@craiu

Cybersecurity researcher focused on threat intel & APTs. Breaking down attacks, hunting threats, and crafting YARA rules. Buddy @ Three Buddy Problem

Bucharest
Joined October 2007
Costin Raiu retweeted
I ran variant analysis across all historical versions of Balad, Neshan, Tapsi & Snapp Android apps. None had similar malicious behavior as Divar in their history. Other interesting things came up, but none are necessarily malicious and are more like vendor (legitimate) shenanigans. 103 APKs reviewed so far. Many more to cover, if going back further in date becomes necessary like Divar. I'll publish the report for that later tonight as well.
1
3
42
1,769
Costin Raiu retweeted
I'm creating a full kill-chain lab for the Divar app compromise case, which I find extremely interesting. Depending on how Divar decides to release IoCs or OneSignal notification logs and artifacts, this one is going to stay in cyber pew pew history books. The genius in the whole chain IMO, is that you can have stable precision targeting of individual users, which their device IDs are linked to PII. I'll obviously not release a sandbox escape and LPE with it, but the demo message and binary serves the purpose.
4
3
1
40
2,491
Costin Raiu retweeted
btw I think this is a mistake. The relatively small but strong MoE model does have a lot of purpose, and it's shame no one thinks it's relevant anymore. It would also be perfect for the upcoming 64 GB DGX Spark. It's not too late to change your mind @Alibaba_Qwen @QwenDevs Pls reconsider releasing Qwen4-35B.
Bad news There probably won't be any new 35B MoE from Qwen anymore. That's too bad. The 35B was awesome.
16
3
121
12,805
Costin Raiu retweeted
Too lazy to write it all myself, so I tasked my minions to draft a summary report about the case: darkcell.se/divar This is all based on observations from APK binaries. Divar's side of the story and their internal investigations, which has triggered the clean update release, should paint a much better picture about this VERY interesting incident.
During the IR/IL war, I highlighted why a compromise of the Bad-e-Saba mobile app could matter for wartime tracking and effects delivery. A recently rushed update of Divar mobile app seem to be showing a similar but much worse pattern. ⚠️This is my speculation, not fact, that this case is a state-sponsored compromise!⚠️ Their app (and safe to assume their entire infrastructure) was compromised and backdoored. The backdoor basically allows specially crafted and encoded push notification, to specific/all users, to deliver a payload to the app, which is then exected on the mobile device. Neat delivery and C2 mechansim! The app versions released between Nov 2025 and Sep 2026 were compromised. Considering their massive used base (claimed 30+ Million), this could have been a hell of a targeting and pre-positioning oportunity before the war. It might sound puzzling why a second-hand marketplace website and mobile app might be an interesting target? What can you even do with code-execution on a grandma's phone selling her old squeaky sofa? Any database or platform that can directly link an identifier to an individual or location is the intelligence equivalent of digital gold. Want to track an individual, or a cluster of people, based on any PII (personally identifiable information)? Divar and similar platforms are just perfect for that. Now consider that many of those users also have the app installed on their phones. You’ve identified and clustered some of them, and you want more data from their devices—or, potentially, live tracking, a hot mic, or anything in between. That's why you insert such covert capability into their app. You no longer would need expensive 0-click Android or iOS chains and risk burning them. You can target any specific user and run arbitrary code on the device. The code can be a local privilege escalation exploit (which is MUCH cheaper & easier to maintain) and you're pretty much done! The genius behind this whole chain, and the timing of infections, makes me consider it extremely unlikely for this to be just a simple nasty developer's approach to a problem that I can't even imagine what it could have been. Notification messages are logged on both devices and backend, in multiple places. I guess we have to hope Divar will release a proper analysis report of this case. In reality however, chances of hearing anything back is as high as any other notable incident during the same timeframe. nearly zero.
