Sign in

🇺🇦 Xorhex 🇺🇦

@xorhex.bsky.social
266 followers 618 following 131 posts
PostsRepliesMedia
Reposted by 🇺🇦 Xorhex 🇺🇦
RE//verse @re-verse.io · 28/09/2026
RE//verse 2027 is on the way, and you should probably be there! If you know, you know. If you don’t, this is a very good year to fix that. re-verse.io
011
🇺🇦 Xorhex 🇺🇦 @xorhex.bsky.social · 28/09/2026
Looking at the SOS agenda 🔥, the FOMO is real. www.stateofstatecraft.com/agenda
stateofstatecraft.com
Agenda - State of Statecraft
The purpose of SOS is to discuss state-sponsored operations and drive understanding of geopolitical risk and impact through study of the actors or systems that facilitate them.
021
🇺🇦 Xorhex 🇺🇦 @xorhex.bsky.social · 25/09/2026
Made the mistake of not waiting until all of the latest season of Slow Horses had been released before starting.
040
Reposted by 🇺🇦 Xorhex 🇺🇦
Wesley Shields @wxs.bsky.social · 09/09/2026
Nice work on this! It cost me a bit of my sanity last week but was definitely interesting to see.
132
Reposted by 🇺🇦 Xorhex 🇺🇦
安坂星海 Azaka || VTuber @azaka.fun · 08/09/2026
after ALL THESE YEARS, I just now realized the Droid ID follows RFC 4122 and contains the time of the LNK and MAC address of the creating machine
022
Reposted by 🇺🇦 Xorhex 🇺🇦
Cindʎ Xiao 🍉 @cxiao.net · 08/09/2026
I'm here at #RustConf! I have cool cards! Feel free to find me after my talk, message me here, or message me on the conference Discord (you can find me in my talk's channel `#reverse-engineering-rust-malware-in-2026`) if you want to get one of these!
001
Reposted by 🇺🇦 Xorhex 🇺🇦
Wesley Shields @wxs.bsky.social · 04/09/2026
I just had to look it up but "base64 ascii" modifiers in combination DO NOT include the ascii version of the string. This is well documented (yara.readthedocs.io/en/latest/wr...) but something I had forgot. If I forget it (and I'm the one who wrote that feature) then I bet others do too.
yara.readthedocs.io
Writing YARA rules — yara 4.5.0 documentation
121
Reposted by 🇺🇦 Xorhex 🇺🇦
Julian-Ferdinand Vögele @julianferdinand.bsky.social · 27/08/2026
Today Insikt Group released new research on BlueDelta’s initial access campaigns targeting government and diplomatic organizations in Romania, Spain, and Türkiye, using diplomatic-themed docs to deliver the backdoor HOOKEDGE. Check out the report here: www.recordedfuture.com/research/blu...
recordedfuture.com
BlueDelta Targets Defense and Diplomacy with HOOKEDGE
Discover how the Russian state-sponsored threat group BlueDelta is using the HOOKEDGE backdoor to target defense and diplomatic organizations across Europe
072
Reposted by 🇺🇦 Xorhex 🇺🇦
Wesley Shields @wxs.bsky.social · 21/08/2026
This stuff is the same as UNC5976 (and yes, i had to go look that up because we dont use the UNC designation internally on my team) discussed in our post yesterday: cloud.google.com/blog/topics/...
cloud.google.com
Distinct Clusters Target Individuals of Interest to Russia | Google Cloud Blog
Distinct Russian clusters have been conducting phishing activity focused on Application Specific Passwords (ASP), OAuth flows, and malware delivery. All of these operations seem focused on account com...
064
Reposted by 🇺🇦 Xorhex 🇺🇦
Binary Ninja @binary.ninja · 18/08/2026
What do Binary Ninja workflows do for you? A lot! Check out what @mei@donotsta.re managed to pull off using them to clean up conditional jump threading: codeberg.org/mei-b/bn-ana...
