šØ Trojanized CPU-Z ā STXRAT ā PureLogs Stealer ā PureHVNC ā 54hrs of exfil through a hidden QEMU VM.
We caught everything after.
First documented full post-exploitation chain for this campaign. IOCs & hunting artifacts link in thread
#ThreatIntel#DFIR#Malware
Before I was arrested in 2009, I was at the height of my little cybercriminal "empire". I was standing at a crossroads. Part of me wanted an exit and a chance to redirect my skills toward something constructive. Another part of me feared that if I walked away, all the risks I had taken as a hacker would have meant nothing.
11 years in prison for hacking taught me that the reputation I thought I had built in that world, the ideals I believed in, and the status I thought mattered turned out to be far more futile than I could have imagined at the time. When everything collapsed, I realized that none of that mattered. I learned that most of what passes for loyalty and respect in cybercrime is conditional.
Today, there's no reason to turn to cybercrime in order to feel accepted or to enjoy camaraderie and acceptance among peers, or to pursue a sense of justice and vindication. Cybercrime isn't the solution, or the stepping stone.
All the hackers in my crew from back in the day have respectable cybersecurity careers today,Ā because sooner or later everyone learns the same lesson. Cybercrime has limits, and it does not put food on the table without tremendous risk. #realtalk#hacking#hacktivism#truecrime
This was a fun one to dig into
Confirmed exploitation requires:
⢠User registration enabled
⢠LA-Studio Element Kit = 1.5.6.3
⢠At least one published Elementor page
PoC confirmed (details withheld).
Nice find by Jitlada. Boeing777 & Waris Damkham!
ā ļø GootLoader now uses 500ā1,000 ZIP files glued together!
The broken ZIP wonāt open in WinRAR or 7-Zip, but Windows Explorer still opens it and runs the JavaScript malware. Each download is different, so file hashes donāt match.
š Learn how this ZIP trick bypasses defenses ā thehackernews.com/2026/01/goā¦
Great write-up on the #gootloader zip! Hopefully with these details @MicrosoftSec will take this seriously and fix their ZIP unarchiver.
Great Yara rule. #100daysofyara
Gootloader malware returned in November after a hiatus. They work with Vanilla Tempest (currently using Rhysida ransomware). We took a deep look at their first-stage delivery mechanismāa deliberately broken ZIP archive designed to bypass detection. (1/12)
@gnamedotcom@dowomain@brandomainable please act on the domains reported case GW2026010920446794. My reputation, plus what I provided on Friday, should be enough to stop protecting a criminal's infrastructure
Right before the holidays, I broke the news that DHS had effectively forced out the staffer running CISA's ransomware warning program: cybersecuritydive.com/news/cā¦
People who worked w/ him are really worried. And we may be starting to see the impact... linkedin.com/feed/update/urnā¦
New Yearās wish:
#Gootloader hangs up the keyboard so we can all stop running this endless game of cyber cat and mouse.
Let the mouse rest. Let the cat rest. Let me rest.
You may not know Dave Stern, but you should. The Pre-Ransomware Notification Initiative (PRNI) effort by CISA prevented an estimated $9 billion in damages by working with industry to notify companies of ransomware attacks before attackers lock systems.
It is disheartening to see Dave leave CISA, but this is an incredible legacy to leave behind and a model we should look to replicate in the future.
cybersecuritydive.com/news/cā¦
CertCentral is now TheCertGraveyard[.]org & CertGraveyard[.]org.
The CertCentral API returns an error directing to use the new domains.
Please give me a like or a share to get the word out.
Also use the site to report and investigate certificates used to sign malware. :)
I'm being required to give up the domain CertCentral[.]org; and the change has to happen by Monday.
I'm noodling on alternative names. Keep an eye out for the change.