Threat Labs

Notes from the life of the reverse engineering wizards

GhostDNS Exploit Kit Strikes Back

Router exploit kits are very popular in Brazil, and late November we noticed a spike in the number of URLs blocked by Avast’s Web Shield. Taking a closer look, two landing pages, targeting Brazilians, hosting the GhostDNS router exploit kit used to...

The secret life of GPS trackers (1/2)

Cheap GPS trackers can come handy in every situation, for your car, relatives, kids. But it turns out that many of them share the same flaws. Unsecured communications, default passwords and cloud environment that is far from secure.

F-Scrack-mimikatz – A bundle of tools

Recently when analyzing samples which attempt to bypass various applocking techniques we revisited an older bundle of various tools with the sole purpose to make money for the operators. Although the campaign seems to be long inactive it illustrates...

Clipsa – Multipurpose password stealer

High level overview Clipsa is a multipurpose password stealer, written in Visual Basic, focusing on stealing cryptocurrencies, brute-forcing and stealing administrator credentials from unsecured WordPress websites, replacing crypto-addresses present...

CyberSec & AI Prague 2019

Have you ever wondered how AI is used in cybersecurity? Join us at the end of October for a conference about new advances in machine learning. You will see how AI can help protect people against the bad guys on the Internet – a goal we trully...