CyberRaiju @jaiminton.com · 18/09/2026Give me your best captions! So far I have: "I guess the last driver crashed" and... "10 minutes into nmap and chill, and she gives you this look" 000
CyberRaiju @jaiminton.com · 27/05/2026Threat actors are impersonating real recruiters and sending bulk, tailored phishing emails by using ChatGPT, your public LinkedIn profiles, and a tool known as blinq. More details: www.jaiminton.com/internal-blo...jaiminton.comFake Recruiter Phishing Through AI and LinkedInThreat actors are posing as fake tech recruiters to steal information and scam you out of money 010
CyberRaiju @jaiminton.com · 08/04/2026Episode 4 of Breach Log is now out! In this episode I'm joined by Cameron Cottam who tells his story about responding to a critical alert at 2am. Enjoy. Spotify: open.spotify.com/episode/26Lr... Other Providers: creators.spotify.com/pod/profile/...open.spotify.comEp4: Think Twice Before You Fix It with Cameron 010
CyberRaiju @jaiminton.com · 06/03/2026Episode 3 of Breach Log is now available! Whether you're heading into the weekend or beginning your Friday, I hope you can carve out a mere 20 minutes to enjoy another story from the vault of detecting and responding to hacks around the world. open.spotify.com/episode/7MY3...open.spotify.comEp3: Care to Exchange 0-days? 000
CyberRaiju @jaiminton.com · 18/02/2026If you've worked in Detection Engineering, Threat Hunting, Incident Response, or an adjacent field, or have been impacted by a breach and have a story to tell, get in contact I'd love to hear it and have you on the podcast. Details on the about page. creators.spotify.com/pod/profile/...creators.spotify.comBreach Log - Behind every hack is a story to tell • A podcast on Spotify for CreatorsBreaches happen every single day, and behind every breach is a story. These are the stories from those involved. It's the stories of those who found, or responded to a breach, or even those who were i... 000
CyberRaiju @jaiminton.com · 08/02/2026Episode 2 of Breach Log is now available! Special thanks to Max Margolis for joining me and telling his story. If you have a story you'd like to share, get in contact and we can have some fun! breachlogpodcast [@] gmail[.]com open.spotify.com/episode/4SDz...open.spotify.comSpotify – Web Player 011
CyberRaiju @jaiminton.com · 12/01/2026Please let me know your thoughts and feelings, and if you have a story to tell get in contact and we'll have a chat to get your story told with a format that has more back and forth 😁 🙏 120
CyberRaiju @jaiminton.com · 12/01/2026The first episode of a new podcast 'Breach Log' is now available. If you like defensive cyber security stories being told then this may appeal to you. It's available on all good providers, but the RSS and Spotify link are below RSS: rss.com/podcasts/bre... Spotify: open.spotify.com/episode/4WVi...rss.com1: The Vampire RAT | Podcast Episode on RSS.comIt's all fun and games until a researcher identifies a backdoor with ransomware capability, global victims, and hacked systems all around the world. Now if only someone would listen.This story comes f... 130
CyberRaiju @jaiminton.com · 10/10/2025Our new research is now live, and it's full of juicy insights. From a log poisoning vulnerability, to an RMM you've likely never heard of, and a list of victim locations that span the globe! 👀 👇 031
CyberRaiju @jaiminton.com · 16/08/2025As of Thurs Aug 14th we're seeing clear indications that a threat actor has now weaponised and is exploiting vulnerabilities in Axis camera software (CVE-2025-30023/4/5/6) which was presented at DEFCON. Indicators on Xitter/LinkedIn www.linkedin.com/posts/activi... x.com/CyberRaiju/s...linkedin.comSign Up | LinkedIn500 million+ members | Manage your professional identity. Build and engage with your professional network. Access knowledge, insights and opportunities. 030
