Sign in

malmoeb.bsky.social

@malmoeb.bsky.social
701 followers 1K following 621 posts

Head of Investigations at InfoGuard AG - dfir.ch

PostsRepliesMedia
malmoeb.bsky.social @malmoeb.bsky.social · 03/10/2026
[1] blog.talosintelligence.com/uat-10147-de...
blog.talosintelligence.com
UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities
The newly identified SPECTRE implant represents an evolution in commodity intrusion tooling, integrating cross-platform C2 operations, process injection, credential theft, anti-analysis protections, a...
000
malmoeb.bsky.social @malmoeb.bsky.social · 03/10/2026
The rootkit is using insmod to load the malicious module, and the module itself resides on disk. Plus, after loading, you face various rootkit detection techniques. Loading it before any EDR / security tooling might be the easier part of the whole "stealth" journey.
100
malmoeb.bsky.social @malmoeb.bsky.social · 03/10/2026
But "before any security tooling" is too absolute IMO. In the analyzed unit (see blog post from TALOS), the rootkit is explicitly stating "After=systemd-modules-load.service", so kernel modules loaded through the normal early boot path may already be resident.
100
malmoeb.bsky.social @malmoeb.bsky.social · 03/10/2026
if an EDR only attaches its eBPF programs, kprobes, tracepoints, or other telemetry after its userspace service starts, the rootkit may already have loaded and established its hooks by then.
100
malmoeb.bsky.social @malmoeb.bsky.social · 03/10/2026
With DefaultDependencies=no and Before=sysinit[.]target, the malicious systemd unit is deliberately moved into very early userspace initialization. That can matter from a detection perspective:
100
malmoeb.bsky.social @malmoeb.bsky.social · 03/10/2026
“Crucially, this service is configured with Before=sysinit[].target, ensuring the rootkit executes on every system boot prior to the initialization of any security tooling.” [1] This is an interesting approach, but it may be worded too generically.
100
malmoeb.bsky.social @malmoeb.bsky.social · 01/10/2026
I published a short field note about TrickDump, and how we encountered this technique in a recent engagement: dfir.ch/posts/field_...
dfir.ch
Field Notes: Reconstructing the Attacker's LSASS Dump | dfir.ch
Technical blog by Stephan Berger (@malmoeb)
031
malmoeb.bsky.social @malmoeb.bsky.social · 30/09/2026
My colleague Matt Green published velociraptor-skills, a set of reusable AI skills for DFIR with Velociraptor. Read the full blog post here: labs.infoguard.ch/posts/ai_ate...
labs.infoguard.ch
AI Ate My Velociraptor - InfoGuard Labs
Introducing velociraptor-skills, a set of reusable AI skills for DFIR with Velociraptor.
111
malmoeb.bsky.social @malmoeb.bsky.social · 27/09/2026
there have likely been plenty of opportunities to detect them before the ransom wallpaper appears. Not detecting the ransomware binary isn't the same as not detecting the attack. 🙂 securelist.com/tr/payload-r...
securelist.com
PAYLOAD ransomware attacks through Active Directory GPO
Kaspersky GERT experts dive into the technical incident analysis of PAYLOAD ransomware: an encryptionless, binary-less operation that abused Active Directory mechanisms for managing Group Policy Objec...
020
malmoeb.bsky.social @malmoeb.bsky.social · 27/09/2026
But there is something amusing about framing “traditional ransomware detection wouldn’t catch this” as the big defensive challenge. By the time an attacker has domain-admin-equivalent privileges, can create and link GPOs at the domain root, turn off the firewall domain-wide, and exfiltrate data,
securelist.com
PAYLOAD ransomware attacks through Active Directory GPO
Kaspersky GERT experts dive into the technical incident analysis of PAYLOAD ransomware: an encryptionless, binary-less operation that abused Active Directory mechanisms for managing Group Policy Objec...
111
malmoeb.bsky.social @malmoeb.bsky.social · 27/09/2026
This GPO-based “ransomware without ransomware” technique is pretty cool: abuse trusted Group Policy to deliver the impact, without ever dropping an encryptor on Windows endpoints.
