<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Derp: Security Research</title>
    <link>https://www.derp.ca/</link>
    <description>Original malware analysis, threat intelligence, and security research from the Derp team.</description>
    <language>en</language>
    <lastBuildDate>Tue, 14 Jul 2026 12:00:00 GMT</lastBuildDate>
    <atom:link href="https://www.derp.ca/feed.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>From EtherHiding to a native RAT: ClickFix on new-blog.artlist[.]io</title>
      <link>https://www.derp.ca/research/artlist-clickfix-native-rat/</link>
      <guid isPermaLink="true">https://www.derp.ca/research/artlist-clickfix-native-rat/</guid>
      <description>Static teardown of a ClickFix chain on new-blog.artlist[.]io, from Polygon EtherHiding and PowerShell delivery to a manually mapped native Windows RAT.</description>
      <pubDate>Tue, 14 Jul 2026 12:00:00 GMT</pubDate>
      <author>kirk@derp.ca (Kirk)</author>
    </item>
    <item>
      <title>SilverFox-style loader chain: Panasonic shells, Alibaba OSS carriers, and a Sauron backdoor</title>
      <link>https://www.derp.ca/research/silverfox-panasonic-sauron-loader-chain/</link>
      <guid isPermaLink="true">https://www.derp.ca/research/silverfox-panasonic-sauron-loader-chain/</guid>
      <description>Technical analysis of a SilverFox-style loader chain hiding behind Panasonic PC Notification metadata, using Alibaba OSS carriers, signed side-load hosts, RPC Task Scheduler staging, and a Sauron backdoor.</description>
      <pubDate>Sun, 21 Jun 2026 12:00:00 GMT</pubDate>
      <author>kirk@derp.ca (Kirk)</author>
    </item>
    <item>
      <title>AI-Powered Cheats &amp; Stolen Secrets: Teardown of the Yuta/Solara Roblox Stealer</title>
      <link>https://www.derp.ca/research/yuta-solara-roblox-python-rat/</link>
      <guid isPermaLink="true">https://www.derp.ca/research/yuta-solara-roblox-python-rat/</guid>
      <description>Deep-dive analysis of a trojanized Roblox executor that functions as a highly convincing lure with live DeepSeek script generation, while silently staging a Python 3.12 variant of Glove Stealer that bypasses Google Chrome&apos;s App-Bound Encryption.</description>
      <pubDate>Thu, 04 Jun 2026 12:00:00 GMT</pubDate>
      <author>kirk@derp.ca (Kirk)</author>
    </item>
    <item>
      <title>PoisonX WindowsTelemetry: BYOVD-Assisted RAT With a Plugin Loader</title>
      <link>https://www.derp.ca/research/poisonx-windowstelemetry-byovd-rat/</link>
      <guid isPermaLink="true">https://www.derp.ca/research/poisonx-windowstelemetry-byovd-rat/</guid>
      <description>PoisonX WindowsTelemetry chain: VERSION.dll sideloading, BYOVD scheduler, 10FX RAT protocol, SOCKS relay, plugin loading, and C2 reuse across two archives.</description>
      <pubDate>Tue, 19 May 2026 12:00:00 GMT</pubDate>
      <author>kirk@derp.ca (Kirk)</author>
    </item>
    <item>
      <title>CrystalX: unpacking a Go RAT through three encrypted layers</title>
      <link>https://www.derp.ca/research/crystalx-go-rat/</link>
      <guid isPermaLink="true">https://www.derp.ca/research/crystalx-go-rat/</guid>
      <description>Static reverse engineering of a 6.9 MB Go RAT delivered through a C stub loader with XOR, ChaCha20, DEFLATE, AES-GCM strings, and WebSocket C2.</description>
      <pubDate>Mon, 18 May 2026 12:00:00 GMT</pubDate>
      <author>kirk@derp.ca (Kirk)</author>
    </item>
    <item>
      <title>Vidar v1.5 in Go: same family, new language, heavy sandbox checks</title>
      <link>https://www.derp.ca/research/vidar-go-sandbox-dead-drop/</link>
      <guid isPermaLink="true">https://www.derp.ca/research/vidar-go-sandbox-dead-drop/</guid>
      <description>A Go 1.25.4 Vidar v1.5 sample uses a twelve-category sandbox scoring system, Telegram and Steam dead-drop C2 discovery, and process injection APIs.</description>
      <pubDate>Sat, 16 May 2026 12:00:00 GMT</pubDate>
