G2 Logo

Trouble Brewing - Dissecting a fake homebrew update that stole user data

By Oliver Simonnet, Lead Cyber Security Researcher at CultureAI

Table of contents

  • Preamble
  • Malvertising - Effective and on the rise
  • Looking at the install command
  • Reverse engineering the payload
  • Reversing the decoding function:
  • Reversing the decryption function
  • Decoding the second stage payload:
  • Conclusion
  • Indicators of Compromise (IoCs)
  • References
Oliver Simonnet avatar

Oliver Simonnet

Lead Security Researcher

10 March 20258 min read
Share:

Recommended for you

[object Object]

The Back Room Problem: Why Most Organisations Lack AI Data Visibility

It’s that time of year when shadows feel a little longer and the unknown a little closer. But in most organisations, the...

[object Object]

A January Snapshot: Real-World AI Usage

This snapshot from CultureAI’s January usage data highlights how AI is actually being used across everyday workflows, an...

[object Object]

CultureAI Joins Microsoft’s Agentic Launchpad: What This Means for the Future of AI Usage Control

We’re excited to share that CultureAI has been selected by Microsoft, in collaboration with NVIDIA and WeTransact, as on...