Posts
All the articles I've posted.
-
Anatomy of a Crypto Drainer: Phishing, a 22MB Payload, and 180 Identical Beacons
A user clicked through a phishing warning and ended up with what the evidence points to as a crypto drainer. Here's what the traffic looked like and how we assessed it.
-
Receiving a Responsible Disclosure: What Happens When a Researcher Finds Something First
An independent researcher found an open directory listing on one of our public-facing servers exposing archive files that had been sitting there since 2023. Here's how we handled it.
-
MFA Bypass via Push Fatigue: When the Second Factor Isn't Enough
A phishing campaign captured two sets of credentials and resulted in one full account breach with MFA bypass. Here's how it unfolded and what contained it.
-
PcClient.bal RAT Outbreak: Six Hosts, After-Hours Beaconing, and a Gap in Egress Policy
A single IDS alert turned into a six-host RAT cluster, all beaconing after hours on non-standard ports. The firewall didn't catch it. The IDS did.