Sign in

CyberRaiju

@jaiminton.com
299 followers 380 following 41 posts

An Aussie who does cyber things | Sr. Manager @Huntress.com | Former Principal @CrowdStrike.com and HuntressLabs | jaiminton.com | www.youtube.com/@cyberraiju/featured

PostsRepliesMedia
CyberRaiju @jaiminton.com · 18/09/2026
Give me your best captions! So far I have: "I guess the last driver crashed" and... "10 minutes into nmap and chill, and she gives you this look"
000
CyberRaiju @jaiminton.com · 27/05/2026
Threat actors are impersonating real recruiters and sending bulk, tailored phishing emails by using ChatGPT, your public LinkedIn profiles, and a tool known as blinq. More details: www.jaiminton.com/internal-blo...
jaiminton.com
Fake Recruiter Phishing Through AI and LinkedIn
Threat actors are posing as fake tech recruiters to steal information and scam you out of money
010
CyberRaiju @jaiminton.com · 08/04/2026
Episode 4 of Breach Log is now out! In this episode I'm joined by Cameron Cottam who tells his story about responding to a critical alert at 2am. Enjoy. Spotify: open.spotify.com/episode/26Lr... Other Providers: creators.spotify.com/pod/profile/...
open.spotify.com
Ep4: Think Twice Before You Fix It with Cameron
010
CyberRaiju @jaiminton.com · 06/03/2026
Episode 3 of Breach Log is now available! Whether you're heading into the weekend or beginning your Friday, I hope you can carve out a mere 20 minutes to enjoy another story from the vault of detecting and responding to hacks around the world. open.spotify.com/episode/7MY3...
open.spotify.com
Ep3: Care to Exchange 0-days?
000
CyberRaiju @jaiminton.com · 18/02/2026
If you've worked in Detection Engineering, Threat Hunting, Incident Response, or an adjacent field, or have been impacted by a breach and have a story to tell, get in contact I'd love to hear it and have you on the podcast. Details on the about page. creators.spotify.com/pod/profile/...
creators.spotify.com
Breach Log - Behind every hack is a story to tell • A podcast on Spotify for Creators
Breaches happen every single day, and behind every breach is a story. These are the stories from those involved. It's the stories of those who found, or responded to a breach, or even those who were i...
000
CyberRaiju @jaiminton.com · 08/02/2026
Episode 2 of Breach Log is now available! Special thanks to Max Margolis for joining me and telling his story. If you have a story you'd like to share, get in contact and we can have some fun! breachlogpodcast [@] gmail[.]com open.spotify.com/episode/4SDz...
open.spotify.com
Spotify – Web Player
011
CyberRaiju @jaiminton.com · 12/01/2026
Please let me know your thoughts and feelings, and if you have a story to tell get in contact and we'll have a chat to get your story told with a format that has more back and forth 😁 🙏
120
CyberRaiju @jaiminton.com · 12/01/2026
The first episode of a new podcast 'Breach Log' is now available. If you like defensive cyber security stories being told then this may appeal to you. It's available on all good providers, but the RSS and Spotify link are below RSS: rss.com/podcasts/bre... Spotify: open.spotify.com/episode/4WVi...
rss.com
1: The Vampire RAT | Podcast Episode on RSS.com
It's all fun and games until a researcher identifies a backdoor with ransomware capability, global victims, and hacked systems all around the world. Now if only someone would listen.This story comes f...
130
CyberRaiju @jaiminton.com · 10/10/2025
Our new research is now live, and it's full of juicy insights. From a log poisoning vulnerability, to an RMM you've likely never heard of, and a list of victim locations that span the globe! 👀 👇
031
CyberRaiju @jaiminton.com · 16/08/2025
As of Thurs Aug 14th we're seeing clear indications that a threat actor has now weaponised and is exploiting vulnerabilities in Axis camera software (CVE-2025-30023/4/5/6) which was presented at DEFCON. Indicators on Xitter/LinkedIn www.linkedin.com/posts/activi... x.com/CyberRaiju/s...
linkedin.com
Sign Up | LinkedIn
500 million+ members | Manage your professional identity. Build and engage with your professional network. Access knowledge, insights and opportunities.
