Nation-State Actor’s Arsenal: An In-Depth Look at Lazarus’ ScoringMathTea

In October 2025, the ESET Research Team published an excellent article about the identification of a new instance of the Operation DreamJob cyberespionage campaign, conducted by the Lazarus APT Group, aligned with the North Korean government. This instance was identified by ESET as Gotta Fly, as it was determined that Lazarus was directing cyberattacks with Read More… »

Mustang Panda Employ Publoader Through ClaimLoader: Yes.. another DLL Side-Loading Technique Delivery via Phishing

In this new post I will analyze, once again, an execution chain of payloads delivered via Phishing from another Threat Actor China-Nexus, however, implementing the same TTP, yes, DLL Side-Loading! In this research, I will explore a campaign by Threat Actor Mustang Panda, identified in June 2025 by IBM’s X-Force, which targets the Tibetan community Read More… »

Veletrix Loader Infection: A Look from a Digital Forensic Perspective

This analysis serves as a complementary study to my previous research on the reverse engineering of Veletrix Loader and the infrastructure analysis of the China-nexus threat actor operating this campaign. In this post, I’ll examine the Veletrix Loader infection from a digital forensics perspective, analyzing volatile memory captured from an infected system. The rationale behind Read More… »

VELETRIX Loader Dissection: Kill Chain Analysis of China-Nexus Telecommunications Infrastructure Targeting

In my work I had the opportunity to analyze a China-Nexus Threat Actor, called Earth Alux, and this research, which only covers the fundamental points of the Kill Chain and the analysis of some components of its Toolkit, was the starting point of a long process of studies on how the Chinese state invested in Read More… »

[Amadey] Targeted Analysis of its Campaign’s Kill Chain, String and Traffic Encryption Algorithm, and Download of Additional Modules

A while back, I wrote a post about my BabbleLoader research (which you can access here), where in addition to reverse engineering its defense evasion capabilities, I also analyzed the public intelligence available on how the sample I was analyzing had been delivered to victims.It was at this point that, through UnpacMe, in partnership with Read More… »

Technical Analysis of Lockbit4.0 Evasion Tales

The Ransomware-as-a-Service (RaaS) group Lockbit is the main pillar of this Ransomware business model, largely due to its strong commitment to the development of its product, producing Ransomware with implementations that are up to date on the date of each release. The Lockbit4.0 (or Lockbit Green) version is no different, as it is a major Read More… »

[BabbleLoader] A Deep Dive into EDR and Machine Learning-Based Endpoint Protection Evasion

Every now and then, some group innovates the Malware market, and it seems that the BabbleLoader developers are willing to do this, but not by discovering new evasion techniques, but rather by knowing how to use them to evade detection products that contain Machine Learning (AI). This research will cover the following topics: Below is Read More… »

Complete Course and Certification Review of Zero2Automated – The Advanced Malware Analysis

This post will be a complete review of the Zero2Automated – The Advanced Malware Analysis course, and the certification exam available at the end of the course delivered by 0ffset Training Solutions. About the Course I won’t waste your time reading obvious things that can be found in one of the links I attached above. Read More… »

[Case Study: Latrodectus] Analyzing and Implementing String Decryption Algorithms

This article has a slightly different objective than the last ones I published, it is not about an analysis of specific malware. Today’s article is about a case study of the Latrodectus string decryption algorithm (analyzed in the previous research). The objective is to study how to identify a string decryption algorithm when reverse engineering Read More… »

Latrodectus [IceNova] – Technical Analysis of the… New IcedID… Its Continuation… Or its Replacement?

My first public malware research was for a strain of IcedID. A few months later, in my nighttime activities, I was working on technical analysis research for Sodinokibi (REvil), a Ransomware that is no longer seen, however, is part of the evolutionary history of the business model that we now know as RaaS. But, I Read More… »