logo

NightMARE on 0xelm Street, a guided tour

ID: 1ea14d99-853c-5056-9777-f83177d3508a

STIX ID: report--1ea14d99-853c-5056-9777-f83177d3508a

Feed Name: Elastic Security Labs

Threat Score
70/100

Date Published: 2025-10-14

Date Updated: 2026-04-27

...
...

This article presents nightMARE v0.16, a Python library for malware reverse engineering that integrates Rizin and Unicorn, describes its analysis, emulation, and malware modules, and provides a step-by-step example extracting configuration from the LUMMA stealer (locating keys, identifying the decryption routine, emulating ChaCha20-based decryption, and recovering C2 domains and a sample hash).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.