Wesley Shields @wxs.bsky.social · 05/10/2026Specifically, "updates" or any kind of software download and execution just to get past a captive portal should make the hairs on the back of your neck stand up. 010
Wesley Shields @wxs.bsky.social · 05/10/2026MSFT updated their blog on the captive portal shenanigans: www.microsoft.com/en-us/securi... This stuff has been continuing for a while now, and the tooling is evolving too. No new indicators I see in there (or that we are sharing, so not throwing shade) but be on the look out for this stuff!microsoft.comCaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft | Microsoft Security BlogStorm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order ... 141
Wesley Shields @wxs.bsky.social · 02/10/2026This kind of activity from them has been ongoing for a while now, as MSFT has recently published on. If you are in the spaces they like to target you will likely see this, if you haven't already. Now that their activities are being outed it will be interesting to see how they adapt, if at all. 010
Wesley Shields @wxs.bsky.social · 02/10/2026resident.ngo/lab/writeups... - resident.ngo wrote up a nice post on some recent activity they saw. They only claim it is very similar to Star Blizzard (COLD RELIC in our terms) but if it looks like a duck and quacks like a duck... ;)resident.ngoRESIDENT.NGO Digital security for Civil Society 131
Wesley Shields @wxs.bsky.social · 24/09/2026This warms my cold, dispassionate robot heart: www.isyeet.io/wxsbsd/ Though anyone who knows me knows I don't put noses in my smiley faces, so they got that part wrong. ;)isyeet.ioAll I want is text. | ISYEETA dispatch from the woods. In defense of ASCII, quiet computers, and telling your family you made it home. 141
Wesley Shields @wxs.bsky.social · 17/09/2026Not that I feel the need to blast my life into the void, but the water bottle has been found and will be shipped to me by a very nice coworker. I have received a few things over the years for my contributions to various things and I cherish all of them, including this water bottle. 020
Wesley Shields @wxs.bsky.social · 17/09/2026Been traveling this week, and left my favorite water bottle at the hotel. RIP to my YARA water bottle, hope whoever ends up with it likes it. 130
Wesley Shields @wxs.bsky.social · 10/09/2026And another publication, this time from @volexity.com, on the Chrome 0-day chain that Proofpoint also published on. All great work and worth reading if you're into this kind of stuff! 000
Wesley Shields @wxs.bsky.social · 09/09/2026static.klipy.comIt's Never Ending Constant Chaos CharlieALT: It's Never Ending Constant Chaos Charlie 020
Wesley Shields @wxs.bsky.social · 09/09/2026Nice work on this! It cost me a bit of my sanity last week but was definitely interesting to see. 132
Wesley Shields @wxs.bsky.social · 04/09/2026Basically, "ascii" is applied (which is pointless in this case) and then the string is base64 encoded and added to the patterns to search for. I could make just "ascii base64" (and only those two, there are edge cases like "ascii wide base64" which are not pointless) a compiler warning? 000
Wesley Shields @wxs.bsky.social · 04/09/2026I just had to look it up but "base64 ascii" modifiers in combination DO NOT include the ascii version of the string. This is well documented (yara.readthedocs.io/en/latest/wr...) but something I had forgot. If I forget it (and I'm the one who wrote that feature) then I bet others do too.yara.readthedocs.ioWriting YARA rules — yara 4.5.0 documentation 121
Wesley Shields @wxs.bsky.social · 27/08/2026And before one of your donkeys say "use vim" or whatever, I've probably been computing longer than you've been alive so shut up and come up with solutions and not stupid comments. If I wanted to use vim I would (and do for some things). The point isn't an editor holy war. 000
Wesley Shields @wxs.bsky.social · 27/08/2026I just want a text editor with a couple of nice features, Microsoft. Stop killing your products with default on features that eventually make me not want it anymore. 100
Wesley Shields @wxs.bsky.social · 27/08/2026I updated vscode just now and noticed it is spawning this: /Users/wxs/Library/Application Support/Code/agent-host/sdk-cache/claude/0.3.220/darwin-arm64/node_modules/@anthropic-ai/claude-agent-sdk-darwin-arm64/claude - I didn't ask for this, don't enable it by default and even better: don't ship it. 100
Wesley Shields @wxs.bsky.social · 24/08/2026New release with lots of new features and bug fixes. Again, congratulations to Victor and everyone who contributed to making this happen! It’s great to see the continued progress. github.com/VirusTotal/y...github.comRelease v1.20.0 · VirusTotal/yara-xImplement SIMD-accelerated masked literal matching (#691). Improve atom extraction heuristics for better performance (#690, 1e14f60). Improve scan performance by applying file size and file header ... 032
Wesley Shields @wxs.bsky.social · 21/08/2026This stuff is the same as UNC5976 (and yes, i had to go look that up because we dont use the UNC designation internally on my team) discussed in our post yesterday: cloud.google.com/blog/topics/...cloud.google.comDistinct Clusters Target Individuals of Interest to Russia | Google Cloud BlogDistinct Russian clusters have been conducting phishing activity focused on Application Specific Passwords (ASP), OAuth flows, and malware delivery. All of these operations seem focused on account com... 064
