Original analysis
Research
Incident and technique analysis written by hand, each published with the Sigma rules it produced. Briefs are generated daily from the corpus; these are not.
-
September 12, 2026 · T1566.004, T1598, T1583.001, T1557, T1111, T1078.004, T1036.005, T1027.013, T1098.005 · 6 Sigma rules
A vishing-delivered adversary-in-the-middle kit from the ShinyHunters-linked company.claims campaign hides a Cloudflare Turnstile widget beneath a pixel-clone Google reCAPTCHA at 1% opacity, and exfiltrates credentials first-party over an XOR channel keyed off the _fbc cookie rather than to Telegram. Prior public reporting had the campaign's infrastructure but no kit to fingerprint; this is the kit.
-
EtherHiding on BSC Testnet: an On-Chain Conversion Registry Keyed by Visitor IP
August 11, 2026 · T1195.002, T1102.001, T1204.004, T1218.011, T1105, T1027.007, T1055, T1620, T1562.006, T1497, T1574.002, T1555.003, T1005, T1041, T1573 · 7 Sigma rules
A rogue Google Tag Manager container delivers a ClickFix lure via payloads stored in BSC testnet smart contracts, staging a loader over WebDAV. The loader is unpacked through all five layers, then a decrypted third stage that uses a WOW64 32->64-bit transition (Heaven's Gate) to run 64-bit code beneath the reach of 32-bit endpoint hooks. The technique stack matches the HijackLoader/IDAT lineage; a sandbox run confirms the chain and identifies the final payload as ACR Stealer, side-loaded through a signed javac.exe and exfiltrating browser and wallet data over TLS. The operator also runs a world-readable on-chain registry that de-duplicates victims by public IP address.