Andreas Klopsch

379 posts

Andreas Klopsch

Andreas Klopsch

@hackingump1

Reverse Engineer @ Microsoft (MIRAGE)

Katılım Ocak 2020
279 Takip Edilen881 Takipçiler
Andreas Klopsch retweetledi
Ramin Nafisi
Ramin Nafisi@MalwareRE·
Another quality technical blog from #MIRAGE, this time on Secret Blizzard’s beloved #Kazuar malware. This blog is an in-depth analysis of Kazuar’s progression from a single, monolithic framework into a modular bot ecosystem composed of three distinct module types, each with clearly defined roles. Together, these components distribute functionality across the P2P botnet, enabling flexible configuration, lower observability, and broad tasking while minimizing opportunities for detection. microsoft.com/en-us/security…
English
0
15
33
5.2K
Andreas Klopsch retweetledi
Ramin Nafisi
Ramin Nafisi@MalwareRE·
Microsoft Threat Intelligence uncovered a macOS‑focused cyber campaign by the North Korean threat actor Sapphire Sleet that relies on social engineering rather than software vulnerabilities. microsoft.com/en-us/security…
English
0
6
24
1.5K
Andreas Klopsch retweetledi
Microsoft Threat Intelligence
Microsoft Threat Intelligence@MsftSecIntel·
The Russian military intelligence actor Forest Blizzard has conducted large-scale exploitation of vulnerable small office/home office (SOHO) devices to hijack DNS requests and enable persistent, passive visibility and reconnaissance at scale. msft.it/6012Q24hI By compromising edge devices that are upstream of larger targets, threat actors could take advantage of less closely monitored assets to pivot into enterprise environments. We have identified over 200 organizations and 5,000 consumer devices impacted by Forest Blizzard’s malicious DNS infrastructure. Microsoft Threat Intelligence is publishing this research to increase awareness of the risks associated with insecure home and small-office internet devices and to give users and organizations tools to mitigate, detect, and hunt for these threats where they might be impacted.
English
9
94
227
29.4K
Andreas Klopsch
Andreas Klopsch@hackingump1·
🚨 RIFT Update 🚨 Improved rustc compiler detection ✅ Fixed bugs causing incorrect FLIRT signatures for nightly builds 🛠️ Plus, multiple stability fixes! We’re making RIFT easier to use—big features coming soon 😎 👉 github.com/microsoft/RIFT #RIFT #rust #microsoft #infosec
English
0
0
3
118
Andreas Klopsch retweetledi
vx-underground
vx-underground@vxunderground·
Lots of frustration in the malware analysis and reverse engineering community. It's been discovered a DEFCON talk, presentation, and the code which coincided with it, was AI slop. The talk itself had hallucinated terminology which (apparently) no one at DEFCON noticed. Bad.
vx-underground tweet media
English
73
165
3.3K
155K
Andreas Klopsch retweetledi
Ramin Nafisi
Ramin Nafisi@MalwareRE·
#PipeMagic is a highly modular backdoor used by the financially motivated threat actor Storm-2460. It masquerades as a legitimate open-source ChatGPT Desktop Application. Microsoft Threat Intelligence encountered PipeMagic as part of research on an attack chain involving the exploitation of CVE-2025-29824, an elevation of privilege vulnerability in Windows Common Log File System (CLFS). PipeMagic is a sophisticated malware framework designed for flexibility and persistence. Quality blog by MSTIC malware intelligence, research and analysis (MIRAGE) team: microsoft.com/en-us/security… #pipemagic #mstic #mirage #threatintelligence
Ramin Nafisi tweet media
English
0
16
56
22.4K
Andreas Klopsch retweetledi
Ramin Nafisi
Ramin Nafisi@MalwareRE·
Do you find analyzing Rust binaries/malware tedious and unpleasant? You’re not alone! If you’re attending #REcon this year, our own @hackingump1 will be unveiling #RIFT today at 2PM EST (not at REcon? We got you covered, stay tuned). We have been using RIFT internally for some time and it has truly transformed the way we handle and analyze Rust binaries. cfp.recon.cx/recon-2025/tal… #RIFT #Rust #REon25 #MSTIC #MIRAGE
Andreas Klopsch@hackingump1

Presenting "Unveiling RIFT: Advanced Pattern Matching for Rust Libraries" at RECON Montreal 2025! Sharing research on discovering Rust dependencies in compiled binaries. See you there! 🚀 #RECON2025 #RustLang #ReverseEngineering

English
0
13
37
22.8K
Andreas Klopsch retweetledi
herrcore
herrcore@herrcore·
Unpacking VMProtect 3 (x64) 🤷‍♂️
English
6
170
780
57.6K