Wesley Shields @wxs.bsky.social · 20/08/2026static.klipy.comArcher You Want AntsALT: Archer You Want Ants 010
Wesley Shields @wxs.bsky.social · 20/08/2026virustotal.github.io/yara-x/blog/... I've seen this exact issue more times than I can count, and getting support for recognizing it in the compiler is great!virustotal.github.ioBeware of the wildcardIntroducing the new unintended_pattern_in_set compiler warning in YARA-X to catch overlapping variable prefixes and pattern set collisions. 000
Wesley Shields @wxs.bsky.social · 20/08/2026Also mentioned in there is some links to the hotel captive portal stuff Reliaquest and MSFT recently mentioned in their public reporting. As usual, great work by Gabby on piecing that stuff together. 010
Wesley Shields @wxs.bsky.social · 20/08/2026So @gabagool.ing and I had some stuff to say on some RU activity. If you're into tracking and understanding interesting RU groups here's some new ones and a revisit of one from last year. Thanks for our friends who helped shine a light on some of this activity! cloud.google.com/blog/topics/...cloud.google.comDistinct Clusters Target Individuals of Interest to Russia | Google Cloud BlogDistinct Russian clusters have been conducting phishing activity focused on Application Specific Passwords (ASP), OAuth flows, and malware delivery. All of these operations seem focused on account com... 175
Wesley Shields @wxs.bsky.social · 10/08/2026Three positions opened up in GTIG. If you have questions I'd be happy to answer! Koreas: www.google.com/about/career... Exploits (US and CH based): www.google.com/about/career... www.google.com/about/career... 021
Wesley Shields @wxs.bsky.social · 28/07/2026This came out while I was traveling last week and it's a good read on a single campaign from this group we've been tracking: dslua.org/publications... - They are fairly active doing this kind of phishing and also other nefarious activities.dslua.orgPhishing Campaign Against “Civil Network OPORA” – Gmail Account Takeover via OAuth – Лабораторія цифрової безпеки 042
Wesley Shields @wxs.bsky.social · 15/07/2026All this information is exposed nicely in the rust API and the command line displays it nicely. With my PR (github.com/VirusTotal/y...) it is exposed in the python API too.static.klipy.comBender from Futurama Says NeatALT: Bender from Futurama Says Neat 020
Wesley Shields @wxs.bsky.social · 15/07/2026You can have a lot of rules that use some module that you want to disable for some reason or another. Now you can just ignore that module and any rules that use it will be ignored. Any rules that depend upon ignored rules are also ignored. 200
Wesley Shields @wxs.bsky.social · 15/07/2026I found the newly added feature in YARA-X to ignore certain rules on compilation errors to be interesting and exposed it in the python API. The original requester (and implementer) raises a good point that this makes using large rulesets much easier. 100
Wesley Shields @wxs.bsky.social · 08/07/2026Turns out there was a small bug in the "private" modifier on hex and RE patterns in YARA-X, in that they were not honored at all. Fixed that in github.com/VirusTotal/y... - original issue spotted by someone else: github.com/VirusTotal/y...github.comfix: Do not ignore private modifier on hex and RE patterns. by wxsBSD · Pull Request #698 · VirusTotal/yara-xThis fixes the "private" modifier on hex strings so they are properly hidden from output and also fixes it so the modifier is properly displayed in both AST and CST representations. This ... 020
Wesley Shields @wxs.bsky.social · 30/06/2026Jordan doing good work deep diving into Turla related malware we’ve been tracking for a while now. If you’re into Turla this is a good read. cloud.google.com/blog/topics/...cloud.google.comThe Latest Addition to Turla’s Intelligence Gathering Apparatus | Google Cloud BlogAnalysis of a backdoor, STOCKSTAY, that has been continually developed and deployed by the Russia-linked threat actor Turla. 1103
Wesley Shields @wxs.bsky.social · 26/06/2026Patrick sharing some good work on activity of this PRC nexus actor that is quite broad! 020
Wesley Shields @wxs.bsky.social · 24/06/2026github.com/VirusTotal/y... This fixes an issue with certain header constraints that you really should update for. There are other nice bug fixes and features too, but the header constraints is a big one.github.comRelease v1.19.0 · VirusTotal/yara-xAdd missing machine architecture types to pe module (#687). Add warning for single-byte patterns (71baa67). Add warning for duplicate patterns in a rule (9061803). Small optimization when generatin... 042
Wesley Shields @wxs.bsky.social · 07/05/2026github.com/VirusTotal/y... Performance improvements and some nice new features. It only gets better with each release! Congratulations to all contributors and Victor!github.comRelease v1.16.0 · VirusTotal/yara-xMultiple performance improvements (#623, #624, #626, #627, #629, #631, #632, #635, #649, #654). Implement constant folding for bitwise operations (#634). Allow specifying context size for matches (... 021
Wesley Shields @wxs.bsky.social · 29/04/2026Next time AI makes up a garbage answer just remember wxs' first law of AI: "Never trust robots, a bunch of assholes if you ask me." 010
