Sign in

hasherezade.bsky.social

@hasherezade.bsky.social
1.5K followers 75 following 27 posts

Programmer, #malware analyst. Author of #PEbear, #PEsieve, #TinyTracer. Private account. All opinions expressed here are mine only (not of my employer etc) ; hasherezade.net

PostsRepliesMedia
hasherezade.bsky.social @hasherezade.bsky.social · 31/08/2026
My research blog about #JSCeal is finally out! It was quite a journey. I hope you will like it! research.checkpoint.com/2026/breakin... // #V8 #bytecode #malware #deobfuscation #BlackHatUSA2026
080
Reposted by @hasherezade.bsky.social
Catalin Cimpanu @campuscodi.risky.biz · 08/08/2026
In an update, CERT Poland says the Russian data wiper attack that targeted a power plant last December also targeted a previously unreported second plant cert.pl/en/posts/202...
cert.pl
Follow-Up Report of the December 2025 Energy Sector Incident
During the attacks against Poland's energy sector in late 2025, a second combined heat and power plant was also affected. We are publishing a report detailing an investigation that lasted more than th...
01811
hasherezade.bsky.social @hasherezade.bsky.social · 01/08/2026
At #BlackHat2026, I’ll walk through the #JSCeal #malware case study and the static deobfuscation toolkit I built to recover readable code from the obfuscated #V8 compiled bytecode. If you’ll be at #BlackHat, I’d be glad to see you there! blackhat.com/us-26/briefi...
030
Reposted by @hasherezade.bsky.social
Catalin Cimpanu @campuscodi.risky.biz · 23/06/2026
Two members of the Scattered Spider hacking group—Thalha Jubair and Owen Flowers—pleaded guilty to hacking Transport for London last year www.bbc.com/news/article...
bbc.com
Two men plead guilty over £39m Transport for London cyber attack
The data breach affected 10m customers and disrupted some services for three months in summer 2024.
1116
Reposted by @hasherezade.bsky.social
Karsten Hahn @struppigel.bsky.social · 19/06/2026
New trainings sample on samplepedia Backdoor, obfuscated Python bytecode. 0/60 on Virustotal, which means it's still fresh. www.virustotal.com/gui/file/4ad... samplepedia.cc/sample/4ada6...
012
Reposted by @hasherezade.bsky.social
Catalin Cimpanu @campuscodi.risky.biz · 17/06/2026
-China arrests members of Silver Fox cybercrime group -EU to help Ukraine in major cyberattacks -MS-ISAC loses 70% of members -SBOM still not widely adopted -Infosec execs call for lifting Anthropic ban Newsletter: news.risky.biz/risky-bullet... Podcast: risky.biz/RBNEWS578/
283
Reposted by @hasherezade.bsky.social
dan @danabra.mov · 06/06/2026
this is actually a very good article
0xkato.xyz
How LLMs Actually Work
A from-the-ground-up walkthrough of how modern LLMs work, from tokens to transformer blocks to the next-token loop
1028854
hasherezade.bsky.social @hasherezade.bsky.social · 06/06/2026
Now the Linux build is also available as AppImage:
Alternative Linux builds available.
190
hasherezade.bsky.social @hasherezade.bsky.social · 06/06/2026
New release: #PEbear 0.7.2: github.com/hasherezade/... - with important bugfixes and new features:
PE-bear release notes - available on GitHub
194
hasherezade.bsky.social @hasherezade.bsky.social · 28/05/2026
New #TinyTracer (4.0) is ready: github.com/hasherezade/... - refactored for compatibility with the latest PIN - and with some new features!
094
Reposted by @hasherezade.bsky.social
ChiefGyk3D @chiefgyk3d.com · 23/05/2026
This is the point AI fanboys keep missing. Yes, AI can help you ship faster. That does not mean it understands architecture, consistency, maintainability, or long term technical debt for you. You still need to know what you are doing
3125
Reposted by @hasherezade.bsky.social
Fernando Mercês @mer0x36.bsky.social · 28/01/2026
dz6 v0.4.2 is out! github.com/mentebinaria... - now with a smoother scrolling. 🙂
github.com
GitHub - mentebinaria/dz6: A vim-inspired, TUI-based hexadecimal editor
A vim-inspired, TUI-based hexadecimal editor. Contribute to mentebinaria/dz6 development by creating an account on GitHub.
021
Reposted by @hasherezade.bsky.social
hasherezade.bsky.social @hasherezade.bsky.social · 27/11/2025
And #FlareOn12 Task 8: wp.me/p2mVNF-2Qf
wp.me
Flare-On 12 – Task 8
In this mini-series I describe the solutions of my favorite tasks from this year’s Flare-On competition. To those of you who are not familiar, Flare-On is a marathon of reverse engineering. This ye…
082
hasherezade.bsky.social @hasherezade.bsky.social · 20/11/2025
Long overdue, but here’s my writeup for #FlareOn12 Task 9: hshrzd.wordpress.com/2025/11/20/f...
hshrzd.wordpress.com
Flare-On 12 – Task 9
