<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>malware on Reverse Engineering</title>
    <link>https://reverse.put.as/categories/malware/</link>
    <description>Recent content in malware on Reverse Engineering</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en-us</language>
    <managingEditor>reverser@put.as (fG!)</managingEditor>
    <webMaster>reverser@put.as (fG!)</webMaster>
    <copyright>&amp;copy; 2025 fG!</copyright>
    <lastBuildDate>Fri, 17 Dec 2021 14:20:59 +0000</lastBuildDate><atom:link href="https://reverse.put.as/categories/malware/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Knock Knock! Who&#39;s There? - An NSA VM</title>
      <link>https://reverse.put.as/2021/12/17/knock-knock-whos-there/</link>
      <pubDate>Fri, 17 Dec 2021 14:20:59 +0000</pubDate>
      <author>reverser@put.as (fG!)</author>
      <guid>https://reverse.put.as/2021/12/17/knock-knock-whos-there/</guid>
      <description>&lt;p&gt;Back in 2017 (feels like ages ago) I decided to take a peek into the ShadowBrokers leaks and reverse some of the tools.&lt;/p&gt;
&lt;p&gt;I started on &lt;code&gt;dewdrop&lt;/code&gt; simply because it had a macOS version. I made local presentations at &lt;a href=&#34;https://www.meetup.com/0xOPOSEC/&#34;&gt;0xOpoSec&lt;/a&gt; and &lt;a href=&#34;https://www.bsideslisbon.org&#34;&gt;BSidesLisbon&lt;/a&gt; but those slides were never published for obvious reasons (aka live implants all over the Internet).&lt;/p&gt;
&lt;p&gt;Significant time has passed and everyone went crazy last week with the beautiful &lt;a href=&#34;https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-into-nso-zero-click.html&#34;&gt;NSO exploit VM&lt;/a&gt; published by Project Zero, so why not ride the wave and present a simple NSA BPF VM. It is still an interesting work and you have to admire the great engineering that goes behind this code. It&amp;rsquo;s not everyday that you can take a peek at code developed by a well funded state actor.&lt;/p&gt;
&lt;p&gt;This post is only going to focus on the BPF part of the implant so you will have to fill in the blanks about everything else.&lt;/p&gt;</description>
    </item>
    
    <item>
      <title>The Finfisher Tales, Chapter 1: The dropper</title>
      <link>https://reverse.put.as/2020/09/26/the-finfisher-tales-chapter-1/</link>
      <pubDate>Sat, 26 Sep 2020 18:03:00 +0100</pubDate>
      <author>reverser@put.as (fG!)</author>
      <guid>https://reverse.put.as/2020/09/26/the-finfisher-tales-chapter-1/</guid>
      <description>&lt;p&gt;Amnesty International finally dropped the bomb and released a &lt;a href=&#34;https://www.amnesty.org/en/latest/research/2020/09/german-made-finspy-spyware-found-in-egypt-and-mac-and-linux-versions-revealed/&#34;&gt;report&lt;/a&gt; about FinSpy spyware made by FinFisher Gmbh.&lt;/p&gt;
&lt;p&gt;The most interesting thing was the revelation of Mac and Linux versions, something that was missing from previous reports on this commercial malware (&lt;a href=&#34;https://securelist.com/new-finspy-ios-and-android-implants-revealed-itw/91685/&#34;&gt;Kaspersky&lt;/a&gt;, &lt;a href=&#34;https://wikileaks.org/spyfiles/docs/gamma/291_remote-monitoring-and-infection-solutions-finspy-mobile.html&#34;&gt;Wikileaks&lt;/a&gt;).&lt;/p&gt;</description>
    </item>
    
    <item>
      <title>Is macOS under the biggest malware attack ever?</title>
      <link>https://reverse.put.as/2020/09/17/evilquest-revisited/</link>
      <pubDate>Thu, 17 Sep 2020 15:30:08 +0100</pubDate>
      <author>reverser@put.as (fG!)</author>
      <guid>https://reverse.put.as/2020/09/17/evilquest-revisited/</guid>
      <description>&lt;p&gt;No. I just clickbaited you but don&amp;rsquo;t leave yet, keep reading for something fun!&lt;/p&gt;</description>
    </item>
    
    <item>
      <title>FruitFly&#39;s dropper script and its missing tricks</title>
      <link>https://reverse.put.as/2020/03/04/a-fruitfly-dropper-and-the-missing-tricks/</link>
      <pubDate>Wed, 04 Mar 2020 00:14:40 +0100</pubDate>
      <author>reverser@put.as (fG!)</author>
      <guid>https://reverse.put.as/2020/03/04/a-fruitfly-dropper-and-the-missing-tricks/</guid>
      <description>&lt;p&gt;&lt;strong&gt;Note to original post:&lt;/strong&gt;&lt;br&gt;
&lt;em&gt;This post was originally written back in May 2019 but was removed because of &amp;ldquo;pressure&amp;rdquo; from my employer at the time, Apple. It was written over the weekend on my own equipment and was all about information I had way before I joined Apple. Personally I don&amp;rsquo;t think there is any special drama here other than unreleased technical details about a malware that is dead and its author busted long time ago. When paranoia and envy are dominant then everything can be a potential media drama in people&amp;rsquo;s mind. It&amp;rsquo;s all bullshit. My position didn&amp;rsquo;t change and given that there is an upcoming presentation about this malware by &lt;a href=&#34;https://objectivebythesea.com/v3/content.html#tReed&#34;&gt;Thomas Reed&lt;/a&gt; at Objective By The Sea it&amp;rsquo;s time to re-release this.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;While sorting out my Mac malware collection I found out that I had an unreleased (no known public references) FruitFly/Quimitchin dropper script lost in my archives.&lt;/p&gt;
&lt;p&gt;FruitFly made big headlines two years ago and its author has been &lt;a href=&#34;https://www.zdnet.com/article/ohio-hacker-indicted-fruitfly-malware-spy-on-thousands-of-mac-users/&#34;&gt;arrested&lt;/a&gt;. It was first reported by &lt;a href=&#34;https://blog.malwarebytes.com/threat-analysis/2017/01/new-mac-backdoor-using-antiquated-code/&#34;&gt;MalwareBytes&lt;/a&gt; and then a new variant was analysed by &lt;a href=&#34;https://papers.put.as/papers/macosx/2017/VB2017-Wardle.pdf&#34;&gt;Patrick Wardle&lt;/a&gt;. Besides being under the radar for more than a decade, it was kind of exotic malware because most of its code was written in Perl. Last time I did something serious in Perl was twenty years ago or so!&lt;/p&gt;</description>
    </item>
    
  </channel>
</rss>
