๐Ÿง  Agent Tesla Daily Report

โฌ‡๏ธ Trend: declining (21%)
๐Ÿ“Š 9 new samples
๐ŸŒ 0 C2 servers

Full analysis, IOCs, and hashes:
https://www.yazoul.net/malware/agent-tesla/reports/2026-04-08

#CyberSecurity #MalwareAnalysis #SOC

Agent Tesla Report - 9 New Samples (Apr 2026) | Yazoul Malware Tracker

9 new Agent Tesla samples detected. Trend: declining (21%). Includes IOCs, hashes, C2 servers, and detection rates from MalwareBazaar.

Yazoul Security

๐Ÿง  Formbook Daily Report

โžก๏ธ Trend: stable (9%)
๐Ÿ“Š 8 new samples
๐ŸŒ 55 C2 servers

Full analysis, IOCs, and hashes:
https://www.yazoul.net/malware/formbook/reports/2026-04-07

#CyberSecurity #MalwareAnalysis #SOC

Formbook Report - 8 New Samples (Apr 2026) | Yazoul Malware Tracker

8 new Formbook samples detected. Trend: stable (9%). Includes IOCs, hashes, C2 servers, and detection rates from MalwareBazaar.

Yazoul Security

https://archive.org/details/500ms-supply-chain-verification-toolkit

The name references Andres Freund's 500ms SSH delay that uncovered the
XZ backdoor.

The core finding: JsonSchema.Net.dll shipped in Microsoft's
DesktopAppInstaller has a SHA256 that doesn't match any official NuGet
release. It has a PE timestamp of year 2095. And it's signed by
Microsoft's HSM.

You can verify this on your own Windows 11 machine without downloading
anything from me:

Get-FileHash "C:\Program Files\WindowsApps\Microsoft.DesktopAppInstaller*\ConfigurationRemotingServer\JsonSchema.Net.dll"

Compare with NuGet official: https://www.nuget.org/packages/JsonSchema.Net/7.2.3

The toolkit also includes anomalies in Google's cloudcode_cli (104K
internal refs) and Intel's IGCCTray (GCP data exfil in a graphics driver).

๐Ÿ” 500ms โ€” Supply chain anomalies in Windows 11 default binaries

JsonSchema.Net.dll in Microsoft DesktopAppInstaller:
โ†’ Hash โ‰  any official NuGet release
โ†’ PE timestamp: year 2095
โ†’ Signed by Microsoft HSM post-modification

Verify on YOUR OWN Windows 11 (no download needed):
Get-FileHash "C:\Program Files\WindowsApps\Microsoft.DesktopAppInstaller*\...\JsonSchema.Net.dll"
Compare: nuget.org/packages/JsonSchema.Net/7.2.3

#infosec #supplychainattack #malwareanalysis #microsoft #cybersecurity #threatintel #windows11 #forensics

500ms โ€” Supply Chain Verification Toolkit : Anonymous Security Researcher : Free Download, Borrow, and Streaming : Internet Archive

500ms โ€” Supply Chain Compromise Verification ToolkitNamed after Andres Freund's 500ms that uncovered the XZ backdoor.Three binaries from a standard Windows...

Internet Archive

๐Ÿง  AsyncRAT Daily Report

โฌ‡๏ธ Trend: declining (62%)
๐Ÿ“Š 3 new samples
๐ŸŒ 100 C2 servers

Full analysis, IOCs, and hashes:
https://www.yazoul.net/malware/async-rat/reports/2026-04-06

#CyberSecurity #MalwareAnalysis #SOC

AsyncRAT Report - 3 New Samples (Apr 2026) | Yazoul Malware Tracker

3 new AsyncRAT samples detected. Trend: declining (62%). Includes IOCs, hashes, C2 servers, and detection rates from MalwareBazaar.

Yazoul Security

๐Ÿง  QuasarRAT Daily Report

โฌ‡๏ธ Trend: declining (46%)
๐Ÿ“Š 5 new samples
๐ŸŒ 0 C2 servers

Full analysis, IOCs, and hashes:
https://www.yazoul.net/malware/quasar-rat/reports/2026-04-04

#CyberSecurity #MalwareAnalysis #SOC

QuasarRAT Report - 5 New Samples (Apr 2026) | Yazoul Malware Tracker

5 new QuasarRAT samples detected. Trend: declining (46%). Includes IOCs, hashes, C2 servers, and detection rates from MalwareBazaar.

