OpenFraudMonitoring V1.0

A follow-up to my OpenFraudMonitoring presentation, covering two new features built to empower investigations: a graph view for correlating sessions, and behavioral fingerprinting with behavior-based risk rules.

July 30, 2026

UAC-0057 / GhostWriter / UNC1151: JavaScript backdoor campaign analysis

Technical analysis of a recent UNC1151 (GhostWriter) campaign targeting Ukrainian entities. Covers deobfuscation of the OYSTERFRESH dropper and OYSTERBLUES backdoor, CTI infrastructure hunting, and a MITRE ATT&CK technique mapping.

July 19, 2026

OpenFraudMonitoring presentation

This blog post describes my latest development project, which is a Fraud Monitoring solution that fingerprints users and enables the detection of Threat Actors. I give an example of how it enabled me to discover malicious behavior on one of my selfhosted microservices.

July 13, 2026

Xworm V7.4 analysis

This report documents the internals of the V7.4 builder of Xworm, and analyzes various samples compiled with all available flags in order to understand the implementation methods of the malware. A YARA detection rule and a MITRE ATT&CK technique mapping are provided.

June 28, 2026