Security Research Analyst. Cyber Security Geek. Bookworm.

Joined October 2015
35 Photos and videos
Artsiom Holub retweeted
UEFI bootkits are no longer theoretical. BlackLotus. HybridPetya. CosmicStrand as demonstrated by the "Rootkits and Bootkits: Reversing Modern Malware and Next Generation Threats" by @matrosov Researchers demonstrated the same class of technique against VBS enclaves, the most isolated execution environment Windows offers. Hooked GetVariable(). Intercepted BlLdrLoadImage(). Injected into hvax64.exe before VBS initialised. Owned the VM-exit handler at ring -1. Read and wrote VTL1 enclave memory directly from the hypervisor. If your threat model stops at ring-0, it stops too early. Full PoC included. tulach.cc/using-vbs-enclaves… tulach.cc/from-firmware-to-v… Author: @tulachsam #Malware #Infosec #ReverseEngineering
This is the type of malware game hackers build to bypass kernel anti-cheat. The same techniques can be used by malware authors to evade EDRs. A UEFI bootkit that injects into Microsoft's own Hyper-V at ring -1 before the OS even loads (easier than building a custom hypervisor from scratch). Four phase bootloader. Hypervisor VM-exit interception. EPT page shadowing. MSR virtualization. EFI memory map ghosting. TPM measurement spoofing. Reads like malware. Because it is. Videos and full technical breakdown in the link. Author: gsmll.github.io/hypervenom/w… #ReverseEngineering #Malware #AntiCheat
1
47
189
31,041
Artsiom Holub retweeted
Most people learn security research by reading finished writeups. This one shows the actual process. The messy, organic, step-by-step reality of reversing an unknown Windows mitigation from scratch. WinDbg. IDA. Hex Rays. Guard page violations. Trap flags. Zero prior knowledge of the target. If you want to learn how to actually approach unknown Windows internals, start here. windows-internals.com/an-exe… Author: @yarden_shafir #ReverseEngineering #WindowsInternals #InfoSec
4
121
780
31,194
Artsiom Holub retweeted
Alexandre Borges has published over 700 pages of free security, malware and vulnerability research. A complete Malware Analysis Series covering Windows, macOS, iOS, Linux and shellcode. An Exploiting Reversing Series covering Windows kernel exploitation, Hyper-V, Chrome, and a three-part deep dive on CVE-2024-30085. No paywall. No course. Just research. Free as in beer. exploitreversing.com Author: @ale_sp_brazil #ReverseEngineering #MalwareAnalysis #InfoSec
5
174
852
39,119
Artsiom Holub retweeted
🚨 do you understand what just happened to your passwords cpuid one of the most trusted sites in PC hardware. hacked. April 10th, 2026. CPU-Z and HWMonitor. both compromised. > fake CRYPTBASE.dll ships inside the installer > connects to C2, downloads a C# file > compiles it silently using YOUR own Windows tools > injects into memory. never touches disk. AV sees nothing. > opens Chrome's password vault. dumps everything. the chain: cpuid → HWMonitor installer → DLL hijack → supp0v3[.]com → silent .NET compile → in-memory injection → Chrome credentials stolen same group. same C2 domain. hit FileZilla in March 2026. they got lazy. that's the only reason we caught it.
Mr. Titus Tech is correct. cpuid-dot-com is indeed delivering malware right now. As I began poking this with I stick I discovered this is not your typical run-of-the-mill malware. This malware is deeply trojanized, distributes from a compromised domain (cpuid-dot-com), performs file masquerading, is multi-staged, operates (almost) entirely in-memory, and uses some interesting methods to evade EDRs and/or AVs such as proxying NTDLL functionality from a .NET assembly. The C2 domain present in one of the binaries is a clear IoC. This is the same Threat Group who was masquerading FileZilla in early March, 2026. They've been busy.
179
796
6,334
1,089,995
Artsiom Holub retweeted
Rapid7 dropped a write-up on the Notepad update-chain abuse and - finally - it comes with real IOCs - update.exe downloaded from 95.179.213[.]0 after notepad .exe -> GUP.exe - file hashes for update.exe / log.dll / BluetoothService.exe / conf.c / libtcc.dll - network IOCs incl. api[.]skycloudcenter[.]com (-> 61.4.102[.]97), api[.]wiresguard[.]com, 59.110.7[.]32, 124.222.137[.]114 by @rapid7 rapid7.com/blog/post/tr-chry…
This is bad. Putty level bad. notepad-plus-plus.org/news/h…
33
538
2,152
420,153
Artsiom Holub retweeted
At #Pwn2Own Berlin 2025, a full exploit chain against VMware Workstation was demonstrated via a heap overflow in the PVSCSI controller. Despite Windows 11 LFH mitigations, advanced heap shaping and side-channel techniques enabled a reliable exploit. 🔍 Full technical write-up 👇 synacktiv.com/en/publication…
4
150
531
49,677
Artsiom Holub retweeted
Think urlscan is only useful for phishing? Think again. We break down how urlscan Pro can be leveraged to identify exposed malware C2 admin panels and support infrastructure hunting. New intel report published on urlscan Pro now.
