Sign in

cryptax.bsky.social

@cryptax.bsky.social
268 followers 177 following 138 posts

Android malware analysis. Ph0wn CTF founder. IoT hacking. Frequent speaker at Virus Bulletin, Insomnihack etc. Based in France. Currently testing Bluesky. Otherwise on Mastodon.social.

PostsRepliesMedia
cryptax.bsky.social @cryptax.bsky.social · 31/07/2026
Blogged on Labuba RAT: cryptax.github.io/posts/labuba... My blog post is focused on reversing some anti-analysis features of the malware. For a general (technical) overview of the malware, read this blackpointcyber.com/blog/labub
cryptax.github.io
LabubaRAT anti-analysis features
LabubaRAT is a Remote Access Tool (RAT) implemented in Rust. It was discovered and analyzed by two researchers at Blackpoint Cyber’s Adversary Pursuit Group. Usually, when there’s one technical analys...
000
Reposted by @cryptax.bsky.social
Virus Bulletin @virusbtn.bsky.social · 26/06/2026
Join Axelle Apvrille from Fortinet at VB2026 in Seville for a walkthrough of a real cyber incident that targeted an 89-year-old man in February 2026, revealing the full process used by the cybercriminals. 📅 Oct 15 | 09:30-10:00 | Red Room 👉 tinyurl.com/mrxpt752
012
Reposted by @cryptax.bsky.social
Joe Tidy BBC News @joetidy.bsky.social · 23/06/2026
How 100 hospitals switched to pen and paper to defeat a national cyber-attack. Here is our in-depth 10 minute YouTube documentary which we produced about the incredible response of Romanian cyber security teams and the unseen heroics of doctors and nurses in 2024. www.youtube.com/watch?v=WxY6...
youtube.com
How 100 hospitals switched to pen and paper to defeat a cyber attack - BBC World Service
YouTube video by BBC World Service
21711
cryptax.bsky.social @cryptax.bsky.social · 16/06/2026
Back from Capture The Evidence v2 organized by @eternalblue-off.bsky.social . It's an investigation-oriented CTF. All challenges and scenario are in French, but my blog is in English to motivate you to learn French and participate to the next edition ;P cryptax.github.io/posts/cte-v2/
cryptax.github.io
Capture The Evidence v2 (2026)
Capture The Evidence v2 - June 2026 French gendarmerie 🇫🇷 organized a special CTF called “Capture The Evidence” from June 5 to June 15, 2026. I participated for the first time, with a team of 4 called...
010
cryptax.bsky.social @cryptax.bsky.social · 01/06/2026
Last Friday, I was at Auvergn'hack, a small single-tracked conference in the middle of France. A very friendly atmosphere, beautiful weather, great venue, and several very interesting talks. cryptax.github.io/posts/auverg... #landlock #opencode #auvergne #quantum #crypto #conference #CTF
010
cryptax.bsky.social @cryptax.bsky.social · 26/05/2026
Ce vendredi, atelier "reverse avec IA" à Auvergn'hack : www.auvergnhack.fr - Configurer OpenCode - Installer Ghidra + son serveur MCP - Créer un agent et des skills pour le reverse - Résoudre divers challenges CTF et CrackMe avec IA - Visual Studio Code + Cline - Rétro-ingénierie de Saint Nectaire
232
Reposted by @cryptax.bsky.social
NorthSec @nsec.io · 13/05/2026
Can't make it to NorthSec conferences this year? We got you covered! Talks will be livestreamed on Youtube on starting Thursday morning at 9:00, Eastern Time. ⏯️ Youtube playlist: www.youtube.com/playlist?lis...
youtube.com
NorthSec 2026 - YouTube
022
cryptax.bsky.social @cryptax.bsky.social · 04/05/2026
We're speaking at THCon, with Damien, on Wednesday this week. AI has really changed CTFd. Can we do something about it? Yes. We'll present a couple of ideas we experimented with - and hope it gives you tons of other ideas. #CTF #AI
122
cryptax.bsky.social @cryptax.bsky.social · 13/04/2026
If you want to learn to use #AI #agents and #skills, my new blog post might interest you. It's about the setup I used to play @1ns0mn1h4ck.bsky.social CTF. Obviously, this is *not* the way to go to learn #CTF skills... cryptax.medium.com/agent-skills...
cryptax.medium.com
Agent & skills setup for Insomni’hack CTF
“Artificial Intelligence ruins CTFs and easily solves challenges”. Have you tried? I wanted to try and see for myself (1) how difficult the…
130
Reposted by @cryptax.bsky.social
EternalBlue Officiel @eternalblue-off.bsky.social · 10/04/2026
Inscription au CTE L’enfer numérique de la RGPACA 🚓 Inscrivez vous en suivant le lien suivant : 🔗 grist.numerique.gouv.fr/o/docs/forms... 🚨 Chaque équipier doit s’inscrire : vous recevrez un e-mail au plus tard 7 jours après votre inscription, pour vous signifier sa bonne prise en compte.