030
CyberRaiju @jaiminton.com · 24/06/2025
Masquerading as `IO Broker Installer` on disk from the compiled MSI that seems to have artifacts from a SyslogCenter executable previously used by Octowave Loader that was still left in the MSI. PR made to #hijacklibs github.com/wietze/Hijac...
github.com
Create tbb.yml by JPMinty · Pull Request #128 · wietze/HijackLibs
New Octowave variant using this to deliver ACR/Amatera Stealer
010
CyberRaiju @jaiminton.com · 24/06/2025
TBB: www.virustotal.com/gui/file/f5c... APP-2.3: www.virustotal.com/gui/file/b50... ZXING: www.virustotal.com/gui/file/f4c... XCEED: www.virustotal.com/gui/file/118... BLOOD: www.virustotal.com/gui/file/d96...
virustotal.com
VirusTotal
VirusTotal
120
CyberRaiju @jaiminton.com · 24/06/2025
Adobe printer driver sideloads tbb.dll, tbb.dll loads app-2.3.dll which gets stego from blood.wav, uses zxing.presentation.dll and Xceed.Wpf.AvalonDock.Themes.Aero.dll MSI: www.virustotal.com/gui/file/f5c... Components all with 0 VT detections. DLLs are legitimate ones that were modified.
110
CyberRaiju @jaiminton.com · 24/06/2025
New Octowave Loader sample is leading to Amatera Stealer deployment over the past week. 0 VT detections on any component of the malware loader. Proofpoint rules detect the outbound C2 traffic. My Yara rule detects the installer.
264
CyberRaiju @jaiminton.com · 16/05/2025
I've been thinking a lot about recent layoffs, AI advancements, and what it means for this industry as a whole. Hopefully at least some of this resonates with others and hits the mark. www.jaiminton.com/internal-blo...
jaiminton.com
Job Security in Cyber Security is Changing
At what point is your “secure” job at risk?
000
CyberRaiju @jaiminton.com · 10/05/2025
Their latest version 52 fixes the issue, but you need to have 50 installed to install 52, this is not a standalone installer, just an update, and the old versions are still the default download on their website. eu.community.samsung.com/t5/samsung-s...
000
CyberRaiju @jaiminton.com · 09/05/2025
Now in open Beta, simply upload an executable and the DLL it insecurely loads, fill in some extra fields and generate a rule With a code editor and validation, this should make submitting to the project much easier! Link: www.jaiminton.com/tools/hijack... Direct: hijacklibs-assistant.streamlit.app
000
CyberRaiju @jaiminton.com · 09/05/2025
HijackLibs.net details hundreds of publicly disclosed DLL Hijacking opportunities. With over 700 stars on GitHub and a growing list, @wietzebeukema.nl does an amazing job maintaining it. Despite this contributing can be time consuming. That's why I've created HijackLibs Helper!👇
131
CyberRaiju @jaiminton.com · 07/05/2025
We have reached out to Samsung. There is active exploitation in the wild. Be sure to look for new files created in the server directory of your MagicInfo install, and child processes spawning from the Apache Tomcat process.
101
CyberRaiju @jaiminton.com · 07/05/2025
The version offered on their website via the download button is currently not even the latest, so even if it was patched (it isn't, the vulnerable class has not changed at all) anyone downloading the software is getting an outdated version! No updates here: security.samsungtv.com/securityUpda...
101
CyberRaiju @jaiminton.com · 07/05/2025
I've confirmed Samsung's MagicINFO 21.1050 is VULNERABLE to the publicly reported POC in the blog below. ssd-disclosure.com/ssd-advisory... The media is reporting this as CVE-2024-7399, but if it is then the patch is incomplete. There is currently NO PATCH AVAILABLE!
132
CyberRaiju @jaiminton.com · 22/04/2025
The DLLs and everything, currently undetected once again: DLL1: www.virustotal.com/gui/file/888... DLL2: www.virustotal.com/gui/file/ea3... DLL3: www.virustotal.com/gui/file/0c6... Malicious WAV Stego: www.virustotal.com/gui/file/93c...
