[{"content":"Article Summary # This article addresses the needs of job seekers aiming for penetration testing positions by curating 20 real-world projects spanning entry‑level to expert‑level scenarios. It emphasises applying the STAR method (Situation, Task, Action, Result) and quantifying achievements to enhance resume competitiveness. Core points include: Entry‑level projects such as open‑source CMS …","date":"April 24, 2026","permalink":"/posts/2026/20260424113800/","section":"Diary","summary":"","title":"20 Penetration Testing Projects Worth Adding to Your Resume"},{"content":"Article Summary: A proxy software development kit (SDK) named Popa has been exposed, capable of transforming mobile phones, TV boxes, and other devices into residential proxy network nodes. The SDK is distributed through pirated applications, counterfeit boxes, and bundled installations across Android and Windows platforms. Its operations are highly stealthy, employing dynamic configuration to …","date":"July 23, 2026","permalink":"/posts/2026/20260723220000/","section":"Diary","summary":"","title":"Exposure of a Botnet Linked to an Israeli Listed Company"},{"content":"Executive Summary # FortiGuard Labs has identified a sophisticated multi-stage attack campaign attributed to the North Korea-linked threat actor Kimsuky. The group is abusing GitHub as a living-off-the-land Command and Control (C2) infrastructure to target South Korean organizations.\nThe attack chain starts with obfuscated Windows Shortcut (LNK) files delivered via phishing emails. These LNK files …","date":"April 8, 2026","permalink":"/posts/2026/20260408190100/","section":"Diary","summary":"","title":"North Korea-Linked Hackers Use GitHub as C2 Infrastructure to Attack South Korea"},{"content":"Notable Changes Observed in Malicious LNK Files Distributed by Kimsuky Group # Article Summary: The North Korean Kimsuky hacker group recently used malicious LNK files disguised as HWP documents to launch multi-stage attacks. They extended the attack chain by adding intermediate stages such as XML, VBS, and PS1 files to evade detection. The attack creates hidden folders, registers scheduled tasks …","date":"April 13, 2026","permalink":"/posts/2026/20260413204700/","section":"Diary","summary":"","title":"Kimsuky Deploys Malicious LNK Files to Implant Python-Based Backdoor in Multi-Stage Attack"},{"content":"In early 2026, Israel\u0026rsquo;s National Cyber Directorate disclosed critical threat intelligence: the Iranian state-sponsored APT42 group is leveraging a PowerShell backdoor named TAMECAT to conduct precision espionage attacks against defense officials and core government personnel across multiple nations.\nThis malicious software operates as an \u0026ldquo;invisible spy\u0026rdquo;—it writes nothing to disk, …","date":"April 28, 2026","permalink":"/posts/2026/20260428220000/","section":"Diary","summary":"","title":"TAMECAT: APT42's New PowerShell Backdoor Targeting Military and Government Officials"},{"content":"Article Summary: This article systematically elaborates on the technical evolution and implementation principles of self-mutating malware, covering the core mechanisms of polymorphic and metamorphic engines. Through two concrete examples — Veil64 and Morpheus — the author \u0026ldquo;f00crew\u0026rdquo; from Hong Kong China, analyzes key techniques such as register randomization, algorithmic variants, and …","date":"April 11, 2026","permalink":"/posts/2026/20260411133500/","section":"Diary","summary":"","title":"The Art of Self-Mutating Malware"},{"content":"","date":null,"permalink":"/categories/","section":"Categories","summary":"","title":"Categories"},{"content":"","date":null,"permalink":"/tags/counter-intelligence/","section":"Tags","summary":"","title":"Counter-Intelligence"},{"content":"All diary entries will be shown here.