members

New Kimsuky Malware “EndClient RAT”: First Technical Report and IOCs

Ovi
Ovi
Introduction I have had the pleasure to work with PSCORE for quite some time now and we recently did a talk at RightsCon together about the cyber security dynamics for…
members

Proximity and power: civil society’s role in democratizing spyware research

Ovi
Ovi
Threat intelligence today is a commodity. It is monetized, gated, and shaped to fit the needs of commercial clients before communities. It's a product, collected and tracked to…
members

[0x0v1] Newsletter | RightsCon, Meta's "Threat Ideation(??)" and democratizing spyware forensics

Ovi
Ovi
Yeah that's me, up there, on a stage. Beige all around me, repping McModernism. As a conference speaker and attendee for the better part of a decade, I’…
members

Targeted Threats Research - South & North Korea (a breakdown of 3 years of civil society threat research in Korea)

Ovi
Ovi
This research will be discussed at RightsCon 2025: Unveiling North Korea’s cyber threats: safeguarding human rights Sections: 1. Executive Summary 2. Introduction 3. Methodology 1. Sample submission 2. Auditing…
members

[0x0v1] Newsletter | Disabling TLS Certificate Checks in Flutter (BoringSSL) with Frida

Ovi
Ovi

Server-side Device Validation Protocols in High-Security Android Applications - Cashapp, Revolut, Banking, Healthcare, Government etc.

Ovi
Ovi
In my previous two posts about Android emulator bypassing (Android Network Emulator Bypassing for high security apps - Cashapp, Revolut, Banking, Healthcare, Government etc. & Advanced Android Emulator Bypass Techniques for…
members

[0x0v1] Newsletter | Avoid WhatToExpect pregnancy app, if you care about your privacy & security

Ovi
Ovi
There's snow outside today as winter closes in, and it's feeling pretty cozy. I'm sitting here with a coffee, starting to write some proposals…
members

[0x0v1] Newsletter | General update November 2024

Ovi
Ovi

RE:privacy | Critical vulnerabilities & privacy concerns in WhatToExpect fertility app

Ovi
Ovi
A high level summary of this issue is provided below. A deep technical breakdown of the vulnerabilities is provided later on to supporters of my work. Executive Summary This research…

Android Network Emulator Bypassing for high security apps - Cashapp, Revolut, Banking, Healthcare, Government etc.

Ovi
Ovi
Learn to bypass emulator detection in high-security Android apps using network techniques like SSL unpinning, IP spoofing, and request modification. This guide offers practical methods for intercepting traffic and making emulators look like real devices.…