alden
@re.wtf
📤 677
📥 410
📝 13
sr detection engineer @ huntress • malware enjoyer • macOS security
https://alden.io
reposted by
alden
Kenneth Kinion
6 months ago
Hot on the heels of the researched published by
@huntress.com
, hunting for Zoom-themed lures from DPRK's
#BlueNoroff
💥Learn hunting techniques 💥Leverage new Validin features and data 💥Full, unredacted indicator list (domains, IPs, hashes)
www.validin.com/blog/zooming...
loading . . .
Zooming through BlueNoroff Indicators with Validin | Validin
Pivoting through recently-reported indicators to find BlueNoroff-associated domains
https://www.validin.com/blog/zooming_through_bluenoroff_pivots/
1
2
2
excited bc today
@huntress.com
is releasing our analysis of a gnarly intrusion into a web3 company by the DPRK's BlueNoroff!! 🤠 we've observed 8 new pieces of macOS malware from implants to infostealers! and they're actually good (for once)!
www.huntress.com/blog/inside-...
loading . . .
Inside the BlueNoroff Web3 macOS Intrusion Analysis | Huntress
Learn how DPRK's BlueNoroff group executed a Web3 macOS intrusion. Explore the attack chain, malware, and techniques in our detailed technical report.
https://www.huntress.com/blog/inside-bluenoroff-web3-intrusion-analysis
6 months ago
1
29
21
finally got around to rewriting the copy as yara binja plugin! 🥰 has a few quality of life improvements (new formats) and address wildcarding is fixed for ARM! (sorry bout that mac homies) ❤️ it's also now available in the plugin repository! 🔥
github.com/ald3ns/copy-...
8 months ago
0
7
2
reposted by
alden
Jamie Levy 🦉
8 months ago
CVE-2025-2825 or CVE-2025-31161: A vulnerability by any other name is still a threat 😇: We've updated the blog to reflect some new attacker tradecraft observed yesterday cc
@huntress.com
@re.wtf
@johnhammond.bsky.social
#DFIR
#vuln
#CVE
www.huntress.com/blog/crushft...
loading . . .
CrushFTP CVE-2025-31161 Auth Bypass and Post-Exploitation | Huntress
Huntress observed in-the-wild exploitation of CVE-2025-31161, an authentication bypass vulnerability in versions of CrushFTP and further post-exploitation leveraging MeshCentral and other malware.
https://www.huntress.com/blog/crushftp-cve-2025-31161-auth-bypass-and-post-exploitation
0
4
1
pwning my FTP server is a weird way to say you have a Crush on me but okay 🥰 anyways check out our analysis of some CrushFTP CVE-2025-31161 post exploitation activity!
www.huntress.com/blog/crushft...
loading . . .
https://www.huntress.com/blog/crushftp-cve-2025-31161-auth-bypass-and-post-exploitation
https://t.co/gUPHQRZUEG
8 months ago
0
6
3
reposted by
alden
Selena Larson
9 months ago
Published some new research on how RMMs are taking over as a first-stage payload
www.proofpoint.com/us/blog/thre...
loading . . .
Remote Monitoring and Management (RMM) Tooling Increasingly an Attacker’s First Choice | Proofpoint US
Key findings More threat actors are using legitimate remote monitoring and management (RMM) tools as a first-stage payload in email campaigns. RMMs can be used for
https://www.proofpoint.com/us/blog/threat-insight/remote-monitoring-and-management-rmm-tooling-increasingly-attackers-first-choice
0
34
16
reposted by
alden
Jacob Latonis
9 months ago
nightmare blunt rotation
2
37
8
BREAKING: DOGE has uncovered that the CIA spent $10,000,000 on zyns and has been feeding them to analysts to increase productivity! 😱
10 months ago
0
7
0
reposted by
alden
cabal
11 months ago
our network has raised hundreds of dollars to give firefighters the zyn they need to keep protecting LA from the fires. Thank you!!
1
18
9
reminder to say happy new years to the russian espionage groups in ur network 🥰🇷🇺
@nosecurething.bsky.social
,
@laughingmantis.bsky.social
, and I just dropped a new blog detailing a series of redcurl intrusions across several huntress customer environments 😳
www.huntress.com/blog/the-hun...
loading . . .
