Sign in

Drew

@bugfire.io
149 followers 167 following 429 posts

malware detection and analysis, hunting and gathering, threat research Views are my own.

PostsRepliesMedia
Reposted by Drew
Karsten Hahn @struppigel.bsky.social · 28/09/2026
New blog: OpenSUpdater Hides in Recompiled 7zip SFX blog.gdatasoftware.com/2026/09/3849...
011
Reposted by Drew
James Wilson @jameswilson.io · 23/09/2026
Ransom payments end up in the wallets of drug and other crime gangs too. This changed my mind about ransom payment regulation. Geoff White (CyberHack, Conti Files, Lazarus Heist) and I sat down for a chat about just how ransomware gangs turn traceable bitcoin into cash. 🎧 risky.biz/RBFEATURES40/
risky.biz
How to launder illicit Bitcoin - Risky Business Media
In this podcast episode, investigative journalist Geoff White joins James Wilson to talk about what happens to the money after ransomware [Read More]
043
Reposted by Drew
Brad @malware-traffic-analysis.net · 23/09/2026
To combat the spread of AI slop, I've hand-crafted an image to represent a ClickFix campaign I'm calling "Macfinger ClickFix." Think of the movie Goldfinger, but with macOS malware and the internet instead of James Bond and Miss Galore. More info at: isc.sans.edu/diary/33360
031
Reposted by Drew
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 20/09/2026
I’m speechless all over again. 😭 Thanks for including me in this week’s Good News Corner of your weekinsecurity.com newsletter @zackwhittaker.com ! And thanks forever to the @sentinelone.com SentinelLabs LABSCON crew & community for bringing knowledge & magic people together all these years 💜💖🎉
weekinsecurity.com
~this week in security~
a weekly cybersecurity newsletter by Zack Whittaker, plus articles and more.
0163
Drew @bugfire.io · 16/09/2026
Great write up on Mythic C2 from Andrew Northern censys.com/blog/mythic-...
censys.com
Mythic C2 Activity at Internet Scale - Censys
Censys tracks 131 hosts exposing Mythic to the public Internet. Learn about the C2 framework and how to defend against it.
001
Reposted by Drew
Ryan Naraine @ryanaraine.bsky.social · 15/09/2026
"That is straight-up fraud."
122
Reposted by Drew
Karsten Hahn @struppigel.bsky.social · 06/09/2026
🦔 📹 New Video: Hooking V8 JavaScript ➡️ compiled V8 ➡️ we write a reusable hook script ➡️ we overcome basic anti-hooking #MalwareAnalysisForHedgehogs #V8 #JavaScript www.youtube.com/watch?v=Y8_A...
youtube.com
Malware Analysis - Hooking V8 JavaScript bytecode
YouTube video by MalwareAnalysisForHedgehogs
041
Drew @bugfire.io · 29/08/2026
@bajiri.bsky.social Big shoutout to you as I recently made good use of your EvilAI blog from earlier this year! Excellent content and IOCs!
120
Reposted by Drew
James Wilson @jameswilson.io · 11/08/2026
ICYMI: I published a pod on private AI inference. Hosted LLMs that hide your chats from the provider. Trusted execution environments, GPU confidential computing, attestation, KV-cache side channels, and why “we don’t train on your data” is not the same as “we can’t see it.” risky.biz/RBFEATURES34/
risky.biz
How private LLM inference actually works - Risky Business Media
In this podcast episode James Wilson chats with Tinfoil co-founder Tanya Verma about how you can run a powerful LLM in the cloud without t [Read More]
032
Drew @bugfire.io · 31/07/2026
Highly recommend this podcast!
010
Reposted by Drew
Greg Lesnewich @greg-l.bsky.social · 29/07/2026
So remember last week when we said we hadn’t see TA488/Laundry Bear/Void since Feb? Well... We kinda lied Day before the release, we found em throwing a half click against Outlook to install one of the coolest implants we’ve ever examined: OWAReaper www.proofpoint.com/us/blog/thre...
proofpoint.com
Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit | Proofpoint US
Threat Research would like to thank the Proofpoint Cloudmark Authority team for their collaboration. Key Findings On 22 July 2026, one day prior to Proofpoint’s recent joint release
22414
Reposted by Drew
ThreatInsight @threatinsight.proofpoint.com · 28/07/2026
Our Proofpoint AI threat researchers continue to observe activity on underground criminal forums, suggesting that Indirect Prompt Injection (IDPI) could soon be leveraged as an intrusion vector. Explore the methods that are being actively developed and sold: www.proofpoint.com/us/blog/thre....
