NtAlertThread

1K posts

NtAlertThread banner
NtAlertThread

NtAlertThread

@ElementalX2

🇮🇳 Katılım Mart 2019
682 Takip Edilen2.1K Takipçiler
Sabitlenmiş Tweet
NtAlertThread
NtAlertThread@ElementalX2·
New Research! seqrite.com/blog/operation… We have found an interesting campaign targeting an entity of Chinese telecom with VELETRIX implant. The implant uses anti-sandbox, shellcode obfuscation technique via IPV4 and execution via EnumCalendarInfo leading to Vshell implant.
NtAlertThread tweet mediaNtAlertThread tweet mediaNtAlertThread tweet mediaNtAlertThread tweet media
English
10
71
252
25K
NtAlertThread retweetledi
Ophir Harpaz
Ophir Harpaz@OphirHarpaz·
begin-re is back 🎉 Lost the domain, kept the course, improved the looks. You can find it now at ophirharpaz.com/begin.re
English
7
45
267
23.6K
NtAlertThread
NtAlertThread@ElementalX2·
Reeeeeversing....
NtAlertThread tweet mediaNtAlertThread tweet media
English
1
5
59
4.8K
NtAlertThread retweetledi
Ryan Naraine
Ryan Naraine@ryanaraine·
"The malware checks for the density of the material being simulated and only acts when that value passes 30 g/cm³, the threshold uranium can only reach under the shock compression of an implosion device." Symantec advances the fast16 research security.com/threat-intelli…
English
1
16
53
10.2K
NtAlertThread retweetledi
Hussein Muhaisen
Hussein Muhaisen@husseinmuhaisen·
I just published a NEW blog post -> reverse engineering the multi stage file format steganography chain from TeamPCP's telnyx SDK (4.87.1 and 4.87.2) husseinmuhaisen.com/blog/reverse-e…
English
0
11
33
3.6K
NtAlertThread retweetledi
R136a1
R136a1@TheEnergyStory·
Have you noticed that those deep-dive stories about complex Windows malware have pretty much vanished, especially in recent years? It feels like the era of "blockbuster" Windows malware has just gone silent, and this blog post tries to give some answers why. r136a1.dev/2026/05/07/whe…
English
19
132
596
82.2K
NtAlertThread retweetledi
eversinc33 🤍🔪⋆。˚ ⋆
When practicing on a VM crackme recently, I created a devirtualizer which lifts the virtual machine to LLVM to defeat the protection. LLVM-based devirtualisation is a lot of fun and I wrote down my experience and lessons learned on my blog: eversinc33.com/2026/05/07/llv…
English
18
103
508
35.9K
NtAlertThread retweetledi
ThreadLinqs
ThreadLinqs@threadlinqs·
NEW THREAT INTEL: OceanLotus APT32 PyPI Supply Chain Attack - 3 malicious wheels drop ZiChatBot cross-platform malware via Zulip API C2. 9 detections, 42 IOCs. #TL-2026-0467" target="_blank" rel="nofollow noopener">intel.threadlinqs.com/#TL-2026-0467 #ThreatIntel #CyberSecurity #APT32 #SupplyChain #PyPI
ThreadLinqs tweet media
English
0
2
7
582
NtAlertThread retweetledi
Justin Elze
Justin Elze@HackingLZ·
I wrote a blog but you can speed run it with this and this.
Justin Elze tweet mediaJustin Elze tweet media
English
6
15
87
10.7K
NtAlertThread
NtAlertThread@ElementalX2·
Interesting FUD sample, with .vhdx extension uploaded from 🇱🇻 & 🇻🇳 and some with RAR extension, DLL Sideloading into multiple executables công việc.rar 5afd45ac84838b38445cbbb0fdeb4ae178cf24f1ef096f53a9553fb8c6676368 @malwrhunterteam
NtAlertThread tweet media
English
0
8
23
2.2K
NtAlertThread retweetledi
Check Point Research
Check Point Research@_CPResearch_·
VECT RaaS is making headlines via partnerships with BreachForums and TeamPCP. Behind the polished image is a weak operator: the ransomware is bug-ridden, poorly built, and most encrypted files aren’t fully recoverable, even with the decryption key. research.checkpoint.com/2026/vect-rans…
English
0
31
98
29.1K
NtAlertThread retweetledi
Tommy M (TheAnalyst)
Tommy M (TheAnalyst)@ffforward·
@malwrhunterteam Likely who we call TA4922, some details in proofpoint.com/us/blog/threat… Some outlets calls them "Silver Fox APT" based on... that they, like every small-time Chinese threat actors, use WinOS 4.0/ValleyRAT where the source code was leaked... in 2022... 🤷‍♂️
English
0
3
6
821
NtAlertThread
NtAlertThread@ElementalX2·
It is strange, that APT36 operators track very minute details about security researchers. The first version of GymRAT had no mention of "WhisperLynx", just because we published and presented various research against SilentLynx APT, blud thought they could just misattribute LOL.
R3BELF0X@goldenjackel12

#APT36 #WhisperLynx Users/WhisperLynx/Desktop/My creation/My creation/My creation/Creation/Target_update/client/New folder/window_Gym _trainer.go /api/register?member_id=%s /api/progress?member_id=%s&update=%s /api/download?exercise=%s WIN-HQ8EO8P8GBF @500mk500 @PrakkiSathwik

English
0
2
20
1.7K