home.social

#chacha20 — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #chacha20, aggregated by home.social.

fetched live
  1. ‘The Gentlemen’ Profile: Why This Ransomware Group Wants In Before It Locks You Out

    The Gentlemen is a financially motivated ransomware group operating since July 2025 using a Ransomware-as-a-Service model with dual-extortion tactics. They exfiltrate sensitive data before encrypting systems, targeting Windows, Linux, and ESXi environments. The group focuses heavily on preparation before encryption, using legitimate administrative tools like PowerRun.exe for privilege escalation, and establishing persistence through multiple mechanisms including registry modifications, scheduled tasks, and autostart configurations. They disable security tools, delete logs, terminate database and backup services, and use XChaCha20 and Curve25519 encryption. Primarily targeting medium-to-large organizations in the Asia-Pacific region, their activity has increased by 2,100% compared to typical levels. Victims receive ransom notes with approximately 10-day deadlines threatening to publish stolen data on leak sites if demands are not met.

    Pulse ID: 6a9035ff9a03d932d9008b31
    Pulse Link: otx.alienvault.com/pulse/6a903
    Pulse Author: AlienVault
    Created: 2026-08-27 13:05:03

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #0Day #Asia #ChaCha20 #CyberSecurity #Encryption #Extortion #ICS #InfoSec #Linux #OTX #OpenThreatExchange #RAT #RansomWare #RansomwareAsAService #SMS #Windows #bot #AlienVault

  2. ‘The Gentlemen’ Profile: Why This Ransomware Group Wants In Before It Locks You Out

    The Gentlemen is a financially motivated ransomware group operating since July 2025 using a Ransomware-as-a-Service model with dual-extortion tactics. They exfiltrate sensitive data before encrypting systems, targeting Windows, Linux, and ESXi environments. The group focuses heavily on preparation before encryption, using legitimate administrative tools like PowerRun.exe for privilege escalation, and establishing persistence through multiple mechanisms including registry modifications, scheduled tasks, and autostart configurations. They disable security tools, delete logs, terminate database and backup services, and use XChaCha20 and Curve25519 encryption. Primarily targeting medium-to-large organizations in the Asia-Pacific region, their activity has increased by 2,100% compared to typical levels. Victims receive ransom notes with approximately 10-day deadlines threatening to publish stolen data on leak sites if demands are not met.

    Pulse ID: 6a9035ff9a03d932d9008b31
    Pulse Link: otx.alienvault.com/pulse/6a903
    Pulse Author: AlienVault
    Created: 2026-08-27 13:05:03

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #0Day #Asia #ChaCha20 #CyberSecurity #Encryption #Extortion #ICS #InfoSec #Linux #OTX #OpenThreatExchange #RAT #RansomWare #RansomwareAsAService #SMS #Windows #bot #AlienVault

  3. ‘The Gentlemen’ Profile: Why This Ransomware Group Wants In Before It Locks You Out

    The Gentlemen is a financially motivated ransomware group operating since July 2025 using a Ransomware-as-a-Service model with dual-extortion tactics. They exfiltrate sensitive data before encrypting systems, targeting Windows, Linux, and ESXi environments. The group focuses heavily on preparation before encryption, using legitimate administrative tools like PowerRun.exe for privilege escalation, and establishing persistence through multiple mechanisms including registry modifications, scheduled tasks, and autostart configurations. They disable security tools, delete logs, terminate database and backup services, and use XChaCha20 and Curve25519 encryption. Primarily targeting medium-to-large organizations in the Asia-Pacific region, their activity has increased by 2,100% compared to typical levels. Victims receive ransom notes with approximately 10-day deadlines threatening to publish stolen data on leak sites if demands are not met.

    Pulse ID: 6a9035ff9a03d932d9008b31
    Pulse Link: otx.alienvault.com/pulse/6a903
    Pulse Author: AlienVault
    Created: 2026-08-27 13:05:03

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #0Day #Asia #ChaCha20 #CyberSecurity #Encryption #Extortion #ICS #InfoSec #Linux #OTX #OpenThreatExchange #RAT #RansomWare #RansomwareAsAService #SMS #Windows #bot #AlienVault

  4. ‘The Gentlemen’ Profile: Why This Ransomware Group Wants In Before It Locks You Out

    The Gentlemen is a financially motivated ransomware group operating since July 2025 using a Ransomware-as-a-Service model with dual-extortion tactics. They exfiltrate sensitive data before encrypting systems, targeting Windows, Linux, and ESXi environments. The group focuses heavily on preparation before encryption, using legitimate administrative tools like PowerRun.exe for privilege escalation, and establishing persistence through multiple mechanisms including registry modifications, scheduled tasks, and autostart configurations. They disable security tools, delete logs, terminate database and backup services, and use XChaCha20 and Curve25519 encryption. Primarily targeting medium-to-large organizations in the Asia-Pacific region, their activity has increased by 2,100% compared to typical levels. Victims receive ransom notes with approximately 10-day deadlines threatening to publish stolen data on leak sites if demands are not met.

    Pulse ID: 6a9035ff9a03d932d9008b31
    Pulse Link: otx.alienvault.com/pulse/6a903
    Pulse Author: AlienVault
    Created: 2026-08-27 13:05:03

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #0Day #Asia #ChaCha20 #CyberSecurity #Encryption #Extortion #ICS #InfoSec #Linux #OTX #OpenThreatExchange #RAT #RansomWare #RansomwareAsAService #SMS #Windows #bot #AlienVault

  5. ‘The Gentlemen’ Profile: Why This Ransomware Group Wants In Before It Locks You Out

    The Gentlemen is a financially motivated ransomware group operating since July 2025 using a Ransomware-as-a-Service model with dual-extortion tactics. They exfiltrate sensitive data before encrypting systems, targeting Windows, Linux, and ESXi environments. The group focuses heavily on preparation before encryption, using legitimate administrative tools like PowerRun.exe for privilege escalation, and establishing persistence through multiple mechanisms including registry modifications, scheduled tasks, and autostart configurations. They disable security tools, delete logs, terminate database and backup services, and use XChaCha20 and Curve25519 encryption. Primarily targeting medium-to-large organizations in the Asia-Pacific region, their activity has increased by 2,100% compared to typical levels. Victims receive ransom notes with approximately 10-day deadlines threatening to publish stolen data on leak sites if demands are not met.

