/categories/threat-intel
Threat Intelligence & Operations
Honeypots, attacker telemetry, campaigns, malware observation, and defensive operations.
4 posts
- How a Pirate "Free Netflix" App Smuggles Video Inside .jpg FilesTearing apart a streaming APK my sister installed. Not malware — but a React Native WebView shell, 24 rotating decoy domains, a signed-token ad wall as DRM, and MPEG-TS transport streams wearing JPEG and JS costumes.9 min read
- I Built a Honeypot Framework, Deployed It for 5 Days, and the Internet Showed Up With Malware and Opinions119,001 events. 1,120 unique IPs. 16 malware samples. 822 terminal recordings. The same Chinese worm. The same cryptominer. A 29MB botnet propagation binary. And a tool I wrote to make sense of all of it.22 min read
- I Mass-Accepted SSH Logins for 48 Hours and Catalogued Everything That Walked In38,208 events. 374 unique IPs. 12 malware samples. A self-propagating Chinese worm. A multi-architecture cryptominer. Two competing SSH backdoor campaigns. One very convincing fake server.18 min read
- SSH Under Siege: 30 Days of Brute-Force Telemetry on an Exposed VM 🌐1,595 brute-force attempts. 64 IPs. 20+ countries. A month of SSH login fails against my Oracle Cloud VM, with a globe to make it look impressive.6 min read