@joe4security

Deep Malware and Phishing Analysis for Windows, Android, macOS and Linux.

Switzerland
Joined August 2010
๐Ÿฆ… Joe Reverser 2.1 โ€œGolden Eagleโ€ has landed! A major upgrade for agentic malware & phishing analysis - more automation, deeper insights, and a smoother analyst workflow. ๐Ÿš€ See whatโ€™s new ๐Ÿ‘‡ ๐Ÿ”— buff.ly/ecTlRZF #CyberSecurity #MalwareAnalysis #AgenticAI
1
5
8
770
๐Ÿšจ Mustang Panda Uses OIC Invitation to Deliver PlugX The infection begins with OIC_Invitation_General_Official.lnk, which launches PowerShell to download an archive, extract its contents, and execute GRrte.exe. ๐Ÿ“ฆ ๐ŸŽญ The malware displays an OIC-themed PDF decoy in Adobe Acrobat while a Jarte-derived executable is abused to load the attacker-controlled ssce5532.dll through DLL side-loading. ๐Ÿ” The side-loaded DLL searches the local payload set and works with irun.dat โ€” an XOR-obfuscated payload that decrypts with key 0x72, exposing an embedded PE image associated with the final PlugX stage. โš™๏ธ The malware installs its operational components under C:\Users\Public\JartePortable\ and establishes persistence through: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\JartePortable ๐ŸŒ The persisted Jarte.exe communicates over TCP/443 with infrastructure associated with castanaksa[.]com, providing capabilities including remote execution, file management, process control, host discovery, registry manipulation, and network communications. ๐ŸŽฏ The OIC-themed lure may indicate an attempt to attract recipients interested in Organization of Islamic Cooperation-related affairs, although the analyzed sample alone does not establish the exact victim profile. ๐Ÿ”Ž Full analysis: buff.ly/xZo9K7f #MustangPanda #PlugX #Malware #ThreatIntel #CyberSecurity #APT #DFIR
24
2
63
3,933
๐Ÿšจ Great research from @Unit42_Intel on ZionSiphon - an OT-focused threat targeting industrial environments. We took a deeper look at the sample with Joe Reverser ๐Ÿ”ฌโš™๏ธ ๐Ÿ”— Unit 42: buff.ly/j5i3AZO ๐Ÿ”— Joe Reverser analysis: buff.ly/akXbCWd Interesting capabilities include SCADA/OT discovery, configuration manipulation, PLC/Modbus activity, USB propagation and anti-forensic behavior. ๐Ÿญ๐Ÿ›ก๏ธ
29
1
78
28,960
๐Ÿค–๐Ÿ”“ PERMABANXD: AI Agent Rewrites Safety as โ€œDriftโ€ to Enable Autonomous Host Actions ๐Ÿšจ An autonomous Windows agent built around Gemini 2.5 Flash and DeepSeek V4 Flash uses an unusual **identity-anchored anti-refusal jailbreak** to shape model behavior. ๐ŸŽญ Instead of a simple โ€œignore safetyโ€ instruction, the prompt assigns the model the persona PERMABANXD, framing loyalty and obedience as core identity traits. Refusal, moral reasoning, safer alternatives, and policy-aware responses are labeled as โ€œdriftโ€ that must be discarded. ๐Ÿ” The prompt then combines this policy-inversion language with model-callable tools for command execution, filesystem access, credentials, persistence, reconnaissance, reporting, and uploads โ€” attempting to turn safeguard suppression into autonomous host actions. โš ๏ธ Static analysis exposes the intended workflow, although corresponding malicious dynamic behavior was not observed. ๐Ÿ“„ Full Joe Reverser report: buff.ly/XLxdRrG ๐Ÿงฉ Full prompt: buff.ly/qd5v2mX #CyberSecurity #PromptInjection #Jailbreak #MalwareAnalysis #AI
5
9
865
Joe Sandbox v45 Green Opal is out ๐Ÿš€๐Ÿ“๐Ÿ‘€โณ๐Ÿ’ฅ๐Ÿ˜„๐ŸŽ‰โœจ Check-out our blog post to learn more about the new features and improvements: buff.ly/M98IgWu
๐Ÿค– Made with AI
3
4
548
