Paul Rascagneres

1.6K Followers
561 Following
336 Posts
Lord of Loaders @volexity
Websitehttp://www.r00ted.com

Dangerous Invitations: @volexity has published our #threatintel team’s findings on two new campaigns abusing Device Code & OAuth authentication workflows. Throughout 2025, Volexity has identified dozens of campaigns from state-sponsored threat actors abusing these workflows, showing no signs of slowing.

This blog post, details the creative social engineering tactics used by Russian threat actor UTA0355 in recent campaigns to impersonate European security events. Read the full blog post here: https://www.volexity.com/blog/2025/12/04/dangerous-invitations-russian-threat-actor-spoofs-european-security-events-in-targeted-phishing-attacks/

@volexity has released updates to its #opensource GoResolver project and other #golang tools! This work was part of a project for one of our #summerinternship students. Read more details about this project in our special blog post: https://www.volexity.com/blog/2025/08/11/go-get-em-updates-to-volexity-golang-tooling/

We are proud to contribute to the open source community + work alongside students in our annual #internship program! If you would like to learn more about internships at Volexity, check out our program details here: https://www.volexity.com/internships/

#threatintel #malwareanalysis

Go Get 'Em: Updates to Volexity Golang Tooling

Volexity’s GoResolver tool was released in April 2025 to help with analysis of these samples, reducing analyst load when working with obfuscated Golang binaries. However, there are still some difficulties when working with Golang samples, even in the absence of obfuscation. Challenges include organization of string information and propagation of runtime type information. To ease these challenges Volexity has released a new utility, GoStringExtractor, and added functionality to the existing GoResolver tool.

Volexity

We are counting down to #FTSCon 2025! We have a slate of great speakers — you don't want to miss this event!

If you haven't registered yet, register here: https://events.humanitix.com/from-the-source-2025-hosted-by-the-volatility-foundation.

See the event page for details: https://volatilityfoundation.org/from-the-source-2025/

Stay tuned for speaker spotlights!

#FTSCon Speaker Spotlight: Juan Andrés Guerrero-Saade is presenting “From Threat Hunting to Threat Gathering” in the HUNTER track.

See the full list of speakers + event info, including how to register, here: https://volatilityfoundation.org/from-the-source-2025/

#FTSCon Speaker Spotlight: Toni de la Fuente is presenting “Open Cloud Security, lessons learned building Prowler” in the MAKER track.

See the full list of speakers + event info, including how to register, here: https://volatilityfoundation.org/from-the-source-2025/

#FTSCon Speaker Spotlight: Wesley Shields is presenting “COLDRIVER: NOROBOT/YESROBOT/MAYBEROBOT” in the HUNTER track.

See the full list of speakers + event info, including how to register, here: https://volatilityfoundation.org/from-the-source-2025/

#FTSCon Speaker Spotlight: Aleksandra Doniec ("hasherezade") is presenting “Uncovering Malware's Secrets with TinyTracer” in the MAKER track.

See the full list of speakers + event info, including how to register, here: https://volatilityfoundation.org/from-the-source-2025/

#FTSCon Speaker Spotlight: Joseph Edwards ( @blackBoxRE ) is presenting “The Forensics of Zoom's Remote Control” in the HUNTER track

See the full list of speakers + event info, including how to register, here: https://volatilityfoundation.org/from-the-source-2025/.

#FTSCon Speaker Spotlight: Andrew Case (@attrc) is presenting “Detection and Analysis of Memory-Only Linux Rootkits” in the MAKER track.

See the full list of speakers + event info, including how to register, here: https://volatilityfoundation.org/from-the-source-2025/

#FTSCon Speaker Spotlight: Michael Horka is presenting “Lilac Typhoon aboard the Indigo Train - The Current State of Chinese Obfuscation Networks” in the HUNTER track.

See the full list of speakers + event info, including how to register, here: https://volatilityfoundation.org/from-the-source-2025/