Reports
Threat Intelligence Reports
Original malware analysis and reverse engineering — each report ships with detection rules and machine-readable indicators. Filter by tag or search by name.
No items match that filter.
Report Series
Multi-Actor AI-Agent Framework Abuse
6 reports · read in order
Part 1 of 6 · Start here
Multi-Actor AI-Agent Framework Abuse (8 Operators)
Part 2 of 6
Russian Gemini CLI Credential Mill (213.165.51.115)
Part 3 of 6
Turkish ARPA AI-Augmented Observability Compromise (209.38.205.158)
Part 4 of 6
Rovodev AI-Co-Authored Mirai Variant + Matrix C2 (87.106.143.220)
Part 5 of 6
Korean Claude Code + OpenClaw Operator (221.150.15.104)
Part 6 of 6
GHOST Cryptojacker Kit — Vova75Rus Supply Chain (77.110.96.200)
Flask C2 & MSSQL CLR Backdoor on a Windows Post-Exploitation Staging Host
CVE-2026-41940 cPanel Harvester Toolkit (216.126.227.49)
Report Series
Multi-Cluster Open Directory — 79.137.192.3 (Rhadamanthys / BellaMain / Inkognito)
3 reports · read in order
HijackLoader / Penguish / Rugmi to AsyncRAT Multi-Vector Phishing Campaign
AdaptixC2 Open Directory Exposure (45.130.148.125)
Chaos Ransomware (TorBrowserTor) Multi-Stage Loader (94.103.1.13)
ShinyHunters Data Leak Site (91.215.85.22)
OpenStrike Expanded Toolkit — 106 New Files (2026-04-08)
OpenStrike Beacon Toolkit (172.105.0.126)
Shadow RAT & XWorm Open Directory Campaign
Open Directory at 193.56.255.154 — XiebroC2 v3.1 & Covenant C2
ZeroTrace Multi-Family MaaS Operation (74.0.42.25)
Sliver C2 Toolchain with ScareCrow Loader (45.94.31.220)
Webserver Compromise Kit (91.236.230.250)
Remcos RAT OpenDirectory Campaign
NsMiner: Multi-Stage Cryptojacking Operation
Report Series
Arsenal-237 — Threat Actor R&D Repository (109.230.231.37)
2 reports · read in order
Dual-RAT Analysis: Pulsar RAT vs. NjRAT/XWorm
PULSAR RAT (server.exe) — Technical Analysis & Business Risk Assessment
Hybrid Loader/Stealer Ecosystem Masquerading as Sogou
Houselet.exe — The Go-Based Loader Masquerading as PlayStation Remote Play
AdvancedRouterScanner
From Webshells to The Cloud
Quasar + XWorm + PowerShell
Reports are © Joseph. All rights reserved — free to read, but reuse requires written permission.