In this mini-series I describe the solutions of my favorite tasks from this year’s Flare-On competition. To those of you who are not familiar, Flare-On is a marathon of reverse engineering. T…
1132
Reposted by @hasherezade.bsky.social
Gynvael Coldwind @gynvael.bsky.social · 01/11/2025
Heeey, ncurses/terminfo has a small virtual machine! And if there's a VM, there are CTF challenges :) hackarcana.com/public-exerc... hackarcana.com/public-exerc... (third one coming next week, will be a bit harder)
0167
Reposted by @hasherezade.bsky.social
Volatility @volatilityfoundation.org · 29/10/2025
The 13th annual @volatility #PluginContest is OPEN for submissions until 31 Dec 2025! This contest is designed to encourage research & development in the field of #memoryanalysis. Every year, contributions from all around the world continue to help build the next generation of #memoryforensics.
volatilityfoundation.org
The 13th Annual Volatility Plugin Contest is Open!
We are excited to announce that the Volatility Plugin Contest is officially open for submissions! The annual Plugin Contest is your opportunity to: Directly contribute to the open source forensics …
014
Reposted by @hasherezade.bsky.social
Catalin Cimpanu @campuscodi.risky.biz · 24/10/2025
-iOS 26 change deletes clues of old spyware infections -Starlink disables 2.5k scam compound terminals -Caribbean hospital still down 5 months after ransomware attack -Poland charges officials in Pegasus scandal Newsletter: news.risky.biz/risky-bullet... Podcast: risky.biz/RBNEWS495/
11811
Reposted by @hasherezade.bsky.social
Paul Hudson @twostraws.bsky.social · 22/10/2025
Today I'm launching my new app, Hacktivate. It teaches real-world computer science skills through 240 "capture the flag" challenges, and works on iPhone, iPad, and Mac with one purchase. I've poured a ton of love into it, and I'd love to hear what you think 🙌 apps.apple.com/gb/app/hackt...
apps.apple.com
‎Hacktivate: Capture the Flag
‎Crack codes. Break firewalls. Conquer the map. Hacktivate is the ultimate cybersecurity challenge: a world map of 240 missions where every puzzle is built on real cybersecurity techniques hackers us...
1816430
Reposted by @hasherezade.bsky.social
clibm079 @clibm079.bsky.social · 19/10/2025
I used PE-bear for the first time to dump an embedded binary. Its intuitive UI made extraction effortless. Because malware often embeds payloads with the form A in B to evade detection, pulling out the inner binary was crucial for deeper analysis and IoCs hunting.
222
hasherezade.bsky.social @hasherezade.bsky.social · 11/10/2025
Finally done with #FlareOn12. What a ride! I am looking forward to read other people’s solutions, especially of those who did the 9th task quickly.
090
Reposted by @hasherezade.bsky.social
Volatility @volatilityfoundation.org · 18/09/2025
#FTSCon Speaker Spotlight: Aleksandra Doniec (@hasherezade.bsky.social) is presenting “Uncovering Malware's Secrets with TinyTracer” in the MAKER track. See the full list of speakers + event info, including how to register, here: volatilityfoundation.org/from-the-sou...
026
Reposted by @hasherezade.bsky.social
Karsten Hahn @struppigel.bsky.social · 01/09/2025
My intermediate level malware analysis course is there. 60% off for the next two weeks. malwareanalysis-for-hedgehogs.learnworlds.com/course/inter...
malwareanalysis-for-hedgehogs.learnworlds.com
Malware Analysis - Intermediate Level
Signature writing, deobfuscation, dynamic API resolving, syscalls, hooking, shellcode analysis and more
196
Reposted by @hasherezade.bsky.social
Hexacorn @hexacorn.bsky.social · 06/07/2025
Beyond good ol’ Run key, Part 148 www.hexacorn.com/blog/2025/07...
051
hasherezade.bsky.social @hasherezade.bsky.social · 06/06/2025
New #TinyTracer (v3.0) is out - with many cool features: github.com/hasherezade/... - check them out!
1156
Reposted by @hasherezade.bsky.social
sixtyvividtails @sixtyvividtails.bsky.social · 06/05/2025
1. Pause thread midway in exploit races (even ⓪). 2. Or block entire CPU core. Kernel APCs run at APC_LEVEL (🤯), so thread scheduling kinda disabled (think priority == ∞). 3. Or build upon @hasherezade.bsky.social work & generalize #WaitingThreadHijacking — making it, in fact, Waitless.
021
Reposted by @hasherezade.bsky.social
sixtyvividtails @sixtyvividtails.bsky.social · 06/05/2025
Heard of #ContextJail? It's a nasty new technique: puts target thread into ⓪ deadloop, for as long as you can afford. Requires THREAD_GET_CONTEXT right. The gist? Just spam NtGetContextThread(tgt).😸 Target will be jailed, running nt!PspGetSetContextSpecialApc 🔁. Src & binary in [ALT]. Usecases: ⤵️
Screenshot of contextjail.exe running with default arguments.