Yazoul Security

๐Ÿง  Agent Tesla Daily Report

โฌ‡๏ธ Trend: declining (54%)
๐Ÿ“Š 10 new samples
๐ŸŒ 0 C2 servers

Full analysis, IOCs, and hashes:
https://www.yazoul.net/malware/agent-tesla/reports/2026-04-04

#CyberSecurity #MalwareAnalysis #SOC

Agent Tesla Report - 10 New Samples (Apr 2026) | Yazoul Malware Tracker

10 new Agent Tesla samples detected. Trend: declining (54%). Includes IOCs, hashes, C2 servers, and detection rates from MalwareBazaar.

Yazoul Security

๐Ÿง  Vidar Daily Report

โฌ‡๏ธ Trend: declining (39%)
๐Ÿ“Š 19 new samples
๐ŸŒ 100 C2 servers

Full analysis, IOCs, and hashes:
https://www.yazoul.net/malware/vidar/reports/2026-04-03

#CyberSecurity #MalwareAnalysis #SOC

Vidar Report - 19 New Samples (Apr 2026) | Yazoul Malware Tracker

19 new Vidar samples detected. Trend: declining (39%). Includes IOCs, hashes, C2 servers, and detection rates from MalwareBazaar.

Yazoul Security

FLARE Learning Hub

Free hub with reverse engineering, malware analysis, labs, and debugging modules for hands-on Windows x64 training.

https://github.com/mandiant/flare-learning-hub

#ReverseEngineering #MalwareAnalysis

GitHub - mandiant/flare-learning-hub: Free educational content on reverse engineering and malware analysis from the FLARE team

Free educational content on reverse engineering and malware analysis from the FLARE team - mandiant/flare-learning-hub

GitHub

BSides Luxembourg talk announcement!

๐Ÿง๐Ÿšจ ๐—ก๐—ข๐—ง ๐—ฆ๐—ข ๐—›๐—”๐—ฅ๐— ๐—Ÿ๐—˜๐—ฆ๐—ฆ: ๐—ง๐—›๐—˜ ๐—›๐—œ๐——๐——๐—˜๐—ก ๐—ช๐—ข๐—ฅ๐—Ÿ๐—— ๐—ข๐—™ ๐—Ÿ๐—œ๐—ก๐—จ๐—ซ ๐—ฃ๐—”๐—–๐—ž๐—˜๐—ฅ๐—ฆ ๐—”๐—ก๐—— ๐——๐—˜๐—ง๐—˜๐—–๐—ง๐—œ๐—ข๐—ก ๐—–๐—›๐—”๐—Ÿ๐—Ÿ๐—˜๐—ก๐—š๐—˜๐—ฆ - ๐— ๐—”๐—ฆ๐—ฆ๐—œ๐— ๐—ข ๐—•๐—˜๐—ฅ๐—ง๐—ข๐—–๐—–๐—›๐—œ ๐Ÿ›ก๏ธ๐Ÿ”

Linux packers and loaders are a sneaky blind spot in cybersecurity. They hide code with encryption and obfuscation, then run it straight from memory to dodge detection. This talk dives into the โ€œhARMlessโ€ ARM64 packer, showing off tricks like layered encryption and direct syscalls, while exposing a harsh truth: many defenses on Linux barely see it coming.

Massimo Bertocchi https://pretalx.com/bsidesluxembourg-2026/speaker/SU38N8/ Massimo Bertocchi is a Zรผrich-based Threat Hunter and Detection Engineer with dual Masterโ€™s degrees from KTH Royal Institute of Technology and Aalto University, recognized for his award-winning research uncovering covert C2 channels in Microsoft Teams that enable high-speed data exfiltration and expose critical gaps in enterprise security monitoring.

๐Ÿ“… Conference dates: 6โ€“8 May 2026 | 09:00โ€“18:00
๐Ÿ“ 14, Porte de France, Esch-sur-Alzette, Luxembourg
๐ŸŽŸ๏ธ Tickets: https://2026.bsides.lu/tickets/
๐Ÿ“… Schedule Link: https://pretalx.com/bsidesluxembourg-2026/schedule/
#BSidesLuxembourg2026 #CyberSecurity #ThreatHunting #MalwareAnalysis #CloudSecurity #DetectionEngineering

Tried to book a bar. Ended up reverse engineering a malware campaign instead.

A fake "Cloudflare verify" page copied an obfuscated PowerShell loader to my clipboard. So I broke it down:

XOR-obfuscated script
Payload delivery
RedCap infostealer analysis
REMnux, Ghidra & Hybrid Analysis

Also watched the infrastructure get taken down mid-write-up.

First time doing any RE

https://blog.michaelrbparker.com/post/17

(Still haven't booked that drink.)

#CyberSecurity #MalwareAnalysis #ThreatAnalysis

Tried to buy a pint, Finding a Trojan: My First Malware Analysis

This story all started with me and some mates wanting to get a drink in one of those cool, trendy hipster places you see online (I promise I'm only 20

Tea's Blog