Daily Writeups
3.92K subscribers
4 photos
135K links
Daily Bug Bounty / Cybersecurity Writeups
Source Code : https://github.com/Spix0r/writeup-miner
Download Telegram
⤷ Title: An Investigation of AMSI Evasion
════════════════════════
𐀪 Author: John Ford
════════════════════════
ⴵ Time: Wed, 08 Oct 2025 22:41:17 GMT
════════════════════════
⌗ Tags: #defense_evasion #powershell #penetration_testing #amsi
⤷ Title: Amatera Stealer Campaign Uses ClickFix to Deploy Malware, Bypassing EDR by Patching AMSI in Memory
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 00:10:03 +0000
════════════════════════
⌗ Tags: #Malware #Amatera Stealer #AMSI Bypass #ClickFix #Credential Theft #NetSupport RAT #powershell #Pure Crypter #WoW64 syscalls
⤷ Title: LazyHook: New Framework Uses Hardware Breakpoints to Bypass EDR Stealthily
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 10:39:52 +0000
════════════════════════
⌗ Tags: #Open Source Tool #AMSI Bypass #cybersecurity #EDR evasion #Hardware Breakpoint #Hooking #LazyHook #Stealth #System Call Interception #Windows Security
⤷ Title: Ransomware Groups Pivot: The Rise of Weyhro C2, a New Advanced Command-and-Control Platform
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 04:37:38 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AMSI Bypass #Command and Control #cybercrime #cybersecurity #evasion techniques #HVNC #Memory_Only Malware #ransomware #threat intelligence #Weyhro C2
⤷ Title: Founding: The Next-Gen Loader Generator for Advanced Evasion
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 03:21:55 +0000
════════════════════════
⌗ Tags: #Open Source Tool #AMSI Bypass #Cybersecurity 2025 #ETW Blinding #Founding #Indirect Syscalls #Malware Evasion #Obfuscation #red teaming #Sandbox Evasion #shellcode
⤷ Title: The Ghost in the Machine: Master Stealth with the Orsted C2 Framework
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 26 Dec 2025 02:44:26 +0000
════════════════════════
⌗ Tags: #Open Source Tool #AMSI Evasion #Command and Control #cybersecurity #Go_lang #Ligolo_ng #Orsted C2 #Penetration Testing #post_exploitation #red teaming #Sandbox Deception
⤷ Title: Amsi’yi anlamak
════════════════════════
𐀪 Author: Ege
════════════════════════
ⴵ Time: Mon, 12 Jan 2026 07:05:55 GMT
════════════════════════
⌗ Tags: #hacking #cybersecurity #siber_guvenlik #reverse_engineering #amsi
⤷ Title: Bypassing AMSI
════════════════════════
𐀪 Author: z3l3v
════════════════════════
ⴵ Time: Thu, 12 Mar 2026 20:40:08 GMT
════════════════════════
⌗ Tags: #amsi_bypas #windows_defender #ethical_hacking #red_team #windows
⤷ Title: The Invisible Thread: Inside the Multi-Stage Python Injection Powering VioletRAT
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 14 Mar 2026 07:08:06 +0000
════════════════════════
⌗ Tags: #Malware #.NET CLR Hosting #AMSI Bypass #Cyber Security 2026 #malware analysis #Process Hollowing #Python injection #RAT #shellcode #SonicWall #VioletRAT
⤷ Title: STX RAT: The New Financial Predator Hiding in the “Start of Text”
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 13 Apr 2026 09:00:35 +0000
════════════════════════
⌗ Tags: #Malware #AMSI Ghosting #encryption #eSentire #Financial Cybersecurity #HVNC #infosec #malware #rat #Stealth Malware #STX RAT #threat intelligence
⤷ Title: New “PowMix” Botnet Preys on Czech Workforce with Lure of Compliance
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Apr 2026 09:11:43 +0000
════════════════════════
⌗ Tags: #Malware #AMSI Bypass #botnet #Cisco Talos #cyber_espionage #Czech Republic #EDEKA Phishing #Heroku Abuse #infosec #Malware Analysis #PowerShell Malware #PowMix #REST API Mimicry
⤷ Title: AI Hype Hijacked: How a Fake Claude Installer Blinds Windows Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 21 Apr 2026 06:30:25 +0000
════════════════════════
⌗ Tags: #Malware #AMSI Bypass #Claude AI #ClickFix #cybersecurity #infosec #malware #mshta.exe #MSIX #phishing #powershell #Rapid7
⤷ Title: AMSI: Bypass Methods Every Red Teamer Needs
════════════════════════
𐀪 Author: Victor
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 17:17:27 GMT
════════════════════════
⌗ Tags: #cybersecurity #red_teaming #hacking #amsi_bypas #malware_development
⤷ Title: The InstallFix Trap: Fake Claude AI Google Ads Drop Fileless RedLine Malware on Developers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 08 May 2026 06:11:33 +0000
════════════════════════
⌗ Tags: #Malware #AMSI Bypass #Anthropic #Claude AI #ClickFix #cybersecurity #Fileless Malware #Google Ads Phishing #infosec #InstallFix #Redline stealer #Threat Intel
⤷ Title: Weaponized JPEG Payload Deploys Trojanized ScreenConnect for Covert Espionage
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 07:01:10 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AMSI Bypass #ConnectWise #Cyber Security #Cyfirma #infosec #JPEG Exploit #Operation SilentCanvas #PowerShell Malware #ScreenConnect #Trojan #UAC bypass
⤷ Title: Hackers Use PyInstaller and AMSI Patching to Deliver XWorm RAT v7.4
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Fri, 15 May 2026 16:42:58 +0000
════════════════════════
⌗ Tags: #Security #Malware #Scams and Fraud #AMSI #Cyber Attack #Cybersecurity #Point Wild #PyInstaller #RAT #XWorm #XWorm 7.4
⤷ Title: CountLoader Malware Weaponizes EtherHiding to Deploy Stealth Crypto Clippers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 18 May 2026 09:15:54 +0000
════════════════════════
⌗ Tags: #Malware #AMSI Bypass #CountLoader #Crypto theft #Cryptocurrency Clipper #Cyber Security #EtherHiding #Fileless Malware #infosec #McAfee Labs #threat intelligence
⤷ Title: Multi-Stage PyInstaller Loader Weaponizes AMSI Patching to Deploy XWorm RAT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 20 May 2026 06:13:42 +0000
════════════════════════
⌗ Tags: #Malware #AMSI Bypass #Cyber Security #defense evasion #infosec #Malware Analysis #Point Wild #PyInstaller Loader #rat #Remote Access Trojan #VirtualProtect #XWorm
⤷ Title: Under the PyInstaller Mask: Point Wild Exposes XWorm V7.4 Stealth Loader and AMSI Bypass
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 20 May 2026 07:49:06 +0000
════════════════════════
⌗ Tags: #Malware #.NET Reflection Plugins #AES Encrypted C2 Configuration #AMSI Bypass In_Memory Execution #Fileless Remote Administrative Trojan #Hidden System File Attributes #Point Wild Threat Intelligence #PyInstaller Loader Forensic #Runtime Windows API Resolving #Win.Kernel_Svc_AJ8iOw.exe #XWorm V7.4 Malware
⤷ Title: CrySome RAT Spread Through Fake Freight Rate Confirmation Phishing
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 15 Jul 2026 08:30:03 +0000
════════════════════════
⌗ Tags: #Malware #AMSI Bypass #Credential Theft #CrySome RAT #phishing attack #Remote Access Trojan #WinDefCtl