#lolbins — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #lolbins, aggregated by home.social.
-
Git clone malware – come i ransomware group sfruttano l'open source (aka il LOLBins dei poveri) - Che incubo! DI NUOVO @signorina37 al @[email protected]! 😂
#LOLBins
Living Off the Land Binaries
"Usare strumenti già presenti nel sistema per fare cose che il sistema non vorrebbe che tu facessi." -
Git clone malware – come i ransomware group sfruttano l'open source (aka il LOLBins dei poveri) - Che incubo! DI NUOVO @signorina37 al @[email protected]! 😂
#LOLBins
Living Off the Land Binaries
"Usare strumenti già presenti nel sistema per fare cose che il sistema non vorrebbe che tu facessi." -
CrashFix marks a notable escalation in ClickFix tradecraft.
The campaign combines browser DoS, fake Chrome extensions, delayed execution, LOLBin abuse (finger.exe → ct.exe), and a portable Python environment to deploy a covert RAT only after identifying high-value systems.
This is a strong case for:
• Behavior-based detection
• EDR in block mode
• Restricting legacy utilities
• User-focused threat modeling💬 Which detection layer would catch this earliest in your environment?
🔔 Follow @technadu for deep technical threat analysis
#InfoSec #CrashFix #ClickFix #PythonMalware #LOLBins #EDR #ThreatHunting #DetectionEngineering #MicrosoftDefender #TechNadu
-
Microsoft elimanará WMIC en la actualización Windows 11 25H2 https://blog.elhacker.net/2025/09/microsoft-elimanara-wmic-lolbin-windows11.html #powershell #ransomware #LOLBins #Windows #wmi
-
Microsoft elimanará WMIC en la actualización Windows 11 25H2 https://blog.elhacker.net/2025/09/microsoft-elimanara-wmic-lolbin-windows11.html #powershell #ransomware #LOLBins #Windows #wmi
-
No PE header? No problem.
@FortiGuardLabs dropped a deep dive into a malware sample dumped without a PE header — like a cybercriminal rage-quit halfway through packing their payload.
You ever load a binary in IDA and think, “Am I being punk’d?”
Yeah, it’s one of those samples.This sample:
Reconstructs its own PE structure at runtime
Hides config data in obfuscated blobs
Uses anti-sandbox tricks to avoid analysis
Drops yet another info-stealer, because originality is dead
It’s engineered to break basic static analysis and dodge sandboxes like it’s speedrunning DEFCON CTF.
🔗 Full breakdown:
https://www.fortinet.com/blog/threat-research/deep-dive-into-a-dumped-malware-without-a-pe-headerTL;DR for blue teamers:
Static AV signatures won’t help here
Watch for suspicious memory allocations + hollowing patterns
Endpoint heuristics > file-based detection
Log your PowerShell and LOLBins — this thing probably brings friends
If your EDR cries when it sees raw shellcode, maybe give it a hug
#ThreatIntel #MalwareAnalysis #ReverseEngineering #Infosec #PEFilesAreSo2020 #EDREvasion #LOLbins #CyberSecurity #BlueTeam
-
No PE header? No problem.
@FortiGuardLabs dropped a deep dive into a malware sample dumped without a PE header — like a cybercriminal rage-quit halfway through packing their payload.
You ever load a binary in IDA and think, “Am I being punk’d?”
Yeah, it’s one of those samples.This sample:
Reconstructs its own PE structure at runtime
Hides config data in obfuscated blobs
Uses anti-sandbox tricks to avoid analysis
Drops yet another info-stealer, because originality is dead
It’s engineered to break basic static analysis and dodge sandboxes like it’s speedrunning DEFCON CTF.
🔗 Full breakdown:
https://www.fortinet.com/blog/threat-research/deep-dive-into-a-dumped-malware-without-a-pe-headerTL;DR for blue teamers:
Static AV signatures won’t help here
Watch for suspicious memory allocations + hollowing patterns
Endpoint heuristics > file-based detection
Log your PowerShell and LOLBins — this thing probably brings friends
If your EDR cries when it sees raw shellcode, maybe give it a hug
#ThreatIntel #MalwareAnalysis #ReverseEngineering #Infosec #PEFilesAreSo2020 #EDREvasion #LOLbins #CyberSecurity #BlueTeam
-
They don’t need malware. They weaponize what’s already trusted - PowerShell, WMI, CertUtil. This is Living Off the Land. Defend or be devoured.
