MalwareAnalysisForHedgehogs, Principal Malware Researcher at GDATA, he/him 🦔🌈🏳️‍⚧️

International
If you have purchased a ThinkNode M9 LoRA device from @Elecrow1/@ELECROW_JP, be aware the internally-mounted MicroSD card is infected: elecrow.com/Thinknode-M9-Sec…
1
1
5
670
🦔 📹 New Video: Hooking V8 JavaScript ➡️ compiled V8 ➡️ we write a reusable hook script ➡️ we overcome basic anti-hooking #MalwareAnalysisForHedgehogs #V8 #JavaScript piped.video/watch?v=Y8_AScwa…
1
11
53
8,226
Karsten Hahn retweeted
We are pleased to release tmp.0ut 5 Volume! Get your viruses, rootkits, strange ELFs, weird machines, tiny files, cool art, and phresh beats here!! tmpout.sh/5/
21
329
1,188
84,462
Karsten Hahn retweeted
When RE’ing #malware with LLMs, have the LLM also write helper scripts (string/payload decrypters and config extractors) and run these manually on the malware binaries. These make it much easier to validate the LLM's RE quickly and can help expose hallucinations.
4
11
71
4,924
Blog: "Bad advice and myths around malware prevention" If you ever heard or said "visiting websites can't infect you", "PDFs aren't malicious" or "exploits are rare and always targeted" this article might be for you. blog.gdatasoftware.com/2026/… #GDATATechBlog #GDATA
12
34
2,558
New video: Compiled V8 JavaScript for reversers 🎥 ➡️ V8 compilation pipeline ➡️ bytecode caching ➡️ how bytenode abuses caching for protection piped.video/watch?v=YSSCMSMc… #MalwareAnalysisForHedgehogs #JavaScript #V8
1
19
66
5,927
I asked a clanker to make me a prompt that I can use to generate images of malware, like literal pictures that represent malware such as the ones used in samplepedia, not PE images. I got a warning for cyber abuse with threats to shut down my account o.O
8
1
28
4,237
I published an API tracer for kernel mode drivers using speakeasy emulation AI notice: It's vibe-coded. I manually analyzed ~20 drivers to verify and improve the output and tested with a corpus of ~100 drivers. github.com/struppigel/hedgeh…
1
25
82
10,961
New trainings sample on samplepedia Backdoor, obfuscated Python bytecode. 0/60 on Virustotal, which means it's still fresh. virustotal.com/gui/file/4ada… samplepedia.cc/sample/4ada60…
8
39
1,970
I submitted a new sample to samplepedia.cc PoisonX rootkit. Video solution follows the next days. samplepedia.cc/sample/db5d28…
1
13
61
5,785
This seems to be a prevalent issue now: People vibe code security applications and the LLM generates real malware for testing. The generated test files rely on real threat actor infrastructure to download or exfiltrate. hxxps://github.com/DataDog/guarddog/blob/main/tests
2
16
50
7,605
This one was a similar case
Look like the dev told an LLM to generate test files for a Shai Hulud detection app. The LLM complied and generated malicious test files. github.com/Cobenian/shai-hul…
1
4
2,804