<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Cyberwox Unplugged: Labs]]></title><description><![CDATA[Practical demonstrations & technical deep dives.]]></description><link>https://www.cyberwoxunplugged.com/s/labs</link><image><url>https://substackcdn.com/image/fetch/$s_!pA5b!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b1ed158-420f-4ae6-9aaa-adc23c31da06_1280x1280.png</url><title>Cyberwox Unplugged: Labs</title><link>https://www.cyberwoxunplugged.com/s/labs</link></image><generator>Substack</generator><lastBuildDate>Thu, 14 May 2026 00:25:37 GMT</lastBuildDate><atom:link href="https://www.cyberwoxunplugged.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Dayspring Johnson]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[cyberwox@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[cyberwox@substack.com]]></itunes:email><itunes:name><![CDATA[Day Johnson]]></itunes:name></itunes:owner><itunes:author><![CDATA[Day Johnson]]></itunes:author><googleplay:owner><![CDATA[cyberwox@substack.com]]></googleplay:owner><googleplay:email><![CDATA[cyberwox@substack.com]]></googleplay:email><googleplay:author><![CDATA[Day Johnson]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Threat Intelligence Case Study: Dissecting a Multi-Stage Phishing Campaign Against YouTube Creators]]></title><description><![CDATA[They Tried to Hack Me With an &#8216;Undetected&#8217; Malware Loader using Google Drive, Cloudflare, and LOLBins.]]></description><link>https://www.cyberwoxunplugged.com/p/threat-intelligence-case-study-dissecting</link><guid isPermaLink="false">https://www.cyberwoxunplugged.com/p/threat-intelligence-case-study-dissecting</guid><dc:creator><![CDATA[Day Johnson]]></dc:creator><pubDate>Tue, 02 Sep 2025 12:00:37 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/b414ad82-f7b4-41d4-b73c-fadc5df1457a_1280x720.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Phishing has been around since the dawn of email, but it hasn&#8217;t stayed the same.</p><p>What once appeared as clumsy scams with broken English and shady attachments has evolved into sophisticated, multi-layered attacks. Modern attacker campaigns not only deceive users but also utilize legitimate cloud services and Windows tools to blend into regular activity seamlessly.</p><p>This analysis covers a recent phishing attack that targeted me personally as a YouTube creator. On the surface, it appeared to be just another &#8220;appeal your ban&#8221; email. But once analyzed, it unraveled into a sophisticated malware chain that used <strong>Google Drive for delivery</strong>, <strong>Cloudflare for hosting</strong>, and <strong>Microsoft binaries like </strong><code>mshta.exe</code><strong> and Excel</strong> as the actual malware delivery mechanism.</p><blockquote><p><strong>One important note</strong>: I learned much of this&nbsp;<em>in real time</em>. I haven&#8217;t worked in a purely Windows environment in a few years, so a lot of this was deducing and making inferences based on past knowledge, some training I&#8217;ve taken, and pure intuition.</p></blockquote><p>During my investigation, I didn&#8217;t start with a pre-written script or specific expectations. Instead, I learned each step in real-time, shifting from VirusTotal to ANY.RUN, dissecting a VBScript, and asking more questions as new behaviors appeared. </p><p>This approach makes this case worth sharing, as it involved not just analysis but a<strong>ctive learning in practice</strong>.</p><p>The goal here isn&#8217;t just to show <em>what happened</em>, but also <em>why it matters</em>. I&#8217;ll break down the campaign stage by stage, explain the attacker&#8217;s logic, and highlight what defenders can learn &#8212; whether you&#8217;re just starting out or already working in incident response.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberwoxunplugged.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberwoxunplugged.com/subscribe?"><span>Subscribe now</span></a></p><div class="pullquote"><h3><strong>&#127909; Extended Video Analysis</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!UN9D!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a2b1e25-26b6-4c87-9b67-441b54a8a1b4_2500x626.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!UN9D!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a2b1e25-26b6-4c87-9b67-441b54a8a1b4_2500x626.png 424w, https://substackcdn.com/image/fetch/$s_!UN9D!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a2b1e25-26b6-4c87-9b67-441b54a8a1b4_2500x626.png 848w, https://substackcdn.com/image/fetch/$s_!UN9D!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a2b1e25-26b6-4c87-9b67-441b54a8a1b4_2500x626.png 1272w, https://substackcdn.com/image/fetch/$s_!UN9D!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a2b1e25-26b6-4c87-9b67-441b54a8a1b4_2500x626.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!UN9D!,w_2400,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a2b1e25-26b6-4c87-9b67-441b54a8a1b4_2500x626.png" width="330" height="82.632" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3a2b1e25-26b6-4c87-9b67-441b54a8a1b4_2500x626.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;large&quot;,&quot;height&quot;:626,&quot;width&quot;:2500,&quot;resizeWidth&quot;:330,&quot;bytes&quot;:143194,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cyberwoxunplugged.com/i/172138516?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6caf0ef3-fc50-4c7a-bae0-ca03b365df52_2500x2500.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:&quot;center&quot;,&quot;offset&quot;:false}" class="sizing-large" alt="" srcset="https://substackcdn.com/image/fetch/$s_!UN9D!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a2b1e25-26b6-4c87-9b67-441b54a8a1b4_2500x626.png 424w, https://substackcdn.com/image/fetch/$s_!UN9D!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a2b1e25-26b6-4c87-9b67-441b54a8a1b4_2500x626.png 848w, https://substackcdn.com/image/fetch/$s_!UN9D!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a2b1e25-26b6-4c87-9b67-441b54a8a1b4_2500x626.png 1272w, https://substackcdn.com/image/fetch/$s_!UN9D!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a2b1e25-26b6-4c87-9b67-441b54a8a1b4_2500x626.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p>For readers who want to see this campaign in action, I&#8217;ve published a <strong>30-minute video analysis</strong> that walks through the complete sandbox detonation, script deobfuscation, and reflective loader behavior.</p><p>This video is available <strong>exclusively to Cyberwox Syndicate members on YouTube</strong>, along with a library of other technical breakdowns covering Detection Engineering, Threat Hunting scenarios, Incident Response case studies, Career Advice, Python Coding &amp; AI.</p><p><strong><a href="https://youtu.be/GlDCDxNOT1c">&#128204; </a></strong><em><strong><a href="https://youtu.be/GlDCDxNOT1c">Learn more about the Syndicate and gain access here</a>.</strong></em></p></div><h1>Analysis</h1><h2>Phase 1: Initial Access (The Phish)</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZKUg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa504f9e7-8120-4255-8e92-be6b13c353c1_1498x526.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZKUg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa504f9e7-8120-4255-8e92-be6b13c353c1_1498x526.png 424w, https://substackcdn.com/image/fetch/$s_!ZKUg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa504f9e7-8120-4255-8e92-be6b13c353c1_1498x526.png 848w, https://substackcdn.com/image/fetch/$s_!ZKUg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa504f9e7-8120-4255-8e92-be6b13c353c1_1498x526.png 1272w, https://substackcdn.com/image/fetch/$s_!ZKUg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa504f9e7-8120-4255-8e92-be6b13c353c1_1498x526.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZKUg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa504f9e7-8120-4255-8e92-be6b13c353c1_1498x526.png" width="1456" height="511" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a504f9e7-8120-4255-8e92-be6b13c353c1_1498x526.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:511,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:125409,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cyberwoxunplugged.com/i/172138516?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa504f9e7-8120-4255-8e92-be6b13c353c1_1498x526.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ZKUg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa504f9e7-8120-4255-8e92-be6b13c353c1_1498x526.png 424w, https://substackcdn.com/image/fetch/$s_!ZKUg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa504f9e7-8120-4255-8e92-be6b13c353c1_1498x526.png 848w, https://substackcdn.com/image/fetch/$s_!ZKUg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa504f9e7-8120-4255-8e92-be6b13c353c1_1498x526.png 1272w, https://substackcdn.com/image/fetch/$s_!ZKUg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa504f9e7-8120-4255-8e92-be6b13c353c1_1498x526.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong><a href="https://attack.mitre.org/tactics/TA0001/">Source</a>: </strong>TA0001</p><p>The email appeared deceptively routine: a&nbsp;<strong>Google Drive share</strong>&nbsp;notification informing me that my channel was at risk of being banned unless I filed an &#8220;appeal.&#8221;</p><p>Historically, phishing emails attached malicious Office documents or zipped EXEs. </p><p>In recent years, defenders have become more resilient against those vectors. As a result, attackers have shifted to:</p><ul><li><p><strong>Cloud file-sharing abuse</strong> (Google Drive, Dropbox, OneDrive) to bypass filters.</p></li><li><p><strong>Impersonation of high-value brands</strong> (YouTube, PayPal, Microsoft).</p></li><li><p><strong>Social urgency</strong>: &#8220;Act now, or lose access.&#8221;</p></li></ul><p>&#128248; <em>[Screenshot: phishing email / Google Drive link]</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Ch2s!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F720c7ac8-237d-4137-8d5f-67625051cc52_2862x1312.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Ch2s!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F720c7ac8-237d-4137-8d5f-67625051cc52_2862x1312.png 424w, https://substackcdn.com/image/fetch/$s_!Ch2s!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F720c7ac8-237d-4137-8d5f-67625051cc52_2862x1312.png 848w, https://substackcdn.com/image/fetch/$s_!Ch2s!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F720c7ac8-237d-4137-8d5f-67625051cc52_2862x1312.png 1272w, https://substackcdn.com/image/fetch/$s_!Ch2s!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F720c7ac8-237d-4137-8d5f-67625051cc52_2862x1312.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Ch2s!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F720c7ac8-237d-4137-8d5f-67625051cc52_2862x1312.png" width="1456" height="667" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/720c7ac8-237d-4137-8d5f-67625051cc52_2862x1312.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:667,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:401815,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cyberwoxunplugged.com/i/172138516?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F720c7ac8-237d-4137-8d5f-67625051cc52_2862x1312.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Ch2s!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F720c7ac8-237d-4137-8d5f-67625051cc52_2862x1312.png 424w, https://substackcdn.com/image/fetch/$s_!Ch2s!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F720c7ac8-237d-4137-8d5f-67625051cc52_2862x1312.png 848w, https://substackcdn.com/image/fetch/$s_!Ch2s!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F720c7ac8-237d-4137-8d5f-67625051cc52_2862x1312.png 1272w, https://substackcdn.com/image/fetch/$s_!Ch2s!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F720c7ac8-237d-4137-8d5f-67625051cc52_2862x1312.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>&#128248; <em>[Screenshot: phishing email / Vimeo too]</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QuZg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9253b03-ba95-4b47-8a68-8eeea2639f60_2360x1468.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QuZg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9253b03-ba95-4b47-8a68-8eeea2639f60_2360x1468.png 424w, https://substackcdn.com/image/fetch/$s_!QuZg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9253b03-ba95-4b47-8a68-8eeea2639f60_2360x1468.png 848w, https://substackcdn.com/image/fetch/$s_!QuZg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9253b03-ba95-4b47-8a68-8eeea2639f60_2360x1468.png 1272w, https://substackcdn.com/image/fetch/$s_!QuZg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9253b03-ba95-4b47-8a68-8eeea2639f60_2360x1468.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QuZg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9253b03-ba95-4b47-8a68-8eeea2639f60_2360x1468.png" width="1456" height="906" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e9253b03-ba95-4b47-8a68-8eeea2639f60_2360x1468.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:906,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:403850,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cyberwoxunplugged.com/i/172138516?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9253b03-ba95-4b47-8a68-8eeea2639f60_2360x1468.