Back_To_Operators
Blue Team ONLINE

0x_OLYMPUS

Threat Research Leader

Leads threat research. Reverse engineering, APT campaign tracking, and malware analysis, mapping threat-actor tooling and infrastructure.

Reverse Engineering APT Tracking Malware Analysis
9 Reports

Intelligence Reports

// AUTHORED BY 0x_OLYMPUS

TOTAL: 9
HIGH
Malware Analysis & Reverse Engineering
2026-07-17

Technical Analysis: ValleyRAT Delivered via Trojanized DingTalk Downloader and NVIDIA DLL Sideloading

A deep dive into a ValleyRAT (Silver Fox / Winos4.0 cluster) infection chain abusing a legitimately signed NVIDIA binary for DLL sideloading, culminating in process injection and a WebSocket-based C2 channel.

0x_OLYMPUS
HIGH
Malware Analysis & Reverse Engineering
2026-04-26

Technical Analysis: UpCrypter Loader Delivering XWorm V5.6 RAT Targeting Brazilian Users

Full chain analysis of a multi-stage campaign delivering XWorm V5.6 via a .NET loader (UpCrypter) disguised as a NF-e lure, with complete static, dynamic, and config extraction.

0x_OLYMPUS
HIGH
Malware Analysis & Reverse Engineering
2026-01-11

Technical Analysis: XWorm v5.6 JavaScript Dropper → Fileless Loader Chain

multi-stage malware infection chain delivering XWorm RAT v5.6 using a JavaScript dropper masquerading as a PDF document

0x_OLYMPUS
CRITICAL
Malware Analysis & Reverse Engineering
2026-01-04

Technical Analysis: EvilSoul1337 Stealer-as-a-Service

Dissecting a Node.js-based Stealer-as-a-Service (SaaS) platform utilizing Electron, Discord Webhooks, and WebSocket C2s targeting gamers.

0x_OLYMPUS
CRITICAL
Threat Hunting
2026-01-04

Active Phishing & PIX Fraud Operation Impersonating Brazilian DETRAN

Impersonation of Brazilian DETRAN (Department of Motor Vehicles).

0x_OLYMPUS
HIGH
Malware Analysis & Reverse Engineering
2025-12-22

Technical Analysis: CS2 Fake Cheat Ransomware

A deep dive into a .NET ransomware distributed as a Counter-Strike 2 'Mod Menu' targeting Brazilian gamers.

0x_OLYMPUS
HIGH
Malware Analysis & Reverse Engineering
2025-12-22

Technical Analysis: WhatsApp Web Automation Worm

Investigation of a Python-based stage that hijacks browser sessions to automate mass malware dissemination via WhatsApp Web.

0x_OLYMPUS
MEDIUM
Malware Analysis & Reverse Engineering
2025-12-22

Malware Campaign: LNK + MSBuild abuse targeting Brazil

Analysis of a campaign distributing malware via .LNK files disguised as DANFE/CFDI invoices, abusing MSBuild to execute fileless payloads.

0x_OLYMPUS
CRITICAL
Cyber Threat Intelligence
2025-12-22

Investigation: Critical IDOR in PIX Payment Gateway

Analysis of a mass phishing campaign mimicking the Postal Service that revealed a massive IDOR in a payment processor, exposing PII and enabling fraud.

0x_OLYMPUS