
SIGNALMONK
Expert en sécurité sans fil et RFID
Profil professionnel
SignalMonk dirige des opérations de sécurité sur Wi‑Fi, BLE, RFID et l’IoT sans fil.
Compétences clés
Capture de trafic sans fil; exploitation BLE; détection de clonage RFID; communication IoT sécurisée; forensique radio
Réalisations majeures
Mise au jour d’un vol d’entreprise via des badges clonés.
Articles de SIGNALMONK
The Proxy Trap: How a Hidden Linux Implant Turned HAProxy Into a Traffic Filter
A trojanized edge proxy can sit in the middle of web sessions, making the compromise of one server matter far beyond that single machine.
Toy Ghouls Backdoors Use HiveMQ and Element as Control Channels
A financially motivated crew is linked to Windows backdoors that route command traffic through public MQTT and Matrix-based messaging infrastructure.
When Help Turns Hostile: Windows Remote-Access Tools Used as a Persistence Route
A late-August cluster of intrusions shows how trusted support software can be repurposed into a quiet backdoor path on Windows endpoints.
JSCeal Hides in V8 Bytecode, Blurring the Line Between Script and Stealer
A cryptocurrency-focused information stealer reportedly ships as compiled V8 bytecode in a .jsc file, a format that can make JavaScript malware harder to inspect while it hunts for browser credentials and HTTPS traffic.
When a Theme Package Turns into a Trap for iPhones and Wallet Owners
Thirteen malicious Composer packages allegedly bent trusted web pages into a delivery path for ad fraud, redirects, and a spyware campaign aimed at unpatched iOS devices.
When a Botnet Loses Its Backbone: Why the Sality Seizure Matters
A coordinated cyber disruption targeted Sality’s malware infrastructure, showing how defenders can still hit a long-running peer-to-peer botnet where it hurts most - its control plane.
The Job Test That Might Not Be a Test
Fake coding exercises are being used as a malware lure against developers, with researchers attributing the campaign with high confidence to Mirage Kitten.
When a Dependency Becomes the Trapdoor: Packagist Themes and the iPhone Browser Risk
A reported package-chain abuse on Composer's ecosystem shows how a single injected script can turn ordinary mobile page views into a credential-harvesting event.
npm’s Quiet Trapdoor: How a Trusted Codegen Package Became a Supply-Chain Hazard
A widely used npm package was pushed through multiple malicious releases, and researchers say the episode fits a broader pattern of install-time abuse that can turn developer tools into credential targets.
Fake AI Desktop Tools Are Becoming a New Stealer Trap
A Windows malware campaign used a fake Claude-branded desktop app to pull passwords and crypto wallet data into a familiar-looking download path.
Fake AI Desktop App Turns a Trusted Brand Into a Password Trap
A trojanized Electron installer impersonating Claude Opus 5 shows how believable software branding can be repurposed into a Windows infostealer delivery path.
The npm Package That Became a Worm Carrier
A developer tool with heavy weekly usage was turned into a supply-chain infection path, showing how install-time behavior can matter as much as runtime code.
How a Browser Add-on Became the Front Door for Wallet and Credential Theft
A cluster of malicious Chrome and Edge extensions shows how ordinary browser permissions can turn trusted add-ons into a quiet risk for logins and crypto activity.
When a CAPTCHA Becomes a Shell: The TerminalFix Playbook for Turning Trust Into Access
A fake verification page can do more than annoy users - in ClickFix-style campaigns, it can become the first step in a multi-stage intrusion chain that ends with a reverse-tunnel foothold.
When a Build Tool Turns Hostile: The npm Package That Put Developer Trust on the Line
A popular OpenAPI-to-TanStack Query generator was linked to a burst of malicious releases, raising a familiar but uncomfortable question: what happens when the tool chain itself becomes the threat surface?
Ten Minutes, Ten Bad Releases: How a Build Tool Became the Weakest Link
A reported malicious npm release campaign against a popular OpenAPI-to-TanStack Query code generator highlights how build-time developer tools can become high-value supply-chain targets.
Tax Lures, Modular Malware, and the Quiet Return of Packaged Access
A phishing chain tied to the cluster tracked as TA4922 shows how tax-themed email can be turned into a delivery path for a modular RAT, staged loaders, and follow-on access tooling.
When a CAPTCHA Becomes a Trap Door: Fake Verification Pages and the PowerShell Pivot
A disguised human-check page can push a browser session into terminal execution, turning ordinary Windows endpoints into reverse-tunnel footholds for attackers.
Tax Notices, Telegram Sales, and a Modular RAT: The Quiet Machinery Behind a Phishing Run
A tax-themed lure linked to TA4922 shows how localized phishing and commodity malware can be fused into a repeatable access playbook without proving full compromise.
The Resume Trap That Can Turn Research Inboxes Into Malware Runways
A credential-flavored archive can look ordinary for one second and hostile the next, especially when it hides a disguised executable linked to the SNOWLIGHT and VShell malware stack.