7
1
37
2,539
Costin Raiu retweeted
GLM 5.3 Flash on TensorFold v1.4 is out 🔥 This is a MAJOR release, with a lot of changes, additions, and fixes, starting with the quant. - NEW EXL3 quant optimized for TensorFold! - Same size, same speed, better quality. 3x DGX Sparks support: - New TP=3 path - Around 6M KV cache - 77 tok/s on prose, single stream - 146 tok/s on prose, 4 concurrent stream - Prefill up to 2064 tp/s New features / fixed issues: - Concurrency issues were completely fixed! - Improvements and fixes in tool calling. - Stability and diagnostics improvements. Special thanks to @YasaarBiladama for letting me use his 2x RTX 6000 PRO server to create the my EXL3 quant! mia-ai.net/models/GLM-5.3-Fl…
34
26
13
289
56,252
Costin Raiu retweeted
During the IR/IL war, I highlighted why a compromise of the Bad-e-Saba mobile app could matter for wartime tracking and effects delivery. A recently rushed update of Divar mobile app seem to be showing a similar but much worse pattern. ⚠️This is my speculation, not fact, that this case is a state-sponsored compromise!⚠️ Their app (and safe to assume their entire infrastructure) was compromised and backdoored. The backdoor basically allows specially crafted and encoded push notification, to specific/all users, to deliver a payload to the app, which is then exected on the mobile device. Neat delivery and C2 mechansim! The app versions released between Nov 2025 and Sep 2026 were compromised. Considering their massive used base (claimed 30+ Million), this could have been a hell of a targeting and pre-positioning oportunity before the war. It might sound puzzling why a second-hand marketplace website and mobile app might be an interesting target? What can you even do with code-execution on a grandma's phone selling her old squeaky sofa? Any database or platform that can directly link an identifier to an individual or location is the intelligence equivalent of digital gold. Want to track an individual, or a cluster of people, based on any PII (personally identifiable information)? Divar and similar platforms are just perfect for that. Now consider that many of those users also have the app installed on their phones. You’ve identified and clustered some of them, and you want more data from their devices—or, potentially, live tracking, a hot mic, or anything in between. That's why you insert such covert capability into their app. You no longer would need expensive 0-click Android or iOS chains and risk burning them. You can target any specific user and run arbitrary code on the device. The code can be a local privilege escalation exploit (which is MUCH cheaper & easier to maintain) and you're pretty much done! The genius behind this whole chain, and the timing of infections, makes me consider it extremely unlikely for this to be just a simple nasty developer's approach to a problem that I can't even imagine what it could have been. Notification messages are logged on both devices and backend, in multiple places. I guess we have to hope Divar will release a proper analysis report of this case. In reality however, chances of hearing anything back is as high as any other notable incident during the same timeframe. nearly zero.
اجرای کد از راه دور در اپلیکیشن دیوار مربوط به پیامک امنیتی دیوار در بررسی به یک زنجیره غیرعادی در کد Android رسیدم که در صورت دریافت یک Intent با الگوی مشخص، می‌تواند به دریافت و اجرای کد از یک منبع خارجی منجر شود. جزئیات را مرحله‌به‌مرحله توضیح می‌دهم. 👇 #دیوار #سایبری
9
16
2
101
9,258
Costin Raiu retweeted
Running local Ai is going to be a controlled substance soon 😦
8
13
2
90
7,759
Costin Raiu retweeted
I was thinking about how to respond to the @MiaAI_lab "expose", and @volatilemarkts has put it beautifully. I have seen how hard Mia works when creating recipes and messaging me in the early hours with results and screenshots, etc. You are doing an incredible job, Mia!
I know the story behind @MiaAI_lab It’s a lot less sensational than a 3,000-word exposé. When it’s finally told, the people who dressed a git clone up as an investigation are going to be disappointed—and they should be. But it isn’t my story to tell. It’s hers. I’m not an old man, but I’m not a young one either. I’ve worked across enough industries to know how to reinvent myself, and through all of it, the one thing I’ve protected is my family. In the end, that’s all that matters. Some of us live in parts of the world where that reminder is stark and real. For others, it’s an abstraction—a luxury born of safety, far removed from hardship or the casual cruelty of strangers. I’ve always felt safe in our tech and builder community. Let’s keep it that way. Let’s stop jumping to conclusions and stop investigating each other over shadows. You do not know it yet, but we need each other. No knowledge is yours, mine, or theirs. As Jensen pointed out this week, once you put your work out into the open, it belongs to everyone. That is how we move forward. Nothing belongs to any of us in the end anyway. I’m too deep in the code and too anchored to my family to chase ghosts. @MiaAI_lab recipes run my machines every day; that’s all the provenance I’ll ever need. Be nice, or leave. Please leave my friend alone and respect her privacy as I respect yours. "When people show you they're not a safe space, believe them." - Chad Hurley
17
8
2
164
10,919
Costin Raiu retweeted
Replying to @craiu
Agreed, a mix of local AI with frontier is the key. Local AI is very useful when frontier guardrails keep kicking in. Also local AI do a good job for many tasks, model as Qwen, DeepSeek and GLM are really good.