    Pulse ID: 6a9035ff9a03d932d9008b31
    Pulse Link: otx.alienvault.com/pulse/6a903
    Pulse Author: AlienVault
    Created: 2026-08-27 13:05:03

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #0Day #Asia #ChaCha20 #CyberSecurity #Encryption #Extortion #ICS #InfoSec #Linux #OTX #OpenThreatExchange #RAT #RansomWare #RansomwareAsAService #SMS #Windows #bot #AlienVault

  6. New Mirai-Based Linux Botnet 'Evooo1Bot' Turns Victims Into Proxies

    A sophisticated Linux botnet named Evooo1Bot has been actively targeting internet-facing devices since July 2026, exploiting multiple vulnerabilities in edge devices across diverse regions. Built on the leaked Mirai source code, this modular botnet features significantly enhanced capabilities including encrypted command-and-control communications, SSH brute-force scanning, and a reverse SOCKS relay module that transforms compromised devices into persistent proxies. The malware employs multiple encryption layers using AES-256-CTR, ChaCha20, and XOR-based obfuscation, alongside an integrated exploit arsenal targeting IoT devices, networking equipment, and enterprise applications. The SOCKS relay functionality enables attackers to conceal their origin, pivot into internal networks, and conduct follow-on operations through victim infrastructure, placing it well beyond conventional Mirai-derived malware in terms of technical sophistication.

    Pulse ID: 6a7f349eb2e90e5a682c7e6f
    Pulse Link: otx.alienvault.com/pulse/6a7f3
    Pulse Author: AlienVault
    Created: 2026-08-14 15:30:38

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ChaCha20 #CyberSecurity #Edge #Encryption #InfoSec #IoT #Linux #Malware #Mirai #OTX #OpenThreatExchange #RAT #RCE #SSH #bot #botnet #AlienVault

  7. New Mirai-Based Linux Botnet 'Evooo1Bot' Turns Victims Into Proxies

    A sophisticated Linux botnet named Evooo1Bot has been actively targeting internet-facing devices since July 2026, exploiting multiple vulnerabilities in edge devices across diverse regions. Built on the leaked Mirai source code, this modular botnet features significantly enhanced capabilities including encrypted command-and-control communications, SSH brute-force scanning, and a reverse SOCKS relay module that transforms compromised devices into persistent proxies. The malware employs multiple encryption layers using AES-256-CTR, ChaCha20, and XOR-based obfuscation, alongside an integrated exploit arsenal targeting IoT devices, networking equipment, and enterprise applications. The SOCKS relay functionality enables attackers to conceal their origin, pivot into internal networks, and conduct follow-on operations through victim infrastructure, placing it well beyond conventional Mirai-derived malware in terms of technical sophistication.

    Pulse ID: 6a7f349eb2e90e5a682c7e6f
    Pulse Link: otx.alienvault.com/pulse/6a7f3
    Pulse Author: AlienVault
    Created: 2026-08-14 15:30:38

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ChaCha20 #CyberSecurity #Edge #Encryption #InfoSec #IoT #Linux #Malware #Mirai #OTX #OpenThreatExchange #RAT #RCE #SSH #bot #botnet #AlienVault

  8. New Mirai-Based Linux Botnet 'Evooo1Bot' Turns Victims Into Proxies

    A sophisticated Linux botnet named Evooo1Bot has been actively targeting internet-facing devices since July 2026, exploiting multiple vulnerabilities in edge devices across diverse regions. Built on the leaked Mirai source code, this modular botnet features significantly enhanced capabilities including encrypted command-and-control communications, SSH brute-force scanning, and a reverse SOCKS relay module that transforms compromised devices into persistent proxies. The malware employs multiple encryption layers using AES-256-CTR, ChaCha20, and XOR-based obfuscation, alongside an integrated exploit arsenal targeting IoT devices, networking equipment, and enterprise applications. The SOCKS relay functionality enables attackers to conceal their origin, pivot into internal networks, and conduct follow-on operations through victim infrastructure, placing it well beyond conventional Mirai-derived malware in terms of technical sophistication.

    Pulse ID: 6a7f349eb2e90e5a682c7e6f
    Pulse Link: otx.alienvault.com/pulse/6a7f3
    Pulse Author: AlienVault
    Created: 2026-08-14 15:30:38

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ChaCha20 #CyberSecurity #Edge #Encryption #InfoSec #IoT #Linux #Malware #Mirai #OTX #OpenThreatExchange #RAT #RCE #SSH #bot #botnet #AlienVault

  9. New Mirai-Based Linux Botnet 'Evooo1Bot' Turns Victims Into Proxies

    A sophisticated Linux botnet named Evooo1Bot has been actively targeting internet-facing devices since July 2026, exploiting multiple vulnerabilities in edge devices across diverse regions. Built on the leaked Mirai source code, this modular botnet features significantly enhanced capabilities including encrypted command-and-control communications, SSH brute-force scanning, and a reverse SOCKS relay module that transforms compromised devices into persistent proxies. The malware employs multiple encryption layers using AES-256-CTR, ChaCha20, and XOR-based obfuscation, alongside an integrated exploit arsenal targeting IoT devices, networking equipment, and enterprise applications. The SOCKS relay functionality enables attackers to conceal their origin, pivot into internal networks, and conduct follow-on operations through victim infrastructure, placing it well beyond conventional Mirai-derived malware in terms of technical sophistication.

