Skip to main content
← All Articles

Tag

#Obfuscation

15 articles

Advertisement

LOW
Threat Intel

Polymorphic Phishing Page Analysis: JavaScript Obfuscation Flaws

Analysis of a polymorphic phishing page utilizing heavy JavaScript obfuscation and variable scope bugs that cause browser loops.

Runtime Rebel Intel
3 min read · Sep 1, 2026
Deobfuscating Malicious JavaScript for Threat Analysis
INFO
Threat Intel

Deobfuscating Malicious JavaScript for Threat Analysis

Understanding JavaScript obfuscation techniques used in phishing and malware. Learn static and dynamic deobfuscation methods to uncover malicious intent.

Runtime Rebel Intel
4 min read · Sep 1, 2026
INFO
Threat Intel

Detecting SSRF Hostname Obfuscation: 1u.ms and Cloud Metadata

Attackers are leveraging hostnames and services like 1u.ms to obfuscate IP addresses (e.g., 169.254.169.254), bypassing traditional SSRF blocklist defenses.

Runtime Rebel Intel
4 min read · Aug 25, 2026
WordlistLoader Evades Detection, Delivers Amatera Infostealer
HIGH
Malware

WordlistLoader Evades Detection, Delivers Amatera Infostealer

WordlistLoader uses a novel text-based obfuscation to bypass security, deploying the Amatera infostealer in ClickFix-style campaigns, posing a significant threat.

Runtime Rebel Intel
4 min read · Aug 25, 2026
Text Salting: Hidden Text Tactics Bypass AI Email Filters
MEDIUM
Threat Intel

Text Salting: Hidden Text Tactics Bypass AI Email Filters

Over 1 million emails are leveraging text salting techniques, embedding hidden characters to bypass AI and LLM-based email security filters, posing a significant…

Runtime Rebel Intel
5 min read · Jul 16, 2026
MEDIUM
Threat Intel

Linux Process Name Masquerading: Analyzing T1036 Obfuscation

Explore the technical methods behind Linux process name masquerading (MITRE ATT&CK T1036) used by actors like Velvet Ant to evade detection.

Runtime Rebel Intel
4 min read · Jun 24, 2026

Advertisement

MEDIUM
Malware

Excel VBA Macro Obfuscation: How to Detect Hidden Payloads

Learn how to analyze and detect obfuscated VBA macros in Excel files using oledump.py. Technical guide on character substitution and string reversal techniques.

Runtime Rebel Intel
3 min read · Jun 8, 2026
INFO
Malware

Obfuscating Strings in C++ Implants: Detection and Analysis

Analyze how stack strings help malware authors evade static analysis. Explore the assembly-level mechanics and detection strategies for Windows implants.

Runtime Rebel Intel
4 min read · May 23, 2026
HIGH
Malware

Analysis of Cross-Platform NPM Stealer Using Discord Webhooks

Technical teardown of an obfuscated Node.js infostealer targeting Discord tokens, crypto wallets, and browser credentials via cross-platform scripts.

Runtime Rebel Intel
4 min read · May 22, 2026
MEDIUM
Malware

Malicious PDF Structure Analysis and Obfuscation Detection

Learn how to detect malicious PDF obfuscation and analyze internal structures like /OpenAction and /JS streams to identify hidden malware payloads.

Runtime Rebel Intel
4 min read · May 21, 2026
MEDIUM
Malware

Detect Obfuscated JavaScript Phishing Delivered via RAR Archives

Security researchers identify a new phishing campaign using heavily obfuscated JavaScript within RAR archives to bypass traditional endpoint detection.

Runtime Rebel Intel
4 min read · Apr 10, 2026
Emoji-Based C2: Threat Actors Adopt Covert Communication Tactics
MEDIUM
Threat Intel

Emoji-Based C2: Threat Actors Adopt Covert Communication Tactics

Threat actors are increasingly using emojis for covert Command and Control communications to evade security filters. Learn how to detect these obfuscated TTPs.

Runtime Rebel Intel
4 min read · Apr 9, 2026
DeepLoad Malware Leverages AI for Evasion and Credential Theft
HIGH
Malware

DeepLoad Malware Leverages AI for Evasion and Credential Theft

DeepLoad, an AI-powered malware, uses massive junk code to evade detection while stealing credentials. Learn its TTPs and mitigation strategies.

Runtime Rebel Intel
4 min read · Mar 31, 2026
MEDIUM
Threat Intel

SVG-Based Phishing: Using Scalable Vector Graphics for Credential Theft

Discover how threat actors leverage SVG files to bypass email filters and execute credential theft through embedded JavaScript and HTML forms.

Runtime Rebel Intel
4 min read · Mar 25, 2026
LOW
Threat Intel

Exploiting IPv4-Mapped IPv6 Addresses to Obfuscate Web Scanning

Attackers leverage RFC 4038 IPv4-mapped IPv6 addresses to bypass security filters and obfuscate scanning activities targeting proxy-related URLs.

Runtime Rebel Intel
3 min read · Mar 17, 2026