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!QuZg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9253b03-ba95-4b47-8a68-8eeea2639f60_2360x1468.png 424w, https://substackcdn.com/image/fetch/$s_!QuZg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9253b03-ba95-4b47-8a68-8eeea2639f60_2360x1468.png 848w, https://substackcdn.com/image/fetch/$s_!QuZg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9253b03-ba95-4b47-8a68-8eeea2639f60_2360x1468.png 1272w, https://substackcdn.com/image/fetch/$s_!QuZg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9253b03-ba95-4b47-8a68-8eeea2639f60_2360x1468.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This was clearly not a <strong>handcrafted spearphish</strong>. </p><p>It appeared to be a campaign, hitting multiple inboxes simultaneously (redacted) with just enough polish to deceive distracted users.</p><div><hr></div><h2>Phase 2: The Fake Appeal Site &amp; Clipboard Hijacking</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7EyH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff577a58a-f375-477e-a467-c7df01ecfd35_1480x554.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7EyH!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff577a58a-f375-477e-a467-c7df01ecfd35_1480x554.png 424w, https://substackcdn.com/image/fetch/$s_!7EyH!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff577a58a-f375-477e-a467-c7df01ecfd35_1480x554.png 848w, https://substackcdn.com/image/fetch/$s_!7EyH!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff577a58a-f375-477e-a467-c7df01ecfd35_1480x554.png 1272w, https://substackcdn.com/image/fetch/$s_!7EyH!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff577a58a-f375-477e-a467-c7df01ecfd35_1480x554.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7EyH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff577a58a-f375-477e-a467-c7df01ecfd35_1480x554.png" width="1456" height="545" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f577a58a-f375-477e-a467-c7df01ecfd35_1480x554.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:545,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:152205,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cyberwoxunplugged.com/i/172138516?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff577a58a-f375-477e-a467-c7df01ecfd35_1480x554.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!7EyH!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff577a58a-f375-477e-a467-c7df01ecfd35_1480x554.png 424w, https://substackcdn.com/image/fetch/$s_!7EyH!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff577a58a-f375-477e-a467-c7df01ecfd35_1480x554.png 848w, https://substackcdn.com/image/fetch/$s_!7EyH!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff577a58a-f375-477e-a467-c7df01ecfd35_1480x554.png 1272w, https://substackcdn.com/image/fetch/$s_!7EyH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff577a58a-f375-477e-a467-c7df01ecfd35_1480x554.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong><a href="https://attack.mitre.org/techniques/T1566/002/">Source</a>: </strong>T1566.002</p><p>Clicking through the initial link <code>policy[.]video</code> led to <code>youtube.strike.alert[.]org</code> - a fake &#8220;YouTube Appeal Center.&#8221; </p><p>The page was convincing enough to mimic YouTube&#8217;s workflows.</p><p>&#128248; <em>[Screenshot: fake appeal page]</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Yfvg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e44e0d7-472a-406f-ac30-9391aee228fd_2158x1212.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Yfvg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e44e0d7-472a-406f-ac30-9391aee228fd_2158x1212.png 424w, https://substackcdn.com/image/fetch/$s_!Yfvg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e44e0d7-472a-406f-ac30-9391aee228fd_2158x1212.png 848w, https://substackcdn.com/image/fetch/$s_!Yfvg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e44e0d7-472a-406f-ac30-9391aee228fd_2158x1212.png 1272w, https://substackcdn.com/image/fetch/$s_!Yfvg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e44e0d7-472a-406f-ac30-9391aee228fd_2158x1212.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Yfvg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e44e0d7-472a-406f-ac30-9391aee228fd_2158x1212.png" width="1456" height="818" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1e44e0d7-472a-406f-ac30-9391aee228fd_2158x1212.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:818,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:711653,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cyberwoxunplugged.com/i/172138516?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e44e0d7-472a-406f-ac30-9391aee228fd_2158x1212.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Yfvg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e44e0d7-472a-406f-ac30-9391aee228fd_2158x1212.png 424w, https://substackcdn.com/image/fetch/$s_!Yfvg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e44e0d7-472a-406f-ac30-9391aee228fd_2158x1212.png 848w, https://substackcdn.com/image/fetch/$s_!Yfvg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e44e0d7-472a-406f-ac30-9391aee228fd_2158x1212.png 1272w, https://substackcdn.com/image/fetch/$s_!Yfvg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e44e0d7-472a-406f-ac30-9391aee228fd_2158x1212.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>&#128248; <em>[Screenshot: me posing as Mr. Beast]</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2FUG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8b30b7a-b16c-4bf4-944b-f611bee47da8_2980x1478.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2FUG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8b30b7a-b16c-4bf4-944b-f611bee47da8_2980x1478.png 424w, https://substackcdn.com/image/fetch/$s_!2FUG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8b30b7a-b16c-4bf4-944b-f611bee47da8_2980x1478.png 848w, https://substackcdn.com/image/fetch/$s_!2FUG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8b30b7a-b16c-4bf4-944b-f611bee47da8_2980x1478.png 1272w, https://substackcdn.com/image/fetch/$s_!2FUG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8b30b7a-b16c-4bf4-944b-f611bee47da8_2980x1478.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2FUG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8b30b7a-b16c-4bf4-944b-f611bee47da8_2980x1478.png" width="1456" height="722" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e8b30b7a-b16c-4bf4-944b-f611bee47da8_2980x1478.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:722,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:871785,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cyberwoxunplugged.com/i/172138516?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8b30b7a-b16c-4bf4-944b-f611bee47da8_2980x1478.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!2FUG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8b30b7a-b16c-4bf4-944b-f611bee47da8_2980x1478.png 424w, https://substackcdn.com/image/fetch/$s_!2FUG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8b30b7a-b16c-4bf4-944b-f611bee47da8_2980x1478.png 848w, https://substackcdn.com/image/fetch/$s_!2FUG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8b30b7a-b16c-4bf4-944b-f611bee47da8_2980x1478.png 1272w, https://substackcdn.com/image/fetch/$s_!2FUG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8b30b7a-b16c-4bf4-944b-f611bee47da8_2980x1478.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Here&#8217;s the clever part: it didn&#8217;t even ask me to log in to my channel afterwards. </p><p>Instead, it auto-populated my <strong>clipboard</strong> with a command and told me to complete the appeal process by executing: <strong>Win+R &#8594; Paste &#8594; Enter.</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6BRL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ed13493-f524-4085-9175-91c79a825fc5_2980x1660.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6BRL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ed13493-f524-4085-9175-91c79a825fc5_2980x1660.png 424w, https://substackcdn.com/image/fetch/$s_!6BRL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ed13493-f524-4085-9175-91c79a825fc5_2980x1660.png 848w, https://substackcdn.com/image/fetch/$s_!6BRL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ed13493-f524-4085-9175-91c79a825fc5_2980x1660.png 1272w, https://substackcdn.com/image/fetch/$s_!6BRL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ed13493-f524-4085-9175-91c79a825fc5_2980x1660.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6BRL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ed13493-f524-4085-9175-91c79a825fc5_2980x1660.png" width="1456" height="811" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8ed13493-f524-4085-9175-91c79a825fc5_2980x1660.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:811,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:766871,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cyberwoxunplugged.com/i/172138516?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ed13493-f524-4085-9175-91c79a825fc5_2980x1660.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6BRL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ed13493-f524-4085-9175-91c79a825fc5_2980x1660.png 424w, https://substackcdn.com/image/fetch/$s_!6BRL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ed13493-f524-4085-9175-91c79a825fc5_2980x1660.png 848w, https://substackcdn.com/image/fetch/$s_!6BRL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ed13493-f524-4085-9175-91c79a825fc5_2980x1660.png 1272w, https://substackcdn.com/image/fetch/$s_!6BRL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ed13493-f524-4085-9175-91c79a825fc5_2980x1660.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>This represents a notable evolution in attacker techniques.</em> </p><p>Historically, attackers tricked users into downloading EXEs. Today, they <strong>social-engineer users into running native binaries</strong> already on their system. </p><p>This helps them to &#8220;Live Off The Land&#8221;.</p><blockquote><p>Also, clipboard hijacking is an under-discussed topic in phishing defense. Most training advises &#8220;don&#8217;t click links&#8221; but rarely emphasizes &#8220;be cautious about what you paste.&#8221;</p></blockquote><p>&#128248; <em>[Screenshot: Win+R instructions / pasted clipboard injection]</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!e2Mj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc417053-7f99-449a-a844-58c9be04d456_3016x1686.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!e2Mj!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc417053-7f99-449a-a844-58c9be04d456_3016x1686.png 424w, https://substackcdn.com/image/fetch/$s_!e2Mj!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc417053-7f99-449a-a844-58c9be04d456_3016x1686.png 848w, https://substackcdn.com/image/fetch/$s_!e2Mj!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc417053-7f99-449a-a844-58c9be04d456_3016x1686.png 1272w, https://substackcdn.com/image/fetch/$s_!e2Mj!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc417053-7f99-449a-a844-58c9be04d456_3016x1686.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!e2Mj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc417053-7f99-449a-a844-58c9be04d456_3016x1686.png" width="1456" height="814" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dc417053-7f99-449a-a844-58c9be04d456_3016x1686.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:814,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:973078,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cyberwoxunplugged.com/i/172138516?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc417053-7f99-449a-a844-58c9be04d456_3016x1686.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!e2Mj!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc417053-7f99-449a-a844-58c9be04d456_3016x1686.png 424w, https://substackcdn.com/image/fetch/$s_!e2Mj!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc417053-7f99-449a-a844-58c9be04d456_3016x1686.png 848w, https://substackcdn.com/image/fetch/$s_!e2Mj!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc417053-7f99-449a-a844-58c9be04d456_3016x1686.png 1272w, https://substackcdn.com/image/fetch/$s_!e2Mj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc417053-7f99-449a-a844-58c9be04d456_3016x1686.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><blockquote><p><code>C:\WINDOWS\system32\mshta.exe hxxps://policy-agreement[.]com/DMCA_Notice.hta</code></p></blockquote><p>The paste leveraged <code>mshta.exe</code>, a signed Microsoft binary capable of fetching and executing remote HTA (HTML Application) files. </p><div><hr></div><h2>Tooling Transparency (Not Sponsored)</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QHnK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaf355a3-b7d7-45c4-8613-5c0bd4277ffa_1600x500.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QHnK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaf355a3-b7d7-45c4-8613-5c0bd4277ffa_1600x500.png 424w, https://substackcdn.com/image/fetch/$s_!QHnK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaf355a3-b7d7-45c4-8613-5c0bd4277ffa_1600x500.png 848w, https://substackcdn.com/image/fetch/$s_!QHnK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaf355a3-b7d7-45c4-8613-5c0bd4277ffa_1600x500.png 1272w, https://substackcdn.com/image/fetch/$s_!QHnK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaf355a3-b7d7-45c4-8613-5c0bd4277ffa_1600x500.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QHnK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaf355a3-b7d7-45c4-8613-5c0bd4277ffa_1600x500.png" width="1456" height="455" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/caf355a3-b7d7-45c4-8613-5c0bd4277ffa_1600x500.