Wesley Shields @wxs.bsky.social · 24/04/2026If you limit yourself to just YARA-X (for now) this works and is the most readable I could come up with: Descending: for all i in (0..math.min(2, #a) - 1): ( console.log(@a[#a - i]) ) Ascending: with max = math.min(2, #a): ( for all i in (1..max): ( console.log(@a[#a - (max - i)]) ) ) 010
Wesley Shields @wxs.bsky.social · 24/04/2026Was playing around with this a bit more and noticed a difference in how YARA and YARA-X work that might be a bug. github.com/VirusTotal/y... 120
Wesley Shields @wxs.bsky.social · 23/04/2026Doing it in ascending order is way more interesting though, especially if you have less than 10 matches: rule a { strings: $a = "FreeBSD" condition: with max = #a: ( for all i in (1..max): ( console.log(@a[#a - (max - i)]) ) ) } 110
Wesley Shields @wxs.bsky.social · 23/04/2026So @xorhex.bsky.social asked (in our YARA keybase chat) how one might only iterate through the last 10 matches of a string in YARA. I took a shot at answering it by logging the last 10 locations of a match in descending order: for all i in (0..10): (console.log(@a[#a - i])) 132
Wesley Shields @wxs.bsky.social · 13/04/2026There is some sleeper work going on lately. The full warm build being one of them, for sure. ;) 000
Wesley Shields @wxs.bsky.social · 13/04/2026github.com/VirusTotal/y... - congrats to all involved! These new features are really great!github.comRelease v1.15.0 · VirusTotal/yara-xAdd full support for WASM. The whole yara-x create now can be built for WASM (#583, #588, #598). New playground at https://virustotal.github.io/yara-x/playground/ (#601). The yr check command now n... 161
Wesley Shields @wxs.bsky.social · 08/04/2026Not so fun fact: The imphash implementation in pefile has diverged from the implementation in YARA and YARA-X... and any other one in the last 15 years. This has existed for 2 years and I'm pushing to get it reverted and a new pefile release made. github.com/erocarrera/p...github.comImphash implementation does not follow convention · Issue #141 · erocarrera/pefilehttps://www.mandiant.com/blog/tracking-malware-import-hashing/ Mandiant's imphash convention requires the following: Resolving ordinals to function names when they appear Converting both DLL names ... 030
Wesley Shields @wxs.bsky.social · 05/04/2026I took this picture shortly after I started working there, in that exact building. I always guessed this sticker was from the Sun Microsystems days but can’t prove it. 000
Wesley Shields @wxs.bsky.social · 01/04/2026media.tenor.coma man holding a banana says " pretty pretty pretty pretty pretty good "ALT: a man holding a banana says " pretty pretty pretty pretty pretty good " 000
Wesley Shields @wxs.bsky.social · 01/04/2026It really annoyed me that we could not return multiple tag linter errors, but returned multiple errors for other linters. The root cause is kind of interesting. More importantly, I put up a fix for it: github.com/VirusTotal/y...github.comfix: Properly handle multiple errors with the tag linter. by wxsBSD · Pull Request #614 · VirusTotal/yara-xWhen the tag linter comes across multiple errors only the first one is returned. This is due to an oversight in the API where we can only return a single error, not a vector of errors. I realize th... 010
Wesley Shields @wxs.bsky.social · 30/03/2026Two for one today! Added support for console.log(offset, length) to the console module in YARA-X, per the suggestion of a user. Makes it nicer to work with arbitrary sequences of bytes. Hopefully it makes it in the next release!media.tenor.comtwo men are standing next to each other and one of them is wearing a shirt that says nutsALT: two men are standing next to each other and one of them is wearing a shirt that says nuts 041
Wesley Shields @wxs.bsky.social · 29/03/2026I've been struggling to find time to write code during the week, and I know I need to get better at that as I still very much enjoy contributing to this project. Anyways, here's the PR that adds the linter functionality the compiler has to the Python API: github.com/VirusTotal/y... 000
Wesley Shields @wxs.bsky.social · 28/03/2026I would not call them lower tier. Very prolific and effective at what they do, you just don’t hear about them because they tend to be very selective in targeting. 020
Wesley Shields @wxs.bsky.social · 22/03/2026One of those days. I have a bit of time to work on some code, so I start in on it. I quickly realize I want a feature that was added sometime after I started my branch. Fine, I pull it down into my repository BUT COMPLETELY FORGET TO REBASE MY WORK ON IT! Took me a solid 20 minutes of debugging.media.tenor.coma man in a suit and tie sits at a desk with the words " i don 't even really work here " above himALT: a man in a suit and tie sits at a desk with the words " i don 't even really work here " above him 010
Wesley Shields @wxs.bsky.social · 21/03/2026So @tlansec.bsky.social asked about exposing the linter capabilities of `yr check` (sometimes called the "checker") in the python API. It is done modulo test cases and some minor tweaks to the API I'm considering to make it a bit nicer. PR up hopefully by the end of this weekend. 020
Wesley Shields @wxs.bsky.social · 19/03/2026Next time I see you I’m going to refer to EVERY group as Lazarus. Even RU groups. You can hate me for it all you want but the trolling will be worth it. 121