
Exfiltration over Telegram Bots: Skidding Infostealer Logs
An investigation of Telegram bot exfiltration, infostealer log formats, and the visibility those records provide.

An investigation of Telegram bot exfiltration, infostealer log formats, and the visibility those records provide.

Tracing changes in PrivateLoader protocols and string obfuscation, with YARA and Suricata detection.

Configuration and infection-data analysis of AgentTesla and OriginLogger, including their exfiltration methods.

Investigating the proxying, spam, and cryptocurrency-mining activity of the modular Tofsee botnet.

A Colibri Loader unpacking walkthrough covering anti-analysis techniques, string decryption, and YARA detection.

Tracking PrivateLoader delivery chains and identifying 30 malware families in the collected payloads.

Building a PrivateLoader string decryptor and YARA rule from a stack-based XOR pattern.