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:455,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!QHnK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaf355a3-b7d7-45c4-8613-5c0bd4277ffa_1600x500.png 424w, https://substackcdn.com/image/fetch/$s_!QHnK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaf355a3-b7d7-45c4-8613-5c0bd4277ffa_1600x500.png 848w, https://substackcdn.com/image/fetch/$s_!QHnK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaf355a3-b7d7-45c4-8613-5c0bd4277ffa_1600x500.png 1272w, https://substackcdn.com/image/fetch/$s_!QHnK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaf355a3-b7d7-45c4-8613-5c0bd4277ffa_1600x500.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This analysis was powered heavily by <strong>ANY.RUN&#8217;s</strong> interactive malware sandbox, which made it possible to observe each stage of the phishing chain in real time.</p><p>This issue is <strong>not sponsored by ANY.RUN</strong>, but I want to be transparent in crediting the platform because it played a central role in uncovering everything laid out here.</p><p>For defenders who want to go deeper than running single samples, ANY.RUN recently rolled out <strong>Threat Intelligence Feeds</strong> that aggregate behavioral data across thousands of detonations. This expands visibility from &#8220;what happened in my one sandbox run&#8221; to &#8220;what&#8217;s happening across the wild right now.&#8221;</p><blockquote><p><a href="https://bit.ly/cwx-anyrun-threat-intelligence-lookup">&#128204; </a><em><a href="https://bit.ly/cwx-anyrun-threat-intelligence-lookup">If you&#8217;re serious about threat intelligence, threat hunting or detection engineering, it&#8217;s worth exploring.</a></em></p></blockquote><p>You can also find the ANY.RUN report for this investigation <a href="https://any.run/report/743ef8592f3778f2ec8eeb62862cf7082861cf38f95fc7255d1fbcc944c50a10/8ed30515-955e-48fe-92a7-a6f4b119aa4e?_gl=1*jkrgb5*_gcl_au*MjEzMTU5NTA2NC4xNzU0OTE3NDg0*FPAU*MjEzMTU5NTA2NC4xNzU0OTE3NDg0*_ga*NTU1Mzc2NDEuMTc1NDc5NjcxNw..*_ga_53KB74YDZR*czE3NTYzNTQ4MTkkbzIyJGcwJHQxNzU2MzU0ODE5JGo2MCRsMCRoODcwNTcxNTc1">here</a>.</p><div><hr></div><h2>Phase 3: MSHTA &amp; Living Off the Land</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!fGZ-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17ec4a88-4a0c-451e-a47c-67f52b8ec91f_1478x1038.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!fGZ-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17ec4a88-4a0c-451e-a47c-67f52b8ec91f_1478x1038.png 424w, https://substackcdn.com/image/fetch/$s_!fGZ-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17ec4a88-4a0c-451e-a47c-67f52b8ec91f_1478x1038.png 848w, https://substackcdn.com/image/fetch/$s_!fGZ-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17ec4a88-4a0c-451e-a47c-67f52b8ec91f_1478x1038.png 1272w, https://substackcdn.com/image/fetch/$s_!fGZ-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17ec4a88-4a0c-451e-a47c-67f52b8ec91f_1478x1038.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!fGZ-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17ec4a88-4a0c-451e-a47c-67f52b8ec91f_1478x1038.png" width="1456" height="1023" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/17ec4a88-4a0c-451e-a47c-67f52b8ec91f_1478x1038.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1023,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:278212,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cyberwoxunplugged.com/i/172138516?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17ec4a88-4a0c-451e-a47c-67f52b8ec91f_1478x1038.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!fGZ-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17ec4a88-4a0c-451e-a47c-67f52b8ec91f_1478x1038.png 424w, https://substackcdn.com/image/fetch/$s_!fGZ-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17ec4a88-4a0c-451e-a47c-67f52b8ec91f_1478x1038.png 848w, https://substackcdn.com/image/fetch/$s_!fGZ-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17ec4a88-4a0c-451e-a47c-67f52b8ec91f_1478x1038.png 1272w, https://substackcdn.com/image/fetch/$s_!fGZ-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17ec4a88-4a0c-451e-a47c-67f52b8ec91f_1478x1038.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong><a href="https://attack.mitre.org/techniques/T1218/005/">Source</a>:</strong> T1218.005 </p><p>MSHTA isn&#8217;t malware. It&#8217;s actually part of Windows, specifically a <strong>Living-Off-the-Land (LOLBIN) binary</strong>. </p><p>Attackers abuse it because:</p><ul><li><p>It&#8217;s trusted, signed by Microsoft.</p></li><li><p>It bypasses application whitelisting in many enterprises.</p></li><li><p>It supports remote execution of HTAs with full scripting capabilities (CRAZY WORK).</p></li></ul><p>&#128248; <em>[Screenshot: MSHTA Madness during analysis]</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5E3O!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9144db08-a5d9-4b10-8eca-5f7f3ae17042_2252x1638.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5E3O!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9144db08-a5d9-4b10-8eca-5f7f3ae17042_2252x1638.png 424w, https://substackcdn.com/image/fetch/$s_!5E3O!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9144db08-a5d9-4b10-8eca-5f7f3ae17042_2252x1638.png 848w, https://substackcdn.com/image/fetch/$s_!5E3O!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9144db08-a5d9-4b10-8eca-5f7f3ae17042_2252x1638.png 1272w, https://substackcdn.com/image/fetch/$s_!5E3O!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9144db08-a5d9-4b10-8eca-5f7f3ae17042_2252x1638.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5E3O!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9144db08-a5d9-4b10-8eca-5f7f3ae17042_2252x1638.png" width="1456" height="1059" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9144db08-a5d9-4b10-8eca-5f7f3ae17042_2252x1638.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1059,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:678373,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cyberwoxunplugged.com/i/172138516?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9144db08-a5d9-4b10-8eca-5f7f3ae17042_2252x1638.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!5E3O!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9144db08-a5d9-4b10-8eca-5f7f3ae17042_2252x1638.png 424w, https://substackcdn.com/image/fetch/$s_!5E3O!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9144db08-a5d9-4b10-8eca-5f7f3ae17042_2252x1638.png 848w, https://substackcdn.com/image/fetch/$s_!5E3O!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9144db08-a5d9-4b10-8eca-5f7f3ae17042_2252x1638.png 1272w, https://substackcdn.com/image/fetch/$s_!5E3O!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9144db08-a5d9-4b10-8eca-5f7f3ae17042_2252x1638.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Historically, MSHTA abuse goes back to at least 2017, when APT32 and FIN7 used it in phishing campaigns (maybe one of them is targeting influencers now). </p><p>In this case, <code>mshta.exe</code> was instructed to download and run an HTA file called <code>DMCA_notice.hta</code>from a remote server. </p><p>That file contained the next stage: <strong>VBScript code</strong>.</p><p><a href="https://redcanary.com/threat-detection-report/techniques/mshta/">Light reading on MSHTA from Red Canary</a>.</p><p><a href="https://lolbas-project.github.io/lolbas/Binaries/Mshta/">MSHTA LOLBIN Profile</a>.</p><div><hr></div><h2>Phase 4: The HTA Loader (VBScript &#8594; Excel)</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!aubV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7556b11-2c87-486d-a75f-df87ff436047_1786x988.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!aubV!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7556b11-2c87-486d-a75f-df87ff436047_1786x988.png 424w, https://substackcdn.com/image/fetch/$s_!aubV!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7556b11-2c87-486d-a75f-df87ff436047_1786x988.png 848w, https://substackcdn.com/image/fetch/$s_!aubV!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7556b11-2c87-486d-a75f-df87ff436047_1786x988.png 1272w, https://substackcdn.com/image/fetch/$s_!aubV!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7556b11-2c87-486d-a75f-df87ff436047_1786x988.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!aubV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7556b11-2c87-486d-a75f-df87ff436047_1786x988.png" width="1456" height="805" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e7556b11-2c87-486d-a75f-df87ff436047_1786x988.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:805,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:262979,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cyberwoxunplugged.com/i/172138516?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7556b11-2c87-486d-a75f-df87ff436047_1786x988.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!aubV!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7556b11-2c87-486d-a75f-df87ff436047_1786x988.png 424w, https://substackcdn.com/image/fetch/$s_!aubV!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7556b11-2c87-486d-a75f-df87ff436047_1786x988.png 848w, https://substackcdn.com/image/fetch/$s_!aubV!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7556b11-2c87-486d-a75f-df87ff436047_1786x988.png 1272w, https://substackcdn.com/image/fetch/$s_!aubV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7556b11-2c87-486d-a75f-df87ff436047_1786x988.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong><a href="https://attack.mitre.org/techniques/T1218/005/">Source</a>: </strong>T1218.005</p><p>As mentioned previously, the downloaded HTA file contained obfuscated VBScript code. </p><p>This is where we begin to see the <strong>transition from social engineering to execution.</strong></p><blockquote><p>SN: I&#8217;m not all that familiar with VBScript, but I can get by.</p></blockquote><p>The VBScript:</p><ul><li><p>Spawned an <strong>Excel.Application</strong> COM object.</p></li><li><p>Temporarily enabled the registry key <code>AccessVBOM</code> (which governs programmatic access to the VBA project model).</p></li><li><p>Injected a Base64-decoded VBA macro directly into Excel.</p></li><li><p>Wired a <code>Workbook_NewSheet</code> event to ensure execution.</p></li></ul><p>&#128248; <em>[Screenshot: Registry key modification &#8211; AccessVBOM enabled]</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3hta!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef4092bf-c79f-4128-92e6-21ebc913729b_2600x1584.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3hta!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef4092bf-c79f-4128-92e6-21ebc913729b_2600x1584.png 424w, https://substackcdn.com/image/fetch/$s_!3hta!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef4092bf-c79f-4128-92e6-21ebc913729b_2600x1584.png 848w, https://substackcdn.com/image/fetch/$s_!3hta!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef4092bf-c79f-4128-92e6-21ebc913729b_2600x1584.png 1272w, https://substackcdn.com/image/fetch/$s_!3hta!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef4092bf-c79f-4128-92e6-21ebc913729b_2600x1584.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3hta!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef4092bf-c79f-4128-92e6-21ebc913729b_2600x1584.png" width="1456" height="887" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ef4092bf-c79f-4128-92e6-21ebc913729b_2600x1584.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:887,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:441406,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cyberwoxunplugged.com/i/172138516?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef4092bf-c79f-4128-92e6-21ebc913729b_2600x1584.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3hta!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef4092bf-c79f-4128-92e6-21ebc913729b_2600x1584.png 424w, https://substackcdn.com/image/fetch/$s_!3hta!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef4092bf-c79f-4128-92e6-21ebc913729b_2600x1584.png 848w, https://substackcdn.com/image/fetch/$s_!3hta!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef4092bf-c79f-4128-92e6-21ebc913729b_2600x1584.png 1272w, https://substackcdn.com/image/fetch/$s_!3hta!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef4092bf-c79f-4128-92e6-21ebc913729b_2600x1584.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>&#128248; <em>[Screenshot: Subtle string concatenation obfuscation behavior]</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!VCeu!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0208ffc-d627-4023-a75a-906e91618770_2600x1584.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!VCeu!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0208ffc-d627-4023-a75a-906e91618770_2600x1584.png 424w, https://substackcdn.com/image/fetch/$s_!VCeu!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0208ffc-d627-4023-a75a-906e91618770_2600x1584.png 848w, https://substackcdn.com/image/fetch/$s_!VCeu!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0208ffc-d627-4023-a75a-906e91618770_2600x1584.png 1272w, https://substackcdn.com/image/fetch/$s_!VCeu!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0208ffc-d627-4023-a75a-906e91618770_2600x1584.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!VCeu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0208ffc-d627-4023-a75a-906e91618770_2600x1584.png" width="1456" height="887" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b0208ffc-d627-4023-a75a-906e91618770_2600x1584.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:887,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:428284,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cyberwoxunplugged.com/i/172138516?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0208ffc-d627-4023-a75a-906e91618770_2600x1584.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!VCeu!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0208ffc-d627-4023-a75a-906e91618770_2600x1584.png 424w, https://substackcdn.com/image/fetch/$s_!VCeu!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0208ffc-d627-4023-a75a-906e91618770_2600x1584.png 848w, https://substackcdn.com/image/fetch/$s_!VCeu!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0208ffc-d627-4023-a75a-906e91618770_2600x1584.png 1272w, https://substackcdn.com/image/fetch/$s_!VCeu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0208ffc-d627-4023-a75a-906e91618770_2600x1584.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Quick aside, I thought this string concatenation behavior was quite interesting.</p><p>Instead of writing the suspicious string outright (<code>"Excel.Application"</code>), the attacker breaks it into smaller fragments:</p><pre><code><code>tmpString = "Exc"
