# rhys (blogs) — RSS Amplifier

Recent posts from the 1 feeds in the RSS Amplifier directory that cover rhys.

Page: <https://rssamplifier.com/topics/rhy/blogs>  
Feed: <https://rssamplifier.com/topics/rhy/blogs.md>

---

## [Pixels to Payload: Dissecting a Four-Stage Bitmap-Steganography Dropper Delivering AsyncRAT](https://blog.threatuniverse.co.uk/posts/asyncrat-bitmap-steganography-dropper/)

_2026-07-18 · Rhys Downing_

Note: The bulk of this analysis and write-up was produced with the Kimi K3 large language model. Summary The sample analysed here is a four-stage .NET delivery chain that deploys AsyncRAT version 0.5.8. The outer binary poses as an Armenian-language water-cycle simulation, complete with a functioning particle engine, control panel, and live charts. Its two bitmap resources are not artwork. They…

## [Dissecting a Multi-Stage macOS Infostealer](https://blog.threatuniverse.co.uk/posts/usersyncworker-macos-infostealer/)

_2025-12-23 · Rhys Downing_

Summary I recently obtained a sample of a macOS infostealer that caught my attention for its operational sophistication. What initially appeared to be a straightforward Swift downloader revealed itself to be a well-engineered three-stage attack chain with some interesting anti-analysis and evasion techniques. Concurrent analysis by Jamf Threat Labs has confirmed this sample is a variant of MacSync…

## [DeerStealer's Qihoo 360 Trojan Horse](https://blog.threatuniverse.co.uk/posts/deerstealer-qihoo-360-trojan/)

_2025-12-06 · Rhys Downing_

Summary Analysis of a trojanized MSI installer revealed an atypical antivirus evasion technique. The malware did not merely bypass detection. It weaponized a legitimately signed component from Qihoo 360 Safe, one of China&rsquo;s largest security suites, to establish persistence and attempt kernel-level access. DeerStealer, a commodity infostealer sold for $200-$3,000/month on dark web forums,…

