Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://infosec.exchange/@VXShare" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>VXShare</span></a></span> <span class="h-card" translate="no"><a href="https://myside-yourside.net/@StarkRG" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>StarkRG</span></a></span> <span class="h-card" translate="no"><a href="https://social.zerojay.com/@jay" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>jay</span></a></span> <span class="h-card" translate="no"><a href="https://infosec.exchange/@vildis" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>vildis</span></a></span> <span class="h-card" translate="no"><a href="https://infosec.exchange/@vxunderground" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>vxunderground</span></a></span> OFC, if their corporate firewall didn't blocklist your domain, most <a href="https://infosec.space/tags/MITM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MITM</span></a>-based <em>"<a href="https://infosec.space/tags/NetworkSecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>NetworkSecurity</span></a>"</em> solutions and <em>"<a href="https://infosec.space/tags/EndpointProtection" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>EndpointProtection</span></a>"</em> will checksum files and instantly yeet them into the shadow realm.</p><ul><li>Researchers should OFC only run those said malware <em>only for research purposes and on <a href="https://infosec.space/tags/airgapped" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>airgapped</span></a>, sanctioned systems</em> but they need to get their hands on them in the first place.</li></ul><p>And lets be honest: Like with chemistry and medicine, one wants to have a supplier that isn't shady af but actually transparent. </p><ul><li>The "alternative" would be to go into some <em>"dark corners"</em> and risk getting something else entirely.</li></ul>