tmpString = tmpString &amp; "el.App"
tmpString = tmpString &amp; "lication"</code></code></pre><p>Then, at runtime, those fragments are concatenated into the full string:<br><code>Excel.Application</code></p><p>That reconstructed string is then passed into <code>CreateObject()</code> to instantiate Excel via COM automation.</p><p><em>Why would an attack do all this?</em></p><p><strong>Signature Evasion: </strong>Static scanners will often look for explicit strings like <code>"Excel.Application"</code>, <code>"Wscript.Shell"</code>, or <code>"MSXML2.XMLHTTP"</code>. Breaking them up prevents easy pattern-matching.</p><p><strong>Analyst Friction: </strong>For someone casually inspecting the script, it appears more confusing, and you need to reassemble the pieces mentally.</p><p><strong>Commodity Obfuscation: </strong>This technique is cheap and easy to implement. You often see it in phishing droppers, VBA/VBS loaders, and even JavaScript malware.</p><p><strong>Victim Susceptibility</strong>: This technique bypasses the traditional &#8220;open this malicious document&#8221; step, which a suspecting victim will be privy to.</p><p><a href="https://redcanary.com/threat-detection-report/techniques/obfuscated-files-information/#:~:text=String%20concatenation%20is%20another%20common,based%20detective%20and%20preventive%20controls.">Red Canary has a nicely written blog on this behavior</a>.</p><div><hr></div><h2>Phase 5: The VBA Reflective Loader</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!mXUr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd37465f-5e11-47f6-8feb-e9a6135c5980_1506x878.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!mXUr!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd37465f-5e11-47f6-8feb-e9a6135c5980_1506x878.png 424w, https://substackcdn.com/image/fetch/$s_!mXUr!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd37465f-5e11-47f6-8feb-e9a6135c5980_1506x878.png 848w, https://substackcdn.com/image/fetch/$s_!mXUr!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd37465f-5e11-47f6-8feb-e9a6135c5980_1506x878.png 1272w, https://substackcdn.com/image/fetch/$s_!mXUr!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd37465f-5e11-47f6-8feb-e9a6135c5980_1506x878.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!mXUr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd37465f-5e11-47f6-8feb-e9a6135c5980_1506x878.png" width="1456" height="849" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dd37465f-5e11-47f6-8feb-e9a6135c5980_1506x878.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:849,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:278908,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cyberwoxunplugged.com/i/172138516?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd37465f-5e11-47f6-8feb-e9a6135c5980_1506x878.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!mXUr!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd37465f-5e11-47f6-8feb-e9a6135c5980_1506x878.png 424w, https://substackcdn.com/image/fetch/$s_!mXUr!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd37465f-5e11-47f6-8feb-e9a6135c5980_1506x878.png 848w, https://substackcdn.com/image/fetch/$s_!mXUr!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd37465f-5e11-47f6-8feb-e9a6135c5980_1506x878.png 1272w, https://substackcdn.com/image/fetch/$s_!mXUr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd37465f-5e11-47f6-8feb-e9a6135c5980_1506x878.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong><a href="https://attack.mitre.org/techniques/T1620/">Source</a>:</strong> T1620</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0D0U!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ed2e3c7-b98d-4eab-b870-bf87ea1ef754_1506x1008.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0D0U!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ed2e3c7-b98d-4eab-b870-bf87ea1ef754_1506x1008.png 424w, https://substackcdn.com/image/fetch/$s_!0D0U!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ed2e3c7-b98d-4eab-b870-bf87ea1ef754_1506x1008.png 848w, https://substackcdn.com/image/fetch/$s_!0D0U!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ed2e3c7-b98d-4eab-b870-bf87ea1ef754_1506x1008.png 1272w, https://substackcdn.com/image/fetch/$s_!0D0U!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ed2e3c7-b98d-4eab-b870-bf87ea1ef754_1506x1008.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0D0U!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ed2e3c7-b98d-4eab-b870-bf87ea1ef754_1506x1008.png" width="1456" height="975" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7ed2e3c7-b98d-4eab-b870-bf87ea1ef754_1506x1008.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:975,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:345239,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cyberwoxunplugged.com/i/172138516?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ed2e3c7-b98d-4eab-b870-bf87ea1ef754_1506x1008.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!0D0U!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ed2e3c7-b98d-4eab-b870-bf87ea1ef754_1506x1008.png 424w, https://substackcdn.com/image/fetch/$s_!0D0U!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ed2e3c7-b98d-4eab-b870-bf87ea1ef754_1506x1008.png 848w, https://substackcdn.com/image/fetch/$s_!0D0U!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ed2e3c7-b98d-4eab-b870-bf87ea1ef754_1506x1008.png 1272w, https://substackcdn.com/image/fetch/$s_!0D0U!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ed2e3c7-b98d-4eab-b870-bf87ea1ef754_1506x1008.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong><a href="https://attack.mitre.org/techniques/T1027/011/">Source</a>: </strong>T1027.011</p><p>Once injected, the macro acted like a <strong>reflective shellcode loader</strong>. </p><p>Instead of dropping a file to disk, it:</p><ul><li><p>Converted encoded Base64 payload strings back into executable code.</p></li><li><p>Used indirect API calls (<code>DispCallFunc</code>) to resolve Windows functions dynamically, avoiding static detection.</p><ul><li><p><a href="https://learn.microsoft.com/en-us/windows/win32/api/oleauto/nf-oleauto-dispcallfunc">More about DispCallFunc</a>.</p></li></ul></li><li><p>Reserved RWX (Read-Write-Execute) memory (<code>VirtualAlloc</code>), copied shellcode into it (<code>RtlMoveMemory</code>), and executed it with <code>CreateThread</code>.</p><ul><li><p><a href="https://learn.microsoft.com/en-us/windows/win32/api/memoryapi/nf-memoryapi-virtualalloc">More about VirtualAlloc</a>.</p></li><li><p><a href="https://learn.microsoft.com/en-us/windows/win32/devnotes/rtlmovememory">More about RtlMoveMemory</a>.</p></li></ul></li></ul><p>&#128248; <em>[Screenshot: Any.Run view &#8211; Excel.exe outbound connection]</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!LjeU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2455a9dd-544f-4175-98fa-802d7173cd09_2302x1658.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!LjeU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2455a9dd-544f-4175-98fa-802d7173cd09_2302x1658.png 424w, https://substackcdn.com/image/fetch/$s_!LjeU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2455a9dd-544f-4175-98fa-802d7173cd09_2302x1658.png 848w, https://substackcdn.com/image/fetch/$s_!LjeU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2455a9dd-544f-4175-98fa-802d7173cd09_2302x1658.png 1272w, https://substackcdn.com/image/fetch/$s_!LjeU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2455a9dd-544f-4175-98fa-802d7173cd09_2302x1658.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!LjeU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2455a9dd-544f-4175-98fa-802d7173cd09_2302x1658.png" width="1456" height="1049" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2455a9dd-544f-4175-98fa-802d7173cd09_2302x1658.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1049,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:643025,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cyberwoxunplugged.com/i/172138516?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2455a9dd-544f-4175-98fa-802d7173cd09_2302x1658.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!LjeU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2455a9dd-544f-4175-98fa-802d7173cd09_2302x1658.png 424w, https://substackcdn.com/image/fetch/$s_!LjeU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2455a9dd-544f-4175-98fa-802d7173cd09_2302x1658.png 848w, https://substackcdn.com/image/fetch/$s_!LjeU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2455a9dd-544f-4175-98fa-802d7173cd09_2302x1658.png 1272w, https://substackcdn.com/image/fetch/$s_!LjeU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2455a9dd-544f-4175-98fa-802d7173cd09_2302x1658.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This is the same type of technique often employed in advanced malware &amp; C2 frameworks, such as <strong>Cobalt Strike</strong>. </p><p>The difference here is that it was part of a phishing campaign targeting YouTube creators, which illustrates how attacker tradecraft once exclusive to nation-states or red-team operations is now appearing in common campaigns.</p><p>The macro reached out to:</p><ul><li><p><code>hxxps://policy-agreement[.]com/agrees.bin</code> (x86 payload)</p></li><li><p><code>hxxps://policy-agreement[.]com/agreese.bin</code> (x64 payload)</p></li></ul><p>Both were delivered over HTTPS, with certificate errors ignored &#8212; another way of blending into normal traffic.</p><blockquote><p>It&#8217;s crazy that this binary never touched disk. It lived entirely in memory.</p></blockquote><p><a href="https://www.hack-notes.pro/maldev/reflective-loader">Some cool notes on reflective loaders</a>.</p><div><hr></div><h2>Phase 6: Command and Control</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZuEA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b133046-baeb-4b52-9b72-9b8b603d3a0d_1490x686.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZuEA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b133046-baeb-4b52-9b72-9b8b603d3a0d_1490x686.png 424w, https://substackcdn.com/image/fetch/$s_!ZuEA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b133046-baeb-4b52-9b72-9b8b603d3a0d_1490x686.png 848w, https://substackcdn.com/image/fetch/$s_!ZuEA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b133046-baeb-4b52-9b72-9b8b603d3a0d_1490x686.png 1272w, https://substackcdn.com/image/fetch/$s_!ZuEA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b133046-baeb-4b52-9b72-9b8b603d3a0d_1490x686.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZuEA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b133046-baeb-4b52-9b72-9b8b603d3a0d_1490x686.png" width="1456" height="670" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2b133046-baeb-4b52-9b72-9b8b603d3a0d_1490x686.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:670,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:164386,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cyberwoxunplugged.com/i/172138516?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b133046-baeb-4b52-9b72-9b8b603d3a0d_1490x686.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ZuEA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b133046-baeb-4b52-9b72-9b8b603d3a0d_1490x686.png 424w, https://substackcdn.com/image/fetch/$s_!ZuEA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b133046-baeb-4b52-9b72-9b8b603d3a0d_1490x686.png 848w, https://substackcdn.com/image/fetch/$s_!ZuEA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b133046-baeb-4b52-9b72-9b8b603d3a0d_1490x686.png 1272w, https://substackcdn.com/image/fetch/$s_!ZuEA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b133046-baeb-4b52-9b72-9b8b603d3a0d_1490x686.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong><a href="https://attack.mitre.org/tactics/TA0011/">Source</a>: </strong>TA0011<strong> </strong></p><p>Excel itself acted as the beacon, the communication channel.</p><ul><li><p><strong>C2 domain:</strong> <code>policy-agreement[.]com</code></p></li><li><p><strong>Protocol:</strong> HTTPS (but with bad certificates silently bypassed)</p></li><li><p><strong>User-Agent:</strong> An outdated Internet Explorer string (<code>Mozilla/4.0; MSIE 6.0; Windows NT 5.0</code>). This can help evade modern detection rules that expect current browser signatures.</p></li><li><p><strong>Infrastructure:</strong> Cloudflare-protected, backend IP in Amsterdam (RIPE NCC allocation).