members
Advanced Android Emulator Bypass Techniques for High-Security Apps: CashApp, Revolut, Healthcare & More
Introduction
Apps handling our most sensitive data—whether managing financial transactions in CashApp, Revolut, or other banking platforms, or safeguarding personal records in healthcare applications—often employ robust emulation detection…
members
UCID902: Uncovering nation state watering hole credential harvesting campaigns targeting human rights activists by APT threat group UCID902 (2023)
This is a repost of some critical research I performed back in 2023 that was originally hosted on Interlab's website. Since Interlab has been abandoned by it'…
members
Security and privacy analysis: MDM applications (국방모바일보안) for South Korean Military personnel (2023)
This is a repost of some critical research I performed back in 2023 that was originally hosted on Interlab's website. Since Interlab has been abandoned by it'…
members
RambleOn Android Spyware (December 2022)
This is a repost of some critical research I performed back in 2022 that was originally hosted on Interlab's website. Since Interlab has been abandoned by it'…
members
Account Takeover via browsable intent filter in [Redacted] Android app
Mobile app security is an interesting field; since app sandbox restrictions are very good, finding security issues can be extremely hard. I think this is an interesting bug simply because…
members
instructSOCIETY | Visual programming of malware tutorial & project files // part 2
0:00
/1:16
1×
Introduction
This is a paid subscriber only tutorial that gives you exclusive access to learn how I created the programmatic visualizations of malware within the…
members
instructSOCIETY | Malware digraphs & modelling // part 1
The visualization of malware has been a widely discussed topic over the years, though it hasn't garnered as much attention in the last decade. Nearly ten years ago,…
members
RE:archive | APT37's ROKRAT HWP Object Linking and Embedding
Please note: The sample covered in this report is from 2022. I have covered this sample for archiving purposes and does not pertain to a known recent threat campaign, though…
members
RE:privacy | Glow Fertility women's health app - IDOR vulnerability leads to 25 million userbase dataleak
Summary
As part of the RE:privacy project, I am reverse engineering and hacking reproductive health apps to interrogate the security and privacy of these products. You can find out…