Research worth sharing.
Investigations, experiments, and methods from the people in the club.
Analyzing the Midnight Blizzard Eviction Plan
A hands-on walkthrough of rebuilding the Midnight Blizzard OAuth attack chain in Azure and developing an eviction plan for it.
Darkgate 3: Return of the Temp
Analyzing the prolific malware loader that loves AutoIt.
Install Linters, Get Malware - DevSecOps Speedrun Edition
How Scavenger rode a compromised npm eslint-config-prettier: loader/stealer internals, anti-analysis + XXTEA C2, Chromium targeting, BeamNG ties, and actionable IOCs (with InvokeRE)
Supper is served
A deep dive into Supper (Interlock RAT) a fileless Windows backdoor linked to Vice Society clarifying public report errors and detailing its C2 protocol, encryption, self-deletion, and reverse shell behavior.
Analyzing the RedTiger Malware Stealer
Analysis of RedTiger, a python based stealer that leverages Discord to exfiltrate credentials
Dissecting a fresh BlankGrabber sample
Analysis of BlankGrabber, a python based stealer
Threat hunting for shits and giggles
Analyzing XWorm and tracking related infrastructure with hunt.io
Full investigations written and published by the IRCC community.