Sign in

Karsten Hahn

@struppigel.bsky.social
321 followers 31 following 111 posts
PostsRepliesMedia
Karsten Hahn @struppigel.bsky.social · 28/09/2026
New blog: OpenSUpdater Hides in Recompiled 7zip SFX blog.gdatasoftware.com/2026/09/3849...
011
Karsten Hahn @struppigel.bsky.social · 10/09/2026
BlueMoon exploit kit allows to infect systems if a user opens a link via Chrome or Chromium based browsers via v8 sandbox escape and RCE on Windows. www.proofpoint.com/us/blog/thre...
proofpoint.com
Once in a BlueMoon: Multiple State-Aligned Threat Actors Rapidly Adopt Novel Exploit Chain Using Chrome and Windows Zero-Days | Proofpoint US
Analyst note: Proofpoint uses the UNK_ designator to define clusters of activity that are still developing and have not been observed for long enough to receive a numerical TA designation.
031
Karsten Hahn @struppigel.bsky.social · 06/09/2026
🦔 📹 New Video: Hooking V8 JavaScript ➡️ compiled V8 ➡️ we write a reusable hook script ➡️ we overcome basic anti-hooking #MalwareAnalysisForHedgehogs #V8 #JavaScript www.youtube.com/watch?v=Y8_A...
youtube.com
Malware Analysis - Hooking V8 JavaScript bytecode
YouTube video by MalwareAnalysisForHedgehogs
041
Karsten Hahn @struppigel.bsky.social · 19/08/2026
Blog: "Bad advice and myths around malware prevention" If you ever heard or said "visiting websites can't infect you", "PDFs aren't malicious" or "exploits are rare and always targeted" this article might be for you. blog.gdatasoftware.com/2026/07/3846... #GDATATechBlog #GDATA
blog.gdatasoftware.com
Bad Advice and Myths Around Malware Prevention
Bad advice about malware prevention creates false confidence. Nuanced advice matters! Learn why websites, old exploits, and PDF files can still pose risks.
000
Karsten Hahn @struppigel.bsky.social · 12/08/2026
New video: Compiled V8 JavaScript for reversers 🎥 ➡️ V8 compilation pipeline ➡️ bytecode caching ➡️ how bytenode abuses caching for protection www.youtube.com/watch?v=YSSC... #MalwareAnalysisForHedgehogs #JavaScript #V8
youtube.com
Compiled JavaScript - V8 compilation pipeline and Bytenode
YouTube video by MalwareAnalysisForHedgehogs
021
Karsten Hahn @struppigel.bsky.social · 24/07/2026
Do you remember the BlockBlasters Steam game that was used to steal from a man with cancer? FBI arrested the threat actor www.techspot.com/news/113163-...
techspot.com
FBI arrests 21-year-old accused of infecting 8,000 PCs with malware through fake Steam games
The suspect, identified by the FBI as Zyaire Dontaevious Zamarion Wilkins, is accused of running a sophisticated cybercrime operation with unnamed co-conspirators for nearly two years. The...
100
Karsten Hahn @struppigel.bsky.social · 21/06/2026
I asked a clanker to make me a prompt that I can use to generate images of malware, like literal pictures that represent malware such as the ones used in samplepedia, not PE images. I got a warning for cyber abuse with threats to shut down my account o.O
041
Karsten Hahn @struppigel.bsky.social · 20/06/2026
I published an API tracer for kernel mode drivers using speakeasy emulation AI notice: It's vibe-coded. I manually analyzed ~20 drivers to verify and improve the output and tested with a corpus of ~100 drivers. github.com/struppigel/h...
010
Karsten Hahn @struppigel.bsky.social · 19/06/2026
New trainings sample on samplepedia Backdoor, obfuscated Python bytecode. 0/60 on Virustotal, which means it's still fresh. www.virustotal.com/gui/file/4ad... samplepedia.cc/sample/4ada6...
012
Karsten Hahn @struppigel.bsky.social · 14/06/2026
🦔 📹 Poison X kernel mode rootkit analysis ➡️ kernel mode driver theory ➡️ Ghidra markup ➡️ basic string deobfuscation #MalwareAnalysisForHedgehogs www.youtube.com/watch?v=yx6A...
youtube.com
Malware Analysis - PoisonX rootkit, Kernel driver rootkit markup in Ghidra
YouTube video by MalwareAnalysisForHedgehogs
131
Karsten Hahn @struppigel.bsky.social · 13/06/2026
I submitted a new sample to samplepedia.cc PoisonX rootkit. Video solution follows the next days. samplepedia.cc/sample/db5d2...
