MalwareAnalysisForHedgehogs, Principal Malware Researcher at GDATA, he/him 🦔🌈🏳️‍⚧️

Joined May 2014
1,602 Photos and videos
Pinned Tweet
My intermediate level malware analysis course is there. 60% off for the next two weeks. malwareanalysis-for-hedgehog…

11
49
221
30,569
I submitted a new sample to samplepedia.cc PoisonX rootkit. Video solution follows the next days. samplepedia.cc/sample/db5d28…
1
7
35
1,382
This seems to be a prevalent issue now: People vibe code security applications and the LLM generates real malware for testing. The generated test files rely on real threat actor infrastructure to download or exfiltrate. hxxps://github.com/DataDog/guarddog/blob/main/tests
2
12
50
6,132
This one was a similar case x.com/struppigel/status/2021…

Look like the dev told an LLM to generate test files for a Shai Hulud detection app. The LLM complied and generated malicious test files. github.com/Cobenian/shai-hul…
1
3
2,637
.@_hwangstice did a detailed writeup how the equation editor exploit CVE-2017-11882 works. hwangstice.github.io/blog/rt…
18
36
3,772
😂 @rifteyy just pointed me to this gem in the VT comment section for the empty file virustotal.com/gui/file/e3b0…
1
4
32
3,035
Karsten Hahn retweeted
Together with @bzvr_, @2igosha and Anton Kargin, we identified that the DAEMON Tools software has been compromised in a complex supply chain attack since April 8. We see thousands of infections across 100 countries. If you use DAEMON Tools, run a malware scan immediately! [1/7]
23
345
1,084
180,423
Karsten Hahn retweeted
Apr 23
Malware delivery site https[:]//www-rarlab[.]com - WinRAR app.any.run/tasks/aabc0c21-3…
3
7
43
5,411
New Video: Build your own LLM dynamic analysis lab 🦔🎥 ➡️ AI debugs and unpacks with x64dbg ➡️ AI can access powershell terminal youtube.com/watch?v=QrWzRgPs…
33
95
7,887
Karsten Hahn retweeted
Mr. Titus Tech is correct. cpuid-dot-com is indeed delivering malware right now. As I began poking this with I stick I discovered this is not your typical run-of-the-mill malware. This malware is deeply trojanized, distributes from a compromised domain (cpuid-dot-com), performs file masquerading, is multi-staged, operates (almost) entirely in-memory, and uses some interesting methods to evade EDRs and/or AVs such as proxying NTDLL functionality from a .NET assembly. The C2 domain present in one of the binaries is a clear IoC. This is the same Threat Group who was masquerading FileZilla in early March, 2026. They've been busy.
HWInfo and CPU-Z both compromised. Millions about to be PWNED! CPU Z: hybrid-analysis.com/sample/e… HW Monitor: hybrid-analysis.com/sample/4…
Community note
The post mentions HWInfo, but the link is for HWMonitor. These are different tools from different developers. HWInfo is unaffected. CPU-Z and HWMonitor from cpuid.com are compromised with malware. igorslab.de/en/warning-cpu… reddit.com/r/pcmasterrace… hwinfo.com/forum/threads/…
118
948
7,815
1,643,254
My colleagues have worked hard on analysing and writing a blog article on Kiss Loader. But on your site you make it look like this was your analysis work. Please fix that, @SOC_Prime The person below did not write the KISS loader article with that title.
2
6
52
4,801
Whilst there is a small link to gdata on the top right, there is no indication what that means, and I did not notice that link for the first 20 min. My colleagues are not mentioned anywhere in the text. This is the original: blog.gdatasoftware.com/2026/…
3
25
1,808
Karsten Hahn retweeted
The recording of my first Binary Cartography webinar is now public: Agentic Reverse Engineering: How AI Agents Are Changing Binary Analysis Topics: keygenning, cracking & anti-tamper removal Recording: youtube.com/watch?v=DZcDaXTv… Slides/code/samples: github.com/mrphrazer/binary-…
4
117
403
40,142
My malware analysis courses have now a new certificate design. malwareanalysis-for-hedgehog…
2
17
167
8,883
Added a task for the SugarSMP spark stealer sample to samplepedia samplepedia.cc/sample/060ed0…
2
15
1,220
Karsten Hahn retweeted
Today I’m launching Threat Hunting Labs. Over the years I’ve analyzed many real-world intrusions. One thing became obvious: most training platforms don’t resemble how investigations actually happen. So I built something different. Threat Hunting Labs focuses on investigation-driven learning using real telemetry and structured investigative paths. If you want to get better at investigating breaches, you should practice investigating breaches. More details here: threathuntinglabs.com/blog/i…
21
116
584
47,111
Karsten Hahn retweeted
I am genuinely impressed by mainstream media outlets ability to find absolute nobodies in cybersecurity. It's remarkable. I am often left speechless. There has been dozens occasions, especially as of recent, where some media outlet will be like, "Today as a special guest is world-renowned cybersecurity expert and ethical hacker Joe McCyberSecurity". I'm like, who the fuck is Joe McCybersecurity? I've been doing cybersecurity and malware stuff for a long time and I've never once seen or heard of Joe McCybersecurity. If he is world-renowned, I would THINK I would have seen them or heard of them. The camera then pans over to Joe McCybersecurity and it is the most generic cookie cutter white dude in a cheap suit and the tag below him will say something like, "Joe McCybersecurity, Ethical Hacker, CEO of Cybersecurity McJoe Industries" I'm like, "Cybersecurity McJoe Industries? What the fuck is that?". I look it up and it's a generic WordPress website hosted on GoDaddy with an expired SSL cert. Joe McCybersecurity then babbles incomprehensible nonsense for about 60 seconds until the TV host goes "woaw" and it cuts to a commercial. Absolute cinema.
112
148
2,318
91,263
2
5
34
2,326