<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>0xD3lta Research</title><description>Offensive and defensive cybersecurity research — Red Team techniques, malware analysis, threat hunting, and more.</description><link>https://0xdelta.org/</link><language>en</language><item><title>Technical Analysis: UpCrypter Loader Delivering XWorm V5.6 RAT Targeting Brazilian Users</title><link>https://0xdelta.org/blog/blue-team/malware-analysis-reverse-engineering/xworm-ucrypter-rat/</link><guid isPermaLink="true">https://0xdelta.org/blog/blue-team/malware-analysis-reverse-engineering/xworm-ucrypter-rat/</guid><description>Full chain analysis of a multi-stage campaign delivering XWorm V5.6 via a .NET loader (UpCrypter) disguised as a NF-e lure, with complete static, dynamic, and config extraction.</description><pubDate>Fri, 24 Apr 2026 00:00:00 GMT</pubDate><category>Blue Team</category><category>Malware Analysis &amp; Reverse Engineering</category><category>XWorm</category><category>RAT</category><category>UpCrypter</category><category>DotNet</category><category>Malware Analysis</category><category>Threat Hunting</category><category>Brazil</category><author>0x_OLYMPUS</author></item><item><title>TheGentlemen Ransomware: Threat Overview and Analysis</title><link>https://0xdelta.org/blog/blue-team/cyber-threat-intelligence/thegentlemen-ransomware-overview/</link><guid isPermaLink="true">https://0xdelta.org/blog/blue-team/cyber-threat-intelligence/thegentlemen-ransomware-overview/</guid><description>Technical overview of TheGentlemen ransomware group, covering its operational model, TTPs, initial access vectors, and defensive considerations.</description><pubDate>Tue, 07 Apr 2026 00:00:00 GMT</pubDate><category>Blue Team</category><category>Cyber Threat Intelligence</category><category>Ransomware</category><category>Threat Intelligence</category><category>Cybersecurity</category><category>TTPs</category><category>Blue Team</category><category>Malware</category><author>ANKHCORP</author></item><item><title>Critical 10.0: Full BI Infrastructure Compromise via Default Credentials</title><link>https://0xdelta.org/blog/red-team/web-security/critical-microstrategy-default-creds/</link><guid isPermaLink="true">https://0xdelta.org/blog/red-team/web-security/critical-microstrategy-default-creds/</guid><description>A detailed write-up on how factory-default credentials on a MicroStrategy administrative panel led to a complete takeover of corporate Business Intelligence assets.</description><pubDate>Wed, 28 Jan 2026 00:00:00 GMT</pubDate><category>Red Team</category><category>Web Security</category><category>Bug Bounty</category><category>Broken Authentication</category><category>MicroStrategy</category><category>Critical</category><category>Administrative Access</category><author>SERROS404</author></item><item><title>Cyrillic Phishing: When a Domain Looks Legit — but Isn’t</title><link>https://0xdelta.org/blog/red-team/offensive-techniques/cyrillic-phishing-homograph-attack/</link><guid isPermaLink="true">https://0xdelta.org/blog/red-team/offensive-techniques/cyrillic-phishing-homograph-attack/</guid><description>An in-depth look at how threat actors abuse Unicode characters in IDN homograph attacks to achieve initial access through phishing.</description><pubDate>Tue, 13 Jan 2026 00:00:00 GMT</pubDate><category>Red Team</category><category>Offensive Techniques</category><category>Red Team</category><category>Initial Access</category><category>Phishing</category><category>Homograph Attack</category><category>Social Engineering</category><category>IDN Abuse</category><author>ANKHCORP</author></item><item><title>Technical Analysis: XWorm v5.6 JavaScript Dropper → Fileless Loader Chain</title><link>https://0xdelta.org/blog/blue-team/malware-analysis-reverse-engineering/xwormrat/</link><guid isPermaLink="true">https://0xdelta.org/blog/blue-team/malware-analysis-reverse-engineering/xwormrat/</guid><description>multi-stage malware infection chain delivering XWorm RAT v5.6 using a JavaScript dropper masquerading