#LOLBins #infosec #cybersecurity #redteam #ethicalhacking #windowssecurity #postexploitation #DeadSwitchhttp://tomsitcafe.com/2025/05/06/living-off-the-land-how-hackers-use-your-tools-against-you/
-
They don’t need malware. They weaponize what’s already trusted - PowerShell, WMI, CertUtil. This is Living Off the Land. Defend or be devoured.
#LOLBins #infosec #cybersecurity #redteam #ethicalhacking #windowssecurity #postexploitation #DeadSwitchhttp://tomsitcafe.com/2025/05/06/living-off-the-land-how-hackers-use-your-tools-against-you/
-
Was looking for a good Awesome list on Living Off the Land ( #LOL #LOtL ) tools/techniques. Found some helpful sites / repos but either nothing I could contribute to or it was limited.
So... I made one: https://github.com/danzek/awesome-lol-commonly-abused
Contributions welcome, whether by replying to this post or sending a PR on GitHub.
-
#Hackers are abusing #Microsoft tools more than ever before
Abuse of #LOLbins in #cyberattacks is skyrocketing, Sophos says
https://www.techradar.com/pro/security/hackers-are-abusing-microsoft-tools-more-than-ever-before
-
#Hackers are abusing #Microsoft tools more than ever before
Abuse of #LOLbins in #cyberattacks is skyrocketing, Sophos says
https://www.techradar.com/pro/security/hackers-are-abusing-microsoft-tools-more-than-ever-before
-
The Bite from Inside: The Sophos Active Adversary Report – Source: news.sophos.com https://ciso2ciso.com/the-bite-from-inside-the-sophos-active-adversary-report-source-news-sophos-com/ #ActiveAdversaryReport #SecurityOperations #incidentresponse #activeadversary #ThreatResearch #nakedsecurity #0CISO2CISO #featured #LoLBINs #MDR #RDP #IR
-
The Bite from Inside: The Sophos Active Adversary Report – Source: news.sophos.com https://ciso2ciso.com/the-bite-from-inside-the-sophos-active-adversary-report-source-news-sophos-com/ #ActiveAdversaryReport #SecurityOperations #incidentresponse #activeadversary #ThreatResearch #nakedsecurity #0CISO2CISO #featured #LoLBINs #MDR #RDP #IR
-
Detecting Malicious Use of LOLBins: https://www.huntress.com/blog/detecting-malicious-use-of-lolbins
-
Anatomía de un ataque del ransomware Akira https://blog.elhacker.net/2024/07/anatomia-de-un-ataque-del-ransomware-akira.html #ransomware #LOLBins #akira #ioc #ttp
-
Anatomía de un ataque del ransomware Akira https://blog.elhacker.net/2024/07/anatomia-de-un-ataque-del-ransomware-akira.html #ransomware #LOLBins #akira #ioc #ttp
-
Did you know that the finger command can be used for data exfil? We recently had an incident where this type of activity was found
https://www.huntress.com/blog/cant-touch-this-data-exfiltration-via-finger
#DFIR #lolbins #lolbas #exfil #mchammer #CTI #cybersecurity
@keydet89 -
Did you know that the finger command can be used for data exfil? We recently had an incident where this type of activity was found
https://www.huntress.com/blog/cant-touch-this-data-exfiltration-via-finger
#DFIR #lolbins #lolbas #exfil #mchammer #CTI #cybersecurity
@keydet89 -
"🍎 macOS Malware 2023: Navigating the New Threat Landscape 🌐"
Apple's XProtect recently updated to version 2173, introducing rules for Atomic Stealer and Adload. However, 2023 has unveiled novel methods to compromise Macs, leaving users vulnerable unless additional protective measures are taken. Key insights:
Shift in Malware Behavior: Many macOS malware families in 2023 have ditched persistence. Infostealers, for instance, achieve their goals in a single execution, stealing user data and then transmitting it to a remote server. 📥🔓
Sophisticated Social Engineering: Threat actors are employing advanced social engineering tactics. RustBucket malware, for example, lured victims with a business deal, urging them to download a 'proprietary' PDF viewer, which in reality was malware. 🎣📄
