about 1 month ago
Spotify
open.spotify.com/episode/5lkC...
loading . . .
Mark Dowd on AI hacking, exploit chains, zero-day sales
Spotify video
https://open.spotify.com/episode/5lkCeDPbpuzay0CyW82Sd0?si=oikqrorARc6O0wnZ7ErbdA
0
2
1
reposted by
Drew
Brad
about 1 month ago
2026-04-23 (Thursday):
#SmartApeSG
campaign using
#ClickFix
instructions to push some sort of
#RAT
. Not sure what this
#malware
is yet, but it looks like a RAT. Details at
www.malware-traffic-analysis.net/2026/04/23/i...
1
4
2
reposted by
Drew
John Hammond
about 1 month ago
Joined by Katrina Manson to hear all about her latest book release: Project Maven & the Dawn of AI Warfare ๐ We talk AI usage at the Pentagon, drone intel, AI enabled targeting, and the ethical tipping point of autonomous weapons. Super fascinating ideas. Video:
youtu.be/OVgruylpVXc
0
3
2
reposted by
Drew
Karsten Hahn
about 1 month ago
New Video: Build your own LLM dynamic analysis lab ๐ฆ๐ฅ โก๏ธ AI debugs and unpacks with x64dbg โก๏ธ AI can access powershell terminal
www.youtube.com/watch?v=QrWz...
loading . . .
Build your own AI based Dynamic Reversing Lab, x64dbg automate
YouTube video by MalwareAnalysisForHedgehogs
https://www.youtube.com/watch?v=QrWzRgPsyTE
0
2
1
reposted by
Drew
John Hammond
about 2 months ago
Wild story on a big AI-powered social engineering campaign, leveraging Device Code phishing to steal Entra ID/Microsoft accounts -- all with entirely unique and personalized per-victim lures from vibecode-crafted infrastructure ๐คฏ Video:
youtu.be/9b3kirR8s2U
0
2
3
reposted by
Drew
Karsten Hahn
2 months ago
I wrote an article about SugarSMP Minecraft scams, Spark stealer, extortion and hacked accounts. After a brief contact to the threat actor, we talked to two victims and followed the trail. Analysis in collaboration with @rifteyy
#GDATATechblog
#GDATA
blog.gdatasoftware.com/2026/03/3839...
loading . . .
Minecraft: SugarSMP's Dark Tale of Scams, Malware & Extortion
Some Minecraft players were looking for safe haven away from griefers, but found an elaborate web of malware, deception and extortion.
https://blog.gdatasoftware.com/2026/03/38390-minecraft-mod-sugarsmp-malware
0
2
3
reposted by
Drew
Thomas Roccia :verified:
2 months ago
๐ค A month ago I published a blog post on how to monitor Claude Code sessions using hooks and NOVA Protector! At the time, no one was really talking about this. Coding agents were being handed full access to your machine and people were just trusting the output blindly. The post covers how I [โฆ]
loading . . .
Original post on infosec.exchange
https://infosec.exchange/@fr0gger/116242406074517572
1
2
2
reposted by
Drew
KoifSec
3 months ago
New post out! "The Red Queenโs Race: Arms Race Dynamics in Threat Detection"
medium.com/@koifsec/the...
loading . . .
The Red Queenโs Race: Arms Race Dynamics in Threat Detection
โNow, here, you see, it takes all the running you can do, to keep in the same place.โ โ The Red Queen, Through the Looking-Glass
https://medium.com/@koifsec/the-red-queens-race-arms-race-dynamics-in-threat-detection-4f532a149fda
0
1
1
reposted by
Drew
ThreatInsight
3 months ago
On this episode of Discarded, our team explores how
#artificialintelligence
is shaping modern
#malware
analysis and detection workflows. Listen now on your favorite
#podcast
platform, and you'll get a balanced view of AI's growing impact on cybersecurity. ๐๏ธ:
www.proofpoint.com/us/podcasts/...