111
cryptax.bsky.social @cryptax.bsky.social · 27/03/2026
Ph0wn Mag #3 eZine is out! With writeups of FrangiPh0wn (teaser of Ph0wn) and Ph0wn CTF 2026 github.com/ph0wn/writeu...
001
cryptax.bsky.social @cryptax.bsky.social · 05/03/2026
What's particularly cool about Ph0wn CTF? 1. It's onsite. If you haven't ever been to an onsite CTF, you absolutely must. 2. It's dedicated to connected devices, so you get to interact with tons of equipment! 3. The challenges are really awesome, yes, yes. Register at ph0wn.org - March 13/14
ph0wn.org
Ph0wn CTF
021
cryptax.bsky.social @cryptax.bsky.social · 04/03/2026
Oh? Rust based keylogger?!
000
Reposted by @cryptax.bsky.social
Le Cartographe 🗺️🍷 @lecartographe.bsky.social · 03/03/2026
Ce mardi 3 mars 2026, une éclipse totale de Lune se produit. Une partie de la planète aura l’occasion de voir le satellite prendre une teinte rougeâtre, ce qui amène parfois à l’appeler « Lune de sang ». #PosterCarto de la #Lune ! :) 👇 le-cartographe.net/publications...
0144
Reposted by @cryptax.bsky.social
Laurent Cheylus @lcheylus.bsky.social · 03/03/2026
Can AI Agents detect some hidden Backdoors in Binaries? Experiments with Code injected in C/Rust Projects, then analyze of resulting Binary with AI Coding Agents + access to reverse engineering Tools (Ghidra, Radare2, and binutils) #ReverseEngineering #AI quesma.com/blog/introdu...
quesma.com
We hid backdoors in ~40MB binaries and asked AI + Ghidra to find them - Quesma Blog
BinaryAudit benchmarks AI agents using Ghidra to find backdoors in compiled binaries of real open-source servers, proxies, and network infrastructure.
032
Reposted by @cryptax.bsky.social
CNES @cnes.fr · 03/03/2026
👁️🌌 La nébuleuse de l’Œil du Chat comme vous ne l’avez jamais vue ! Grâce à Hubble Space Telescope et Euclid, une nouvelle image spectaculaire révèle les derniers instants d’une étoile à 4 300 années-lumière. 👉 À lire ici : cnes.fr/actualites/i... #Cnes @esa.int @ec-euclid.bsky.social
cnes.fr
En images : la nébuleuse de l’Œil du Chat vue par Hubble et Euclid | CNES
Une nouvelle image a été dévoilée aujourd’hui par l’ESA : une observation conjointe des satellites Hubble et Euclid, qui se sont intéressés de très près à la nébuleuse de l’Œil du Chat, ou NGC 6543.
16224
cryptax.bsky.social @cryptax.bsky.social · 04/03/2026
Reminds me of ph0wn teaser !! #ctf
000
Reposted by @cryptax.bsky.social
Phrack Zine @phrack.org · 04/03/2026
I spy a Phrack gnome in the latest FIRE #ansi pack! Thanks @nail7.bsky.social, it's so cool!
Phrack gnome ansified by nail!
0296
cryptax.bsky.social @cryptax.bsky.social · 02/03/2026
⏰Time to register to ph0wn CTF now! There are also a few remaining seats to the Embedded Rust workshop, where you'll implement the 🐍Snake game on Micro:Bit. Don't forget your pirate costume 🧙‍♀️for the Creative Contest, and your xploits for ph0wn2own! ph0wn.org
ph0wn.org
Ph0wn CTF
000
cryptax.bsky.social @cryptax.bsky.social · 24/02/2026
This piece of code (Arduino) is vulnerable. What's the best fix? Comment. Don't know, or want to discuss about it? Come to ph0wn in Sophia Antipolis on March 13-14: ph0wn.org (free, registration required).
