MatheuZ

712 posts

MatheuZ banner
MatheuZ

MatheuZ

@MatheuzSecurity

Red Team Operator, Cyber Threat Intelligence, Malware Researcher

Brazil Katılım Eylül 2020
360 Takip Edilen2.3K Takipçiler
Sabitlenmiş Tweet
MatheuZ
MatheuZ@MatheuzSecurity·
github.com/MatheuZSecurit… Hey guys, I posted a really cool zine in pure TXT about Unhooking Linux EDR, attacking the cleanup_module function, to be able to remove any hook from an EDR for example. Feel free to read.
MatheuZ tweet media
English
4
48
174
14.1K
MatheuZ retweetledi
Phrack Zine
Phrack Zine@phrack·
Phrack wants your art! The theme for this issue is retro sci-fi / old-school cybernetic futures. CRT glow, vector grids, space paranoia, BBS aesthetics, analog cyberpunk, forgotten futures. But we accept all kinds of contributions :) ANSI, illustration, collage, renders, weird experiments. Send it to: arts@phrack.org Deadline June 30th
Phrack Zine tweet media
English
0
18
39
1.4K
MatheuZ
MatheuZ@MatheuzSecurity·
@extencil Check out the Singularity rootkit guys😂🤣
English
0
0
1
66
MatheuZ
MatheuZ@MatheuzSecurity·
@heyZeus131313 You're mixing unrelated things. Residential proxies explain IP origin, not who wrote the code. The rootkits mentioned are Brazilian, and there are others as well this is about authorship and technical scene, not attack location.
English
1
0
3
243
Dubya
Dubya@heyZeus131313·
@MatheuzSecurity Brazil is just a massive residential proxy exit node. These are all coming from other places. Not Brazil. 🇧🇷
English
1
0
0
71
MatheuZ
MatheuZ@MatheuzSecurity·
Brazil is a Linux kernel rootkit factory. Diamorphine, Brokepkg, KoviD, Reptile and now Singularity. Some of the most well-known Linux kernel rootkits came from Brazilian researchers. Brazil has a crazy strong scene in linux rootkit development
English
22
114
1.4K
43.4K
Noir Burner
Noir Burner@NoirBurner·
@MatheuzSecurity I love when people keep the culture alive I have been writing e-zines for a while but is hard to find people doing it now a days... amazing job
English
1
0
1
16
MatheuZ
MatheuZ@MatheuzSecurity·
github.com/MatheuZSecurit… Hey guys, I posted a really cool zine in pure TXT about Unhooking Linux EDR, attacking the cleanup_module function, to be able to remove any hook from an EDR for example. Feel free to read.
MatheuZ tweet media
English
4
48
174
14.1K
MatheuZ
MatheuZ@MatheuzSecurity·
@duket2122 I've spoken with the creators of Kovid, Diamorphine, and Brokepkg. Reptile's creator is Brazilian and has even spoken at a Brazilian conference. Do some research or get basic knowledge before giving your opinion Furthermore, I am the creator of Singularity and I am Brazilian :)
English
2
0
5
175
MatheuZ
MatheuZ@MatheuzSecurity·
@duket2122 lol are you completely delusional?
English
1
0
6
538
Lc
Lc@duket2122·
@MatheuzSecurity None of these are from Brazilians and I mean it because I am Brazilian and work in this field. None are Brazilians.
English
1
0
3
666
MatheuZ
MatheuZ@MatheuzSecurity·
@who1sroot Yes, you can find a repository with the Reptile files here: codeberg.org/hardenedvault/… Github was taking down several repositories a while back, so I think it's a good idea to take projects from GitHub and upload them to a Gitea instance to avoid "disappearing from the internet".
English
1
0
10
827
whoisroot
whoisroot@who1sroot·
@MatheuzSecurity Talking about Reptile, the GH repo (and it's forks) got nuked. Does anyone have a copy? Also, I have been thinking of running a Gitea instance of only "dangerous"/blacklisted repos (Reptile, Havoc, various RATs etc), "for archival purposes only", what do you guys think?
English
1
0
7
1.1K
MatheuZ
MatheuZ@MatheuzSecurity·
@Vindix007 That's a different discussion though. I'm talking about Linux kernel rootkit research, not desktop OS popularity. And even on Windows, Brazil has had a strong offensive security scene for a long time.
English
0
0
8
124
Mr.X
Mr.X@Vindix007·
@MatheuzSecurity Strong presence in Linux, but the vast majority of the population uses Winblow$ 11.
English
1
0
4
1.3K
MatheuZ
MatheuZ@MatheuzSecurity·
@m0nadlabs That's very interesting, I'll take a look
English
0
0
1
65
Anderson Nascimento
Anderson Nascimento@andersonc0d3·
Brokepkg and Kovid? Never heard of them. I also had written one for FreeBSD, probably way before those ones you mentioned. I had implemented hooking via debug registers, keylogger through the keyboard driver and some other features. It was a nice project to tinker with computers back then. :) Rootkits em kernel space - Redshift, um rootkit para o kernel do FreeBSD pt.slideshare.net/slideshow/root…
English
1
3
50
6.8K
MatheuZ
MatheuZ@MatheuzSecurity·
@andersonc0d3 Damn, that's really cool. Great work! I had no idea about Redshift. Another one for the Brazilian rootkit hall of fame 😄
English
0
0
15
2.5K
MatheuZ
MatheuZ@MatheuzSecurity·
Wrote 5k lines for this zine
MatheuZ tweet media
English
14
23
523
16.6K