1
1
591
There's a coordinated campaign against abliterated open-weight models right now. Local models are useful. Abuse is possible, sure, but security researchers also use them for real work because frontier labs overdo the guardrails. Lots of people reached out to me after the last 3BP podcast episode with @juanandres_gs and @ryanaraine, saying they acquired a local AI hardware miniPC, loaded it with something like Bonsai and been cooking with it, together with claude and codex. The path to success does not mean using only frontier models or local models, it is about mixing them harmoniously.
9
16
2
69
4,528
Costin Raiu retweeted
I'll be posting all my latest local model recipes and updates on my website, so check it out if you want to keep up. mia-ai.net/
4
6
1
110
7,529
Costin Raiu retweeted
Run GLM 5.3 Flash EXL3 with TensorFold ⚡️ This is a completely new recipe that ushers a whole new level of performance for @NVIDIAAI 2x DGX Sparks. Conservative default for stability: - 1M context by default - 2.7M KV cache pool (!) - Yes, it's not a typo - 2.7M KV in just two Sparks - 4 concurrent streams by default Performance: - 60 tok/s on prose, single stream. - 108 tok/s on prose, 4 concurrent streams. ~1,950 prefill tok/s for most context lengths. Stress-tested to handle a variety of workflows. This is by far the BEST model to run if you have two DGX Sparks. Extremely smooth experience! Expect further improvements! Thanks to @ashxhart for developing such a powerful engine! TensorFold will be used in many of my upcoming recipes. Get it here: github.com/MiaAI-Lab/GLM-5.3…
131
89
59
680
145,144
Costin Raiu retweeted
NIST finds GLM-5.3 to be the most cyber capable open weight model, passing Kimi K3, but still lagging behind US frontier. Anthropic independently agrees with this.
23
15
2
259
12,145
Costin Raiu retweeted
Since January 2026, Microsoft has observed Russian state threat actor Star Blizzard evolve their detection evasion capabilities through large-scale phishing campaigns, the use of accounts on compromised websites, and a novel malware delivery technique that Microsoft tracks as #RedFlick, a malware delivery technique used to deploy the actor’s custom backdoor, #CosmicPulse. This blog provides updated technical analysis of Star Blizzard’s tactics, techniques, and procedures (TTPs) observed throughout 2026, building on our 2025 and 2023 blogs. #MIRAGE microsoft.com/en-us/security…
6
12
1,198
Costin Raiu retweeted
Abliteration now works with the speed boost for GLM 5.3 Flash EXL3! In my first tests, decode was about 10% faster than the current abliterated setup, depending on workload. github.com/MiaAI-Lab/GLM-5.3…
GLM-5.3 Flash on 2x DGX Spark (TP2) is much faster now! DEFAULT ON: You get faster inference automatically, using the same weights. Decode is 3.9–5.2% faster, and 16k/64k prefill TTFT is down 11.5–12.6%. RECOMMENDED SPEED BOOST: A matched EXL3 target + 6-bpw DFlash2 draft is estimated to make decode up to 16% faster than the previous default, depending on workload! It needs extra weights and a one-time local build, so add GLM53_MODEL_PRESET=dense-h3 to .env to opt in; the launcher handles the rest. Update 👇
5
8
4
90
8,396
Costin Raiu retweeted
Also applies for GLM 5.3 Flash Basically Anthropic confirmed my own conclusions that GLM is the most capable < 1T param model you can run locally.
44
63
7
947
32,714
Costin Raiu retweeted
After receiving criticism, AISI edited this to say defenses beyond alignment are essential. But that's not a casual mistake. It reveals exactly why these AI safety groups are so dangerous, and why we need to reject them.
Defenses beyond alignment MAY be necessary? MAY? What the hell am I reading.
31
106
16
515
43,267