232
Reposted by Drew
Tim Blazytko @mrphrazer.bsky.social · 02/07/2026
New Binary Cartography episode: Pinpointing Interesting Code in Binaries We cover heuristics for protocols, crypto routines, library functions, RC4, decryption loops -- and how these signals guide agents youtu.be/HQA3U5MnD5U Slides & samples: github.com/mrphrazer/bi...
youtu.be
Pinpointing Interesting Code in Binaries: Heuristics, Statistics, and Agents
YouTube video by Tim Blazytko
031
Reposted by Drew
Censys @censys.bsky.social · 29/06/2026
New research from Censys Senior Security Researcher Aidan Holland maps the AsyncRAT family across ~40 variants. The detection signal is its inherited TLS certificate metadata that persists across forks. Read more: bit.ly/4eQP03m
052
Reposted by Drew
Tim Blazytko @mrphrazer.bsky.social · 29/06/2026
Premiering at this year's @hexacon.bsky.social: my reworked Software Deobfuscation Techniques training. It now combines deep technical know-how with agentic workflows to automate large-scale deobfuscation. www.hexacon.fr/trainer/soft...
121
Reposted by Drew
Karsten Hahn @struppigel.bsky.social · 19/06/2026
New trainings sample on samplepedia Backdoor, obfuscated Python bytecode. 0/60 on Virustotal, which means it's still fresh. www.virustotal.com/gui/file/4ad... samplepedia.cc/sample/4ada6...
012
Reposted by Drew
ThreatInsight @threatinsight.proofpoint.com · 18/06/2026
#SocGholish, the “FakeUpdates” web injects framework linked to major ransomware events, has been disrupted by #OperationEndgame. ❌ 100 servers and domains worldwide dismantled ❌ 14,971 websites remediated Learn more: www.proofpoint.com/us/blog/thre.... 🧵⤵️
141
Reposted by Drew
Karsten Hahn @struppigel.bsky.social · 14/06/2026
🦔 📹 Poison X kernel mode rootkit analysis ➡️ kernel mode driver theory ➡️ Ghidra markup ➡️ basic string deobfuscation #MalwareAnalysisForHedgehogs www.youtube.com/watch?v=yx6A...
youtube.com
Malware Analysis - PoisonX rootkit, Kernel driver rootkit markup in Ghidra
YouTube video by MalwareAnalysisForHedgehogs
131
Reposted by Drew
Lenny Zeltser @lennyzeltser.com · 26/05/2026
Much of our security work is communicating with colleagues throughout the org. 10 habits that sharpen how the technical work gets heard. zeltser.com/strong-communication-sk…
zeltser.com
10 Communication Tips for Security and IT Professionals
Explaining security and IT work is often harder than the work itself. Ten habits will sharpen how you explain it to specialists, executives, and everyone in between.
061
Reposted by Drew
Jeremy Kirk @jkirk.bsky.social · 14/05/2026
Device-code phishing is surging. One cybercriminal tool can target virtually every Microsoft user. Okta Threat Intelligence digs deep into the OAuth CLI device flow and how to minimize your attack surface. www.okta.com/blog/threat-...
okta.com
Device code phishing: it’s phishing with dynamite
Okta Threat Intelligence studies recent abuse of the device code authorization flow in service provider ecosystems, and provides links to detection and remediation strategies for protecting clients cr...
022
Drew @bugfire.io · 09/05/2026
I highly recommend this comprehensive blog on EDR internals 0xdbgman.github.io/posts/edr-in...
0xdbgman.github.io
EDR Tradecraft: Internals, Detection, Evasion & Advanced Researchg
Technical reference on modern EDR architecture, detection mechanisms, evasion techniques, and reverse-engineering methodology. Covers kernel callback APIs, file-system mini-filters, ETW providers, the...
010
Reposted by Drew
Squiblydoo @squiblydoo.bsky.social · 07/05/2026
We report certificates for revocation when they sign malware. What about before they sign malware? I've started adding certificates to Cert Graveyard that are being used to "warm" the certificate and improve it's score before being sign malware. 1/4
141
Reposted by Drew
mthcht @mthcht.bsky.social · 29/04/2026
Launching oauthsentry.github.io Look up any OAuth app ID and find out what it actually is across thousands of legitimate, risky, and malicious apps (Entra, Google, GitHub). Multiple feeds, API, detection ideas and remediation guidance. Still improving the detections a bit 🦾
oauthsentry.github.io
OAuthSentry - OAuth application intelligence for defenders
Search OAuth Application IDs across Microsoft Entra, Google Workspace and more. Three classification feeds for defenders: compliance, risky, and malicious. Includes investigation playbooks, forensic t...
113
Drew @bugfire.io · 01/05/2026
Great listen!
021
Reposted by Drew
Lenny Zeltser @lennyzeltser.com · 29/04/2026
Out-of-the-box Claude Code is solid for general work. What makes it indispensable is the personalization, hardening, and connectors you layer on top. I mapped my setup into a seven-layer Personal AI Stack, so you can optimize yours.
zeltser.com
The Personal AI Stack: A Power User's Guide
An AI tool like Claude Code gives you solid general-purpose capabilities out of the box. To make it truly indispensable, add the layers that teach it who you are, how you work, and what you do.