</p></li></ul><p>&#128248; <em>[Screenshot: Excel.exe using legacy UserAgent]</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!GrvY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c940d40-f2e9-47a3-8e55-4a12172618da_2302x1658.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!GrvY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c940d40-f2e9-47a3-8e55-4a12172618da_2302x1658.png 424w, https://substackcdn.com/image/fetch/$s_!GrvY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c940d40-f2e9-47a3-8e55-4a12172618da_2302x1658.png 848w, https://substackcdn.com/image/fetch/$s_!GrvY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c940d40-f2e9-47a3-8e55-4a12172618da_2302x1658.png 1272w, https://substackcdn.com/image/fetch/$s_!GrvY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c940d40-f2e9-47a3-8e55-4a12172618da_2302x1658.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!GrvY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c940d40-f2e9-47a3-8e55-4a12172618da_2302x1658.png" width="1456" height="1049" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1c940d40-f2e9-47a3-8e55-4a12172618da_2302x1658.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1049,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:623014,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cyberwoxunplugged.com/i/172138516?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c940d40-f2e9-47a3-8e55-4a12172618da_2302x1658.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!GrvY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c940d40-f2e9-47a3-8e55-4a12172618da_2302x1658.png 424w, https://substackcdn.com/image/fetch/$s_!GrvY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c940d40-f2e9-47a3-8e55-4a12172618da_2302x1658.png 848w, https://substackcdn.com/image/fetch/$s_!GrvY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c940d40-f2e9-47a3-8e55-4a12172618da_2302x1658.png 1272w, https://substackcdn.com/image/fetch/$s_!GrvY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c940d40-f2e9-47a3-8e55-4a12172618da_2302x1658.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!iF0v!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba71e4f8-2d28-4fd6-9a78-c966708c46a6_2500x979.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!iF0v!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba71e4f8-2d28-4fd6-9a78-c966708c46a6_2500x979.png 424w, https://substackcdn.com/image/fetch/$s_!iF0v!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba71e4f8-2d28-4fd6-9a78-c966708c46a6_2500x979.png 848w, https://substackcdn.com/image/fetch/$s_!iF0v!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba71e4f8-2d28-4fd6-9a78-c966708c46a6_2500x979.png 1272w, https://substackcdn.com/image/fetch/$s_!iF0v!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba71e4f8-2d28-4fd6-9a78-c966708c46a6_2500x979.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!iF0v!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba71e4f8-2d28-4fd6-9a78-c966708c46a6_2500x979.png" width="1456" height="570" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ba71e4f8-2d28-4fd6-9a78-c966708c46a6_2500x979.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:570,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:188886,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:&quot;&quot;,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cyberwoxunplugged.com/i/159067704?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F913f1923-04a0-4fe6-afb6-5e0fca6d78b1_2500x2500.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!iF0v!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba71e4f8-2d28-4fd6-9a78-c966708c46a6_2500x979.png 424w, https://substackcdn.com/image/fetch/$s_!iF0v!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba71e4f8-2d28-4fd6-9a78-c966708c46a6_2500x979.png 848w, https://substackcdn.com/image/fetch/$s_!iF0v!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba71e4f8-2d28-4fd6-9a78-c966708c46a6_2500x979.png 1272w, https://substackcdn.com/image/fetch/$s_!iF0v!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba71e4f8-2d28-4fd6-9a78-c966708c46a6_2500x979.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Join a vibrant cybersecurity community of over 6,500 people who are constantly engaging in conversations and supporting one another, covering topics from cybersecurity and college to certifications, resume assistance, and various non-professional interests like fitness, finance, anime, and other exciting subjects.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://discord.gg/cyberwoxacademy&quot;,&quot;text&quot;:&quot;Join Us!&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://discord.gg/cyberwoxacademy"><span>Join Us!</span></a></p><div><hr></div><h2>Attribution Notes</h2><p>I am <strong>not assigning this campaign to a named actor</strong>. </p><p>The evidence suggests a&nbsp;<strong>commodity crimeware operation</strong>&nbsp;or an&nbsp;<strong>affiliate-driven ecosystem,</strong> rather than a bespoke, state-sponsored group (bummer).</p><p>Several factors inform this assessment:</p><ul><li><p><strong>Targeting:</strong> &#8220;YouTube appeal&#8221; lures are a well-worn tactic in campaigns designed to hijack creator accounts for monetization (ad fraud, crypto scams, or resale). This is not new at all.</p></li><li><p><strong>Tradecraft reuse:</strong> The clipboard &#8594; Win+R &#8594; <code>mshta.exe</code> pattern, HTA/VBScript loader, and reflective VBA macro are drawn from widely circulated public code. Even the outdated Internet Explorer User-Agent hints at template reuse rather than original development.</p></li><li><p><strong>Infrastructure:</strong> The use of Cloudflare-fronted domains like <code>policy-agreement[.]com</code> with generic naming and shared backend IPs is consistent with low-cost, low-OPSEC phishing kits that frequently rotate their infrastructure.</p></li><li><p><strong>Execution:</strong> While reflective loading and fileless execution look &#8220;advanced,&#8221; these have become standardized in the malware-as-a-service space and don&#8217;t necessarily indicate a high-skill actor.</p></li></ul><p>What&#8217;s missing for higher-confidence attribution are overlaps in infrastructure (domain clusters, cert reuse), payload families, or development artifacts. </p><p>Given the current depth of my analysis, my most accurate framing is <strong>a financially motivated loader campaign leveraging commodity techniques against YouTube creators.</strong></p><div><hr></div><h1>Defense Mechanisms</h1><p>This campaign leaves behind multiple breadcrumbs across host, network, and memory. Below are hunting opportunities mapped to <strong>MITRE ATT&amp;CK TTPs</strong>, with practical angles defenders can pursue.</p><h3><strong>Process &amp; Execution Hunts</strong></h3><ul><li><p><code>mshta.exe</code><strong> launching Excel</strong></p><ul><li><p><strong>ATT&amp;CK:</strong> T1218.005 - Signed Binary Proxy Execution: MSHTA</p></li><li><p><strong>Hunt idea:</strong> Query EDR/Sysmon logs for <code>mshta.exe</code> spawning <code>excel.exe</code> (rare, highly suspicious).</p></li><li><p>Example:</p><ul><li><p>Sysmon Event ID 1 (ProcessCreate)</p></li><li><p><code>ParentImage: mshta.exe</code> + <code>Image: excel.exe</code></p></li></ul></li></ul></li><li><p><strong>Excel spawning unusual child processes</strong></p><ul><li><p><strong>ATT&amp;CK:</strong> T1106 - Native API; T1105 &#8211; Ingress Tool Transfer</p></li><li><p>Hunt for <code>excel.exe</code> with outbound network activity or process injection behaviors (should be nearly nonexistent in normal use).</p></li></ul></li></ul><h3><strong>Registry Hunts</strong></h3><ul><li><p><strong>Modification of AccessVBOM key</strong></p><ul><li><p><code>HKCU\Software\Microsoft\Office\&lt;ver&gt;\Excel\Security\AccessVBOM</code></p></li><li><p><strong>ATT&amp;CK:</strong> T1112 - Modify Registry</p></li><li><p>Hunt for registry changes that enable VBOM access, especially those followed by Excel activity.</p></li><li><p>Sysmon Event ID 13 (RegistryEvent) with <code>TargetObject: *\AccessVBOM</code></p></li></ul></li></ul><h3><strong>Network Hunts</strong></h3><ul><li><p><strong>Excel initiating HTTPS connections</strong></p><ul><li><p><strong>ATT&amp;CK:</strong> T1071.001 - Application Layer Protocol: Web (HTTPS)</p></li><li><p>Hunt for unusual parent process (<code>excel.exe</code>) establishing TLS sessions.</p></li><li><p>Alert on legacy User-Agent strings (<code>Mozilla/4.0; MSIE 6.0; Windows NT 5.0</code>) in proxy logs.</p></li></ul></li><li><p><strong>Connections to suspicious domains behind Cloudflare</strong></p><ul><li><p><strong>ATT&amp;CK:</strong> T1102 - Web Service; T1105 - Ingress Tool Transfer</p></li><li><p>Focus on domains recently registered, mismatched TLS certs, or with patterns mimicking legitimate services (<code>policy-agreement[.]com</code>, <code>youtube.strike.alert[.]org</code>).</p></li></ul></li></ul><h3><strong>Memory / API Call Hunts</strong></h3><ul><li><p><strong>Excel performing reflective code loading</strong></p><ul><li><p><strong>ATT&amp;CK:</strong> T1620 - Reflective Code Loading</p></li><li><p>Look for Office processes calling <code>VirtualAlloc</code>, <code>RtlMoveMemory</code>, and <code>CreateThread</code>.</p></li><li><p><a href="https://learn.microsoft.com/en-us/windows-hardware/drivers/devtest/event-tracing-for-windows--etw-">ETW</a> or EDR telemetry can reveal these unusual API sequences.</p></li></ul></li></ul><h3><strong>Clipboard / User Interaction Hunts</strong></h3><ul><li><p><strong>Clipboard injection leading to Win+R execution</strong></p><ul><li><p><strong>ATT&amp;CK:</strong> T1056.001 - Input Capture: Clipboard Data</p></li><li><p>Hunt for patterns of auto-pasted <code>mshta.exe</code> commands in user activity logs.</p></li><li><p>Harder to detect, but can be spotted in forensic investigations.</p></li></ul></li></ul><h2>Defensive Controls to Prioritize</h2><ul><li><p>Restrict or disable <code>mshta.exe</code> (AppLocker / WDAC).</p></li><li><p>Enable Microsoft <a href="https://learn.microsoft.com/en-us/defender-endpoint/attack-surface-reduction">ASR</a> rules:</p><ul><li><p><em>Block Office applications from creating child processes</em></p></li><li><p><em>Block Win32 API calls from Office macros</em></p></li></ul></li><li><p>Harden macro execution policies; disable programmatic access to VBOM.</p></li><li><p>Add proxy/firewall detections for Excel/Office Apps outbound HTTPS traffic.</p></li></ul><div><hr></div><h1>Indicators of Compromise (IoCs)</h1><p><strong>IPs</strong></p><ul><li><p>188.114.96.3</p></li><li><p>185.158.133.1</p></li></ul><p><strong>Domains</strong></p><ul><li><p><code>policy[.]video</code></p></li><li><p><code>youtube.strike.alert[.]org</code></p></li><li><p><code>policy-agreement[.]com</code></p></li></ul><p><strong>Files</strong></p><ul><li><p><code>DMCA_notice.hta</code></p></li><li><p><code>agrees.bin</code></p></li><li><p><code>agreese.bin</code></p></li></ul><p><strong>Hashes</strong></p><ul><li><p>af32902cf27ffe3d4c1de4cf889edb0ed4ecae0f910ab47a2a0188be08b39f83</p></li></ul><p><strong>Registry</strong></p><ul><li><p><code>HKCU\Software\Microsoft\Office\&lt;ver&gt;\Excel\Security\AccessVBOM</code></p></li></ul><p><strong>Processes</strong></p><ul><li><p><code>mshta.exe</code> launching HTA &#8594; Excel.exe network activity</p></li></ul><div><hr></div><h1>Detection Opportunities</h1><p><strong>Host-Based:</strong></p><ul><li><p>Monitor for <code>mshta.exe</code> spawning Office processes.</p></li><li><p>Alert on AccessVBOM registry changes.</p></li><li><p>Hunt for RWX memory allocations in Excel (or other office apps).</p></li></ul><p><strong>Network-Based:</strong></p><ul><li><p>Excel initiating HTTPS sessions.</p></li><li><p>Legacy User-Agent strings.</p></li><li><p>C2 domains behind Cloudflare with ignored TLS validation.</p></li></ul><p><strong>Prevention:</strong></p><ul><li><p>Restrict/block MSHTA in enterprise environments (as needed).</p></li><li><p>Enforce Office <a href="https://learn.microsoft.com/en-us/defender-endpoint/attack-surface-reduction-rules-reference">ASR</a> rules (&#8220;block child processes,&#8221; &#8220;block API calls from macros&#8221;).</p></li><li><p>Disable programmatic VBOM access via GPO.</p></li></ul><div><hr></div><h1>Conclusion</h1><p>What happened to me is part of a larger trend showing that phishing is no longer just an email with bad grammar. It&#8217;s now:</p><ul><li><p><strong>Blended trust abuse</strong>: Cloud services + legitimate binaries.</p></li><li><p><strong>Multi-stage loaders</strong>: HTA &#8594; VBScript &#8594; Excel &#8594; reflective shellcode.</p></li><li><p><strong>Defense evasion</strong>: fileless, memory-resident, TLS-encrypted C2.</p></li></ul><p>For newer defenders, the lesson is not to underestimate a &#8220;simple phish.&#8221; </p><p>For seasoned analysts, this campaign demonstrates how low-cost adversaries are now borrowing tradecraft once considered &#8220;sophisticated.&#8221;</p><p>This incident serves as a reminder that attackers don&#8217;t have to invent new methods constantly. They simply adapt existing, proven techniques in ways that defenders might overlook.</p><div><hr></div><h2>Closing Note</h2><p>Thank you for reading!</p><p>This is my <strong>first full analysis-style newsletter,</strong> as most of my writing here has been reflective or career-focused. However, this time I wanted to share what it looks like when I sit down and work through a real-world attack in detail.