G2 Logo

Trouble Brewing - Dissecting a fake homebrew update that stole user data

By Oliver Simonnet, Lead Cyber Security Researcher at CultureAI

Table of contents

  • Preamble
  • Malvertising - Effective and on the rise
  • Looking at the install command
  • Reverse engineering the payload
  • Reversing the decoding function:
  • Reversing the decryption function
  • Decoding the second stage payload:
  • Conclusion
  • Indicators of Compromise (IoCs)
  • References
Oliver Simonnet avatar

Oliver Simonnet

Lead Security Researcher

10 March 20258 min read
Share:

Recommended for you

[object Object]

Microsoft Marketplace: CultureAI Now Available

Microsoft’s Agentic Launchpad, in collaboration with NVIDIA and WeTransact, reflects that shift. It brings together a gr...

[object Object]

The Beginning of a New Norm

The recent breach at Vercel has drawn a lot of attention, not because the initial entry point was unusual, but because o...

[object Object]

CultureAI Launches Global Partner Program to Power Secure AI Adoption at Scale

Today, we’re excited to announce the launch of the CultureAI Partner Program, a global, channel-first initiative designe...