100
malmoeb.bsky.social @malmoeb.bsky.social · 27/09/2026
icloud[.]com is already listed by the Living Off Trusted Sites (LOTS) Project for malicious downloads and exfiltration, but not, as far as I can see, for this particular technique. Definitely something to watch for. Source: securelist.com/macsync-new-...
securelist.com
A new version of the MacSync macOS stealer targets crypto enthusiasts and developers
We look at a new version of the MacSync macOS stealer with a backdoor module that targets crypto enthusiasts and developers.
000
malmoeb.bsky.social @malmoeb.bsky.social · 27/09/2026
Those commands then download the next stage, again from iCloud. So, effectively, a public iCloud Calendar is being used as a trusted-hosted shell-script carrier.
100
malmoeb.bsky.social @malmoeb.bsky.social · 27/09/2026
Most of the iCalendar content is obviously not valid shell syntax, so zsh simply produces errors as it works through it. Eventually, however, it reaches attacker-controlled shell commands embedded after the DESCRIPTION: field, and executes them.
100
malmoeb.bsky.social @malmoeb.bsky.social · 27/09/2026
MacSync's iCloud Calendar trick is pretty cool. One MacSync downloader analyzed by Securelist contains a URL such as: caldav.icloud[.]com/published... It retrieves a public .ics calendar, creates an anonymous pipe, launches zsh -s, sets the pipe as stdin, and feeds it into it line by line.
100
malmoeb.bsky.social @malmoeb.bsky.social · 24/09/2026
For the love of the (macOS) game. My new blog post covers a macOS DFIR blind spot: zsh startup files such as .zshrc, .zprofile, and .zshenv can have compiled .zwc counterparts. The full blog post here: dfir.ch/posts/compil...
110
malmoeb.bsky.social @malmoeb.bsky.social · 22/09/2026
I think monitoring for AV alerts (and exclusions!) could go a long way. The basics make the difference. ☝️ [1] github.com/nikaiw/VMkatz
000
malmoeb.bsky.social @malmoeb.bsky.social · 22/09/2026
Set-MpPreference -DisableRealtimeMonitoring $true Add-MpPreference -ExclusionPath "C:\" And then pointing it to a directory, "and let it find everything", as pointed out in the documentation. ./vmkatz.exe C:\ClusterStorage\CSV01\node-002\
100
malmoeb.bsky.social @malmoeb.bsky.social · 22/09/2026
Defender detected it with the following signature: VirTool:Win64/Vekesz.A The out-of-the-box release from GitHub is also heavily flagged, but one could compile (and obfuscate) the code to stay under the radar. In our case, the attacker just disabled real-time monitoring and added an exclusion:
100
malmoeb.bsky.social @malmoeb.bsky.social · 22/09/2026
On a recent Incident response case, we encountered VMkatz. "It extracts Windows secrets - NTLM hashes, DPAPI master keys, Kerberos tickets, cached domain credentials, LSA secrets, NTDS.dit, BitLocker keys - directly from VM memory snapshots and virtual disks, on the NAS, the hypervisor.." [1]
github.com
GitHub - nikaiw/VMkatz: Extract Windows credentials directly from VM memory snapshots and virtual disks
Extract Windows credentials directly from VM memory snapshots and virtual disks - nikaiw/VMkatz
111
malmoeb.bsky.social @malmoeb.bsky.social · 16/09/2026
New blog post: Living Inside the Shell: zsh Modules on macOS zsh is much more than a command interpreter. Through its module system, the shell can perform operations that defenders often associate with separate binaries dfir.ch/posts/zsh_mo...
010
malmoeb.bsky.social @malmoeb.bsky.social · 14/09/2026
Microsoft recommends the following mitigations to reduce the impact of this threat: Block web pages from automatically running Flash plugins. 😂 Source: microsoft.com/en-us/securi...
000
malmoeb.bsky.social @malmoeb.bsky.social · 14/09/2026
My new "field note" shows how a seemingly generic Microsoft Defender alert can lead to a much more useful forensic finding when correlated with filesystem artifacts. Full article here: dfir.ch/posts/field_...
022
malmoeb.bsky.social @malmoeb.bsky.social · 11/09/2026
Someone at BSides Frankfurt asked me this week if I could share the slides from my talk. Of course - and not just those. 🙂 All my conference presentations are available here: github.com/malmoeb/pres...
