<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Threat Unpacked</title><description>Operational malware analysis — deep dives into incidents, implants, and intrusion sets.</description><link>https://threatunpacked.com/</link><item><title>DragonForce: Deep Reverse Engineering of the Ransomware Behind M&amp;S and Co-op UK</title><link>https://threatunpacked.com/2026/07/07/dragonforce-ransomware-deep-re/</link><guid isPermaLink="true">https://threatunpacked.com/2026/07/07/dragonforce-ransomware-deep-re/</guid><description>Full technical analysis of DragonForce&apos;s Windows x86 encryptor: MinGW C++ with Salsa20 multi-mode encryption, BYOVD kernel driver EDR bypass (rentdrv2.sys + truesight.sys), WMI shadow copy deletion, Restart Manager file handle killing, IOCP network scanning, and COM-based scheduled task persistence.</description><pubDate>Tue, 07 Jul 2026 12:00:00 GMT</pubDate></item><item><title>RansomHub: Deep Reverse Engineering of the #1 Active RaaS</title><link>https://threatunpacked.com/2026/07/06/ransomhub-go-ransomware-deep-re/</link><guid isPermaLink="true">https://threatunpacked.com/2026/07/06/ransomhub-go-ransomware-deep-re/</guid><description>Full technical analysis of RansomHub&apos;s Go-based Windows encryptor: garble package obfuscation, X25519+ChaCha20 encryption scheme, built-in SMB lateral movement using go-smb, IOCP parallel file encryption, and service recovery disruption.</description><pubDate>Mon, 06 Jul 2026 12:00:00 GMT</pubDate></item><item><title>SafePay Ransomware: Deep Reverse Engineering of a LockBit 3.0 Fork</title><link>https://threatunpacked.com/2026/07/05/safepay-ransomware-lockbit-fork-deep-re/</link><guid isPermaLink="true">https://threatunpacked.com/2026/07/05/safepay-ransomware-lockbit-fork-deep-re/</guid><description>Assembly-level analysis of SafePay ransomware — a LockBit 3.0 derivative with a custom CRC-32 import resolver, triple-XOR string obfuscation, IOCP-driven parallel encryption, and NT-layer privilege escalation. Full API inventory recovered by cracking 130+ export hashes.</description><pubDate>Sun, 05 Jul 2026 12:00:00 GMT</pubDate></item><item><title>WealthGAF and ASYNCBOTNET: A Fake Forex CRM Brand Built to Deliver a Four-Stage Python RAT</title><link>https://threatunpacked.com/2026/07/04/wealthgaf-asyncbotnet-forex-rat/</link><guid isPermaLink="true">https://threatunpacked.com/2026/07/04/wealthgaf-asyncbotnet-forex-rat/</guid><description>A 2,253-byte ZIP posing as API documentation for a fake forex CRM delivers a four-stage chain: LNK trojan with conhost --headless hiding, a compiled AutoIt downloader, a PNG/ZIP polyglot Python bundle, and a previously undocumented Socket.IO RAT named ASYNCBOTNET that monitors 14 crypto wallets and 12 exchanges. A single TLS certificate ties WealthGAF to a 13-brand fake forex platform cluster, all sharing the same Kubernetes C2 origin.</description><pubDate>Sat, 04 Jul 2026 18:00:00 GMT</pubDate></item><item><title>Ph-Tagged, Tunnel-Hopping, and APC-Injecting: Inside the SERPENTINE#CLOUD Dropper Chain</title><link>https://threatunpacked.com/2026/07/04/serpentine-cloud-cloudflare-tunnel-asyncrat/</link><guid isPermaLink="true">https://threatunpacked.com/2026/07/04/serpentine-cloud-cloudflare-tunnel-asyncrat/</guid><description>A WsgiDAV opendir tip from @smica83 leads to a live SERPENTINE#CLOUD staging server on a Cloudflare Tunnel. Three BAT files, two delivery paths, four Python runtimes, an Early Bird APC DLL, and a naming convention that traces the campaign back to December 2022.