> WHOAMI
Forged by offensive and defensive practitioners, 0xDelta Research focuses on the real mechanics of modern intrusions. We work in the environments where attacks unfold for real.
By blending offensive insight with defensive precision, we convert adversary tradecraft into reliable, high-impact protection.
"If you're looking for marketing-safe security, we're not it."
Latest Intelligence
[ DECLASSIFIED_REPORTS ]
Fake DocuSign / DANFE-NFe Phishing Campaign Delivering an HVNC-Capable Windows Backdoor
End-to-end reconstruction of a four-stage Brazilian phishing chain — fake DocuSign/NFe lure, LNK/PowerShell dropper, NSIS loader — delivering a custom HVNC backdoor with keylogging and Firefox artifact theft over raw-TCP C2.
Hardcoded App Key: Unauthenticated Remote Config Exposure and Data Poisoning in a Mobility Android App
A hardcoded app key inside an analytics SDK exposed feature flags and allowed arbitrary event injection in an Android fleet-management app — with zero authentication.
Dissecting IDOR: When Hidden Resources Are Still Accessible Through the API
A practical breakdown of Insecure Direct Object Reference (IDOR) — theory, a real-world private-album API case study, comparison with other disclosed reports, and detection/mitigation strategies.