\n","date":null,"permalink":"/posts/","section":"Diary","summary":"","title":"Diary"},{"content":"","date":null,"permalink":"/tags/economic-security/","section":"Tags","summary":"","title":"Economic-Security"},{"content":"","date":null,"permalink":"/tags/humint/","section":"Tags","summary":"","title":"Humint"},{"content":"Article Summary:\nThis in-depth analysis examines recently disclosed operational methods employed by Japanese law enforcement agencies to counter industrial espionage, focusing on the systematic use of \u0026ldquo;chance encounters\u0026rdquo; to identify and develop informants. The piece dissects the techniques used to target employees of technology-focused enterprises, including the …","date":"August 30, 2026","permalink":"/posts/2026/20260817230700/","section":"Diary","summary":"","title":"In-depth Assessment: Japanese Police Disclosure of 'Chance Encounter' Recruitment of Industrial Espionage Informants – Risk Warning for Enterprises and Personnel in Japan"},{"content":"","date":null,"permalink":"/tags/industrial-espionage/","section":"Tags","summary":"","title":"Industrial-Espionage"},{"content":"","date":null,"permalink":"/tags/japan/","section":"Tags","summary":"","title":"Japan"},{"content":"","date":null,"permalink":"/tags/osint/","section":"Tags","summary":"","title":"Osint"},{"content":"","date":null,"permalink":"/tags/risk-assessment/","section":"Tags","summary":"","title":"Risk-Assessment"},{"content":"","date":null,"permalink":"/tags/","section":"Tags","summary":"","title":"Tags"},{"content":"","date":null,"permalink":"/categories/threat-intelligence/","section":"Categories","summary":"","title":"Threat Intelligence"},{"content":"A digital garden documenting cybersecurity, humanities and social sciences analysis, as well as daily life.\n","date":null,"permalink":"/","section":"Welcome","summary":"","title":"Welcome"},{"content":"","date":null,"permalink":"/tags/ai-scraping/","section":"Tags","summary":"","title":"Ai-Scraping"},{"content":"","date":null,"permalink":"/tags/alarum-technologies/","section":"Tags","summary":"","title":"Alarum-Technologies"},{"content":"","date":null,"permalink":"/tags/android-malware/","section":"Tags","summary":"","title":"Android-Malware"},{"content":"","date":null,"permalink":"/tags/botnet/","section":"Tags","summary":"","title":"Botnet"},{"content":"","date":null,"permalink":"/tags/malware-analysis/","section":"Tags","summary":"","title":"Malware-Analysis"},{"content":"","date":null,"permalink":"/tags/netnut/","section":"Tags","summary":"","title":"Netnut"},{"content":"","date":null,"permalink":"/tags/neunative/","section":"Tags","summary":"","title":"Neunative"},{"content":"","date":null,"permalink":"/tags/popa/","section":"Tags","summary":"","title":"Popa"},{"content":"","date":null,"permalink":"/tags/proxy-network/","section":"Tags","summary":"","title":"Proxy-Network"},{"content":"","date":null,"permalink":"/tags/residential-proxy/","section":"Tags","summary":"","title":"Residential-Proxy"},{"content":"","date":null,"permalink":"/tags/sdk/","section":"Tags","summary":"","title":"Sdk"},{"content":"","date":null,"permalink":"/tags/threat-intelligence/","section":"Tags","summary":"","title":"Threat-Intelligence"},{"content":"","date":null,"permalink":"/tags/vo1d-botnet/","section":"Tags","summary":"","title":"Vo1d-Botnet"},{"content":"","date":null,"permalink":"/tags/windows-sdk/","section":"Tags","summary":"","title":"Windows-Sdk"},{"content":"","date":null,"permalink":"/tags/apt42/","section":"Tags","summary":"","title":"Apt42"},{"content":"","date":null,"permalink":"/tags/cyberwarfare/","section":"Tags","summary":"","title":"Cyberwarfare"},{"content":"","date":null,"permalink":"/tags/espionage/","section":"Tags","summary":"","title":"Espionage"},{"content":"","date":null,"permalink":"/tags/fileless-malware/","section":"Tags","summary":"","title":"Fileless-Malware"},{"content":"","date":null,"permalink":"/tags/incident-response/","section":"Tags","summary":"","title":"Incident-Response