021
Reposted by 🇺🇦 Xorhex 🇺🇦
Greg Lesnewich @greg-l.bsky.social · 29/07/2026
So remember last week when we said we hadn’t see TA488/Laundry Bear/Void since Feb? Well... We kinda lied Day before the release, we found em throwing a half click against Outlook to install one of the coolest implants we’ve ever examined: OWAReaper www.proofpoint.com/us/blog/thre...
proofpoint.com
Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit | Proofpoint US
Threat Research would like to thank the Proofpoint Cloudmark Authority team for their collaboration. Key Findings On 22 July 2026, one day prior to Proofpoint’s recent joint release
22415
Reposted by 🇺🇦 Xorhex 🇺🇦
Julian-Ferdinand Vögele @julianferdinand.bsky.social · 09/07/2026
1/ Today @milenkowski.bsky.social from @sentinellabs.bsky.social and I are publishing a project we've been working on over the past few months. We found suspected China- and India-linked espionage actors independently targeting the same victim: #Balochistan Police in #Pakistan. s1.ai/spy2flags
s1.ai
One Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law Enforcement
China and India ran separate espionage operations against the same Pakistani police force, each drawn by different stakes in Pakistan's internal security.
1910
Reposted by 🇺🇦 Xorhex 🇺🇦
pinkflawd.bsky.social @pinkflawd.bsky.social · 08/07/2026
I'll be teaching an online edition of my Advanced Linux Malware Reverse Engineering training across 6 days July 20th-22nd, and 27th-29th, and have a small contingent of seats still available - more info and registration here: docs.google.com/forms/d/e/1F...
044
Reposted by 🇺🇦 Xorhex 🇺🇦
Julian-Ferdinand Vögele @julianferdinand.bsky.social · 01/07/2026
Colleagues of mine at Insikt Group just released new research on the Iran-nexus cluster #TAG-182, deploying #MarkiRAT, a malware family previously observed in use by #FerociousKitten, for internal and external surveillance: www.recordedfuture.com/research/nex...
recordedfuture.com
Iran-Nexus TAG-182 Disseminates MarkiRAT Surveillance Tool
Discover how Iranian-nexus threat cluster TAG-182 uses MarkiRAT malware and fake VPN/media apps to conduct cyber surveillance operations against domestic targets.
099
Reposted by 🇺🇦 Xorhex 🇺🇦
Kyle Ehmke @kyleehmke.bsky.social · 29/06/2026
Suspicious domain ms365update[.]com was registered through MonoVM on 6/22/26 using juliarhorton@onionmail[.]org (H/t @domaintools.bsky.social). Today the domain began using Cloudflare and its subdomain www.ms365update[.]com now redirects to Google DNS.
221
Reposted by 🇺🇦 Xorhex 🇺🇦
Wesley Shields @wxs.bsky.social · 24/06/2026
github.com/VirusTotal/y... This fixes an issue with certain header constraints that you really should update for. There are other nice bug fixes and features too, but the header constraints is a big one.
github.com
Release v1.19.0 · VirusTotal/yara-x
Add missing machine architecture types to pe module (#687). Add warning for single-byte patterns (71baa67). Add warning for duplicate patterns in a rule (9061803). Small optimization when generatin...
042
Reposted by 🇺🇦 Xorhex 🇺🇦
Tim Blazytko @mrphrazer.bsky.social · 19/06/2026
The slides from our @reconmtl.bsky.social talk with @nicolo.dev on agentic deobfuscation are now online. Topics: commercial VMs, anti-cheat, DRM systems, malware, and anti-agentic obfuscation. Slides: synthesis.to/presentation...
0107
Reposted by 🇺🇦 Xorhex 🇺🇦
Daniel Gordon @validhorizon.bsky.social · 12/06/2026
My name is Daniel Gordon and I am writing to let you know that you have a serious problem. Next week I will be speaking at FirstCon about The Art of Notification. Distilled lessons learned from hundreds of victim notifications I’ve done over the years. www.first.org/conference/2...
first.org
38th Annual FIRST Conference: DENVER (US), June 14-19, 2026
38th Annual FIRST Conference - Denver (US), June 14-19, 2026.