      <author>kirk@derp.ca (Kirk)</author>
    </item>
    <item>
      <title>Eimeria: five layers from RAR5 to RunPE</title>
      <link>https://www.derp.ca/research/eimeria-multi-stage-loader/</link>
      <guid isPermaLink="true">https://www.derp.ca/research/eimeria-multi-stage-loader/</guid>
      <description>Five-layer delivery chain from a RAR5 archive through a signed carrier DLL side-load, AES-CBC hidden in a fake zlib DLL, IExpress extraction, AutoIt process hollowing, and a .NET C2 beacon on WebSocket.</description>
      <pubDate>Fri, 08 May 2026 12:00:00 GMT</pubDate>
      <author>kirk@derp.ca (Kirk)</author>
    </item>
    <item>
      <title>VECT ransomware: small files decrypt, large files lose their nonces</title>
      <link>https://www.derp.ca/research/vect-ransomware-nonce-loss/</link>
      <guid isPermaLink="true">https://www.derp.ca/research/vect-ransomware-nonce-loss/</guid>
      <description>A VECT 2.0 Windows sample can recover small files with a static ChaCha20 key and saved 12-byte nonce, but its large-file path keeps only the final nonce and loses the rest.</description>
      <pubDate>Sat, 02 May 2026 12:00:00 GMT</pubDate>
      <author>kirk@derp.ca (Kirk)</author>
    </item>
    <item>
      <title>M3rx ransomware: inside a new leak-site actor and Go encryptor</title>
      <link>https://www.derp.ca/research/m3rx-ransomware-go-encryptor/</link>
      <guid isPermaLink="true">https://www.derp.ca/research/m3rx-ransomware-go-encryptor/</guid>
      <description>M3rx surfaced with a small leak-site burst and a Go ransomware sample using gzip+gob config data, X25519, AES-CTR file encryption, AES-GCM key wrapping, and a 0x400-byte footer.</description>
      <pubDate>Mon, 27 Apr 2026 12:00:00 GMT</pubDate>
      <author>kirk@derp.ca (Kirk)</author>
    </item>
    <item>
      <title>Kyber ransomware is not just post-quantum name-dropping</title>
      <link>https://www.derp.ca/research/kyber-ransomware-hybrid-crypto/</link>
      <guid isPermaLink="true">https://www.derp.ca/research/kyber-ransomware-hybrid-crypto/</guid>
      <description>A Rust Kyber ransomware sample uses AES-256-CTR style file encryption, Kyber1024-sized material, active X25519 arithmetic, and a fixed 0x744 trailer.</description>
      <pubDate>Sun, 26 Apr 2026 12:00:00 GMT</pubDate>
      <author>kirk@derp.ca (Kirk)</author>
    </item>
    <item>
      <title>Urelas is old, weird, and still watching Korean card games</title>
      <link>https://www.derp.ca/research/urelas-korean-card-game-capture/</link>
      <guid isPermaLink="true">https://www.derp.ca/research/urelas-korean-card-game-capture/</guid>
      <description>A fresh Urelas cluster shows thousands of March-April 2026 samples, Korean ISP command-and-control hosts, a bit-flipped MSMP config, and JPEG capture records built for Korean card-game clients.</description>
      <pubDate>Sat, 25 Apr 2026 12:00:00 GMT</pubDate>
      <author>kirk@derp.ca (Kirk)</author>
    </item>
    <item>
      <title>TryNodeUpdate turns GitHub and BSC into a TCP control lane</title>
      <link>https://www.derp.ca/research/trynodeupdate-github-node-bsc-contract-c2/</link>
      <guid isPermaLink="true">https://www.derp.ca/research/trynodeupdate-github-node-bsc-contract-c2/</guid>
      <description>A PowerShell sample installs a GitHub-hosted Node controller, uses a BNB Smart Chain contract to resolve its backend, then hands elevated Windows hosts to a native rpc.exe helper.</description>
      <pubDate>Fri, 24 Apr 2026 12:00:00 GMT</pubDate>
      <author>kirk@derp.ca (Kirk)</author>
    </item>
    <item>
      <title>Qilin: inside the Windows ransomware build behind 1,000+ victims</title>
      <link>https://www.derp.ca/research/qilin-ransomware-teardown/</link>
      <guid isPermaLink="true">https://www.derp.ca/research/qilin-ransomware-teardown/</guid>
