External writing
My articles published with Group-IB, Trend Micro, and other vendors. Each link opens on the original site. Filter by category on this page only.
No items match this category.
-
HEAVYGRAM: A Telegram-based Surveillance Backdoor Linked to Handala Hack
Analysis of HEAVYGRAM, a Telegram-based Windows backdoor linked to Handala Hack, used to surveil Iranian dissidents and opponents.
-
HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels
Research on abusing Microsoft 365 calendars and Graph API as covert C2 channels.
-
Operation Olalampo: Inside MuddyWater’s Latest Campaign
Analysis of MuddyWater’s Operation Olalampo, including new malware variants and Telegram-based C2.
-
Unmasking MuddyWater’s New Malware Toolkit Driving International Espionage
Coverage of a MuddyWater phishing campaign distributing Phoenix backdoor malware across MENA and beyond.
-
Mapping the Infrastructure and Malware Ecosystem of MuddyWater
Deep look at MuddyWater’s tooling, targeting, and infrastructure management through 2025.
-
Exploiting Trust: How Signed Drivers Fuel Modern Kernel Level Attacks on Windows
How attackers abuse digitally signed drivers and Windows kernel loaders to gain privileged access.
-
Ransomware debris: an analysis of the RansomHub operation
Overview of RansomHub’s RaaS model, affiliate panel, recruitment, and extortion tactics.
-
The beginning of the end: the story of Hunters International
Technical details on Hunters International ransomware, Storage Software, and the group’s evolution.
-
RansomHub Never Sleeps Episode 1: The evolution of modern ransomware
First episode on how ransomware evolved into sophisticated RaaS operations led by groups like RansomHub.
-
Hunting for A New Stealthy Universal Rootkit Loader
Analysis of a stealthy signed rootkit loader linked to FiveSys activity.
-
BlackCat Ransomware Deploys New Signed Kernel Driver
Technical look at a new signed kernel driver used in BlackCat ransomware defense evasion.
-
An In-Depth Look at Windows Kernel Threats
White paper on modern Windows kernel threats, signed-driver abuse, and rootkit techniques.