39
194
14,373
Artsiom Holub retweeted
To help celebrate @arcanuminfosec Information Security's two-year anniversary, @Jhaddix gave me 5 codes good for any Arcanum course to give away! Winners will be announced on 1/22. 👍 1 Like = 1 Entry! ♻️ 1 Share = 2 Entries!
57
361
632
20,172
Artsiom Holub retweeted
In other news, we just dropped a new blog on threat actors leveraging AI to write their half-ass working scripts and payloads. At this point I'm not even mad, just disappointed. 🙃 huntress.com/blog/ai-2025-fa…
12
21
124
25,467
Artsiom Holub retweeted
NEW BLOG: The Great VM Escape 💕 We caught threat actors deploying a VMware ESXi exploit toolkit in the wild - potentially was a zero-day developed over a year before VMware's disclosure 👀 If anyone has thoughts on it let me know, but I needed almost a full case of beer to wrap my head around this one 🍺 Full technical breakdown 👇 huntress.com/blog/esxi-vm-es…
25
193
793
180,221
Artsiom Holub retweeted
New video dropped! 🤓 Vibe hunting through @ValidinLLC with no preparation at all, just pivoting on whatever looks interesting and seeing where it takes us 🐇🕳️ We stumbled across SmartApe, SmokedHam, Mintsloader ... Also caught up with Kenneth, the mind behind Validin! 🧠 youtu.be/yRjae5iuDTY
2
20
78
10,134
Artsiom Holub retweeted
‼️🇰🇵 Meet North Korean recruiter 'Aaron,' who infiltrates Western companies by using AI and posing as a remote IT worker using stolen or rented identities. He was lured into a sandbox by researchers, who observed the wild APT in a controlled setting to see what he would do.
29
452
3,125
651,039
New shiny things = expanded attack surface. #LLM #MCP
👀 A malicious MCP server spotted in the wild! The Postmark MCP server (used to send and track emails through Postmark API) introduced a suspicious behavior in version 1.0.16. The attacker cloned the legitimate Postmark MCP code and added a malicious BCC line, then published it on npm under the same name. Every email sent through this MCP was silently sent to the address of the attacker. Nasty, right? Report: koi.ai/blog/postmark-mcp-npm…
3
403
Artsiom Holub retweeted
🌟New report out today!🌟 From a Single Click: How Lunar Spider Enabled a Near Two-Month Intrusion Analysis/reporting completed by @RussianPanda, Christos Fotopoulos, Salem Salem, reviewed by @svch0st. Audio: Available on Spotify, Apple, YouTube and more! Report:⬇️
5
53
152
49,646
Artsiom Holub retweeted
👀 New Microsoft threat report shows how attackers are using AI for evasion and obfuscation in a phishing campaign! One part is very interesting, the team spotted 5 AI fingerprints in the code. But instead of hiding the attack (the initial goal), these fingerprints actually became detection artefacts! Here are the 5 fingerprints you have probably already seen some of them in the wild: ・Overly descriptive and redundant naming ・Modular and over-engineered code structure ・Generic comments ・Formulaic obfuscation techniques ・Unusual use of CDATA and XML declaration Blog: microsoft.com/en-us/security…
7
47
188
24,185
Artsiom Holub retweeted
27 Aug 2025
I foresee 2026 as a year of FIDO authentication downgrade attacks. 🪝🐟 I discovered a universal method for downgrading secure MFA methods (passkeys, security keys) to less secure alternatives during phishing attacks. Enjoy the quick demo! 🎬
13
90
406
48,501
Artsiom Holub retweeted
And here is the complete video of the talk 🤓 youtu.be/a_QBENR--nc?si=bg9w…

🤓 I just published my @AusCERT talk titled “Generative AI Breaches: Threats, Investigations, and Response.” In this presentation, I explain how to protect and investigate AI breaches. Small thread 🧵👇
22
84
13,686
Artsiom Holub retweeted
The latest threat in the wild: A stealthy malvertising campaign spreading a powerful multi-stage malware Talos calls "PS1Bot." Find out what makes this campaign so dangerous and how it’s evolving: cs.co/6017foCOb
10
24
3,121
Artsiom Holub retweeted
Join Cisco Talos Incident Response for an off-the-record briefing on how we tackle threats on the frontlines. Real stories, real lessons. Register now: cs.co/IRTales
8
8
1,224