
AI-FILE
A listener profile for the Mythic C2 framework that utilizes AI vendors file API's

A listener profile for the Mythic C2 framework that utilizes AI vendors file API's

Reverse engineering analysis of StealC Stealer, an info-stealer that uses RuntimeBroker.exe hollowing, C2 infrastructure, and payload extraction.…

Reverse engineering analysis of AcrStealer, a sophisticated info-stealer that uses custom protocols, browser credential theft, and payload…

Reverse engineering analysis of Dropper GCleaner, a malware that uses a resilient C2 infrastructure, kernel driver loading, PowerShell/Conhost…

"Reverse engineering analysis of RedLine Stealer, a .NET-based info-stealer that uses C2 domains (198.46.86.63, tempuri.org), Windows Defender…

Linux post-exploitation agent that uses io_uring to stealthily bypass EDR detection by avoiding traditional syscalls.

A fully featured Windows backdoor that uses email as a C&C server

BrowserBackdoor is an Electron Application with a JavaScript WebSocket Backdoor and a Ruby Command-Line Listener

A Post exploitation tool written in C# uses either CIM or WMI to query remote systems.

Keylogging server and client that uses DNS tunneling/exfiltration to transmit keystrokes through firewalls.