~/research
Malware analysis & reverse engineering
Writeups from pulling apart real samples. Everything here is static analysis unless stated otherwise. Samples are linked to public repositories rather than hosted here, and indicators on this site are defanged.
2
writeups
7
samples analysed
19
indicators published
4
submissions
A key hook that throws away every keystroke it captures
A desktop cat that taps along with your typing needs a system-wide keyboard hook to do it, which is indistinguishable from a keylogger until you read the code. Pulling apart Bongo Cat on macOS, and finding a note the developers left for whoever did.
A payload that only decrypts with the file carrying it
Pulling apart a fake game that turned out to be a four-stage loader for Amatera Stealer, and the carrier-keyed encoding that made the final payload impossible to extract without the exact bytes of its own MSBuild project.
Amatera Stealer
community submissions
Shared back
Indicators and samples go to the public trackers so detection vendors and other researchers can act on them, not just sit in a writeup.
7 samples from the RenPy/MSBuild loader chain, linked into a dropped_by / dropping chain
21 indicators — 15 downloader C2 domains, the stage-1 install tracker, and 5 sample hashes — all approved
6 detection rules covering the carrier project, launcher script, dropper and both loader stages
Microsoft Security Intelligence
2026-08Full chain submitted for Defender coverage, with a note not to signature the clean Ren'Py launcher