Today the FSB (Federal Security Service of the Russian Federation) released a statement stating that the United States government has targeted, and infected, thousands of Russians that were using Apple iPhones devices.
More information: fsb.ru/fsb/press/message/sin…
Added syscall number resolver which uses initial process.
To avoid bypass AV/EDR hooking, this PoC creates a suspended initial process by NtCreateUserProcess API and resolve syscall number from it.
github.com/daem0nc0re/Atomic…
Probably one of the more interesting projects I am learning this evening.
PowerLessShell rely on MSBuild.exe to remotely execute PowerShell scripts and commands without spawning powershell.exe. You can also execute raw shellcode using the same approach.
github.com/Mr-Un1k0d3r/Power…