    Pulse ID: 6a7f349eb2e90e5a682c7e6f
    Pulse Link: otx.alienvault.com/pulse/6a7f3
    Pulse Author: AlienVault
    Created: 2026-08-14 15:30:38

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ChaCha20 #CyberSecurity #Edge #Encryption #InfoSec #IoT #Linux #Malware #Mirai #OTX #OpenThreatExchange #RAT #RCE #SSH #bot #botnet #AlienVault

  10. New Mirai-Based Linux Botnet 'Evooo1Bot' Turns Victims Into Proxies

    A sophisticated Linux botnet named Evooo1Bot has been actively targeting internet-facing devices since July 2026, exploiting multiple vulnerabilities in edge devices across diverse regions. Built on the leaked Mirai source code, this modular botnet features significantly enhanced capabilities including encrypted command-and-control communications, SSH brute-force scanning, and a reverse SOCKS relay module that transforms compromised devices into persistent proxies. The malware employs multiple encryption layers using AES-256-CTR, ChaCha20, and XOR-based obfuscation, alongside an integrated exploit arsenal targeting IoT devices, networking equipment, and enterprise applications. The SOCKS relay functionality enables attackers to conceal their origin, pivot into internal networks, and conduct follow-on operations through victim infrastructure, placing it well beyond conventional Mirai-derived malware in terms of technical sophistication.

    Pulse ID: 6a7f349eb2e90e5a682c7e6f
    Pulse Link: otx.alienvault.com/pulse/6a7f3
    Pulse Author: AlienVault
    Created: 2026-08-14 15:30:38

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ChaCha20 #CyberSecurity #Edge #Encryption #InfoSec #IoT #Linux #Malware #Mirai #OTX #OpenThreatExchange #RAT #RCE #SSH #bot #botnet #AlienVault

  11. Multi-Functional Linux Botnet "Evooo1Bot"

    A previously undocumented Linux botnet named Evooo1Bot has been discovered, actively targeting Internet-facing devices since July 2026. Built upon Mirai's DDoS engine, it extends functionality with encrypted C2 communications, SSH brute-force scanning, SOCKS relay capabilities, credential sniffing, and an integrated exploit arsenal. The malware employs multi-layer string encryption using AES-256-CTR, ChaCha20, and XOR-based key derivation. It exploits numerous vulnerabilities across edge devices, routers, and enterprise applications. The reverse SOCKS relay module transforms compromised devices into persistent proxies, enabling attackers to conceal their origin and pivot into internal networks. The botnet features 28 remote commands organized into modules for persistence, self-update, file transfer, interactive shell, sniffing, proxy relay, SSH scanning, DDoS attacks, and CVE exploitation. Multiple persistence mechanisms ensure continued operation across systemd, SysV init, cron, and shell profiles.

    Pulse ID: 6a7e2be6ba37cc87ae552659
    Pulse Link: otx.alienvault.com/pulse/6a7e2
    Pulse Author: AlienVault
    Created: 2026-08-13 20:41:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ChaCha20 #CyberSecurity #DDoS #DoS #ELF #Edge #Encryption #InfoSec #Linux #Malware #Mirai #OTX #OpenThreatExchange #Proxy #RAT #RCE #SMS #SSH #bot #botnet #AlienVault

  12. Multi-Functional Linux Botnet "Evooo1Bot"

    A previously undocumented Linux botnet named Evooo1Bot has been discovered, actively targeting Internet-facing devices since July 2026. Built upon Mirai's DDoS engine, it extends functionality with encrypted C2 communications, SSH brute-force scanning, SOCKS relay capabilities, credential sniffing, and an integrated exploit arsenal. The malware employs multi-layer string encryption using AES-256-CTR, ChaCha20, and XOR-based key derivation. It exploits numerous vulnerabilities across edge devices, routers, and enterprise applications. The reverse SOCKS relay module transforms compromised devices into persistent proxies, enabling attackers to conceal their origin and pivot into internal networks. The botnet features 28 remote commands organized into modules for persistence, self-update, file transfer, interactive shell, sniffing, proxy relay, SSH scanning, DDoS attacks, and CVE exploitation. Multiple persistence mechanisms ensure continued operation across systemd, SysV init, cron, and shell profiles.

    Pulse ID: 6a7e2be6ba37cc87ae552659
    Pulse Link: otx.alienvault.com/pulse/6a7e2
    Pulse Author: AlienVault
    Created: 2026-08-13 20:41:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ChaCha20 #CyberSecurity #DDoS #DoS #ELF #Edge #Encryption #InfoSec #Linux #Malware #Mirai #OTX #OpenThreatExchange #Proxy #RAT #RCE #SMS #SSH #bot #botnet #AlienVault

  13. Multi-Functional Linux Botnet "Evooo1Bot"

    A previously undocumented Linux botnet named Evooo1Bot has been discovered, actively targeting Internet-facing devices since July 2026. Built upon Mirai's DDoS engine, it extends functionality with encrypted C2 communications, SSH brute-force scanning, SOCKS relay capabilities, credential sniffing, and an integrated exploit arsenal. The malware employs multi-layer string encryption using AES-256-CTR, ChaCha20, and XOR-based key derivation. It exploits numerous vulnerabilities across edge devices, routers, and enterprise applications. The reverse SOCKS relay module transforms compromised devices into persistent proxies, enabling attackers to conceal their origin and pivot into internal networks. The botnet features 28 remote commands organized into modules for persistence, self-update, file transfer, interactive shell, sniffing, proxy relay, SSH scanning, DDoS attacks, and CVE exploitation. Multiple persistence mechanisms ensure continued operation across systemd, SysV init, cron, and shell profiles.

    Pulse ID: 6a7e2be6ba37cc87ae552659
    Pulse Link: otx.alienvault.com/pulse/6a7e2
    Pulse Author: AlienVault
    Created: 2026-08-13 20:41:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ChaCha20 #CyberSecurity #DDoS #DoS #ELF #Edge #Encryption #InfoSec #Linux #Malware #Mirai #OTX #OpenThreatExchange #Proxy #RAT #RCE #SMS #SSH #bot #botnet #AlienVault

  14. Multi-Functional Linux Botnet "Evooo1Bot"

    A previously undocumented Linux botnet named Evooo1Bot has been discovered, actively targeting Internet-facing devices since July 2026. Built upon Mirai's DDoS engine, it extends functionality with encrypted C2 communications, SSH brute-force scanning, SOCKS relay capabilities, credential sniffing, and an integrated exploit arsenal. The malware employs multi-layer string encryption using AES-256-CTR, ChaCha20, and XOR-based key derivation. It exploits numerous vulnerabilities across edge devices, routers, and enterprise applications. The reverse SOCKS relay module transforms compromised devices into persistent proxies, enabling attackers to conceal their origin and pivot into internal networks. The botnet features 28 remote commands organized into modules for persistence, self-update, file transfer, interactive shell, sniffing, proxy relay, SSH scanning, DDoS attacks, and CVE exploitation. Multiple persistence mechanisms ensure continued operation across systemd, SysV init, cron, and shell profiles.