031
malmoeb.bsky.social @malmoeb.bsky.social · 11/09/2026
If you're at BSides Tallinn, come join our anti-forensics workshop. I'm offering a 4-hour hands-on training session packed with lessons from years of incident-response work. Techniques you can apply directly in your own investigations.
020
malmoeb.bsky.social @malmoeb.bsky.social · 07/09/2026
After a fantastic first session at BruCON Spring Training earlier this year, we’re very happy to teach our Anti-Forensics course again - this time at DeepSec in Vienna. Really looking forward to teaching this one again - and to a full classroom! :) More information here: deepsec.net/schedule.html
010
malmoeb.bsky.social @malmoeb.bsky.social · 23/08/2026
Definitely something to look out for. [1] www.huntress.com/blog/defcon-...
huntress.com
Post-DEF CON Phishing Uses Malicious Google Doc to Deliver Malware | Huntress
Huntress researcher uncovers post-Black Hat & DEF CON phishing campaign using X DMs & malicious documents to deliver AMOS, NetSupport RAT, and other malware.
000
malmoeb.bsky.social @malmoeb.bsky.social · 23/08/2026
What’s particularly interesting about this vector is that the victim remains entirely on docs.google.com throughout the process. This makes the process appear significantly more trustworthy than a classic phishing page on a third-party domain.
docs.google.com
Sign in - Google Accounts
100
malmoeb.bsky.social @malmoeb.bsky.social · 23/08/2026
After entering the supposedly correct key, the Apps Script interface displayed a fake error message and then offered repair/update steps (your classic Click Fix steps).
100
malmoeb.bsky.social @malmoeb.bsky.social · 23/08/2026
This sidebar mimicked a “Document Decryption” feature and awaited an “Access Key” sent separately by the attacker. The decryption was designed to fail intentionally.
100
malmoeb.bsky.social @malmoeb.bsky.social · 23/08/2026
The attacker sent the victim a legitimate Google Docs link that appeared to be a partially encrypted conference/planning document. Embedded in the document was a Google Apps Script that displayed its own HTML sidebar (DecryptPanel.html).
100
malmoeb.bsky.social @malmoeb.bsky.social · 23/08/2026
After a bit of tinkering, I was able to replicate the Google Docs attack vector described in the Huntress blog post [1] Attackers can use Google’s “App Scripts” feature (in Docs) to create a clever pretext. Essentially, the attack works as follows:
130
malmoeb.bsky.social @malmoeb.bsky.social · 30/06/2026
And here is the second part of the Cleartext Password Series: dfir.ch/posts/fantas...
dfir.ch
Fantastic clear-text passwords and where to collect them (Part 2 - Windows) | dfir.ch
Technical blog by Stephan Berger (@malmoeb)
001
malmoeb.bsky.social @malmoeb.bsky.social · 23/06/2026
[1] isc.sans.edu/diary/From+a... [2] dfir.ch/posts/n-iocs/
isc.sans.edu
From a VHDX File to a Remcos RAT - SANS Internet Storm Center
From a VHDX File to a Remcos RAT, Author: Xavier Mertens
000
malmoeb.bsky.social @malmoeb.bsky.social · 23/06/2026
PowerShell, AppData, Dynamic DNS, and Run Key as a persistence mechanism. Four of the eight areas I covered in my first blog post, N-IOCs to Rule Them All [2]. The information presented remains relevant, and finding such infections is not that hard, even if they might bypass AV rules and signatures.
100
malmoeb.bsky.social @malmoeb.bsky.social · 23/06/2026
In a recent ISC SANS Diary, Xavier Mertens 🇧🇪 discussed a malicious ZIP archive that led to Remcos, a pretty common RAT. As Xavier noted, "Most of the files used in this infection path remain undetected by most AVs." [1]
100
malmoeb.bsky.social @malmoeb.bsky.social · 22/06/2026
Even if these techniques are not novel, I still consider them interesting enough to publish and, most importantly, to raise awareness of all the places an attacker could steal your password. Enjoy.