</description><pubDate>Sat, 04 Jul 2026 12:00:00 GMT</pubDate></item><item><title>Root in Eight Weeks: Reconstructing a Chinese Operator&apos;s Kill Chain Through Brazil&apos;s Federal District Government Network</title><link>https://threatunpacked.com/2026/07/02/semob-gdf-kill-chain/</link><guid isPermaLink="true">https://threatunpacked.com/2026/07/02/semob-gdf-kill-chain/</guid><description>File timestamps preserved inside a 9.1GB archive found on a Chinese threat actor&apos;s staging server let us reconstruct a complete intrusion: WordPress web shell to DirtyPipe container escape, socat tunnelling, fscan credential spray across 164 government machines, and 754MB of internal GitLab source code — all in eight weeks.</description><pubDate>Thu, 02 Jul 2026 22:00:00 GMT</pubDate></item><item><title>Ice Scorpion on Alibaba: A Chinese Operator&apos;s Singapore Staging Server, 164 Compromised Brazilian Government Machines, and a 933MB Fake GPU Driver</title><link>https://threatunpacked.com/2026/07/02/behinder-alibaba-brazil-staging/</link><guid isPermaLink="true">https://threatunpacked.com/2026/07/02/behinder-alibaba-brazil-staging/</guid><description>A Shodan hit on an Alibaba Cloud Singapore IP leads to a 9.1GB archive that turns out to be an attacker&apos;s working directory from inside a compromised Brazilian government server — containing a DirtyPipe exploit, fscan lateral movement results across the GDF internal network, 164 confirmed credential compromises, and 754MB of exfiltrated GitLab source code.</description><pubDate>Thu, 02 Jul 2026 20:00:00 GMT</pubDate></item><item><title>MegaDumper: One Staging Server, Five Years, Zero Detections</title><link>https://threatunpacked.com/2026/07/02/megadumper-trumvps-five-year-staging-server/</link><guid isPermaLink="true">https://threatunpacked.com/2026/07/02/megadumper-trumvps-five-year-staging-server/</guid><description>A Shodan scan for Singapore open directories surfaces a TRUMVPS server that has been quietly hosting the same .NET credential stealer — under the same filename — since 2021. The current build has zero detections.</description><pubDate>Thu, 02 Jul 2026 18:00:00 GMT</pubDate></item><item><title>NAKAZ MO: Property Declaration Lure Targeting Ukrainian Ministry of Defence Personnel</title><link>https://threatunpacked.com/2026/07/02/nakaz-mo-ukraine-lnk-ps1-downloader/</link><guid isPermaLink="true">https://threatunpacked.com/2026/07/02/nakaz-mo-ukraine-lnk-ps1-downloader/</guid><description>A ZIP archive impersonating wartime asset disclosure paperwork delivers a two-stage LNK→PowerShell downloader to Ukrainian targets — with a geo-fenced C2 that returns 403 to every sandbox that tries to fetch the payload.</description><pubDate>Thu, 02 Jul 2026 14:00:00 GMT</pubDate></item><item><title>In the Wild: Indonesia&apos;s Cyber Underground Comes for Your Cloud</title><link>https://threatunpacked.com/2026/07/02/sea-underground-2026-govti-v4-tempix-botnet/</link><guid isPermaLink="true">https://threatunpacked.com/2026/07/02/sea-underground-2026-govti-v4-tempix-botnet/</guid><description>How a mass Next.js exploitation campaign named after the President is quietly backdooring AWS Singapore, DigitalOcean, and anything else it can reach</description><pubDate>Thu, 02 Jul 2026 12:00:00 GMT</pubDate></item><item><title>CHM Lure, Nuitka Python Backdoor, CDN Fronting: APT Targets Pakistan Military</title><link>https://threatunpacked.com/2026/07/01/chm-nuitka-python-pakistan-military-apt/</link><guid isPermaLink="true">https://threatunpacked.com/2026/07/01/chm-nuitka-python-pakistan-military-apt/</guid><description>A CHM file themed around restricted Pakistani defense exhibitions drops a Nuitka-compiled Python backdoor named after the country&apos;s annual military budget document. The C2 routes through a G-Core CDN edge node shared with Microsoft Windows Update traffic — designed to disappear into network telemetry.