Skip to main content
Bubka

Bubka

Malware Analysis | Reverse Engineering | Digital Forensics and Incident Response

Current focus: ELK SIEM · Executable analysis

GitHub · LinkedIn

Recent

CDEF-EtherRAT

An attacker breached Maromalix’s public-facing web application by exploiting CVE-2025-55182 (Next.js Deserialization RCE). They deployed a multi-stage implant dubbed EtherRAT, which utilizes a blockchain-based C2 mechanism via Ethereum smart contracts to dynamically resolve infrastructure. The attacker exfiltrated sensitive data, established multiple persistence mechanisms, and ultimately patched the vulnerability to lock out other actors.