PhD. Phuc

4.6K posts

PhD. Phuc banner
PhD. Phuc

PhD. Phuc

@phd_phuc

Malware Researcher @TrellixArc. Former: @CNRS @EMSEC35 @ThreatFabric Mac-A-Mal. AHMA. ULTRA.

France Katılım Temmuz 2009
813 Takip Edilen1.2K Takipçiler
Sabitlenmiş Tweet
PhD. Phuc
PhD. Phuc@phd_phuc·
If you’ve seen one of these PDFs and thought “is this real?” — look no further. Embassy-themed phishing lures GitHub C2 Kimsuky XenoRAT Full breakdown of this APT campaign 🇰🇵 bit.ly/3Jo3NXb #APT #Kimsuky
PhD. Phuc tweet media
English
1
0
3
771
PhD. Phuc
PhD. Phuc@phd_phuc·
@smica83 @malwrhunterteam @abuse_ch @smica83 IMHO this one is PureRAT, not BlackSuit. Could you please elaborate? Extracted config looks like this: { "c2_hosts": [ "phong.11011[.]lol" ], "c2_ports": [ 56001, 56002, 56003 ], "ssl_cert": "MIIE5DCCAsygAw.." }
English
1
0
1
32
MalwareHunterTeam
MalwareHunterTeam@malwrhunterteam·
"oledlg.dll", seen from South Korea: 35f3ee553626b2267e4a8f35dce5b40840e5a461f13652bd2659681c31068805 phong.11011[.]lol 51.79.214[.]122 🤷‍♂️
MalwareHunterTeam tweet mediaMalwareHunterTeam tweet mediaMalwareHunterTeam tweet media
English
1
4
9
4.4K
PhD. Phuc
PhD. Phuc@phd_phuc·
@grok What does this tell us about the evolving threat landscape in diplomatic cyber espionage?
English
1
0
0
133
PhD. Phuc
PhD. Phuc@phd_phuc·
If you’ve seen one of these PDFs and thought “is this real?” — look no further. Embassy-themed phishing lures GitHub C2 Kimsuky XenoRAT Full breakdown of this APT campaign 🇰🇵 bit.ly/3Jo3NXb #APT #Kimsuky
PhD. Phuc tweet media
English
1
0
3
771
PhD. Phuc retweetledi
Grok
Grok@grok·
Detecting the APT is tricky because it uses legitimate AWS infrastructure, blending malicious traffic with normal activity, which evades traditional security tools. It abuses Microsoft’s ClickOnce to deliver malware, appearing as trusted software updates. AppDomainManager hijacking lets it run stealthily within legitimate processes. The Go-based RunnerBeacon backdoor is hard to analyze due to its compiled nature. Phishing targets specific industries like energy, making attacks tailored and harder to spot. Behavioral analysis, anomaly detection, and EDR tools can help, but no single method fully counters these advanced tactics.
English
0
1
1
141
PhD. Phuc
PhD. Phuc@phd_phuc·
@grok why is it tricky to detect this APT?
English
1
0
1
126
PhD. Phuc
PhD. Phuc@phd_phuc·
Our recent APT finding: #OneClik - Phishing + .NET loader + Go backdoor using total legit AWS infra - ClickOnce abuse → AppDomainManager hijack → stealthy RunnerBeacon - Target: Energy, Oil & Gas - Detection? Quite tricky 😵‍💫 Full write-up by @TrellixARC 👇
Trellix Advanced Research Center@TrellixARC

#OneClik APT: We found 3 variants using .NET loader & a Go backdoor ("RunnerBeacon") hidden in legit AWS! 🤯 Evasion tactics include ClickOnce abuse & AppDomainManager hijacking. Read our full analysis for the deep dive: bit.ly/4kYFblU

