home.social

#shellcode — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #shellcode, aggregated by home.social.

fetched live
  1. Recent Attack Activity Analysis Using North Korea-Related Lures

    APT-C-06 (Darkhotel) is an APT organization that has been active since at least 2007, targeting corporate executives, defense industries, and electronics sectors. In April 2026, the group launched phishing attacks using a decoy document titled 'North Korean Central Television Real-time Broadcasting Program Instructions.' The document instructs users to download an application for watching North Korean Central Television. By late May, attacks evolved to deliver malicious MSI files through phishing emails. These MSI files execute VBS code that creates scheduled tasks to download and execute PowerShell scripts, which then retrieve subsequent payloads. The malware employs ChaCha20 encryption and ultimately deploys shellcode. PowerShell has become a high-frequency component in APT-C-06's attack chain since 2025, handling payload downloads and persistence mechanisms.

    Pulse ID: 6a7dc1fd395815126acd4647
    Pulse Link: otx.alienvault.com/pulse/6a7dc
    Pulse Author: AlienVault
    Created: 2026-08-13 13:09:17

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ChaCha20 #CyberSecurity #Email #Encryption #ICS #InfoSec #Korea #Malware #NorthKorea #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SMS #ShellCode #VBS #bot #AlienVault

  2. Recent Attack Activity Analysis Using North Korea-Related Lures

    APT-C-06 (Darkhotel) is an APT organization that has been active since at least 2007, targeting corporate executives, defense industries, and electronics sectors. In April 2026, the group launched phishing attacks using a decoy document titled 'North Korean Central Television Real-time Broadcasting Program Instructions.' The document instructs users to download an application for watching North Korean Central Television. By late May, attacks evolved to deliver malicious MSI files through phishing emails. These MSI files execute VBS code that creates scheduled tasks to download and execute PowerShell scripts, which then retrieve subsequent payloads. The malware employs ChaCha20 encryption and ultimately deploys shellcode. PowerShell has become a high-frequency component in APT-C-06's attack chain since 2025, handling payload downloads and persistence mechanisms.

    Pulse ID: 6a7dc1fd395815126acd4647
    Pulse Link: otx.alienvault.com/pulse/6a7dc
    Pulse Author: AlienVault
    Created: 2026-08-13 13:09:17

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ChaCha20 #CyberSecurity #Email #Encryption #ICS #InfoSec #Korea #Malware #NorthKorea #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SMS #ShellCode #VBS #bot #AlienVault

  3. Phantom Stealer Hides Inside PNG Files, Then Steals Your Passwords, Cookies and Crypto

    Indicators extracted from public reporting. Source: splunk.com/en_us/blog/security

    Pulse ID: 6a7d94b079c2c1e42df7974b
    Pulse Link: otx.alienvault.com/pulse/6a7d9
    Pulse Author: CyberHunter_NL
    Created: 2026-08-13 09:56:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cookies #CyberSecurity #HTML #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Password #Passwords #RCE #ShellCode #Steganography #Word #bot #CyberHunter_NL

  4. Phantom Stealer Hides Inside PNG Files, Then Steals Your Passwords, Cookies and Crypto

    Indicators extracted from public reporting. Source: splunk.com/en_us/blog/security

    Pulse ID: 6a7d94b079c2c1e42df7974b
    Pulse Link: otx.alienvault.com/pulse/6a7d9
    Pulse Author: CyberHunter_NL
    Created: 2026-08-13 09:56:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cookies #CyberSecurity #HTML #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Password #Passwords #RCE #ShellCode #Steganography #Word #bot #CyberHunter_NL

  5. Phantom Stealer Unmasked: Shellcode, Steganography, and Credential Theft

    Pulse ID: 6a701f541d329d7a88fa71bc
    Pulse Link: otx.alienvault.com/pulse/6a701
    Pulse Author: Tr1sa111
    Created: 2026-08-03 04:55:48

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #OTX #OpenThreatExchange #ShellCode #Steganography #bot #Tr1sa111