Highlighted:

* prisoner thread (latched to CPU1 with priority 15) couldn't run for the entire test duration (30 seconds).

* 99 jailer threads (latched to 6/8 processors, CPU2..CPU7) were using 20% of total CPU time.


Overlay: pseudo-ASSCII art with prisoner thread and 6 jailer threads (guards), spamming NtGetContextThread to block the prisoner.


Source and compiled binary:
https://pastebin.com/pBJcGp1y
176
hasherezade.bsky.social @hasherezade.bsky.social · 14/04/2025
My new blog for CPR: introducing Waiting Thread Hijacking - a remote process injection technique targeting waiting threads: research.checkpoint.com/2025/waiting... #ProcessInjection
research.checkpoint.com
Waiting Thread Hijacking: A Stealthier Version of Thread Execution Hijacking - Check Point Research
Research by: hasherezade Key Points Introduction Process injection is one of the important techniques used by attackers. We can find its variants implemented in almost every malware. It serves purpose...
31510
Reposted by @hasherezade.bsky.social
Catalin Cimpanu @campuscodi.risky.biz · 01/04/2025
Zscaler has published a technical report on HijackLoader (IDAT Loader, GhostPulse) and its recent changes, such as its new call stack spoofing module, anti-VM module, and support for scheduled task persistence www.zscaler.com/blogs/securi...
zscaler.com
New HijackLoader Evasion Tactics | ThreatLabz
Learn how HijackLoader has introduced call stack spoofing and new modules to improve its evasion and anti-analysis capabilities.
1104
Reposted by @hasherezade.bsky.social
pixelatedboat aka “mr bluesky” @pixelatedboat.bsky.social · 01/04/2025
Abolish April Fool’s day. Society has moved past the need for April Fool’s day
536132441529
Reposted by @hasherezade.bsky.social
Catalin Cimpanu @campuscodi.risky.biz · 27/03/2025
KELA has published a profile on Rey and Pryx, the two main individuals behind the Hellcat hacking group, responsible for several breaches over the past months, such as Schneider Electric, Telefónica, and Orange Romania. www.kelacyber.com/blog/hellcat...
kelacyber.com
Hellcat Hacking Group Unmasked: Investigating Rey and Pryx | KELA Cyber
KELA’s latest research uncovers key insights into two key threat actors of Hellcat Group, Pryx and Rey. Read more.
082
Reposted by @hasherezade.bsky.social
Kim Zetter @kimzetter.bsky.social · 24/03/2025
We all knew this day would arrive when the DNA samples you willingly provided 23andMe would be up for sale. Company now says it's seeking a buyer as it files for bankruptcy. 23andMe says any buyer will have to adhere to privacy laws for customer DNA/data they acquire. people.com/23andme-file...
people.com
23andMe Files for Bankruptcy as CEO Anne Wojcicki Resigns — What Will Happen to Your DNA Data?
Genetics company 23andMe has filed for bankruptcy and its CEO is stepping down, leaving many users concerned about the future of their data.
68035
Reposted by @hasherezade.bsky.social
Catalin Cimpanu @campuscodi.risky.biz · 23/03/2025
Clevo Boot Guard Keys Leaked in Update Package www.binarly.io/blog/clevo-b...
binarly.io
Clevo Boot Guard Keys Leaked in Update Package
Over the past few years, the Binarly Research team has led the way in documenting security problems haunting the entire UEFI ecosystem. We presented our discoveries at major security conferences like ...
