
MalConfig
This is part of a module for the framework that i'm constantly developing. Currently only information of the C2 are disclosed here.

This is part of a module for the framework that i'm constantly developing. Currently only information of the C2 are disclosed here.

Ghidra processor description module for NEC/Renesas v810 and v830 families

Tutorial and source code for building a custom YARA module in C to extract malware configurations, with a practical Danabot example and reusable…

Technical analysis and proof-of-concept bypass for CVE-2023-33668 in DigiExam proctoring software, demonstrating weak VM detection and native module…

GNU Radio out-of-tree (OOT) module for QRadioLink blocks.

Proof-of-concept exploit for CVE-2023-50564 targeting Pluck CMS, delivering a reverse shell via malicious module installation.

GhostLock One-Tap Execution App (CVE-2026-43499)

Abstracts and expedites the process of backdooring stock firmware images for consumer/SOHO routers

PoC code of Shade BIOS (stripped) presented at Black Hat USA 2025

Android Malware Tracker

SM-F9360 (Galaxy Z Fold4, q4q) locked-bootloader KernelSU root — CVE-2026-43499 temp root → LD_PRELOAD DEFEX bypass → no-LTO clang-12 kernelsu.ko.…

Research on CVE-2025-3052, an Insyde firmware vulnerability that exposes an arbitrary write primitive capable of modifying security-critical pointers.

Android Ransomware Development - AES256 encryption + CVE-2019-2215 (reverse root shell) + Data Exfiltration