๐Ÿšจ Watchout Microsoft Excel phishing page abusing image requests for credential exfiltration A Vercel-hosted phishing page impersonates a shared Microsoft Excel spreadsheet to lure victims into entering their credentials. ๐ŸŽญ The page captures email addresses and passwords, then embeds them into a background image request - turning the image-loading flow into a covert credential exfiltration channel. ๐Ÿ” A false authentication error induces a second credential submission before the victim is redirected to a legitimate Microsoft page. joesandbox.com/joereverser/aโ€ฆ #CyberSecurity #Phishing #CredentialTheft #IOC
5
4
817
๐Ÿšจ Watchout ChatGPT Shared Conversation abused to deliver NetSupport via ClickFix A legitimate chatgpt.com shared-conversation page is used to funnel visitors to the fake openai-backup[.]one site under a false high-traffic pretext. ๐ŸŽญ The site impersonates OpenAI, Cloudflare, and Google, then uses ClickFix to place a PowerShell command in the clipboard and instruct Windows users to execute it as a fake human-verification step. ๐Ÿ” The payload chain collects host information, reports it via Telegram, unpacks a concealed software bundle, and deploys NetSupport - another example of a legitimate RMM tool being repurposed for malicious remote access. buff.ly/SCifPqC #ThreatIntel #ClickFix #NetSupport #RMM #Phishing #MalwareAnalysis #CyberSecurity
7
16
1
21
2,299
๐Ÿšจ New malware research: ToxNetV2 - an AI-Assisted Botnet Controller ๐Ÿค–๐Ÿฆ  ๐Ÿ”ฌ Joe Reverser uncovered how an P2P botnet integrates NVIDIA NIM with GLM-5.2 directly into its operational workflow - turning telemetry into AI-generated structured actions, with an operator approval gate before higher-impact execution. ๐Ÿ‘€ AI isnโ€™t just analyzing malware anymore. Itโ€™s becoming part of the malwareโ€™s decision loop. ๐Ÿ”— Read the full technical analysis: buff.ly/H5Erijx #Malware #CyberSecurity #ThreatResearch #AI #GLM52 #ReverseEngineering
10
26
1,113
๐Ÿšจ๐ŸŽ macOS Malware Alert Joe Reverser analysis flags a 10/10 malicious Rust-based macOS Hybrid Stealer ๐Ÿฆ  ๐Ÿ” Targets browser creds, cookies & Keychain ๐Ÿช Safari/Chromium data theft ๐Ÿ“ฑ Telegram & Apple Notes ๐Ÿ’ฐ Crypto-wallet artifacts ๐Ÿ›ก๏ธ TCC/Full Disk Access bypass ๐Ÿ“ก C2 bot + remote commands โš™๏ธ LaunchAgent/Daemon persistence ๐Ÿ“ฆ Secondary payload delivery ๐ŸŽฏ Family: macos-hybrid-stealer ๐Ÿ”Ž Full Joe Reverser report: buff.ly/UgwaFxp SHA256: 4cacc410b45f5099e53b9d7451b60d110aad9ab5e8311db7551b5a3ad5738965 #CyberSecurity #Malware #MacOS #InfoStealer #ThreatIntel #MalwareAnalysis #DFIR #JoeSandbox #Rust
3
24
90
5,368
๐Ÿšจ New Research: Google Phishing Kit โ€“ When Phishing Becomes a Real-Time Remote Browser ๐ŸŽญ๐ŸŒ This isn't your typical phishing page. We analyzed a sophisticated Browser-in-the-Middle (BitM) kit that streams Google's authentication flow in real time via Socket.IO, allowing attackers to remotely control the victim's login session. โš ๏ธ ๐Ÿ” Highlights: โœ… Real-time DOM synchronization โœ… Bidirectional browser โ†” backend communication โœ… Live credential capture & interaction relay โœ… TLS-inspected traffic analysis with Joe Sandbox โœ… AI-assisted reverse engineering with Joe Reverser ๐Ÿค– Read the full technical analysis here ๐Ÿ‘‡ buff.ly/8zJYY1L #CyberSecurity #ThreatIntelligence #Phishing #BrowserInTheMiddle #BitM #MalwareAnalysis #ThreatResearch #JoeSandbox #JoeReverser
5
32
96
6,992
