Sign in

alden

@re.wtf
724 followers 412 following 13 posts

malware enjoyer • macOS security alden.io

PostsRepliesMedia
Reposted by alden
Kenneth Kinion @kennethkinion.bsky.social · 20/06/2025
Hot on the heels of the researched published by @huntress.com, hunting for Zoom-themed lures from DPRK's #BlueNoroff 💥Learn hunting techniques 💥Leverage new Validin features and data 💥Full, unredacted indicator list (domains, IPs, hashes) www.validin.com/blog/zooming...
validin.com
Zooming through BlueNoroff Indicators with Validin | Validin
Pivoting through recently-reported indicators to find BlueNoroff-associated domains
122
alden @re.wtf · 18/06/2025
LMFAO woah woah it's good by comparison! 😭 we take what we can get in macOS land
000
alden @re.wtf · 18/06/2025
excited bc today @huntress.com is releasing our analysis of a gnarly intrusion into a web3 company by the DPRK's BlueNoroff!! 🤠 we've observed 8 new pieces of macOS malware from implants to infostealers! and they're actually good (for once)! www.huntress.com/blog/inside-...
huntress.com
Inside the BlueNoroff Web3 macOS Intrusion Analysis | Huntress
Learn how DPRK's BlueNoroff group executed a Web3 macOS intrusion. Explore the attack chain, malware, and techniques in our detailed technical report.
13019
alden @re.wtf · 15/04/2025
finally got around to rewriting the copy as yara binja plugin! 🥰 has a few quality of life improvements (new formats) and address wildcarding is fixed for ARM! (sorry bout that mac homies) ❤️ it's also now available in the plugin repository! 🔥 github.com/ald3ns/copy-...
072
Reposted by alden
Jamie Levy 🦉 @gleeda.bsky.social · 08/04/2025
CVE-2025-2825 or CVE-2025-31161: A vulnerability by any other name is still a threat 😇: We've updated the blog to reflect some new attacker tradecraft observed yesterday cc @huntress.com @re.wtf @johnhammond.bsky.social #DFIR #vuln #CVE www.huntress.com/blog/crushft...
huntress.com
CrushFTP CVE-2025-31161 Auth Bypass and Post-Exploitation | Huntress
Huntress observed in-the-wild exploitation of CVE-2025-31161, an authentication bypass vulnerability in versions of CrushFTP and further post-exploitation leveraging MeshCentral and other malware.
031
alden @re.wtf · 04/04/2025
pwning my FTP server is a weird way to say you have a Crush on me but okay 🥰 anyways check out our analysis of some CrushFTP CVE-2025-31161 post exploitation activity! www.huntress.com/blog/crushft...
t.co
https://www.huntress.com/blog/crushftp-cve-2025-31161-auth-bypass-and-post-exploitation
063
Reposted by alden
Selena Larson @selenalarson.bsky.social · 11/03/2025
Published some new research on how RMMs are taking over as a first-stage payload www.proofpoint.com/us/blog/thre...
proofpoint.com
Remote Monitoring and Management (RMM) Tooling Increasingly an Attacker’s First Choice | Proofpoint US
Key findings    More threat actors are using legitimate remote monitoring and management (RMM) tools as a first-stage payload in email campaigns.  RMMs can be used for
03416
Reposted by alden
Jacob Latonis @jacoblatonis.me · 08/03/2025
nightmare blunt rotation
a screenshot of the "Languages" section of a GitHub repo, showing 58.8% C, 28.6% JavaScript, and 12.6% Python
2368
alden @re.wtf · 14/02/2025
BREAKING: DOGE has uncovered that the CIA spent $10,000,000 on zyns and has been feeding them to analysts to increase productivity! 😱
Cool mint zyn containers that are CIA branded
070
Reposted by alden
cabal @cabal.cx · 14/01/2025
our network has raised hundreds of dollars to give firefighters the zyn they need to keep protecting LA from the fires. Thank you!!
1188
alden @re.wtf · 09/01/2025
🫶
010
alden @re.wtf · 09/01/2025
reminder to say happy new years to the russian espionage groups in ur network 🥰🇷🇺 @nosecurething.bsky.social, @laughingmantis.bsky.social, and I just dropped a new blog detailing a series of redcurl intrusions across several huntress customer environments 😳 www.huntress.com/blog/the-hun...
huntress.com
Hunt for RedCurl | Huntress
Huntress discovered RedCurl activity across several organizations in Canada going back to 2023. Learn more about how this APT operates and how they aim to remain undetected while exfiltrating sensitiv...