    Pulse ID: 6a7e2be6ba37cc87ae552659
    Pulse Link: otx.alienvault.com/pulse/6a7e2
    Pulse Author: AlienVault
    Created: 2026-08-13 20:41:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ChaCha20 #CyberSecurity #DDoS #DoS #ELF #Edge #Encryption #InfoSec #Linux #Malware #Mirai #OTX #OpenThreatExchange #Proxy #RAT #RCE #SMS #SSH #bot #botnet #AlienVault

  15. Multi-Functional Linux Botnet "Evooo1Bot"

    A previously undocumented Linux botnet named Evooo1Bot has been discovered, actively targeting Internet-facing devices since July 2026. Built upon Mirai's DDoS engine, it extends functionality with encrypted C2 communications, SSH brute-force scanning, SOCKS relay capabilities, credential sniffing, and an integrated exploit arsenal. The malware employs multi-layer string encryption using AES-256-CTR, ChaCha20, and XOR-based key derivation. It exploits numerous vulnerabilities across edge devices, routers, and enterprise applications. The reverse SOCKS relay module transforms compromised devices into persistent proxies, enabling attackers to conceal their origin and pivot into internal networks. The botnet features 28 remote commands organized into modules for persistence, self-update, file transfer, interactive shell, sniffing, proxy relay, SSH scanning, DDoS attacks, and CVE exploitation. Multiple persistence mechanisms ensure continued operation across systemd, SysV init, cron, and shell profiles.

    Pulse ID: 6a7e2be6ba37cc87ae552659
    Pulse Link: otx.alienvault.com/pulse/6a7e2
    Pulse Author: AlienVault
    Created: 2026-08-13 20:41:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ChaCha20 #CyberSecurity #DDoS #DoS #ELF #Edge #Encryption #InfoSec #Linux #Malware #Mirai #OTX #OpenThreatExchange #Proxy #RAT #RCE #SMS #SSH #bot #botnet #AlienVault

  16. Recent Attack Activity Analysis Using North Korea-Related Lures

    APT-C-06 (Darkhotel) is an APT organization that has been active since at least 2007, targeting corporate executives, defense industries, and electronics sectors. In April 2026, the group launched phishing attacks using a decoy document titled 'North Korean Central Television Real-time Broadcasting Program Instructions.' The document instructs users to download an application for watching North Korean Central Television. By late May, attacks evolved to deliver malicious MSI files through phishing emails. These MSI files execute VBS code that creates scheduled tasks to download and execute PowerShell scripts, which then retrieve subsequent payloads. The malware employs ChaCha20 encryption and ultimately deploys shellcode. PowerShell has become a high-frequency component in APT-C-06's attack chain since 2025, handling payload downloads and persistence mechanisms.

    Pulse ID: 6a7dc1fd395815126acd4647
    Pulse Link: otx.alienvault.com/pulse/6a7dc
    Pulse Author: AlienVault
    Created: 2026-08-13 13:09:17

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ChaCha20 #CyberSecurity #Email #Encryption #ICS #InfoSec #Korea #Malware #NorthKorea #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SMS #ShellCode #VBS #bot #AlienVault

  17. Recent Attack Activity Analysis Using North Korea-Related Lures

    APT-C-06 (Darkhotel) is an APT organization that has been active since at least 2007, targeting corporate executives, defense industries, and electronics sectors. In April 2026, the group launched phishing attacks using a decoy document titled 'North Korean Central Television Real-time Broadcasting Program Instructions.' The document instructs users to download an application for watching North Korean Central Television. By late May, attacks evolved to deliver malicious MSI files through phishing emails. These MSI files execute VBS code that creates scheduled tasks to download and execute PowerShell scripts, which then retrieve subsequent payloads. The malware employs ChaCha20 encryption and ultimately deploys shellcode. PowerShell has become a high-frequency component in APT-C-06's attack chain since 2025, handling payload downloads and persistence mechanisms.

    Pulse ID: 6a7dc1fd395815126acd4647
    Pulse Link: otx.alienvault.com/pulse/6a7dc
    Pulse Author: AlienVault
    Created: 2026-08-13 13:09:17

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ChaCha20 #CyberSecurity #Email #Encryption #ICS #InfoSec #Korea #Malware #NorthKorea #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SMS #ShellCode #VBS #bot #AlienVault

  18. Recent Attack Activity Analysis Using North Korea-Related Lures

    APT-C-06 (Darkhotel) is an APT organization that has been active since at least 2007, targeting corporate executives, defense industries, and electronics sectors. In April 2026, the group launched phishing attacks using a decoy document titled 'North Korean Central Television Real-time Broadcasting Program Instructions.' The document instructs users to download an application for watching North Korean Central Television. By late May, attacks evolved to deliver malicious MSI files through phishing emails. These MSI files execute VBS code that creates scheduled tasks to download and execute PowerShell scripts, which then retrieve subsequent payloads. The malware employs ChaCha20 encryption and ultimately deploys shellcode. PowerShell has become a high-frequency component in APT-C-06's attack chain since 2025, handling payload downloads and persistence mechanisms.

    Pulse ID: 6a7dc1fd395815126acd4647
    Pulse Link: otx.alienvault.com/pulse/6a7dc
    Pulse Author: AlienVault
    Created: 2026-08-13 13:09:17

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ChaCha20 #CyberSecurity #Email #Encryption #ICS #InfoSec #Korea #Malware #NorthKorea #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SMS #ShellCode #VBS #bot #AlienVault

  19. Recent Attack Activity Analysis Using North Korea-Related Lures

    APT-C-06 (Darkhotel) is an APT organization that has been active since at least 2007, targeting corporate executives, defense industries, and electronics sectors. In April 2026, the group launched phishing attacks using a decoy document titled 'North Korean Central Television Real-time Broadcasting Program Instructions.' The document instructs users to download an application for watching North Korean Central Television. By late May, attacks evolved to deliver malicious MSI files through phishing emails. These MSI files execute VBS code that creates scheduled tasks to download and execute PowerShell scripts, which then retrieve subsequent payloads. The malware employs ChaCha20 encryption and ultimately deploys shellcode. PowerShell has become a high-frequency component in APT-C-06's attack chain since 2025, handling payload downloads and persistence mechanisms.