0
2
1
reposted by
Drew
Thomas Roccia :verified:
3 months ago
๐ค Happy to see that my DEFCON talk on crypto money laundering and tracking techniques was featured in the DEFCON 33 Almanac! Read it here:
https://harris.uchicago.edu/sites/default/files/the_def_con_33_hackers_almanack.pdf
0
2
1
reposted by
Drew
Allan โRansomware Sommelierโ Liska
3 months ago
I started making comics, in part, as a respite from the grind that is cybersecurity. Only hackers/scammers are everywhere. Iโm no
@johnhammond.bsky.social
but here is my video on how scammers try to take advantage of creators on Kickstarter.
add a skeleton here at some point
0
3
4
This looks very interesting! ๐
add a skeleton here at some point
4 months ago
0
0
0
reposted by
Drew
CyberRaiju
4 months ago
Episode 2 of Breach Log is now available! Special thanks to Max Margolis for joining me and telling his story. If you have a story you'd like to share, get in contact and we can have some fun! breachlogpodcast [@] gmail[.]com
open.spotify.com/episode/4SDz...
loading . . .
Spotify โ Web Player
https://open.spotify.com/episode/4SDz0RGNXaRVVEJNgabTyh?si=VKSgAn0mSgKrs4Q2mPyfig
0
1
1
reposted by
Drew
Thomas Roccia :verified:
4 months ago
๐ค Let me introduce you to MoltThreats: The first AI Threat Intel Feed for Ai Agents! In one week, OpenClaw became a widely used general AI agent. People started to run their own agents all over the world and connect them directly to the internet. But this [โฆ]
[Original post on infosec.exchange]
1
3
2
reposted by
Drew
Brad
4 months ago
2026-01-31 (Friday): I've posted a new traffic analysis exercise. It's Lumma in the room-ah! Join the fun at
www.malware-traffic-analysis.net/2026/01/31/i...
I mean, this guy looks like he's having fun.
0
5
3
reposted by
Drew
Brad
4 months ago
2026-01-22 (Thursday):
#RemcosRAT
infection persistent on an infected Windows host. This was caused by
#ClickFix
instructions from
#SmartApeSG
through a fake CAPTCHA page. Details of this
#Remcos
#RAT
infection are available at
www.malware-traffic-analysis.net/2026/01/06/i...
0
3
2
reposted by
Drew
Mehmet Ergene
4 months ago
I've released my new course: Practical Threat Hunting for Beginners Similar courses: $$$$ This course: $$
academy.bluraven.io/course/pract...
#ThreatHunting
#DetectionEngineering
loading . . .
Practical Threat Hunting for Beginners
Learn the core knowledge and practical skills required to perform effective threat hunting in real-world environments.
https://academy.bluraven.io/course/practical-threat-hunting-for-beginners
0
3
2
reposted by
Drew
Karsten Hahn
4 months ago
๐ฆ ๐น New Video: Can office files be malicious without Macros? โก๏ธ VSTO Add-Ins โก๏ธ External Templates โก๏ธ Checklist for Office analysis
#MalwareAnalysisForHedgehogs
www.youtube.com/watch?v=RtHH...
loading . . .
Malware Analysis - Malicious MS Office files without Macros
YouTube video by MalwareAnalysisForHedgehogs
https://www.youtube.com/watch?v=RtHHckH5IsI
2
6
5
Karsten's samplepedia is a great resource for malware samples and analysis solutions!
add a skeleton here at some point
4 months ago
0
1
0
reposted by
Drew
Josh Stroschein | The Cyber Yeti
4 months ago
Is the 9-5 a thing of the past? ๐ Dhillon Kannabhiran (HITB) says the "hacker ethos" is replacing the corporate ladder. From on-demand bug hunting to working across time zones, the rules of the game have changed.
podcasts.apple.com/us/podcast/e...
loading . . .
0
2
1
reposted by
Drew
Sarah Gooding
4 months ago
๐ตโ๐ซ The Chrome extension ecosystem really is the wild west, and remains largely uncharted territory for security teams. You need visibility into whatโs actually running in the browser. cc:
@campuscodi.risky.biz
@zackwhittaker.com
@bleepingcomputer.com
add a skeleton here at some point
0
8
6
Nice work from
@malware-traffic-analysis.net
in the ISC diary blog on Lumma scheduled tasks from yesterday:
isc.sans.edu/diary/Infect...
loading . . .
Infection repeatedly adds scheduled tasks and increases traffic to the same C2 domain
Infection repeatedly adds scheduled tasks and increases traffic to the same C2 domain, Author: Brad Duncan
https://isc.sans.edu/diary/Infection+repeatedly+adds+scheduled+tasks+and+increases+traffic+to+the+same+C2+domain/32628/
4 months ago
0
2
0
reposted by
Drew
Lenny Zeltser
5 months ago
I released a tool for making your website or docs easily available to AI assistants via an MCP server. This helps ensure people's AI tooling can access the latest details at the right time. For instance, this is how REMnux users now can get info about its malware analysis tools.
loading . . .
