DCat

Blog Posts

Thoughts, tutorials, and insights about technology and development.

July 24, 2026
Comprehensive Analysis: Multi-Stage Crypto Wallet Phishing Campaign

This analysis documents a sophisticated multi-stage phishing campaign targeting cryptocurrency wallet users. The attack chain spans from email delivery through credential exfiltration, incorporating TDS (Traffic Direction System) cloaking, BIP39 cryptographic validation, and social engineering across five sequential stages.

PhishingCryptocurrencySecurity AnalysisReverse Engineering
July 11, 2026
PhaaS research: a Ledger seed phishing campaign from a Google ad

Notes on an active crypto phishing campaign impersonating Ledger — a verified Google advertiser buying "ledger" ads pointing at a typosquat that walks you through a fake firmware update and harvests your recovery phrase.

threat-intelphishingphaascryptoledgerseed-phrasemalvertising
July 8, 2026
Diving into a non documented WhatsApp anti-censorship feature

I discovered a non documented anti-censorship feature in WhatsApp that allows users to bypass censorship in certain countries.

WhatsAppAnti-CensorshipNetworkingpsiphon
June 9, 2025
PhaaS in the Wild: Dissecting the TCC Payment Page Phishing Kit

Full technical breakdown of an active Phishing-as-a-Service kit targeting Colombian banking customers. The kit impersonates logistics company TCC, runs a real-time card keylogger via an obfuscated runtime, routes victims by BIN prefix, and exfiltrates data through postMessage to a Chinese-built multi-tenant C2 platform at tcc-ayv.cc.

threat-intelphishingphaascolombiabankingreverse-engineeringobfuscationcard-skimmer
April 4, 2025
Malware Analysis: Persistence, Obfuscation & Steganography

A deep dive into a malware sample hiding inside a fake PDF — emoji-obfuscated batch scripts, C2 communication, and payloads embedded in JPEGs using steganography.

malwarereverse-engineeringsteganographyobfuscationsecurity
January 30, 2025
Terminal Makeover: From Boring to Beautiful 🎨

Your terminal is where you live as a dev. This guide turns that bland default setup into something you'll actually want to open — autocompletion, syntax highlighting, a clean prompt, and pro tools included.

terminalproductivitytools
July 15, 2024
Fake Interview Scams - Malware Execution via VSCode and Express App

This blog post explores a fake tech interview scam that infects victims' machines through a malicious GitHub repository. The infection occurs via Visual Studio Code's `.vscode` folder and a legitimate-looking Express app, allowing attackers to execute arbitrary code and steal sensitive information.

threat-intelmalwarephishingtech-interviewgithubvscodeexpress