"},{"content":"","date":null,"permalink":"/tags/iran/","section":"Tags","summary":"","title":"Iran"},{"content":"","date":null,"permalink":"/tags/lnk/","section":"Tags","summary":"","title":"Lnk"},{"content":"","date":null,"permalink":"/tags/nation-state/","section":"Tags","summary":"","title":"Nation-State"},{"content":"","date":null,"permalink":"/tags/phishing/","section":"Tags","summary":"","title":"Phishing"},{"content":"","date":null,"permalink":"/tags/powershell/","section":"Tags","summary":"","title":"Powershell"},{"content":"","date":null,"permalink":"/tags/tamecat/","section":"Tags","summary":"","title":"Tamecat"},{"content":"","date":null,"permalink":"/tags/telegram-c2/","section":"Tags","summary":"","title":"Telegram-C2"},{"content":"","date":null,"permalink":"/tags/vbscript/","section":"Tags","summary":"","title":"Vbscript"},{"content":"","date":null,"permalink":"/tags/career/","section":"Tags","summary":"","title":"Career"},{"content":"","date":null,"permalink":"/tags/ctf/","section":"Tags","summary":"","title":"Ctf"},{"content":"","date":null,"permalink":"/tags/cybersecurity/","section":"Tags","summary":"","title":"Cybersecurity"},{"content":"","date":null,"permalink":"/tags/hands-on/","section":"Tags","summary":"","title":"Hands-On"},{"content":"","date":null,"permalink":"/tags/lab-setup/","section":"Tags","summary":"","title":"Lab-Setup"},{"content":"","date":null,"permalink":"/categories/penetration-testing/","section":"Categories","summary":"","title":"Penetration Testing"},{"content":"","date":null,"permalink":"/tags/penetration-testing/","section":"Tags","summary":"","title":"Penetration-Testing"},{"content":"","date":null,"permalink":"/tags/portfolio/","section":"Tags","summary":"","title":"Portfolio"},{"content":"","date":null,"permalink":"/tags/projects/","section":"Tags","summary":"","title":"Projects"},{"content":"","date":null,"permalink":"/tags/red-teaming/","section":"Tags","summary":"","title":"Red-Teaming"},{"content":"","date":null,"permalink":"/tags/resume/","section":"Tags","summary":"","title":"Resume"},{"content":"","date":null,"permalink":"/tags/dropbox-c2/","section":"Tags","summary":"","title":"Dropbox-C2"},{"content":"","date":null,"permalink":"/tags/evasion/","section":"Tags","summary":"","title":"Evasion"},{"content":"","date":null,"permalink":"/tags/kimsuky/","section":"Tags","summary":"","title":"Kimsuky"},{"content":"","date":null,"permalink":"/tags/multi-stage-attack/","section":"Tags","summary":"","title":"Multi-Stage-Attack"},{"content":"","date":null,"permalink":"/tags/north-korea/","section":"Tags","summary":"","title":"North-Korea"},{"content":"","date":null,"permalink":"/tags/persistence/","section":"Tags","summary":"","title":"Persistence"},{"content":"","date":null,"permalink":"/tags/python-backdoor/","section":"Tags","summary":"","title":"Python-Backdoor"},{"content":"","date":null,"permalink":"/tags/scheduled-task/","section":"Tags","summary":"","title":"Scheduled-Task"},{"content":"","date":null,"permalink":"/tags/anti-virus/","section":"Tags","summary":"","title":"Anti-Virus"},{"content":"","date":null,"permalink":"/tags/code-obfuscation/","section":"Tags","summary":"","title":"Code-Obfuscation"},{"content":"","date":null,"permalink":"/tags/malware/","section":"Tags","summary":"","title":"Malware"},{"content":"","date":null,"permalink":"/categories/malware-analysis/","section":"Categories","summary":"","title":"Malware Analysis"},{"content":"","date":null,"permalink":"/tags/metamorphic/","section":"Tags","summary":"","title":"Metamorphic"},{"content":"","date":null,"permalink":"/tags/polymorphic/","section":"Tags","summary":"","title":"Polymorphic"},{"content":"","date":null,"permalink":"/tags/reverse-engineering/","section":"Tags","summary":"","title":"Reverse-Engineering"},{"content":"","date":null,"permalink":"/tags/self-mutating/","section":"Tags","summary":"","title":"Self-Mutating"},{"content":" [Confidential] U.S. Department