
Amadey and StealC: Malware-as-a-Service Unavailable
C2 mapping, malware emulation, and infection telemetry supporting the Amadey and StealC disruption.

C2 mapping, malware emulation, and infection telemetry supporting the Amadey and StealC disruption.

A BSides Lisbon talk connecting malware analysis, DNS intelligence, and sinkhole telemetry in an Android TV botnet investigation.

An investigation of Telegram bot exfiltration, infostealer log formats, and the visibility those records provide.

Tracing changes in PrivateLoader protocols and string obfuscation, with YARA and Suricata detection.

Configuration and infection-data analysis of AgentTesla and OriginLogger, including their exfiltration methods.

Investigating the proxying, spam, and cryptocurrency-mining activity of the modular Tofsee botnet.

A Colibri Loader unpacking walkthrough covering anti-analysis techniques, string decryption, and YARA detection.

Tracking PrivateLoader delivery chains and identifying 30 malware families in the collected payloads.

Building a PrivateLoader string decryptor and YARA rule from a stack-based XOR pattern.

A historical investigation of FluBot distribution, infection telemetry, and its domain-generation algorithm.

Sinkhole observations of pre-installed Android threats and insecure device-update mechanisms.

An Android advertising SDK investigation, with a historical appendix of sample hashes, package names, and domains.