AfroSec
791 subscribers
457 photos
33 videos
7 files
239 links
hello friend
am AfroSec | AASTU dropout | cybersecurity enthusiast | CRTO | CRTOM | CRTA | passionate about Red Teaming :)

portifolio : https://afrosec.et
blog: https://blog.afrosec.et
file : @Afr0Files
Download Telegram
tweaking ctf and in the mean time hearing this legends's masterpiece ๐Ÿ‘Œ๐Ÿ‘Œ
feels epic sunday ngl its been long time since i feel Sunday like this

@AfroSec
โคโ€๐Ÿ”ฅ4โค2๐Ÿฅฐ2๐Ÿ‘1๐ŸŒš1
#redteam_yap

Have you heard about MOTW (Mark of the Web)?

aight letโ€™s cook

MOTW is basically a trust badge Windows slaps on files that come from the internet.
Think of it as Windows saying:

> โ€œyoo hold up bro, youโ€™re a guest here โ€

Whatโ€™s really happening?

* MOTW is implemented using NTFS Alternate Data Streams (ADS)
* When a file is downloaded from the internet, Windows attaches metadata like:

- ZoneId
- Source URL
- Referrer info
- Most common case: ZoneId = 3 (Internet Zone)
there are 5 zones

ZoneId, Meaning
0 Local computer
1 Local intranet
2 Trusted sites
3 Internet (most common for downloads)
4 Restricted sites

Once that tag exists, Windows components start acting paranoid:

- ๐Ÿ›‘ Microsoft SmartScreen
- ๐Ÿ›‘ Microsoft Office (Protected View)
- ๐Ÿ›‘ Other security-aware apps

Result?
Pop-ups like:

> โ€œAre you _sure_ you want to open this file?โ€
> โ€œThis file came from an untrusted source.โ€

From an attackerโ€™s perspectiveโ€ฆ yeah, thatโ€™s annoying ๐Ÿ˜

๐Ÿ˜ˆ Attacker mindset: Okay, how do we blend in?

Since MOTW depends on ADS, the game becomes:
> Deliver the payload without inheriting ADS

Especially useful for multi-stage payloads, loaders, or initial access files.

and yup there are well-known, still-used ways to do this :)

1. MOTW Evasion Techniques (Still Wildly Relevant) Container / Disk Image Formats

Examples:
- .iso
- .vhd
- .vhdx
- .img

Why this works:
- When mounted via Windows Explorer, files inside the virtual disk do NOT inherit MOTW

- Payload comes out looking โ€œlocalโ€ ๐Ÿ‘Œ
> Still abused heavily in real-world campaigns btw.

2. Physical Transfer / Internal Copy

- USB devices
- Copying from another internal machine

No browser โ†’ no ADS โ†’ no MOTW
Old-school, but effective.

3. Internal Email Attachments

- Payload archived (ZIP/RAR)
- Password-protected archive
- Sent from a compromised internal mailbox

> Even in modern Microsoft 365 environments (as of 2026):
> Internal emails do NOT apply MOTW by default
> Unless orgs explicitly enforce custom policies


This is gold for lateral movement and internal phishing ๐ŸŽฏ

Real Threat Actors Using These Techniques
Groups known to abuse MOTW bypass paths:

- TA505
- APT38
- APT29

@AfroSec
โœ4๐Ÿ”ฅ2โšก1
Forwarded from Tech Nerd (Tech Nerd)
โ€œComparison is the thief of joyโ€ is advice for people already in motion โ€ฆ not for those who havenโ€™t started

@selfmadecoder
๐Ÿ”ฅ14โค2โšก1
yellow fam ๐Ÿ™ƒ

jst found cozzy coffe house while heading home ๐Ÿ‘Œ

@AfroSec
๐Ÿ”ฅ11๐Ÿ‘1
whaaaat an actual fuck is this man ๐Ÿ˜ข๐Ÿคฏ๐Ÿคฏ like those ai chatbot and agent companies should really test their agents especially their RAG pipeline

i was just chatting wiz one chatbot and suddenly i got an idea to test it and when i do boom this happened, it reveals its code base with snippets lol :)

sorry for the image quality btw

@AfroSec
๐Ÿคฏ7๐Ÿ‘2๐Ÿ‘€1
Forwarded from Genesis (ISRAฦŽL)
your future doctor is using chatpgt to pass his tests so you better start eating healthy foods
๐Ÿคฃ9๐Ÿ˜3๐Ÿ˜ญ2
late night grind loading ๐Ÿ˜…