030
Karsten Hahn @struppigel.bsky.social · 12/06/2026
This seems to be a prevalent issue now: People vibe code security applications and the LLM generates real malware for testing. The generated test files rely on real threat actor infrastructure to download or exfiltrate. hxxps://github.com/DataDog/guarddog/blob/main/tests
334
Karsten Hahn @struppigel.bsky.social · 07/05/2026
😂 @rifteyy just pointed me to this gem in the VT comment section for the empty file www.virustotal.com/gui/file/e3b...
010
Karsten Hahn @struppigel.bsky.social · 19/04/2026
New Video: Build your own LLM dynamic analysis lab 🦔🎥 ➡️ AI debugs and unpacks with x64dbg ➡️ AI can access powershell terminal www.youtube.com/watch?v=QrWz...
youtube.com
Build your own AI based Dynamic Reversing Lab, x64dbg automate
YouTube video by MalwareAnalysisForHedgehogs
021
Karsten Hahn @struppigel.bsky.social · 24/03/2026
My malware analysis courses have now a new certificate design. malwareanalysis-for-hedgehogs.learnworlds.com/courses
010
Karsten Hahn @struppigel.bsky.social · 23/03/2026
Added a task for the SugarSMP spark stealer sample to samplepedia samplepedia.cc/sample/060ed...
000
Karsten Hahn @struppigel.bsky.social · 17/03/2026
I wrote an article about SugarSMP Minecraft scams, Spark stealer, extortion and hacked accounts. After a brief contact to the threat actor, we talked to two victims and followed the trail. Analysis in collaboration with @rifteyy #GDATATechblog #GDATA blog.gdatasoftware.com/2026/03/3839...
blog.gdatasoftware.com
Minecraft: SugarSMP's Dark Tale of Scams, Malware & Extortion
Some Minecraft players were looking for safe haven away from griefers, but found an elaborate web of malware, deception and extortion.
023
Karsten Hahn @struppigel.bsky.social · 15/03/2026
🦔 📹 Video: Building your own AI Malware Analysis Lab ➡️ old system, 16 GB RAM ➡️ using Remnux #MalwareAnalysisForHedgehogs #LLM www.youtube.com/watch?v=YOdu...
youtube.com
Build your own AI Malware Analysis Lab with Remnux
YouTube video by MalwareAnalysisForHedgehogs
000
Karsten Hahn @struppigel.bsky.social · 07/03/2026
🦔 📹 New video: NodeJs analysis when deobfuscator fails ➡️ #MythJs stealer sample ➡️ pkg VFS exploration tool ➡️ js-confuser #MalwareAnalysisForHedgehogs www.youtube.com/watch?v=gtLq...
youtube.com
Malware Analysis - Deobfuscating NodeJs pkg packed stealer MythJs
YouTube video by MalwareAnalysisForHedgehogs
100
Karsten Hahn @struppigel.bsky.social · 03/03/2026
New blog: Using LLMs the right way for malware analysis 💡Tips for building an autonomous AI analysis lab on a 12 yo laptop and getting stuff done faster without loss of accuracy. blog.gdatasoftware.com/2026/03/3838...
000
Karsten Hahn @struppigel.bsky.social · 28/02/2026
GuvercinInstaller.exe 1/72 #kurdishmyth stealer, NodeJS ➡️Infects discord_desktop_core\index.js ➡️Steals various browser and discord data. ➡️Exfiltrates via discord webhook. The code references kurdishmyth and mythprivate www.virustotal.com/gui/file/496...
100
Karsten Hahn @struppigel.bsky.social · 26/02/2026
We wrote about HijackLoader. Not exactly a new topic, but certainly an interesting journey. It provides some tools for HijackLoader too. blog.gdatasoftware.com/2026/02/3837...
blog.gdatasoftware.com
Free Games, Costly Consequences, and Loads of Malware
The Spanish games platform PiviGames is being abused as a malware distribution hub. This was discovered after someone looked for help on Reddit.
110
Karsten Hahn @struppigel.bsky.social · 21/02/2026
samplepedia.cc update: You have now a new "My articles" overview (see profile dropdown menu), which allows you to add article drafts and manage articles. You can decide to publish such a draft as a solution later.