      <description>Teardown of the CheckQilin Windows build from 2025&apos;s top ransomware crew: BYOVD EDR killer, AES/ChaCha20 dispatch, RSA-OAEP footer, one-byte password bypass.</description>
      <pubDate>Thu, 09 Apr 2026 12:00:00 GMT</pubDate>
      <author>kirk@derp.ca (Kirk)</author>
    </item>
    <item>
      <title>SERPENTINE#CLOUD returns: ClickFix lure drops five RATs</title>
      <link>https://www.derp.ca/research/serpentine-cloud-clickfix-return/</link>
      <guid isPermaLink="true">https://www.derp.ca/research/serpentine-cloud-clickfix-return/</guid>
      <description>Same operator, new delivery chain. ClickFix through Cloudflare tunnels drops five RAT families simultaneously - including Brute Ratel C4 wrapping PureHVNC.</description>
      <pubDate>Fri, 03 Apr 2026 12:00:00 GMT</pubDate>
      <author>kirk@derp.ca (Kirk)</author>
    </item>
    <item>
      <title>Axios npm compromise: XOR dropper to cross-platform RAT</title>
      <link>https://www.derp.ca/research/axios-npm-supply-chain-rat/</link>
      <guid isPermaLink="true">https://www.derp.ca/research/axios-npm-supply-chain-rat/</guid>
      <description>Axios 1.14.1 supply chain attack torn apart. XOR dropper deobfuscated, macOS Mach-O decompiled, Windows PowerShell RAT reversed, C2 protocol mapped.</description>
      <pubDate>Tue, 31 Mar 2026 12:00:00 GMT</pubDate>
      <author>kirk@derp.ca (Kirk)</author>
    </item>
    <item>
      <title>Breaking Aura: five obfuscation layers &amp; hates sandboxes</title>
      <link>https://www.derp.ca/research/aura-stealer-reverse-engineering/</link>
      <guid isPermaLink="true">https://www.derp.ca/research/aura-stealer-reverse-engineering/</guid>
      <description>Five code obfuscation layers broken, transport encryption reversed, and the full server-pushed config decrypted from a live Aura Stealer C2. Heaven&apos;s Gate, CFF, FNV-1a hash tables, and AES-256-CBC.</description>
      <pubDate>Sat, 28 Mar 2026 12:00:00 GMT</pubDate>
      <author>kirk@derp.ca (Kirk)</author>
    </item>
    <item>
      <title>Pay2Key encryptor: what a January 2026 build reveals</title>
      <link>https://www.derp.ca/research/pay2key-ransomware-crypto-briefing/</link>
      <guid isPermaLink="true">https://www.derp.ca/research/pay2key-ransomware-crypto-briefing/</guid>
      <description>Crypto analysis of a Jan 2026 Pay2Key encryptor. ChaCha20 + Curve25519 via OpenSSL, null nonce, session.tmp on disk. Intermittent mode leaves 70-87% plaintext in large files.</description>
      <pubDate>Thu, 26 Mar 2026 12:00:00 GMT</pubDate>
      <author>kirk@derp.ca (Kirk)</author>
    </item>
    <item>
      <title>A Sliver dropper that asks GPT-4 for permission</title>
      <link>https://www.derp.ca/research/ai-gated-sliver-dropper/</link>
      <guid isPermaLink="true">https://www.derp.ca/research/ai-gated-sliver-dropper/</guid>
      <description>Analysis of a Go binary that sends host telemetry to GPT-4 and only drops its Sliver C2 payload if the model says the environment is safe. We recovered the full system prompt.</description>
      <pubDate>Wed, 25 Mar 2026 12:00:00 GMT</pubDate>
      <author>kirk@derp.ca (Kirk)</author>
    </item>
    <item>
      <title>InterLock: full tooling teardown of a ransomware operation</title>
      <link>https://www.derp.ca/research/interlock-tooling-teardown/</link>
      <guid isPermaLink="true">https://www.derp.ca/research/interlock-tooling-teardown/</guid>
      <description>Static analysis of 15 InterLock samples: ScreenConnect delivery, NodeSnake implants in three languages, a shared crypter, and dual-platform ransomware.</description>
      <pubDate>Wed, 25 Mar 2026 12:00:00 GMT</pubDate>
      <author>kirk@derp.ca (Kirk)</author>
    </item>
    <item>
      <title>Payload ransomware group: mutex MakeAmericaGreatAgain</title>
      <link>https://www.derp.ca/research/payload-ransomware-babuk-derivative/</link>
      <guid isPermaLink="true">https://www.derp.ca/research/payload-ransomware-babuk-derivative/</guid>
