https://cocomelonc.github.io/malware/2026/03/05/malware-cryptography-44.html next one from my blog.
Today, we will move away from classical encryption and use pure #mathematics. We are going to use the Discrete Fourier Transform (DFT) to turn our #shellcode into #frequency noise.
You might wonder: is this just a “academic” trick, or does it have real-world applications in high-end cyber espionage?
While we don’t often see a pure DFT loop in every commodity #malware, the philosophy behind it is a hallmark of sophisticated #APT groups. Here is why this idea is more “real” than it looks.
twitter/X
#hacking #cybersecurity #programming #research #maldev #book #threatintel #purpleteam #ethicalhacking #math
Today, we will move away from classical encryption and use pure #mathematics. We are going to use the Discrete Fourier Transform (DFT) to turn our #shellcode into #frequency noise.
You might wonder: is this just a “academic” trick, or does it have real-world applications in high-end cyber espionage?
While we don’t often see a pure DFT loop in every commodity #malware, the philosophy behind it is a hallmark of sophisticated #APT groups. Here is why this idea is more “real” than it looks.
twitter/X
#hacking #cybersecurity #programming #research #maldev #book #threatintel #purpleteam #ethicalhacking #math
🔥7❤3👍3😍3
My pet project (draft) was selected to be presented at DEFCON Singapore 2026, which will take place from April 28 to April 30, 2026.
#hacking #malware #threatintel #programming #research
#hacking #malware #threatintel #programming #research
GitHub
GitHub - cocomelonc/peekaboo: It bridges my research with a functional tool. I want to provide a safe, open-source framework for…
It bridges my research with a functional tool. I want to provide a safe, open-source framework for hackers to test evasion and for defenders to improve detection through hands-on learning. - cocome...
🔥11❤5👏3🥰1
BadPaw_and_MeowMeow.pdf
212 B
Exposing a Russian Campaign Targeting Ukraine Using New Malware Duo: BadPaw and MeowMeow
#hacking #apt #malware #threatintel #research #report #cats
#hacking #apt #malware #threatintel #research #report #cats
❤6🔥3👏2
https://cocomelonc.github.io/linux/2026/03/12/linux-hacking-10.html next one. #APT groups and #HiddenWasp using this mechanism to hide #malware from #detection
X/twitter
#hacking #cybersecurity #research #linux #programming #threatintel #purpleteam #redteam #blueteam #maldev #malwareanalysis #book
X/twitter
#hacking #cybersecurity #research #linux #programming #threatintel #purpleteam #redteam #blueteam #maldev #malwareanalysis #book
❤8
Eid Mubarak 💝
https://cocomelonc.github.io/macos/2026/03/19/mac-malware-persistence-5.html next one from my blog, classic trick. Used by #Lazarus #APT and #osx.flashback #botnet in the wild
X/Twitter
#hacking #malware #cybersecurity #threatintel #research #programming #macos #ethicalhacking #purpleteam #book #malwareanalysis #maldev
https://cocomelonc.github.io/macos/2026/03/19/mac-malware-persistence-5.html next one from my blog, classic trick. Used by #Lazarus #APT and #osx.flashback #botnet in the wild
X/Twitter
#hacking #malware #cybersecurity #threatintel #research #programming #macos #ethicalhacking #purpleteam #book #malwareanalysis #maldev
5❤15
260320.pdf
744.5 KB
Government of Iran Cyber Actors Deploy Telegram C2 to Push Malware to Identified Targets
Malware development trick 40: Stealing data via legit Telegram API. Simple C example.
Mobile malware development trick 1. Abuse Telegram Bot API. Simple Android (Java/Kotlin) stealer example.
MacOS hacking part 1: stealing data via legit Telegram API. Simple C example
#malware #hacking #threatintel #redteam #blueteam #report #research #FBI #iran #APT
Malware development trick 40: Stealing data via legit Telegram API. Simple C example.
Mobile malware development trick 1. Abuse Telegram Bot API. Simple Android (Java/Kotlin) stealer example.
MacOS hacking part 1: stealing data via legit Telegram API. Simple C example
#malware #hacking #threatintel #redteam #blueteam #report #research #FBI #iran #APT
❤7🔥3🤔1
https://cocomelonc.github.io/macos/2026/03/20/mac-malware-persistence-6.html next one from my blog.
The #macOS-specific variant of the technique used by #HiddenWasp and #Skidmap #malware.
X/Twitter
#hacking #cybersecurity #threatintel #maldev #malwareanalysis #redteam #blueteam #research #persistence #book
The #macOS-specific variant of the technique used by #HiddenWasp and #Skidmap #malware.
