
Pierre LE BOURHIS
Senior Threat Researcher
Articles by Pierre LE BOURHIS

Don’t eat the ChocoPoCs! How vulnerability researchers were repeatedly targeted by trojanised exploits
This article details a campaign targeting vulnerability researchers with "ChocoPoC" malware embedded inside trojanised Python dependencies. Exploiting the pressure to quickly test new vulnerabilities, threat actors distribute a persistent Remote Access Trojan (RAT) that exfiltrates data and harvests credentials from compromised developer environments.

Silver Fox: The Only Tax Audit Where the Fine Print Installs Malware
Track the 2025-2026 shift of China-based Silver Fox from financial crime to APT espionage. Discover how they exploit tax-themed phishing and RMM tools to target South Asian entities.

Advent Of Configuration Extraction – Part 4: Turning capa Into A Configuration Extractor For TinyShell variant
Learn how to extract TinyShell configuration data using capa, Capstone and Python to recover RC4-encrypted C2 settings from Linux malware.

Advent of Configuration Extraction – Part 3: Mapping GOT/PLT and Disassembling the SNOWLIGHT Loader
In-depth analysis of the Snowlight malware loader, focusing on GOT/PLT mapping and ELF disassembly for configuration extraction.

Advent of Configuration Extraction – Part 2: Unwrapping QuasarRAT’s Configuration
Learn how QuasarRAT configuration extraction works using pythonnet, dnlib and IL analysis to recover encrypted .NET malware settings.

Advent of Configuration Extraction – Part 1: Pipeline Overview - First Steps with Kaiji Configuration Unboxing
Learn how TDR automates Kaiji configuration extraction using Assemblyline, introducing the malware analysis pipeline and MACO-based workflows

The Sharp Taste of Mimo'lette: Analyzing Mimo’s Latest Campaign targeting Craft CMS
Analysis of the CVE-2025-32432 compromise chain by Mimo: exploitation, loader, crypto miner, proxyware, and detection opportunities.

ClearFake’s New Widespread Variant: Increased Web3 Exploitation for Malware Delivery
ClearFake's new variant abuses the Binance Smart Chain and fake CAPTCHAs to deliver malware. A technical analysis of its Web3 evasion and ClickFix infection chain.

PikaBot: a Guide to its Deep Secrets and Operations
This blog post provides an in-depth analysis of PikaBot, focusing on its anti-analysis techniques implemented in the different malware stages.

Mallox affiliate leverages PureCrypter in MS-SQL exploitation campaigns
Learn about the techniques used by the Mallox ransomware affiliate to compromise an MS-SQL server. Dive into our detailed technical analysis.