dfir.ch
Fantastic clear-text passwords and where to collect them (Part 1 - Linux) | dfir.ch
Technical blog by Stephan Berger (@malmoeb)
010
malmoeb.bsky.social @malmoeb.bsky.social · 22/06/2026
I created two blog posts based on my Fantastic Cleartext Passwords talk, which I presented last year at BSides Munich, and I released the first part (Linux) today. The second part (Windows) will be released next week.
dfir.ch
Fantastic clear-text passwords and where to collect them (Part 1 - Linux) | dfir.ch
Technical blog by Stephan Berger (@malmoeb)
142
malmoeb.bsky.social @malmoeb.bsky.social · 17/06/2026
Elastic has had a detection rule since December 2020 [2]. Would your detection stack catch it? [1] labs.infoguard.ch/posts/bravox... [2] github.com/elastic/dete...
010
malmoeb.bsky.social @malmoeb.bsky.social · 17/06/2026
A memory dump of the lsass.exe process (lsass.dmp) was created on a server, hardly a subtle move, but when there is no one watching, there is no judge. [1] I checked our case data, and this is more common than one might assume 🫣.
100
malmoeb.bsky.social @malmoeb.bsky.social · 17/06/2026
Dumping LSASS to a file named lsass.dmp is not exactly stealthy tradecraft anymore. However, I was reading the analysis of the BravoX ransomware group from my colleague Florian Scheiber, and he writes:
100
malmoeb.bsky.social @malmoeb.bsky.social · 16/06/2026
We recently analyzed an interesting piece of malware that utilizes the legitimate JavaScript runtime, Deno. The malware was used as a first-stage implant after the user was tricked into downloading and running the malware. Read the full article here: labs.infoguard.ch/posts/anatom...
labs.infoguard.ch
Anatomy of a Deno-Based Proxy & RAT - InfoGuard Labs
Analysis of a Deno-based malware intrusion that began with mailbombing and a fake Microsoft Teams IT-support call, leading a victim to execute a malicious archive. The payload is a modular JavaScript ...
000
malmoeb.bsky.social @malmoeb.bsky.social · 04/06/2026
The customer was lucky the upload directory wasn't directly reachable from the internet; otherwise, it would have been an RCE in under a minute. Is monitoring for leaked credentials and secrets part of your security posture?
000
malmoeb.bsky.social @malmoeb.bsky.social · 04/06/2026
One set worked. Upon logging in, they discovered dozens of webshells! Someone had clearly found these leaked credentials before we did and tried to exploit the server. The first sign of exploitation dates back to 2024, although the credentials had already leaked in 2022.
100
malmoeb.bsky.social @malmoeb.bsky.social · 04/06/2026
One of our pentesters was tasked with assessing a customer's perimeter and found an exposed FTP server. They queried the server's FQDN on a specialized service and (surprisingly?) found leaked login credentials.
100
malmoeb.bsky.social @malmoeb.bsky.social · 02/06/2026
This is purely speculative; I haven't tested it out in a lab. However, isn't it super interesting how many places you can find artifacts that could help you solve your case? That's why I love digital forensics so much :)
010
malmoeb.bsky.social @malmoeb.bsky.social · 02/06/2026
3) If a task successfully migrates, it is placed back into the active \Tasks folder and properly linked in the TaskCache registry hive. 4) The Tasks_Migrated folder is left behind. It effectively becomes a graveyard of scheduled tasks as they existed at the exact moment the upgrade was initiated.
100
malmoeb.bsky.social @malmoeb.bsky.social · 02/06/2026
I guess the upgrade process goes something like this: 1) The migration engine duplicates the contents of the live \Tasks folder into \Tasks_Migrated. 2) The engine then attempts to register and import these tasks into the new operating system environment.
100
malmoeb.bsky.social @malmoeb.bsky.social · 02/06/2026
Its primary purpose is to safely back up existing Windows Task Scheduler jobs before the OS modifies the system state, ensuring that user-defined and third-party software tasks are not permanently lost if the migration fails or the tasks become incompatible with the new build.
100
malmoeb.bsky.social @malmoeb.bsky.social · 02/06/2026
Instead, it is created automatically by the Windows upgrade engine (Setup/Migration routines) during a major OS upgrade, such as moving from Windows 10 to Windows 11, or applying a major Windows Feature Update.
100