</description><pubDate>Wed, 01 Jul 2026 14:00:00 GMT</pubDate></item><item><title>FUD .url, WebDAV Delivery, and a NetSupport RAT Phoning Home on Telegram</title><link>https://threatunpacked.com/2026/07/01/fud-url-webdav-netsupport-rat/</link><guid isPermaLink="true">https://threatunpacked.com/2026/07/01/fud-url-webdav-netsupport-rat/</guid><description>A Windows URL shortcut disguised as a PDF had 1/75 detections at submission time. It used the WebDAV-over-HTTP UNC trick to silently execute an EXE off a Hong Kong opendir. Two stages later: a silent NetSupport Manager install beaconing to a 16-day-old C2 domain while Telegram told the operator their new victim was live.</description><pubDate>Wed, 01 Jul 2026 12:00:00 GMT</pubDate></item><item><title>Silverfox Dropper Campaign: Three Lures, One C2, Gambling Infrastructure</title><link>https://threatunpacked.com/2026/07/01/silverfox-rar-z-extension-industrial-lure/</link><guid isPermaLink="true">https://threatunpacked.com/2026/07/01/silverfox-rar-z-extension-industrial-lure/</guid><description>A RAR renamed .z to bypass filters drops a Silverfox InnoSetup installer with a spreader payload. Three lures in one campaign: industrial safety training, a Chinese company seal, and an HR recruitment form. The C2 IP hosted Chinese gambling sites from late 2023 into early 2024.</description><pubDate>Wed, 01 Jul 2026 12:00:00 GMT</pubDate></item><item><title>One Tweet, Sixteen Servers: Pivoting the Chopi RAT Vishing Operation</title><link>https://threatunpacked.com/2026/06/30/chopi-rat-vishing-opendir-pivot/</link><guid isPermaLink="true">https://threatunpacked.com/2026/06/30/chopi-rat-vishing-opendir-pivot/</guid><description>A WsgiDAV opendir gave me staging payloads and a leaked debug log. AES config RE confirmed all six C2 IPs and the full encrypted capability set. PE build timestamp forensics revealed two back-to-back build sessions; the operator&apos;s dropper cluster leaked their build-system path on VirusTotal. Neo4j graph of 70 nodes across 3 cloud providers. YARA rules included.</description><pubDate>Tue, 30 Jun 2026 12:00:00 GMT</pubDate></item><item><title>It Only Decrypts on the Victim: DPAPI Host-Locking in a ShadowPad .dat</title><link>https://threatunpacked.com/2026/06/30/paper-dat-dpapi-host-locked-shadowpad/</link><guid isPermaLink="true">https://threatunpacked.com/2026/06/30/paper-dat-dpapi-host-locked-shadowpad/</guid><description>VirusTotal called it PlugX. It broke down into an RC4 layer I could crack offline, a ScatterBrain-flavoured shellcode stub, and then a wall: the real implant is sealed with machine-scoped DPAPI, so it only decrypts on the one victim it was built for. Here&apos;s everything up to that wall, why the wall is the whole point, and why I think this is closer to ShadowPad than PlugX.</description><pubDate>Tue, 30 Jun 2026 12:00:00 GMT</pubDate></item><item><title>Unpacking Canon.dat: PlugX, a Config Extractor, and the C2 Infrastructure Behind It</title><link>https://threatunpacked.com/2026/06/27/unpacking-canon-dat-plugx-c2-infrastructure/</link><guid isPermaLink="true">https://threatunpacked.com/2026/06/27/unpacking-canon-dat-plugx-c2-infrastructure/</guid><description>A single XOR&apos;d Canon.dat turned into a campaign map: reversing the CanonStager loader, writing a memory-based config extractor, pulling the related samples, and walking nine builds out to their CloudFlare-fronted C2 origins.