of Defense CMMC Cybersecurity Briefing Document Leaked on the Dark Web\nA threat actor has claimed to be selling a U.S. Department of Defense (DoD) CMMC cybersecurity briefing document. The document focuses on the core elements of the CMMC 2.0 framework, including its implementation processes, compliance requirements, and supporting systems. It serves as a …","date":"April 8, 2026","permalink":"/posts/2026/20260408171400/","section":"Diary","summary":"","title":"[Confidential] U.S. Department of Defense CMMC Cybersecurity Briefing Document Leaked on the Dark Web"},{"content":"Article Summary:\nThis in-depth analysis examines the recent Russian expulsions of British diplomats, exposing a core shift in the UK-Russia intelligence confrontation and its strategic implications. The piece focuses on three key figures — Michael Skinner, Tabassum Parveen Rashid, and Albertus Gerardus Janse van Rensburg — dissecting their roles within the British intelligence network. Skinner …","date":"April 8, 2026","permalink":"/posts/2026/20260408210400/","section":"Diary","summary":"","title":"Analysis of Russia’s Expulsion of British Diplomats: The Shifting Battlefield of the UK-Russia Intelligence War"},{"content":"","date":null,"permalink":"/tags/apt/","section":"Tags","summary":"","title":"Apt"},{"content":"","date":null,"permalink":"/tags/cyber-espionage/","section":"Tags","summary":"","title":"Cyber-Espionage"},{"content":"","date":null,"permalink":"/categories/dark-web/","section":"Categories","summary":"","title":"Dark Web"},{"content":"","date":null,"permalink":"/tags/dark-web/","section":"Tags","summary":"","title":"Dark-Web"},{"content":"","date":null,"permalink":"/tags/data-breach/","section":"Tags","summary":"","title":"Data-Breach"},{"content":"","date":null,"permalink":"/tags/department-of-defense/","section":"Tags","summary":"","title":"Department-of-Defense"},{"content":"","date":null,"permalink":"/tags/diplomats/","section":"Tags","summary":"","title":"Diplomats"},{"content":"","date":null,"permalink":"/tags/dprk/","section":"Tags","summary":"","title":"Dprk"},{"content":"","date":null,"permalink":"/tags/economic-espionage/","section":"Tags","summary":"","title":"Economic-Espionage"},{"content":"","date":null,"permalink":"/tags/expulsion/","section":"Tags","summary":"","title":"Expulsion"},{"content":"","date":null,"permalink":"/tags/fsb/","section":"Tags","summary":"","title":"Fsb"},{"content":"","date":null,"permalink":"/tags/github-c2/","section":"Tags","summary":"","title":"Github-C2"},{"content":"","date":null,"permalink":"/tags/humin/","section":"Tags","summary":"","title":"Humin"},{"content":"","date":null,"permalink":"/tags/intelligence-war/","section":"Tags","summary":"","title":"Intelligence-War"},{"content":"","date":null,"permalink":"/tags/leaked/","section":"Tags","summary":"","title":"Leaked"},{"content":"","date":null,"permalink":"/tags/lolbins/","section":"Tags","summary":"","title":"Lolbins"},{"content":"","date":null,"permalink":"/tags/rok-rat/","section":"Tags","summary":"","title":"Rok-Rat"},{"content":"","date":null,"permalink":"/tags/russia/","section":"Tags","summary":"","title":"Russia"},{"content":"","date":null,"permalink":"/tags/uk/","section":"Tags","summary":"","title":"Uk"},{"content":"","date":null,"permalink":"/tags/xeno-rat/","section":"Tags","summary":"","title":"Xeno-Rat"},{"content":"[CONFIDENTIAL] Exposure of Raytheon Cybersecurity Executive Position Recruitment Document on the Dark Web, Involving Foundational Cooperation on Classified Projects within the U.S. Intelligence Apparatus # Article Summary:\nOn January 25, 2026, the threat actor “jrintel” leaked a confidential PDF document concerning the Vice President of Cybersecurity position at Raytheon, a major U.S. defense …","date":"March 30, 2026","permalink":"/posts/2026/20260330214900/","section":"Diary","summary":"","title":"[CONFIDENTIAL] Exposure of Raytheon