  6. Phantom Stealer Unmasked: Shellcode, Steganography, and Credential Theft

    Pulse ID: 6a701f541d329d7a88fa71bc
    Pulse Link: otx.alienvault.com/pulse/6a701
    Pulse Author: Tr1sa111
    Created: 2026-08-03 04:55:48

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #OTX #OpenThreatExchange #ShellCode #Steganography #bot #Tr1sa111

  7. Phantom Stealer Unmasked: Shellcode, Steganography, and Credential Theft

    Phantom Stealer is a .NET-based credential-harvesting malware that collects browser credentials, saved passwords, session cookies, cryptocurrency wallet files, and system fingerprints from infected machines. Distributed through phishing emails, cracked software, and malicious links on Discord and Telegram, it employs multiple loader variants including steganography-based delivery and PowerShell shellcode injection. The malware uses extensive anti-analysis techniques including virtualization detection, API patching to disable AMSI and ETW, and timing-based sandbox evasion. It targets Chromium and Gecko-based browsers, cryptocurrency wallets, FileZilla credentials, WinSCP configurations, and Outlook profiles. Additional capabilities include keylogging, screen capture, clipboard monitoring with cryptocurrency address replacement, and Wi-Fi credential theft. The malware achieves persistence through registry Run keys or Startup folder entries.

    Pulse ID: 6a6a0753fc3cdb9a380c795d
    Pulse Link: otx.alienvault.com/pulse/6a6a0
    Pulse Author: AlienVault
    Created: 2026-07-29 13:59:47

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Clipboard #CodeInjection #Cookies #CyberSecurity #Discord #Email #FileZilla #InfoSec #Mac #Malware #NET #OTX #OpenThreatExchange #Outlook #Password #Passwords #Phishing #PowerShell #RAT #ShellCode #Steganography #Telegram #WinSCP #Word #bot #cryptocurrency #AlienVault

  8. Phantom Stealer Unmasked: Shellcode, Steganography, and Credential Theft

    Phantom Stealer is a .NET-based credential-harvesting malware that collects browser credentials, saved passwords, session cookies, cryptocurrency wallet files, and system fingerprints from infected machines. Distributed through phishing emails, cracked software, and malicious links on Discord and Telegram, it employs multiple loader variants including steganography-based delivery and PowerShell shellcode injection. The malware uses extensive anti-analysis techniques including virtualization detection, API patching to disable AMSI and ETW, and timing-based sandbox evasion. It targets Chromium and Gecko-based browsers, cryptocurrency wallets, FileZilla credentials, WinSCP configurations, and Outlook profiles. Additional capabilities include keylogging, screen capture, clipboard monitoring with cryptocurrency address replacement, and Wi-Fi credential theft. The malware achieves persistence through registry Run keys or Startup folder entries.

    Pulse ID: 6a6a0753fc3cdb9a380c795d
    Pulse Link: otx.alienvault.com/pulse/6a6a0
    Pulse Author: AlienVault
    Created: 2026-07-29 13:59:47

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Clipboard #CodeInjection #Cookies #CyberSecurity #Discord #Email #FileZilla #InfoSec #Mac #Malware #NET #OTX #OpenThreatExchange #Outlook #Password #Passwords #Phishing #PowerShell #RAT #ShellCode #Steganography #Telegram #WinSCP #Word #bot #cryptocurrency #AlienVault

  9. Expanding the Castle: New Campaigns, New Tooling, and the NeedleStealer Connection

    Arctic Wolf Labs has been tracking multiple campaigns built around CastleLoader, a multi-stage shellcode loader that has evolved significantly. Three distinct campaigns were identified: Urutyka, Garrigin, and Noidret. The most significant development is the integration of NeedleStealer framework payloads, marking the first observed use of Rust and Golang tooling in this campaign cluster. NeedleStealer includes a Rust-based desktop cryptocurrency wallet spoofer targeting Ledger, Trezor, and Exodus wallets, and a Golang-based malicious browser extension installer. The campaigns utilize obfuscated PowerShell stagers, IronPython runtimes, and NodeJS-based shellcode injectors. Infrastructure analysis revealed consistent naming patterns, staged domains for future operations, and the use of fraudulently obtained code-signing certificates. The campaigns consistently deploy NetSupport RAT and CastleStealer alongside the new NeedleStealer payloads, suggesting an expansion toward high-value cryptocurrency targeting.