CyberRaiju @jaiminton.com · 24/06/2025Masquerading as `IO Broker Installer` on disk from the compiled MSI that seems to have artifacts from a SyslogCenter executable previously used by Octowave Loader that was still left in the MSI. PR made to #hijacklibs github.com/wietze/Hijac...github.comCreate tbb.yml by JPMinty · Pull Request #128 · wietze/HijackLibsNew Octowave variant using this to deliver ACR/Amatera Stealer 010
CyberRaiju @jaiminton.com · 24/06/2025TBB: www.virustotal.com/gui/file/f5c... APP-2.3: www.virustotal.com/gui/file/b50... ZXING: www.virustotal.com/gui/file/f4c... XCEED: www.virustotal.com/gui/file/118... BLOOD: www.virustotal.com/gui/file/d96...virustotal.comVirusTotalVirusTotal 120
CyberRaiju @jaiminton.com · 24/06/2025Adobe printer driver sideloads tbb.dll, tbb.dll loads app-2.3.dll which gets stego from blood.wav, uses zxing.presentation.dll and Xceed.Wpf.AvalonDock.Themes.Aero.dll MSI: www.virustotal.com/gui/file/f5c... Components all with 0 VT detections. DLLs are legitimate ones that were modified. 110
CyberRaiju @jaiminton.com · 24/06/2025New Octowave Loader sample is leading to Amatera Stealer deployment over the past week. 0 VT detections on any component of the malware loader. Proofpoint rules detect the outbound C2 traffic. My Yara rule detects the installer. 264
CyberRaiju @jaiminton.com · 16/05/2025I've been thinking a lot about recent layoffs, AI advancements, and what it means for this industry as a whole. Hopefully at least some of this resonates with others and hits the mark. www.jaiminton.com/internal-blo...jaiminton.comJob Security in Cyber Security is ChangingAt what point is your “secure” job at risk? 000
CyberRaiju @jaiminton.com · 10/05/2025Their latest version 52 fixes the issue, but you need to have 50 installed to install 52, this is not a standalone installer, just an update, and the old versions are still the default download on their website. eu.community.samsung.com/t5/samsung-s... 000
CyberRaiju @jaiminton.com · 09/05/2025Now in open Beta, simply upload an executable and the DLL it insecurely loads, fill in some extra fields and generate a rule With a code editor and validation, this should make submitting to the project much easier! Link: www.jaiminton.com/tools/hijack... Direct: hijacklibs-assistant.streamlit.app 000
CyberRaiju @jaiminton.com · 09/05/2025HijackLibs.net details hundreds of publicly disclosed DLL Hijacking opportunities. With over 700 stars on GitHub and a growing list, @wietzebeukema.nl does an amazing job maintaining it. Despite this contributing can be time consuming. That's why I've created HijackLibs Helper!👇 131
CyberRaiju @jaiminton.com · 07/05/2025We have reached out to Samsung. There is active exploitation in the wild. Be sure to look for new files created in the server directory of your MagicInfo install, and child processes spawning from the Apache Tomcat process. 101
CyberRaiju @jaiminton.com · 07/05/2025The version offered on their website via the download button is currently not even the latest, so even if it was patched (it isn't, the vulnerable class has not changed at all) anyone downloading the software is getting an outdated version! No updates here: security.samsungtv.com/securityUpda... 101
CyberRaiju @jaiminton.com · 07/05/2025I've confirmed Samsung's MagicINFO 21.1050 is VULNERABLE to the publicly reported POC in the blog below. ssd-disclosure.com/ssd-advisory... The media is reporting this as CVE-2024-7399, but if it is then the patch is incomplete. There is currently NO PATCH AVAILABLE! 132
