Observed Telegram Bot Naming Patterns in Recent MuddyWater Malware Activity
by Robin Dost Subscribe Newsletter I recently took a look at the wave of MuddyWater malware samples from 2026 and...
by Robin Dost Subscribe Newsletter I recently took a look at the wave of MuddyWater malware samples from 2026 and...
by Robin Dost Subscribe Newsletter EDIT: 04.02.2026: I have YARA Rules available for detection, contact me at contact@robin-dost.de if you...
by Robin Dost Subscribe Newsletter Today I stumbled over a rather accidental finding during a routine analysis of North Korean...
by Robin Dost Subscribe Newsletter As already mentioned in my last MuddyWater article, I originally planned to take a closer...
by Robin Dost Subscribe Newsletter There’s yet another update in Gamaredons GamaLoad scripts, which pushed me to write this article...
by Robin Dost Subscribe Newsletter EDIT 2026-01-18: I published a follow-up article analyzing the evolution and version history of the...
by Robin Dost Subscribe Newsletter EDIT: If you're interested in how I efficiently track threat actors such as Gamaredon, feel...
by Robin Dost Subscribe Newsletter In malware analysis, it is tempting to describe change as innovation.New tricks, new tooling, new...
by Robin Dost Subscribe Newsletter After my recent blog posts covering Gamaredon’s ongoing PterodoGraph campaign targeting Ukraine, and following almost...
by Robin Dost Subscribe Newsletter UPDATE 22.12.2025: Gamaredon updated it's payload delivery infrastructure. You can find more information here.UPDATE 08.01.2026:...