1174
Reposted by alden
Greg Lesnewich @greg-l.bsky.social · 01/01/2025
#100DaysofYARA day 1 - the Amos stealer is regularly evolving and updating its obfuscation techniques You know what isn't changing? the dylibs it depends on and the entitlements it requests from the OS. Combined, they give us excellent signal github.com/100DaysofYAR...
2165
Reposted by alden
Sean @whatthefuzzvr.bsky.social · 27/12/2024
Binary diff'ing is hard. But it's super powerful to apply markup from previous reverse engineering efforts to a new binary. Binary Ninja is switching up how they match function signatures with WARP. www.seandeaton.com/binary-ninja... #binaryninja #reverseengineering #ghidra #ida #decompiler
seandeaton.com
Trying Out Binary Ninja's new WARP Signatures with IPSW Diff'ing
Binary diff'ing is pretty complex, but being able to apply markup from one binary to another is quite powerful. Binary Ninja's new WARP extends previous efforts, using SigKit, to quickly identify libr...
0256
alden @re.wtf · 21/12/2024
i gotta step up my whitepaper game smh, my dad is doin numbers
0130
Reposted by alden
Stuart Ashenbrenner @stuartjash.bsky.social · 18/12/2024
Our talk from @objective-see.bsky.social is now available online. Check out @re.wtf and I yap about macOS infostealers. www.youtube.com/watch?v=Hv6A...
youtube.com
#OBTS v7.0: "Stealer Crossing: New Horizons" - Alden Schmidt & Stuart Ashenbrenner
YouTube video by Objective-See Foundation
1104
Reposted by alden
Greg Lesnewich @greg-l.bsky.social · 12/12/2024
since I'm cold and missing #OBTS I wanted to reflect on what @jacoblatonis.me and Tomas have gifted us with the YARA-X Macho module the OG YARA macho parsing left a lot to be desired, and the new YARA-X ver has all sorts of goodies
2188
Reposted by alden
aaron @aaron.cat.gf · 13/12/2024
this holiday season
0168
alden @re.wtf · 12/12/2024
following the recent cleo ITW exploitation, @huntress.com has released our analysis of the full post exploitation chain 🚀 the final java based implant framework is really neat and includes a custom C2 protocol 🔥 huntress.com/blog/cleo-soft…
huntress.com
0142
Reposted by alden
aaron @aaron.cat.gf · 09/12/2024
hotties only want one thing and its the operation triangulation exploit chain
065
Reposted by alden
Stuart Ashenbrenner @stuartjash.bsky.social · 06/12/2024
Yesterday I got to present with the 🐐 @re.wtf. Such a blast talking thru infostealers and the telenovela that they’ve become. #OBTS really is the best, chillest conference out there. Excited for a second day of talks 🤓🍎
0131
alden @re.wtf · 06/12/2024
🍎🤝🔥
070
alden @re.wtf · 27/11/2024
we cookin' for #100DaysofYARA 🤝🔥
0194
Reposted by alden
jiska @naehrdine.bsky.social · 17/11/2024
How does the new iOS inactivity reboot work? What does it protect from? I reverse engineered the kernel extension and the secure enclave processor, where this feature is implemented. naehrdine.blogspot.com/2024/11/reve...
naehrdine.blogspot.com
Reverse Engineering iOS 18 Inactivity Reboot
Wireless and firmware hacking, PhD life, Technology
12277106
Reposted by alden
Jamie Levy 🦉 @gleeda.bsky.social · 15/11/2024
🧵Today’s blogpost focuses on a newer ransomware variant named SafePay. Needless to say, ransomware sucks. When this new variant appeared, it gained our attention. 👀 Let’s dig into what happened and what makes it tick ⬇️:
A redacted view of the SafePay onion website hosting information about compromised machinesDirectory listing from the attacker's onion siteApache Server info page
23612
Reposted by alden
Alex Delamotte @alex.leetnoob.com · 14/11/2024
I wrote a post on the realities of cloud & webserver ransomware. Check it out to see some of the toolsets & frameworks that can be used for these attacks.
0147
alden @re.wtf · 14/11/2024
some huntress homies cooked a blog on a new ransom group called safepay RE was fun until we realized it was ripped lockbit code 💀😭 imagine not being able to write your own ransomware, true skill issue smh some funny opsec fails too, watch ya status www.huntress.com/blog/its-not...
t.co
https://www.huntress.com/blog/its-not-safe-to-pay-safepay
0154
alden @re.wtf · 11/10/2023
thrunting thractors w thrintel
010