    Pulse ID: 6a7dc1fd395815126acd4647
    Pulse Link: otx.alienvault.com/pulse/6a7dc
    Pulse Author: AlienVault
    Created: 2026-08-13 13:09:17

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ChaCha20 #CyberSecurity #Email #Encryption #ICS #InfoSec #Korea #Malware #NorthKorea #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SMS #ShellCode #VBS #bot #AlienVault

  20. Recent Attack Activity Analysis Using North Korea-Related Lures

    APT-C-06 (Darkhotel) is an APT organization that has been active since at least 2007, targeting corporate executives, defense industries, and electronics sectors. In April 2026, the group launched phishing attacks using a decoy document titled 'North Korean Central Television Real-time Broadcasting Program Instructions.' The document instructs users to download an application for watching North Korean Central Television. By late May, attacks evolved to deliver malicious MSI files through phishing emails. These MSI files execute VBS code that creates scheduled tasks to download and execute PowerShell scripts, which then retrieve subsequent payloads. The malware employs ChaCha20 encryption and ultimately deploys shellcode. PowerShell has become a high-frequency component in APT-C-06's attack chain since 2025, handling payload downloads and persistence mechanisms.

    Pulse ID: 6a7dc1fd395815126acd4647
    Pulse Link: otx.alienvault.com/pulse/6a7dc
    Pulse Author: AlienVault
    Created: 2026-08-13 13:09:17

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ChaCha20 #CyberSecurity #Email #Encryption #ICS #InfoSec #Korea #Malware #NorthKorea #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SMS #ShellCode #VBS #bot #AlienVault

  21. DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

    DeadLock is an emerging ransomware operation first observed in July 2025, distinguished by its use of decentralized infrastructure combining Session messaging network with blockchain-backed services for victim communications and data leak operations. The encryptor implements double extortion tactics, encrypting files while threatening to leak exfiltrated data, with over 80 organizations published on their leak site as of July 2026. The malware features a resource-aware throttling mechanism to maintain system responsiveness during encryption, language-based geofencing to avoid former Soviet and CIS countries, and hybrid cryptography using Curve25519 and XChaCha20. Its recovery ecosystem leverages Polygon blockchain for configuration storage, Session network for encrypted communications, and Wasabi file hosting, creating resilient infrastructure resistant to traditional takedown efforts. Multiple groups have deployed DeadLock, including affiliates of Lynx and INC ransomware ecosystems, targeting organization...

    Pulse ID: 6a7a12d2aa28d8347ab323f6
    Pulse Link: otx.alienvault.com/pulse/6a7a1
    Pulse Author: AlienVault
    Created: 2026-08-10 18:05:06

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BlockChain #ChaCha20 #CyberSecurity #Encryption #Extortion #ICS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Rust #bot #AlienVault

  22. DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

    DeadLock is an emerging ransomware operation first observed in July 2025, distinguished by its use of decentralized infrastructure combining Session messaging network with blockchain-backed services for victim communications and data leak operations. The encryptor implements double extortion tactics, encrypting files while threatening to leak exfiltrated data, with over 80 organizations published on their leak site as of July 2026. The malware features a resource-aware throttling mechanism to maintain system responsiveness during encryption, language-based geofencing to avoid former Soviet and CIS countries, and hybrid cryptography using Curve25519 and XChaCha20. Its recovery ecosystem leverages Polygon blockchain for configuration storage, Session network for encrypted communications, and Wasabi file hosting, creating resilient infrastructure resistant to traditional takedown efforts. Multiple groups have deployed DeadLock, including affiliates of Lynx and INC ransomware ecosystems, targeting organization...

    Pulse ID: 6a7a12d2aa28d8347ab323f6
    Pulse Link: otx.alienvault.com/pulse/6a7a1
    Pulse Author: AlienVault
    Created: 2026-08-10 18:05:06

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BlockChain #ChaCha20 #CyberSecurity #Encryption #Extortion #ICS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Rust #bot #AlienVault

  23. DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

    DeadLock is an emerging ransomware operation first observed in July 2025, distinguished by its use of decentralized infrastructure combining Session messaging network with blockchain-backed services for victim communications and data leak operations. The encryptor implements double extortion tactics, encrypting files while threatening to leak exfiltrated data, with over 80 organizations published on their leak site as of July 2026. The malware features a resource-aware throttling mechanism to maintain system responsiveness during encryption, language-based geofencing to avoid former Soviet and CIS countries, and hybrid cryptography using Curve25519 and XChaCha20. Its recovery ecosystem leverages Polygon blockchain for configuration storage, Session network for encrypted communications, and Wasabi file hosting, creating resilient infrastructure resistant to traditional takedown efforts. Multiple groups have deployed DeadLock, including affiliates of Lynx and INC ransomware ecosystems, targeting organization...

    Pulse ID: 6a7a12d2aa28d8347ab323f6
    Pulse Link: otx.alienvault.com/pulse/6a7a1
    Pulse Author: AlienVault
    Created: 2026-08-10 18:05:06

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BlockChain #ChaCha20 #CyberSecurity #Encryption #Extortion #ICS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Rust #bot #AlienVault

  24. DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

    DeadLock is an emerging ransomware operation first observed in July 2025, distinguished by its use of decentralized infrastructure combining Session messaging network with blockchain-backed services for victim communications and data leak operations. The encryptor implements double extortion tactics, encrypting files while threatening to leak exfiltrated data, with over 80 organizations published on their leak site as of July 2026. The malware features a resource-aware throttling mechanism to maintain system responsiveness during encryption, language-based geofencing to avoid former Soviet and CIS countries, and hybrid cryptography using Curve25519 and XChaCha20. Its recovery ecosystem leverages Polygon blockchain for configuration storage, Session network for encrypted communications, and Wasabi file hosting, creating resilient infrastructure resistant to traditional takedown efforts. Multiple groups have deployed DeadLock, including affiliates of Lynx and INC ransomware ecosystems, targeting organization...