      <description>Full static analysis of the Payload ransomware group. Curve25519 + ChaCha20 encryption, Windows + ESXi builds, 12 victims, 2,603 GB exfiltrated.</description>
      <pubDate>Sun, 15 Mar 2026 12:00:00 GMT</pubDate>
      <author>kirk@derp.ca (Kirk)</author>
    </item>
    <item>
      <title>HellsUchecker: ClickFix to blockchain-backed backdoor</title>
      <link>https://www.derp.ca/research/hellsuchecker-clickfix-etherhiding/</link>
      <guid isPermaLink="true">https://www.derp.ca/research/hellsuchecker-clickfix-etherhiding/</guid>
      <description>A 10-stage ClickFix chain uses finger.exe, EtherHiding smart contracts, and Hell&apos;s Gate syscalls to deliver a memory-resident x64 backdoor.</description>
      <pubDate>Wed, 11 Mar 2026 12:00:00 GMT</pubDate>
      <author>kirk@derp.ca (Kirk)</author>
    </item>
    <item>
      <title>Tranium wiper: static analysis of a Go binary</title>
      <link>https://www.derp.ca/research/tranium-wiper-analysis/</link>
      <guid isPermaLink="true">https://www.derp.ca/research/tranium-wiper-analysis/</guid>
      <description>Analysis of Tranium, a Go wiper disguised as ransomware. AES-CBC encryption, MBR overwrite, 30+ system files destroyed, 10 persistence mechanisms, zero payment infrastructure.</description>
      <pubDate>Tue, 10 Mar 2026 12:00:00 GMT</pubDate>
      <author>kirk@derp.ca (Kirk)</author>
    </item>
    <item>
      <title>GhostWeaver - a malware that lives up to its name</title>
      <link>https://www.derp.ca/research/ghostweaver-tag124-powershell-rat/</link>
      <guid isPermaLink="true">https://www.derp.ca/research/ghostweaver-tag124-powershell-rat/</guid>
      <description>A TAG-124 fileless PowerShell RAT with 1/76 VT detection. We decoded the wire protocol, four DGA systems, persistence modes, and probed the live C2 server.</description>
      <pubDate>Sun, 08 Mar 2026 12:00:00 GMT</pubDate>
      <author>kirk@derp.ca (Kirk)</author>
    </item>
    <item>
      <title>FakeGit: LuaJIT malware distributed via GitHub at scale</title>
      <link>https://www.derp.ca/research/fakegit-luajit-github-campaign/</link>
      <guid isPermaLink="true">https://www.derp.ca/research/fakegit-luajit-github-campaign/</guid>
      <description>A Vietnamese operator has run 600+ malicious ZIPs through 47+ GitHub accounts for 13 months. C2 resolves via Polygon smart contract. Final payload is StealC.</description>
      <pubDate>Wed, 04 Mar 2026 12:00:00 GMT</pubDate>
      <author>kirk@derp.ca (Kirk)</author>
    </item>
    <item>
      <title>OCRFix botnet hides C2 in BNB Smart Chain contracts</title>
      <link>https://www.derp.ca/research/ocrfix-etherhiding-botnet/</link>
      <guid isPermaLink="true">https://www.derp.ca/research/ocrfix-etherhiding-botnet/</guid>
      <description>A three-stage VBSEdit botnet uses BSC testnet smart contracts to resolve C2 URLs at runtime. One blockchain transaction rotates every bot to a new domain.</description>
      <pubDate>Tue, 03 Mar 2026 12:00:00 GMT</pubDate>
      <author>kirk@derp.ca (Kirk)</author>
    </item>
    <item>
      <title>Archive.org Stego Delivers Remcos and AsyncRAT</title>
      <link>https://www.derp.ca/research/archive-org-stego-campaign/</link>
      <guid isPermaLink="true">https://www.derp.ca/research/archive-org-stego-campaign/</guid>
      <description>An operator hides .NET injector DLLs in 4K wallpaper JPEGs on archive.org, rotating daily across four accounts to deliver Remcos and AsyncRAT.</description>
      <pubDate>Sat, 28 Feb 2026 12:00:00 GMT</pubDate>
      <author>kirk@derp.ca (Kirk)</author>
    </item>
    <item>
      <title>IronChain: A Ransomware That Cannot Decrypt</title>
      <link>https://www.derp.ca/research/ironchain-wiper-analysis/</link>
      <guid isPermaLink="true">https://www.derp.ca/research/ironchain-wiper-analysis/</guid>
