>_
The Fuzz.

The archive

2 posts · filtered by Malware Analysis

>
$ open --post valleyrat-
Malware Analysis

Inside a 2026 ValleyRAT drop: Squirrel, Unity, Rust, and a 1-second password crack

Walking one Silver Fox sample from MalwareBazaar through every stage. Encrypted SFX, two signed-binary sideload hops, an 111 MB Rust loader with obfstr-style string XOR, a hardware-breakpoint VEH that finds 0F 05 opcodes for direct syscalls, and a custom-base64 carrier disguised as a Windows MUI.

Apr 28, 202620 min
$ open --post lumma-stea
Malware Analysis

Pulling C2s out of a Lumma Stealer build, step by step

Walking one MalwareBazaar Lumma sample from password-protected zip to a deployable IOC list. Static-only path: 9 hardcoded .shop C2s, the Lumma 4.0 protocol surface, the Chrome 127 App-Bound Encryption bypass, and a YARA rule for the build family.

Apr 24, 202622 min