CF

Cyril François

Abonnieren
Artikel von Cyril François
The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions
Security Labs

The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions

Elastic Security Labs tracked this malicious browser extension across seven campaigns and 15 months, through Brazilian bank lures and the Ethereum smart contracts that hold its C2 configuration.

Cyril François
TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains
Security Labs

TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains

TELEPUZ is a modular malware that emerged through CLICKFIX-VIDAR attacks in April. We reverse-engineered it to show you the infrastructure and evasion techniques that matter.

Cyril François
The Cost of Understanding: LLM-Driven Reverse Engineering vs Iterative LLM Obfuscation
Security Labs

The Cost of Understanding: LLM-Driven Reverse Engineering vs Iterative LLM Obfuscation

Elastic Security Labs explores the ongoing arms race between LLM-driven reverse engineering and obfuscation.

Cyril François
Fake Installers to Monero: A Multi-Tool Mining Operation
Security Labs

Fake Installers to Monero: A Multi-Tool Mining Operation

Elastic Security Labs dissects a long-running operation deploying RATs, cryptominers, and CPA fraud through fake installer lures, tracking its evolution across campaigns and Monero payouts.

Jia Yu Chan
BADIIS to the Bone: New Insights to a Global SEO Poisoning Campaign
Security Labs

BADIIS to the Bone: New Insights to a Global SEO Poisoning Campaign

In November 2025, Elastic Security Labs observed an intrusion affecting a multinational organization based in Southeast Asia. During the analysis of this activity, our team observed various post-compromise techniques and tooling used to deploy BADIIS malware onto a Windows web server consistent with other industry publications.

Jia Yu Chan
NightMARE on 0xelm Street, a guided tour
Security Labs

NightMARE on 0xelm Street, a guided tour

This article describes nightMARE, a python-based library for malware researchers that was developed by Elastic Security Labs to help scale analysis. It describes how we use nightMARE to develop malware configuration extractors and carve out intelligence indicators.

Cyril François
Shedding light on the ABYSSWORKER driver
Security Labs

Shedding light on the ABYSSWORKER driver

Elastic Security Labs describes ABYSSWORKER, a malicious driver used with the MEDUSA ransomware attack-chain to disable anti-malware tools.

Cyril François
You've Got Malware: FINALDRAFT Hides in Your Drafts
Security Labs

You've Got Malware: FINALDRAFT Hides in Your Drafts

During a recent investigation (REF7707), Elastic Security Labs discovered new malware targeting a foreign ministry. The malware includes a custom loader and backdoor with many features including using Microsoft’s Graph API for C2 communications.

Cyril François
Katz and Mouse Game: MaaS Infostealers Adapt to Patched Chrome Defenses
Security Labs

Katz and Mouse Game: MaaS Infostealers Adapt to Patched Chrome Defenses

Elastic Security Labs breaks down bypass implementations from the infostealer ecosystem’s reaction to Chrome 127's Application-Bound Encryption scheme.

Jia Yu Chan
Dissecting REMCOS RAT: An in-depth analysis of a widespread 2024 malware, Part Four
Security Labs

Dissecting REMCOS RAT: An in-depth analysis of a widespread 2024 malware, Part Four

In previous articles in this multipart series, malware researchers on the Elastic Security Labs team decomposed the REMCOS configuration structure and gave details about its C2 commands. In this final part, you’ll learn more about detecting and hunting REMCOS using Elastic technologies.

Cyril François
Dissecting REMCOS RAT: An in-depth analysis of a widespread 2024 malware, Part Three
Security Labs

Dissecting REMCOS RAT: An in-depth analysis of a widespread 2024 malware, Part Three

In previous articles in this multipart series, malware researchers on the Elastic Security Labs team dove into the REMCOS execution flow. In this article, you’ll learn more about REMCOS configuration structure and its C2 commands.

