> WHOAMI
Forged by offensive and defensive practitioners, 0xD3lta Research focuses on the real mechanics of modern intrusions. We work in the environments where attacks unfold for real.
By blending offensive insight with defensive precision, we convert adversary tradecraft into reliable, high-impact protection.
"If you're looking for marketing-safe security, we're not it."
Latest Intelligence
[ DECLASSIFIED_REPORTS ]
Technical Analysis: ValleyRAT Delivered via Trojanized DingTalk Downloader and NVIDIA DLL Sideloading
A deep dive into a ValleyRAT (Silver Fox / Winos4.0 cluster) infection chain abusing a legitimately signed NVIDIA binary for DLL sideloading, culminating in process injection and a WebSocket-based C2 channel.
Operational Security Analysis: Mass Surveillance Mitigation via Mullvad VPN
SecOps analysis of Mullvad's anonymity model — identity decoupling, RAM-only infrastructure, System Transparency (stboot), and zero-retention architecture.
Technical Analysis: UpCrypter Loader Delivering XWorm V5.6 RAT Targeting Brazilian Users
Full chain analysis of a multi-stage campaign delivering XWorm V5.6 via a .NET loader (UpCrypter) disguised as a NF-e lure, with complete static, dynamic, and config extraction.
Core Operators
[ UNIT_MEMBERS ]