Note: The bulk of this analysis and write-up was produced with the Kimi K3 large language model. Summary The sample analysed here is a four-stage .NET delivery chain that deploys AsyncRAT version 0.5.8. The outer binary poses as an Armenian-language water-cycle simulation, complete with a functioning particle engine, control panel, and live charts. Its two bitmap resources are not artwork. They…
Summary I recently obtained a sample of a macOS infostealer that caught my attention for its operational sophistication. What initially appeared to be a straightforward Swift downloader revealed itself to be a well-engineered three-stage attack chain with some interesting anti-analysis and evasion techniques. Concurrent analysis by Jamf Threat Labs has confirmed this sample is a variant of MacSync…
Summary Analysis of a trojanized MSI installer revealed an atypical antivirus evasion technique. The malware did not merely bypass detection. It weaponized a legitimately signed component from Qihoo 360 Safe, one of China’s largest security suites, to establish persistence and attempt kernel-level access. DeerStealer, a commodity infostealer sold for $200-$3,000/month on dark web forums,…
About This Blog Welcome to my corner of the cybersecurity universe! This is a dedicated space for threat intelligence, threat/security research, and everything related to the ever-evolving world of cybersecurity. About Me I’m Rhys Downing, a cybersecurity professional specializing in threat research and security operations. My work involves analyzing emerging threats, investigating security…
Note: Please bear in mind that this is my first time publishing an analysis like this, and there may be mistakes. Therefore, please let me know if any facts are incorrect so that they can be corrected. Introduction This originated from a Microsoft Defender for Endpoint alert, where it was identified as a threat actor on one endpoint. The threat actor is labelled as Storm-1113. According to…