I tweet about my learning in Malware analysis, Threat Intel, Detection engineer and DFIR journey.
Opinions are mine only!securityinbits.com SingaporeJoined September 2015
@Securityinbits I recently built a lightweight Python tool to detect & block clipboard manipulation in real time:
👉 github.com/marktsec/Clipb…
Open-source, feedback welcome!
ClickFix just got clever-ditched Win+R for Win+X (Power User Menu) ⚠️
New variant drops Lumma after Defender exclusion:
- Prompts for elevation till user accept
- Add defender exclusion on %temp%
- Drops & runs Lumma
Multiple Sigma rules fired 💥
Process Tree👇
There are plenty of malware‑analysis tools - but pe‑sieve (@hasherezade) + YARA Forge (@cyb3rops) is one of the sharpest offline combos to identify malware families.
Dump → PE‑sieve
Scan → YARA Forge
ID → Malware family
Step‑by‑step walkthrough in the video below 👇
Defending against Akira? (Part 1)
Akira Ransomware is topping the charts again 📈
In the latest @TheDFIRReport case, TA abused wbadmin to dump before encryption
Sigma rule👇
I'll cover other commands Akira is using next. Stay tuned.
Event Log IDs in the reply 👇
Oh my god, making a YouTube video takes so much time - X is much easier 😌
I’m working on my 2nd video of the year, but the audio quality isn’t great.
The video is about how to identify a malware family using pe-sieve and YARA rules.
1st video - Text wasn’t very clear, but the…
Deep dive into ClickFix delivering Quasar RAT:
✅ Live exploit demo (fake Cloudflare)
✅ Clipboard payload & Telegram bot analysis
✅ C2 traffic interception via FakeNet-NG
✅ Malware detection using YARA Forge rules
Watch this video to see how it all unfolds👇
Cybercriminals are levelling up their game with ClickFix - targeting multiple OS & languages
Screenshot
Linux
Mac
Win
Multilingual Support:
Interesting domain from @solostalking
Follow along! I'll keep this thread updated as I dig deeper. And feel free to jump in.
One of the easiest ways to spot newly active ClickFix domains:
Use this @fofabot query 👇
body="In the verification window, press <b>Ctrl</b>"
Over 50+ domains in last 30 days
TOP 2 title:
- Checking if you are human
- reCAPTCHA Verification
Trading view themed ClickFix 👇
327 Followers 2K FollowingCo-founder and CEO at CouponRoller. Canadian-born, Israeli-educated. Many years in the high-tech scene. Tweeting about #startups and being an #entrepreneur.
1K Followers 2K FollowingBlue girl gone red / recovering .edu CISO / Will infodump about Tron on demand / Finally acquiesced to “cyber” as a prefix / Not @jotunvillur. she/her
10K Followers 462 FollowingThreat Researcher at Check Point @_CPResearch_ #DFIR #Reversing - All opinions expressed here are mine only.
https://t.co/iWvwWF1AnN
89K Followers 910 FollowingProgrammer, #malware analyst. Author of #PEbear, #PEsieve, #TinyTracer. Private account. All opinions expressed here are mine only (not of my employer etc)
665 Followers 1K Following🇮🇹 | IT Engineer with Cyber Security passion | Malware Analysis | Reverse Engineering | CTI
- views and opinions are solely my own -
4.3M Followers 3 FollowingOpenAI’s mission is to ensure that artificial general intelligence benefits all of humanity. We’re hiring: https://t.co/dJGr6Lg202
229K Followers 679 FollowingOn a mission to become a better writer, thinker, and entrepreneur • Ex-dentist, now building an internet business (at ~$500k/year).
8K Followers 217 Followingai/ml engineer. youngest to get a phd in biostats from ucsd. spent the last 6 years building AI systems for startups, mid-sized companies & global enterprises
1.4M Followers 1K FollowingBuilding @EurekaLabsAI. Previously Director of AI @ Tesla, founding team @ OpenAI, CS231n/PhD @ Stanford. I like to train large deep neural nets.
210K Followers 359 FollowingI build & teach AI stuff. Founder @TakeoffAI where we’re building an AI coding tutor. Come learn to code + build with AI at https://t.co/oJ8PNoAutE.
2K Followers 68 FollowingPwned Labs delivers fun and immersive cybersecurity training experiences for individuals and businesses. Join the community: https://t.co/kyG413GZDa
9K Followers 853 FollowingBad guy chaser, writer/author, espionage & ransomware SME. Sometimes I harass my dog. He is the brains behind these projects and opinions are his.
30K Followers 192 FollowingEmpowering businesses with proactive security solutions: Interactive Sandbox,
TI Lookup and Feeds. Sign up for free: https://t.co/8hIX0Qh5ME
325K Followers 119 FollowingEmpowering the world to fight cyber threats with indispensable cybersecurity skills and resources. Build the path to a secure future with OffSec.
26K Followers 1K FollowingI play with vulnerabilities and exploits. I used to be here on Twitter but now I'm here:
@[email protected]
https://t.co/hXggdAVkSQ
1K Followers 595 FollowingRetired National Security Agency, U.S. Cyber Command, Cyber National Mission Force, and U.S. Space Command
Monitoring cyber events #ThreatIntelligence
1K Followers 95 FollowingDeveloper - Reverse Engineer - CTF player - Scrub.
🔧 I develop #AsmResolver, ✍️ blog at https://t.co/2WDyyrf4Rc, and sometimes 👾 hack with @Shellphish
14K Followers 916 FollowingWindows Internals expert, author, and trainer. Teaching system programming & debugging at TrainSec. Check out my books & courses! 🚀 #WindowsInternals #TrainSec
No recent Favorites. New Favorites will appear here.