by Robin Dost Ein Kommentar aus der Praxis der Cyber Threat Intelligence PETITION UNTERSCHREIBEN This article is written in German, since it concerns German domestic policy and legislation. If you d like to read it in English, you can do it here. Am 2. Juli 2026 hat der Koalitionsausschuss von CDU, CSU und SPD unter Punkt [ ] The post Wenn der Staat das Licht ausmacht: Warum die IFG-Novelle die…
by Robin Dost Actor tracking: APT43 (Kimsuky) / MB-0010 I can t sleep right now, because it s too hot in Germany, so i thought why not finishing an analysis i almost forgot about. In this analysis i am using Malwarebox Tooling for most of my work. Everything started with a suspicious CHM sample arriving in MANTIS.SHA256: 0efbd18c77479b458078521c18bdad84852b71250122a17cb8105c10d3df38d4 [ ] The post…
by Robin Dost Malware: HijackLoader / IDATLoader - Remcos Agent 7.1.0 ProActor tracking: UAC-0184 / MB-0005Related analysis: UAC-0184: From HTA to a Signed Network StackA YARA rule for this sample is available on request: contact@robin-dost.de. In my previous UAC-0184 analysis, I documented a loader chain built around a legitimate Plane9 application, several local payload containers [ ] The post…
by Robin Dost A few months ago, I analyzed a UAC-0226 campaign delivering a GIFTEDCROOK stealer through a weaponized WinRAR archive.Of course, that wasn t it yet, we re going to keep tracking our friends, so let s go 🙂 The chain was relatively simple: Sample: 420f1931af9b3f7d02c5edfc78eb69abdad6e71d2c3e9b81f9cbc3823a503654 The sample discussed here follows the same general idea, but the [ ] The…
by Robin Dost Today, we are taking a look at malware linked to yet another threat actor, one that has been active since at least February 2026. Since I could not associate the malware with any previously attributed threat actor, I am naming the actor GhostShell (you’ll find out why later in this article) and [ ] The post GhostShell (MB-0009): Targeting Ukraine’s UAV Operations and Defense Supply…
by Robin Dost Part 5 of 7 of building the Malwarebox EcosystemURL: https://feed.iim.malwarebox.euMalwarebox: https://malwarebox.euIIM: https://iim.malwarebox.euIIM Spec: https://github.com/MalwareboxEU/IIM I have been working on IIM for a while now, mostly because adversary infrastructure is still weirdly underrepresented in public CTI.If you track adversaries, you re probably familiar with the…
by Robin Dost Surprise, surprise a new UAC article 😁 Actor: UAC-0244 / UAC-0247 / MB-0006Malwarebox Identifier: 0006IIM Chain: https://feed.iim.malwarebox.eu/chain/uac-0247-ukrvarta-fpv-dopomoga-2026-03 This article is a little bit older, mainly because I have been spending a lot of time on Malwarebox and several other articles recently. It is also part of my UAC series, where I [ ] The post…
by Robin Dost EDIT: The next article in my UAC series is out: https://blog.synapticsystems.de/uac-0247-malware-targeting-fpv-operators/ Actor: UAC-0184 / MB-0007 (Malwarebox IDIIM Chain: https://feed.iim.malwarebox.eu/chain/uac-0184-pseudo-png-passmark-2026-05 In the last articles, I spent quite some time looking at actors that primarily target Ukraine. Gamaredon and APT28 are the obvious names…
by Robin DostPart 4 of 7 of building the Malwarebox EcosystemWebsite: https://iimql.malwarebox.euGitHub: https://github.com/MalwareboxEU/IIMQL In the previous part, I introduced IIM, the Infrastructure Intelligence Model. But once you have a structure, the next obvious question is: How do you search it? Because describing one chain is nice.Describing ten chains is useful.Describing a few thousand…
by Robin Dost Part 3 of 7 of building the Malwarebox EcosystemOfficial Website: https://iim.malwarebox.euGitHub: https://github.com/MalwareboxEU/IIM EDIT: I released part 4 / 7 IIMQL – The Query Language for Adversary Infrastructure (4/7) Threat intelligence has a small problem. We have more data than ever. Blocklists with millions of entries. Feeds that refresh every thirty seconds. Vendors [ ]…