OpenFraudMonitoring V1.0
https://blog.dreadfog.fr/posts/tlpclear_20260730_ofm_v1/
Published: July 30, 2026 00:00
A follow-up to my OpenFraudMonitoring presentation, covering two new features built to empower investigations: a graph view for correlating sessions, and behavioral fingerprinting with behavior-based risk rules.
UAC-0057 / GhostWriter / UNC1151: JavaScript backdoor campaign analysis
https://blog.dreadfog.fr/posts/tlpclear_20260719_unc1151_belarus/
Published: July 18, 2026 00:00
Technical analysis of a recent UNC1151 (GhostWriter) campaign targeting Ukrainian entities. Covers deobfuscation of the OYSTERFRESH dropper and OYSTERBLUES backdoor, CTI infrastructure hunting, and a MITRE ATT&CK technique mapping.
OpenFraudMonitoring presentation
https://blog.dreadfog.fr/posts/tlpclear_20260713_ofm_presentation/
Published: July 13, 2026 00:00
This blog post describes my latest development project, which is a Fraud Monitoring solution that fingerprints users and enables the detection of Threat Actors. I give an example of how it enabled me to discover malicious behavior on one of my selfhostedā¦
Xworm V7.4 analysis
https://blog.dreadfog.fr/posts/tlpclear_20260628_xworm_v7_4/
Published: June 28, 2026 00:00
This report documents the internals of the V7.4 builder of Xworm, and analyzes various samples compiled with all available flags in order to understand the implementation methods of the malware. A YARA detection rule and a MITRE ATT&CK technique mappingā¦