Publishing Your Website Content to AI Assistants
When people ask AI assistants about your product or project, they often get outdated information. Here's how to publish your static website content directly to AI tools using Cloudflare Workers and th...
https://zeltser.com/publishing-to-ai-assistants
0
1
2
Recommending this one, itโs a great idea! ๐
add a skeleton here at some point
5 months ago
0
1
0
Found the perfect product for
@selenalarson.bsky.social
- changing fingernail color on demand via iPhone! Next up: hacking Selenaโs nails!
www.reuters.com/video/watch/...
loading . . .
Color-changing 'iPolish' smart nailsย unveiled at CES 2026
The Florida-based company digital beauty brand iPolish unveiled smart, color-changing press-on nails at CES in Las Vegas that can flip between over 400 shades in as little as five seconds. "When you w...
https://www.reuters.com/video/watch/idRW543609012026RP1/
5 months ago
1
0
0
reposted by
Drew
Josh Stroschein | The Cyber Yeti
5 months ago
๐ฃ Happy New Year everyone! If you're looking to get some hands-on malware/reversing training to kick off the year, now is your chance! Check out this virtual training we'll be offering in March with RingZer0 ๐
ringzer0.training/countermeasu...
loading . . .
The FLARE Guide to Windows Internals and Advanced Reversing
Developed by the FLARE team at Google Cloud Security, this immersive six-day virtual training provides a comprehensive deep dive into the complex world of modern Windows malware.
https://ringzer0.training/countermeasure-spring-2026-the-flare-guide-to-windows-internals/
0
2
1
reposted by
Drew
Brad
5 months ago
2026-01-07 (Wednesday):
#MassLogger
infection from email attachment. Copies of the emails, associated malware, indicators, and a
#pcap
of the infection traffic are available at
www.malware-traffic-analysis.net/2026/01/07/i...
0
3
1
reposted by
Drew
Maria Varmazis
5 months ago
So many of us set this up ages ago and have totally forgotten we're still fetching POP3 mail - time to go through and migrate things I guess. Ughh like I needed this chore right now??
add a skeleton here at some point
1
4
1
reposted by
Drew
Brad
5 months ago
2026-01-06 (Tuesday):
#SmartApeSG
CAPTCHA page uses
#ClickFix
technique to push
#RemcosRAT
, with
#Remcos
#RAT
C2 server at 192.144.56[.]80. A
#pcap
of the traffic, the Remcos RAT
#malware
, and a list of indicators are available at
www.malware-traffic-analysis.net/2026/01/06/i...
0
6
2
As most of us get back to work in earnest this week, I canโt help but think of the sheer chaos of 2025 and now strapping in for the dumpster that is already on fire for this year. Godspeed to all in โ26!
5 months ago
0
0
0
Great idea here ๐
add a skeleton here at some point
5 months ago
0
1
0
reposted by
Drew
Squiblydoo
5 months ago
#100DaysofYARA
- Day 2 YARA rule to detect the default Delphi darkmode dib icon. I've seen this icon excessively over the years. Using @unpacme 's YARA hunting tools, I saw 0 known goodware and 800 packed junk. Rule at end 1/4
2
8
3
reposted by
Drew
Brad
5 months ago
2026-01-01 (Thursday):
#LummaStealer
infection with follow-up malware. A
#pcap
of the infection traffic, the
#Lumma
#Stealer
files, and a list of IOCs are available at
www.malware-traffic-analysis.net/2026/01/01/i...
0
3
1
reposted by
Drew
Kostas
5 months ago
๐๐๐๐ ๐น๐ฎ๐๐ป๐ฐ๐ต๐ฒ๐ฑ ๐ฎ๐๐ฒ๐๐ผ๐บ๐ฒ-๐ฑ๐ณ๐ถ๐ฟ-๐๐ธ๐ถ๐น๐น๐ ๐๐ถ๐๐ต @fr0gger_ ! Designed to save time during investigations and everyday DFIR tasks Thomas has built an excellent malware triage skill, and Iโve added a couple of timeline analysis skills to help you get started.
loading . . .
GitHub - tsale/awesome-dfir-skills: A curated collection of DFIR skills and workflows for InfoSec practitioners.
