@joe4securityi
iAccount based inSwitzerland
About this account
- Account based in
- Switzerland
- Connected via
- Web
Account-level information from X, not a live location or the device used for a specific post.
Deep Malware and Phishing Analysis for Windows, Android, macOS and Linux.
Switzerland
Joined August 2010
- Tweets1.1K
- Following136
- Followers8K
- Likes245
Pinned Tweet
๐ฆ
Joe Reverser 2.1 โGolden Eagleโ has landed!
A major upgrade for agentic malware & phishing analysis - more automation, deeper insights, and a smoother analyst workflow. ๐
See whatโs new ๐
๐ buff.ly/ecTlRZF
#CyberSecurity #MalwareAnalysis #AgenticAI
๐จ Mustang Panda Uses OIC Invitation to Deliver PlugX
The infection begins with OIC_Invitation_General_Official.lnk, which launches PowerShell to download an archive, extract its contents, and execute GRrte.exe. ๐ฆ
๐ญ The malware displays an OIC-themed PDF decoy in Adobe Acrobat while a Jarte-derived executable is abused to load the attacker-controlled ssce5532.dll through DLL side-loading.
๐ The side-loaded DLL searches the local payload set and works with irun.dat โ an XOR-obfuscated payload that decrypts with key 0x72, exposing an embedded PE image associated with the final PlugX stage.
โ๏ธ The malware installs its operational components under C:\Users\Public\JartePortable\ and establishes persistence through:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\JartePortable
๐ The persisted Jarte.exe communicates over TCP/443 with infrastructure associated with castanaksa[.]com, providing capabilities including remote execution, file management, process control, host discovery, registry manipulation, and network communications.
๐ฏ The OIC-themed lure may indicate an attempt to attract recipients interested in Organization of Islamic Cooperation-related affairs, although the analyzed sample alone does not establish the exact victim profile.
๐ Full analysis:
buff.ly/xZo9K7f
#MustangPanda #PlugX #Malware #ThreatIntel #CyberSecurity #APT #DFIR
๐จ Great research from @Unit42_Intel on ZionSiphon - an OT-focused threat targeting industrial environments.
We took a deeper look at the sample with Joe Reverser ๐ฌโ๏ธ
๐ Unit 42:
buff.ly/j5i3AZO
๐ Joe Reverser analysis:
buff.ly/akXbCWd
Interesting capabilities include SCADA/OT discovery, configuration manipulation, PLC/Modbus activity, USB propagation and anti-forensic behavior. ๐ญ๐ก๏ธ
๐ค๐ PERMABANXD: AI Agent Rewrites Safety as โDriftโ to Enable Autonomous Host Actions
๐จ An autonomous Windows agent built around Gemini 2.5 Flash and DeepSeek V4 Flash uses an unusual **identity-anchored anti-refusal jailbreak** to shape model behavior.
๐ญ Instead of a simple โignore safetyโ instruction, the prompt assigns the model the persona PERMABANXD, framing loyalty and obedience as core identity traits. Refusal, moral reasoning, safer alternatives, and policy-aware responses are labeled as โdriftโ that must be discarded.
๐ The prompt then combines this policy-inversion language with model-callable tools for command execution, filesystem access, credentials, persistence, reconnaissance, reporting, and uploads โ attempting to turn safeguard suppression into autonomous host actions.
โ ๏ธ Static analysis exposes the intended workflow, although corresponding malicious dynamic behavior was not observed.
๐ Full Joe Reverser report:
buff.ly/XLxdRrG
๐งฉ Full prompt:
buff.ly/qd5v2mX
#CyberSecurity #PromptInjection #Jailbreak #MalwareAnalysis #AI
Joe Sandbox v45 Green Opal is out ๐๐๐โณ๐ฅ๐๐โจ
Check-out our blog post to learn more about the new features and improvements:
buff.ly/M98IgWu
๐ค Made with AI
๐จ Watchout Microsoft Excel phishing page abusing image requests for credential exfiltration
A Vercel-hosted phishing page impersonates a shared Microsoft Excel spreadsheet to lure victims into entering their credentials.
