Johann Aydinbas
@jaydinbas
Followers
2K
Following
2K
Media
65
Statuses
529
Reverse engineering, malware
Joined December 2016
Couldn't find a _pure_ Python implementation of PowerShell's SecureStringToBSTR, used in some malware samples, so I wrote one: https://t.co/fvwEQBlaFw
gist.github.com
Pure Python implementation of SecureStringToBSTR. GitHub Gist: instantly share code, notes, and snippets.
0
0
5
🔎Our CERT is releasing a new technical report on 🇰🇵Operation #DreamJob, focusing on recent evolution in its tooling. Following an IR engagement at a large manufacturing client based in 🇪🇺, we investigated artefacts we attribute to #UNC2970. ➡️Full blog: https://t.co/o8px0jZmfc
1
51
193
Multiple members of the German parliament received suspicius thumb drives, urged not to plug them in (GER): https://t.co/9sfZ6dtKnM
spiegel.de
Abgeordnete verschiedener Bundestagsfraktionen haben laut Medienberichten verdächtige USB-Sticks zugeschickt bekommen. Demnach warnt die Bundestagspolizei davor, die Sticks an Geräte anzuschließen.
0
0
0
All I want for Christmas is a Transporter Erector Launcher Hwasong 18 in 1/48 scale resin print 🥰
0
0
1
New Kimsuky Malware “EndClient RAT”: First Technical Report and IOCs https://t.co/GQceqxXMHj
#kimsuky #lazarus #northkorea #humanrights @lazarusholic
0x0v1.com
Introduction I have had the pleasure to work with PSCORE for quite some time now and we recently did a talk at RightsCon together about the cyber security dynamics for human rights in Korea. PSCORE's...
0
3
9
🚨 How Fast You Detect - and Respond - Can Define the Outcome of a Cyber Incident 👉 Read more on our latest blog where we show how early detection and response made the difference https://t.co/OITMBaQp7n
medium.com
What if an attacker in your environment isn’t game over, but rather your chance to take control?
0
2
2
#ESETresearch has discovered the first known cases of collaboration between Gamaredon and Turla, in Ukraine. Both groups are affiliated with the FSB, Russia’s main domestic intelligence and security agency. https://t.co/1cADq5kf7p 1/3
welivesecurity.com
ESET researchers reveal how the notorious APT group Turla collaborates with fellow FSB-associated group known as Gamaredon to compromise high‑profile targets in Ukraine.
3
39
96
Another absolute banger from Chollima Group. Those that worked it are animals and hats off to the unnamed. https://t.co/4NO9Gwm8VM
0
11
18
🔥 So, at DEF CON there was a talk about deobfuscation: VMDragonSlayer by @Van1sh_BSidesIT. The author released the code and there's clearly huge amounts of AI slop.🤖 Now, WE WENT TO THE TALK and spoke with the speaker after the talk. 🧵
How did this AI slop get a talk at the main track @ DEFCON????????? https://t.co/uN5KrfiBg7
7
49
335
News🔥#NordStream attacks: German police investigators have obtained arrest warrants for six Ukrainian nationals - the whole crew of the „#Andromeda“. A seventh suspect allegedly was killed fighting Russians last year. Our report: https://t.co/uqZJfGvuVl
#Ukraine #Sabotage
tagesschau.de
Die Nord-Stream-Ermittlungen sind weiter fortgeschritten als bislang bekannt. Fahnder haben nach Recherchen von ARD, SZ und Zeit nun Haftbefehle gegen sechs Ukrainer erwirkt. Es gibt weitere Hinweise...
4
10
17
📣 Introducing the IDA Domain API: a new open-source Python API that makes scripting in IDA simpler and more consistent. https://t.co/UmRf3eEDy0
1
20
77
Der Cyberraum ist nicht losgelöst von der physischen Welt. Manche Cyberangriffe haben das Ziel, Straftaten in der sogenannten "Realwelt" zu ermöglichen. U. a. wurden Lagerhaltungs-Datenbanken kompromittiert, um zielgenau Waren zu stehlen. Mehr Beispiele:
bsi.bund.de
0
4
9
It's been a while! In our latest blog post we shed light on the #SafePay #ransomware which has been targeting 🇩🇪German organizations lately. You can read it here: https://t.co/HUTvVoAlDG
medium.com
Analysis of the SafePay ransomware recently focusing on Germany
0
3
3
AhnLab has released the TA-ShadowCricket (Shadowforce) report. I worked on it as the lead author together with NCSC (The National Cybersecurity Center). I would like to thank NCSC and my colleagues for their support. https://t.co/RqKfYonne1 (Korean) @jaydinbas
asec.ahnlab.com
NCSC와 함께한 TA-ShadowCricket 분석: 최신 악성코드 트렌드와 IRC 서버 추적 ASEC
1
5
26
The European Council 🇪🇺 has issued sanctions against Stark Industries, a hosting company registered in the UK 🇬🇧, as "they have been acting as enablers of various Russian state-sponsored and affiliated actors to conduct destabilising activities including, information manipulation
2
34
71
The Cybersecurity Observatory of Unipegaso has unveiled a report on Sarcoma ransomware, detailing its aggressive tactics and significant breaches, urging enhanced defenses against this growing threat. #SarcomaRansomware #Cybersecurity
securityaffairs.com
Cybersecurity Observatory of the Unipegaso's malware lab published a detailed analysis of the Sarcoma ransomware.
0
5
8