Karsten Hahn

498 Followers
78 Following
131 Posts
Malware Analyst at G DATA. Ransomware hunter. he/him 🦔🌈🏳️‍⚧️
😂 @rifteyy just pointed me to this gem in the VT comment section for the empty file
https://www.virustotal.com/gui/file/e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855/community

New Video: Build your own LLM dynamic analysis lab 🦔🎥

➡️ AI debugs and unpacks with x64dbg
➡️ AI can access powershell terminal

https://www.youtube.com/watch?v=QrWzRgPsyTE

Build your own AI based Dynamic Reversing Lab, x64dbg automate

YouTube

My malware analysis courses have now a new certificate design.

https://malwareanalysis-for-hedgehogs.learnworlds.com/courses

I wrote an article about SugarSMP Minecraft scams, Spark stealer, extortion and hacked accounts.

After a brief contact to the threat actor, we talked to two victims and followed the trail.

Analysis in collaboration with @rifteyy
#GDATATechblog #GDATA
https://blog.gdatasoftware.com/2026/03/38390-minecraft-mod-sugarsmp-malware

Minecraft: SugarSMP's Dark Tale of Scams, Malware & Extortion

Some Minecraft players were looking for safe haven away from griefers, but found an elaborate web of malware, deception and extortion.

🦔 📹 Video: Building your own AI Malware Analysis Lab
➡️ old system, 16 GB RAM
➡️ using Remnux
#MalwareAnalysisForHedgehogs #LLM
https://www.youtube.com/watch?v=YOduz8VIvvw
Build your own AI Malware Analysis Lab with Remnux

YouTube
49660527c1c910ad2d3c5625c1b44682e465e45b65883dfc8d7d229d1bd0ebd8

🦔 📹 New video: NodeJs analysis when deobfuscator fails
➡️ #MythJs stealer sample
➡️ pkg VFS exploration tool
➡️ js-confuser

#MalwareAnalysisForHedgehogs
https://www.youtube.com/watch?v=gtLqrjsGRmQ

Malware Analysis - Deobfuscating NodeJs pkg packed stealer MythJs

YouTube

New blog: Using LLMs the right way for malware analysis

💡Tips for building an autonomous AI analysis lab on a 12 yo laptop and getting stuff done faster without loss of accuracy.

https://blog.gdatasoftware.com/2026/03/38381-llm-malware-analysis

GuvercinInstaller.exe 1/72
#kurdishmyth stealer, NodeJS

➡️Infects discord_desktop_core\index.js
➡️Steals various browser and discord data.
➡️Exfiltrates via discord webhook.

The code references kurdishmyth and mythprivate

The wallet exfiltration webhook uses a photo of Abdullah Öcalan as its avatar image.

You will find the same malware family with this VT search query:

vhash:087076656d156d05655253z72zff7z11z23z13z93z12b4z11z behaviour_processes:"C:\\Windows\\system32\\cmd.exe /d /s /c \"taskkill /F /IM discord.exe\""

https://www.virustotal.com/gui/file/49660527c1c910ad2d3c5625c1b44682e465e45b65883dfc8d7d229d1bd0ebd8?nocache=1