</p><p>This kind of analysis is something I plan to do more often, blending <strong>storytelling, threat intelligence, and detection engineering</strong> into reports that are useful to both students and seasoned professionals.</p><p>Your feedback means a great deal as I develop this format. If you found this valuable, please share it with someone in your network who would also benefit from it.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberwoxunplugged.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&quot;,&quot;text&quot;:&quot;Share Cyberwox Unplugged&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberwoxunplugged.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share Cyberwox Unplugged</span></a></p>]]></content:encoded></item><item><title><![CDATA[The Power Of Cyber Threat Intelligence]]></title><description><![CDATA[Turning Raw Indicators Into Threat Intelligence with ANY.RUN.]]></description><link>https://www.cyberwoxunplugged.com/p/the-power-of-cyber-threat-intelligence</link><guid isPermaLink="false">https://www.cyberwoxunplugged.com/p/the-power-of-cyber-threat-intelligence</guid><dc:creator><![CDATA[Day Johnson]]></dc:creator><pubDate>Wed, 27 Aug 2025 12:46:38 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/171532050/2163c4ea3713ee8f7021c0c8b5b0c9c5.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>Conflict today doesn&#8217;t just play out on land, sea, or in the air. It&#8217;s expanded into cyberspace. </p><p>Behind every headline of breaches and takedowns are targeted campaigns carried out by methodical, well-resourced threat actors &#8212; each with their motives, tactics, and long-term goals.</p><p>One such group is <strong>Salt Typhoon</strong> (also tracked as <em>FamousSparrow</em> and <em>GhostEmperor</em> depending on the vendor). </p><p>A Chinese nation-state&#8211;backed adversary that has been discovered infiltrating major U.S. telecom networks &#8212; from T-Mobile to Verizon, Samsung, and others.</p><p>Salt Typhoon is known for stealth, patience, and precision. </p><p>They leave behind only faint traces across compromised networks, making it exceptionally difficult for defenders to contain or eradicate their activity.</p><p>That challenge is exactly where <strong>cyber threat intelligence (CTI)</strong> comes in.</p><div><hr></div><h2>From IOCs to Insight</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Axx3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47df7173-4df3-4c3d-9309-361ec161e956_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Axx3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47df7173-4df3-4c3d-9309-361ec161e956_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!Axx3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47df7173-4df3-4c3d-9309-361ec161e956_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!Axx3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47df7173-4df3-4c3d-9309-361ec161e956_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!Axx3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47df7173-4df3-4c3d-9309-361ec161e956_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Axx3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47df7173-4df3-4c3d-9309-361ec161e956_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/47df7173-4df3-4c3d-9309-361ec161e956_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Generated image&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Generated image" title="Generated image" srcset="https://substackcdn.com/image/fetch/$s_!Axx3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47df7173-4df3-4c3d-9309-361ec161e956_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!Axx3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47df7173-4df3-4c3d-9309-361ec161e956_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!Axx3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47df7173-4df3-4c3d-9309-361ec161e956_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!Axx3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47df7173-4df3-4c3d-9309-361ec161e956_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Threat intelligence is not just about collecting IOCs (indicators of compromise, such as hashes, IPs, and domains) and feeding them into SIEMs. </p><p>At its best, CTI is about <strong>connecting the dots</strong>: finding patterns across disparate indicators, uncovering infrastructure, profiling adversary behavior, and turning raw data into actionable defense.</p><p>The value lies in the transformation:</p><ul><li><p>From a file hash &#8594; to the malware family behind it.</p></li><li><p>From a suspicious domain &#8594; to the broader C2 network.</p></li><li><p>From isolated alerts &#8594; to an adversary campaign strategy.</p></li></ul><p>When done well, this enables defenders to build more effective detections, strengthen playbooks, automate enrichment, and prioritize risks in line with evolving active threat landscapes.</p><div><hr></div><h1><strong>About Me</strong></h1><p>If you're new here, I'm Day, a Cybersecurity Engineer at Amazon. With five years in cybersecurity, my experience covers Detection Engineering, Cloud Security, Incident Response, Threat Hunting, and most recently, Threat Intelligence.</p><p>Before Amazon, I worked at Datadog as a cloud threat detection engineer, where I researched cloud threats and built detections for various cloud providers and SaaS applications.</p><p>I've worked my way up from various SOC analyst roles, investigating everything from endpoint threats to building detection systems for cloud-based abuse, so I know exactly what it takes to break into this field and make career advancements.</p><p>I started, just like many of you, learning from scratch, asking questions, and figuring it out one step at a time. <strong>And now, I'm here to help you do the same.</strong></p><p>If you want to stay up-to-date on the cybersecurity industry and everything technical and career-related, be sure to like and subscribe to the newsletter for more content like this.</p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!iF0v!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba71e4f8-2d28-4fd6-9a78-c966708c46a6_2500x979.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!iF0v!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba71e4f8-2d28-4fd6-9a78-c966708c46a6_2500x979.png 424w, https://substackcdn.com/image/fetch/$s_!iF0v!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba71e4f8-2d28-4fd6-9a78-c966708c46a6_2500x979.png 848w, https://substackcdn.com/image/fetch/$s_!iF0v!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba71e4f8-2d28-4fd6-9a78-c966708c46a6_2500x979.png 1272w, https://substackcdn.com/image/fetch/$s_!iF0v!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba71e4f8-2d28-4fd6-9a78-c966708c46a6_2500x979.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!iF0v!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba71e4f8-2d28-4fd6-9a78-c966708c46a6_2500x979.png" width="1456" height="570" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ba71e4f8-2d28-4fd6-9a78-c966708c46a6_2500x979.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:570,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:188886,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:&quot;&quot;,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cyberwoxunplugged.com/i/159067704?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F913f1923-04a0-4fe6-afb6-5e0fca6d78b1_2500x2500.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!iF0v!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba71e4f8-2d28-4fd6-9a78-c966708c46a6_2500x979.png 424w, https://substackcdn.com/image/fetch/$s_!iF0v!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba71e4f8-2d28-4fd6-9a78-c966708c46a6_2500x979.png 848w, https://substackcdn.com/image/fetch/$s_!iF0v!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba71e4f8-2d28-4fd6-9a78-c966708c46a6_2500x979.png 1272w, https://substackcdn.com/image/fetch/$s_!iF0v!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba71e4f8-2d28-4fd6-9a78-c966708c46a6_2500x979.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Join a vibrant cybersecurity community of over 6,500 people who are constantly engaging in conversations and supporting one another, covering topics from cybersecurity and college to certifications, resume assistance, and various non-professional interests like fitness, finance, anime, and other exciting subjects.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://discord.gg/cyberwoxacademy&quot;,&quot;text&quot;:&quot;Join Us!&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://discord.gg/cyberwoxacademy"><span>Join Us!</span></a></p><div><hr></div><h2>Applying CTI in Practice</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!zraM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98a3f83f-688c-453c-bf11-bac3b7c8a0a2_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!zraM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98a3f83f-688c-453c-bf11-bac3b7c8a0a2_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!zraM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98a3f83f-688c-453c-bf11-bac3b7c8a0a2_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!zraM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98a3f83f-688c-453c-bf11-bac3b7c8a0a2_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!zraM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98a3f83f-688c-453c-bf11-bac3b7c8a0a2_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!zraM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98a3f83f-688c-453c-bf11-bac3b7c8a0a2_1024x1024.png" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/98a3f83f-688c-453c-bf11-bac3b7c8a0a2_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Generated image&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Generated image" title="Generated image" srcset="https://substackcdn.com/image/fetch/$s_!zraM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98a3f83f-688c-453c-bf11-bac3b7c8a0a2_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!zraM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98a3f83f-688c-453c-bf11-bac3b7c8a0a2_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!zraM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98a3f83f-688c-453c-bf11-bac3b7c8a0a2_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!zraM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98a3f83f-688c-453c-bf11-bac3b7c8a0a2_1024x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>As a Security Engineer at Amazon, I&#8217;ve had the opportunity to use threat intelligence at scale. </p><p>But CTI isn&#8217;t just for enterprise SOCs. With the right tools, individual analysts and researchers can explore and learn from the same adversary tradecraft.</p><p>For this issue, I investigated <strong>Salt Typhoon</strong> using ANY.RUN&#8217;s Threat Intelligence Platform. It blends <strong>interactive sandboxing</strong> (their signature strength) with curated intelligence and lookup capabilities. Here&#8217;s what that looks like in practice:</p><ul><li><p><strong>Starting with a handful of IOCs</strong>, such as an IP address, a SHA-256 hash, or a domain name.</p></li><li><p><strong>Pivoting into reports</strong> &#8594; correlating with published research from vendors like Trend Micro.</p></li><li><p><strong>Interactive detonation</strong> &#8594; running suspicious files in a sandbox, observing process creation, persistence mechanisms, and outbound C2 calls.</p></li><li><p><strong>Hunting for connections</strong> &#8594; mapping behaviors against known TTPs and extracting new indicators.</p></li><li><p><strong>YARA integration</strong> &#8594; building and running rules directly in the platform to surface related artifacts.</p></li></ul><p>What begins as a single suspicious hash quickly expands into a narrative: a Trojan is dropped, a service is created for persistence, reconnaissance of the host is conducted, and finally, communication with a C2 domain occurs.</p><div><hr></div><h2>Why It Matters</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!FWa0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f9f759f-63b3-4fd4-997e-584e9f0f3b09_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!FWa0!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f9f759f-63b3-4fd4-997e-584e9f0f3b09_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!FWa0!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f9f759f-63b3-4fd4-997e-584e9f0f3b09_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!FWa0!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f9f759f-63b3-4fd4-997e-584e9f0f3b09_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!FWa0!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f9f759f-63b3-4fd4-997e-584e9f0f3b09_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!FWa0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f9f759f-63b3-4fd4-997e-584e9f0f3b09_1024x1024.png" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3f9f759f-63b3-4fd4-997e-584e9f0f3b09_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Generated image&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Generated image" title="Generated image" srcset="https://substackcdn.com/image/fetch/$s_!FWa0!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f9f759f-63b3-4fd4-997e-584e9f0f3b09_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!FWa0!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f9f759f-63b3-4fd4-997e-584e9f0f3b09_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!FWa0!