RSSAmplifier

Blog

haxrob

Telco / mobile and IoT security. Surfing the information super highway one keystroke at a time.

haxrob.netRSS feed ↗15 posts

Latest posts

Hiding in plain sight - Mount namespaces

An exceptionally stealthy technique to hide files and masquerade processes on Linux systems

BPFDoor - Part 2 - The Present

Despite the venerable BPFDoor malware has once again found itself in the media spotlight . Recent variants avoid existing detections, so we will take a look at samples found in significant telecommunications provider breach in April 2025. 💡 Recommended for prior reading: Trend Micro (2025), Sandfly Security (2022), Elastic (2022). Detection

BPFDoor - Part 1 - The Past

An exploration into the archeological roots of the BPFDoor Linux malware.

FASTCash for Linux

Analysis of a newly discovered Linux based variant of the DPRK attributed FASTCash malware along with background information on payment switches used in financial networks.

Hiding in plain sight - Abusing the dynamic linker

A stealthy process stomping method compatible with UNIX-like systems with anti-forensic enhancements for Linux.

Hiding in plain sight: Modifying process names in UNIX-like systems

Exploring ways malware on Linux and other UNIX-like systems can disguise their process names.

How did Facebook intercept their competitor's encrypted mobile app traffic?

A technical investigation into information uncovered in a class action lawsuit that Facebook had intercepted encrypted traffic from user's devices running the Onavo Protect app in order to gain competitive insights.

GTPDOOR - A novel backdoor tailored for covert access over the roaming exchange

Discovery and analysis of a magic packet type implant that communicates C2 traffic over the GTP-C 3GPP protocol.

Gamified tooth brushing

A quick look into a connected toothbrush. Surprisingly this one was rather well behaved.

Battling the dynamic linker with lazy bindings and the AFL++ fuzzer

Notes on fuzzing with AFL and shared libraries can't resolve symbols

BM2 - Dumping and modifying the battery monitor firmware

Part 4 of the battery monitor series - Two methods to obtain the firmware from the hardware for analysis and modification

That battery monitor that spied on it's users. What happened after it was exposed?

8th May 2024 - The following is an "archive" of the investigation done live over X / Twitter to find out what changes had been made after my expose on a popular car battery monitor which you can read here . At the time of the original postings, it had garnished

A smart Wi-Fi power plug that almost killed me (literally)

Exploring a Smart Wi-Fi plug when something goes very wrong ..

Mate, your smart lightbulb is tracking your location

Answering a friends question on why his lightbulb app was asking for location permissions. An archive of the "live tweeting" which lead to the answer ...

BM2 - Reversing the BLE protocol of the BM2 Battery Monitor

Part 3 of the battery monitor series -Analysing the BLE protocol in a car battery monitor to set the foundations to replace the application which tracks user’s location