<feed xmlns="http://www.w3.org/2005/Atom"> <id>https://gelato07.github.io/</id><title>Cyber Weblog</title><subtitle></subtitle> <updated>2026-10-09T01:47:14+00:00</updated> <author> <name>Lachlan Gelavis</name> <uri>https://gelato07.github.io/</uri> </author><link rel="self" type="application/atom+xml" href="https://gelato07.github.io/feed.xml"/><link rel="alternate" type="text/html" hreflang="en" href="https://gelato07.github.io/"/> <generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator> <rights> © 2026 Lachlan Gelavis </rights> <icon>/assets/img/favicons/favicon.ico</icon> <logo>/assets/img/favicons/favicon-96x96.png</logo> <entry><title>OAuth Device Code Phishing Research and Findings</title><link href="https://gelato07.github.io/posts/OAuth-Device-Code-Phishing/" rel="alternate" type="text/html" title="OAuth Device Code Phishing Research and Findings" /><published>2026-09-29T16:00:00+00:00</published> <updated>2026-09-30T09:35:28+00:00</updated> <id>https://gelato07.github.io/posts/OAuth-Device-Code-Phishing/</id> <content type="text/html" src="https://gelato07.github.io/posts/OAuth-Device-Code-Phishing/" /> <author> <name>Lachlan Gelavis</name> </author> <category term="Threat Intelligence Research" /> <summary>A short report on OAuth device code phishing, an attack technique that has grown rapidly in 2026. It covers how attackers use real login pages to steal access tokens and bypass MFA.</summary> </entry> <entry><title>Foundations of Malware Analysis and Its Role in Evidence Discovery</title><link href="https://gelato07.github.io/posts/Coming-Soon-Digital-Forensics-Incident-Response/" rel="alternate" type="text/html" title="Foundations of Malware Analysis and Its Role in Evidence Discovery" /><published>2026-09-29T16:00:00+00:00</published> <updated>2026-10-02T06:08:27+00:00</updated> <id>https://gelato07.github.io/posts/Coming-Soon-Digital-Forensics-Incident-Response/</id> <content type="text/html" src="https://gelato07.github.io/posts/Coming-Soon-Digital-Forensics-Incident-Response/" /> <author> <name>Lachlan Gelavis</name> </author> <category term="Digital Forensics / Incident Response" /> <summary>Learn the foundations of malware analysis and Windows forensics, then follow a RAT from static and dynamic analysis to Prefetch, Amcache and Registry evidence</summary> </entry> <entry><title>From Blockchain to Clipboard: Dissecting an EtherHiding ClickFix Attack</title><link href="https://gelato07.github.io/posts/EtherHiding-Blockchain-ClickFix/" rel="alternate" type="text/html" title="From Blockchain to Clipboard: Dissecting an EtherHiding ClickFix Attack" /><published>2026-09-27T16:00:00+00:00</published> <updated>2026-09-29T11:41:57+00:00</updated> <id>https://gelato07.github.io/posts/EtherHiding-Blockchain-ClickFix/</id> <content type="text/html" src="https://gelato07.github.io/posts/EtherHiding-Blockchain-ClickFix/" /> <author> <name>Lachlan Gelavis</name> </author> <category term="Byte-Sized Deep Dives" /> <summary>A walkthrough of a real EtherHiding campaign, tracing how attackers use Polygon smart contracts as a dead drop to serve a ClickFix/FakeCAPTCHA and deliver information stealers.</summary> </entry> <entry><title>Fake CAPTCHAs: How Attackers Use Them to Spread Malware</title><link href="https://gelato07.github.io/posts/Clickfix-FakeCaptcha-Delivering-Lumma-Stealer/" rel="alternate" type="text/html" title="Fake CAPTCHAs: How Attackers Use Them to Spread Malware" /><published>2025-05-01T16:00:00+00:00</published> <updated>2026-09-26T03:47:58+00:00</updated> <id>https://gelato07.github.io/posts/Clickfix-FakeCaptcha-Delivering-Lumma-Stealer/</id> <content type="text/html" src="https://gelato07.github.io/posts/Clickfix-FakeCaptcha-Delivering-Lumma-Stealer/" /> <author> <name>Lachlan Gelavis</name> </author> <category term="Articles" /> <summary>A breakdown of fake CAPTCHA malvertising campaigns used to deliver malware and information stealers like LummaStealer and StealC with a look at attack flows, findings, detection ideas to put in place, and response actions.</summary> </entry> </feed>