CyberRaiju @jaiminton.com · 22/04/2025The DLLs and everything, currently undetected once again: DLL1: www.virustotal.com/gui/file/888... DLL2: www.virustotal.com/gui/file/ea3... DLL3: www.virustotal.com/gui/file/0c6... Malicious WAV Stego: www.virustotal.com/gui/file/93c... 010
CyberRaiju @jaiminton.com · 22/04/2025It keeps going, new sample: www.virustotal.com/gui/file/d70... At the time of scanning 1 vendor detected it, still only 3 at the moment. Deploying LummaC2 unsurprisingly. This time a binary signed by 'ONE UP LTD' from the Nuclear Coffee VideoGet application used to load into memory.👇 111
CyberRaiju @jaiminton.com · 22/04/2025MSI: www.virustotal.com/gui/file/625... DLL1: www.virustotal.com/gui/file/dd9... DLL2: www.virustotal.com/gui/file/ccf... DLL3: www.virustotal.com/gui/file/3d7... DLL4: www.virustotal.com/gui/file/d0f... 010
CyberRaiju @jaiminton.com · 22/04/2025Likely from a fake Cloudflare challenge. Has 4 malicious DLLs, a Progress.pak supporting file, and shellcode inside of Presentations\Application.wav Deploys LummaC2 into memory which is now using both Telegram channel and Steam Community names for C2 fallback. 👇 110
CyberRaiju @jaiminton.com · 22/04/2025Another notable Octowave Loader sample with installer MSI showing low VT hits, and malicious DLL's being completely undetected. Sideloads into the legitimate Audacity. Installs itself as 'Directory Converter' in the user LocalAppData 'Programs' directory. 👇 221
CyberRaiju @jaiminton.com · 03/04/2025New video released 🎉: Once again looking at malware sent over Discord, but this time we can analyse it statically after performing AES decryption. You may also see reference in the video to some stealers which have since shutdown or rebranded 😎 Enjoy! www.youtube.com/watch?v=knu0...youtube.comDISCORD "try my game" MALWARE | Reverse Engineering Leet Stealer, Electron Malware Used By HACKERSYouTube video by Jai Minton - CyberRaiju 011
CyberRaiju @jaiminton.com · 23/03/2025Are you interested in Generative AI and 💉 Prompt Injection techniques? I've just released a short video exploring the Main Gandalf challenge by Lakera AI and how you can convince 🧙♂️ to give you his secrets through specifically crafted prompts. Enjoy! www.youtube.com/watch?v=pQ5K...youtube.comHacking Gandalf AI (LLM) to reveal SECRETS | Basic PROMPT INJECTION techniquesYouTube video by Jai Minton - CyberRaiju 130
CyberRaiju @jaiminton.com · 15/03/2025Just released 🎉 In classic copycat form, now we have real CAPTCHAs protecting fake installers that use the ClickFix 'WIN + R technique'🤦♂️. New video released where I fail a legitimate CAPTCHA multiple times while searching for malware 😂 youtu.be/LrOJBiWOHbEyoutu.beForget FAKE CAPTCHAs, I got MALWARE via a REAL CAPTCHA! | I2Parcae Malware AnalysisYouTube video by Jai Minton - CyberRaiju 030
CyberRaiju @jaiminton.com · 04/03/2025I took a look at a new malware loader which uses steganography within WAV 🌊 files to deliver its payload on an endpoint. Enjoy! www.youtube.com/watch?v=NiNI...youtube.comI found MALWARE inside of MUSIC! (Octowave Steganography Malware Analysis)YouTube video by Jai Minton - CyberRaiju 052
CyberRaiju @jaiminton.com · 27/02/2025Termite had access to Genea for 2 weeks through their Citrix environment before exfiltrating 900gb+ of patient records to Digital Ocean. This is an org that helps couples have a family. 🤬😡 www.genea.com.au/pages/import... www.genea.com.au/sfsites/c/cm... 030
CyberRaiju @jaiminton.com · 02/02/2025I frequently get asked is "what skills do I need need to excel as an analyst", so I figure this is a good opportunity to shed some light on what analysis is, and why certifications alone won't make you a good analyst. www.jaiminton.com/high-impact-...jaiminton.comHISAC - High Impact Security Analysis and CommunicationHow to be a well rounded SOC/MDR/Cyber/Information Security Analyst. 084