042
Reposted by 🇺🇦 Xorhex 🇺🇦
Volexity @volexity.com · 04/06/2026
@volexity.com has published details from an incident response engagement in September 2025 involving multiple #BRICKSTORM variants deployed by a threat actor that Volexity tracks as VerdantBamboo. [1/4]
volexity.com
VerdantBamboo: Just Another BRICKSTORM in the Firewall
In September 2025, Volexity conducted an incident response engagement that began after suspicious network traffic was observed from a Linux-based virtual machine appliance on a customer’s network. The...
186
Reposted by 🇺🇦 Xorhex 🇺🇦
Cindʎ Xiao 🍉 @cxiao.net · 02/06/2026
See you at RustConf! :D
021
Reposted by 🇺🇦 Xorhex 🇺🇦
PIVOTcon @pivotcon.bsky.social · 14/05/2026
#PIVOTcon26 edition is over! Time to #pivot to #PIVOTcon27 Big thanks to our sponsors for making this happen! @silentpush.bsky.social @vertexproject.bsky.social @censys.bsky.social @urlscan-bot.bsky.social #validin @talosintelligence.com (continued...) 🔽 1/3
196
Reposted by 🇺🇦 Xorhex 🇺🇦
Cindʎ Xiao 🍉 @cxiao.net · 11/05/2026
Very excited to present at RustConf this year! :D
031
Reposted by 🇺🇦 Xorhex 🇺🇦
Max 'Libra' Kersten @maxkersten.nl · 29/04/2026
Its been two weeks since (my workshop at) @botconf.infosec.exchange.ap.brid.gy 2026, and last weekend I found some time to write about my experience: maxkersten.nl/2026/04/27/m...
maxkersten.nl
My impression of Botconf 2026 – Max Kersten
011
Reposted by 🇺🇦 Xorhex 🇺🇦
Binary Ninja @binary.ninja · 27/04/2026
The debugger got some real love in our latest update. Hardware breakpoints and conditional breakpoints have both landed, and the new debug adapters make things faster and more reliable across a range of workflows. Read more from the latest blog: binary.ninja/2026/04/13/b...
052
Reposted by 🇺🇦 Xorhex 🇺🇦
Squiblydoo @squiblydoo.bsky.social · 24/04/2026
CertGraveyard's PKI Lab is available now. Want to better understand code-signing certificates? The site allows you to extract and view certificates. The Cert Inspection tool parses out all of the bits and flags anomalies. 1/2
153
Reposted by 🇺🇦 Xorhex 🇺🇦
Wesley Shields @wxs.bsky.social · 23/04/2026
So @xorhex.bsky.social asked (in our YARA keybase chat) how one might only iterate through the last 10 matches of a string in YARA. I took a shot at answering it by logging the last 10 locations of a match in descending order: for all i in (0..10): (console.log(@a[#a - i]))
132
Reposted by 🇺🇦 Xorhex 🇺🇦
Doug Metz @dwmetz.bsky.social · 17/04/2026
MalChela 3.2: More Cowbell? More Intel! One of the things I value most about the open-source community is that the best improvements to a tool often don’t come from inside it — they come from outside conversations.  A short while back, the author of mlget, xorhex,  reached out and suggested I add…
bakerstreetforensics.com
MalChela 3.2: More Cowbell? More Intel!
One of the things I value most about the open-source community is that the best improvements to a tool often don’t come from inside it — they come from outside conversations.  A short while back, the author of mlget, xorhex,  reached out and suggested I add more malware retrieval sources to FOSSOR, one of my earlier tools for pulling down samples from threat intel repositories.  
011
🇺🇦 Xorhex 🇺🇦 @xorhex.bsky.social · 14/04/2026
For the few people using #BinYars, it has been updated to support #BinaryNinja 5.3 and now targets YARA-X 1.15.0 Update via Binja's plugin manager to get the latest. github.com/xorhex/BinYa... #YARA #YARAX
github.com
GitHub - xorhex/BinYars-SideWidget
Contribute to xorhex/BinYars-SideWidget development by creating an account on GitHub.
