#reverseengineering

59 posts · Last used 5d

Hello Mastodon! I'm into Computer #Security, #Programming, #ReverseEngineering, #Hacking, #Linux, #AmateurRadio, #Privacy, #OpenSource, #Cryptography and generally anything creative and interesting involving tech. Especially things that help people communicate and use computers more privately and securely. Lately I've been tinkering with mesh networks like #Meshtastic, #MeshCore and #Reticulum. Longtime #QubesOS and #GrapheneOS user. I also enjoy touching grass like #Camping, #Backpacking and generally being in nature. Would recommend. This is a personal/professional account so keep an eye out for various writeups and research, for work and for fun. Previous jobs ranged from #SoftwareEngineering to Computer Security #Research and #InfoSec, and I'm looking for more of the same. #Introduction
0
0
1
0
---------------- 🦠 Malware Analysis =================== Settra is a ransomware operation first identified in June 2026 that has already claimed 50-70+ enterprise victims across technology, manufacturing, financial services, healthcare, and retail sectors. The group operates double-extortion: data exfiltration followed by encryption and ransom negotiation via Tox and darknet portals. 🔹 Intrusion Methodology Human-operated intrusions begin through compromised VPNs or valid accounts. Credential dumping uses Mimikatz and ProcDump. Lateral movement relies on dual-use tools including PAExec and NetExec. Durable remote access is established via Mesh Agent. Before encryption, operators abuse signed STProcessMonitor drivers via BYOVD to blind endpoint defenses. 🔹 Encryptor Architecture The encryptor is a two-stage design recovered through offline static reverse engineering by Cynet Research Labs. Outer loader (win64.exe): • Password-gated entry • PEB export hashing for API resolution • Anti-debugging gates • ~200,000-round SHA-256 KDF for key derivation • AES-256-CTR decryption of inner payload • Custom LP77 decompression • Process hollowing into a suspended self-copy Inner PE payload executes systematic anti-forensics: • Wipes 12 targeted event logs via wevtutil • Purges Windows Prefetch • Deletes PowerShell command history • Wipes USN change journals • Disables Windows Recovery (reagentc, bcdedit, wbadmin, Disable-ComputerRestore) • Resizes VSS shadow storage stealthily • Powers down Hyper-V VMs via WMI (ROOT\virtualization\v2) to release .vhdx file locks 🔹 Cryptography Files encrypted using Windows CNG (BCryptGenRandom, BCryptEncrypt) with unique symmetric keys wrapped by an embedded 4096-bit RSA-1 public key. Files renamed to .locked (preceded by temporary .locked_wip). The RSA private key is never present on the victim host. The encryptor contains zero C2 network communication stacks, making it fully offline. 🔹 Detection Claims Cynet claims proactive interception within 1 second of detonation via kernel-level driver decoy traps. This is a vendor claim from the same organization that performed the analysis, so treat with appropriate skepticism. 🔹 Key Takeaways The encryptor design is notable for its complete lack of network communication, heavy anti-forensics targeting recovery infrastructure, and deliberate Hyper-V shutdown to access locked virtual disks. The BYOVD approach using signed STProcessMonitor drivers is increasingly common in ransomware operations. 🔹 ransomware #malware #threatintelligence #BYOVD #reverseengineering 🔗 Source: https://www.cynet.com/settra-ransomware-inside-a-new-enterprise-grade-extortion-threat/
0
0
0
0
New Pwndbg release! We now disassemble code backwards in context and nearpc, display indirect jumps, nearpc -f works without debug syms, added stack-vis command to visualize stack frames, improved v2p, p2w and pageinfo kernel debugging commands & more! See https://github.com/pwndbg/pwndbg/releases/tag/2026.09.15 Please sponsor us: https://github.com/sponsors/pwndbg ! #pwndbg #gdb #lldb #reverseengineering #security #lowlevel #exploitation #pwning
10
1
8
0

🚗 Every modern car is a network on wheels.

Behind every brake press, gear shift, and steering input, dozens of ECUs exchange thousands of messages over CAN Bus.

If you're learning: • Automotive Cybersecurity • CAN Bus • ECU Hacking • Reverse Engineering • Embedded Systems • OBD-II • CAN FD • Automotive Ethernet

This is the guide you need.

Read the complete guide 👇 https://thecybersecguru.com/glossary/can-bus-explained/

#Cybersecurity #CANBus #AutomotiveCybersecurity #ReverseEngineering #EmbeddedSystems #ECU #Automotive #IoT #CANFD #Engineering

5
0
5
0