<feed xmlns="http://www.w3.org/2005/Atom"> <id>https://0xsec1.github.io/</id><title>0xSec</title><subtitle>ctfplayer, infosec, blog, redteamer </subtitle> <updated>2026-04-29T06:34:08+00:00</updated> <author> <name>0xSec</name> <uri>https://0xsec1.github.io/</uri> </author><link rel="self" type="application/atom+xml" href="https://0xsec1.github.io/feed.xml"/><link rel="alternate" type="text/html" hreflang="en" href="https://0xsec1.github.io/"/> <generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator> <rights> © 2026 0xSec </rights> <icon>/assets/img/favicons/favicon.ico</icon> <logo>/assets/img/favicons/favicon-96x96.png</logo> <entry><title>MT7902: A Complete WiFi &amp; Bluetooth Guide for Arch and Fedora</title><link href="https://0xsec1.github.io/posts/mt7902_installation_guide/" rel="alternate" type="text/html" title="MT7902: A Complete WiFi &amp;amp; Bluetooth Guide for Arch and Fedora" /><published>2026-04-29T00:00:00+00:00</published> <updated>2026-04-29T00:00:00+00:00</updated> <id>https://0xsec1.github.io/posts/mt7902_installation_guide/</id> <content type="text/html" src="https://0xsec1.github.io/posts/mt7902_installation_guide/" /> <author> <name>0xSec</name> </author> <category term="Linux" /> <summary>Introduction Figure: MT7902 Linux Patch If you have a laptop (mine is Asus Vivobook go 15) with the MediaTek MT7902 network card, you already know the struggle for its driver support. Native support for this chip is missing from the mainline Linux kernel (at least until Linux 7.x drops). Out of the box, you get no WiFi and no Bluetooth in order to get your internet working either you have to ...</summary> </entry> <entry><title>RustyWater: Reverse Engineering MuddyWater’s Rust Toolkit</title><link href="https://0xsec1.github.io/posts/rustyWater/" rel="alternate" type="text/html" title="RustyWater: Reverse Engineering MuddyWater’s Rust Toolkit" /><published>2026-04-23T00:00:00+00:00</published> <updated>2026-04-23T00:00:00+00:00</updated> <id>https://0xsec1.github.io/posts/rustyWater/</id> <content type="text/html" src="https://0xsec1.github.io/posts/rustyWater/" /> <author> <name>0xSec</name> </author> <category term="Malware" /> <summary>Overview The MuddyWater attacks are primarily against Middle Eastern nations. However, its also observed attacks against surrounding nations and beyond, including targets in India and the USA. MuddyWater attacks are characterized by the use of a slowly evolving PowerShell-based first stage backdoor we call “POWERSTATS”. Despite broad scrutiny and reports on MuddyWater attacks, the activity cont...</summary> </entry> <entry><title>AppDomain Hijacking: Analyzing a LNK malware</title><link href="https://0xsec1.github.io/posts/lnk_malware/" rel="alternate" type="text/html" title="AppDomain Hijacking: Analyzing a LNK malware" /><published>2026-03-04T00:00:00+00:00</published> <updated>2026-03-04T09:01:12+00:00</updated> <id>https://0xsec1.github.io/posts/lnk_malware/</id> <content type="text/html" src="https://0xsec1.github.io/posts/lnk_malware/" /> <author> <name>0xSec</name> </author> <category term="Malware" /> <summary>Overview Windows shortcut files use the .lnk file extension and function as a virtual link that allows people to easily access other files without having to navigate through multiple folders on a Windows host. The flexibility of LNK files makes them a powerful tool for attackers, as they can both execute malicious content and masquerade as legitimate files to deceive victims into unintentionall...</summary> </entry> <entry><title>Operation Ghazwa: Disecting APT36's RAT</title><link href="https://0xsec1.github.io/posts/apt36/" rel="alternate" type="text/html" title="Operation Ghazwa: Disecting APT36&amp;apos;s RAT" /><published>2026-02-11T00:00:00+00:00</published> <updated>2026-02-11T07:26:59+00:00</updated> <id>https://0xsec1.github.io/posts/apt36/</id> <content type="text/html" src="https://0xsec1.github.io/posts/apt36/" /> <author> <name>0xSec</name> </author> <category term="Malware" /> <summary>Overview Operation C-Major aka: APT 36, APT36, C-Major, COPPER FIELDSTONE, Earth Karkaddan, Green Havildar, Mythic Leopard, ProjectM, Storm-0156, TMP.Lapis, Transparent Tribe Group targeting Indian Army or related assets in India, as well as activists and civil society in Pakistan. Attribution to a Pakistani connection has been made by TrendMicro and others. Technical Analysis After getting a...</summary> </entry> <entry><title>Analysis of GonePostal: APT28’s Custom VBA Backdoor for Microsoft Outlook</title><link href="https://0xsec1.github.io/posts/gonepostal/" rel="alternate" type="text/html" title="Analysis of GonePostal: APT28’s Custom VBA Backdoor for Microsoft Outlook" /><published>2026-02-09T00:00:00+00:00</published> <updated>2026-02-09T20:30:23+00:00</updated> <id>https://0xsec1.github.io/posts/gonepostal/</id> <content type="text/html" src="https://0xsec1.github.io/posts/gonepostal/" /> <author> <name>0xSec</name> </author> <category term="Malware" /> <summary>Overview KTA007, also known as Fancy Bear, APT28, and Pawn Storm, is a state sponsored political and economic espionage group associated with the Russian Military’s Main Intelligence Directorate (GRU) Unit 26165. The group has been implicated in several high-profile cyberattacks such as the 2016 Democratic National Committee breach, the International Olympic Committee, the Norwegian Parliament ...</summary> </entry> </feed>
