2ero
648 posts

2ero
@2eroHunter
#APT Hunter #CTI Twitter only represents my personal opinion
Katılım Nisan 2016
949 Takip Edilen3.4K Takipçiler

They're using a new OLLVM obfuscator in this newer build - or at least with different functionalities enabled. My config parser's still got it though :)

m4n0w4r@kienbigmummy
English

#VoidLink 看来大家人手一份😂😂😂

Unit 42@Unit42_Intel
We investigated an open web directory on a #VoidLink C2 server that reveals new samples and possible overlaps with activity we track as CL-STA-1015. Previous versions of VoidLink have been seen in the wild as early as 2025-12-02. Details at: bit.ly/4s6Ehr8
中文

What if we have Timeline Explorer (in steroids), but for Mac? 👀
Born out of pure frustration with Windows-only forensic tools so I'm about to release this personal project for DFIR analysts running macOS who are tired of being second-class citizens. And for Incident responders who need to triage timelines in the field without booting up a Windows VM.
*Data displayed is based on emulation exercises using fictional information.
#dfir #macos

English

@ElementalX2 @malwrhunterteam @smica83 @volrant136 ok
the chain is very nice the final .net RAT also
English

Susp Indian #APT Targetting Pak Navy
jalaiyt.rar from Pakistan
b25bc18bda9be41df2b9ecd2fa6b060196a842bb90ac17bdb03faf1ba6292dad
drops _Outreach 2026-27 NHQ.pdf .lnk
d53c1a27f692f4320428d849abb21824
interesting chain
@malwrhunterteam @smica83 @volrant136 @ElementalX2

English

#Bitter #APT also uses CVE-2025-8088.
f6f2fdc38cd61d8d9e8cd35244585967
84128d40db28e8ee16215877d4c4b64a
41fcaf0267134fcdea7e4d516b69e16e
cloud.google.com/blog/topics/th…
Português

@alisaesage You should come to China for tourism if you have time; Chinese men from different regions are very different.
English











