RansomwareThe DFIR Report·1 year ago

Flash Alert: From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira

Bumblebee malware, active as an initial access tool since late 2021, has been leveraged in recent campaigns using SEO poisoning to distribute payloads by impersonating legitimate IT tools in search results. The malware has been observed delivering AdaptixC2 and Akira ransomware in coordinated attack chains that begin with compromised search engine results. This campaign represents an evolution in Bumblebee's delivery tactics, shifting from earlier methods to search-based social engineering attacks.

Behind the Book: Threat Hunting macOS with Jaron Bradley

13Cubed·2.2K views · 1 year ago

In this episode, I sit down with Jaron Bradley, author of the upcoming book Threat Hunting macOS. With the recent release of the new 13Cubed training course Investigating macOS Endpoints, this felt like the perfect time to bring Jaron on the channel to discuss his new book — a resource I believe will be an excellent companion to the course. 📘 Order Jaron’s Book – Threat Hunting macOS

Windows Memory Forensics Challenge

13Cubed·4K views · 1 year ago

Welcome to a special Windows Memory Forensics Challenge from 13Cubed. This is an excellent opportunity to get some hands-on practice with Windows memory forensics. You'll find the questions below, as well as a link to download the memory sample needed to answer those questions.

MalwareThe DFIR Report·1 year ago

KongTuke FileFix Leads to New Interlock RAT Variant

The Interlock ransomware group has deployed a new PHP-based variant of their remote access trojan, marking a significant shift from their previous JavaScript implementation known as NodeSnake. Researchers from The DFIR Report and Proofpoint have observed this evolved RAT being distributed through a campaign leveraging KongTuke FileFix, with notable activity detected since May 2025. This variant demonstrates increased resilience and represents an escalation in the group's technical capabilities.

RansomwareThe DFIR Report·1 year ago

Hide Your RDP: Password Spray Leads to RansomHub Deployment

A password spray attack against an internet-facing RDP server in November 2024 provided initial access to a victim environment, with the threat actor using known malicious IPs to attempt logins across multiple accounts. Following successful RDP authentication hours after the initial spray attempt, the attacker proceeded to deploy RansomHub ransomware. The intrusion demonstrates the persistent threat posed by exposed remote access services and the need for defensive measures against credential-based attacks.

Reverse Engineering Access Tokens Part 2

OALabs·5K views · 1 year ago

This tutorial covers Windows Access Tokens, the Logon Session, Token Elevation, AdjustTokenPrivileges and the Windows Access Control Model. This is part of our IDA Pro reverse engineering series. The full series can be found on our patron...

From Zero to Zero Day (and beyond) - Life of a Hacker: Jonathan Jacobi

LiveOverflow·38K views · 1 year ago

I met Jonathan in 2018 at the CCC when he was just 18 years old. Back then he referenced my videos which had a little bit of impact on his life. Now a lot of time has passed and in this interview I want to get to know Jonathan better. How did he get into hacking, founding of the CTF team perfect blue, working as a vulnerability researcher and ultimately transitioning into a new career.

Automated AI Reverse Engineering with MCP for IDA and Ghidra (Live VIBE RE)

OALabs·49K views · 1 year ago

Testing MCP plugins for IDA and Ghidra live with @mrexodia IDA MCP

Reverse Engineering Access Tokens Part 1

OALabs·5.2K views · 1 year ago

This tutorial walks through the process of reverse engineering malware which uses AdjustTokenPrivileges to enable SeDebugPrivilege. No steps are skipped in the process! This is Module 2.2 of our IDA Pro reverse engineering series. The full series can be found on our patron...

The German Hacking Championship

LiveOverflow·37K views · 1 year ago

An amazing event for aspiring German hackers is happening right now. I went to the finals in 2024, share a few impressions and tell you about this year's event.

Do you know this common Go vulnerability?

LiveOverflow·97K views · 1 year ago

When auditing code it's crucial to know about common issues. In this video we explore a Go issue that I was not aware of.

USB Ethernet Adapter Malware??? Chinese RJ45-USB Full Analysis - Part 1

OALabs·39K views · 1 year ago

Reverse engineering all stages with line by line code analysis. e3f57d5ebc882a0a0ca96f9ba244fe97fb1a02a3297335451b9c5091332fe359 OP

Google's Mobile VRP Behind the Scenes with Kristoffer Blasiak (Hextree Podcast Ep.1)

LiveOverflow·18K views · 1 year ago

"There are not that many people that do Android research [...] There is no lack of targets. If people would actually look, there is lots to it. The scope is huge." - This is a conversation with Kristoffer Blasiak about Google's Mobile Vulnerability Rewards Program (VRP).

Reverse Engineering LAB Setup Tutorial (updated)

OALabs·22K views · 1 year ago

If you are just getting started with reverse engineering this the place to start. In this tutorial we provide an overview the current setup that we currently run, this is also the same setup used in all of our live streams and tutorials. The full notes for this tutorial are unlocked for everyone on our Patreon including links to all of the tools mentioned

My theory on how the webp 0day was discovered (BLASTPASS)

LiveOverflow·70K views · 1 year ago
Load more