Skip to content

Breaking

Copy/Paste Technique Used to Deliver XWORM PDF Lure Delivering GoTo (LogMeIn) RMM Unsuccessful Crypto Phishing Attempt on Me SVG Capabilities and Behaviors Updated LandUpdate808 Analysis

Malasada Tech

Da Samala Tech blogs on malware and stuffs

Malasada Tech

Da Samala Tech blogs on malware and stuffs

  • Home
  • About
CopyPaste

Copy/Paste Technique Used to Deliver XWORM

Aaron Samala May 16, 2025 No Comments

XWORM is observed being distributed via Copy/Paste. XWORM C2 traffic uses a pattern that can be matched. Using Discord webhooks for C2 is not new, but it’s new to me.…

Threat Intelligence

PDF Lure Delivering GoTo (LogMeIn) RMM

Aaron Samala May 12, 2025 No Comments

This documents chrunting for delivery sites that connect to api.telegramorg, finding a malicious GoTo RMM, and developing masq-monitor and Snort/Suricata detections. Tactical Pause THE CONTENT, VIEWS, AND OPINIONS EXPRESSED ON…

Phishing

Unsuccessful Crypto Phishing Attempt on Me

Aaron Samala April 7, 2025 No Comments

This documents the analysis I performed on a crypto phishing domain that a phisher DM’d me. It documents how I was able to pivot on file hashes the site served,…

Malware Research Phishing

SVG Capabilities and Behaviors

Aaron Samala March 16, 2025 No Comments

TL;DR This documents my research into three methods an attacker could use, with an SVG file, in a phishing attack to direct the victim to the next stage in the…

ClickFix LandUpdate808 Malware Research

Updated LandUpdate808 Analysis

Aaron Samala January 5, 2025 No Comments

It’s been a while since I’ve posted about LandUpdate808. There was a compromised site that is local to Hawaii that I recently noticed, and it prompted me to research the…

ClickFix Malware Research Phishing

ClickFix Delivery Initiated via Phishing Email

Aaron Samala December 28, 2024 No Comments

TL;DR Phishing email uses ClickFix to initiate multi-stage delivery (incomplete analysis at final stage). Tactical Pause THE CONTENT, VIEWS, AND OPINIONS EXPRESSED ON THIS DOCUMENT ARE MY OWN AND DO…

Threat Intelligence

Silent Push to find SmartApeSG, LandUpdate808, and TA582 Infra

Aaron Samala December 27, 2024 1 Comment

Using Silent Push to find the following infrastructure TL;DR You can use Silent Push’s query builder to monitor certain adversary infrastructure based on simple properties such as ASN, name server,…

Lumma Stealer Threat Intelligence

Lumma Stealer Delivered via YouTube Videos for Cheats

Aaron Samala November 28, 2024 No Comments

TL;DR / Summary Up Front ALOHA! This shows how you can take WatchingRac‘s post, create a profile of the delivery behavior, and search YouTube for slight variations to find other…

ClickFix Threat Intelligence

ClickFix Baddys via RussianPanda’s Workflow

Aaron Samala November 26, 2024 No Comments

TL;DR This documents specific steps you can take to find ClickFix infrastructure via RussianPanda‘s workflow. Summary Up Front This document builds on RussianPanda’s workflow to find ClickFix infrastructure. You can…

Threat Intelligence

Open Directory Search Leads to Aged APT-C-35 Findings

Aaron Samala November 24, 2024 No Comments

TL;DR I saw a post on X that inspired me to search Shodan. I found an open directory associated with APT-C-35 (attribution based on file hashes that were listed in…

Posts pagination

1 2 … 4

Next Page »

Recent Posts

  • Copy/Paste Technique Used to Deliver XWORM
  • PDF Lure Delivering GoTo (LogMeIn) RMM
  • Unsuccessful Crypto Phishing Attempt on Me
  • SVG Capabilities and Behaviors
  • Updated LandUpdate808 Analysis

Recent Comments

  1. Updated LandUpdate808 Analysis - Malasada Tech on Silent Push to find SmartApeSG, LandUpdate808, and TA582 Infra
  2. Navy Federal Credit Union Masquerades Found! - Malasada Tech on USAA Masquerades Found!
  3. Aaron Samala on USAA Masquerades Found!
  4. Emiliano Carlesi on USAA Masquerades Found!
  5. Gootkit is broken right now - Malasada Tech on Gootloader Isn’t Broken

Archives

  • May 2025
  • April 2025
  • March 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024

Categories

  • ClickFix
  • CopyPaste
  • Cybersecurity Trends
  • Gootkit
  • Gootloader
  • Gootloader Backlinks
  • LandUpdate808
  • Lumma Stealer
  • Malware Research
  • Phishing
  • Skimmer
  • SocGholish
  • Threat Intelligence

You Missed

CopyPaste

Copy/Paste Technique Used to Deliver XWORM

Threat Intelligence

PDF Lure Delivering GoTo (LogMeIn) RMM

Phishing

Unsuccessful Crypto Phishing Attempt on Me

Malware Research Phishing

SVG Capabilities and Behaviors

Malasada Tech

Da Samala Tech blogs on malware and stuffs

Copyright © All rights reserved | Blogarise by Themeansar.