Karsten Hahn

9.4K posts

Karsten Hahn banner
Karsten Hahn

Karsten Hahn

@struppigel

MalwareAnalysisForHedgehogs, Principal Malware Researcher at GDATA, he/him 🦔🌈🏳️‍⚧️

International Katılım Mayıs 2014
787 Takip Edilen25.7K Takipçiler
allthingsida
allthingsida@allthingsida·
I did not know Ghidra does that. Sorry, if this is silly, I stumbled upon it by accident.
English
10
54
1K
64.9K
Karsten Hahn
Karsten Hahn@struppigel·
New Video: Build your own LLM dynamic analysis lab 🦔🎥 ➡️ AI debugs and unpacks with x64dbg ➡️ AI can access powershell terminal youtube.com/watch?v=QrWzRg…
YouTube video
YouTube
English
0
32
95
7.6K
Karsten Hahn retweetledi
vx-underground
vx-underground@vxunderground·
Mr. Titus Tech is correct. cpuid-dot-com is indeed delivering malware right now. As I began poking this with I stick I discovered this is not your typical run-of-the-mill malware. This malware is deeply trojanized, distributes from a compromised domain (cpuid-dot-com), performs file masquerading, is multi-staged, operates (almost) entirely in-memory, and uses some interesting methods to evade EDRs and/or AVs such as proxying NTDLL functionality from a .NET assembly. The C2 domain present in one of the binaries is a clear IoC. This is the same Threat Group who was masquerading FileZilla in early March, 2026. They've been busy.
vx-underground tweet media
Chris Titus Tech@christitustech

HWInfo and CPU-Z both compromised. Millions about to be PWNED! CPU Z: hybrid-analysis.com/sample/eff5ece… HW Monitor: hybrid-analysis.com/sample/4968501…

English
120
991
8K
1.6M
SOC Prime
SOC Prime@SOC_Prime·
@struppigel You are right that the source attribution is not visible enough on the page. We appreciate the feedback and will use it to improve how source authors and original research are credited in the UX. Thank you!
English
1
0
2
82
Karsten Hahn
Karsten Hahn@struppigel·
My colleagues have worked hard on analysing and writing a blog article on Kiss Loader. But on your site you make it look like this was your analysis work. Please fix that, @SOC_Prime The person below did not write the KISS loader article with that title.
Karsten Hahn tweet media
English
2
6
53
4.7K
Karsten Hahn
Karsten Hahn@struppigel·
@bbaskin Bad example. Detection as "GameHack" is accurate and is not a malware verdict.
English
1
0
3
283
Brian Baskin
Brian Baskin@bbaskin·
As a malware analyst I am uniquely qualified to explain that a file with a Virustotal score of 30/72 is actually legit
Brian Baskin tweet media
English
41
34
1.2K
116.5K
Karsten Hahn
Karsten Hahn@struppigel·
Whilst there is a small link to gdata on the top right, there is no indication what that means, and I did not notice that link for the first 20 min. My colleagues are not mentioned anywhere in the text. This is the original: blog.gdatasoftware.com/2026/03/38399-…
English
0
3
25
1.7K
Karsten Hahn retweetledi
Tim Blazytko
Tim Blazytko@mr_phrazer·
The recording of my first Binary Cartography webinar is now public: Agentic Reverse Engineering: How AI Agents Are Changing Binary Analysis Topics: keygenning, cracking & anti-tamper removal Recording: youtube.com/watch?v=DZcDaX… Slides/code/samples: github.com/mrphrazer/bina…
YouTube video
YouTube
English
4
117
404
39.6K
vx-underground
vx-underground@vxunderground·
I don't understand what I'm doing wrong. I try, and try, and try, and I still don't have any success. I don't know if people are born privileged, or if it's my bad luck, or maybe I just suck... But some how people are getting free malware on the internet and I'm not not
vx-underground tweet media
English
20
14
565
64.6K
vx-underground
vx-underground@vxunderground·
tl;dr normie to big stinky nerd translator I'm going to share something embarrassing, but this is true. I have found a good usage of AI (for me, at least). I'm a big stinky nerd and I have a hard time understanding what people are saying to me. I am an extremely explicit communicator. I usually say exactly what I mean (for better or worse). I get very confused when people imply something, or lean heavily on emotional phrasing, to implicitly communicate. I have been unironically using AI to explain what people are saying to me. I'll detail the conversation to the best of my ability if it was communicated verbally, if it was online I copy-paste my message and the persons response (or comment). The silly AI slop robot then translates what the person says into explicit communication for me so I understand better. Basically, the dumb ass slop machine robot is better at understanding humans than me. Sometimes I have zero idea what someone is talking about or trying to convey. pic related: machine deciphering human language and explaining to my dumb nerd brain
vx-underground tweet media
English
46
18
843
32K
Karsten Hahn retweetledi
Kostas
Kostas@Kostastsale·
Today I’m launching Threat Hunting Labs. Over the years I’ve analyzed many real-world intrusions. One thing became obvious: most training platforms don’t resemble how investigations actually happen. So I built something different. Threat Hunting Labs focuses on investigation-driven learning using real telemetry and structured investigative paths. If you want to get better at investigating breaches, you should practice investigating breaches. More details here: threathuntinglabs.com/blog/introduci…
English
21
116
586
46.9K
Karsten Hahn
Karsten Hahn@struppigel·
@RussianPanda9xx Wrinkles that were deepened from smiling a lot during your life are a very charismatic feature and interesting to look at. I have a deep "third eye" / brooding wrinkle between my eyebrows, not sure if I am happy about it, but it's accurate.
English
1
0
7
562
Karsten Hahn retweetledi
vx-underground
vx-underground@vxunderground·
I am genuinely impressed by mainstream media outlets ability to find absolute nobodies in cybersecurity. It's remarkable. I am often left speechless. There has been dozens occasions, especially as of recent, where some media outlet will be like, "Today as a special guest is world-renowned cybersecurity expert and ethical hacker Joe McCyberSecurity". I'm like, who the fuck is Joe McCybersecurity? I've been doing cybersecurity and malware stuff for a long time and I've never once seen or heard of Joe McCybersecurity. If he is world-renowned, I would THINK I would have seen them or heard of them. The camera then pans over to Joe McCybersecurity and it is the most generic cookie cutter white dude in a cheap suit and the tag below him will say something like, "Joe McCybersecurity, Ethical Hacker, CEO of Cybersecurity McJoe Industries" I'm like, "Cybersecurity McJoe Industries? What the fuck is that?". I look it up and it's a generic WordPress website hosted on GoDaddy with an expired SSL cert. Joe McCybersecurity then babbles incomprehensible nonsense for about 60 seconds until the TV host goes "woaw" and it cuts to a commercial. Absolute cinema.
English
112
150
2.3K
91K