095
Reposted by @hasherezade.bsky.social
vx-underground (automated mirror) @vxundergroundre.bsky.social · 22/03/2025
Someone has done an excellent job collecting RATs and documenting them by version. They also included images. A+ work. This is amazing (we're going to ingest this eventually) github.com/Cryakl/Ultim...
github.com
GitHub - Cryakl/Ultimate-RAT-Collection: For educational purposes only, exhaustive samples of 450+ classic/modern trojan builders including screenshots.
For educational purposes only, exhaustive samples of 450+ classic/modern trojan builders including screenshots. - Cryakl/Ultimate-RAT-Collection
04517
hasherezade.bsky.social @hasherezade.bsky.social · 22/03/2025
A small demo/tutorial on unpacking executables with #PEsieve and #TinyTracer: hshrzd.wordpress.com/2025/03/22/u... - automatic OEP finding, reconstructing IAT, avoiding antidebugs and fixing imports broken by shims
hshrzd.wordpress.com
Tutorial: unpacking executables with TinyTracer + PE-sieve
In this short blog I would like to demonstrate you how to unpack an executable with PE-sieve and Tiny Tracer. As an example, let’s use the executable that was packed with a modified UPX: 8f66…
02813
Reposted by @hasherezade.bsky.social
tmp0ut @tmpout.sh · 21/03/2025
Would you look at that, it's tmp.0ut Volume 4! Happy Friday, hope you enjoy this latest issue! tmpout.sh/4/
table of contents for tmp.0ut volume 4
212163
Reposted by @hasherezade.bsky.social
netspooky @vacci.ne · 21/03/2025
Did anyone find the secret art page? 👀
2103
Reposted by @hasherezade.bsky.social
RE//verse @re-verse.io · 21/03/2025
Next RE//verse video released! Andrew's Day 2 keynote was the next most requested video. It starts with an aside from neuroscience, ends with a challenge to all tool developers and has a fantastic journey between:
youtu.be
RE//verse 2025: What 20 Years of RE Practice and Tool Research Feels Like It’s Done (Andrew Ruef)
Andrew starts his keynote with a journey into neuroscience and ends with a challenge for all reverse engineering tooling authors.Original Abstract:From RE//v...
032
Reposted by @hasherezade.bsky.social
nixCraft @cyberciti.biz · 20/03/2025
whoever made this one, it is perfect for IT work or life in general.
510715
Reposted by @hasherezade.bsky.social
Catalin Cimpanu @campuscodi.risky.biz · 16/03/2025
Prodaft has published a technical analysis of Anubis, a new Python-based backdoor linked to Savage Ladybug (FIN7) operations catalyst.prodaft.com/public/repor...
082
Reposted by @hasherezade.bsky.social
Catalin Cimpanu @campuscodi.risky.biz · 16/03/2025
The BlackBasta ransomware gang developed and used its own custom tool to brute-force enterprise firewalls and VPN remote-access products. Named Bruted, the tool was written in PHP and could brute-force the following products (see image) blog.eclecticiq.com/inside-brute...
A table that lists Microsoft RDWeb, Cisco ASA, SonicWall NetExtender, Fortinet SSL VPN, WatchGuard SSL VPN, Palo Alto GlobalProtect, and Cisco Gateway
12715
Reposted by @hasherezade.bsky.social
Catalin Cimpanu @campuscodi.risky.biz · 11/03/2025