X/Twitter
#hacking #cybersecurity #threatintel #maldev #malwareanalysis #redteam #blueteam #research #persistence #book
❤6🔥1
Malware, Cats and Cryptography
https://cocomelonc.github.io/book/2025/05/19/aiya-mmd-book.html Alhamdulillah, I finished writing this book in few days. I wrote this book to help my friends: Nurkhankyzy Aiya, Acute myeloid leukemia (AML). and all those children who are fighting…
It's sad, but the little angel who inspired the title of this book has passed away after a long journey of treatment ❤️
#book #research #hacking #charity
#book #research #hacking #charity
😢43❤7💔7😭2
https://cocomelonc.github.io/macos/2026/03/29/mac-malware-persistence-7.html next one from #macOS #malware #persistence series. This trick was first documented by Patrick Wardle
enjoy!
X/Twitter
#hacking #programming #research #book #apple #maldev #cybersecurity #threatintel #malwareanalysis #redteam #blueteam #purpleteam
enjoy!
X/Twitter
#hacking #programming #research #book #apple #maldev #cybersecurity #threatintel #malwareanalysis #redteam #blueteam #purpleteam
❤7👍1🔥1👾1
macOS ClickFix Campaign Targets Claude Code Users with AMOS Stealer and Backdoor Access
ANY.RUN analysts identified a macOS-specific ClickFix campaign targeting users of AI tools such as Claude Code, Grok, n8n, NotebookLM, Gemini CLI, OpenClaw, and Cursor
#hacking #malware #stealer #research #anyrun
ANY.RUN analysts identified a macOS-specific ClickFix campaign targeting users of AI tools such as Claude Code, Grok, n8n, NotebookLM, Gemini CLI, OpenClaw, and Cursor
#hacking #malware #stealer #research #anyrun
❤7
By the way, the coolest thing is that ANY.RUN announced a Sandbox for macOS! ❤️
#hacking #malware #sandbox #anyrun #threatintel #research #programming #malwareanalysis #blueteam
#hacking #malware #sandbox #anyrun #threatintel #research #programming #malwareanalysis #blueteam
ANY.RUN's Cybersecurity Blog
Ready for macOS Threats: Cross-Platform SOC Analysis with ANY.RUN
macOS threats are targeting enterprise environments. See how SOC teams can investigate cross-platform malware faster with interactive sandbox.
❤10
https://cocomelonc.github.io/macos/2026/04/01/malware-mac-13.html next one from my blog.
The C code only uses standard libraries and sysctl. enjoy!
twitter/X
#hacking #malware #research #book #threatintel #virustotal #apt #maldev #malwareanalysis #purpleteam
The C code only uses standard libraries and sysctl. enjoy!
twitter/X
#hacking #malware #research #book #threatintel #virustotal #apt #maldev #malwareanalysis #purpleteam
❤8
https://cocomelonc.github.io/macos/2026/04/02/mac-malware-persistence-8.html next one on my blog.
This post is quick observation of classic trick.
X/Twitter
#malware #hacking #threatintel #research #persistence #macos #purpleteam #redteam #blueteam #apt #book
This post is quick observation of classic trick.
X/Twitter
#malware #hacking #threatintel #research #persistence #macos #purpleteam #redteam #blueteam #apt #book
❤7🔥1👏1
NCSC_APT28_exploit_routers_to_enable_DNS_hijacking_operations.pdf
385.6 KB
Russian cyber actor #apt28 exploit vulnerable routers to hijack DNS, enabling adversary‑in‑the‑middle #attacks and theft of #passwords and #authentication #tokens.
#hacking #malware #threatintel #apt #research
#hacking #malware #threatintel #apt #research
❤5🔥2
https://cocomelonc.github.io/android/2026/04/12/malware-android-3.html next one from my blog. Thanks to ANY.RUN for the API! ♥️
twitter/X
#hacking #malware #android #stealer #apt #maldev #malwareanalysis #threatintel #research #cybersecurity #purpleteam #redteam #blueteam #programming #book #telegram
twitter/X
#hacking #malware #android #stealer #apt #maldev #malwareanalysis #threatintel #research #cybersecurity #purpleteam #redteam #blueteam #programming #book #telegram
❤9👍2🔥1👏1
28-30 April 2026 - DEFCON Singapore
28 April 2026 Threat Modelling SG Community event
6-9 May 2026 BSides Luxembourg
22-23 May 2026 Bsides Prishtina
#conferences #research #malware #threatintel #cybersecurity #book
28 April 2026 Threat Modelling SG Community event
6-9 May 2026 BSides Luxembourg
22-23 May 2026 Bsides Prishtina
#conferences #research #malware #threatintel #cybersecurity #book
1❤9
DEFCON Singapore DEMO LABS my demos:
Tuesday at 10:00 for 45 minutes, at Demo Labs Track 1
Wednesday at 15:00 for 45 minutes, at Demo Labs Track 1
Thursday at 13:00 for 45 minutes, at Demo Labs Track 2
peekaboo - still under development
Tuesday at 10:00 for 45 minutes, at Demo Labs Track 1
Wednesday at 15:00 for 45 minutes, at Demo Labs Track 1
Thursday at 13:00 for 45 minutes, at Demo Labs Track 2
peekaboo - still under development
❤9🔥3