sharing a friends GoFundMe https://www.gofundme.com/f/pr77zc-recovery-funds?lid=nlkk8jxujhda
It's been extremely hard to keep this one under wraps.
I just published a new blog post, where one weird string that looks like a cookie value turned out to be a whole cryptostealer and database wiping operation.
https://www.labs.greynoise.io/grimoire/2026-02-24-whats-that-string/
I spent some late nights on this one, and am a little bit ridiculously proud of the work I did.
If you happen to be looking for bad redactions in a large set of data files today for some reason, there's an open source tool for that.