    Pulse ID: 6a7a12d2aa28d8347ab323f6
    Pulse Link: otx.alienvault.com/pulse/6a7a1
    Pulse Author: AlienVault
    Created: 2026-08-10 18:05:06

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BlockChain #ChaCha20 #CyberSecurity #Encryption #Extortion #ICS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Rust #bot #AlienVault

  25. DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

    DeadLock is an emerging ransomware operation first observed in July 2025, distinguished by its use of decentralized infrastructure combining Session messaging network with blockchain-backed services for victim communications and data leak operations. The encryptor implements double extortion tactics, encrypting files while threatening to leak exfiltrated data, with over 80 organizations published on their leak site as of July 2026. The malware features a resource-aware throttling mechanism to maintain system responsiveness during encryption, language-based geofencing to avoid former Soviet and CIS countries, and hybrid cryptography using Curve25519 and XChaCha20. Its recovery ecosystem leverages Polygon blockchain for configuration storage, Session network for encrypted communications, and Wasabi file hosting, creating resilient infrastructure resistant to traditional takedown efforts. Multiple groups have deployed DeadLock, including affiliates of Lynx and INC ransomware ecosystems, targeting organization...

    Pulse ID: 6a7a12d2aa28d8347ab323f6
    Pulse Link: otx.alienvault.com/pulse/6a7a1
    Pulse Author: AlienVault
    Created: 2026-08-10 18:05:06

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BlockChain #ChaCha20 #CyberSecurity #Encryption #Extortion #ICS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Rust #bot #AlienVault

  26. 📢 MedusaHVNC : un RAT MaaS qui détourne des sessions navigateur via un bureau caché Windows
    📝 🔍 **Contexte** : Le 27 juillet 2026, BlackFog publie une analyse technique détaillée de **MedusaHVNC**, un nouveau **remote access trojan (RAT)...
    📖 cyberveille : cyberveille.ch/posts/2026-07-2
    🌐 source : blackfog.com/medusahvnc-a-hidd
    #AutoIt #ChaCha20 #Cyberveille

  27. 📢 VECT 2.0 : un ransomware RaaS qui détruit irrémédiablement les fichiers par défaut de conception
    📝 ## 🔍 Contexte

    Publié le 28 avril 2026 par Check Point Research (CPR), cet article présente une analys...
    📖 cyberveille : cyberveille.ch/posts/2026-04-2
    🌐 source : research.checkpoint.com/2026/v
    #ChaCha20 #ESXi #Cyberveille

  28. Szyfrowanie danych, usuwanie backupów, zacieranie śladów… analiza ransomware Dire Wolf

    Dire Wolf jest nową grupą przestępczą, której aktywność zaobserwowano w maju br. Pierwszymi ofiarami cyberprzestępców były firmy z sektora technologicznego, finansowego oraz budownictwa działające we Włoszech, Tajlandii, Australii oraz Indii. Działania cyberprzestępców ukierunkowane są głównie na zysk finansowy. W celu zwiększenia szansy na uzyskanie okupu, wykorzystują technikę double extortion, grożąc...

    #Teksty #Chacha20 #Curbe25519 #Direwolf #DoubleExtortion #Ransomware

    sekurak.pl/szyfrowanie-danych-

  29. Szyfrowanie danych, usuwanie backupów, zacieranie śladów… analiza ransomware Dire Wolf

    Dire Wolf jest nową grupą przestępczą, której aktywność zaobserwowano w maju br. Pierwszymi ofiarami cyberprzestępców były firmy z sektora technologicznego, finansowego oraz budownictwa działające we Włoszech, Tajlandii, Australii oraz Indii. Działania cyberprzestępców ukierunkowane są głównie na zysk finansowy. W celu zwiększenia szansy na uzyskanie okupu, wykorzystują technikę double extortion, grożąc...

    #Teksty #Chacha20 #Curbe25519 #Direwolf #DoubleExtortion #Ransomware

    sekurak.pl/szyfrowanie-danych-

  30. Szyfrowanie danych, usuwanie backupów, zacieranie śladów… analiza ransomware Dire Wolf

    Dire Wolf jest nową grupą przestępczą, której aktywność zaobserwowano w maju br. Pierwszymi ofiarami cyberprzestępców były firmy z sektora technologicznego, finansowego oraz budownictwa działające we Włoszech, Tajlandii, Australii oraz Indii. Działania cyberprzestępców ukierunkowane są głównie na zysk finansowy. W celu zwiększenia szansy na uzyskanie okupu, wykorzystują technikę double extortion, grożąc...

    #Teksty #Chacha20 #Curbe25519 #Direwolf #DoubleExtortion #Ransomware

    sekurak.pl/szyfrowanie-danych-

  31. Szyfrowanie danych, usuwanie backupów, zacieranie śladów… analiza ransomware Dire Wolf

    Dire Wolf jest nową grupą przestępczą, której aktywność zaobserwowano w maju br. Pierwszymi ofiarami cyberprzestępców były firmy z sektora technologicznego, finansowego oraz budownictwa działające we Włoszech, Tajlandii, Australii oraz Indii. Działania cyberprzestępców ukierunkowane są głównie na zysk finansowy. W celu zwiększenia szansy na uzyskanie okupu, wykorzystują technikę double extortion, grożąc...

    #Teksty #Chacha20 #Curbe25519 #Direwolf #DoubleExtortion #Ransomware

    sekurak.pl/szyfrowanie-danych-

  32. Szyfrowanie danych, usuwanie backupów, zacieranie śladów… analiza ransomware Dire Wolf

    Dire Wolf jest nową grupą przestępczą, której aktywność zaobserwowano w maju br. Pierwszymi ofiarami cyberprzestępców były firmy z sektora technologicznego, finansowego oraz budownictwa działające we Włoszech, Tajlandii, Australii oraz Indii. Działania cyberprzestępców ukierunkowane są głównie na zysk finansowy. W celu zwiększenia szansy na uzyskanie okupu, wykorzystują technikę double extortion, grożąc...