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f9f759f-63b3-4fd4-997e-584e9f0f3b09_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!FWa0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f9f759f-63b3-4fd4-997e-584e9f0f3b09_1024x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The power of CTI lies in turning <strong>fragments into a story</strong>. </p><p>Instead of drowning in endless IOCs, analysts can contextualize activity, link it to known actors, and anticipate what might come next.</p><p>In this case, a few scattered data points around Salt Typhoon transformed into a clearer picture of:</p><ul><li><p>Their infrastructure choices</p></li><li><p>Their persistence techniques</p></li><li><p>Their reconnaissance behavior</p></li><li><p>Their communication patterns</p></li></ul><p>With that knowledge, defenders can proactively hunt for related TTPs in their environments or simulate adversary behavior to test defenses.</p><div class="pullquote"><p><em><strong>ANY.RUN Threat Intelligence</strong></em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QHnK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaf355a3-b7d7-45c4-8613-5c0bd4277ffa_1600x500.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QHnK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaf355a3-b7d7-45c4-8613-5c0bd4277ffa_1600x500.png 424w, https://substackcdn.com/image/fetch/$s_!QHnK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaf355a3-b7d7-45c4-8613-5c0bd4277ffa_1600x500.png 848w, https://substackcdn.com/image/fetch/$s_!QHnK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaf355a3-b7d7-45c4-8613-5c0bd4277ffa_1600x500.png 1272w, https://substackcdn.com/image/fetch/$s_!QHnK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaf355a3-b7d7-45c4-8613-5c0bd4277ffa_1600x500.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QHnK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaf355a3-b7d7-45c4-8613-5c0bd4277ffa_1600x500.png" width="1456" height="455" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/caf355a3-b7d7-45c4-8613-5c0bd4277ffa_1600x500.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:455,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:22296,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cyberwoxunplugged.com/i/159067704?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaf355a3-b7d7-45c4-8613-5c0bd4277ffa_1600x500.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!QHnK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaf355a3-b7d7-45c4-8613-5c0bd4277ffa_1600x500.png 424w, https://substackcdn.com/image/fetch/$s_!QHnK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaf355a3-b7d7-45c4-8613-5c0bd4277ffa_1600x500.png 848w, https://substackcdn.com/image/fetch/$s_!QHnK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaf355a3-b7d7-45c4-8613-5c0bd4277ffa_1600x500.png 1272w, https://substackcdn.com/image/fetch/$s_!QHnK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaf355a3-b7d7-45c4-8613-5c0bd4277ffa_1600x500.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This issue is powered by ANY.RUN, which sponsored this deep dive. ANY.RUN makes it easy to turn raw indicators into actionable intelligence without needing to set up your own lab environment. If you&#8217;re serious about developing threat intelligence skills, it&#8217;s worth checking out.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://bit.ly/cwx-anyrun-threat-intelligence-lookup&quot;,&quot;text&quot;:&quot;&#128640;Unlock (free) ANY.RUN Threat Intel&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://bit.ly/cwx-anyrun-threat-intelligence-lookup"><span>&#128640;Unlock (free) ANY.RUN Threat Intel</span></a></p></div><h1>Closing</h1><p>What began as a file hash and a suspicious domain evolved into a broader narrative about Salt Typhoon&#8217;s operations. That&#8217;s the heart of cyber threat intelligence: transforming raw signals into stories that defenders can act on.</p><p>If you&#8217;re early in your cybersecurity journey, practice this workflow yourself:</p><ul><li><p>Begin with a known IOC from a publicly available report.</p></li><li><p>Pivot into related domains, files, and hashes.</p></li><li><p>Map the TTPs you discover against frameworks like MITRE ATT&amp;CK.</p></li><li><p>Build detections or run hunts based on your findings.</p></li></ul><p>That&#8217;s how you transition from merely &#8220;consuming&#8221; intel to&nbsp;<strong>generating actionable intelligence</strong>&nbsp;&#8212; a skill that grows from home labs to Fortune 500 SOCs.</p><p>Here&#8217;s a video that can help you do that:</p><div id="youtube2-A0r6A7kWD58" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;A0r6A7kWD58&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/A0r6A7kWD58?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><div><hr></div><p>Thanks for reading Cyberwox Unplugged! This post is public, so feel free to share it.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberwoxunplugged.com/p/the-power-of-cyber-threat-intelligence?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cyberwoxunplugged.com/p/the-power-of-cyber-threat-intelligence?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Why I’m Building a New Cybersecurity Homelab ]]></title><description><![CDATA[Five Years Later!]]></description><link>https://www.cyberwoxunplugged.com/p/why-im-building-a-new-cybersecurity</link><guid isPermaLink="false">https://www.cyberwoxunplugged.com/p/why-im-building-a-new-cybersecurity</guid><dc:creator><![CDATA[Day Johnson]]></dc:creator><pubDate>Fri, 22 Aug 2025 12:03:17 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/f1ae16ec-e503-41e5-8bd3-4ce65b325387_1280x720.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Five years ago, I was just a curious college freshman with a few spare computer parts, a lot of Google searches, and a dream of breaking into cybersecurity. </p><p>That spark led me to build my very first homelab in a small apartment bedroom. No mentors, no structured guidance, just curiosity and trial-and-error.</p><p>That project changed everything. It was the first time I saw what was really happening under the hood: how hosts behaved, how networks communicated, how virtual machines could mimic production environments. </p><p>My entire career in incident response, detection engineering, threat hunting, and cloud security traces back to that moment.</p><p>Now, half a decade later, I&#8217;m starting over.</p><p>But this time, I&#8217;m building with real-world experience behind me, more intention, and a vision.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!o68v!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3dfae1c-aa15-4dcf-a471-030775b06714_768x1024.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!o68v!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3dfae1c-aa15-4dcf-a471-030775b06714_768x1024.jpeg 424w, https://substackcdn.com/image/fetch/$s_!o68v!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3dfae1c-aa15-4dcf-a471-030775b06714_768x1024.jpeg 848w, https://substackcdn.com/image/fetch/$s_!o68v!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3dfae1c-aa15-4dcf-a471-030775b06714_768x1024.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!o68v!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3dfae1c-aa15-4dcf-a471-030775b06714_768x1024.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!o68v!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3dfae1c-aa15-4dcf-a471-030775b06714_768x1024.jpeg" width="768" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b3dfae1c-aa15-4dcf-a471-030775b06714_768x1024.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:768,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:164497,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cyberwoxunplugged.com/i/171047974?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3dfae1c-aa15-4dcf-a471-030775b06714_768x1024.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!o68v!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3dfae1c-aa15-4dcf-a471-030775b06714_768x1024.jpeg 424w, https://substackcdn.com/image/fetch/$s_!o68v!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3dfae1c-aa15-4dcf-a471-030775b06714_768x1024.jpeg 848w, https://substackcdn.com/image/fetch/$s_!o68v!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3dfae1c-aa15-4dcf-a471-030775b06714_768x1024.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!o68v!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3dfae1c-aa15-4dcf-a471-030775b06714_768x1024.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>Dec 2020 &#8594; 18-year-old me - working as a Cybersecurity Intern &amp; full-time college sophomore at the time.</em></p><div><hr></div><h1>Why Start Over?</h1><p>The first lab was raw curiosity. </p><p>Plugging things together, watching packets fly, and trying to make sense of it all.</p><p>That&#8217;s exactly what I needed at the time. But I&#8217;ve grown. I&#8217;m no longer the kid trying to figure out what a SIEM even is. I&#8217;m a security engineer at Amazon who&#8217;s lived in the trenches of incident response, adversary detection, and cloud security.</p><p>And with that growth comes new questions:</p><ul><li><p><em>How can I push my homelab into its next evolution?</em></p></li><li><p><em>How can I design my homelab to build and test the new skills I want to develop at this stage of my career?</em></p></li><li><p><em>How can my new homelab help me learn new skills?</em></p></li></ul><p>This time, the goal is not just tinkering. I&#8217;m designing a <strong>home Security Operations Center (SOC)</strong> where I can experiment, prototype, and learn new skills in public.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1zYc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40728e3d-7e23-43da-bbca-767c91ca6ff7_768x1024.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1zYc!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40728e3d-7e23-43da-bbca-767c91ca6ff7_768x1024.jpeg 424w, https://substackcdn.com/image/fetch/$s_!1zYc!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40728e3d-7e23-43da-bbca-767c91ca6ff7_768x1024.jpeg 848w, https://substackcdn.com/image/fetch/$s_!1zYc!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40728e3d-7e23-43da-bbca-767c91ca6ff7_768x1024.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!1zYc!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40728e3d-7e23-43da-bbca-767c91ca6ff7_768x1024.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1zYc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40728e3d-7e23-43da-bbca-767c91ca6ff7_768x1024.jpeg" width="768" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/40728e3d-7e23-43da-bbca-767c91ca6ff7_768x1024.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:768,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:190974,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cyberwoxunplugged.com/i/171047974?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40728e3d-7e23-43da-bbca-767c91ca6ff7_768x1024.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!1zYc!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40728e3d-7e23-43da-bbca-767c91ca6ff7_768x1024.jpeg 424w, https://substackcdn.com/image/fetch/$s_!1zYc!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40728e3d-7e23-43da-bbca-767c91ca6ff7_768x1024.jpeg 848w, https://substackcdn.com/image/fetch/$s_!1zYc!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40728e3d-7e23-43da-bbca-767c91ca6ff7_768x1024.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!1zYc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40728e3d-7e23-43da-bbca-767c91ca6ff7_768x1024.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>Jan 2021 &#8594; For a while, I thought I was going to become a network (security) engineer, so here I am in 2021, diving into network security for Cisco routers and switches. Spoiler: I did not become a network security engineer.</em></p><div><hr></div><h2><strong>About Me</strong></h2><p>If you're new here, I'm Day, a Cybersecurity Engineer at Amazon. With five years in cybersecurity, my experience covers Detection Engineering, Cloud Security, Incident Response, Threat Hunting, and most recently, Threat Intelligence.</p><p>Before Amazon, I worked at Datadog as a cloud threat detection engineer, where I researched cloud threats and built detections for various cloud providers and SaaS applications.</p><p>I've worked my way up from SOC analyst roles, investigating everything from endpoint threats to cloud-based abuse, so I know exactly what it takes to break into this field.</p><p>I started, just like many of you, learning from scratch, asking questions, and figuring it out one step at a time. <strong>And now, I'm here to help you do the same.</strong></p><p>I was able to break into cybersecurity as early as my freshman year of college. I&#8217;ve secured several jobs and interviews before earning my college degree, and I&#8217;ve helped thousands of people achieve the same success on my various content channels and in my Discord Community.</p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!iF0v!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba71e4f8-2d28-4fd6-9a78-c966708c46a6_2500x979.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!iF0v!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba71e4f8-2d28-4fd6-9a78-c966708c46a6_2500x979.png 424w, https://substackcdn.com/image/fetch/$s_!iF0v!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba71e4f8-2d28-4fd6-9a78-c966708c46a6_2500x979.png 848w, https://substackcdn.com/image/fetch/$s_!iF0v!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba71e4f8-2d28-4fd6-9a78-c966708c46a6_2500x979.png 1272w, https://substackcdn.com/image/fetch/$s_!iF0v!