Local LLM
A 15 KB DLL that silently rewrites cryptocurrency addresses on your clipboard. I pulled it apart statically, confirmed it in a sandbox, recovered all nine of
malware
A Go crypter, a RAT with SQLite in its WebAssembly belly, and an encrypted C2 configuration that eventually introduced itself through an error message. The salad
Reverse Engineering
Part 1 told you what Overlord RAT is. This post is the 48 hours after that: we rebuilt its C2 in an offline lane, drove the
malware
How a routine MalwareBazaar pull turned into a full teardown of a Go surveillance implant that hides its operator on a virtual monitor and how an
notes
We took two C2 IP addresses from a malware news article and pivoted through Shodan, DNS, reverse MX lookups, certificate transparency, WHOIS, and MITRE ATT&