010
CyberRaiju @jaiminton.com · 22/04/2025
It keeps going, new sample: www.virustotal.com/gui/file/d70... At the time of scanning 1 vendor detected it, still only 3 at the moment. Deploying LummaC2 unsurprisingly. This time a binary signed by 'ONE UP LTD' from the Nuclear Coffee VideoGet application used to load into memory.👇
111
CyberRaiju @jaiminton.com · 22/04/2025
MSI: www.virustotal.com/gui/file/625... DLL1: www.virustotal.com/gui/file/dd9... DLL2: www.virustotal.com/gui/file/ccf... DLL3: www.virustotal.com/gui/file/3d7... DLL4: www.virustotal.com/gui/file/d0f...
010
CyberRaiju @jaiminton.com · 22/04/2025
Likely from a fake Cloudflare challenge. Has 4 malicious DLLs, a Progress.pak supporting file, and shellcode inside of Presentations\Application.wav Deploys LummaC2 into memory which is now using both Telegram channel and Steam Community names for C2 fallback. 👇
110
CyberRaiju @jaiminton.com · 22/04/2025
Another notable Octowave Loader sample with installer MSI showing low VT hits, and malicious DLL's being completely undetected. Sideloads into the legitimate Audacity. Installs itself as 'Directory Converter' in the user LocalAppData 'Programs' directory. 👇
221
CyberRaiju @jaiminton.com · 03/04/2025
New video released 🎉: Once again looking at malware sent over Discord, but this time we can analyse it statically after performing AES decryption. You may also see reference in the video to some stealers which have since shutdown or rebranded 😎 Enjoy! www.youtube.com/watch?v=knu0...
youtube.com
DISCORD "try my game" MALWARE | Reverse Engineering Leet Stealer, Electron Malware Used By HACKERS
YouTube video by Jai Minton - CyberRaiju
011
CyberRaiju @jaiminton.com · 23/03/2025
Are you interested in Generative AI and 💉 Prompt Injection techniques? I've just released a short video exploring the Main Gandalf challenge by Lakera AI and how you can convince 🧙‍♂️ to give you his secrets through specifically crafted prompts. Enjoy! www.youtube.com/watch?v=pQ5K...
youtube.com
Hacking Gandalf AI (LLM) to reveal SECRETS | Basic PROMPT INJECTION techniques
YouTube video by Jai Minton - CyberRaiju
130
CyberRaiju @jaiminton.com · 15/03/2025
Just released 🎉 In classic copycat form, now we have real CAPTCHAs protecting fake installers that use the ClickFix 'WIN + R technique'🤦‍♂️. New video released where I fail a legitimate CAPTCHA multiple times while searching for malware 😂 youtu.be/LrOJBiWOHbE
youtu.be
Forget FAKE CAPTCHAs, I got MALWARE via a REAL CAPTCHA! | I2Parcae Malware Analysis
YouTube video by Jai Minton - CyberRaiju
030
CyberRaiju @jaiminton.com · 04/03/2025
I took a look at a new malware loader which uses steganography within WAV 🌊 files to deliver its payload on an endpoint. Enjoy! www.youtube.com/watch?v=NiNI...
youtube.com
I found MALWARE inside of MUSIC! (Octowave Steganography Malware Analysis)
YouTube video by Jai Minton - CyberRaiju
052
CyberRaiju @jaiminton.com · 27/02/2025
Termite had access to Genea for 2 weeks through their Citrix environment before exfiltrating 900gb+ of patient records to Digital Ocean. This is an org that helps couples have a family. 🤬😡 www.genea.com.au/pages/import... www.genea.com.au/sfsites/c/cm...
030
CyberRaiju @jaiminton.com · 02/02/2025
I frequently get asked is "what skills do I need need to excel as an analyst", so I figure this is a good opportunity to shed some light on what analysis is, and why certifications alone won't make you a good analyst. www.jaiminton.com/high-impact-...
jaiminton.com
HISAC - High Impact Security Analysis and Communication
How to be a well rounded SOC/MDR/Cyber/Information Security Analyst.
