<feed xmlns="http://www.w3.org/2005/Atom"> <id>https://dmpdump.github.io/</id><title>dmpdump</title><subtitle>CTI, threat intelligence, reverse engineering, programming, malware</subtitle> <updated>2026-04-27T00:31:50+00:00</updated> <author> <name>dmpdump</name> <uri>https://dmpdump.github.io/</uri> </author><link rel="self" type="application/atom+xml" href="https://dmpdump.github.io/feed.xml"/><link rel="alternate" type="text/html" hreflang="en" href="https://dmpdump.github.io/"/> <generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator> <rights> © 2026 dmpdump </rights> <icon>/assets/img/favicons/favicon.ico</icon> <logo>/assets/img/favicons/favicon-96x96.png</logo> <entry><title>Rebex-based Telegram RAT Targeting Vietnam</title><link href="https://dmpdump.github.io/posts/TelegramRat/" rel="alternate" type="text/html" title="Rebex-based Telegram RAT Targeting Vietnam" /><published>2026-04-25T00:00:00+00:00</published> <updated>2026-04-25T00:00:00+00:00</updated> <id>https://dmpdump.github.io/posts/TelegramRat/</id> <content src="https://dmpdump.github.io/posts/TelegramRat/" /> <author> <name>dmpdump</name> </author> <summary>On April 1, 2026, a zip archive named CV - Vu PLPC So2156516.zip was uploaded to VirusTotal from Vietnam. This archive contains a Microsoft Compiled HTML (CHM) file named Word Document - CV - Vu PLPC KT nam 2026.chm. CHM files have historically been used by a plethora of threat actors. In my personal experience, I have seen CHM files trojanized primarily in state-sponsored/targeted activity rat...</summary> </entry> <entry><title>Low Detection Linux and macOS Backdoor</title><link href="https://dmpdump.github.io/posts/Linux_Backdoor/" rel="alternate" type="text/html" title="Low Detection Linux and macOS Backdoor" /><published>2026-02-14T00:00:00+00:00</published> <updated>2026-03-15T22:01:22+00:00</updated> <id>https://dmpdump.github.io/posts/Linux_Backdoor/</id> <content src="https://dmpdump.github.io/posts/Linux_Backdoor/" /> <author> <name>dmpdump</name> </author> <summary>In early March, MalwareHunterTeam shared a hash associated with a Linux backdoor with 0 detection in VirusTotal. It is well known that AV engines in VirusTotal do not implement the full capability of AV solutions, however, the presence of obviously malicious unobfuscated code made it an interesting finding. The backdoor has been in VirusTotal since January 27, 2026 with 2 distinct submissions, ...</summary> </entry> <entry><title>Rare Earth Material Lure Delivering Shellcode Loader</title><link href="https://dmpdump.github.io/posts/Reia/" rel="alternate" type="text/html" title="Rare Earth Material Lure Delivering Shellcode Loader" /><published>2025-11-26T00:00:00+00:00</published> <updated>2025-11-26T00:00:00+00:00</updated> <id>https://dmpdump.github.io/posts/Reia/</id> <content src="https://dmpdump.github.io/posts/Reia/" /> <author> <name>dmpdump</name> </author> <summary>On November 21, 2025, Malware Hunter Team shared an interesting sample on X, uploaded to VirusTotal from Singapore. The ZIP file in question is named China’s Governance of Rare Earths and its Global Implications.zip. It contains a password-protected PDF named China’s Governance of Rare Earths and its Global Implications.pdf and an executable named SecurityKey.exe. The lure is clear: the victim ...</summary> </entry> <entry><title>Unknown Malware Using Azure Functions as C2</title><link href="https://dmpdump.github.io/posts/AzureFunctionsMalware/" rel="alternate" type="text/html" title="Unknown Malware Using Azure Functions as C2" /><published>2025-09-07T00:00:00+00:00</published> <updated>2025-09-10T02:56:16+00:00</updated> <id>https://dmpdump.github.io/posts/AzureFunctionsMalware/</id> <content src="https://dmpdump.github.io/posts/AzureFunctionsMalware/" /> <author> <name>dmpdump</name> </author> <summary>On August 28, 2025, an ISO named Servicenow-BNM-Verify.iso was uploaded to VirusTotal from Malaysia with very low detections: The ISO image contains 4 files, two of them hidden. servicenow-bnm-verify.lnk, a shortcut file that simply executes PanGpHip.exe PanGpHip.exe, a legitimate Palo Alto Networks executable libeay32.dll, a legitimate OpenSSL library (hidden) libwaapi.dll, a mal...</summary> </entry> <entry><title>SLOW#TEMPEST Cobalt Strike Loader</title><link href="https://dmpdump.github.io/posts/CobaltStrike_HK/" rel="alternate" type="text/html" title="SLOW#TEMPEST Cobalt Strike Loader" /><published>2025-08-02T00:00:00+00:00</published> <updated>2025-08-04T00:57:53+00:00</updated> <id>https://dmpdump.github.io/posts/CobaltStrike_HK/</id> <content src="https://dmpdump.github.io/posts/CobaltStrike_HK/" /> <author> <name>dmpdump</name> </author> <summary>On July 18, 2025, an ISO image with moderate detection was updated to VirusTotal from Hong Kong. ISO SHA2: 6573136f9b804ddc637f6be3a4536ed0013da7a5592b2f3a3cd37c0c71926365 The ISO image has a structure which I have seen multiple times in threat activity targeting Chinese-speaking users. Once the ISO is mounted, the victim sees a shortcut (LNK) file with a deceiving folder icon. Additionally...</summary> </entry> </feed>
