UAC-0184: From HTA to a Signed Network Stack
by Robin Dost Subscribe Newsletter EDIT: The next article in my UAC series is out: https://blog.synapticsystems.de/uac-0247-malware-targeting-fpv-operators/ Actor: UAC-0184 / MB-0007...
by Robin Dost Subscribe Newsletter EDIT: The next article in my UAC series is out: https://blog.synapticsystems.de/uac-0247-malware-targeting-fpv-operators/ Actor: UAC-0184 / MB-0007...
by Robin DostPart 4 of 7 of building the Malwarebox EcosystemWebsite: https://iimql.malwarebox.euGitHub: https://github.com/MalwareboxEU/IIMQL In the previous part, I introduced IIM,...
by Robin Dost Part 3 of 7 of building the Malwarebox EcosystemOfficial Website: https://iim.malwarebox.euGitHub: https://github.com/MalwareboxEU/IIM EDIT: I released part 4...
by Robin Dost Subscribe Newsletter Today I took a look at a pretty standard LNK malware sample and ended up...
by Robin Dost Subscribe Newsletter EDIT: I have YARA rules available for this one, if you need them, contact me...
by Robin Dost Subscribe Newsletter Part 1 of 7 of building the Malwarebox EcosystemOfficial Website: https://kraken.malwarebox.eu Whitepaper Tracking Gamaredon infrastructure is...
by Robin Dost Subscribe Newsletter I recently took a look at the wave of MuddyWater malware samples from 2026 and...
by Robin Dost Subscribe Newsletter EDIT: 04.02.2026: I have YARA Rules available for detection, contact me at contact@robin-dost.de if you...
by Robin DostPart 2 of 7 of building the Malwarebox EcosystemOfficial Website: https://acdp.malwarebox.euGitHub: https://github.com/MalwareboxEU/ACDP Introduction Much of my previous work has focused...
by Robin Dost Subscribe Newsletter Today I stumbled over a rather accidental finding during a routine analysis of North Korean...