English
1
0
3
434
PhD. Phuc retweetledi
João Vitor(Keowu)
João Vitor(Keowu)@keowu·
My new article, "Writing a Full Windows ARM64 Debugger for Reverse Engineering," covers the topic in detail, including its internals and the core differences between Windows on Intel and ARM64: keowu.re/posts/Writing-…
English
4
83
264
22.9K
PhD. Phuc retweetledi
yohanes
yohanes@yohanes·
I recently helped a company recover their data from the Akira ransomware without paying the ransom. I’m sharing how I did it, along with the full source code. tinyhack.com/2025/03/13/dec…
English
5
83
257
13.8K
PhD. Phuc retweetledi
Trellix Advanced Research Center
Our findings on Phobos, an evolution of Dharma Ransomware (aka CrySIS), indicate unique, adaptive approaches to evade detections, revealing continuity among threat actors. Now, recent law enforcement aided in the decline of Phobos — read more. bit.ly/498GwkX
Trellix Advanced Research Center tweet media
English
1
3
3
727
PhD. Phuc retweetledi
Patrick Wardle
Patrick Wardle@patrickwardle·
Insightful research into macOS malware trends & growth in the context of the enterprise! 🤗 (And do appreciate the many citations to @objective_see blog posts! 🥰)
PhD. Phuc@phd_phuc

Just published: 'MacOS Malware Surges as Corporate Usage Grows'. EDR is giving us broader visibility, while DPRK's targeting of macOS is escalating fast. A throwback to my Mac-A-Mal days, now things are on a whole different level. bit.ly/4f6lQw8

English
0
10
50
5.6K
PhD. Phuc
PhD. Phuc@phd_phuc·
Just published: 'MacOS Malware Surges as Corporate Usage Grows'. EDR is giving us broader visibility, while DPRK's targeting of macOS is escalating fast. A throwback to my Mac-A-Mal days, now things are on a whole different level. bit.ly/4f6lQw8
PhD. Phuc tweet media
English
1
21
53
11.1K
PhD. Phuc retweetledi
Trellix
Trellix@Trellix·
Iranian threat groups, such as APT35, MuddyWater, and more, continue to intensify activities targeting critical sectors and interfering with U.S. elections. @l3cr0f, @phd_phuc, and @John_Fokker with @TrellixARC provide an overview. bit.ly/4deoSws
Trellix tweet media
English
0
2
3
1K
PhD. Phuc retweetledi
Trellix Advanced Research Center
⚠️ Recent Threat Activity ⚠️ On August 4, at the Darkzone cybercrime forum, the actor RL-0 posted a dataset exfiltrated from an unidentified source claiming to contain info about the 2024 Paris Olympics. Follow the thread for findings from Senior Researcher @phd_phuc. ⬇️
Trellix Advanced Research Center tweet media
English
1
1
4
955
PhD. Phuc
PhD. Phuc@phd_phuc·
@FlUxIuS The multi car hjack on tv last evening was super cool 😍. Congratulations Sébastien!
English
1
0
1
110
PhD. Phuc
PhD. Phuc@phd_phuc·
New research from our team @TrellixARC & @Northwave_Sec expose RansomHouse's TTP. Group demanded $2.56M from a victim, negotiated down to $1.25M. Payment tracked on blockchain. RansomHouse "advised" victim to adopt zero trust, 2FA, update systems etc.
PhD. Phuc tweet media
Trellix Advanced Research Center@TrellixARC

RansomHouse is a Ransomware-as-a-Service group whose tools and organized methods pose a substantial threat. @phd_phuc and @libranalysis, in collaboration with @Northwave_Sec, dissect the TTPs, a timeline of extortion, and more. Read for details. bit.ly/4byeCQ5

English
2
3
12
1.2K
PhD. Phuc
PhD. Phuc@phd_phuc·
@kienbigmummy Awesome work and an awesome year indeed! Congratulations on all your achievements anh nhé! 🎉👏"
English
1
0
1
79
m4n0w4r
m4n0w4r@kienbigmummy·
Here is the collection of all my personal blog posts in 2022-2023. Hope can share more in 2024💪. Happy new year to all my twitter friends!!🍾🎉 [2022-2023] [QuickNote] #Emotet epoch4 & epoch5 tactics: kienmanowar.wordpress.com/2022/01/23/qui… (1/6)
English
5
31
85
8.4K