Back_To_Operators
Blue Team ONLINE

0x_OLYMPUS

Threat Research Leader

Tracks APT campaigns, dissects malware, and connects the dots between threat actors and their tooling. If there's a pattern, he finds it.

Reverse Engineering APT Tracking Malware Analysis
8 Reports

Intelligence Reports

// AUTHORED BY 0x_OLYMPUS

TOTAL: 8
HIGH
Malware Analysis & Reverse Engineering
2026-04-24

Technical Analysis: UpCrypter Loader Delivering XWorm V5.6 RAT Targeting Brazilian Users

Full chain analysis of a multi-stage campaign delivering XWorm V5.6 via a .NET loader (UpCrypter) disguised as a NF-e lure, with complete static, dynamic, and config extraction.

0x_OLYMPUS
HIGH
Malware Analysis & Reverse Engineering
2026-01-09

Technical Analysis: XWorm v5.6 JavaScript Dropper → Fileless Loader Chain

multi-stage malware infection chain delivering XWorm RAT v5.6 using a JavaScript dropper masquerading as a PDF document

0x_OLYMPUS
CRITICAL
Malware Analysis & Reverse Engineering
2026-01-04

Technical Analysis: EvilSoul1337 Stealer-as-a-Service

Dissecting a Node.js-based Stealer-as-a-Service (SaaS) platform utilizing Electron, Discord Webhooks, and WebSocket C2s targeting gamers.

0x_OLYMPUS
CRITICAL
Threat Hunting
2025-12-21

Active Phishing & PIX Fraud Operation Impersonating Brazilian DETRAN

Impersonation of Brazilian DETRAN (Department of Motor Vehicles).

0x_OLYMPUS
HIGH
Malware Analysis & Reverse Engineering
2025-11-26

Technical Analysis: CS2 Fake Cheat Ransomware

A deep dive into a .NET ransomware distributed as a Counter-Strike 2 'Mod Menu' targeting Brazilian gamers.

0x_OLYMPUS
HIGH
Malware Analysis & Reverse Engineering
2025-11-19

Technical Analysis: WhatsApp Web Automation Worm

Investigation of a Python-based stage that hijacks browser sessions to automate mass malware dissemination via WhatsApp Web.

0x_OLYMPUS
MEDIUM
Malware Analysis & Reverse Engineering
2025-08-24

Malware Campaign: LNK + MSBuild abuse targeting Brazil

Analysis of a campaign distributing malware via .LNK files disguised as DANFE/CFDI invoices, abusing MSBuild to execute fileless payloads.

0x_OLYMPUS
CRITICAL
Cyber Threat Intelligence
2025-04-24

Investigation: Critical IDOR in PIX Payment Gateway

Analysis of a mass phishing campaign mimicking the Postal Service that revealed a massive IDOR in a payment processor, exposing PII and enabling fraud.

0x_OLYMPUS