Cybersecurity Executive Position Recruitment Document on the Dark Web, Involving Foundational Cooperation on Classified Projects within the U.S. Intelligence Apparatus"},{"content":"[CONFIDENTIAL] Leak of RFID and Wireless Application Documents from Sanctioned U.S. Arms Manufacturer Lockheed Martin on the Dark Web # A threat actor has claimed to be selling a document belonging to U.S. defense industry contractor Lockheed Martin. The file is a confidential technical and project report supplied by GlobeRanger to Lockheed Martin. Its core content revolves around the RFID edge …","date":"March 30, 2026","permalink":"/posts/2026/20260330223100/","section":"Diary","summary":"","title":"[CONFIDENTIAL] Leak of RFID and Wireless Application Documents from Sanctioned U.S. Arms Manufacturer Lockheed Martin on the Dark Web"},{"content":"","date":null,"permalink":"/tags/confidential/","section":"Tags","summary":"","title":"Confidential"},{"content":"","date":null,"permalink":"/tags/defense-contractor/","section":"Tags","summary":"","title":"Defense-Contractor"},{"content":"","date":null,"permalink":"/tags/lockheed-martin/","section":"Tags","summary":"","title":"Lockheed-Martin"},{"content":"","date":null,"permalink":"/tags/raytheon/","section":"Tags","summary":"","title":"Raytheon"},{"content":"","date":null,"permalink":"/tags/rfid/","section":"Tags","summary":"","title":"Rfid"},{"content":"","date":null,"permalink":"/tags/abm/","section":"Tags","summary":"","title":"Abm"},{"content":"","date":null,"permalink":"/tags/active-directory/","section":"Tags","summary":"","title":"Active-Directory"},{"content":"","date":null,"permalink":"/categories/apple/","section":"Categories","summary":"","title":"Apple"},{"content":"","date":null,"permalink":"/tags/apple/","section":"Tags","summary":"","title":"Apple"},{"content":"","date":null,"permalink":"/tags/device-management/","section":"Tags","summary":"","title":"Device-Management"},{"content":"","date":null,"permalink":"/tags/enterprise/","section":"Tags","summary":"","title":"Enterprise"},{"content":"","date":null,"permalink":"/tags/jamf/","section":"Tags","summary":"","title":"Jamf"},{"content":"","date":null,"permalink":"/tags/mac/","section":"Tags","summary":"","title":"Mac"},{"content":"","date":null,"permalink":"/tags/mdm/","section":"Tags","summary":"","title":"Mdm"},{"content":"With the development of mobile internet technology, more and more businesses are adopting mobile devices for their operations. Among the many choices available on the market, Apple’s iPhone, iPad, and MacBook have gained popularity due to their high-quality user experience and premium image. Do you know how to correctly procure Apple devices for business use? Most users don’t see this as an issue, …","date":"January 22, 2025","permalink":"/posts/2025/20250122180600/","section":"Diary","summary":"","title":"The Right Approach to Managing Apple Devices in Enterprises — ABM"},{"content":"While Macs are less common than Windows PCs, they have successfully entered the IT landscape of many enterprises. IT teams need to find solutions that integrate Macs with existing Windows Active Directory (AD) domains and determine the necessary tools or systems. Deciding how to integrate Macs into a Windows infrastructure is no simple task. Organisations need to clarify the number of Macs …","date":"January 22, 2025","permalink":"/posts/2025/20250122183900/","section":"Diary","summary":"","title":"Three Ways to Manage Macs in a Business Environment"},{"content":"","date":null,"permalink":"/tags/hibernate/","section":"Tags","summary":"","title":"Hibernate"},{"content":"","date":null,"permalink":"/tags/power-management/","section":"Tags","summary":"","title":"Power-Management"},{"content":"","date":null,"permalink":"/tags/sleep/","section":"Tags","summary":"","title":"Sleep"},{"content":"The Difference Between Sleep and Hibernate on Computers, and How to Enable Hibernate # 