The Blind Eagle APT group has compromised over 1,600 victims inside Colombian institutions and government agencies. The campaign took place in November & December of last year and used an exploit similar to a zero-day exploited by Russian hackers in Ukraine. research.checkpoint.com/2025/blind-e...
research.checkpoint.com
Blind Eagle: …And Justice for All - Check Point Research
Key Points Introduction APT-C-36, also known as Blind Eagle, is a threat group that engages in both espionage and cybercrime. It primarily targets organizations in Colombia and other Latin American co...
086
hasherezade.bsky.social @hasherezade.bsky.social · 09/03/2025
[DEMO] Searching for #AceLdr in memory, with #PEsieve/#HollowsHunter threads scan: www.youtube.com/watch?v=RQf2... ; read more: github.com/hasherezade/...
youtube.com
[DEMO] Searching for AceLdr in memory, with PE-sieve/HollowsHunter thread scan
YouTube video by hasherezade
044
hasherezade.bsky.social @hasherezade.bsky.social · 09/03/2025
#PEbear (github.com/hasherezade/...) is now available via WinGet (learn.microsoft.com/en-us/window...)! You can install it easier than ever - just type: `winget install pe-bear` from Powershell.
0128
Reposted by @hasherezade.bsky.social
nixCraft @cyberciti.biz · 28/02/2025
meanwhile in Australia 😂
833258
Reposted by @hasherezade.bsky.social
eversinc33 🤍🔪⋆。˚ ⋆ @eversinc33.bsky.social · 01/03/2025
Released part III of my anti anti rootkit series recently. I showcase a way to implement a 'threadless' rootkit by using a spin on the .data pointer hijacking technique known from kernel game cheats. This part concludes the trilogy, but theres more to come ;) eversinc33.com/posts/anti-a...
eversinc33.com
(Anti-)Anti-Rootkit Techniques - Part III: Hijacking Pointers
Hijacking .data ptrs to execute rootkit code
051
Reposted by @hasherezade.bsky.social
Hexacorn @hexacorn.bsky.social · 22/02/2025
Good Exports are real www.hexacorn.com/blog/2025/02...
031
hasherezade.bsky.social @hasherezade.bsky.social · 08/02/2025
New release: #IDA_IFL (Interactive Functions List) plugin v1.5 - works for IDA 9. Shout-out to my new contributor, @mahmoudimus.bsky.social who added the support! github.com/hasherezade/...
061
Reposted by @hasherezade.bsky.social
Josh Stroschein | The Cyber Yeti @jstrosch.bsky.social · 06/02/2025
⌛ This series will take you through installing WinDbg and configuring Binary Ninja to use the WinDbg engine to create and use TTD traces. It will also show you how to capture TTD traces and replay them in Binary Ninja 👇
buff.ly
Getting Started with Time-Travel Debugging in Binary Ninja
This series will take you through installing WinDbg and configuring Binary Ninja to use the WinDbg engine to create and use TTD traces. It will also show you...
044
Reposted by @hasherezade.bsky.social
Gynvael Coldwind @gynvael.bsky.social · 27/01/2025
Soft deadline for Paged Out! #6 is upon us – 1 Feb 2025 – pagedout.institute?page=cfp.php
pagedout.institute
CFP ⁂ Paged Out!
043
Reposted by @hasherezade.bsky.social
ChiefGyk3D @chiefgyk3d.com · 27/01/2025
Today, January 27, is Holocaust Remembrance Day—a time to reflect on the six million Jews murdered in the Holocaust, including members of my family. Six family names lost to history serve as a painful reminder of the deep, personal connections many of us have to this tragedy. 1/4
1133