RSSAmplifier

Blog

Synaptic Security Blog

blog.synapticsystems.deRSS feed ↗10 posts

Latest posts

Wenn der Staat das Licht ausmacht: Warum die IFG-Novelle die deutsche Threat-Intelligence-Arbeit trifft

by Robin Dost Ein Kommentar aus der Praxis der Cyber Threat Intelligence PETITION UNTERSCHREIBEN This article is written in German, since it concerns German domestic policy and legislation. If you d like to read it in English, you can do it here. Am 2. Juli 2026 hat der Koalitionsausschuss von CDU, CSU und SPD unter Punkt [ ] The post Wenn der Staat das Licht ausmacht: Warum die IFG-Novelle die…

Inside Kimsuky’s CHM Tradecraft: Multi-Stage Execution and Selective Payload Delivery

by Robin Dost Actor tracking: APT43 (Kimsuky) / MB-0010 I can t sleep right now, because it s too hot in Germany, so i thought why not finishing an analysis i almost forgot about. In this analysis i am using Malwarebox Tooling for most of my work. Everything started with a suspicious CHM sample arriving in MANTIS.SHA256: 0efbd18c77479b458078521c18bdad84852b71250122a17cb8105c10d3df38d4 [ ] The post…

UAC-0184 Tooling Evolution: OneDrive Sideload to Remcos

by Robin Dost Malware: HijackLoader / IDATLoader - Remcos Agent 7.1.0 ProActor tracking: UAC-0184 / MB-0005Related analysis: UAC-0184: From HTA to a Signed Network StackA YARA rule for this sample is available on request: contact@robin-dost.de. In my previous UAC-0184 analysis, I documented a loader chain built around a legitimate Plane9 application, several local payload containers [ ] The post…

Tracking UAC-0226 Tooling Evolution: From WinRAR ADS to Reflective GIFTEDCROOK Loading

by Robin Dost A few months ago, I analyzed a UAC-0226 campaign delivering a GIFTEDCROOK stealer through a weaponized WinRAR archive.Of course, that wasn t it yet, we re going to keep tracking our friends, so let s go 🙂 The chain was relatively simple: Sample: 420f1931af9b3f7d02c5edfc78eb69abdad6e71d2c3e9b81f9cbc3823a503654 The sample discussed here follows the same general idea, but the [ ] The…

GhostShell (MB-0009): Targeting Ukraine’s UAV Operations and Defense Supply Chain

by Robin Dost Today, we are taking a look at malware linked to yet another threat actor, one that has been active since at least February 2026. Since I could not associate the malware with any previously attributed threat actor, I am naming the actor GhostShell (you’ll find out why later in this article) and [ ] The post GhostShell (MB-0009): Targeting Ukraine’s UAV Operations and Defense Supply…

IIM Feed: Attack Pattern Mapping for Adversary Infrastructure (5/7)

by Robin Dost Part 5 of 7 of building the Malwarebox EcosystemURL: https://feed.iim.malwarebox.euMalwarebox: https://malwarebox.euIIM: https://iim.malwarebox.euIIM Spec: https://github.com/MalwareboxEU/IIM I have been working on IIM for a while now, mostly because adversary infrastructure is still weirdly underrepresented in public CTI.If you track adversaries, you re probably familiar with the…

UAC-0244 / UAC-0247: Malware Targeting FPV drone operators

by Robin Dost Surprise, surprise a new UAC article 😁 Actor: UAC-0244 / UAC-0247 / MB-0006Malwarebox Identifier: 0006IIM Chain: https://feed.iim.malwarebox.eu/chain/uac-0247-ukrvarta-fpv-dopomoga-2026-03 This article is a little bit older, mainly because I have been spending a lot of time on Malwarebox and several other articles recently. It is also part of my UAC series, where I [ ] The post…

UAC-0184: From HTA to a Signed Network Stack

by Robin Dost EDIT: The next article in my UAC series is out: https://blog.synapticsystems.de/uac-0247-malware-targeting-fpv-operators/ Actor: UAC-0184 / MB-0007 (Malwarebox IDIIM Chain: https://feed.iim.malwarebox.eu/chain/uac-0184-pseudo-png-passmark-2026-05 In the last articles, I spent quite some time looking at actors that primarily target Ukraine. Gamaredon and APT28 are the obvious names…

IIMQL – The Query Language for Adversary Infrastructure (4/7)

by Robin DostPart 4 of 7 of building the Malwarebox EcosystemWebsite: https://iimql.malwarebox.euGitHub: https://github.com/MalwareboxEU/IIMQL In the previous part, I introduced IIM, the Infrastructure Intelligence Model. But once you have a structure, the next obvious question is: How do you search it? Because describing one chain is nice.Describing ten chains is useful.Describing a few thousand…

IIM – The Grammar of Adversary Infrastructure (3/7)

by Robin Dost Part 3 of 7 of building the Malwarebox EcosystemOfficial Website: https://iim.malwarebox.euGitHub: https://github.com/MalwareboxEU/IIM EDIT: I released part 4 / 7 IIMQL – The Query Language for Adversary Infrastructure (4/7) Threat intelligence has a small problem. We have more data than ever. Blocklists with millions of entries. Feeds that refresh every thirty seconds. Vendors [ ]…