@AfroSec
๐Ÿ”ฅ7๐Ÿ˜3โšก1
i wonder why attackers love chrome tho ๐Ÿ˜… all the time chrome exploit mtsm

@AfroSec
๐Ÿค“5๐Ÿคทโ€โ™‚3
look at this distinguished man, helping his bro out with some work lol ๐Ÿ˜‚๐Ÿ˜‚

@AfroSec
๐Ÿ˜18๐Ÿคฃ4
Forwarded from Florida๐Ÿ›ธ
Machine Learning Augmented Attacks

Recent threat reporting shows malicious actors are actively using AI as a force multiplier for offensive operations.

The interesting part isnโ€™t that AI can generate code(i mean we already knew that)
The real shift is:
-Polymorphic Malware: rapid generation of variants to evade signature-based detection.
-Linguistic Smoothing: low skill actors are now bypassing "broken English" red flags in phishing.
-Condensed Attack Cycles: Reconnaissance and profiling that took days now take minutes.

๐Ÿ”ดFor Security & Red Teams
Focus less on what is generated,and more on how fast and how often:-
1.Content Velocity: abnormal speeds in phishing deployment.
2. LLM Wrappers: malicious use of open-source models in botnets.
3. Linguistic Patterns: Fluency โ‰  legitimacy
4.Adaptive Payload Mutation: watch for rapid iteration patterns rather than static signatures.

AI is now part of both the exploit chain and the defense stack,the advantage wonโ€™t belong to whoever โ€œuses AIโ€,it will belong to whoever understands how it changes execution speed.
๐Ÿ”ฅ4๐Ÿ‘Œ2
This media is not supported in your browser
VIEW IN TELEGRAM
the most unserious generation besmeam ๐Ÿ˜ญ๐Ÿ˜ญ๐Ÿ˜‚

@AfroSec
๐Ÿคฃ8๐Ÿ˜ญ4๐Ÿ˜1
#RandomThought

The Cyber sec Community here on telegram is not that active and known, so why dont we support each other and how many Enthusiast alu milewun lemasayet asbealewu so personal channel'm hone big channel sharing about cyber sec, ena if you want me to mention it here, send me your channel link @geez2012bot and i will check it ena if it looks helpful i will forward some posts from it, bezawu entewaweqalen.
tinish neger bihonm, let me support be aqme biye newu. Maqachewunm i will share some.

@geeztechgroup @geezsecurity #geeztech
โค6
Forwarded from INSA Cyber Talent Center
แ‰ แŒ‰แŒ‰แ‰ต แˆฒแŒ แ‰ แ‰… แ‹จแАแ‰ แˆจแ‹‰ แ‹จNathan Hailu Interview แ‹›แˆฌ แˆ›แ‰ณ 2:00 LT แ‰ แ‰€แŒฅแ‰ณ แŠฅแ‹šแ‹‰ แ‰ปแŠ“แˆ แˆ‹แ‹ญ แ‹ญแŒ แ‰ฅแ‰แŠ• ๐Ÿ”ด LIVE TONIGHT โ€“ 2:00 LT

Interview with Natan Hailu
Co-Founder @ GeezSecurity | HTB Certified Penetration Tester ๐Ÿ”

Cybersecurity โ€ข Ethical Hacking โ€ข Bug Hunting

๐Ÿ“ t.me/insactc

Donโ€™t miss it ๐Ÿš€

#LiveTonight #CyberSecurity
๐Ÿ‘4
hellooo everyone
how u doin ๐Ÿ˜Š ?

@AfroSec
๐Ÿ˜7
aigh enough of the jokes ena malet am planing to post some advanced APT level shii from now on hmm which will strength us as a community

u ready right ??

@AfroSec
๐Ÿ‘7โšก2