
Pierre LE BOURHIS
Senior Threat Researcher
Articles byPierre LE BOURHIS

Silver Fox: The Only Tax Audit Where the Fine Print Installs Malware
Track the 2025-2026 shift of China-based Silver Fox from financial crime to APT espionage. Discover how they exploit tax-themed phishing and RMM tools to target South Asian entities.

Advent Of Configuration Extraction – Part 4: Turning capa Into A Configuration Extractor For TinyShell variant
Learn how to extract TinyShell configuration data using capa, Capstone and Python to recover RC4-encrypted C2 settings from Linux malware.

Advent of Configuration Extraction – Part 3: Mapping GOT/PLT and Disassembling the SNOWLIGHT Loader
In-depth analysis of the Snowlight malware loader, focusing on GOT/PLT mapping and ELF disassembly for configuration extraction.

Advent of Configuration Extraction – Part 2: Unwrapping QuasarRAT’s Configuration
Learn how QuasarRAT configuration extraction works using pythonnet, dnlib and IL analysis to recover encrypted .NET malware settings.

Advent of Configuration Extraction – Part 1: Pipeline Overview - First Steps with Kaiji Configuration Unboxing
Learn how TDR automates Kaiji configuration extraction using Assemblyline, introducing the malware analysis pipeline and MACO-based workflows

The Sharp Taste of Mimo'lette: Analyzing Mimo’s Latest Campaign targeting Craft CMS
Analysis of the CVE-2025-32432 compromise chain by Mimo: exploitation, loader, crypto miner, proxyware, and detection opportunities.

ClearFake’s New Widespread Variant: Increased Web3 Exploitation for Malware Delivery
ClearFake is a malicious JavaScript framework deployed on compromised websites to deliver malware through the drive-by download technique. When it first emerged in July 2023, the injected code was designed to display a fake web browser download page,

PikaBot: a Guide to its Deep Secrets and Operations
This blog post provides an in-depth analysis of PikaBot, focusing on its anti-analysis techniques implemented in the different malware stages.

Mallox affiliate leverages PureCrypter in MS-SQL exploitation campaigns
Learn about the techniques used by the Mallox ransomware affiliate to compromise an MS-SQL server. Dive into our detailed technical analysis.

Unveiling the intricacies of DiceLoader
This report aims to detail the functioning of a malware used by FIN7 since 2021, named DiceLoader (also known Icebot), and to provide a comprehensive approach of the threat by detailing the related Techniques and Procedures.

CustomerLoader: a new malware distributing a wide variety of payloads
This blog post aims at presenting a technical analysis of CustomerLoader focusing on the decryption of the next-stage payloads, an overview of more than 30 known and distributed malware families, and details on three infection chains observed distrib
Stealc: a copycat of Vidar and Raccoon infostealers gaining in popularity - Part 2
This blogpost is a technical analysis of Stealc infostealer, detailing different characteristics of the malware, including anti analysis, strings de-obfuscation and C2 communication techniques.

Stealc: a copycat of Vidar and Raccoon infostealers gaining in popularity - Part 1
This blogpost aims at presenting the activities of the Stealc’s alleged developer, a technical analysis of the malware and its C2 communications, and how to track it.

PrivateLoader: the loader of the prevalent ruzki PPI service
SEKOIA analysts tracked PrivateLoader’s network infrastructure for several months and recently conducted an in-depth analysis of the malware. In parallel, we also monitored activities related to the ruzki PPI malware service.

Raccoon Stealer v2 - Part 1: The return of the dead
On June 10, 2022, Sekoia analysts stumbled upon active servers hosting a web page named “Raccoon Stealer 2.0”. Discover their research.

Raccoon Stealer v2 - Part 2: In-depth analysis
This blog post is a technical analysis of the new Raccoon Stealer 2.0 stand-alone version. Authors have announced that the malware is also available in a DLL format or could be embedded in other PE.

BumbleBee: a new trendy loader for Initial Access Brokers
BumbleBee is a new malicious loader that is being used by several IABs to gain an initial foothold within victims' networks

Mars, a red-hot information stealer
Mars Stealer is an information stealer sold on underground forums by MarsTeam since June 22, 2021, with the malware-as-a-service model.