020
Karsten Hahn @struppigel.bsky.social · 21/02/2026
Found a nice trainings sample for analysis of kernel mode rootkits ↓ samplepedia.cc/sample/465dc...
010
Karsten Hahn @struppigel.bsky.social · 10/02/2026
Looks like the dev told an LLM to generate test files for a Shai Hulud detection app. The LLM complied and generated malicious test files... github.com/Cobenian/sha...
010
Karsten Hahn @struppigel.bsky.social · 01/02/2026
I created an extraction script for custom PyInstaller applications as seen in suspected EvilAI PDF apps. Script (modified pyinstxtractor-ng): github.com/struppigel/h... Article: samplepedia.cc/sample/8c9d9...
031
Karsten Hahn @struppigel.bsky.social · 01/02/2026
#Samplepedia updates * you can upload images for articles * view count for samples and articles * expert difficulty available samplepedia.cc
030
Karsten Hahn @struppigel.bsky.social · 28/01/2026
anyPDF malware analysis report rifteyy.org/report/anypd...
rifteyy.org
anyPDF decompilation - a highly evasive, fully undetected, signed PDF editor bundled with AdClicker Trojan and Spyware
In this post, we will decrypt a highly evasive C# malicious sample that is fully undetected and inspect it's source code using dnSpy.
030
Karsten Hahn @struppigel.bsky.social · 25/01/2026
🦔 📹 New Video: Can office files be malicious without Macros? ➡️ VSTO Add-Ins ➡️ External Templates ➡️ Checklist for Office analysis #MalwareAnalysisForHedgehogs www.youtube.com/watch?v=RtHH...
youtube.com
Malware Analysis - Malicious MS Office files without Macros
YouTube video by MalwareAnalysisForHedgehogs
264
Karsten Hahn @struppigel.bsky.social · 23/01/2026
If you like binary refinery, check out this sample It's also mostly undetected yet on VT: samplepedia.cc/sample/361f2...
041
Karsten Hahn @struppigel.bsky.social · 16/01/2026
@invokereversing.bsky.social is analyzing Floxif with binary ninja 👇 www.youtube.com/watch?v=2F_B...
youtube.com
Floxif File Infector with Control Flow Obfuscation Analysis (Stream - 06/01/2026)
YouTube video by Invoke RE
032
Karsten Hahn @struppigel.bsky.social · 08/01/2026
Samplepedia update: Users can submit their own images with the samples and there is a platform field. samplepedia.cc
020
Karsten Hahn @struppigel.bsky.social · 04/01/2026
I have created a website, where you can share your sample analysis (via links or posts) and search samples for training based on tags and difficulty. If you write analysis blogs, you can share them there. samplepedia.cc
0147
Karsten Hahn @struppigel.bsky.social · 27/12/2025
I added a python script to monitor a folder during dynamic analysis and dump changed files with timestamp github.com/struppigel/h...
github.com
hedgehog-tools/Python helper scripts/monitor_and_dump_changed_files.py at main · struppigel/hedgehog-tools
Contribute to struppigel/hedgehog-tools development by creating an account on GitHub.
031
Karsten Hahn @struppigel.bsky.social · 21/12/2025
🦔 📹New Video: RenPy game loads stealer, beginner friendly ➡️ strategies for finding malware in 2956 files ➡️ extracting and decompiling RenPy ➡️ remote access tool config extraction ➡️ unpacking native payload #MalwareAnalysisForHedgehogs #RenPy www.youtube.com/watch?v=Fmfg...
youtube.com
Malware Analysis - RenPy game, finding malware code in 2956 files, Beginner friendly
YouTube video by MalwareAnalysisForHedgehogs
031
Karsten Hahn @struppigel.bsky.social · 15/12/2025
New blog: Browser Hijacking techniques -- when malware has different preferences than you www.gdatasoftware.com/blog/2025/11... #GDATA #GDATATechblog #BrowserHijacking
gdatasoftware.com
Browser Hijacking: Three Technique Studies
If you are searching for technical information on how browser hijacking works, there does not seem to be much out there apart from generic removal instructions. This might be an educational gap we sho...
020
Karsten Hahn @struppigel.bsky.social · 13/12/2025
I added a RenPy archive (.rpa, .rpi) extractor to my tools repo github.com/struppigel/h...
github.com
hedgehog-tools/RenPy at main · struppigel/hedgehog-tools
Contribute to struppigel/hedgehog-tools development by creating an account on GitHub.
