Research Archive

Threat Intelligence

Browse entries by research type, time, topic, and threat domain. This page behaves more like an archive than a feed.

2026

A copper-orange Telegram paper plane badge being replicated onto a dark glass panel against a near-black teal-blue dossier background, symbolizing local session replication bypassing authentication
Security Research

Telegram Desktop Local Session Reuse: a Reproduction That Should Not Have Happened

A macOS stealer can copy Telegram Desktop's tdata directory and Telegram for macOS's local session files to another machine, restoring the logged-in state without triggering phone verification, SMS codes, or 2FA. An honest account of the discovery and the cognitive shift from 'this shouldn't happen' to 'but it does.'

2026-07-15 10 min #Malware

2025

Over a near-black teal-blue background, a hooded APT silhouette ascending a multi-stage arrow staircase, a PyYAML RCE backdoor glowing copper-orange at the entry point, lateral-movement arrows threading toward a wallet server, and a smoking trust-chain link — symbolizing the Lazarus Group's targeted APT attack on cryptocurrency exchanges
Security Research

Lazarus Group APT Attack on Cryptocurrency Exchanges: IOC & TTP Disclosure

After nearly a month of forensic investigation into multiple cryptocurrency exchange breaches, I and 23pds confirmed the attacker as Lazarus Group. This article discloses the complete set of IOCs and TTPs, including social engineering entry, PyYAML RCE backdoor deployment, and lateral movement to wallet servers.

2025-02-23 7 min #APT Analysis

2024

Over a near-black teal-blue background, a disguised Aggr extension icon in the Chrome Web Store alongside a flow of stolen cookie data, malicious nodes marked copper-orange in the network topology, and malicious code fragments planted inside a jQuery file scattered across the backdrop — symbolizing the fake Aggr Chrome extension's cookie theft and wash-trading crypto heist
Security Research

Fake Aggr Chrome Extension Crypto Theft Analysis: Cookie Stealing and Wash Trading

In May 2024, a malicious Chrome extension disguised as an Aggr trading tool was found stealing users' cookies from all websites. The attacker embedded malicious code inside a jQuery file, exfiltrating cookie data to a Russian-language server and using wash trading to steal users' crypto assets. The hacker began plotting 3 years ago, deployed the attack 4 months ago, and leveraged KOLs for promotion.

2024-05-31 4 min #Web3 Phishing

2022

Over a near-black teal-blue background, a BGP path lights up copper-orange as it is hijacked within a global routing map, a forged SSL certificate overlays the original, and Internet traffic is redirected to a malicious server — symbolizing the Celer Network cBridge BGP hijacking attack
Security Research

Celer Network cBridge Cross-Chain Bridge Incident Analysis: BGP Hijacking Attack

On August 18, 2022, Celer Network cBridge suffered a BGP Hijacking attack. The attacker hijacked the underlying Internet routing protocol to redirect cross-chain users to a malicious frontend. Through certificate analysis, AS routing tracing, and BGP Trace records, the SlowMist security team confirmed this was a targeted BGP hijacking attack against Celer Network.

2022-08-20 7 min #Web3 Security
Over a near-black teal-blue background, a mobile wallet app icon leaks mnemonic phrase data streams outward, the Sentry server receiving endpoint highlighted, multiple nodes in the blockchain network topology lit in copper-orange and red — symbolizing the Solana mass theft triggered by Slope Wallet Sentry leaking mnemonic phrases
Security Research

Solana Blockchain Mass Theft Analysis: Slope Wallet Sentry Leaks Mnemonic Phrases

On August 3, 2022, a large-scale theft occurred on the Solana blockchain. Slow Mist Security Team analysis found that Slope Wallet Android >= 2.2.0 sent user mnemonic phrases and private keys to the o7e.slope.finance server via Sentry services, causing the mnemonic phrases of approximately 30% of victim addresses to be leaked.

2022-08-04 4 min #Web3 Security