Public Reports
Operational write-ups from authorized adversary simulation campaigns, including TTP emulation, evasion engineering, and full attack-lifecycle replication in isolated environments.
Unmasking NodeRabbit: A Full Adversary Simulation of an Iranian Fake Recruiter RAT
An Iranian government espionage group poses as recruiters on LinkedIn, using trojanized "technical assessment" coding challenges to deliver a custom Node.js backdoor.
Unmasking NodeRabbit: A Full Adversary Simulation of an Iranian Fake Recruiter RAT
An Iranian government espionage group poses as recruiters on LinkedIn, using trojanized "technical assessment" coding challenges to deliver a custom Node.js backdoor.
New Report — Under Progress
A new adversary simulation write-up is currently under review and will be published here soon.
Unmasking Gentlemen Ransomware: A Full Adversary Simulation (EtherRAT)
Ransomware operations have evolved far beyond simple file encryption.