Featured image of post Project Sodinokibi

Project Sodinokibi

Malware Bazaar and VirusTotal platforms revealed some interesting insights into who manages Sodinokibi, from the perspective of incident response.

Featured image of post The p0sT5n1F3r Backdoor

The p0sT5n1F3r Backdoor

P0sT5n1F3r, a stealthy Apache backdoor built to sniff HTTPS traffic. Undetected by anti-malware platforms, the module used RC4 encryption to hide its activities. Reverse engineering revealed the key, exposing a targeted payload designed to steal credit card data.