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba71e4f8-2d28-4fd6-9a78-c966708c46a6_2500x979.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!iF0v!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba71e4f8-2d28-4fd6-9a78-c966708c46a6_2500x979.png" width="1456" height="570" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ba71e4f8-2d28-4fd6-9a78-c966708c46a6_2500x979.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:570,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:188886,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:&quot;&quot;,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cyberwoxunplugged.com/i/159067704?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F913f1923-04a0-4fe6-afb6-5e0fca6d78b1_2500x2500.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!iF0v!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba71e4f8-2d28-4fd6-9a78-c966708c46a6_2500x979.png 424w, https://substackcdn.com/image/fetch/$s_!iF0v!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba71e4f8-2d28-4fd6-9a78-c966708c46a6_2500x979.png 848w, https://substackcdn.com/image/fetch/$s_!iF0v!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba71e4f8-2d28-4fd6-9a78-c966708c46a6_2500x979.png 1272w, https://substackcdn.com/image/fetch/$s_!iF0v!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba71e4f8-2d28-4fd6-9a78-c966708c46a6_2500x979.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Join a vibrant cybersecurity community of over 6,500 people who are constantly engaging in conversations and supporting one another, covering topics from cybersecurity and college to certifications, resume assistance, and various non-professional interests like fitness, finance, anime, and other exciting subjects.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://discord.gg/cyberwoxacademy&quot;,&quot;text&quot;:&quot;Join Us!&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://discord.gg/cyberwoxacademy"><span>Join Us!</span></a></p><div><hr></div><h1>The New Blueprint</h1><p>Here&#8217;s where I&#8217;m starting:</p><ul><li><p><strong>The Hardware:</strong> I&#8217;m converting an old PC into a <strong>Type-1 hypervisor</strong> (bare-metal virtualization). No middleman OS, just pure performance and control.</p></li><li><p><strong>The Core Platform:</strong> Running <strong>Proxmox</strong> for virtualization. I&#8217;m also planning to explore diving deeper into mini-data center operations by leveraging Proxmox&#8217;s clustering functionality.</p></li><li><p><strong>The SOC Engine:</strong> <strong>Wazuh</strong> at the center, doubling as both my SIEM and XDR platform. This also helps me leverage a unified platform that I can plug external integrations into for experiments.</p></li><li><p><strong>Visibility Everywhere:</strong> Rolling out agents to every endpoint I can&#8212;Windows, macOS, IoT devices, even &#8220;smart&#8221; tech around the house. If it talks to the internet, I want visibility.</p></li><li><p><strong>Additional Tools:</strong> Still deciding, but possibilities include Limacharlie for EDR testing, Pfsense for firewall, and maybe some local Container tools that I may use for experimenting with Falco. Wazuh itself has active response, so I&#8217;ll be balancing native vs. add-on capabilities.</p></li><li><p><strong>AI in the SOC:</strong> Beyond buzzwords, I&#8217;ll experiment with using LLMs for anomaly detection, automation, and more intelligent triage workflows. I&#8217;ll also be playing around with MCP integrations to see what that yields.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!cVF3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecdb48b1-8e00-4665-b998-d7b14230eb8e_1024x768.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!cVF3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecdb48b1-8e00-4665-b998-d7b14230eb8e_1024x768.jpeg 424w, https://substackcdn.com/image/fetch/$s_!cVF3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecdb48b1-8e00-4665-b998-d7b14230eb8e_1024x768.jpeg 848w, https://substackcdn.com/image/fetch/$s_!cVF3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecdb48b1-8e00-4665-b998-d7b14230eb8e_1024x768.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!cVF3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecdb48b1-8e00-4665-b998-d7b14230eb8e_1024x768.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!cVF3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecdb48b1-8e00-4665-b998-d7b14230eb8e_1024x768.jpeg" width="1024" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ecdb48b1-8e00-4665-b998-d7b14230eb8e_1024x768.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:138348,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cyberwoxunplugged.com/i/171047974?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecdb48b1-8e00-4665-b998-d7b14230eb8e_1024x768.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!cVF3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecdb48b1-8e00-4665-b998-d7b14230eb8e_1024x768.jpeg 424w, https://substackcdn.com/image/fetch/$s_!cVF3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecdb48b1-8e00-4665-b998-d7b14230eb8e_1024x768.jpeg 848w, https://substackcdn.com/image/fetch/$s_!cVF3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecdb48b1-8e00-4665-b998-d7b14230eb8e_1024x768.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!cVF3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecdb48b1-8e00-4665-b998-d7b14230eb8e_1024x768.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>March 2021 &#8594; the evolution of my &#8220;lab&#8221;. It honestly was just the addition of an excessive 49&#8221; ultrawide screen and stacked monitor setup. </em></p><div><hr></div><h1>Lessons in Frustration (and Growth)</h1><p>One thing hasn&#8217;t changed since my first homelab: trial and error is the name of the game.</p><p>Getting Proxmox running on bare metal was a headache. </p><p>I went through HDMI swaps, capture card experiments, BIOS tweaks, and kernel parameter hacks before things finally booted correctly. </p><p>At one point, it felt like I&#8217;d broken the host. </p><p><em>Spoiler: I hadn&#8217;t. It just required persistence.</em></p><p>Moments like that reminded me why homelabs matter so much. They expose the <em>rust</em> in your technical chops. </p><p>They force you to fail, to troubleshoot, and to learn. And I&#8217;ve found that to be the best preparation for real-world security work.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!DoMX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F195f4a3c-b4b6-4413-99f5-44db4825b0fc_1024x768.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!DoMX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F195f4a3c-b4b6-4413-99f5-44db4825b0fc_1024x768.jpeg 424w, https://substackcdn.com/image/fetch/$s_!DoMX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F195f4a3c-b4b6-4413-99f5-44db4825b0fc_1024x768.jpeg 848w, https://substackcdn.com/image/fetch/$s_!DoMX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F195f4a3c-b4b6-4413-99f5-44db4825b0fc_1024x768.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!DoMX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F195f4a3c-b4b6-4413-99f5-44db4825b0fc_1024x768.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!DoMX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F195f4a3c-b4b6-4413-99f5-44db4825b0fc_1024x768.jpeg" width="1024" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/195f4a3c-b4b6-4413-99f5-44db4825b0fc_1024x768.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:220716,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cyberwoxunplugged.com/i/171047974?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F195f4a3c-b4b6-4413-99f5-44db4825b0fc_1024x768.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!DoMX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F195f4a3c-b4b6-4413-99f5-44db4825b0fc_1024x768.jpeg 424w, https://substackcdn.com/image/fetch/$s_!DoMX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F195f4a3c-b4b6-4413-99f5-44db4825b0fc_1024x768.jpeg 848w, https://substackcdn.com/image/fetch/$s_!DoMX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F195f4a3c-b4b6-4413-99f5-44db4825b0fc_1024x768.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!DoMX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F195f4a3c-b4b6-4413-99f5-44db4825b0fc_1024x768.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>May 2021 &#8594; I spent a lot of time learning about Splunk within my homelab, and it paid a lot of dividends over the ongoing course of my career (till this day).</em></p><div><hr></div><h1>Why It Matters. Why Now?</h1><p>This lab isn&#8217;t about showing off gear (tbh the gear is old) or building the &#8220;perfect&#8221; setup. It&#8217;s about my desire to create a <strong>sandbox for growth</strong>:</p><ul><li><p>For me, it&#8217;s a way to stay sharp outside of work, to play with tools in ways I can&#8217;t in enterprise environments.</p></li><li><p>For the community, it&#8217;s proof that learning never stops. I&#8217;ll be sharing my process openly, mistakes and all, so that others can build their own versions.</p></li><li><p>For the industry, it&#8217;s a reminder that innovation often starts at home, with curiosity and persistence.</p></li></ul><p>Five years ago, my first homelab helped me land interviews, build skills, and eventually start my career. </p><p>Who knows what this next one will spark?</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!K4PV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe3998f0-9424-453f-8398-82cf2271cf6b_1170x608.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!K4PV!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe3998f0-9424-453f-8398-82cf2271cf6b_1170x608.jpeg 424w, https://substackcdn.com/image/fetch/$s_!K4PV!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe3998f0-9424-453f-8398-82cf2271cf6b_1170x608.jpeg 848w, https://substackcdn.com/image/fetch/$s_!K4PV!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe3998f0-9424-453f-8398-82cf2271cf6b_1170x608.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!K4PV!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe3998f0-9424-453f-8398-82cf2271cf6b_1170x608.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!K4PV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe3998f0-9424-453f-8398-82cf2271cf6b_1170x608.jpeg" width="1170" height="608" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fe3998f0-9424-453f-8398-82cf2271cf6b_1170x608.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:608,&quot;width&quot;:1170,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:673769,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cyberwoxunplugged.com/i/171047974?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe3998f0-9424-453f-8398-82cf2271cf6b_1170x608.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!K4PV!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe3998f0-9424-453f-8398-82cf2271cf6b_1170x608.jpeg 424w, https://substackcdn.com/image/fetch/$s_!K4PV!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe3998f0-9424-453f-8398-82cf2271cf6b_1170x608.jpeg 848w, https://substackcdn.com/image/fetch/$s_!K4PV!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe3998f0-9424-453f-8398-82cf2271cf6b_1170x608.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!K4PV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe3998f0-9424-453f-8398-82cf2271cf6b_1170x608.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>January 2022 &#8594; New Apartment with separate setups for work and study/labbing. This is actually me taking the Security Blue Team BTL1 certification!</em> </p><div><hr></div><h1>What&#8217;s Next</h1><p>This was just <strong>Step 1: Laying the foundation.</strong></p><p>Next, I&#8217;ll be deploying Wazuh on Proxmox, configuring my SIEM/XDR stack, and rolling out agents across every machine in my house. </p><p>From there, I&#8217;ll test detection engineering workflows, automation, and maybe even play with AI-assisted incident response.</p><p>If something in my home misbehaves, I want to catch it.<br>If it breaks, I want to know why.<br>And if it teaches me something new, I want to share that with you.</p><p>The journey continues.</p><p>Stay tuned.</p><div><hr></div><h3>&#128161; <strong>A Note of Gratitude</strong></h3><p>This issue of Cyberwox Unplugged is my very first <em>paid</em> post. </p><p>That means you&#8217;re not just reading my reflections&#8212;you&#8217;re directly supporting the growth of this publication and my mission to build practical, real-world cybersecurity content. </p><p>Thank you for being here and investing in the journey with me. </p><p>This is just the beginning.</p><div><hr></div><p>Thanks for reading Cyberwox Unplugged! This post is public, so feel free to share it.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cyberwoxunplugged.com/p/fastest-way-to-become-a-cloud-security?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&amp;token=eyJ1c2VyX2lkIjoxNzI1NDA4MjcsInBvc3RfaWQiOjE2MjEwNzg2MiwiaWF0IjoxNzU1NzQ1OTkyLCJleHAiOjE3NTgzMzc5OTIsImlzcyI6InB1Yi0xOTk2Mjk2Iiwic3ViIjoicG9zdC1yZWFjdGlvbiJ9.L64iV-CLcr3eSErHdxG94GTIhstaqNLlto5goTXkPik&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cyberwoxunplugged.com/p/fastest-way-to-become-a-cloud-security?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&amp;token=eyJ1c2VyX2lkIjoxNzI1NDA4MjcsInBvc3RfaWQiOjE2MjEwNzg2MiwiaWF0IjoxNzU1NzQ1OTkyLCJleHAiOjE3NTgzMzc5OTIsImlzcyI6InB1Yi0xOTk2Mjk2Iiwic3ViIjoicG9zdC1yZWFjdGlvbiJ9.L64iV-CLcr3eSErHdxG94GTIhstaqNLlto5goTXkPik"><span>Share</span></a></p>]]></content:encoded></item></channel></rss>