avallach

@xorhex@infosec.exchange
431 Followers
1,083 Following
1.7K Posts
🇺🇦 Malware Researcher 🇺🇦
Posts are my own and do not reflect my employer.
mlgethttp://github.com/xorhex/mlget
bloghttps://blog.xorhex.com
twittodonhttps://twittodon.com/share.php?t=xorhex&m=xorhex@infosec.exchange

Natto Thoughts examines HAFNIUM-linked hacker Xu Zewei and reveals ties between China’s state security agencies, cybersecurity firm and strategic industries.

https://nattothoughts.substack.com/p/hafnium-linked-hacker-xu-zewei-riding

HAFNIUM-Linked Hacker Xu Zewei: Riding the Tides of China’s Cyber Ecosystem

How one man’s career reveals the interconnected web of China’s state security apparatus, cybersecurity firms, and strategic industries

Natto Thoughts
@runZeroInc this is slick!

Success! Mastodon found the person. Thank you!

I am looking for someone from #italy that used the online handle Lex Tutor from at least 2010-2019. Lex hates #spam and was very vocal about spam groups.

If the #mastodon community can help me find the real person, I would be grateful..

Lex had insights into criminals that we are hunting today.. and I would love to interview them.

Appreciate the boosts to see if the Kevin Bacon game will work.

#cybercrime #scam

So #BinaryRefinery 0.8.25 is out with support for the latest Inno Setup installer files, but more importantly the repo has 4000 commits!!
Exciting! @vector35 's excellent #BinaryNinja ships with built-in BinExport in the latest dev version!
Here's how to use it with #BinDiff: https://dev-docs.binary.ninja/guide/binexport.html
BinExport / BinDiff - Binary Ninja User Documentation

Documentation for the Binary Ninja reverse engineering platform

#Remcos #malware is now at v7.0. No significant changes to the payload side, but improvements to enhance reliability and address bugs based on operator experience added.
Samples:
tria.ge/250709-3vxwa...
tria.ge/250710-vba87...

Looks to be distributed via email campaigns from reboundue[.]com emails

It took quite a bit of work, but VirusShare seems to be mostly back to normal. <knocks on wood> I am still moving things around and squashing the occasional issue, so please let us know if you spot any problems.

In 3 days, a slick new UK edition of Sandworm comes out with a new cover and new foreword that aims to capture in a few pages the events of the 5+ years since the book first published: www.amazon.co.uk/Operation-Sa...

The publisher has tweaked the title to "Operation Sandworm" for UK reasons I don't entirely understand, but it's the same book, and hopefully will now reach a new audience.

https://www.amazon.co.uk/Operation-Sandworm-Hunt-Kremlins-Invisible/dp/1800963130

For those who are interested, I recently did a live session demoing Helix, my new go-to text editor, for members of @thetaggartinstitute community. Enjoy!

https://youtu.be/QullbX0JKq8

Live Session: Helix Intro

YouTube

The slides from our @recon talk, "Breaking Mixed Boolean-Arithmetic Obfuscation in Real-World Applications" (CC @nicolodev are now online!

Slides: https://synthesis.to/presentations/recon25_mba_obfuscation.pdf

Plugin: https://github.com/mrphrazer/obfuscation_analysis

×

In 3 days, a slick new UK edition of Sandworm comes out with a new cover and new foreword that aims to capture in a few pages the events of the 5+ years since the book first published: www.amazon.co.uk/Operation-Sa...

The publisher has tweaked the title to "Operation Sandworm" for UK reasons I don't entirely understand, but it's the same book, and hopefully will now reach a new audience.

https://www.amazon.co.uk/Operation-Sandworm-Hunt-Kremlins-Invisible/dp/1800963130

Out today in the UK! (And Australia!)
@agreenberg I have the old/previous (non-operational?) paperback version. I like the new title though.. kinda works for the UK.. Gives it a kind of military history vibe.. big audience for that here..