041
Karsten Hahn @struppigel.bsky.social · 01/12/2025
My colleague Banu wrote about a new infostealer Arkanix www.gdatasoftware.com/blog/2025/12...
gdatasoftware.com
Arkanix: New Infostealer grabs Browser Data, Wifi Logins, Cryptowallets
G DATA researcher Banu Ramakrishnan has discovered a previously undocumented infostealer malware called Arkanix. Learn about the details in the G DATA blog!
010
Karsten Hahn @struppigel.bsky.social · 30/11/2025
🦔📹 New Video: Modifying string decrypter for a ConfuserEx2 variant ➡️ Defeating antis with Harmony hooks ➡️ AsmResolver ➡️ .NET string deobfuscation #MalwareAnalysisForHedgehogs www.youtube.com/watch?v=sARn...
youtube.com
Malware Analysis - Defeating ConfuserEx Anti-Analysis with Hooking
YouTube video by MalwareAnalysisForHedgehogs
031
Karsten Hahn @struppigel.bsky.social · 28/11/2025
Black Friday offers: 60% off for 2 malware analysis courses (beginner & intermediate) Or 40% off for single course malwareanalysis-for-hedgehogs.learnworlds.com/courses
malwareanalysis-for-hedgehogs.learnworlds.com
Courses
021
Karsten Hahn @struppigel.bsky.social · 22/11/2025
Lecture on Anti Tamper by Tim Blazytko www.youtube.com/watch?v=hQi9...
youtube.com
SP25: Anti Tamper
YouTube video by mr_phrazer
111
Karsten Hahn @struppigel.bsky.social · 19/11/2025
Rhadamanthys loader deobfuscation cyber.wtf/2025/11/19/r...
cyber.wtf
Rhadamanthys Loader Deobfuscation | cyber.wtf
031
Karsten Hahn @struppigel.bsky.social · 17/11/2025
I am suggesting a new malware type: the browser remote access tool (BRAT) It's a form of browser hijacker that remotely controls your browser based on server commands. Typical form: press key combos for copy-pasting URLs, opening tabs, context menu, downloading files etc
031
Karsten Hahn @struppigel.bsky.social · 13/11/2025
For anyone who wants to understand certificates better and how to spot abuse, this is a great read certcentral.org/training
022
Karsten Hahn @struppigel.bsky.social · 26/10/2025
🦔 📹 Video: Analysis of malicious NordVPN setup ➡️ beginner-suitable ➡️ sorry, no spoilers here ;) www.youtube.com/watch?v=5-OY... #MalwareAnalysisForHedgehogs
youtube.com
Malware Analysis - Trojanized NordVPN Setup, Beginner Sample
YouTube video by MalwareAnalysisForHedgehogs
010
Karsten Hahn @struppigel.bsky.social · 15/10/2025
I am looking for good resources for Linux malware analysis, including books and courses. If you have any recommendations please let me know.
011
Karsten Hahn @struppigel.bsky.social · 30/09/2025
My #VirusBulletin2025 loot 😍 I also met someone from vxunderground and all I got was this lousy sticker
130
Karsten Hahn @struppigel.bsky.social · 22/09/2025
Steam game BlockBlasters downloads malware written by Arvin Tan #GDATATechblog @GDATA #GDATA www.gdatasoftware.com/blog/2025/09...
gdatasoftware.com
Infected Steam game downloads malware disguised as patch
A 2D platformer game called BlockBlasters has recently started showing signs of malicious activity after a patch release on August 30. While the user is playing the game, various bits of information a...
000
Karsten Hahn @struppigel.bsky.social · 17/09/2025
My colleague Banu wrote about the connection between AppSuite, OneStart and ManualFinder www.gdatasoftware.com/blog/2025/09...
gdatasoftware.com
AppSuite, OneStart & ManualFinder: The Nexus of Deception
Having taken a look at AppSuite in one of our last articles, we have started pulling on a few loose threads to see where it would take us. It turns out that there are relationships with other maliciou...
121
Karsten Hahn @struppigel.bsky.social · 08/09/2025
🦔 📹 New video: What breakpoints to set for unpacking malware? ➡️ Steps of unpacking stub ➡️ Breakpoint targets ➡️ VirtualAlloc from user to kernel mode #MalwareAnalysisForHedgehogs #Unpacking www.youtube.com/watch?v=fn8r...
youtube.com
Malware Theory - What breakpoints to set for unpacking
YouTube video by MalwareAnalysisForHedgehogs
022