Public Offensive Security Tools: Tools like Geacon, which wraps Cobalt Strike capabilities, are now being seen in macOS malware. Open-source red teaming tools like Mythic and Poseidon have also been spotted in recent campaigns. 🛠️🔥
LOLBins Techniques: "Living off the orchard" techniques are on the rise in macOS. Built-in tools like system_profiler, sw_vers, and curl are being exploited for malicious purposes. 🌳🔧
Abusing Open Source Software: JokerSpy malware, discovered in July 2023, began its infection through a trojanized QR code generator, QRLog. This malware was found in enterprise breaches, including a major cryptocurrency exchange. 🔄💼
Complex Multi-Stage Malware: The Smooth Operator campaign, a sophisticated supply chain attack, compromised businesses via 3CX's call routing software client. The malware was designed for stealth, gathering limited data and then self-deleting. 📞🕵️
While Apple is enhancing its malware detection capabilities, third-party solutions are still crucial for comprehensive protection against both common and advanced threats. SentinelOne offers a robust platform for macOS threat detection and remediation. 🛡️💻
Source: SentinelOne
Tags: #macOS #Malware #CyberSecurity #XProtect #Infostealers #SocialEngineering #OffensiveSecurity #LOLBins #OpenSource #SentinelOne 🌍🔒🖥️
-
"🍎 macOS Malware 2023: Navigating the New Threat Landscape 🌐"
Apple's XProtect recently updated to version 2173, introducing rules for Atomic Stealer and Adload. However, 2023 has unveiled novel methods to compromise Macs, leaving users vulnerable unless additional protective measures are taken. Key insights:
Shift in Malware Behavior: Many macOS malware families in 2023 have ditched persistence. Infostealers, for instance, achieve their goals in a single execution, stealing user data and then transmitting it to a remote server. 📥🔓
Sophisticated Social Engineering: Threat actors are employing advanced social engineering tactics. RustBucket malware, for example, lured victims with a business deal, urging them to download a 'proprietary' PDF viewer, which in reality was malware. 🎣📄
Public Offensive Security Tools: Tools like Geacon, which wraps Cobalt Strike capabilities, are now being seen in macOS malware. Open-source red teaming tools like Mythic and Poseidon have also been spotted in recent campaigns. 🛠️🔥
LOLBins Techniques: "Living off the orchard" techniques are on the rise in macOS. Built-in tools like system_profiler, sw_vers, and curl are being exploited for malicious purposes. 🌳🔧
Abusing Open Source Software: JokerSpy malware, discovered in July 2023, began its infection through a trojanized QR code generator, QRLog. This malware was found in enterprise breaches, including a major cryptocurrency exchange. 🔄💼
Complex Multi-Stage Malware: The Smooth Operator campaign, a sophisticated supply chain attack, compromised businesses via 3CX's call routing software client. The malware was designed for stealth, gathering limited data and then self-deleting. 📞🕵️
While Apple is enhancing its malware detection capabilities, third-party solutions are still crucial for comprehensive protection against both common and advanced threats. SentinelOne offers a robust platform for macOS threat detection and remediation. 🛡️💻
Source: SentinelOne
Tags: #macOS #Malware #CyberSecurity #XProtect #Infostealers #SocialEngineering #OffensiveSecurity #LOLBins #OpenSource #SentinelOne 🌍🔒🖥️
-
The Symantec research team uncovered an espionage campaign from the #APT group they track as #Redfly. The group used multiple tools during the campaign which included the #ShadowPad trojan, #Packerloader, and a key logger. They also abused some #LOLBINs to achieve their goals.