084
CyberRaiju @jaiminton.com · 21/01/2025
This is really big at the moment and you should absolutely be looking at your M365 logs to identify this activity. www.speartip.com/fasthttp-use... We're observing a large number of IPs involved after successful authentication, but a common IP is 113.23.43[.]76
speartip.com
fasthttp Used in New Bruteforce Campaign
SpearTip Security Operations Center, together with the SaaS Alerts team, identified an emerging threat involving the fastHTTP library
030
Reposted by CyberRaiju
mthcht @mthcht.bsky.social · 04/01/2025
I made a windows #DFIR artifacts collection MindMap, it's tough to fit everything into a readable overview (might change later)
12312
CyberRaiju @jaiminton.com · 30/12/2024
This threat actor has started using @github.com to host the PowerShell downloaders making it fairly trivial to find accounts hosting a copy of Vidar Stealer. Some have low, and some have high VT hits. www.virustotal.com/gui/file/f9d... www.virustotal.com/gui/file/847...
041
CyberRaiju @jaiminton.com · 24/12/2024
This. Multiple criticals on our end also. If you think ransomware actors weren't sitting on access waiting until Christmas Eve to strike then you're mistaken. Holidays are prime time for ransomware gangs who would love to give you a ransom message for Christmas in the hope 2025 lands them some $$$
020
CyberRaiju @jaiminton.com · 24/12/2024
Sure sex is good, but have you ever stopped an environment from being ransomed on Christmas Eve?
000
CyberRaiju @jaiminton.com · 23/12/2024
👀 The domain saaadnesss[.]shop registered a month ago used to track infected victims in a Fake Captcha /ClickFix/Clearfake campaign is now already being seen as one of the top 1 million domains as a result of being served from compromised websites. urlscan.io/search/#saaa...
153
CyberRaiju @jaiminton.com · 20/12/2024
It's Dec 2024 and there's a new Telerik deserialisation vulnerability. www.cve.org/CVERecord?id... Meanwhile we're still seeing people exploit CVE-2019-18935 from 5 years ago...
media.tenor.com
a white squirrel is making a funny face with the words just why below it
ALT: a white squirrel is making a funny face with the words just why below it
020
CyberRaiju @jaiminton.com · 16/12/2024
I'm so sorry to hear 😔 I just had to put my cat Pepper down yesterday after a snake bite, so I can sympathize. Very sorry for your loss 💔
110
CyberRaiju @jaiminton.com · 12/12/2024
Had some fun with Alden, @laughingmantis.bsky.social, and Tanner digging into the Java implant that was being deployed by the Cleo 0-day. Our analysis is now live! www.huntress.com/blog/cleo-so... TL;DR: Custom malware specifically targeting Cleo software we called Malichus. Enjoy!
huntress.com
Team Huntress has analyzed Cleo's software vulnerability. Take a look at the technical breakdown of a new family of malware we’ve named Malichus.
083
Reposted by CyberRaiju
Jamie Levy 🦉 @gleeda.bsky.social · 10/12/2024
We’ve identified an emerging threat involving Cleo’s LexiCom, VLTransfer, and Harmony software, commonly used to manage file transfers. #dfir #vulnerability www.huntress.com/blog/threat-...
huntress.com
Cleo Software Actively Being Exploited in the Wild | Huntress
Huntress identified an emerging threat involving Cleo’s LexiCom, VLTransfer, and Harmony software, commonly used to manage file transfers. Read more about this emerging threat on the Huntress Blog.
0149
CyberRaiju @jaiminton.com · 08/12/2024
How do you submit a pull request to a malware author?🤔 Celestial Stealer is checking for my name or online handle and it won't execute if it's found, but my RE machine is using the name Barry so this check will fail. Who do I reach out to about this? 😅 www.trellix.com/blogs/resear...
Screenshot showing Celestial Stealer looking for keywords Jai Minton and cyberraiju
030