141
Reposted by Drew
Ryan Naraine @ryanaraine.bsky.social · 27/04/2026
Spotify open.spotify.com/episode/5lkC...
open.spotify.com
Mark Dowd on AI hacking, exploit chains, zero-day sales
Spotify video
021
Reposted by Drew
Brad @malware-traffic-analysis.net · 24/04/2026
2026-04-23 (Thursday): #SmartApeSG campaign using #ClickFix instructions to push some sort of #RAT. Not sure what this #malware is yet, but it looks like a RAT. Details at www.malware-traffic-analysis.net/2026/04/23/i...
SmartApeSG fake CAPTCHA (verify you are human page) when viewing a legitimate but compromised website.ClickFix instructions from the SmartApeSG fake CAPTCHA (verify you are human page).ClickFix instructions pasted into a Run window on a Windows 11 host.Traffic from the infection filtered in Wireshark.
142
Reposted by Drew
John Hammond @johnhammond.bsky.social · 21/04/2026
Joined by Katrina Manson to hear all about her latest book release: Project Maven & the Dawn of AI Warfare 👀 We talk AI usage at the Pentagon, drone intel, AI enabled targeting, and the ethical tipping point of autonomous weapons. Super fascinating ideas. Video: youtu.be/OVgruylpVXc
022
Reposted by Drew
Karsten Hahn @struppigel.bsky.social · 19/04/2026
New Video: Build your own LLM dynamic analysis lab 🦔🎥 ➡️ AI debugs and unpacks with x64dbg ➡️ AI can access powershell terminal www.youtube.com/watch?v=QrWz...
youtube.com
Build your own AI based Dynamic Reversing Lab, x64dbg automate
YouTube video by MalwareAnalysisForHedgehogs
021
Reposted by Drew
John Hammond @johnhammond.bsky.social · 09/04/2026
Wild story on a big AI-powered social engineering campaign, leveraging Device Code phishing to steal Entra ID/Microsoft accounts -- all with entirely unique and personalized per-victim lures from vibecode-crafted infrastructure 🤯 Video: youtu.be/9b3kirR8s2U
023
Reposted by Drew
Karsten Hahn @struppigel.bsky.social · 17/03/2026
I wrote an article about SugarSMP Minecraft scams, Spark stealer, extortion and hacked accounts. After a brief contact to the threat actor, we talked to two victims and followed the trail. Analysis in collaboration with @rifteyy #GDATATechblog #GDATA blog.gdatasoftware.com/2026/03/3839...
blog.gdatasoftware.com
Minecraft: SugarSMP's Dark Tale of Scams, Malware & Extortion
Some Minecraft players were looking for safe haven away from griefers, but found an elaborate web of malware, deception and extortion.
023
Reposted by Drew
Thomas Roccia :verified: @fr0gger.infosec.exchange.ap.brid.gy · 17/03/2026
🤓 A month ago I published a blog post on how to monitor Claude Code sessions using hooks and NOVA Protector! At the time, no one was really talking about this. Coding agents were being handed full access to your machine and people were just trusting the output blindly. The post covers how I […]
infosec.exchange
Original post on infosec.exchange
122
Reposted by Drew
KoifSec @koifsec.bsky.social · 10/03/2026
New post out! "The Red Queen’s Race: Arms Race Dynamics in Threat Detection" medium.com/@koifsec/the...
medium.com
The Red Queen’s Race: Arms Race Dynamics in Threat Detection
“Now, here, you see, it takes all the running you can do, to keep in the same place.” — The Red Queen, Through the Looking-Glass
011
Reposted by Drew
ThreatInsight @threatinsight.proofpoint.com · 26/02/2026
On this episode of Discarded, our team explores how #artificialintelligence is shaping modern #malware analysis and detection workflows. Listen now on your favorite #podcast platform, and you'll get a balanced view of AI's growing impact on cybersecurity. 🎙️: www.proofpoint.com/us/podcasts/...
011
Reposted by Drew
Thomas Roccia :verified: @fr0gger.infosec.exchange.ap.brid.gy · 16/02/2026
🤓 Happy to see that my DEFCON talk on crypto money laundering and tracking techniques was featured in the DEFCON 33 Almanac! Read it here: harris.uchicago.edu/sites/default/f…
021
Reposted by Drew
Allan “Ransomware Sommelier” Liska @ransomwaresommelier.com · 14/02/2026
I started making comics, in part, as a respite from the grind that is cybersecurity. Only hackers/scammers are everywhere. I’m no @johnhammond.bsky.social but here is my video on how scammers try to take advantage of creators on Kickstarter.