Redfly masqueraded ShadowPad in a "VMware" directory and gained persistence by creating a service that ran the malware once the computer started and the keylogger stored its captured keystrokes in a directory that included "Intel" in the path. The APT group used the reg.exe to dump credentials from he SYSTEM, SAM, and SECURITY hive. They also used a renamed version of ProcDump to dump credentials from LSASS. Powershell was also used to gather information on the storage devices attached to the system and finally a scheduled task was created to preform side-loading and lateral movement. #HappyHunting!
#CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #readoftheday
-
The Symantec research team uncovered an espionage campaign from the #APT group they track as #Redfly. The group used multiple tools during the campaign which included the #ShadowPad trojan, #Packerloader, and a key logger. They also abused some #LOLBINs to achieve their goals.
Redfly masqueraded ShadowPad in a "VMware" directory and gained persistence by creating a service that ran the malware once the computer started and the keylogger stored its captured keystrokes in a directory that included "Intel" in the path. The APT group used the reg.exe to dump credentials from he SYSTEM, SAM, and SECURITY hive. They also used a renamed version of ProcDump to dump credentials from LSASS. Powershell was also used to gather information on the storage devices attached to the system and finally a scheduled task was created to preform side-loading and lateral movement. #HappyHunting!
#CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #readoftheday
-
While most of us celebrate Labor Day let's all try to take a moment to remember those who don't get to spend time with their loved ones today, wherever they may be and whatever they may be doing!
I don't know how this report slid under my radar but the ESET researched team unveil a "Marioesque" themed adversary, #MoustachedBouncer! They are a cyberespionage group that targets foreign embassies in Belarus with the use of their ISP level access and their tools #NightClub and #Disco. Using their (assumed) unique level of access, they compromise their targets by redirecting them to a fake #Microsoft update site which loads JavaScript code then leads to a zip file being downloaded. The team wasn't able to get the zip file, but they were still able to identify some TTPs and #LOLBINS abuse, such as creating a malicious scheduled task. I hope you enjoy and Happy Hunting!
#CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #readoftheday #LaborDay
-
While most of us celebrate Labor Day let's all try to take a moment to remember those who don't get to spend time with their loved ones today, wherever they may be and whatever they may be doing!
I don't know how this report slid under my radar but the ESET researched team unveil a "Marioesque" themed adversary, #MoustachedBouncer! They are a cyberespionage group that targets foreign embassies in Belarus with the use of their ISP level access and their tools #NightClub and #Disco. Using their (assumed) unique level of access, they compromise their targets by redirecting them to a fake #Microsoft update site which loads JavaScript code then leads to a zip file being downloaded. The team wasn't able to get the zip file, but they were still able to identify some TTPs and #LOLBINS abuse, such as creating a malicious scheduled task. I hope you enjoy and Happy Hunting!
#CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #readoftheday #LaborDay
-
Good day everyone! The Microsoft Threat Intelligence team has discovered activity from a group known as #FlaxTyphoon. They are a nation-state group from China that targeted organizations in Taiwan. While the group leverages tools that are commonly used, like #ChinaChopper, #MetaSploit, and #Mimikatz, they also rely on abusing #LOLBINS, or Living-off-the-land binaries and scripts (tools that exist and come with the native operating system). Some of their TTPs include using registry key modification for persistence, using #powershell, #certutil, or #bitsadmin to download tools, and accessing #LSASS process memory and Security Account Manager registry hive for credential access. This is a great article that not only provides high-level details but it provides a starting point for any organization to start threat hunting by using the technical details provided! Enjoy your weekend and #HappyHunting!
#CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #readoftheday
-
Good day everyone! The Microsoft Threat Intelligence team has discovered activity from a group known as #FlaxTyphoon. They are a nation-state group from China that targeted organizations in Taiwan. While the group leverages tools that are commonly used, like #ChinaChopper, #MetaSploit, and #Mimikatz, they also rely on abusing #LOLBINS, or Living-off-the-land binaries and scripts (tools that exist and come with the native operating system). Some of their TTPs include using registry key modification for persistence, using #powershell, #certutil, or #bitsadmin to download tools, and accessing #LSASS process memory and Security Account Manager registry hive for credential access. This is a great article that not only provides high-level details but it provides a starting point for any organization to start threat hunting by using the technical details provided! Enjoy your weekend and #HappyHunting!
#CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #readoftheday
-
SecurityWeek: Chinese-backed APT ‘Flax Typhoon’ Hacks Taiwan with Minimal Malware Footprint https://www.securityweek.com/chinese-backed-apt-flax-typhoon-hacks-taiwan-with-minimal-malware-footprint/ #ThreatIntelligence #Malware&Threats #Nation-State #FlaxTyphoon #LOLbins #China
-
SecurityWeek: Chinese-backed APT ‘Flax Typhoon’ Hacks Taiwan with Minimal Malware Footprint https://www.securityweek.com/chinese-backed-apt-flax-typhoon-hacks-taiwan-with-minimal-malware-footprint/ #ThreatIntelligence #Malware&Threats #Nation-State #FlaxTyphoon #LOLbins #China
-
On Episode 2 of our technical #livestream series #WhatTheVuln, Lindsay Von Tish discussed a technique for bypassing #EDR via #LoLBins. In this blog post, she goes into detail about the technique including how she initially discovered it.
Give it a read today!
https://bfx.social/3Gn3Fmw #infosec -
On Episode 2 of our technical #livestream series #WhatTheVuln, Lindsay Von Tish discussed a technique for bypassing #EDR via #LoLBins. In this blog post, she goes into detail about the technique including how she initially discovered it.
Give it a read today!
https://bfx.social/3Gn3Fmw #infosec -
Now that you’ve seen #WhatTheVuln Episode 2 featuring Lindsay Von Tish and Allan Cecil, check out the corresponding technical write-up where you can take a deep dive into how to use #LoLBins to bypass #EDR protection and install a #C2 agent for advanced #postexploitation control.
And don’t fret if you missed the initial livestream – you can watch the recording on demand! https://bfx.social/3K4T1mS
P.S. Episode 3 is on the way! -
Now that you’ve seen #WhatTheVuln Episode 2 featuring Lindsay Von Tish and Allan Cecil, check out the corresponding technical write-up where you can take a deep dive into how to use #LoLBins to bypass #EDR protection and install a #C2 agent for advanced #postexploitation control.
And don’t fret if you missed the initial livestream – you can watch the recording on demand! https://bfx.social/3K4T1mS
P.S. Episode 3 is on the way! -
Catch Lindsay Von Tish tomorrow as she explains #WhatTheVuln! Allan Cecil will interview her on the details of an #EDR bypass she performed with native Windows binaries (#LoLBins) to install a #C2 agent in a simulated post-exploitation attack scenario.
Watch the #livestream at our LinkedIn or on our YouTube channel! https://bfx.social/3Km1YIK
-
Catch Lindsay Von Tish tomorrow as she explains #WhatTheVuln! Allan Cecil will interview her on the details of an #EDR bypass she performed with native Windows binaries (#LoLBins) to install a #C2 agent in a simulated post-exploitation attack scenario.
Watch the #livestream at our LinkedIn or on our YouTube channel! https://bfx.social/3Km1YIK
-
If you caught today's #WhattheVuln episode featuring Carlos Yanez discussing Zimbra #security, be sure to check out his write-up on the topic, too! https://bfx.social/3lUL75U
Next month we're back with Lindsay Von Tish and Allan Cecil to talk about #EDR bypassing with #LoLBins.
-
If you caught today's #WhattheVuln episode featuring Carlos Yanez discussing Zimbra #security, be sure to check out his write-up on the topic, too! https://bfx.social/3lUL75U
Next month we're back with Lindsay Von Tish and Allan Cecil to talk about #EDR bypassing with #LoLBins.
-
Who Needs #Macros? Threat Actors Pivot to #Abusing #Explorer and Other #LOLBins via Windows #Shortcuts
-
Curated list of Unix binaries that can be exploited to bypass local security restrictions 👍 https://gtfobins.github.io/ #LOLBins #unix #pentest #redteam https://t.co/UlGTVBi06V