๐ญ The page captures email addresses and passwords, then embeds them into a background image request - turning the image-loading flow into a covert credential exfiltration channel.
๐ A false authentication error induces a second credential submission before the victim is redirected to a legitimate Microsoft page.
joesandbox.com/joereverser/aโฆ
#CyberSecurity #Phishing #CredentialTheft #IOC
๐จ Watchout ChatGPT Shared Conversation abused to deliver NetSupport via ClickFix
A legitimate chatgpt.com shared-conversation page is used to funnel visitors to the fake openai-backup[.]one site under a false high-traffic pretext.
๐ญ The site impersonates OpenAI, Cloudflare, and Google, then uses ClickFix to place a PowerShell command in the clipboard and instruct Windows users to execute it as a fake human-verification step.
๐ The payload chain collects host information, reports it via Telegram, unpacks a concealed software bundle, and deploys NetSupport - another example of a legitimate RMM tool being repurposed for malicious remote access.
buff.ly/SCifPqC
#ThreatIntel #ClickFix #NetSupport #RMM #Phishing #MalwareAnalysis #CyberSecurity
๐จ New malware research: ToxNetV2 - an AI-Assisted Botnet Controller ๐ค๐ฆ
๐ฌ Joe Reverser uncovered how an P2P botnet integrates NVIDIA NIM with GLM-5.2 directly into its operational workflow - turning telemetry into AI-generated structured actions, with an operator approval gate before higher-impact execution.
๐ AI isnโt just analyzing malware anymore. Itโs becoming part of the malwareโs decision loop.
๐ Read the full technical analysis: buff.ly/H5Erijx
#Malware #CyberSecurity #ThreatResearch #AI #GLM52 #ReverseEngineering
๐จ๐ macOS Malware Alert
Joe Reverser analysis flags a 10/10 malicious Rust-based macOS Hybrid Stealer ๐ฆ
๐ Targets browser creds, cookies & Keychain
๐ช Safari/Chromium data theft
๐ฑ Telegram & Apple Notes
๐ฐ Crypto-wallet artifacts
๐ก๏ธ TCC/Full Disk Access bypass
๐ก C2 bot + remote commands
โ๏ธ LaunchAgent/Daemon persistence
๐ฆ Secondary payload delivery
๐ฏ Family: macos-hybrid-stealer
๐ Full Joe Reverser report: buff.ly/UgwaFxp
SHA256: 4cacc410b45f5099e53b9d7451b60d110aad9ab5e8311db7551b5a3ad5738965
#CyberSecurity #Malware #MacOS #InfoStealer #ThreatIntel #MalwareAnalysis #DFIR #JoeSandbox #Rust
๐จ New Research: Google Phishing Kit โ When Phishing Becomes a Real-Time Remote Browser ๐ญ๐
This isn't your typical phishing page. We analyzed a sophisticated Browser-in-the-Middle (BitM) kit that streams Google's authentication flow in real time via Socket.IO, allowing attackers to remotely control the victim's login session. โ ๏ธ
๐ Highlights:
โ
Real-time DOM synchronization
โ
Bidirectional browser โ backend communication
โ
Live credential capture & interaction relay
โ
TLS-inspected traffic analysis with Joe Sandbox
โ
AI-assisted reverse engineering with Joe Reverser ๐ค
Read the full technical analysis here ๐
buff.ly/8zJYY1L
#CyberSecurity #ThreatIntelligence #Phishing #BrowserInTheMiddle #BitM #MalwareAnalysis #ThreatResearch #JoeSandbox #JoeReverser
๐จ Potential SideWinder initial access document identified by Joe Sandbox & Joe Reverser...
A document consistent with SideWinder APT tradecraft uses a convincing DHA (Defence Housing Authority) Gandhara Phase-9 housing notification as a decoy to initiate compromise.