Hunt for RedCurl | Huntress
Huntress discovered RedCurl activity across several organizations in Canada going back to 2023. Learn more about how this APT operates and how they aim to remain undetected while exfiltrating sensitiv...
https://www.huntress.com/blog/the-hunt-for-redcurl-2
11 months ago
1
18
5
reposted by
alden
Greg Lesnewich
11 months ago
#100DaysofYARA
day 1 - the Amos stealer is regularly evolving and updating its obfuscation techniques You know what isn't changing? the dylibs it depends on and the entitlements it requests from the OS. Combined, they give us excellent signal
github.com/100DaysofYAR...
2
16
5
reposted by
alden
Sean
11 months ago
Binary diff'ing is hard. But it's super powerful to apply markup from previous reverse engineering efforts to a new binary. Binary Ninja is switching up how they match function signatures with WARP.
www.seandeaton.com/binary-ninja...
#binaryninja
#reverseengineering
#ghidra
#ida
#decompiler
loading . . .
Trying Out Binary Ninja's new WARP Signatures with IPSW Diff'ing
Binary diff'ing is pretty complex, but being able to apply markup from one binary to another is quite powerful. Binary Ninja's new WARP extends previous efforts, using SigKit, to quickly identify libr...
https://www.seandeaton.com/binary-ninja-warp-signatures/
0
25
6
i gotta step up my whitepaper game smh, my dad is doin numbers
add a skeleton here at some point
12 months ago
0
13
0
reposted by
alden
Stuart Ashenbrenner
12 months ago
Our talk from
@objective-see.bsky.social
is now available online. Check out
@re.wtf
and I yap about macOS infostealers.
www.youtube.com/watch?v=Hv6A...
loading . . .
#OBTS v7.0: "Stealer Crossing: New Horizons" - Alden Schmidt & Stuart Ashenbrenner
YouTube video by Objective-See Foundation
https://www.youtube.com/watch?v=Hv6A2XcUv2s
1
10
4
reposted by
alden
Greg Lesnewich
12 months ago
since I'm cold and missing
#OBTS
I wanted to reflect on what
@jacoblatonis.me
and Tomas have gifted us with the YARA-X Macho module the OG YARA macho parsing left a lot to be desired, and the new YARA-X ver has all sorts of goodies
2
19
8
reposted by
alden
aaron
12 months ago
this holiday season
0
16
9
following the recent cleo ITW exploitation,
@huntress.com
has released our analysis of the full post exploitation chain 🚀 the final java based implant framework is really neat and includes a custom C2 protocol 🔥
huntress.com/blog/cleo-soft…
loading . . .
https://huntress.com/blog/cleo-soft…
12 months ago
0
14
2
reposted by
alden
aaron
12 months ago
hotties only want one thing and its the operation triangulation exploit chain
add a skeleton here at some point
0
7
5
reposted by
alden
Stuart Ashenbrenner
12 months ago
Yesterday I got to present with the 🐐
@re.wtf
. Such a blast talking thru infostealers and the telenovela that they’ve become.
#OBTS
really is the best, chillest conference out there. Excited for a second day of talks 🤓🍎
0
13
1
🍎🤝🔥
add a skeleton here at some point
12 months ago
0
7
0
we cookin' for
#100DaysofYARA
🤝🔥
add a skeleton here at some point
about 1 year ago
0
19
4
reposted by
alden
jiska
about 1 year ago
How does the new iOS inactivity reboot work? What does it protect from? I reverse engineered the kernel extension and the secure enclave processor, where this feature is implemented.
naehrdine.blogspot.com/2024/11/reve...
loading . . .
Reverse Engineering iOS 18 Inactivity Reboot
Wireless and firmware hacking, PhD life, Technology
https://naehrdine.blogspot.com/2024/11/reverse-engineering-ios-18-inactivity.html
12
280
118
reposted by
alden
Jamie Levy 🦉
about 1 year ago
🧵Today’s blogpost focuses on a newer ransomware variant named SafePay. Needless to say, ransomware sucks. When this new variant appeared, it gained our attention. 👀 Let’s dig into what happened and what makes it tick ⬇️:
2
36
13
reposted by
alden
Alex Delamotte
about 1 year ago
I wrote a post on the realities of cloud & webserver ransomware. Check it out to see some of the toolsets & frameworks that can be used for these attacks.
add a skeleton here at some point
0
14
7
some huntress homies cooked a blog on a new ransom group called safepay RE was fun until we realized it was ripped lockbit code 💀😭 imagine not being able to write your own ransomware, true skill issue smh some funny opsec fails too, watch ya status
www.huntress.com/blog/its-not...
loading . . .
https://www.huntress.com/blog/its-not-safe-to-pay-safepay
https://t.co/AWFvvMUPmf
about 1 year ago
0
15
4
you reached the end!!
feeds!
log in