as a PDF document</description><pubDate>Fri, 09 Jan 2026 00:00:00 GMT</pubDate><category>Blue Team</category><category>Malware Analysis &amp; Reverse Engineering</category><category>Worm</category><category>DotNet</category><category>RAT</category><category>Malware Analysis</category><category>Reverse Engineering</category><author>0x_OLYMPUS</author></item><item><title>FOSS as a Security Primitive: Why Open Source Is Structurally Superior for Privacy, Integrity, and Trust</title><link>https://0xdelta.org/blog/blue-team/privacy-compliance-officer/foss/</link><guid isPermaLink="true">https://0xdelta.org/blog/blue-team/privacy-compliance-officer/foss/</guid><description>A technical analysis of FOSS as a foundational security control, examining verifiability, attack surface reduction, community auditing, and data sovereignty in contrast to the trust-based failures of proprietary software.</description><pubDate>Thu, 08 Jan 2026 00:00:00 GMT</pubDate><category>Blue Team</category><category>Privacy Compliance Officer</category><category>FOSS</category><category>Open Source</category><category>Privacy</category><category>Security Engineering</category><category>Threat Modeling</category><category>Trust Model</category><author>SPECIEUNKN0WN_</author></item><item><title>Threat Actor Profile: Midia22</title><link>https://0xdelta.org/blog/blue-team/threat-hunting/midia22/</link><guid isPermaLink="true">https://0xdelta.org/blog/blue-team/threat-hunting/midia22/</guid><description>A investigation of Midia22, a Brazilian Initial Access Broker operating across government systems and Telegram cybercrime channels.</description><pubDate>Tue, 06 Jan 2026 00:00:00 GMT</pubDate><category>Blue Team</category><category>Threat Hunting</category><category>Threat Actor</category><category>Initial Access Broker</category><category>Threat Group</category><category>OSINT</category><category>Cybercrime</category><author>VAMPIR3BLUES</author></item><item><title>Technical Analysis: EvilSoul1337 Stealer-as-a-Service</title><link>https://0xdelta.org/blog/blue-team/malware-analysis-reverse-engineering/evilsoul1337/</link><guid isPermaLink="true">https://0xdelta.org/blog/blue-team/malware-analysis-reverse-engineering/evilsoul1337/</guid><description>Dissecting a Node.js-based Stealer-as-a-Service (SaaS) platform utilizing Electron, Discord Webhooks, and WebSocket C2s targeting gamers.</description><pubDate>Sun, 04 Jan 2026 00:00:00 GMT</pubDate><category>Blue Team</category><category>Malware Analysis &amp; Reverse Engineering</category><category>Stealer</category><category>NodeJS</category><category>Electron</category><category>Discord</category><category>Malware Analysis</category><category>SaaS</category><author>0x_OLYMPUS</author></item><item><title>Abusing WhatsApp Desktop for Initial Access: Python ZipApp Reverse Shell</title><link>https://0xdelta.org/blog/red-team/offensive-techniques/whatsapp-pyz-reverseshell/</link><guid isPermaLink="true">https://0xdelta.org/blog/red-team/offensive-techniques/whatsapp-pyz-reverseshell/</guid><description>A technical analysis of how .pyz files can be used to bypass protections and establish a Reverse Shell via WhatsApp Desktop.</description><pubDate>Fri, 26 Dec 2025 00:00:00 GMT</pubDate><category>Red Team</category><category>Offensive Techniques</category><category>Red Team</category><category>Initial Access</category><category>Python</category><category>Evasion</category><category>Social Engineering</category><author>SERROS404</author></item><item><title>Active Phishing &amp; PIX Fraud Operation Impersonating Brazilian DETRAN</title><link>https://0xdelta.org/blog/blue-team/threat-hunting/detranpixfraud/</link><guid isPermaLink="true">https://0xdelta.org/blog/blue-team/threat-hunting/detranpixfraud/</guid><description>Impersonation of Brazilian DETRAN (Department of Motor Vehicles).