Log inSign up
Joe Security
1,131 posts
Joe Security profile banner
@joe4security

Joe Security

@joe4security
Deep Malware and Phishing Analysis for Windows, Android, macOS and Linux.
Switzerland
joesecurity.org
Joined August 2010
136
Following
7,929
Followers
RepliesRepliesRepostsRepostsMediaMedia

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
  • Pinned
    @joe4security
    Joe Security
    @joe4security
    May 26
    Really nice paper on defeating evasive malware - huge kudos to the authors 👏🔥 In a nutshell: They use AI-generated instruction-skip YARA rules to automatically bypass evasions inside CAPE and expose hidden malware behavior 🤯 Also interesting: Joe Sandbox came out as the
    2
  • @joe4security
    Joe Security
    @joe4security
    Aug 27
    🚨 Watchout ChatGPT Shared Conversation abused to deliver NetSupport via ClickFix A legitimate chatgpt.com shared-conversation page is used to funnel visitors to the fake openai-backup[.]one site under a false high-traffic pretext. 🎭 The site impersonates OpenAI,
    7
  • @joe4security
    Joe Security
    @joe4security
    Aug 25
    🚨 New malware research: ToxNetV2 - an AI-Assisted Botnet Controller 🤖🦠 🔬 Joe Reverser uncovered how an P2P botnet integrates NVIDIA NIM with GLM-5.2 directly into its operational workflow - turning telemetry into AI-generated structured actions, with an operator approval
  • @joe4security
    Joe Security
    @joe4security
    Aug 13
    🚨🍎 macOS Malware Alert Joe Reverser analysis flags a 10/10 malicious Rust-based macOS Hybrid Stealer 🦠 🔐 Targets browser creds, cookies & Keychain 🍪 Safari/Chromium data theft 📱 Telegram & Apple Notes 💰 Crypto-wallet artifacts 🛡️ TCC/Full Disk Access bypass 📡 C2 bot +
    3
  • @joe4security
    Joe Security
    @joe4security
    Aug 11
    🚨 New Research: Google Phishing Kit – When Phishing Becomes a Real-Time Remote Browser 🎭🌐 This isn't your typical phishing page. We analyzed a sophisticated Browser-in-the-Middle (BitM) kit that streams Google's authentication flow in real time via Socket.IO,
    5