G2 Logo

Trouble Brewing - Dissecting a fake homebrew update that stole user data

By Oliver Simonnet, Lead Cyber Security Researcher at CultureAI

Table of contents

  • Preamble
  • Malvertising - Effective and on the rise
  • Looking at the install command
  • Reverse engineering the payload
  • Reversing the decoding function:
  • Reversing the decryption function
  • Decoding the second stage payload:
  • Conclusion
  • Indicators of Compromise (IoCs)
  • References
Oliver Simonnet avatar

Oliver Simonnet

Lead Security Researcher

10 March 20258 min read
Share:

Recommended for you

[object Object]

Securing AI in the Enterprise: Facilitating Innovation whilst Securing Adoption

This article explores the double-edged sword that is enterprise AI, the huge benefits it offers and the significant risk...

[object Object]

Empowering Safe GenAI Adoption at a 3,600-Employee Fintech

Learn how a global fintech company stopped over 20 sensitive data leaks to GenAI tools daily—without blocking innovation...

[object Object]

You're Not My Supervisor! Researching My Own New Starter Scam

Within weeks of stepping into a new role, I found myself receiving multiple phishing emails impersonating our CEO. Rathe...