G2 Logo

Trouble Brewing - Dissecting a fake homebrew update that stole user data

By Oliver Simonnet, Lead Cyber Security Researcher at CultureAI

Table of contents

  • Preamble
  • Malvertising - Effective and on the rise
  • Looking at the install command
  • Reverse engineering the payload
  • Reversing the decoding function:
  • Reversing the decryption function
  • Decoding the second stage payload:
  • Conclusion
  • Indicators of Compromise (IoCs)
  • References
Oliver Simonnet avatar

Oliver Simonnet

Lead Security Researcher

10 March 20258 min read
Share:

Recommended for you

[object Object]

Scattered Spider and DragonForce: A Case Study in Human-Centric Cyber Threats

In April 2025, large retailers were targeted by cyber attacks that caused disruption across their services. Although att...

[object Object]

The AI Hunger Games: The Rapid Adoption of DeepSeek: A Security Nightmare

With AI technologies evolving at an unprecedented pace, are we truly prepared to handle the security challenges they pos...

[object Object]

Introducing The Human Threat Map: Mapping and Defending the Human Perimeter

To help organisations understand and contextualise how human behaviours create risks and enable threats we have released...