Andrea Fortuna
AboutRss
  • Jan 28, 2023

    SwiftSlicer: a new Golang-based wiper malware

    Cyber security firm ESET has reported that Ukraine has been hit by a new cyber attack from Russia using a previously undocumented data wiper called SwiftSlicer. … read more »
  • Jan 27, 2023

    New PlugX malware variant spreads via removable USB storage devices

    Cyber-security researchers at Palo Alto Networks’ Unit 42 have discovered a new variant of the PlugX malware that can infect connected USB removable media devices to spread to additional systems.… read more »
  • Jan 25, 2023

    PY#RATION: new Python-based malware

    Researchers at threat analytics firm Securonix have uncovered a new Python-based malware named PY#RATION, a remote access trojan (RAT) that gives its operators control over breached systems… read more »
  • Jan 25, 2023

    Static malware analysis: a basic workflow

    Static malware analysis is the process of analysing malware samples without executing them. In this post, I'd like to share my basic workflow for static malware analysis, with tools and techniques that can be used at each stage.… read more »
  • Jan 22, 2023

    Windows 11 build 22H2 breaks recording of 4688 event

    A very short article that I think will be useful to DFIR colleagues. According to an article from Microsoft, after installing Windows 11 build 22H2, Windows events 4688 stopped working correctly.… read more »
  • Jan 21, 2023

    State-sponsored APT Gamaredon uses Telegram in attacks against Ukraine

    The Russian state-sponsored cyber espionage group known as Gamaredon has been found to be using the popular messaging app Telegram in its recent attacks against Ukraine. The group has been known to target Ukrainian entities since at least 2013.… read more »
  • Jan 20, 2023

    EmojiDeploy: critical RCE vulnerability discovered in Microsoft Azure

    A critical RCE (remote code execution) vulnerability has been discovered impacting multiple services related to Microsoft Azure, potentially allowing a malicious actor to completely take control of a targeted application. The vulnerability was discovered by Israeli cloud infrastructure security firm… read more »
  • Jan 19, 2023

    Cisco Talos: cyber-criminals leverage malicious LNK files to download and execute payloads

    A recent study by Cisco Talos has revealed that it is possible to identify relationships between different threat actors by analyzing the metadata of these malicious LNK files. This information includes the specific tools and techniques used by different groups… read more »
« Previous page Next page »

Andrea Fortuna

  • Andrea Fortuna
  • andrea@andreafortuna.org
  • andreafortuna
  • andreafortunaig
  • andrea-fortuna
  • andreafortuna
  • andreafortunatw

Cybersecurity expert, software developer, experienced digital forensic analyst, musician