top of page
Work Overview
LATEST PROJECTS
Lorem ipsum dolor sit amet, consectetuer adipiscing elit. Aenean commodo ligula eget dolor. Aenean massa. Cum sociis natoque

Blog
Search


Hunt the MP4 that never plays: NetSupport in an ISO-BMFF uuid box
You know the ticket. Someone downloaded a video. The ticket says media. The player refuses to open it. Antivirus already shrugged and called it an MP4. There is no ransomware family name on the alert, and the user swears they never watched anything. That unfair case is when this chain wants you to close it and move on. Here is the plain version before the box jargon. The file is a fake video shell. It is stuffed with a script. It is not a clip you failed to open. It is a carr
7 min read


Spring Ring: hunt the Teams helpdesk that never hits email
Unit 42 published Spring Ring today, 31 August 2026. The activity in the report is from January through April. This is leftover tradecraft, not a weekend outbreak. If you are hunting it because the write-up is new, you are hunting a gap that has been sitting in Teams since winter. The gap is Chat with anyone plus a voice call that never hits the mail gateway. They are not phish-mailing IT. A throwaway .onmicrosoft.com tenant named like a helpdesk opens a Teams chat. Then a 10
5 min read


PaperCut CVE-2026-81578: hunt the emergency patch that did not stay a patch
You have seen this ticket. Print is still working. Someone applied the first emergency PaperCut patch when it dropped, the queue came back, and they closed it. The Application Server web UI is still on the internet because print admins do not like taking that box down twice in one week. That is the hunt. Not the CVE number. The hunt is the emergency patch that did not stay a patch. CISA put CVE-2026-81578 and CVE-2026-82078 on KEV on 31 August 2026. If you only ran Patch 1, y
5 min read


SynkLoader: the lock screen plus the tunnel
PhishLocker is a fake Windows lock screen. The password plus the tunnel is the prize. On 18 August, Expel caught SynkLoader off a scheduled-task EDR hit that started in Microsoft Teams and ended in a fake lock screen. The EDR alert was the first clean look at a loader nobody had published yet. File times and compile stamps ran back to about 28 July. They named it SynkLoader. No crew name came with it. How SynkLoader arrives in Microsoft Teams The user had already been talked
3 min read
bottom of page