    #Teksty #Chacha20 #Curbe25519 #Direwolf #DoubleExtortion #Ransomware

    sekurak.pl/szyfrowanie-danych-

  33. Black Basta Ransomware: What You Need to Know

    Black Basta is a ransomware-as-a-service group that emerged in April 2022, known for double extortion tactics. They target organizations globally, particularly in North America, Europe, and Australia, affecting over 500 entities across various industries. Initial access is gained through phishing, Qakbot, Cobalt Strike, and vulnerability exploitation. The group uses tools like Mimikatz for credential theft and lateral movement. Their process involves data exfiltration using Rclone, followed by file encryption using the ChaCha20 algorithm. The ransomware disables system defenses, deletes shadow copies, and leaves a ransom note. Black Basta has been linked to the FIN7 threat actor due to similarities in EDR evasion techniques.

    Pulse ID: 66ed5a9c197554aebcf74460
    Pulse Link: otx.alienvault.com/pulse/66ed5
    Pulse Author: AlienVault
    Created: 2024-09-20 11:21:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Australia #ChaCha20 #CobaltStrike #CyberSecurity #EDR #Encryption #Europe #Extortion #ICS #InfoSec #NorthAmerica #OTX #OpenThreatExchange #Phishing #Qakbot #RAT #RansomWare #RansomwareAsAService #Rclone #Vulnerability #bot #AlienVault

  34. [Перевод] ChaCha, модификация Salsa20

    ChaCha8 это 256-битный поточный шифр, основанный на 8-раунодовом шифре Salsa20/8. Новшества, привнесенные при работе от Salsa20/8 до ChaCha8, позволили улучшить перемежение бит за раунд, тем самым повысив стойкость к криптоанализу при сохранении, а иногда и уменьшении, времени требуемого на вычисления одного раунда. ChaCha12 и ChaCha20 являются аналогичными модификациями 12-раундового и 20-раундового шифров Salsa20/12 и Salsa20/20. В данной статье описывается семейство шифров ChaCha и объясняется разница между Salsa20 и ChaCha.

    habr.com/ru/articles/784452/

    #chacha20 #daniel_j_bernstein #перевод #перевод_с_английского

  35. [Перевод] ChaCha, модификация Salsa20

    ChaCha8 это 256-битный поточный шифр, основанный на 8-раунодовом шифре Salsa20/8. Новшества, привнесенные при работе от Salsa20/8 до ChaCha8, позволили улучшить перемежение бит за раунд, тем самым повысив стойкость к криптоанализу при сохранении, а иногда и уменьшении, времени требуемого на вычисления одного раунда. ChaCha12 и ChaCha20 являются аналогичными модификациями 12-раундового и 20-раундового шифров Salsa20/12 и Salsa20/20. В данной статье описывается семейство шифров ChaCha и объясняется разница между Salsa20 и ChaCha.

    habr.com/ru/articles/784452/

    #chacha20 #daniel_j_bernstein #перевод #перевод_с_английского

  36. [DE] Ein bisschen Krikelkrakel für einen Kurzvortrag zu @rosenpass und postquantensicherer Kryptografie. Im Safe sind natürlich die sichersten Verfahren gegen regnerische post-quanten-Tage. :)

    [EN] A handful of chicken scratch for a short talk about #RosenPass and post-quantum secure cryptography. When quantum computers finally rain down on our information systems, there’s different levels of security you can have.

    #cryptography #shors #grovers #kyber #mceliece #chacha20

  37. [DE] Ein bisschen Krikelkrakel für einen Kurzvortrag zu @rosenpass und postquantensicherer Kryptografie. Im Safe sind natürlich die sichersten Verfahren gegen regnerische post-quanten-Tage. :)

    [EN] A handful of chicken scratch for a short talk about #RosenPass and post-quantum secure cryptography. When quantum computers finally rain down on our information systems, there’s different levels of security you can have.

    #cryptography #shors #grovers #kyber #mceliece #chacha20

  38. [DE] Ein bisschen Krikelkrakel für einen Kurzvortrag zu @rosenpass und postquantensicherer Kryptografie. Im Safe sind natürlich die sichersten Verfahren gegen regnerische post-quanten-Tage. :)

    [EN] A handful of chicken scratch for a short talk about #RosenPass and post-quantum secure cryptography. When quantum computers finally rain down on our information systems, there’s different levels of security you can have.

    #cryptography #shors #grovers #kyber #mceliece #chacha20

  39. [DE] Ein bisschen Krikelkrakel für einen Kurzvortrag zu @rosenpass und postquantensicherer Kryptografie. Im Safe sind natürlich die sichersten Verfahren gegen regnerische post-quanten-Tage. :)

    [EN] A handful of chicken scratch for a short talk about #RosenPass and post-quantum secure cryptography. When quantum computers finally rain down on our information systems, there’s different levels of security you can have.

    #cryptography #shors #grovers #kyber #mceliece #chacha20

  40. [DE] Ein bisschen Krikelkrakel für einen Kurzvortrag zu @rosenpass und postquantensicherer Kryptografie. Im Safe sind natürlich die sichersten Verfahren gegen regnerische post-quanten-Tage. :)

    [EN] A handful of chicken scratch for a short talk about #RosenPass and post-quantum secure cryptography. When quantum computers finally rain down on our information systems, there’s different levels of security you can have.

    #cryptography #shors #grovers #kyber #mceliece #chacha20

  41. CW: research review

    S. Dey et al., "Cryptanalysis of Reduced Round ChaCha- New Attack and Deeper Analysis"¹

    In this paper we present several analyses on ChaCha, a software stream cipher. First, we consider a divide-and-conquer approach on the secret key bits by partitioning them. The partitions are based on multiple input-output differentials to obtain a significantly improved attack on 6-round ChaCha256 with a complexity of 2^{99.48}. It is 2^{40} times faster than the currently best known attack. Note that, this is the first time an attack could be mounted on reduced round ChaCha with a complexity significantly less than 2^{k}{2}, where the secret key is of k bits. Further, we note that all the attack complexities related to ChaCha are theoretically estimated in general and there are several questions in this regard as pointed out by Dey et al. in Eurocrypt 2022. In this regard, we propose a toy version of ChaCha, with a 32-bit secret key, on which the attacks can be implemented completely to verify whether the theoretical estimates are justified. This idea is implemented for our proposed attack on 6 rounds. Finally, we show that it is possible to estimate the success probabilities of these kinds of PNB-based differential attacks more accurately. Our methodology explains how different cryptanalytic results can be evaluated with better accuracy rather than claiming (Aumasson et al., 2008) that the success probability is significantly better than 50%.

