Joined September 2022
25 Photos and videos
Pinned Tweet
YaraXGUI Improvements HexEditor, Yara Match Table to show all matches found. It supports more tab, yara formatting fixed as well. We can browse for rules and filter files that we want to scan this time. Hex editor is added with the goal to make it more hassle free. Within the hexeditor, we can also apply changes, do basic diffing, mark multiple regions and send to YARA editor. Also included a way to select multiple regions and gaps within each regions can be set a wildcard so we do not need to calculate each size. Can now do disassembly of selected region (capstone), draw basic CFG to do quick checks (maybe for certain obfuscation technique or unique code blocks). Simple parsing for PE and ELF file. Added a wonky and (not-so-reliable) autocomplete (NOT based off parser) but good enough I guess for my workflow). To try the new version: github.com/Owl4444/YaraXGUI/…
4
50
209
14,712
malware Owl retweeted
i love this exploit! universal SELinux bypass still works to this day. I released it for Qualcomm based processors and just realized I never released the Exynos version so here it is unprivated: github.com/chompie1337/s8_20…
Replying to @cr3ghost
"Android kernel exploitation bypassing DAC, SELinux, and Knox" - I don't see this? @chompie writes that io_uring exploits could be potentially used for SELinux bypass, is that what you mean?
2
45
270
19,120
:D
1 ft. @malware_owl more to come, probably
2
1
15
1,882
malware Owl retweeted
kind of a funny story that led to this @malware_owl and i cooked up a little something...
1
1
9
970
Last week @ultimat3hg and I decided to try looking for bugs with the help of Prof. Claude and we did find a little something. Reported it and waiting :D
1
9
858
malware Owl retweeted
Following the idea of @eversinc33 and thanks to Claude I was able to lift the VM bytecode to LLVM IR, but due to the stack model, and the calling convention inside of the bytecode, the lifted code doesn't look so fancy 😂😂😂. Link next
Recently @quarkslab published a solution of a CTF using TritonDSE and QBDI where they analyzed a VM protected binary, and I thought "Shit, I want to analyze something too...". And this weekend I did an analysis of another crackme with a custom VM but this time using Triton! 🧵
3
11
93
9,076
malware Owl retweeted
Claude Opus 4.8 is quite good at RE/VR tasks and can provide additional explainable context on the targets. This in itself is a significant time-saver for any REsearch work.
12
19
157
16,216
malware Owl retweeted
Have you noticed that those deep-dive stories about complex Windows malware have pretty much vanished, especially in recent years? It feels like the era of "blockbuster" Windows malware has just gone silent, and this blog post tries to give some answers why. r136a1.dev/2026/05/07/where-…
20
131
594
82,967
malware Owl retweeted
two years ago people said that coding is dead, now they calling hacking is dead ... My take is probably bug bounty/0day for money is dead, but the joy of understanding something deeply will survive, just like coding as the joy of building things. ( but tbf I think 0day for huge $ will be also survived as well )
8
11
104
10,820
Happen to find CVE-2026-3006 :D TL;DR: A TOCTOU bug. When trying to understand it to implement in a project that I was working on. Kudos to maintainer @BZissimopoulos for swift actions and fixes! The Story: While trying looking for ready made drivers for a project that I am working on, I chanced upon WinFSP. The question I had at the time was whether we could extract some file information using the driver without the need to implement kernel driver. However, as I was reading the implementation in a single screen, I spotted the a common pattern (Multi-fetch of size which is used in ExAllocatePool). After writing an exploit to show crash and fully exploit the driver to get SYSTEM, I was given CVE-2026-3006. The affected driver version can be exploited from Low Integrity CMD as well. Licensees that are using WinFSP or users using any tool that uses WinFSP under the hood are advised to upgrade to the new version of WinFSP! Demo (YouTube): youtu.be/aHV7GEBgy5Q
6
36
156
91,081
malware Owl retweeted
🚨Kaspersky GReAT has uncovered a compromised installer of DAEMON Tools Lite distributed directly from the official vendor site since April 8, 2026. It successfully uses a valid developer digital certificate. Affected versions: 12.5.0.2421 to current. Read more in the thread below🧵 1/5
4
28
109
15,327
malware Owl retweeted
Together with @bzvr_, @2igosha and Anton Kargin, we identified that the DAEMON Tools software has been compromised in a complex supply chain attack since April 8. We see thousands of infections across 100 countries. If you use DAEMON Tools, run a malware scan immediately! [1/7]
23
345
1,083
180,507
malware Owl retweeted
1/2‼️ QuimaRAT v2.0.0, a new cross-platform Java-based RAT, is allegedly being sold on a hacking forum, targeting Windows, macOS, and Linux systems. ⠀ ‣ Threat Actor: QuimaCORE ‣ Category: Malware / RAT Sale ‣ Product: QuimaRAT v2.0.0 ‣ Industry: Cybercrime / Malware-as-a-Service ⠀ The actor is advertising a Java 17 JavaFX based remote access trojan claiming FUD (Fully Undetectable) output, end-to-end encryption (Mutual TLS AES-256-GCM), and no Java requirement on target machines. ⠀ What's advertised: ⠀ ▪️ 70 Windows modules / 44 macOS & Linux modules ▪️ Surveillance: keylogger, clipboard logger, screenshot/screen recorder, hidden VNC, webcam/microphone capture, hidden browser ▪️ Credential theft: browser recovery (Chromium/Firefox/Edge), email clients, LSASS dump, RDP/VPN credentials, crypto wallet artifacts, token stealer ▪️ Evasion: AMSI bypass, ETW patcher, UAC bypass, Defender/Firewall disable, process hollowing, DLL injection, shellcode loader, rootkit module ▪️ Network: scanner, SOCKS5/reverse proxy, port forwarding, lateral movement, AD enumerator ▪️ Builder output formats: JAR, EXE (Launch4j), BAT, VBS, NATIVE formats with embedded JRE ▪️ ProGuard obfuscation with 15,600 runtime classes ⠀ Pricing: $200 (1 month) / $400 (3 months) / $600 (6 months) / $800 (12 months) / $2,400 (lifetime)
2
26
163
17,973
malware Owl retweeted
Infosec community right now…
22
73
578
33,047
The ever awesome @NielsProvos dropping knowledge. Vulnerability research with AI is an orchestration thing not a model capability thing at this point. Echoes my sentiments that winning here (defense v offense) is a question of tokens, agents, agility. provos.org/p/finding-zero-da…
1
18
108
21,938