</description><pubDate>Sat, 27 Jun 2026 12:00:00 GMT</pubDate></item><item><title>Building a Scalable Windows Driver Vulnerability Analyzer (Part 3): From One Driver to 1,775</title><link>https://threatunpacked.com/2026/03/12/building-a-scalable-windows-driver-vulnerability-analyzer-part-3-from-one-driver-to-1775/</link><guid isPermaLink="true">https://threatunpacked.com/2026/03/12/building-a-scalable-windows-driver-vulnerability-analyzer-part-3-from-one-driver-to-1775/</guid><description>In Part 1, I built a pipeline to ingest and classify tens of gigabytes of Windows drivers. In Part 2, I ran it at scale and found the initial results underwhelming. IOCTLance found bugs, but understanding what those bugs meant required more context than symbolic execution alone c</description><pubDate>Thu, 12 Mar 2026 05:13:44 GMT</pubDate></item><item><title>Building a Scalable Windows Driver Vulnerability Analyzer (Part 2)</title><link>https://threatunpacked.com/2026/02/04/building-a-scalable-windows-driver-vulnerability-analyzer-part-2/</link><guid isPermaLink="true">https://threatunpacked.com/2026/02/04/building-a-scalable-windows-driver-vulnerability-analyzer-part-2/</guid><description>In [Part 1], I built a pipeline to churn through gigabytes of drivers. I started with a massive raw dataset of 58.5 GB of drivers. However, feeding this volume into a static analyzer is inefficient. I aggressively filtered the set: This left me with a curated dataset of 28,000 un</description><pubDate>Wed, 04 Feb 2026 04:13:27 GMT</pubDate></item><item><title>Building a Scalable Windows Driver Vulnerability Analyzer (Part 1)</title><link>https://threatunpacked.com/2026/01/21/building-a-scalable-windows-driver-vulnerability-analyzer-part-1/</link><guid isPermaLink="true">https://threatunpacked.com/2026/01/21/building-a-scalable-windows-driver-vulnerability-analyzer-part-1/</guid><description>Background As I spent more time looking at kernel drivers, that interest gradually grew. Finding my first CVE in a Windows driver pushed me to pay closer attention to this area. Around the same time, I started reading more practical write-ups on driver work, including a post by e</description><pubDate>Wed, 21 Jan 2026 01:03:59 GMT</pubDate></item><item><title>Why This Blog Exists</title><link>https://threatunpacked.com/2026/01/07/why-this-blog-exists/</link><guid isPermaLink="true">https://threatunpacked.com/2026/01/07/why-this-blog-exists/</guid><description>Most malware analysis content focuses on what a sample does. This blog focuses on why it matters during an incident. Through case studies, technical deep dives, and operational reflections, I write about: Clarity matters, assumptions are dangerous, and systems fail in ways their </description><pubDate>Wed, 07 Jan 2026 22:31:00 GMT</pubDate></item><item><title>Reversing a Microsoft-Signed Rootkit: The Netfilter Driver</title><link>https://threatunpacked.com/2025/10/07/reversing-a-microsoft-signed-rootkit-the-netfilter-driver/</link><guid isPermaLink="true">https://threatunpacked.com/2025/10/07/reversing-a-microsoft-signed-rootkit-the-netfilter-driver/</guid><description>A detailed technical analysis of Netfilter.sys, a malicious kernel driver that was legitimately signed by Microsoft through attestation signing. This post explores how the rootkit harnesses the Windows Filtering Platform for stealthy IP redirection, the C2 communication mechanism</description><pubDate>Tue, 07 Oct 2025 08:14:24 GMT</pubDate></item></channel></rss>