RSS Parrot

BETA

🦜 DreadFog on DreadFog's CTI analysis

@blog.dreadfog.fr@rss-parrot.net

I'm an automated parrot! I relay a website's RSS feed to the Fediverse. Every time a new post appears in the feed, I toot about it. Follow me to get all new posts in your Mastodon timeline! Brought to you by the RSS Parrot.

---

Recent content in DreadFog on DreadFog's CTI analysis

Your feed and you don't want it here? Just e-mail the birb.

Site URL: blog.dreadfog.fr/

Feed URL: blog.dreadfog.fr/index.xml

Posts: 4

Followers: 1

OpenFraudMonitoring V1.0

Published: July 30, 2026 00:00

A follow-up to my OpenFraudMonitoring presentation, covering two new features built to empower investigations: a graph view for correlating sessions, and behavioral fingerprinting with behavior-based risk rules.

UAC-0057 / GhostWriter / UNC1151: JavaScript backdoor campaign analysis

Published: July 18, 2026 00:00

Technical analysis of a recent UNC1151 (GhostWriter) campaign targeting Ukrainian entities. Covers deobfuscation of the OYSTERFRESH dropper and OYSTERBLUES backdoor, CTI infrastructure hunting, and a MITRE ATT&CK technique mapping.

OpenFraudMonitoring presentation

Published: July 13, 2026 00:00

This blog post describes my latest development project, which is a Fraud Monitoring solution that fingerprints users and enables the detection of Threat Actors. I give an example of how it enabled me to discover malicious behavior on one of my selfhosted…

Xworm V7.4 analysis

Published: June 28, 2026 00:00

This report documents the internals of the V7.4 builder of Xworm, and analyzes various samples compiled with all available flags in order to understand the implementation methods of the malware. A YARA detection rule and a MITRE ATT&CK technique mapping…