000
Reposted by @cryptax.bsky.social
Laluka @laluka.bsky.social · 19/02/2026
Replay de Mardi dernier ⬇️ En vous souhaitant une belle journée 🌻 www.youtube.com/live/asGIbQg...
022
cryptax.bsky.social @cryptax.bsky.social · 17/02/2026
For ph0wn registration, we see that many of you are struggling to put several items in your cart and consequently create x different registrations. It's simple. In pretix, you need to click on "Add tickets for a different date". Then select an other "event" : CTF, social event, workshop. #ph0wn
000
Reposted by @cryptax.bsky.social
Laluka @laluka.bsky.social · 13/02/2026
Hoy ⚔️ Next Stream : FrangiPh0wn CTF - What, How, Who, WriteUps! 💣 👉 Mardi 17 Fevrier à 21h Ft. @Cryptax , Miaou, YoyoChaud 👉 Join Live www.twitch.tv/thelaluka 👉 Discord Events discord.com/events/11337...
012
cryptax.bsky.social @cryptax.bsky.social · 07/02/2026
Are you stuck on one of the first 2 challenges of #FrangiPh0wn? As the teaser ends in 2 days, we've released a few hints, and hope they will help you reach the next level ;) ctf.ph0wn.org #RF #OSINT #AI #retrogaming #ph0wn #CTF
022
cryptax.bsky.social @cryptax.bsky.social · 26/01/2026
📅 March 13-14, 2026 - Sophia Antipolis, France 🤠 Prepare your best outfit for Ph0wn CTF's side event: the "Creative Contest". Come dressed up as a pirate, and get a chance to win a Hydrabus 😃 👉️ Details: ph0wn.org/contest/ #CTF #ph0wn2026 #pirate #flagship #hydrabus #hacker Re-posts appreciated
Image of pirates, with pirate ships in background. This advertises for Ph0wn's creative contests, where if you "exploit the outfit", you get a chance to win a Hydrabus. https://ph0wn.org
031
Reposted by @cryptax.bsky.social
Elbsides @elbsides.bsky.social · 14/01/2026
All hands on keyboard, pen to paper - Elbsides 2026 Call for Paper is open!!! Make good on your New Year resolution to contribute to the infosec community and present on June 5th in Hamburg. www.elbsides.eu/2026/cfp/ #elbsides2026 #CFPisopen #startwriting #infosec
033
cryptax.bsky.social @cryptax.bsky.social · 10/01/2026
FrangiPh0wn, the Ultimate Galette for Hackers and ph0wn CTF teaser, is up until Feb 9. Head to ctf.ph0wn.org, and find the trinkets! Are you up to it? Only 15 participants flagged something up to now. Go for it! #CTF #teaser #RF #OSINT #ph0wn #frangiph0wn
031
cryptax.bsky.social @cryptax.bsky.social · 16/12/2025
Ph0wn #CTF Teaser Announced for January! We hope you get the right tools and skills for Xmas :D Get ready! We will announce #FrangiPh0wn in January. Keep an eye on ph0wn.org
010
cryptax.bsky.social @cryptax.bsky.social · 16/12/2025
Best talks, papers, CTF challenges, tools I encountered in the second half of 2025: cryptax.github.io/nomination-2... Congratulations to those who are listed, and kudos to others :) cc: @trufae.bsky.social @uybhys.bsky.social @nst021.bsky.social @synacktiv.com
cryptax.github.io
Cryptax Nomination Awards 2025 H2
Cryptax Nomination Awards. Lol. In other words, I’m listing my favorite talks, papers, challenges (etc) for the second half of 2025. Nothing more than that. Okay? H2 2025 Category Nominated Best secur...
030
cryptax.bsky.social @cryptax.bsky.social · 08/12/2025
Variants of 2025 of Symbiote and BPFDoor support IPv6, UDP communication with C2. Reverse engineering the samples with r2ai and r2mcp. www.fortinet.com/blog/threat-... #malware #Linux #BPF #r2ai #r2mcp
fortinet.com
New eBPF Filters for Symbiote and BPFdoor Malware | FortiGuard Lab
FortiGuard Labs discovered new Symbiote and BPFDoor variants exploiting eBPF filters to enhance stealth through IPv6 support, UDP traffic, and dynamic port hopping for covert C2 communication.…
001
cryptax.bsky.social @cryptax.bsky.social · 06/11/2025
Pour mon atelier "Reverse engineering with r2ai" à @uybhys.bsky.social demain, si vous avez un laptop x86, téléchargez en avance l'image: docker pull cryptax/r2ai:2025.11 #radare2 #IA #r2ai #UYBHYS25 #docker #workshop
010
cryptax.bsky.social @cryptax.bsky.social · 04/11/2025
Ca va parler de Radare2, de Ghidra, de MCP et d'assembleur en tout genre. L'objectif est d'utiliser l'IA pour faciliter la rétro-ingénierie. L'IA ne fait pas tout (par exemple, elle ne fait pas les crêpes que je compte déguster sur place), mais elle aide ... si on sait l'utiliser. Venez !
