0x0v1 Profile Banner
_0x0v1 Profile
_0x0v1

@0x0v1

Followers
315
Following
436
Media
29
Statuses
453

_hacker _public_interest_technologist _founder_ @barghestasia { disrupting APT, authoritarian gov, surveillance, privacy violations & corporate injustice }

Joined August 2022
Don't wanna be here? Send us removal request.
@IceSolst
solst/ICE of Astarte
1 month
🚨BREAKING AI NEWS: AUTONOMOUS HACKING TOOL UNVEILED by AI experts! China caught using it! The pentesting industry is COOKED!
79
171
2K
@Cyber_O51NT
Cyber_OSINT
2 months
A recent report reveals the "EndClient RAT," a sophisticated malware targeting North Korean Human Rights Defenders, exploiting stolen code-signing to bypass AV, with low detection rates and urgent calls for public awareness. #CyberSecurity #HumanRights
Tweet card summary image
0x0v1.com
Introduction I have had the pleasure to work with PSCORE for quite some time now and we recently did a talk at RightsCon together about the cyber security dynamics for human rights in Korea. PSCORE's...
0
5
15
@0x0v1
_0x0v1
2 months
This is related to the #EndClientRAT report I published yesterday.
@mstoned7
CHA Minseok(Jacky)
2 months
South Korean police are investigating an incident where someone sent malware disguised as a ‘how to deal with stress:’ to a North Korean human rights activist. https://t.co/lxjxmOiDUV (Korean)
0
0
3
@0x0v1
_0x0v1
2 months
My general view and perception of the word 'assistant' has been radically changed, to the point where at times, I have to double check if it means it's true meaning or it is in-fact an AI.
0
0
0
@Proton_Pass
Proton Pass
2 months
>open source >looks inside >no code
@elonmusk
Elon Musk
2 months
https://t.co/op5s4ZikGJ is fully open source, so anyone can use it for anything at no cost
60
267
5K
@0x0v1
_0x0v1
2 months
Highly likely this is #Kimsuky but I don't have enough datapoints on it to validate other than it's using AutoIt and it's targets.
0
1
0
@0x0v1
_0x0v1
2 months
New AutoIt-based campaign targeting Korean HRDs C2 (116[.]202[.]99[.]218). Samples beacon with system info JSON ending in endClient9688. Malware supports upload/download/shell commands. Mutex Global\AB732E15-D8DD-87A1-7464-CE6698819E701. Uses ws2_32 + CryptoAPI. #infosec #IOC
1
1
1
@mynameis_davis
Davis from Youform & OneUp
2 months
Live look at dev teams “actively investigating the issue” as they await a fix from AWS
55
430
11K
@0x0v1
_0x0v1
4 months
Developed by government employees rather than openly in the community, exploits get embargoed, not shared. The paradise of the underground has been paved over by venture capital and compliance frameworks, steamrolling everything we used to stand for. Ref:
phrack.org
Click to read the article on phrack
0
0
0
@0x0v1
_0x0v1
4 months
Now: Hacking is a job title. Curiosity has been commodified. A thousand "Bug Bounty Platforms" are trying to monetize your desire for understanding, to turn it into CVEs and T-shirts. CTFs have become resume-building exercises. Reverse engineers wear corporate badges.
1
0
0
@0x0v1
_0x0v1
4 months
Also include GN/Ninja integration (Google’s build system) for AOSP devices. My guess is most likely used in their Android malware development
0
0
2
@0x0v1
_0x0v1
4 months
- getenforce/setenforce -> Query and modify SELinux enforcemnt - restorecon/runcon -> Reset / run processes under SELinux contexts - sendevent -> Generate low-lvl input evnts (touch/keys) - log, logwrapper -> Interface with Android’s log system - load_policy -> Load SELinux pols
1
0
2
@0x0v1
_0x0v1
4 months
The #Kimsuky divergences in #ToyBox append a new command category in toys/android/ with the following options:
1
0
3
@0x0v1
_0x0v1
4 months
Very interesting. But still need to test it security wise. A very vital use case for this type of technology could include in situations of disaster where internet goes down. War, victims of genocide, protests etc
@callebtc
calle
4 months
bitchat for android is finally on the google play store. install it and get the latest updates as we continue development. upcoming features are going to blow your mind anon. it's going to be insane. please share this post and JOIN THE MESH PIT! https://t.co/ZjaQ1WCszJ
0
0
1
@KNEECAPCEOL
KNEECAP
4 months
A massive GRMA to everyone who came out to support us as their carnival of distraction rolls on. We will be back on September 26th for the Court to determine jurisdiction. We have set out why it does not. Kneecap is not the story. Palestine is the story. The British
227
2K
8K
@0x0v1
_0x0v1
4 months
I guess in the recent update, you could still consider a co-resident app that competes for the forwarded port, but would be less reliable.
0
0
0
@0x0v1
_0x0v1
4 months
Unfortuantely, they patched the bug :(. But since they patched it, I guess it's helpful to now disclose anti-forensic patterns like this.
1
0
0