Nation-State Actor’s Arsenal: An In-Depth Look at Lazarus’ ScoringMathTea

In October 2025, the ESET Research Team published an excellent article about the identification of a new instance of the Operation DreamJob cyberespionage campaign, conducted by the Lazarus APT Group, aligned with the North Korean government. This instance was identified by ESET as Gotta Fly, as it was determined that Lazarus was directing cyberattacks with Read More… »

Mustang Panda Employ Publoader Through ClaimLoader: Yes.. another DLL Side-Loading Technique Delivery via Phishing

In this new post I will analyze, once again, an execution chain of payloads delivered via Phishing from another Threat Actor China-Nexus, however, implementing the same TTP, yes, DLL Side-Loading! In this research, I will explore a campaign by Threat Actor Mustang Panda, identified in June 2025 by IBM’s X-Force, which targets the Tibetan community Read More… »

Veletrix Loader Infection: A Look from a Digital Forensic Perspective

This analysis serves as a complementary study to my previous research on the reverse engineering of Veletrix Loader and the infrastructure analysis of the China-nexus threat actor operating this campaign. In this post, I’ll examine the Veletrix Loader infection from a digital forensics perspective, analyzing volatile memory captured from an infected system. The rationale behind Read More… »

VELETRIX Loader Dissection: Kill Chain Analysis of China-Nexus Telecommunications Infrastructure Targeting

In my work I had the opportunity to analyze a China-Nexus Threat Actor, called Earth Alux, and this research, which only covers the fundamental points of the Kill Chain and the analysis of some components of its Toolkit, was the starting point of a long process of studies on how the Chinese state invested in Read More… »