132
Reposted by @cryptax.bsky.social
Unlock Your Brain, Harden Your System @uybhys.bsky.social · 03/11/2025
#UYBHYS A l'occasion de #UYBHYS25, de 10h à 17h les vendredi 7 et samedi 8 novembre, @ratzillas.bsky.social animera, sur le parvis du #Quartz à #Brest, un atelier de démonstration de "Car Hacking", accessible à toutes et tous sans inscription. 🙂
086
Reposted by @cryptax.bsky.social
Unlock Your Brain, Harden Your System @uybhys.bsky.social · 03/11/2025
#UYBHYS #UYBHYS25 #Brest Il reste encore des places pour quelques ateliers de vendredi et pour la journée de conférences de samedi. Billetterie : pretix.eu/cantine/UYBH...
pretix.eu
Unlock Your Brain, Harden Your System #UYBHYS !
7 Novembre 2025 – 8 Novembre 2025
024
cryptax.bsky.social @cryptax.bsky.social · 22/09/2025
On Thursday afternoon, I am thrilled to give my first r2ai & ghidraMCP workshop at BruCON. Pre-requisites: you are good to go if you already have reversed a binary (with whatever #disassembler, it doesn't matter) OR if you have basic skills and understanding in #assembly. #mcp #LLM #AI
130
cryptax.bsky.social @cryptax.bsky.social · 01/09/2025
Slides of my prez at Barb'hack: www.fortiguard.com/events/6189/... Understand what a recent sample of Linux/Trigona #ransomware does. Learn how to spot #AI errors (hallucinations, omissions etc), learn how to tweak context length, output token limits to get the best out of your model. #barbhack25
fortiguard.com
Publications | FortiGuard Labs
<p>This talk presents 2 different Linux malware:</p><ul><li><p>a shellcode, named Linux/Shellcode_ConnectBack.H!tr. The binary is small and compact, but traditional disassemblers like Ghidra fail to p...
162
cryptax.bsky.social @cryptax.bsky.social · 31/08/2025
I had (several) interesting questions yesterday on r2ai. One of them was that, obviously the tool needed to be used by an experienced reverse engineer. I'd like to comment a bit further. I feel normal that such a tool cannot be used by total beginners. All jobs require some adequate training. 1/n
100
cryptax.bsky.social @cryptax.bsky.social · 31/08/2025
Barb'hack is over and it was a pleasure to attend: very nice folks, friendly organizers, excellent food, best rumps lol and a CTF with a videogame interface+ challenges on Minitel. I loved it! Kudos to the staff. #barbhack25
060
cryptax.bsky.social @cryptax.bsky.social · 25/08/2025
I've very happy to speak at Barb'hack on Saturday. barbhack.fr/2025/fr/conf... There will be 2 demos. One live. One recorded - simply because I don't have the guts to do it live ;P We reverse engineer Linux/Trigona and Linux/Shellcode with radare2 + AI + HI HI standards for Human Intelligence ;P
this image was generated by Dall-E based on a prompt that describes what Linux/Trigona malware does. The malware is implemented in Delphi, thus the FPC (Free Pascal Compiler).
110
cryptax.bsky.social @cryptax.bsky.social · 21/08/2025
Overlays are often used in Android malware. They are actually a burden to other domains such as browser extensions. This research, by Marek Toth, shows how click jacking [on hidden overlays] can trick the end-user in sharing his/her entire password manager. marektoth.com/blog/dom-bas...
marektoth.com
DOM-based Extension Clickjacking: Your Password Manager Data at Risk
I described a new attack technique that I used against 11 password managers. The result was that stored data of tens of millions of users could be at risk.