    #IACR #ResearchPapers #ARX #ChaCha20 #ProbabilisticNeutralBits #Cryptanalysis #DifferentialAttack #Cryptography
    __
    ¹ eprint.iacr.org/2023/134

  42. CW: research review

    S. Dey et al., "Cryptanalysis of Reduced Round ChaCha- New Attack and Deeper Analysis"¹

    In this paper we present several analyses on ChaCha, a software stream cipher. First, we consider a divide-and-conquer approach on the secret key bits by partitioning them. The partitions are based on multiple input-output differentials to obtain a significantly improved attack on 6-round ChaCha256 with a complexity of 2^{99.48}. It is 2^{40} times faster than the currently best known attack. Note that, this is the first time an attack could be mounted on reduced round ChaCha with a complexity significantly less than 2^{k}{2}, where the secret key is of k bits. Further, we note that all the attack complexities related to ChaCha are theoretically estimated in general and there are several questions in this regard as pointed out by Dey et al. in Eurocrypt 2022. In this regard, we propose a toy version of ChaCha, with a 32-bit secret key, on which the attacks can be implemented completely to verify whether the theoretical estimates are justified. This idea is implemented for our proposed attack on 6 rounds. Finally, we show that it is possible to estimate the success probabilities of these kinds of PNB-based differential attacks more accurately. Our methodology explains how different cryptanalytic results can be evaluated with better accuracy rather than claiming (Aumasson et al., 2008) that the success probability is significantly better than 50%.

    #IACR #ResearchPapers #ARX #ChaCha20 #ProbabilisticNeutralBits #Cryptanalysis #DifferentialAttack #Cryptography
    __
    ¹ eprint.iacr.org/2023/134

  43. CW: research review

    S. Dey et al., "Cryptanalysis of Reduced Round ChaCha- New Attack and Deeper Analysis"¹

    In this paper we present several analyses on ChaCha, a software stream cipher. First, we consider a divide-and-conquer approach on the secret key bits by partitioning them. The partitions are based on multiple input-output differentials to obtain a significantly improved attack on 6-round ChaCha256 with a complexity of 2^{99.48}. It is 2^{40} times faster than the currently best known attack. Note that, this is the first time an attack could be mounted on reduced round ChaCha with a complexity significantly less than 2^{k}{2}, where the secret key is of k bits. Further, we note that all the attack complexities related to ChaCha are theoretically estimated in general and there are several questions in this regard as pointed out by Dey et al. in Eurocrypt 2022. In this regard, we propose a toy version of ChaCha, with a 32-bit secret key, on which the attacks can be implemented completely to verify whether the theoretical estimates are justified. This idea is implemented for our proposed attack on 6 rounds. Finally, we show that it is possible to estimate the success probabilities of these kinds of PNB-based differential attacks more accurately. Our methodology explains how different cryptanalytic results can be evaluated with better accuracy rather than claiming (Aumasson et al., 2008) that the success probability is significantly better than 50%.

    #IACR #ResearchPapers #ARX #ChaCha20 #ProbabilisticNeutralBits #Cryptanalysis #DifferentialAttack #Cryptography
    __
    ¹ eprint.iacr.org/2023/134

  44. CW: research review

    S. Dey et al., "Cryptanalysis of Reduced Round ChaCha- New Attack and Deeper Analysis"¹

    In this paper we present several analyses on ChaCha, a software stream cipher. First, we consider a divide-and-conquer approach on the secret key bits by partitioning them. The partitions are based on multiple input-output differentials to obtain a significantly improved attack on 6-round ChaCha256 with a complexity of 2^{99.48}. It is 2^{40} times faster than the currently best known attack. Note that, this is the first time an attack could be mounted on reduced round ChaCha with a complexity significantly less than 2^{k}{2}, where the secret key is of k bits. Further, we note that all the attack complexities related to ChaCha are theoretically estimated in general and there are several questions in this regard as pointed out by Dey et al. in Eurocrypt 2022. In this regard, we propose a toy version of ChaCha, with a 32-bit secret key, on which the attacks can be implemented completely to verify whether the theoretical estimates are justified. This idea is implemented for our proposed attack on 6 rounds. Finally, we show that it is possible to estimate the success probabilities of these kinds of PNB-based differential attacks more accurately. Our methodology explains how different cryptanalytic results can be evaluated with better accuracy rather than claiming (Aumasson et al., 2008) that the success probability is significantly better than 50%.

    #IACR #ResearchPapers #ARX #ChaCha20 #ProbabilisticNeutralBits #Cryptanalysis #DifferentialAttack #Cryptography
    __
    ¹ eprint.iacr.org/2023/134

  45. Which do you consider to be more secure?

    (Yes, I understand that the symmetric cipher itself is almost never the weak point in any modern cryptosystem)

    #AES #CHACHA20 #infosec #cryptography #encryption

  46. Which do you consider to be more secure?

    (Yes, I understand that the symmetric cipher itself is almost never the weak point in any modern cryptosystem)

    #AES #CHACHA20 #infosec #cryptography #encryption

  47. Which do you consider to be more secure?

    (Yes, I understand that the symmetric cipher itself is almost never the weak point in any modern cryptosystem)

    #AES #CHACHA20 #infosec #cryptography #encryption

  48. Which do you consider to be more secure?

    (Yes, I understand that the symmetric cipher itself is almost never the weak point in any modern cryptosystem)

    #AES #CHACHA20 #infosec #cryptography #encryption

  49. Which do you consider to be more secure?

    (Yes, I understand that the symmetric cipher itself is almost never the weak point in any modern cryptosystem)

    #AES #CHACHA20 #infosec #cryptography #encryption