TamperedChef
Operation behind AceLauncher and the AppSuite PDF Editor backdoor — trojanized, code-signed apps distributed via convincing malvertising.
Read profile →Profiles of threat actors behind notable malware campaigns and intrusions.
Operation behind AceLauncher and the AppSuite PDF Editor backdoor — trojanized, code-signed apps distributed via convincing malvertising.
Read profile →Russian GRU unit (APT44) behind the 2015 and 2016 Ukraine power grid attacks, NotPetya, and Olympic Destroyer.
Read profile →Group behind TRISIS/TRITON, the first malware built to target a safety instrumented system rather than the process it protects.
Read profile →Technical breakdowns of notable malware families, from delivery to impact.
A fake browser productivity tool tied to TamperedChef/EvilAI — from AI-generated landing page to .NET binary teardown.
Read profile →The first malware framework built to speak grid-control protocols directly — used against a Kyiv transmission substation in 2016.
Read profile →The first malware to target a safety instrumented system directly — deployed against Triconex controllers at a Saudi petrochemical plant in 2017.
Read profile →Curated tools, references, and reading material for security professionals.
A curated collection of resources, tools, and references for malware analysis and reverse engineering.
View on GitHub →A comprehensive reference on Advanced Persistent Threat groups, their TTPs, and associated campaigns.
View on GitHub →A comprehensive reference on malware families, their capabilities, and how to analyze them.
View on GitHub →In-depth walkthroughs, tutorials, and research breakdowns.
Long-form writeups, research findings, and technical breakdowns.
A practical guide to the PE file format — headers, sections, imports, exports, and detecting packed or obfuscated binaries.
Read post →An introduction to malware analysis — covering types of malware, static vs dynamic analysis techniques, and the tools used to dissect samples.
Read post →Astra covers threat intelligence and malware analysis, with a focus on reverse engineering real samples, tracking the threat actors behind them, and breaking down how these attacks actually work.
Get in Touch