010
Reposted by 🇺🇦 Xorhex 🇺🇦
Catalin Cimpanu @campuscodi.risky.biz · 14/04/2026
JSAC 2026 videos: www.youtube.com/playlist?lis... NDSS 2026 videos: www.youtube.com/@NDSSSymposi...
012
Reposted by 🇺🇦 Xorhex 🇺🇦
Binary Ninja @binary.ninja · 14/04/2026
Binary Ninja 5.3 (Jotunheim) is released: binary.ninja/2026/04/13/b... Major updates: NDS32 support, AArch64 ILP32 ABI, new Universal MachO UI, way more containers, command palette upgrade, type library helpers, ghidra gzf export, updated IDB import, HW and conditional breakpoints, and much more!
binary.ninja
Binary Ninja - Binary Ninja 5.3 (Jotunheim)
Binary Ninja is a modern reverse engineering platform with a scriptable and extensible decompiler.
066
Reposted by 🇺🇦 Xorhex 🇺🇦
安坂星海 Azaka || VTuber @azaka.fun · 11/04/2026
REWorkshop - Axios supply chain attack retrospective 🔔 twitch.tv/azakasekai 🔔 youtube.com/live/RxeAPsO...
021
Reposted by 🇺🇦 Xorhex 🇺🇦
Daniel Gordon @validhorizon.bsky.social · 11/04/2026
It’s trite but this marks the dawn of a new era of hacking. This is Pandora’s box and we just have to hope that some of the defender benefits outweigh the bad. These are the technical details of the hack of the government of Mexico using AI. cdn.prod.website-files.com/69944dd945f2...
cdn.prod.website-files.com
265
Reposted by 🇺🇦 Xorhex 🇺🇦
Decoder Loop @decoderloop.com · 10/04/2026
📣 Our own @cxiao.net will be speaking at @rustconf.com this year, with the talk "Reverse Engineering Rust Malware in 2026"! sched.co/2KHt7 Rust is now a popular language not only for writing legitimate software, but also for writing malware. How are malware reversers dealing with this? #RustConf
142
🇺🇦 Xorhex 🇺🇦 @xorhex.bsky.social · 09/04/2026
#binjaextras has been updated to allow for type information to be applied to both struct members and global variables. Local instance of OALab's hashdb has been added as well - see setup info here: github.com/xorhex/binja... Install/update binjaextras via the plugin manager! #BinaryNinja
github.com
021
Reposted by 🇺🇦 Xorhex 🇺🇦
Squiblydoo @squiblydoo.bsky.social · 01/04/2026
The history of BumbleBee's relationship with certificates can be viewed a few ways with CertGraveyard. You can review via a table, a graph, or download the whole database to transform the data yourself. 4/4
031
Reposted by 🇺🇦 Xorhex 🇺🇦
Wesley Shields @wxs.bsky.social · 30/03/2026
Two for one today! Added support for console.log(offset, length) to the console module in YARA-X, per the suggestion of a user. Makes it nicer to work with arbitrary sequences of bytes. Hopefully it makes it in the next release!
media.tenor.com
two men are standing next to each other and one of them is wearing a shirt that says nuts
ALT: two men are standing next to each other and one of them is wearing a shirt that says nuts
041
Reposted by 🇺🇦 Xorhex 🇺🇦
Signal @signal.org · 19/03/2026
New: Group member labels, a way to describe yourself or your role in a group chat, only visible to that group chat. Label yourself the “Goalie” to your soccer team or “Favorite Child” to your family to stir some drama. Available on Android, Desktop & iOS signal.org/blog/group-m...
signal.org
Label yourself
We all take on different roles in relation to our friends, neighbors, family members, and colleagues. Keep those different roles clear in your many Signal group chats by using group member labels, now...
720130
Reposted by 🇺🇦 Xorhex 🇺🇦
Ben Read @benread.bsky.social · 18/03/2026
Get your tickets (and CFPs) now! This conference is always a great time and you learn a lot.
