G2 Logo

Trouble Brewing - Dissecting a fake homebrew update that stole user data

By Oliver Simonnet, Lead Cyber Security Researcher at CultureAI

Table of contents

  • Preamble
  • Malvertising - Effective and on the rise
  • Looking at the install command
  • Reverse engineering the payload
  • Reversing the decoding function:
  • Reversing the decryption function
  • Decoding the second stage payload:
  • Conclusion
  • Indicators of Compromise (IoCs)
  • References
Oliver Simonnet avatar

Oliver Simonnet

Lead Security Researcher

10 March 20258 min read
Share:

Recommended for you

[object Object]

CultureAI Partners with Highgate IT Solutions

CultureAI, the AI Usage Control Platform, today announced a strategic partnership with Highgate IT Solutions, a UK-based...

[object Object]

5 Themes From a Candid Discussion

Eskenzi's IT Analyst & CISO Forum wasn’t a typical vendor event. No polished decks. No rehearsed narratives. Just operat...

[object Object]

The AI Control Gap: Why Partners Are Now on the Front Line

Partners who move early can shape how customers think about AI governance, risk, and control. Those who wait will be bro...