It's been extremely hard to keep this one under wraps.

I just published a new blog post, where one weird string that looks like a cookie value turned out to be a whole cryptostealer and database wiping operation.

labs.greynoise.io/grimoire/202

I spent some late nights on this one, and am a little bit ridiculously proud of the work I did.

0

If you have a fediverse account, you can quote this note from your own instance. Search https://haunted.computer/users/Dio9sys/statuses/116127574884953647 on your instance and quote it. (Note that quoting is not supported in Mastodon.)