
Tofsee Botnet: Proxying and Mining
Investigating the proxying, spam, and cryptocurrency-mining activity of the modular Tofsee botnet.

Investigating the proxying, spam, and cryptocurrency-mining activity of the modular Tofsee botnet.

Tracking PrivateLoader delivery chains and identifying 30 malware families in the collected payloads.

A historical investigation of FluBot distribution, infection telemetry, and its domain-generation algorithm.

Sinkhole observations of pre-installed Android threats and insecure device-update mechanisms.

An Android advertising SDK investigation, with a historical appendix of sample hashes, package names, and domains.