074
Reposted by 🇺🇦 Xorhex 🇺🇦
dragosr @dragostech.bsky.social · 17/03/2026
Your UEFI firmware can drop a binary into Windows on every boot via Windows Platform Binary Table. OEMs use it for bloatware persistence. Attackers use it the same way. One reg key kills it: reg add "HKLM\SYSTEM\CurrentControlSet\Control\Session Manager" /v DisableWpbtExecution /d 1 /t REG_DWORD /f
1175
Reposted by 🇺🇦 Xorhex 🇺🇦
RE//verse @re-verse.io · 16/03/2026
RE//verse 2026 talks are live on YouTube! Want to revisit a talk or catch the ones you missed? The full playlist is now available: youtube.com/playlist?lis...
084
Reposted by 🇺🇦 Xorhex 🇺🇦
Calle Svensson @zetatwo.bsky.social · 16/03/2026
My @REverseConf talk about reverse engineering #AoE2 is now available on YouTube: www.youtube.com/watch?v=Dp-I... check it out and hear about some reverse engineering techniques and a code pattern matching tool I released: github.com/ZetaTwo/bnil...
youtube.com
RE//verse 2026: Reversing AoE 2: Upgrading tools from Dark Age to Castle Age by Carl Svensson
YouTube video by REverse Conference
263
Reposted by 🇺🇦 Xorhex 🇺🇦
Decoder Loop @decoderloop.com · 17/03/2026
Looking for #RustLang samples to practice your reverse engineering skills on? Just since January, we've added samples from 8 different #malware families to the Rust Malware Sample Gallery: github.com/decoderloop/... 1) KCVY OSLOCK Ransomware 2) An unnamed Rust DDoS botnet 3) FunkSec Ransomware 🧵
github.com
GitHub - decoderloop/rust-malware-gallery: A collection of malware families and malware samples which use the Rust programming language.
A collection of malware families and malware samples which use the Rust programming language. - decoderloop/rust-malware-gallery
122
Reposted by 🇺🇦 Xorhex 🇺🇦
Pasquale Stirparo 🇺🇦 🇪🇺 @pstirparo.bsky.social · 17/03/2026
RationalEdge REDS now supports #APK analysis for #Android #malware, along with LLM-assisted code explainability. If you're looking for a malware repository/analysis platform, reach at rationaledge.io MoRE to come @rationaledge.bsky.social #ThreatResearch #ThreatIntel #CTI #ReverseEngineering 1/3
rationaledge.io
RationalEdge - Know Why
Transform your threat analysis workflow with intelligence you can understand and trust.
143
Reposted by 🇺🇦 Xorhex 🇺🇦
Kyle Ehmke @kyleehmke.bsky.social · 13/03/2026
The dark money group’s democracyunmuted[.]org domain is almost certainly administered using the same Cloudflare account as demfluencers[.]com. The latter—originally registered in June 2025 and operational in the Nov/Dec timeframe—claims to provide paid opportunities and access for influencers.
021
Reposted by 🇺🇦 Xorhex 🇺🇦
PIVOTcon @pivotcon.bsky.social · 10/03/2026
📣 #PIVOTcon26 Agenda is here 🤟 We are thrilled to announce the lineup for this year's edition! 2⃣ days and 19 talks from leading #ThreatResearch experts. The agenda link is in the first comment👇, and the talks and speakers are in the thread.🧵 #CTI #ThreatIntel 1/15
11610
Reposted by 🇺🇦 Xorhex 🇺🇦
Wesley Shields @wxs.bsky.social · 06/03/2026
Victor just released v1.14.0 - improvements in macho module, tighter code generation in the compiler and the new “deps” command. Congratulations to everyone involved! github.com/VirusTotal/y...
032
Reposted by 🇺🇦 Xorhex 🇺🇦
PIVOTcon @pivotcon.bsky.social · 06/03/2026
We are still finalising the agenda and the updated website, so the #PIVOTcon26 lineup announcement will be made early next week. #CTI #ThreatIntel #ThreatResearch #StayTuned
media.tenor.com
a man in a suit and tie stands in front of an amazon prime logo
ALT: a man in a suit and tie stands in front of an amazon prime logo
082