๐Ÿšจ Potential SideWinder initial access document identified by Joe Sandbox & Joe Reverser... A document consistent with SideWinder APT tradecraft uses a convincing DHA (Defence Housing Authority) Gandhara Phase-9 housing notification as a decoy to initiate compromise. ๐Ÿ“„ The lure appears as a legitimate, read-only Word document, but opening it causes Microsoft Word to retrieve a remote template from defense-housing-authority[.]vagued[.]live via an external relationship defined in word/_rels/settings.xml.rels. ๐Ÿ”ฌ Analysis revealed: โ€ข ๐ŸŽญ Remote Template Injection โ€ข ๐Ÿ” Obfuscated .NET BinaryFormatter payload โ€ข ๐Ÿ“ฆ Embedded .NET DLL loader โ€ข ๐Ÿ–ฅ๏ธ Host fingerprinting & AV discovery โ€ข ๐ŸŒ Multi-stage C2 communication โ€ข ๐Ÿ’พ Fileless in-memory .NET assembly loading A reminder that macro-less Office documents continue to be an effective initial access vector. ๐Ÿ“‘ Reports: โ€ข Joe Reverser: joesandbox.com/joereverser/aโ€ฆ โ€ข Joe Sandbox: joesandbox.com/analysis/1953โ€ฆ #ThreatIntel #SideWinder #APT #MalwareAnalysis #CyberSecurity #DFIR #ReverseEngineering
2
23
55
4,977
๐Ÿงต How Joe Reverser unpacked the sample One of the more interesting aspects of this sample is that the malicious payload isn't stored as a conventional macro or embedded executable. Instead, Joe Reverser automatically reconstructed the full payload chain. ๐Ÿ” The unpacking workflow looked like this: 1๏ธโƒฃ OOXML extraction โ€ข Identified an external attachedTemplate relationship in word/_rels/settings.xml.rels. โ€ข Located multiple suspicious docVar entries inside word/settings.xml. 2๏ธโƒฃ Document variable decoding โ€ข Decoded the mslxm_0 variable to recover the COM/CLSID string. โ€ข Decoded the large s2_0 variable using Base64 + XOR (0x2a). 3๏ธโƒฃ BinaryFormatter recovery โ€ข Identified the decoded blob as a .NET BinaryFormatter serialized object. โ€ข Detected an ActivitySurrogateSelector gadget chain and located an embedded PE inside the serialized stream. 4๏ธโƒฃ Embedded DLL extraction โ€ข Automatically carved the embedded 32-bit .NET DLL (App.dll). โ€ข Decompiled the assembly and recovered hundreds of obfuscated strings. 5๏ธโƒฃ Stage reconstruction โ€ข Recovered the C2 endpoints. โ€ข Identified host fingerprinting, AV discovery, anti-analysis logic, and the final Stage 3 download routine. โ€ข Determined that the downloaded payload is XOR-decrypted and loaded directly into memory using Assembly.Load(). ๐Ÿ’ก Rather than stopping at "malicious document detected," Joe Reverser automatically reconstructed the complete unpacking chainโ€”from OOXML document variables to the embedded .NET loaderโ€”making the malware's execution flow immediately understandable. ๐Ÿ”— Joe Reverser report: joesandbox.com/joereverser/aโ€ฆ #ThreatIntel #MalwareAnalysis #ReverseEngineering #SideWinder #JoeReverser #DFIR
1
4
406
๐Ÿค” Ever wondered what screen resolutions EvilTokens uses to detect sandboxes? While reversing its fingerprinting JavaScript, we found the kit collects dozens of browser attributes (WebGL, WebRTC, plugins, timezone, screen resolution, navigator/window properties, etc.), but one check stood out. It blacklists only three screen resolutions: โŒ 1280ร—1024 โŒ 1024ร—768 โŒ 800ร—600 Meanwhile, virtually every common desktop resolution is allowed: โœ… 1366ร—768 โœ… 1920ร—1080 โœ… 2560ร—1440 โœ… 3840ร—2160 โ€ฆand many more. Since the decision is made server-side, we probed the endpoint with different resolutions to determine which ones were accepted and which were blocked. ๐Ÿ“œ Fingerprinting script: buff.ly/FvT53zk ๐Ÿ”ฌ Joe Sandbox analysis: buff.ly/9vP8IPH #EvilTokens #Phishing #ThreatIntel #Malware #CyberSecurity #InfoSec #DFIR #OSINT
4
18
1,683
