security research · malware analysis · reverse engineering
Reverse engineering threats, one sample at a time.
In-depth writeups on malware analysis and reverse engineering — static and dynamic triage, unpacking, ATT&CK mapping, and detection rules you can actually deploy.
SORVEPOTEL / Maverick: A Self-Propagating WhatsApp Campaign
Full chain analysis of the SORVEPOTEL campaign — encrypted ZIP lure, VBS dropper, staged Python payload, and WA-JS session hijacking used for automated propagation.
Infostealer malware linked to Lazarus Group campaigns
Analysis of a highly obfuscated Python infostealer using Base64 and ZLIB, tied to Lazarus Group's ClickFix and Contagious Interview campaigns.