A curated collection of DFIR skills and workflows for InfoSec practitioners. - tsale/awesome-dfir-skills
https://github.com/tsale/awesome-dfir-skills
1
2
1
I listen to a LOT of security related podcasts, and this is the only one that makes me truly think when listening to the topical subjects that are discussed each week. Excellent!
add a skeleton here at some point
5 months ago
1
3
1
reposted by
Drew
Brad
5 months ago
2025-12-29 (Monday):
#ClickFix
page leads to
#NetSupportRAT
infection. Details at
www.malware-traffic-analysis.net/2025/12/29/i...
0
1
1
reposted by
Drew
Karsten Hahn
5 months ago
I added a python script to monitor a folder during dynamic analysis and dump changed files with timestamp
github.com/struppigel/h...
loading . . .
hedgehog-tools/Python helper scripts/monitor_and_dump_changed_files.py at main ยท struppigel/hedgehog-tools
Contribute to struppigel/hedgehog-tools development by creating an account on GitHub.
https://github.com/struppigel/hedgehog-tools/blob/main/Python%20helper%20scripts/monitor_and_dump_changed_files.py
0
3
1
reposted by
Drew
Karsten Hahn
5 months ago
๐ฆ ๐นNew Video: RenPy game loads stealer, beginner friendly โก๏ธ strategies for finding malware in 2956 files โก๏ธ extracting and decompiling RenPy โก๏ธ remote access tool config extraction โก๏ธ unpacking native payload
#MalwareAnalysisForHedgehogs
#RenPy
www.youtube.com/watch?v=Fmfg...
loading . . .
Malware Analysis - RenPy game, finding malware code in 2956 files, Beginner friendly
YouTube video by MalwareAnalysisForHedgehogs
https://www.youtube.com/watch?v=Fmfg0F1e2tM
0
3
1
reposted by
Drew
GreyNoise
6 months ago
React2Shell blog update ๐จ compromised Next.js nodes are rapidly being enlisted into botnets; threat actor activity reaches ~80 source countries; and more.
#React2Shell
#Nextjs
#GreyNoise
#ThreatIntel
loading . . .
CVE-2025-55182 (React2Shell) Opportunistic Exploitation In The Wild: What The GreyNoise Observation Grid Is Seeing So Far
GreyNoise is already seeing opportunistic, largely automated exploitation attempts consistent with the newly disclosed React Server Components (RSC) โFlightโ protocol RCEโoften referred to publicly as...
https://www.greynoise.io/blog/cve-2025-55182-react2shell-opportunistic-exploitation-in-the-wild-what-the-greynoise-observation-grid-is-seeing-so-far
0
6
4
reposted by
Drew
Karsten Hahn
6 months ago
๐ฆ๐น New Video: Modifying string decrypter for a ConfuserEx2 variant โก๏ธ Defeating antis with Harmony hooks โก๏ธ AsmResolver โก๏ธ .NET string deobfuscation
#MalwareAnalysisForHedgehogs
www.youtube.com/watch?v=sARn...
loading . . .
Malware Analysis - Defeating ConfuserEx Anti-Analysis with Hooking
YouTube video by MalwareAnalysisForHedgehogs
https://www.youtube.com/watch?v=sARnT7o8L60
0
3
1
reposted by
Drew
John Hammond
6 months ago
Full length reverse engineering with Invoke RE! Showcasing new iterations of the "Scavenger" malware, or what we saw as "ExoTickler" previously as a fake City Skylines 2 video game mod, now w/ more crypto/creds stealing and C2. Binary Ninja, x64dbg & more:
youtu.be/wFBdeak0t70
0
5
3
reposted by
Drew
Thomas Roccia :verified:
6 months ago
๐ I am running an exclusive 'Black Friday' promo on my book Visual Threat Intelligence with code 'CYBERVTI25'! The ebook is 50% off for the next 4 days, thousands of researchers already read it! The bundle also includes the high quality illustrations from [โฆ]
[Original post on infosec.exchange]
0
2
1
reposted by
Drew
Josh Stroschein | The Cyber Yeti
6 months ago
๐๏ธ In the latest episode of Behind the Binary, Nino Isakovic joins us to talk about the art of deconstructing problems, building a robust RE toolkit, and his work on deobfuscating ScatterBrain! ๐
open.spotify.com/episode/2Iyy...
loading . . .
EP19 The Art of Deconstructing Problems: Tools, Tactics, and the ScatterBrain Obfuscator with Nino Isakovic
Behind the Binary by Google Cloud Security ยท Episode
https://open.spotify.com/episode/2IyyCq8YDm11eAAr8FEWGu?si=f3gPoTPyST-ZjtPM5PFKfA
0
2
1
Load more
feeds!
log in