034
Drew @bugfire.io · 09/02/2026
This looks very interesting! 👇
000
Reposted by Drew
CyberRaiju @jaiminton.com · 08/02/2026
Episode 2 of Breach Log is now available! Special thanks to Max Margolis for joining me and telling his story. If you have a story you'd like to share, get in contact and we can have some fun! breachlogpodcast [@] gmail[.]com open.spotify.com/episode/4SDz...
open.spotify.com
Spotify – Web Player
011
Reposted by Drew
Thomas Roccia :verified: @fr0gger.infosec.exchange.ap.brid.gy · 01/02/2026
🤓 Let me introduce you to MoltThreats: The first AI Threat Intel Feed for Ai Agents! In one week, OpenClaw became a widely used general AI agent. People started to run their own agents all over the world and connect them directly to the internet. But this […] [Original post on infosec.exchange]
131
Reposted by Drew
Brad @malware-traffic-analysis.net · 31/01/2026
2026-01-31 (Friday): I've posted a new traffic analysis exercise. It's Lumma in the room-ah! Join the fun at www.malware-traffic-analysis.net/2026/01/31/i... I mean, this guy looks like he's having fun.
053
Reposted by Drew
Brad @malware-traffic-analysis.net · 29/01/2026
2026-01-22 (Thursday): #RemcosRAT infection persistent on an infected Windows host. This was caused by #ClickFix instructions from #SmartApeSG through a fake CAPTCHA page. Details of this #Remcos #RAT infection are available at www.malware-traffic-analysis.net/2026/01/06/i...
Screenshot from an infected Windows host showing Remcos RAT and how it is persistent.
032
Reposted by Drew
Mehmet Ergene @cyb3rmonk.bsky.social · 27/01/2026
I've released my new course: Practical Threat Hunting for Beginners Similar courses: $$$$ This course: $$ academy.bluraven.io/course/pract... #ThreatHunting #DetectionEngineering
academy.bluraven.io
Practical Threat Hunting for Beginners
Learn the core knowledge and practical skills required to perform effective threat hunting in real-world environments.
022
Reposted by Drew
Karsten Hahn @struppigel.bsky.social · 25/01/2026
🦔 📹 New Video: Can office files be malicious without Macros? ➡️ VSTO Add-Ins ➡️ External Templates ➡️ Checklist for Office analysis #MalwareAnalysisForHedgehogs www.youtube.com/watch?v=RtHH...
youtube.com
Malware Analysis - Malicious MS Office files without Macros
YouTube video by MalwareAnalysisForHedgehogs
264
Drew @bugfire.io · 23/01/2026
Karsten's samplepedia is a great resource for malware samples and analysis solutions!
010
Reposted by Drew
Josh Stroschein | The Cyber Yeti @jstrosch.bsky.social · 21/01/2026
Is the 9-5 a thing of the past? 💀 Dhillon Kannabhiran (HITB) says the "hacker ethos" is replacing the corporate ladder. From on-demand bug hunting to working across time zones, the rules of the game have changed. podcasts.apple.com/us/podcast/e...
021
Reposted by Drew
Sarah Gooding @sarahgooding.bsky.social · 15/01/2026
😵‍💫 The Chrome extension ecosystem really is the wild west, and remains largely uncharted territory for security teams. You need visibility into what’s actually running in the browser. cc: @campuscodi.risky.biz @zackwhittaker.com @bleepingcomputer.com
085
Drew @bugfire.io · 15/01/2026
Nice work from @malware-traffic-analysis.net in the ISC diary blog on Lumma scheduled tasks from yesterday: isc.sans.edu/diary/Infect...
isc.sans.edu
Infection repeatedly adds scheduled tasks and increases traffic to the same C2 domain
Infection repeatedly adds scheduled tasks and increases traffic to the same C2 domain, Author: Brad Duncan
020
Reposted by Drew
Lenny Zeltser @lennyzeltser.com · 12/01/2026
I released a tool for making your website or docs easily available to AI assistants via an MCP server. This helps ensure people's AI tooling can access the latest details at the right time. For instance, this is how REMnux users now can get info about its malware analysis tools.
zeltser.com
Publishing Your Website Content to AI Assistants
When people ask AI assistants about your product or project, they often get outdated information. Here's how to publish your static website content directly to AI tools using Cloudflare Workers and th...
011
Drew @bugfire.io · 12/01/2026
Recommending this one, it’s a great idea! 👇
010
Drew @bugfire.io · 09/01/2026
Found the perfect product for @selenalarson.bsky.social - changing fingernail color on demand via iPhone! Next up: hacking Selena’s nails! www.reuters.com/video/watch/...
reuters.com
Color-changing 'iPolish' smart nails unveiled at CES 2026
The Florida-based company digital beauty brand iPolish unveiled smart, color-changing press-on nails at CES in Las Vegas that can flip between over 400 shades in as little as five seconds. "When you w...
100