/images/ghost.png

Cryptax

This website is personal and does not represent my employer

Blog

The Lazy Workshopper

The Lazy Workshopper Background: by workshop, I mean 1h lab sessions to 2-3 day , trainings with lots of hands-on labs, on technical topics, e.g “reverse android malware”. Some people call this Labs. In French universities, this would be called TP (Travaux Pratiques). I have given quite a few workshops, free or non free. In free workshop, a few participants stand out, that I call the lazy workshoppers. Those are participants who come at a technical lab session with no computer, have no intention of doing the exercices.

LabubaRAT anti-analysis features

LabubaRAT is a Remote Access Tool (RAT) implemented in Rust. It was discovered and analyzed by two researchers at Blackpoint Cyber’s Adversary Pursuit Group. Usually, when there’s one technical analysis, people tend to think it’s “enough”. In reality, in complex malware such as this one, there are always several different angles to look into and that can’t be covered in a single blog post. In this blog post, I am going to cover techniques the malware author used to deceive the analyst.

Capture The Evidence v2 (2026)

Capture The Evidence v2 - June 2026 French gendarmerie 🇫🇷 organized a special CTF called “Capture The Evidence” from June 5 to June 15, 2026. I participated for the first time, with a team of 4 called Eternal Green. The name of our team is a play on words based on Eternal Blue, the organizing team where blue is the color of the gendarmerie, and Green in our case in reference to the (famous?

More blog posts →

Write-ups

THCon 2026 Badge

THCon 2026 Badge The badge at THCon 2026 was created by DVID. It actually had 2 firmware: Shipped on the badges for the conference, and reversed by Virtualabs. Interesting blog post, read it! This firmware has the badges communicate with a master using BLE. A specific firmware for a challenge. Getting the XRefs in Ghidra I had dumped the firmware and retrieved the applicative part see Virtualab’s post, but I was annoyed not to have any xref in Ghidra.

CTE v2 (2026) - Le Vault

CTE v2 (2026) - Le Vault This challenge begins with some OSINT where we need to find a program protected by password. This program is used by Melanie’s friend, Samir Taleb. NB. These are fake identities used all along “Capture The Evidence” v2. Then, we’ll need to provide the author’s name of this challenge as flag. The tags of the challenge suggest there’s a part with OSINT (first part) and a part with Reverse (second part).

CTE v2 (2026) - Toujours en Vente

CTE v2 (2026) - Toujours en Vente This is a reverse engineering challenge created by Miaou for Capture The Evidence (CTE) in June 2026. We are given a binary broker_tool, and we need to find a URL to flag, e.g https://u.rl/path. Reconnaissance The binary is an ELF x86-64, not stripped. We run it: 1 2 3 4 5 6 7 8 9 10 11 12 13 14 =================================== B U S I N E S S P O R T A L =================================== Welcome, valued partner.

More write-ups →