Featured Posts
Popular Posts
-

GigaWiper: The Backdoor That Poses as Ransomware — Then Wipes Your Disk for Good
Read More: GigaWiper: The Backdoor That Poses as Ransomware — Then Wipes Your Disk for GoodMicrosoft has detailed GigaWiper, a Go-based Windows backdoor that merges a raw disk wiper, fake ransomware built on Crucio code, and a secure multi-pass wiper into one modular implant…
Latest Articles
-
GigaWiper: The Backdoor That Poses as Ransomware — Then Wipes Your Disk for Good
Read More: GigaWiper: The Backdoor That Poses as Ransomware — Then Wipes Your Disk for GoodMicrosoft has detailed GigaWiper, a Go-based Windows backdoor that merges a raw disk wiper, fake ransomware built on Crucio code, and a secure multi-pass wiper into one modular implant…
-
Claude Code Proxy Detection: Separating Facts from Speculation
Read More: Claude Code Proxy Detection: Separating Facts from SpeculationClaude Code versions 2.1.193 through 2.1.196 used Unicode steganography to encode China proxy detection signals into system prompts — invisible to the eye, but distinct at the byte level.…
-
How Ransomware Encrypts Your Files: A Technical Deep Dive
Read More: How Ransomware Encrypts Your Files: A Technical Deep DiveRansomware uses a hybrid AES-256 + RSA-4096 encryption scheme that’s mathematically unbreakable without the attacker’s master key. Here’s exactly how it works, why decryptors sometimes exist, and what it…
-
ClickFix on macOS: How Hackers Trick You Into Infecting Your Own Mac
Read More: ClickFix on macOS: How Hackers Trick You Into Infecting Your Own MacClickFix is the social engineering technique that bypasses Gatekeeper entirely by tricking macOS users into pasting malicious Terminal commands. Here’s how it works, what it steals, and how to…
-
LOLBAS: How Hackers Use Windows’ Own Tools Against You
Read More: LOLBAS: How Hackers Use Windows’ Own Tools Against YouAttackers don’t always bring their own tools. certutil, mshta, regsvr32, wmic — Microsoft-signed binaries already on your machine can download payloads, run scripts, and establish persistence without triggering traditional…
-
Dissecting a Phishing Email: What the Headers Actually Tell You
Read More: Dissecting a Phishing Email: What the Headers Actually Tell YouThe From field in a phishing email is trivially spoofed. The real story is in the routing headers — the Received chain, SPF/DKIM/DMARC results, and Message-ID. Here’s how to…
-
North Korea’s Secret Army: How DPRK IT Workers Infiltrated 300+ US Companies
Read More: North Korea’s Secret Army: How DPRK IT Workers Infiltrated 300+ US CompaniesNorth Korean government operatives are posing as remote IT workers inside Western companies, funnelling salaries to fund weapons programs. With $800M+ generated in 2024 and 300+ US firms compromised,…
-
Windows Event Log IDs Every Blue Teamer Should Know
Read More: Windows Event Log IDs Every Blue Teamer Should KnowThere are hundreds of Windows Event IDs but you really only need about 30 of them to catch most attacks. Here are the ones that matter, what they mean,…
-
Google Dorks: How Hackers Use Search Engines to Find Vulnerable Websites
Read More: Google Dorks: How Hackers Use Search Engines to Find Vulnerable WebsitesBefore an attacker writes a single line of exploit code, they’ve already mapped your attack surface using nothing but Google. Here’s how Google Dorking works and how to find…
-
Unveiling the Snake Infostealer: How It Spreads Through Facebook Messenger
Read More: Unveiling the Snake Infostealer: How It Spreads Through Facebook MessengerIn early 2024, researchers at Cybereason uncovered a new threat targeting Facebook users — a Python-based information stealer dubbed Snake (not to be confused with the Russian state-sponsored Snake…
About Author

Subhash Thapa
Security Analyst (SOC, AI, MDR & IR) | CEH | CCSP | CCIO | CSFPC
Latest Posts
Weekly threat intel, straight to your inbox
Free. No noise. Unsubscribe anytime.