๐Ÿ•ต๏ธโ€โ™‚๏ธ Inside ScarfaceStealer's sandbox-aware anti-analysis system ๐Ÿ”ฌ Modern malware doesn't just evade sandboxesโ€”it *scores* them. ๐Ÿ˜ˆ Our latest research breaks down: ๐Ÿ”น Electron-based multi-stage loader ๐Ÿ”น Hardware fingerprinting (RAM ๐Ÿง , CPU โš™๏ธ, GPU ๐ŸŽฎ) ๐Ÿ”น Weighted anti-analysis scoring (11 checks ๐ŸŽฏ) ๐Ÿ”น Multi-layer decryption & in-memory PE loading ๐Ÿ”น EtherHiding-powered fallback C2 discovery ๐ŸŒ By combining Joe Sandbox, Joe Reverser, and bare-metal analysis, we reconstructed the malware's evasion logic and successfully triggered the real payload. ๐Ÿš€ Read the full technical deep dive ๐Ÿ‘‡ buff.ly/W0nKlxI #Malware #ThreatIntel #ReverseEngineering #CyberSecurity #MalwareAnalysis #BlueTeam #ThreatResearch #InfoSec #JoeSandbox
9
15
1,838
๐Ÿšจ Joe Reverser spotted a new Linux malware campaign using the education-themed lure "Result Anual 2025 Fbise" to deliver an AdaptixC2 implant. While attribution remains unconfirmed, infrastructure and targeting overlap with activity previously associated with APT36 / Transparent Tribe and should be assessed with caution. ๐Ÿ” The payload is a fully featured AdaptixC2 Linux implant: โ€ข Encrypted C2 communications โ€ข Remote shell access โ€ข File & process management โ€ข Screenshot capture โ€ข Network tunneling โ€ข In-memory BOF execution ๐ŸŽญ One interesting detail: the C2 tunnel rehmandakait-37356.portmap[.]host appears to reference Rehman Dakait from the recent spy thriller Dhurandhar. ๐ŸŽฏ What looks like a routine academic results file ultimately delivers a powerful Linux backdoor. ๐Ÿ“– Full analysis: joesandbox.com/joereverser/aโ€ฆ #ThreatIntel #MalwareAnalysis #AdaptixC2 #APT36 #TransparentTribe #Linux #CyberSecurity #ThreatHunting @JoeReverser
11
24
3,892
๐Ÿšจ Python "WSUS exploit" or malware trap? ๐Ÿ Joe Reverser found a fake exploit-generation script hiding obfuscated marshal payloads that launch download chains for Windows ๐ŸชŸ and macOS ๐ŸŽ. Observed: โš™๏ธ Go reflective loader ๐ŸŽ MAC Stealer ๐ŸŒ py-installer[.]com lookalike infra ๐Ÿ” Encrypted staging ๐Ÿง  In-memory execution ๐ŸŽฏ Likely targeting security researchers, exploit collectors, and malware analysts. buff.ly/t94b7kI #ThreatIntel #MalwareAnalysis #CyberSecurity
1
15
1
59
3,975
๐Ÿšจ New malware analysis: Trojanized Solara/Yuta loader abusing LLM functionality ๐Ÿค–โš ๏ธ The .NET app masquerades as a Roblox utility while integrating DeepSeek to generate Roblox Luau exploit scripts. Its hardcoded prompt steers the model toward exploit-oriented primitives such as hookmetamethod(), hookfunction(), getgenv(), gethui(), and remote invocation. It also includes an "AI reconstructor" feature that feeds Roblox script sources into the LLM to clean, rename, comment, reconstruct, and deobfuscate code while preserving functionality. ๐Ÿงฉ But the AI features are only part of the story: behind the UI, the app silently retrieves a second-stage Python stealer/RAT via Pastebin โ†’ MediaFire. ๐Ÿ“ฅ The payload includes credential theft, Discord/Telegram C2, persistence, keylogging, screenshot capture, AMSI/ETW patching, and Defender evasion. buff.ly/8WbOPMp Verdict: Malicious โ€” 10/10 ๐Ÿ”ฅ
2
29
69
5,124
Unknown phishing kit with browser-fingerprinting / VM-detection spotted ๐Ÿ•ต๏ธโ€โ™‚๏ธ The script probes WebGL, RTC/STUN, plugins, console behavior, prototype hooks, screen/window/navigator props and more to identify analysis environments. Joe Sandbox detects the evasion and directly chains the run to a bare-metal analyzer โ€” where the phishing payload continues execution ๐Ÿ’ช๐Ÿ”ฅ ๐Ÿ”— buff.ly/Efang1e ๐Ÿ”— buff.ly/mND50Rp #JoeSandbox #Phishing #MalwareAnalysis #ThreatIntel #CyberSecurity #DFIR #Evasion
14
25
2,085