<?xml version="1.0" encoding="utf-8"?><feed xmlns="http://www.w3.org/2005/Atom" ><generator uri="https://jekyllrb.com/" version="4.1.1">Jekyll</generator><link href="https://research.openanalysis.net/feed.xml" rel="self" type="application/atom+xml" /><link href="https://research.openanalysis.net/" rel="alternate" type="text/html" /><updated>2026-06-17T02:18:31+00:00</updated><id>https://research.openanalysis.net/feed.xml</id><title type="html">OALABS Research</title><entry><title type="html">Captured Logs Reveal Hackers Using Claude and Codex to Breach Companies</title><link href="https://research.openanalysis.net/claude/codex/hacking/ai%20hacking/llm/redteam/policy%20violation/2026/06/16/compromised-claude-hacking.html" rel="alternate" type="text/html" title="Captured Logs Reveal Hackers Using Claude and Codex to Breach Companies" /><published>2026-06-16T00:00:00+00:00</published><updated>2026-06-16T00:00:00+00:00</updated><id>https://research.openanalysis.net/claude/codex/hacking/ai%20hacking/llm/redteam/policy%20violation/2026/06/16/compromised-claude-hacking</id><author><name></name></author><category term="claude" /><category term="codex" /><category term="hacking" /><category term="AI hacking" /><category term="LLM" /><category term="redteam" /><category term="policy violation" /><summary type="html"><![CDATA[Full agent sessions captured on a compromised host turned honeypot offer an unprecedented look at how attackers are using AI in real-world intrusions.]]></summary></entry><entry><title type="html">JitterDropper</title><link href="https://research.openanalysis.net/jitterdropper/dropper/rust/srdi/donut/pixeldrain/2026/04/13/jitterdropper.html" rel="alternate" type="text/html" title="JitterDropper" /><published>2026-04-13T00:00:00+00:00</published><updated>2026-04-13T00:00:00+00:00</updated><id>https://research.openanalysis.net/jitterdropper/dropper/rust/srdi/donut/pixeldrain/2026/04/13/jitterdropper</id><author><name></name></author><category term="jitterdropper" /><category term="dropper" /><category term="rust" /><category term="srdi" /><category term="donut" /><category term="pixeldrain" /><summary type="html"><![CDATA[A Rust/MSVC dropper fingerprinted by per-API sleep-jitter budgets]]></summary></entry><entry><title type="html">CryptBot Evolution</title><link href="https://research.openanalysis.net/cryptbot/botnet/yara/config/2024/12/06/cryptbot2.html" rel="alternate" type="text/html" title="CryptBot Evolution" /><published>2024-12-06T00:00:00+00:00</published><updated>2024-12-06T00:00:00+00:00</updated><id>https://research.openanalysis.net/cryptbot/botnet/yara/config/2024/12/06/cryptbot2</id><author><name></name></author><category term="cryptbot" /><category term="botnet" /><category term="yara" /><category term="config" /><summary type="html"><![CDATA[Tracking the many iterations of this stealer]]></summary></entry><entry><title type="html">Spectre Ops</title><link href="https://research.openanalysis.net/spectreops/config/strings/cpp/2024/11/21/spectre-ops.html" rel="alternate" type="text/html" title="Spectre Ops" /><published>2024-11-21T00:00:00+00:00</published><updated>2024-11-21T00:00:00+00:00</updated><id>https://research.openanalysis.net/spectreops/config/strings/cpp/2024/11/21/spectre-ops</id><author><name></name></author><category term="spectreops" /><category term="config" /><category term="strings" /><category term="cpp" /><summary type="html"><![CDATA[Triage for v10 of this commodity implant]]></summary></entry><entry><title type="html">Latrodectus</title><link href="https://research.openanalysis.net/latrodectus/config/emulation/2024/09/30/latrodectus.html" rel="alternate" type="text/html" title="Latrodectus" /><published>2024-09-30T00:00:00+00:00</published><updated>2024-09-30T00:00:00+00:00</updated><id>https://research.openanalysis.net/latrodectus/config/emulation/2024/09/30/latrodectus</id><author><name></name></author><category term="Latrodectus" /><category term="config" /><category term="emulation" /><summary type="html"><![CDATA[Extracting new AES encrypted strings from this RAT]]></summary></entry></feed>