1. Reasons to Choose Sleep or Hibernate # Imagine you\u0026rsquo;re writing a paper, your browser has multiple research tabs open, and you\u0026rsquo;re working on an unfinished coding project. The day\u0026rsquo;s work isn\u0026rsquo;t complete, but you need a break and want to continue tomorrow. If you shut down your computer …","date":"January 20, 2025","permalink":"/posts/2025/20250120072500/","section":"Diary","summary":"","title":"The Difference Between Computer Sleep and Hibernate Modes, and How to Set Up Hibernate"},{"content":"","date":null,"permalink":"/categories/windows/","section":"Categories","summary":"","title":"Windows"},{"content":"","date":null,"permalink":"/tags/windows/","section":"Tags","summary":"","title":"Windows"},{"content":"","date":null,"permalink":"/categories/chip/","section":"Categories","summary":"","title":"Chip"},{"content":"","date":null,"permalink":"/tags/chip/","section":"Tags","summary":"","title":"Chip"},{"content":" Eliminate subjective emotional factors Consider multiple possible causes Identify and establish connections between issues (commonalities) Subjective emotional factors compromise objective analytical judgment and must be eliminated to ensure accurate analysis.\nRST # Network reset due to blocking or issues with hosts IP-DNS mapping.\nSSL_ERR_SYSCALL # An issue where a manually configured proxy …","date":"December 9, 2024","permalink":"/posts/2024/20241209195800/","section":"Diary","summary":"","title":"Comprehensive Analysis of GitHub RST and Git SSL_ERR_SYSCALL"},{"content":"","date":null,"permalink":"/tags/dns/","section":"Tags","summary":"","title":"Dns"},{"content":"","date":null,"permalink":"/tags/download/","section":"Tags","summary":"","title":"Download"},{"content":"","date":null,"permalink":"/tags/github/","section":"Tags","summary":"","title":"Github"},{"content":"","date":null,"permalink":"/tags/network/","section":"Tags","summary":"","title":"Network"},{"content":"","date":null,"permalink":"/tags/npm/","section":"Tags","summary":"","title":"Npm"},{"content":"","date":null,"permalink":"/tags/pip/","section":"Tags","summary":"","title":"Pip"},{"content":"","date":null,"permalink":"/tags/proxy/","section":"Tags","summary":"","title":"Proxy"},{"content":"Before proceeding, you may need to read 《This Book Will Help You Connect to the Internet》 as background knowledge.\nGitHub Downloads # Copy the following hosts into C:\\Windows\\System32\\drivers\\etc\\hosts, and then run the command ipconfig /flushdns to refresh the DNS cache. This host is used to bypass the GFW\u0026rsquo;s restrictions on GitHub (asw, ssh) downloads and cloning. (Note: This does not …","date":"December 9, 2024","permalink":"/posts/2024/20241209010143/","section":"Diary","summary":"","title":"Solution to Slow Download Speeds for Information Development Environment Packages"},{"content":"","date":null,"permalink":"/tags/ssl/","section":"Tags","summary":"","title":"Ssl"},{"content":"Following the tides of data flows, I draw near,\nChasing the signals that surge in waves.\nWe grow closer and closer,\nDistance compressed into a moment\u0026rsquo;s delay.\nHesitating between near and far,\nUnable to see through these ambiguous eyes.\nAs if within reach,\nYet when I approach, it quietly fades away.\n","date":null,"permalink":"/about/","section":"Welcome","summary":"Personal profile and contact information","title":"Excalibra"},{"content":"Here I jot down some sudden ideas and things that need to be done.\nIdeas # Random thoughts that pop up, captured on the fly\nContent Creation # Write an article about personal knowledge management Organize recent thoughts on social observations Document the journey of a technical learning experience Life Logging # Set up a daily micro-habits tracking system Organize photos and build a timeline …","date":null,"permalink":"/ideas/","section":"Welcome","summary":"Inspiration log and task tracking","title":"Ideas"}]