Skip to content(if available)orjump to list(if available)

ScatterBrain: Unmasking the shadow of PoisonPlug's obfuscator

zb3

Given that this was made by a nation-state attacker I'd expect something more sophisticated than pairipcore VM..

So, still waiting for full pairipcore (the newer one) writeup.

bredren

Is it correct to presume that the obfuscated samples might be hard to come by for the average interested viewer?

gcorre01

This is very cool. Can someone help me understand the behind the scenes, what’s their strategy? Their motivations? Are they targeting specific industries or nations for a reason?

ElectRabbit

This is the result when an elite attacker meets an elite analyst group.

That's some very heavy stuff.