2026 Lab work This is part of multiple install guides that I have made as I built out a new personal lab environment. The following diagram shows a high-level view of the pipeline being built ou...
Installing CAPEv2 sandbox (2026 lab)
2026 Lab work This is part of multiple install guides that I have made as I built out a new personal lab environment. The following diagram shows a high-level view of the pipeline being built ou...
Installing InetSim (2026 lab)
2026 Lab work This is part of multiple install guides that I have made as I built out a new personal lab environment. The following diagram shows a high-level view of the pipeline being built ou...
Bringing Local AI Assistance into IDA Pro (Without Leaving Your Lab)
Summary Reverse engineering is still a very manual craft. Even with tools like IDA Pro and Binary Ninja doing heavy lifting on disassembly and decompilation, the actual thinking is still on you. ...
MuddyWater LightPhoenix Deobfuscation
Summary The malware sample from this post is the LightPhoenix malware that was unpacked from the malware loading from a previous post. MuddyWater Malware Loader drops LightPhoenix This post explo...
Wide string decoding
Summary While reverse engineering the MuddyWater malware loader in the previous post (here) there were several cases of string decodings that was worth noting as its own post. This covers a good i...
MuddyWater Malware Loader drops LightPhoenix
Summary This post is dissecting a malware loader that executes an embedded LightPhoenix backdoor payload. LightPhoenix is a C++ backdoor capable of writing files and executing CMD commands. The ma...
MuddyWater Fooder Malware
Summary This part of a series of binary analysis reviews of malware used (or created) by the MuddyWater threat group. MuddyWater may also be known as ATK51, Boggy Serpens, COBALT ULSTER, Earth Veta...
Seylaran Information Stealer malware
Summary The threat actor lures victims into sites that host what looks like a new game to play or test. The victims download game installers that are infected with information stealing malware. Th...
Kimwolf botnet
Summary Kimwolf is a new Android-based DDoS botnet that emerged in late 2025 as a variant or offshoot of the infamous Aisuru botnet. It primarily targets Android TV devices (TV boxes, smart TVs, se...