members

New Kimsuky Malware “EndClient RAT”: First Technical Report and IOCs

Ovi
Ovi
Introduction I have had the pleasure to work with PSCORE for quite some time now and we recently did a talk at RightsCon together about the cyber security dynamics for…
members

Proximity and power: civil society’s role in democratizing spyware research

Ovi
Ovi
Threat intelligence today is a commodity. It is monetized, gated, and shaped to fit the needs of commercial clients before communities. It's a product, collected and tracked to…
members

Targeted Threats Research - South & North Korea (a breakdown of 3 years of civil society threat research in Korea)

Ovi
Ovi
This research will be discussed at RightsCon 2025: Unveiling North Korea’s cyber threats: safeguarding human rights Sections: 1. Executive Summary 2. Introduction 3. Methodology 1. Sample submission 2. Auditing…
members

[0x0v1] Newsletter | Disabling TLS Certificate Checks in Flutter (BoringSSL) with Frida

Ovi
Ovi

Server-side Device Validation Protocols in High-Security Android Applications - Cashapp, Revolut, Banking, Healthcare, Government etc.

Ovi
Ovi
In my previous two posts about Android emulator bypassing (Android Network Emulator Bypassing for high security apps - Cashapp, Revolut, Banking, Healthcare, Government etc. & Advanced Android Emulator Bypass Techniques for…
members

[0x0v1] Newsletter | Avoid WhatToExpect pregnancy app, if you care about your privacy & security

Ovi
Ovi
There's snow outside today as winter closes in, and it's feeling pretty cozy. I'm sitting here with a coffee, starting to write some proposals…
members

[0x0v1] Newsletter | General update November 2024

Ovi
Ovi

RE:privacy | Critical vulnerabilities & privacy concerns in WhatToExpect fertility app

Ovi
Ovi
A high level summary of this issue is provided below. A deep technical breakdown of the vulnerabilities is provided later on to supporters of my work. Executive Summary This research…

Android Network Emulator Bypassing for high security apps - Cashapp, Revolut, Banking, Healthcare, Government etc.

Ovi
Ovi
Learn to bypass emulator detection in high-security Android apps using network techniques like SSL unpinning, IP spoofing, and request modification. This guide offers practical methods for intercepting traffic and making emulators look like real devices.…

Advanced Android Emulator Bypass Techniques for High-Security Apps: CashApp, Revolut, Healthcare & More

Ovi
Ovi
Introduction Apps handling our most sensitive data—whether managing financial transactions in CashApp, Revolut, or other banking platforms, or safeguarding personal records in healthcare applications—often employ robust emulation detection…