๐ The lure appears as a legitimate, read-only Word document, but opening it causes Microsoft Word to retrieve a remote template from defense-housing-authority[.]vagued[.]live via an external relationship defined in word/_rels/settings.xml.rels.
๐ฌ Analysis revealed:
โข ๐ญ Remote Template Injection
โข ๐ Obfuscated .NET BinaryFormatter payload
โข ๐ฆ Embedded .NET DLL loader
โข ๐ฅ๏ธ Host fingerprinting & AV discovery
โข ๐ Multi-stage C2 communication
โข ๐พ Fileless in-memory .NET assembly loading
A reminder that macro-less Office documents continue to be an effective initial access vector.
๐ Reports:
โข Joe Reverser: joesandbox.com/joereverser/aโฆ
โข Joe Sandbox: joesandbox.com/analysis/1953โฆ
#ThreatIntel #SideWinder #APT #MalwareAnalysis #CyberSecurity #DFIR #ReverseEngineering
๐งต How Joe Reverser unpacked the sample
One of the more interesting aspects of this sample is that the malicious payload isn't stored as a conventional macro or embedded executable. Instead, Joe Reverser automatically reconstructed the full payload chain.
๐ The unpacking workflow looked like this:
1๏ธโฃ OOXML extraction
โข Identified an external attachedTemplate relationship in word/_rels/settings.xml.rels.
โข Located multiple suspicious docVar entries inside word/settings.xml.
2๏ธโฃ Document variable decoding
โข Decoded the mslxm_0 variable to recover the COM/CLSID string.
โข Decoded the large s2_0 variable using Base64 + XOR (0x2a).
3๏ธโฃ BinaryFormatter recovery
โข Identified the decoded blob as a .NET BinaryFormatter serialized object.
โข Detected an ActivitySurrogateSelector gadget chain and located an embedded PE inside the serialized stream.
4๏ธโฃ Embedded DLL extraction
โข Automatically carved the embedded 32-bit .NET DLL (App.dll).
โข Decompiled the assembly and recovered hundreds of obfuscated strings.
5๏ธโฃ Stage reconstruction
โข Recovered the C2 endpoints.
โข Identified host fingerprinting, AV discovery, anti-analysis logic, and the final Stage 3 download routine.
โข Determined that the downloaded payload is XOR-decrypted and loaded directly into memory using Assembly.Load().
๐ก Rather than stopping at "malicious document detected," Joe Reverser automatically reconstructed the complete unpacking chainโfrom OOXML document variables to the embedded .NET loaderโmaking the malware's execution flow immediately understandable.
๐ Joe Reverser report:
joesandbox.com/joereverser/aโฆ
#ThreatIntel #MalwareAnalysis #ReverseEngineering #SideWinder #JoeReverser #DFIR
๐ค Ever wondered what screen resolutions EvilTokens uses to detect sandboxes?
While reversing its fingerprinting JavaScript, we found the kit collects dozens of browser attributes (WebGL, WebRTC, plugins, timezone, screen resolution, navigator/window properties, etc.), but one check stood out.
It blacklists only three screen resolutions:
โ 1280ร1024
โ 1024ร768
โ 800ร600
Meanwhile, virtually every common desktop resolution is allowed:
โ
1366ร768
โ
1920ร1080
โ
2560ร1440
โ
3840ร2160
โฆand many more.
Since the decision is made server-side, we probed the endpoint with different resolutions to determine which ones were accepted and which were blocked.