    Pulse ID: 6a682376fe6eac7ecb782129
    Pulse Link: otx.alienvault.com/pulse/6a682
    Pulse Author: AlienVault
    Created: 2026-07-28 03:35:18

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CyberSecurity #Edge #Golang #InfoSec #NetSupport #NetSupportRAT #OTX #OpenThreatExchange #PowerShell #Python #RAT #Rust #ShellCode #bot #cryptocurrency #AlienVault

  10. Expanding the Castle: New Campaigns, New Tooling, and the NeedleStealer Connection

    Arctic Wolf Labs has been tracking multiple campaigns built around CastleLoader, a multi-stage shellcode loader that has evolved significantly. Three distinct campaigns were identified: Urutyka, Garrigin, and Noidret. The most significant development is the integration of NeedleStealer framework payloads, marking the first observed use of Rust and Golang tooling in this campaign cluster. NeedleStealer includes a Rust-based desktop cryptocurrency wallet spoofer targeting Ledger, Trezor, and Exodus wallets, and a Golang-based malicious browser extension installer. The campaigns utilize obfuscated PowerShell stagers, IronPython runtimes, and NodeJS-based shellcode injectors. Infrastructure analysis revealed consistent naming patterns, staged domains for future operations, and the use of fraudulently obtained code-signing certificates. The campaigns consistently deploy NetSupport RAT and CastleStealer alongside the new NeedleStealer payloads, suggesting an expansion toward high-value cryptocurrency targeting.

    Pulse ID: 6a682376fe6eac7ecb782129
    Pulse Link: otx.alienvault.com/pulse/6a682
    Pulse Author: AlienVault
    Created: 2026-07-28 03:35:18

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CyberSecurity #Edge #Golang #InfoSec #NetSupport #NetSupportRAT #OTX #OpenThreatExchange #PowerShell #Python #RAT #Rust #ShellCode #bot #cryptocurrency #AlienVault

  11. The TTF Trap: A Global Campaign of a Low-Detection Lua Loader

    Since late March 2026, a large-scale phishing campaign has been deploying malware including Agent Tesla, Remcos, XWorm, and Best Private LOGGER through fileless techniques and low-detection Lua-based loaders. Attackers impersonate well-known companies using business cooperation lures to distribute malicious archives containing obfuscated JavaScript files. These scripts deploy either AutoIt or LuaJIT interpreters alongside disguised scripts masquerading as TrueType Font (.ttf) files. The Lua loaders employ sophisticated anti-analysis techniques including custom ROT ciphers, decoy memory allocation, and Donut shellcode generation for reflective in-memory payload execution. The campaign evolved from simpler implementations in October 2025 to highly complex versions by June 2026, incorporating API unhooking and advanced debugging countermeasures. Victims are ultimately infected with Remote Access Trojans and infostealers that enable full system control and extensive data exfiltration.

    Pulse ID: 6a59018a415370b96937338d
    Pulse Link: otx.alienvault.com/pulse/6a590
    Pulse Author: AlienVault
    Created: 2026-07-16 16:06:34

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AgentTesla #Autoit #CyberSecurity #InfoSec #InfoStealer #Java #JavaScript #LUA #Malware #OTX #OpenThreatExchange #Phishing #RAT #Remcos #RemoteAccessTrojan #ShellCode #Tesla #Trojan #Worm #XWorm #bot #AlienVault

