NightMARE on 0xelm Street, a guided tour
ID: 1ea14d99-853c-5056-9777-f83177d3508a
STIX ID: report--1ea14d99-853c-5056-9777-f83177d3508a
Feed Name: Elastic Security Labs
Threat Score
This article presents nightMARE v0.16, a Python library for malware reverse engineering that integrates Rizin and Unicorn, describes its analysis, emulation, and malware modules, and provides a step-by-step example extracting configuration from the LUMMA stealer (locating keys, identifying the decryption routine, emulating ChaCha20-based decryption, and recovering C2 domains and a sample hash).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