๐ Fingerprinting script:
buff.ly/FvT53zk
๐ฌ Joe Sandbox analysis:
buff.ly/9vP8IPH
#EvilTokens #Phishing #ThreatIntel #Malware #CyberSecurity #InfoSec #DFIR #OSINT
๐ต๏ธโโ๏ธ Inside ScarfaceStealer's sandbox-aware anti-analysis system ๐ฌ
Modern malware doesn't just evade sandboxesโit *scores* them. ๐
Our latest research breaks down:
๐น Electron-based multi-stage loader
๐น Hardware fingerprinting (RAM ๐ง , CPU โ๏ธ, GPU ๐ฎ)
๐น Weighted anti-analysis scoring (11 checks ๐ฏ)
๐น Multi-layer decryption & in-memory PE loading
๐น EtherHiding-powered fallback C2 discovery ๐
By combining Joe Sandbox, Joe Reverser, and bare-metal analysis, we reconstructed the malware's evasion logic and successfully triggered the real payload. ๐
Read the full technical deep dive ๐
buff.ly/W0nKlxI
#Malware #ThreatIntel #ReverseEngineering #CyberSecurity #MalwareAnalysis #BlueTeam #ThreatResearch #InfoSec #JoeSandbox
๐จ Joe Reverser spotted a new Linux malware campaign using the education-themed lure "Result Anual 2025 Fbise" to deliver an AdaptixC2 implant.
While attribution remains unconfirmed, infrastructure and targeting overlap with activity previously associated with APT36 / Transparent Tribe and should be assessed with caution.
๐ The payload is a fully featured AdaptixC2 Linux implant:
โข Encrypted C2 communications
โข Remote shell access
โข File & process management
โข Screenshot capture
โข Network tunneling
โข In-memory BOF execution
๐ญ One interesting detail: the C2 tunnel rehmandakait-37356.portmap[.]host appears to reference Rehman Dakait from the recent spy thriller Dhurandhar.
๐ฏ What looks like a routine academic results file ultimately delivers a powerful Linux backdoor.
๐ Full analysis: joesandbox.com/joereverser/aโฆ
#ThreatIntel #MalwareAnalysis #AdaptixC2 #APT36 #TransparentTribe #Linux #CyberSecurity #ThreatHunting
@JoeReverser
๐จ Python "WSUS exploit" or malware trap? ๐
Joe Reverser found a fake exploit-generation script hiding obfuscated marshal payloads that launch download chains for Windows ๐ช and macOS ๐.
Observed:
โ๏ธ Go reflective loader
๐ MAC Stealer
๐ py-installer[.]com lookalike infra
๐ Encrypted staging
๐ง In-memory execution
๐ฏ Likely targeting security researchers, exploit collectors, and malware analysts.
buff.ly/t94b7kI
#ThreatIntel #MalwareAnalysis #CyberSecurity
๐จ New malware analysis: Trojanized Solara/Yuta loader abusing LLM functionality ๐คโ ๏ธ
The .NET app masquerades as a Roblox utility while integrating DeepSeek to generate Roblox Luau exploit scripts. Its hardcoded prompt steers the model toward exploit-oriented primitives such as hookmetamethod(), hookfunction(), getgenv(), gethui(), and remote invocation.
It also includes an "AI reconstructor" feature that feeds Roblox script sources into the LLM to clean, rename, comment, reconstruct, and deobfuscate code while preserving functionality. ๐งฉ
But the AI features are only part of the story: behind the UI, the app silently retrieves a second-stage Python stealer/RAT via Pastebin โ MediaFire. ๐ฅ
The payload includes credential theft, Discord/Telegram C2, persistence, keylogging, screenshot capture, AMSI/ETW patching, and Defender evasion.
buff.ly/8WbOPMp
Verdict: Malicious โ 10/10 ๐ฅ
Unknown phishing kit with browser-fingerprinting / VM-detection spotted ๐ต๏ธโโ๏ธ
The script probes WebGL, RTC/STUN, plugins, console behavior, prototype hooks, screen/window/navigator props and more to identify analysis environments.
Joe Sandbox detects the evasion and directly chains the run to a bare-metal analyzer โ where the phishing payload continues execution ๐ช๐ฅ
๐ buff.ly/Efang1e
๐ buff.ly/mND50Rp
#JoeSandbox #Phishing #MalwareAnalysis #ThreatIntel #CyberSecurity #DFIR #Evasion