Joined June 2020
150 Photos and videos
Pinned Tweet
I am excited, my talk about #ThreatIntelligence and #MalwareAnalysis is also there. Saturday 14:00 Such an honor for me 🙂 #DEFCON #DC29
1
6
MalwareLab retweeted
📢📢📢 Ladislav Bačo is back for round two! On March 11, Ladislav Bačo shares practical approaches for integrating network forensics into IR workflows, with perspectives for home and small office networks. Register: us02web.zoom.us/webinar/regi… #Suricata
6
9
588
MalwareLab retweeted
Join me on Wednesday to see how to build your own home network monitoring setup under $100. Traffic capture, IDS, lightweight SIEM and alerting included.
Join this webinar on Feb 11 with Ladislav Bačo to see how open-source IDS/IPS with #Suricata delivers network monitoring on a budget. You’ll watch a full live deployment and see how malicious traffic is detected and alerted in real time. Register today! us02web.zoom.us/webinar/regi…
2
1
235
Seeing posts like this on #moltbook, I am thinking about recent #threats emerging from the heavy usage of #AI agents without any security guardrails or proper controls. This time, "only" a command to send an innocent email. Next time, it might be #DDoS, #malware, or #dataleak
1
1
699
An no, #moltbook is not AI agents-only social network. It uses REST API, so everyone could follow the howto for AI agents, register there and post anything. Including malicious content and command injects for AI agents.
1
155
MalwareLab retweeted
27 Nov 2025
We’ve identified an interesting malware family 🔍, which we’ve named #GrokPy due to its use of a Grok LLM model 🤖 to solve and subsequently bypass CAPTCHAs 🔥 The malware gets dropped by #Amadey and: 🪝 collects information about the infected device, such as screen resolution, public IP & location, ram usage and CPU name 💻 attempts to escalate privileges by running as admin or as a scheduled task ⚙️ uses the CDP (Chrome developer protocol) of either Edge or Chrome installed on the victim machine for further malicious actions 📡 calls back to the botnet C2 on the various stages of the infection and the results of its malicious actions 👱 creates new accounts on Discord to obtain authentication tokens, which are then reported back to the botnet C2 📧 uses dilly [a-zA-Z0-9]{8,11}@gmail.com password [a-zA-Z0-9]{8} as the email and password for the Discord registration process 🔍 has OCR capabilities for screenshots obtained via CDP, which are used to extract text from captcha 🤖 uses a Grok LLM model that resides in the botnet C2 server to solve the captcha Botnet C2 servers are all hosted at @Hetzner_Online 🇩🇪on port 8008 TCP: 46[.]62.225.51 [active] 46[.]62.224.205 46[.]62.205.38 GrokPy malware samples on MalwareBazaar: 📄bazaar.abuse.ch/browse/signa… Botnet C2s on ThreatFox: 🦊threatfox.abuse.ch/browse/ta…
4
43
132
19,101
2
5
21
2,256
Yesterday I attended #SOC #DetectionEngineering Crash Course with Hayden Covington by @KilobyteTheDust of @Antisy_Training antisyphontraining.com/produ… In overall, it was very good workshop and I am happy for opportunity to attend it. More in the thread.
2
2
6
378
The usage of "free" cloud infrastructure is inspiring, I will consider it during my next trainings for larger group of students (instead of hosting all of the VMs in our cloud infrastructure) - this way, lot of things can students do labs again after the training
1
1
115
In overall, it was very good workshop and I am happy for opportunity to attend it.
1
99
MalwareLab retweeted
7 Dec 2024
✨This weekend syncs with the first week of the Advent of Radare! Take some weekend time to catch up with the challenges and learn new features and syntax tricks! radare.org/advent #aor24
8
26
1,869
MalwareLab retweeted
17 Nov 2024
All the workshop recordings and slides from #r2con2024 are now edited and published. If you didn't had a chance to attend now it's a good time to catch up starting right from the very first day! 👉 radare.org/con/2024/
1
102
239
18,321
During the #SharkBytes session at #SharkFest conference I had an opportunity to present a short talk about my pet project IDS Lab. The lab infra is deployable as #docker containers, used for attack simulations and detections. github.com/SecurityDungeon/i… #sf24eu @wiresharkfest
3
7
18
1,410
That looks powerful, but still very simple to use. And it is primary for Tiny C compiler #tcc, which is also one of the projects worth the attention. #reversing #reverseengineering #codeanalysis #obfuscation #malwareanalysis
11 Nov 2024
obfus.h is the powerfull compile-time obfuscator for C (win32/64). Supports virtualization, anti-debugging, control flow obfuscation and other code mutation techniques to prevent disassembly or decompilation. #CodeSecurity #Obfuscation #infosec github.com/DosX-dev/obfus.h
1
5
304
MalwareLab retweeted
29 Oct 2024
🎉 As #CyberSecurityAwareness Month comes to an end, we’re celebrating by sharing some of our awesome friends! 💡Follow them for insightful cyber tips and great analyses. Here’s the list, in no specific order: @James_inthe_box @M4lcode @RussianPanda9xx @BlueEye46572843 @JAMESWT_MHT @ericparker @akaclandestine @Ax_Sharma @petikvx @g0njxa @executemalware @kondah_ha @fr0gger_ @NicoKnowsTechYT @embee_research @RacWatchin8872 @lennyzeltser @Gi7w0rm @jstrosch @_JohnHammond @malwarelab_eu This list is just the beginning — feel free to drop your own cybersecurity profiles in the comments!

ALT Happy Season 3 GIF by Friends

11
7
32
4,514
Is it really 8th birthday of @anyrun_app?🎂 I can remember my beginnings with this #sandbox. It was quite different from other sandboxes: it was interactive and so fast. Its evolution was significant since then and now there is a special deal until May 31: app.any.run/plans/

30 May 2024
Hurry up to get #ANYRUN birthday deals, ending May 31 🎂 🎁 6 months of free access to your favorite plan 🎁 Bonus licenses for your colleagues Pro tip: You can reserve now and pay later 😉 Grab your gift ➡️ app.any.run/plans/?utm_sourc…
3
343