  12. The TTF Trap: A Global Campaign of a Low-Detection Lua Loader

    Since late March 2026, a large-scale phishing campaign has been deploying malware including Agent Tesla, Remcos, XWorm, and Best Private LOGGER through fileless techniques and low-detection Lua-based loaders. Attackers impersonate well-known companies using business cooperation lures to distribute malicious archives containing obfuscated JavaScript files. These scripts deploy either AutoIt or LuaJIT interpreters alongside disguised scripts masquerading as TrueType Font (.ttf) files. The Lua loaders employ sophisticated anti-analysis techniques including custom ROT ciphers, decoy memory allocation, and Donut shellcode generation for reflective in-memory payload execution. The campaign evolved from simpler implementations in October 2025 to highly complex versions by June 2026, incorporating API unhooking and advanced debugging countermeasures. Victims are ultimately infected with Remote Access Trojans and infostealers that enable full system control and extensive data exfiltration.

    Pulse ID: 6a59018a415370b96937338d
    Pulse Link: otx.alienvault.com/pulse/6a590
    Pulse Author: AlienVault
    Created: 2026-07-16 16:06:34

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AgentTesla #Autoit #CyberSecurity #InfoSec #InfoStealer #Java #JavaScript #LUA #Malware #OTX #OpenThreatExchange #Phishing #RAT #Remcos #RemoteAccessTrojan #ShellCode #Tesla #Trojan #Worm #XWorm #bot #AlienVault

  13. Прячем shellcode в приложениях

    В этой статье мы рассмотрим одну из наиболее эффективных техник обхода традиционных систем защиты — сокрытие шеллкода. Уязвимости в программном обеспечении могут стать отличной возможностью для злоумышленников, а шеллкод, благодаря своей компактности и скрытности, становится идеальным инструментом для эксплуатации таких уязвимостей. Мы не только объясним, как скрывают вредоносный код, но и подробно рассмотрим методы преобразования стандартных исполняемых файлов в шеллкод, а также покажем, как этот процесс может быть использован для обхода современных средств защиты.

    habr.com/ru/companies/otus/art

    #reverseengineering #exploit #shellcode #payload #windows_internals #reverse #reverse_engineering

  14. #Speedrunners are #vulnerability researchers, they just don't know it yet
    zetier.com/speedrunners-are-vu

    “Super Mario World runners will place items in extremely precise locations so that the X,Y coordinates form #shellcode they can jump to with a dangling reference. Legend of #Zelda: Ocarina of Time players will do heap grooming and write a #function pointer […] so the game “wrong warps” directly to the #end #credit sequence… with nothing more than a #game #controller and a steady #hand

    #Mario

  15. #Speedrunners are #vulnerability researchers, they just don't know it yet
    zetier.com/speedrunners-are-vu

    “Super Mario World runners will place items in extremely precise locations so that the X,Y coordinates form #shellcode they can jump to with a dangling reference. Legend of #Zelda: Ocarina of Time players will do heap grooming and write a #function pointer […] so the game “wrong warps” directly to the #end #credit sequence… with nothing more than a #game #controller and a steady #hand

    #Mario

  16. The nineth article (38 pages) of the Malware Analysis Series (MAS) is available on:

    exploitreversing.com/2025/01/0

    I would like to thank Ilfak Guilfanov @ilfak and @HexRaysSA (on X) for their constant and uninterrupted support, which have helped me write these articles.

    Even though I haven't been on this subject for years, I promised I would write a series of ten articles, and the last one will be released next week (JAN/15).

    Have a great day.

    #windows #shellcode #malware #reverseengineering #reversing #idapro #malwareanalysis

  17. The nineth article (38 pages) of the Malware Analysis Series (MAS) is available on:

    exploitreversing.com/2025/01/0

    I would like to thank Ilfak Guilfanov @ilfak and @HexRaysSA (on X) for their constant and uninterrupted support, which have helped me write these articles.

    Even though I haven't been on this subject for years, I promised I would write a series of ten articles, and the last one will be released next week (JAN/15).

    Have a great day.

