MatheuzSecurity Profile Banner
MatheuZ Profile
MatheuZ

@MatheuzSecurity

Followers
2K
Following
1K
Media
40
Statuses
631

Red Team Operator, Cyber Threat Intelligence, Malware Researcher

Brazil
Joined September 2020
Don't wanna be here? Send us removal request.
@MatheuzSecurity
MatheuZ
9 months
https://t.co/pWpa1tp2KX Hey guys, I posted a really cool zine in pure TXT about Unhooking Linux EDR, attacking the cleanup_module function, to be able to remove any hook from an EDR for example. Feel free to read.
3
44
153
@MatheuzSecurity
MatheuZ
4 days
I’m excited to share that my name has officially been added to Trend Micro Security Researcher Acknowledgment page for 2025. https://t.co/p5ixQGFxnc #security #vulnerability #researcher #kernel #linux #edr #trendmicro #cybersecurity #hacking #redteam #malware
0
0
4
@the_yellow_fall
Gray Hats
7 days
Singularity is an advanced Linux Kernel 6.x rootkit that uses ftrace hooking to provide comprehensive stealth, including process/file hiding and eBPF/EDR detection evasion. https://t.co/Z3Ur6niMu4
1
29
101
@MatheuzSecurity
MatheuZ
13 days
My second CVE has just been published: CVE-2025-13792 I discovered a critical Code Injection vulnerability in the Qualitor Software system (versions up to 8.20.104/8.24.97) that allows RCE without authentication. More details: https://t.co/mawFoF7DIo #cybersec #cve #webapp
0
1
10
@MatheuzSecurity
MatheuZ
25 days
New stealthy feature to Singularity Hook netlink_unicast for audit evasion Hidden processes now invisible to auditd, ausearch, and audit subsystem queries. Msg filtered at kernel netlink layer before reaching userspace. #rootkits #linux #rootkit https://t.co/MKRjVgBROo
Tweet card summary image
github.com
Stealthy Linux Kernel Rootkit for modern kernels (6x) - MatheuZSecurity/Singularity
2
11
37
@MatheuzSecurity
MatheuZ
25 days
New stealthy feature to Singularity Hook netlink_unicast for audit evasion Hidden processes now invisible to auditd, ausearch, and audit subsystem queries. Msg filtered at kernel netlink layer before reaching userspace. #rootkits #linux #rootkit https://t.co/MKRjVgBROo
Tweet card summary image
github.com
Stealthy Linux Kernel Rootkit for modern kernels (6x) - MatheuZSecurity/Singularity
2
11
37
@eletro_vibez
Eletro Vibez
5 months
VÍRUS 🦠 #Tomorrowland
2
47
269
@ravesnobrasil
ravesnobrasil
1 month
Onde você estava em 2010? Porque a Altruism tava metendo uma sonzeira no Universo Paralello 🤌
2
6
89
@MatheuzSecurity
MatheuZ
2 months
Evading Elastic Security - Deep dive into bypassing detections through string obfuscation, symbol randomization, XOR-encoded fragments & behavioral evasion techniques https://t.co/WB3JF52E4l #infosec #redteam #linux #rootkit #elastic #malware #rootkits
Tweet card summary image
matheuzsecurity.github.io
Bypassing YARA rules and behavioral detection through symbol randomization, module fragmentation, XOR encoding, and ICMP reverse shell staging
0
82
326
@MatheuzSecurity
MatheuZ
2 months
Evading Elastic Security - Deep dive into bypassing detections through string obfuscation, symbol randomization, XOR-encoded fragments & behavioral evasion techniques https://t.co/WB3JF52E4l #infosec #redteam #linux #rootkit #elastic #malware #rootkits
Tweet card summary image
matheuzsecurity.github.io
Bypassing YARA rules and behavioral detection through symbol randomization, module fragmentation, XOR encoding, and ICMP reverse shell staging
0
82
326
@MatheuzSecurity
MatheuZ
2 months
Singularity rootkit update: ICMP reverse shell trigger, which activates a reverse connection through custom ICMP packets. Source: https://t.co/MKRjVgCpDW #linux #rootkits #lkm #singularity #malware #icmp #backdoor #hooking
11
81
396
@MatheuzSecurity
MatheuZ
2 months
Singularity rootkit update: ICMP reverse shell trigger, which activates a reverse connection through custom ICMP packets. Source: https://t.co/MKRjVgCpDW #linux #rootkits #lkm #singularity #malware #icmp #backdoor #hooking
11
81
396
@MatheuzSecurity
MatheuZ
2 months
2
4
21
@MatheuzSecurity
MatheuZ
2 months
2
4
21
@akaclandestine
Clandestine
2 months
Singularity: Deep Dive into a Modern Stealth Linux Kernel Rootkit
blog.kyntra.io
Deep dive into a modern stealth Linux kernel rootkit with advanced evasion and persistence techniques
0
3
7
@MatheuzSecurity
MatheuZ
2 months
Singularity: Deep Dive into a Modern Stealth Linux Kernel Rootkit I published a very interesting article detailing a little more about my Linux Kernel Rootkit and its system call hooking. Feel free to read and share. https://t.co/vz2Ef7a1w5
blog.kyntra.io
Deep dive into a modern stealth Linux kernel rootkit with advanced evasion and persistence techniques
0
17
37
@kyntra_io
Kyntra.io
2 months
🚨 Post novo publicado! 🔎 Singularity: Deep Dive into a Modern Stealth Linux Kernel Rootkit ✍️ @MatheuzSecurity 👉 https://t.co/dLJQZcyeRG #rootkit #cybersecurity #security #linux #kernel #redteam #pentest
5
23
49
@akaclandestine
Clandestine
2 months
Singularity: Deep Dive into a Modern Stealth Linux Kernel Rootkit
blog.kyntra.io
Deep dive into a modern stealth Linux kernel rootkit with advanced evasion and persistence techniques
0
6
19
@MatheuzSecurity
MatheuZ
2 months
Singularity: Deep Dive into a Modern Stealth Linux Kernel Rootkit I published a very interesting article detailing a little more about my Linux Kernel Rootkit and its system call hooking. Feel free to read and share. https://t.co/vz2Ef7a1w5
blog.kyntra.io
Deep dive into a modern stealth Linux kernel rootkit with advanced evasion and persistence techniques
0
17
37