
sweaminecodes
1.9K posts

sweaminecodes
@XaMiNeZH
2026 Yıllık Özeti
@XaMiNeZH hesabının Twitter yılını gör








macOS ventura on an rtx 4090



10 proofs from our next major model Astra on long-standing open problems in mathematics and theoretical computer science (also including new circuit lower bounds for computing the permanent!) GPT-5.6 has already enabled so much exciting work in math and science. Can’t wait to see what comes next!


This kernel rootkit takes its C2 commands through the Windows registry. It registers a CmRegisterCallbackEx routine, then the user-mode agent writes commands into a benign key using nothing but standard registry APIs. Every write gets checked for the magic value 0x2625B7146B and the command is unpacked from it. No IOCTL. No DeviceIoControl. No named pipe. Nothing on the user-mode side that looks like it is talking to a driver at all. The command set behind it is a full kernel toolkit: arbitrary physical memory read and write by building a custom page table and injecting it into a free PML4 slot, PFN database reads, KVA shadow bypass, kernel APC DLL injection, ETW and CKCL and syscall table hooks, HvlGetQpcBias and GetCpuClock patched for timing. Then the HWID spoofing shows up. Disk, Nvidia GPU, SMBIOS, plus forged mouhid and i8042prt input packets. This started life as a game cheat driver. The cheat scene has been shipping production grade kernel capability for a decade and it keeps getting laundered into malware. Author: @xeroxsec Full analysis, IOCs and a YARA rule by 0xSec: 0xsec.gitbook.io/0xsec/malware-… The C2 infrastructure was still live and unflagged on VirusTotal at time of writing.


someone's upset they didn't get invited





@XaMiNeZH karşılaştırmaları
Keşfet
Benzer Profiller
@turkamator88
219.2K görüntülenme
@wx1n11124
138.4K görüntülenme
@turkifsa_aley
46.9K görüntülenme
@ne_puppy
41.7K görüntülenme
@cccxxxyyyiii
35.4K görüntülenme
@slzjtt
29.1K görüntülenme
@gulililucky
19.5K görüntülenme
@oooosugar
18.9K görüntülenme




