111
Reposted by @cryptax.bsky.social
Virus Bulletin @virusbtn.bsky.social · 19/08/2025
Last chance to share your research at VB2025. Whether you have fresh research, practical insights, or real-world case studies to share, now is your moment to step into the spotlight! 📅 24 Aug 2025 — only 5 days left 📍 Berlin. 24–26 Sept 2025 👉 tinyurl.com/3mccm8br
Aug 24
Last-minute CFP still open - only 5 days left
VB2025 Berlin 24-26 Sept 2025
013
cryptax.bsky.social @cryptax.bsky.social · 19/08/2025
I've recently setup a LM Studio server, with several models including gpt-oss. I can use it from my disassembler, here to analyze a Linux/Trigona sample. Learn more about Trigona at Barb'hack on Aug 30 in Toulon. #AI #malware #reverse #assembly #context #lmstudio #GPT
121
cryptax.bsky.social @cryptax.bsky.social · 16/07/2025
I love this kind of analysis 😍 Well done! Exploiting the Thermomix. Hey @synacktiv.com can you cook me a chocolate cake? ;-) www.synacktiv.com/en/publicati...
synacktiv.com
Let Me Cook You a Vulnerability: Exploiting the Thermomix TM5
Related Work The Thermomix TM5 has previously drawn the attention of the security community, notably through research presented by Jean-Michel Besnard at SSTIC 2019 [1], which described a code execut
031
cryptax.bsky.social @cryptax.bsky.social · 10/07/2025
My blog post on how AI is reshaping malware and malware analysis is out: www.fortinet.com/blog/threat-... Examples on Linux/Trigona, Linux/Prometei, Linux/Ladvix and Android/SpyLoan. Enjoy. #malware #r2ai #r2 #claude #delphi #trigona #rust #flutter
fortinet.com
Catching Smarter Mice with Even Smarter Cats | FortiGuard Labs
Explore how AI is changing the cat-and-mouse dynamic of cybersecurity, from cracking obfuscation and legacy languages to challenging new malware built with Flutter, Rust, and Delphi.…
000
cryptax.bsky.social @cryptax.bsky.social · 04/07/2025
W32/SkyAI uses AI? So do I. cryptax.medium.com/w32-skyai-us... - Where the malware loads the AI prompt, what for, why it fails. - How to find the encryption key with AI - Extract & decrypt the embedded PE - How the malware checks if it's on a VM - R2ai tips when curl argument is too long
cryptax.medium.com
W32/SkyAI uses AI? So do I.
A new sample, named W32/SkyAI (or Topozuy, or Skynet), has recently emerged, showing use of a AI prompt bypass attempt. Perfect occasion to…
210
Reposted by @cryptax.bsky.social
Bearstech @bearstech.com · 30/06/2025
Le nouveau zine de @b0rk.jvns.ca : Les règles secrètes du terminal 👉 jvns.ca/blog/2025/06...
table des matières
02011
cryptax.bsky.social @cryptax.bsky.social · 30/06/2025
Vous connaissez les vidéos de @tixlegeek.bsky.social ? Avec cet adorable Tux animé ? Ben, ça me faisait trop envie. Alors j'ai fait pareil avec Pico le Croco ! J'ai repris les explications de @tixlegeek.bsky.social dans le Twitch @laluka.bsky.social EP 193, et j'ai codé pour Pico :)
150
cryptax.bsky.social @cryptax.bsky.social · 17/06/2025
Nicolas Rouvière, of Ph0wn and SHL, will show you how to use Qiling in practice, for dynamic binary emulation. Don't miss it: on-site at SHL (Vallauris), June 19 at 7pm. In 2024, Nicolas used Qiling to solve the Ph0wn CTF teaser. See how here: github.com/ph0wn/writeu... #qiling #CTF #binary
102
cryptax.bsky.social @cryptax.bsky.social · 14/06/2025
Hey, I'd like to share the best talks/papers/videos/tools/CTF challenges I encountered in 2025 H1. This is the official "Cryptax Award 2025 H1" (lol). Congrats! cryptax.github.io/nomination-2... cc: @elbsides.bsky.social @northsec.io @radareorg.bsky.social @bsideskrs.bsky.social
cryptax.github.io
Cryptax Nomination Awards 2025 H1
Cryptax Nomination Awards. Lol. In other words, I’m listing my favorite talks, papers, challenges (etc) for the first half of 2025. Nothing more than that. Okay? H1 2025 Category Nominated Best cyberc...
002
cryptax.bsky.social @cryptax.bsky.social · 13/06/2025
How many times will I have to say this? Antivirus is not stupid and does NOT rely on fixed hashes or whatever to detect malware. This is an outdated myth from prehistoric times. Malware "signatures" understand binary formats + assembly and can easily dynamically detect variants.
061