Eli Salem·Jan 16, 2023Dancing With Shellcodes: Analyzing Rhadamanthys StealerThreat BackgroundA response icon1A response icon1
Eli Salem·Apr 27, 2022The chronicles of Bumblebee: The Hook, the Bee, and the Trickbot connectionIn late March 2022, a new malware dubbed “Bumblebee” was discovered, and reported to be distributed in phishing campaigns containing ISO…
Eli Salem·Feb 16, 2022Highway to Conti: Analysis of BazarloaderAs we look back to summarize the year 2021 we observe that the biggest threat in the cybersecurity landscape is still ransomware. A large…
Eli Salem·Sep 21, 2021The Squirrel Strikes Back: Analysis of the newly emerged cobalt-strike loader “SquirrelWaffle”Since early-mid of September 2021, a new malware loader dubbed “Squirrelwaffle” has been discovered and observed delivering the attack…A response icon3A response icon3
Eli Salem·Jun 21, 2021Dissecting and automating Hancitor’s config extractionThe Hancitor malware, first observed in 2015, is a downloader known to deliver several other malware. In its first years, Hancitor was…A response icon1A response icon1
Eli Salem·Apr 19, 2021Dancing With Shellcodes: Cracking the latest version of GuloaderGuloader is a downloader that has been active since 2019. It is known to deliver various malware, more notably: Agent-Tesla, Netwire…
Eli Salem·Jan 18, 2021Funtastic Packers And Where To Find ThemIn malware, we often see threat actors that tend to obfuscate or encrypt their code in order to slow down the analysis of security…A response icon1A response icon1