      <description>Static analysis of IronChain, a Python wiper disguised as ransomware. The RSA-4096 private key is never saved or exfiltrated -- encrypted files are permanently lost.</description>
      <pubDate>Tue, 24 Feb 2026 12:00:00 GMT</pubDate>
      <author>kirk@derp.ca (Kirk)</author>
    </item>
    <item>
      <title>Python Loader Evolution: Five Encryption Generations</title>
      <link>https://www.derp.ca/research/python-loader-evolution/</link>
      <guid isPermaLink="true">https://www.derp.ca/research/python-loader-evolution/</guid>
      <description>Five generations of Python loader encryption in a 9-RAT campaign: from plaintext RC4 to polymorphic Unicode bytecode, with Donut Chaskey CTR shellcode bridging to .NET.</description>
      <pubDate>Tue, 24 Feb 2026 12:00:00 GMT</pubDate>
      <author>kirk@derp.ca (Kirk)</author>
    </item>
    <item>
      <title>Remcos Banking Fraud via Three AutoIt Persistence Chains</title>
      <link>https://www.derp.ca/research/remcos-autoit-persistence/</link>
      <guid isPermaLink="true">https://www.derp.ca/research/remcos-autoit-persistence/</guid>
      <description>Three AutoIt persistence chains deliver Remcos v7.0.1 Pro for Canadian banking fraud. The third delivers PureHVNC on shared PureLogs C2 infrastructure.</description>
      <pubDate>Tue, 24 Feb 2026 12:00:00 GMT</pubDate>
      <author>kirk@derp.ca (Kirk)</author>
    </item>
    <item>
      <title>PureCrypter: Reverse Engineering a .NET Loader From the PureCoder Ecosystem</title>
      <link>https://www.derp.ca/research/purecrypter-loader-analysis/</link>
      <guid isPermaLink="true">https://www.derp.ca/research/purecrypter-loader-analysis/</guid>
      <description>Technical analysis of PureCrypter, a builder-generated .NET crypter from the PureCoder malware-as-a-service ecosystem, recovered from a multi-stage intrusion tracked as SERPENTINE#CLOUD. Two builds fully reversed.</description>
      <pubDate>Sun, 22 Feb 2026 12:00:00 GMT</pubDate>
      <author>kirk@derp.ca (Kirk)</author>
    </item>
    <item>
      <title>VioletWorm v4.7 (Violet RAT): The Most Dangerous Payload in a 9-RAT Toolkit</title>
      <link>https://www.derp.ca/research/violet-rat-analysis/</link>
      <guid isPermaLink="true">https://www.derp.ca/research/violet-rat-analysis/</guid>
      <description>Technical analysis of VioletWorm v4.7 (also tracked as Violet RAT) -- a .NET RAT with ransomware, HVNC, USB spreading, crypto clipping, and 120 command branches dispatched through C2-delivered plugin DLLs -- recovered from a multi-stage intrusion with tooling overlap to SERPENTINE#CLOUD.</description>
      <pubDate>Sun, 22 Feb 2026 12:00:00 GMT</pubDate>
      <author>kirk@derp.ca (Kirk)</author>
    </item>
    <item>
      <title>PureLogs: Reverse Engineering a .NET RAT From the PureCoder Ecosystem</title>
      <link>https://www.derp.ca/research/plog-rat-analysis/</link>
      <guid isPermaLink="true">https://www.derp.ca/research/plog-rat-analysis/</guid>
      <description>Technical analysis of two PureLogs variants from the PureCoder MaaS ecosystem -- a plugin stager and a monolithic crypto-stealing fat client -- recovered from a multi-stage intrusion tracked as SERPENTINE#CLOUD.</description>
      <pubDate>Sat, 21 Feb 2026 12:00:00 GMT</pubDate>
      <author>kirk@derp.ca (Kirk)</author>
    </item>
    <item>
      <title>GitHub Honeypot Scam: sOLarFLaMEPyL/Arbitrage_Mev_BOT</title>
      <link>https://www.derp.ca/research/arbitrage-mev-bot-honeypot-scam/</link>
      <guid isPermaLink="true">https://www.derp.ca/research/arbitrage-mev-bot-honeypot-scam/</guid>
      <description>Reverse engineering a fund-draining honeypot smart contract disguised as a MEV arbitrage bot on GitHub, exposing the hidden backdoor and withdrawal mechanism.</description>
      <pubDate>Mon, 16 Feb 2026 12:00:00 GMT</pubDate>
      <author>kirk@derp.ca (Kirk)</author>
    </item>
  </channel>
</rss>