

PhD. Phuc
4.6K posts

@phd_phuc
Malware Researcher @TrellixArc. Former: @CNRS @EMSEC35 @ThreatFabric Mac-A-Mal. AHMA. ULTRA.



SideWinder APT is evolving! Our latest @TrellixARC report, written by @phd_phuc and myself, details their new PDF+ClickOnce infection chain, bypassing traditional security targeting diplomatic entities in South Asia. trellix.com/blogs/research…






#OneClik APT: We found 3 variants using .NET loader & a Go backdoor ("RunnerBeacon") hidden in legit AWS! 🤯 Evasion tactics include ClickOnce abuse & AppDomainManager hijacking. Read our full analysis for the deep dive: bit.ly/4kYFblU







Just published: 'MacOS Malware Surges as Corporate Usage Grows'. EDR is giving us broader visibility, while DPRK's targeting of macOS is escalating fast. A throwback to my Mac-A-Mal days, now things are on a whole different level. bit.ly/4f6lQw8










RansomHouse is a Ransomware-as-a-Service group whose tools and organized methods pose a substantial threat. @phd_phuc and @libranalysis, in collaboration with @Northwave_Sec, dissect the TTPs, a timeline of extortion, and more. Read for details. bit.ly/4byeCQ5