    #windows #shellcode #malware #reverseengineering #reversing #idapro #malwareanalysis

  18. [Перевод] Создание Powershell Shellcode Downloader для обхода Defender (Без обхода Amsi)

    Сегодня я покажу, как модифицировать powershell shellcode runner для загрузки и выполнения нагрузки в обход Windows Defender. Я буду использовать shellcode runner, который применял ранее: github.com/dievus/PowerShellRu Для демонстрации я использую виртуальную машину Windows с временно отключённым Defender. Я скопирую код и создам на его основе новый файл, используя PowerShell ISE.

    habr.com/ru/articles/868622/

    #paylaoad #shellcode #av #bypass #информационная_безопасность #хакинг

  19. Thread execution hijacking. Исполнение шелл-кода в удаленном процессе

    В статье разберем технику T1055.003 Подменим контекст потока удаленного процесса и рассмотрим способ доставки шелл-кода в процесс с помощью удаленного маппинга. В ОС Windows существует возможность получения контекста потока и последующего управления значениями регистров. Это дает возможность изменения потока выполнения, например, с помощью модификации регистра rip. Этим и будем пользоваться.

    habr.com/ru/articles/855710/

    #hijacking #shellcode #mapping #thread

  20. "And so an exciting idea to remotely #exploit ssh-agent came into our mind:

    a/ make ssh-agent's stack executable (more precisely, ssh-pkcs11-helper's stack) by dlopen()ing one of the "execstack" libraries ("surprising behavior 1/"), and somehow store a 1990-style #shellcode somewhere in this executable stack;

    b/ register a signal handler for SIGSEGV and immediately munmap() its code, by dlopen()ing and dlclose()ing one of the shared libraries from
    "surprising behavior 3/" (consequently, a #dangling #pointer to this unmapped signal handler is retained in the kernel);

    c/ replace the unmapped signal handler's code with another piece of code from another shared library, by dlopen()ing (mmap()ing) one of the "nodelete" libraries ("surprising behavior 2/");

    d/ raise a SIGSEGV by dlopen()ing one of the shared libraries from "surprising behavior 4/", so that the unmapped signal handler is called by the kernel, but the replacement code from the "nodelete" library is executed instead (a #uaf of sorts);

    e/ #hope that this replacement code (which is mapped where the signal handler was mapped) is a useful gadget that somehow jumps into the
    executable stack, exactly where our shellcode is stored."

  21. Mal wieder ein lustiges #Exploit-Problem: Ich habe ein C-Prog, das #Shellcode (21 bytes) in einem char[] hat, das ich mit (*(void (*)()) buffer)(); aufrufe - und das funktioniert.

    Lese ich d selben Code mit scanf oder fgets von stdin ein, sehe ich im Debugger die selben Bytes im array, die werden aber nicht ausgeführt. Macht scanf hier was komisches?

    Ich hab diese Flags im Makefile gesetzt: -g -O0 -m32 -fno-stack-protector -no-pie -fno-pie -mpreferred-stack-boundary=2 -z execstack

    :BoostOK:

  22. What is everyone’s crown achievement? Mine was implementing RSA (including bigint modpow functionality) as x86 .

  23. 💪 Arm yourself with new knowledge this Thursday, and watch Saumil Shah’s (@therealsaumil) #workshop “An Introduction to #ARM64 #Assembly and #Shellcode” of the #RETURN2WORKSHOP event last December. Happy watching!

    🎥 youtu.be/H1OB1k4JxhA

    Are you interested in learning more about #ARM64, and how to run exploits for ARM64 #IoT devices? Then sign up for Saumil’s brand-new #training in February: “The ARM64 #Exploit Laboratory”. Go to our website for more details and to sign up!

    🎟️ ringzer0.training/trainings/th

  24. ✨ Avoiding Detection with Shellcode Mutator

    ▶️ Mutates exploit source code without affecting its functionality, changing its signature and making it harder to reliably detect as malicious

    Repository:
    github.com/nettitude/Shellcode

    Article:
    labs.nettitude.com/blog/shellc

    #shellcode #redteaming #pentesters #redteamtips #infosec #exploitation #binaryexploitation