security research · malware analysis · reverse engineering

Reverse engineering threats, one sample at a time.

In-depth writeups on malware analysis and reverse engineering — static and dynamic triage, unpacking, ATT&CK mapping, and detection rules you can actually deploy.

0x00 SORVEPOTEL (Water Saci) Mar 06, 2026

SORVEPOTEL / Maverick: A Self-Propagating WhatsApp Campaign

Full chain analysis of the SORVEPOTEL campaign — encrypted ZIP lure, VBS dropper, staged Python payload, and WA-JS session hijacking used for automated propagation.

0x01 Lazarus Group Feb 07, 2025

Infostealer malware linked to Lazarus Group campaigns

Analysis of a highly obfuscated Python infostealer using Base64 and ZLIB, tied to Lazarus Group's ClickFix and Contagious Interview campaigns.