Mr.Z (@zux0x3a) 's Twitter Profile
Mr.Z

@zux0x3a

#redteam #malware_dev #offsec Security Researcher

ID: 1652574038

linkhttps://0xsp.com calendar_today07-08-2013 10:03:43

3,3K Tweet

3,3K Followers

227 Following

Steve S. (@0xtriboulet) 's Twitter Profile Photo

I put a BOF loader in a BOF so that you can run BOFs from a BOF. If you've had issues getting a BOF to work with CS's BOF loader in the past, you now have a drop-in way to get a little bit more compatibility. github.com/0xTriboulet/In…

Gray Hats (@the_yellow_fall) 's Twitter Profile Photo

A new Zero-Click NTLM leak bypasses Microsoft's LNK patch, allowing unauthenticated NTLM hash theft on patched systems. The PoC works by exploiting UNC paths and the default shell32.dll icon reference. #NTLMleak #ZeroClick #LNKattack #Cybersecurity securityonline.info/zero-click-ntl…

International Cyber Digest (@intcyberdigest) 's Twitter Profile Photo

🚨 Multiple cybercriminals were arrested during Operation SIMCARTEL. Europol and Latvian law enforcement dismantled five servers, seized 1,200 SIM box devices and 40,000 active SIM cards. The criminals were linked to over 1,700 cyber fraud cases in Austria and 1,500 in Latvia,

Panos Gkatziroulis 🦄 (@netbiosx) 's Twitter Profile Photo

Parses cached certificate templates from a Windows Registry file and displays them in the same style as Certipy does github.com/outflanknl/reg…

DARKNAVY (@darknavyorg) 's Twitter Profile Photo

We implemented an exploit for RediShell (CVE-2025-49844). While doing so, we discovered that the publicly available PoC incorrectly uses loadstring to trigger the Redis UAF. Kudos to Wiz for the interesting findings!

eversinc33 🤍🔪⋆。˚ ⋆ (@eversinc33) 's Twitter Profile Photo

Wrote a little tracer I found helpful when analyzing obfuscated .NET - might be useful for you, might be not. Have fun :3 github.com/eversinc33/Net…

Dark Web Informer - Cyber Threat Intelligence (@darkwebinformer) 's Twitter Profile Photo

🚨Russian authorities, led by the Ministry of Internal Affairs (MVD) & supported by Rosgvardia, have detained three individuals in the Moscow region. The suspects, described as young IT specialists, are accused of developing & distributing the Meduza Stealer infostealer malware.

S3cur3Th1sSh1t (@shitsecure) 's Twitter Profile Photo

Another Nim C2-Framework developed by Jakob. Can't believe you actually wrote the whole client in Nim as well 😂 Nice one! github.com/jakobfriedl/co… Including a Blog for parts of it: jakobfriedl.github.io/blog/nim-c2-tr…

Another Nim C2-Framework developed by <a href="/virtualloc/">Jakob</a>. Can't believe you actually wrote the whole client in Nim as well 😂 Nice one!

github.com/jakobfriedl/co…

Including a Blog for parts of it:

jakobfriedl.github.io/blog/nim-c2-tr…
Bobby Cooke (@0xboku) 's Twitter Profile Photo

Venom C2 tool drop! 🐍 During a recent red team engagement we needed a simple python agent that needs no dependencies to setup persistence on some exotic boxes we landed on. Some had EDR so we didn't want anything off-the-shelf. The server, agent, and client were made

Venom C2 tool drop! 🐍

During a recent red team engagement we needed a simple python agent that needs no dependencies to setup persistence on some exotic boxes we landed on. 

Some had EDR so we didn't want anything off-the-shelf.
The server, agent, and client were made
SEKTOR7 Institute (@sektor7net) 's Twitter Profile Photo

Reversing Microsoft Defender's signatures for evasion. Deep dive into VDM guts - a gzip-compressed files with no encryption to evade entire signatures with just 1 byte change. A research by RETooling crew (Ch40s 🏴‍☠️ && tonvi). Nicely done, chaps! Post: retooling.io/blog/an-unexpe…

Reversing Microsoft Defender's signatures for evasion.

Deep dive into VDM guts - a gzip-compressed files with no encryption to evade entire signatures with just 1 byte change.

A research by RETooling crew (<a href="/DrCh40s/">Ch40s 🏴‍☠️</a> &amp;&amp; <a href="/t0nvi/">tonvi</a>). Nicely done, chaps!

Post: retooling.io/blog/an-unexpe…
Gi7w0rm (@gi7w0rm) 's Twitter Profile Photo

Rumors are spreading about a mayor #LawEnforcement operation against #Rhadamanthys #Stealer. Who said what? and me have been monitoring the situation closely. -Rhada domains under active law enforcement control - Customers are adviced to delete all servers Image via club1337

Rumors are spreading about a mayor #LawEnforcement operation against #Rhadamanthys #Stealer.
<a href="/g0njxa/">Who said what?</a> and me have been monitoring the situation closely.
-Rhada domains under active law enforcement control
- Customers are adviced to delete all servers

Image via club1337