Mon 13 July 2026
A Python HTTP server left running on a VPS exposed the complete toolkit of an active AiTM phishing operator. What followed was a three-actor investigation spanning custom Evilginx forks, OAuth Device Code Flow abuse, a seven-tool RMM arsenal, and a connection to The Quarry MaaS/PhaaS ecosystem.
Tue 15 July 2025
The article analyzes the Secp0 ransomware, which emerged in early 2025 and operates as conventional double-extortion ransomware, encrypting data while threatening public disclosure, targeting Linux systems.
Tue 20 May 2025
This article provides an analysis of World Leaks, a new extortion platform that emerged in early 2025, detailing its origins, operational challenges, and collaborations with other threat actors.
Fri 28 February 2025
An OSINT investigation into the world of forged documents business
Mon 08 July 2024
This blog post introduces a tool that extracts stolen credentials from text files coming in varying formats in order to address CTI and Red Teaming needs.
Mon 09 March 2020
In this whitepaper, Lexfo analyses Lazarus malwares, from their motives, to their detection and mitigation, through their techniques, tactics, procedures.
Check our offensive & continuous web security assessment service