Cyril François
Dissecting REMCOS RAT: An in-depth analysis of a widespread 2024 malware, Part Two
Security Labs

Dissecting REMCOS RAT: An in-depth analysis of a widespread 2024 malware, Part Two

In the previous article in this series on the REMCOS implant, we shared information about execution, persistence, and defense evasion mechanisms. Continuing this series we’ll cover the second half of its execution flow and you’ll learn more about REMCOS recording capabilities and communication with its C2.

Cyril François
Dissecting REMCOS RAT: An in-depth analysis of a widespread 2024 malware, Part One
Security Labs

Dissecting REMCOS RAT: An in-depth analysis of a widespread 2024 malware, Part One

This malware research article describes the REMCOS implant at a high level, and provides background for future articles in this multipart series.

Cyril François
STIXy Situations: ECSaping your threat data
Security Labs

STIXy Situations: ECSaping your threat data

Structured threat data is commonly formatted using STIX. To help get this data into Elasticsearch, we’re releasing a Python script that converts STIX to an ECS format to be ingested into your stack.

Cyril François
Disclosing the BLOODALCHEMY backdoor
Security Labs

Disclosing the BLOODALCHEMY backdoor

BLOODALCHEMY is a new, actively developed, backdoor that leverages a benign binary as an injection vehicle, and is a part of the REF5961 intrusion set.

Cyril François
Introducing the REF5961 intrusion set
Security Labs

Introducing the REF5961 intrusion set

The REF5961 intrusion set discloses three new malware families targeting ASEAN members. The threat actor leveraging this intrusion set continues to develop and mature their capabilities.

Daniel Stepanic
Elastic charms SPECTRALVIPER
Security Labs

Elastic charms SPECTRALVIPER

Elastic Security Labs has discovered the P8LOADER, POWERSEAL, and SPECTRALVIPER malware families targeting a national Vietnamese agribusiness. REF2754 shares malware and motivational elements of the REF4322 and APT32 activity groups.

Cyril François
Unpacking ICEDID
Security Labs

Unpacking ICEDID

ICEDID is known to pack its payloads using custom file formats and a custom encryption scheme. We are releasing a set of tools to automate the unpacking process and help analysts and the community respond to ICEDID.

Cyril François
BLISTER Loader
Security Labs

BLISTER Loader

The BLISTER loader continues to be actively used to load a variety of malware.

Cyril François
Thawing the permafrost of ICEDID Summary
Security Labs

Thawing the permafrost of ICEDID Summary

Elastic Security Labs analyzed a recent ICEDID variant consisting of a loader and bot payload. By providing this research to the community end-to-end, we hope to raise awareness of the ICEDID execution chain, capabilities, and design.

Cyril François
PHOREAL Malware Targets the Southeast Asian Financial Sector
Security Labs

PHOREAL Malware Targets the Southeast Asian Financial Sector

Elastic Security discovered PHOREAL malware, which is targeting Southeast Asia financial organizations, particularly those in the Vietnamese financial sector.

Daniel Stepanic
QBOT Malware Analysis
Security Labs

QBOT Malware Analysis

Elastic Security Labs releases a QBOT malware analysis report covering the execution chain. From this research, the team has produced a YARA rule, configuration-extractor, and indicators of compromises (IOCs).

Cyril François
Update to the REF2924 intrusion set and related campaigns
Security Labs

Update to the REF2924 intrusion set and related campaigns

Elastic Security Labs is providing an update to the REF2924 research published in December of 2022. This update includes malware analysis of the implants, additional findings, and associations with other intrusions.

Salim Bitam
FLARE-ON 9 Solutions:
Security Labs

FLARE-ON 9 Solutions:

This year's FLARE-ON consisted of 11 different reverse engineering challenges with a range of interesting binaries. We really enjoyed working on these challenges and have published our solutions here to Elastic Security Labs.

Daniel Stepanic
Exploring the QBOT Attack Pattern
Security Labs

Exploring the QBOT Attack Pattern

In this research publication, we'll explore our analysis of the QBOT attack pattern — a full-featured and prolific malware family.

Cyril François