CyberRaiju @jaiminton.com · 21/01/2025This is really big at the moment and you should absolutely be looking at your M365 logs to identify this activity. www.speartip.com/fasthttp-use... We're observing a large number of IPs involved after successful authentication, but a common IP is 113.23.43[.]76speartip.comfasthttp Used in New Bruteforce CampaignSpearTip Security Operations Center, together with the SaaS Alerts team, identified an emerging threat involving the fastHTTP library 030
Reposted by CyberRaijumthcht @mthcht.bsky.social · 04/01/2025I made a windows #DFIR artifacts collection MindMap, it's tough to fit everything into a readable overview (might change later) 12312
CyberRaiju @jaiminton.com · 30/12/2024This threat actor has started using @github.com to host the PowerShell downloaders making it fairly trivial to find accounts hosting a copy of Vidar Stealer. Some have low, and some have high VT hits. www.virustotal.com/gui/file/f9d... www.virustotal.com/gui/file/847... 041
CyberRaiju @jaiminton.com · 24/12/2024This. Multiple criticals on our end also. If you think ransomware actors weren't sitting on access waiting until Christmas Eve to strike then you're mistaken. Holidays are prime time for ransomware gangs who would love to give you a ransom message for Christmas in the hope 2025 lands them some $$$ 020
CyberRaiju @jaiminton.com · 24/12/2024Sure sex is good, but have you ever stopped an environment from being ransomed on Christmas Eve? 000
CyberRaiju @jaiminton.com · 23/12/2024👀 The domain saaadnesss[.]shop registered a month ago used to track infected victims in a Fake Captcha /ClickFix/Clearfake campaign is now already being seen as one of the top 1 million domains as a result of being served from compromised websites. urlscan.io/search/#saaa... 153
CyberRaiju @jaiminton.com · 20/12/2024It's Dec 2024 and there's a new Telerik deserialisation vulnerability. www.cve.org/CVERecord?id... Meanwhile we're still seeing people exploit CVE-2019-18935 from 5 years ago...media.tenor.coma white squirrel is making a funny face with the words just why below itALT: a white squirrel is making a funny face with the words just why below it 020
CyberRaiju @jaiminton.com · 16/12/2024I'm so sorry to hear 😔 I just had to put my cat Pepper down yesterday after a snake bite, so I can sympathize. Very sorry for your loss 💔 110
CyberRaiju @jaiminton.com · 12/12/2024Had some fun with Alden, @laughingmantis.bsky.social, and Tanner digging into the Java implant that was being deployed by the Cleo 0-day. Our analysis is now live! www.huntress.com/blog/cleo-so... TL;DR: Custom malware specifically targeting Cleo software we called Malichus. Enjoy!huntress.comTeam Huntress has analyzed Cleo's software vulnerability. Take a look at the technical breakdown of a new family of malware we’ve named Malichus. 083
Reposted by CyberRaijuJamie Levy 🦉 @gleeda.bsky.social · 10/12/2024We’ve identified an emerging threat involving Cleo’s LexiCom, VLTransfer, and Harmony software, commonly used to manage file transfers. #dfir #vulnerability www.huntress.com/blog/threat-...huntress.comCleo Software Actively Being Exploited in the Wild | HuntressHuntress identified an emerging threat involving Cleo’s LexiCom, VLTransfer, and Harmony software, commonly used to manage file transfers. Read more about this emerging threat on the Huntress Blog. 0149
CyberRaiju @jaiminton.com · 08/12/2024How do you submit a pull request to a malware author?🤔 Celestial Stealer is checking for my name or online handle and it won't execute if it's found, but my RE machine is using the name Barry so this check will fail. Who do I reach out to about this? 😅 www.trellix.com/blogs/resear... 030