RSSAmplifier

Blog

[0x0v1]

Blog of researcher & writer Ovi {O-vie}. Disrupting APTs, hostile gov'ts, surveillance, privacy violations, centralization & corporate injustice.

0x0v1.comRSS feed ↗15 posts

Latest posts

New Kimsuky Malware “EndClient RAT”: First Technical Report and IOCs

Introduction I have had the pleasure to work with PSCORE for quite some time now and we recently did a talk at RightsCon together about the cyber security dynamics for human rights in Korea . PSCORE's work spans to many angles surrounding from child labour abuse to internet freedoms

Proximity and power: civil society’s role in democratizing spyware research

Threat intelligence today is a commodity. It is monetized, gated, and shaped to fit the needs of commercial clients before communities. It's a product, collected and tracked to be baked into security products & to protect share holders. Before it defends anybody, it has to turn a profit.

[0x0v1] Newsletter | RightsCon, Meta's "Threat Ideation(??)" and democratizing spyware forensics

Yeah that's me, up there, on a stage. Beige all around me, repping McModernism. As a conference speaker and attendee for the better part of a decade, I’ve learned to brace for the usual: soulless, windowless auditoriums and a thick fog of corporate greenwashing and rights-

Targeted Threats Research - South & North Korea (a breakdown of 3 years of civil society threat research in Korea)

This research will be discussed at RightsCon 2025: Unveiling North Korea’s cyber threats: safeguarding human rights Sections: Executive Summary Introduction Methodology Sample submission Auditing Malware analysis Email Content analysis Passive DNS & open-source threat intelligence Data Overview Cluster analysis MITRE ATTACK framework Analysis of pre & primary

[0x0v1] Newsletter | Disabling TLS Certificate Checks in Flutter (BoringSSL) with Frida

Server-side Device Validation Protocols in High-Security Android Applications - Cashapp, Revolut, Banking, Healthcare, Government etc.

In my previous two posts about Android emulator bypassing ( Android Network Emulator Bypassing for high security apps - Cashapp, Revolut, Banking, Healthcare, Government etc. & Advanced Android Emulator Bypass Techniques for High-Security Apps: CashApp, Revolut, Healthcare & More ), I discussed methodologies to bypass emulator detection in high-security banking and

[0x0v1] Newsletter | Avoid WhatToExpect pregnancy app, if you care about your privacy & security

There's snow outside today as winter closes in, and it's feeling pretty cozy. I'm sitting here with a coffee, starting to write some proposals for civic society groups, and it's been on my mind to write about the WhatToExpect palaver. In my

[0x0v1] Newsletter | General update November 2024

RE:privacy | Critical vulnerabilities & privacy concerns in WhatToExpect fertility app

A high level summary of this issue is provided below. A deep technical breakdown of the vulnerabilities is provided later on to supporters of my work. Executive Summary This research reveals several critical vulnerabilities in the WhatToExpect application, exposing users’ sensitive personal and reproductive health information to potential misuse

Android Network Emulator Bypassing for high security apps - Cashapp, Revolut, Banking, Healthcare, Government etc.

Learn to bypass emulator detection in high-security Android apps using network techniques like SSL unpinning, IP spoofing, and request modification. This guide offers practical methods for intercepting traffic and making emulators look like real devices.

Advanced Android Emulator Bypass Techniques for High-Security Apps: CashApp, Revolut, Healthcare & More

Introduction Apps handling our most sensitive data—whether managing financial transactions in CashApp , Revolut , or other banking platforms, or safeguarding personal records in healthcare applications—often employ robust emulation detection mechanisms . These defenses are designed to thwart unauthorized tampering, reverse engineering, and porting across unapproved environments,…

[0x0v1] Newsletter | General update October 2024

UCID902: Uncovering nation state watering hole credential harvesting campaigns targeting human rights activists by APT threat group UCID902 (2023)

This is a repost of some critical research I performed back in 2023 that was originally hosted on Interlab's website. Since Interlab has been abandoned by it's owner and thus shut down the website, I'm posting it here to ensure the research I ( solely

Security and privacy analysis: MDM applications (국방모바일보안) for South Korean Military personnel (2023)

This is a repost of some critical research I performed back in 2023 that was originally hosted on Interlab's website. Since Interlab has been abandoned by it's owner and thus shut down the website, I'm posting it here to ensure the research I performed

RambleOn Android Spyware (December 2022)

This is a repost of some critical research I performed back in 2022 that was originally hosted on Interlab's website. Since Interlab has been abandoned by it's owner and thus shut down the website, I'm posting it here to ensure the research I performed