Salad on the Side: Unpacking LunarCrypt and the SalatStealer RAT
A Go crypter, a RAT with SQLite in its WebAssembly belly, and an encrypted C2 configuration that eventually introduced itself through an error message. The salad
A Go crypter, a RAT with SQLite in its WebAssembly belly, and an encrypted C2 configuration that eventually introduced itself through an error message. The salad
The "mass" sample arrived as an AES-encrypted ZIP. What it turned out to be: a decoy Romanian engineering app, a fake Chinese security
Part 1 told you what Overlord RAT is. This post is the 48 hours after that: we rebuilt its C2 in an offline lane, drove the
How a routine MalwareBazaar pull turned into a full teardown of a Go surveillance implant that hides its operator on a virtual monitor and how an
1. Executive Summary On 2026-08-27 at 14:30 UTC, a UK recipient received a phishing email spoofing an Intuit QuickBooks payment notification. The email
So I have been playing around with GLM 5.2 alot more lately for the offensive side of things. As mentioned all over this site, I
Z.ai has announced GLM 5.3. It uses the same base model as GLM 5.2. No new pre-training run. No larger foundation model.
Hugging Face says hosted frontier models blocked its forensic prompts during an AI-driven intrusion. A locally hosted GLM 5.2 helped analyse more than 17,000 events without the evidence or credentials leaving its environment.