</description><pubDate>Sun, 21 Dec 2025 00:00:00 GMT</pubDate><category>Blue Team</category><category>Threat Hunting</category><category>Phishing</category><category>Fraud</category><category>Pix</category><category>Financial Fraud</category><category>Data Exposure</category><author>0x_OLYMPUS</author></item><item><title>Technical Analysis: CS2 Fake Cheat Ransomware</title><link>https://0xdelta.org/blog/blue-team/malware-analysis-reverse-engineering/cs2-ransomware/</link><guid isPermaLink="true">https://0xdelta.org/blog/blue-team/malware-analysis-reverse-engineering/cs2-ransomware/</guid><description>A deep dive into a .NET ransomware distributed as a Counter-Strike 2 &apos;Mod Menu&apos; targeting Brazilian gamers.</description><pubDate>Wed, 26 Nov 2025 00:00:00 GMT</pubDate><category>Blue Team</category><category>Malware Analysis &amp; Reverse Engineering</category><category>Ransomware</category><category>DotNet</category><category>CS2</category><category>Malware Analysis</category><category>Reverse Engineering</category><author>0x_OLYMPUS</author></item><item><title>Technical Analysis: WhatsApp Web Automation Worm</title><link>https://0xdelta.org/blog/blue-team/malware-analysis-reverse-engineering/whatsapp-automation-worm/</link><guid isPermaLink="true">https://0xdelta.org/blog/blue-team/malware-analysis-reverse-engineering/whatsapp-automation-worm/</guid><description>Investigation of a Python-based stage that hijacks browser sessions to automate mass malware dissemination via WhatsApp Web.</description><pubDate>Wed, 19 Nov 2025 00:00:00 GMT</pubDate><category>Blue Team</category><category>Malware Analysis &amp; Reverse Engineering</category><category>WhatsApp</category><category>Worm</category><category>Selenium</category><category>Session Hijacking</category><category>Python</category><category>C2</category><author>0x_OLYMPUS</author></item><item><title>Malware Campaign: LNK + MSBuild abuse targeting Brazil</title><link>https://0xdelta.org/blog/blue-team/malware-analysis-reverse-engineering/lnk-msbuild-campaign/</link><guid isPermaLink="true">https://0xdelta.org/blog/blue-team/malware-analysis-reverse-engineering/lnk-msbuild-campaign/</guid><description>Analysis of a campaign distributing malware via .LNK files disguised as DANFE/CFDI invoices, abusing MSBuild to execute fileless payloads.</description><pubDate>Sun, 24 Aug 2025 00:00:00 GMT</pubDate><category>Blue Team</category><category>Malware Analysis &amp; Reverse Engineering</category><category>LNK</category><category>MSBuild</category><category>Fileless</category><category>Rubeus</category><category>LOLBIN</category><category>GhostBuild</category><author>0x_OLYMPUS</author></item><item><title>Cybersecurity Essentials: Understanding Risks &amp; Defense Stack</title><link>https://0xdelta.org/blog/blue-team/detection-engineering/cybersecurity-essentials/</link><guid isPermaLink="true">https://0xdelta.org/blog/blue-team/detection-engineering/cybersecurity-essentials/</guid><description>A comprehensive guide on modern cyber risks, APTs, and the essential toolset for defensive operations—from Vulnerability Management to IAM.</description><pubDate>Thu, 01 May 2025 00:00:00 GMT</pubDate><category>Blue Team</category><category>Detection Engineering</category><category>Blue Team</category><category>Hardening</category><category>Tools</category><category>IAM</category><category>Network Security</category><author>SPECIEUNKN0WN_</author></item><item><title>Investigation: Critical IDOR in PIX Payment Gateway</title><link>https://0xdelta.org/blog/blue-team/cyber-threat-intelligence/pix-gateway-idor/</link><guid isPermaLink="true">https://0xdelta.org/blog/blue-team/cyber-threat-intelligence/pix-gateway-idor/</guid><description>Analysis of a mass phishing campaign mimicking the Postal Service that revealed a massive IDOR in a payment processor, exposing PII and enabling fraud.</description><pubDate>Thu, 24 Apr 2025 00:00:00 GMT</pubDate><category>Blue Team</category><category>Cyber Threat Intelligence</category><category>IDOR</category><category>Fraud</category><category>PIX</category><category>BurpSuite</category><category>Data Leak</category><category>Phishing</category><author>0x_OLYMPUS</author></item></channel></rss>