- 🏴☠️ Hacker and Speaker.
- 🦾 DEF CON 5411 / Birmingham Cyber Arms Leader.
- 🦮 My partner in crime is a Golden Retriever.
- Contact
| # | CVE | Vulnerability | Short Name | Score | Product | Link |
|---|---|---|---|---|---|---|
| 1 | CVE-2018-19466 | Information Disclosure | LEMPO | 9.8 | Portainer | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19466 |
| 2 | CVE-2019-11881 | Web Parameter Tampering | VanCleef | 4.7 | Rancher | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11881 |
| 3 | CVE-2020-8820 | Stored XSS | - | 5.4 | Webmin | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8820 |
| 4 | CVE-2020-8821 | HTML Injection | - | 5.4 | Webmin | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8821 |
| 5 | CVE-2020-12670 | XSS | - | 6.1 | Webmin | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12670 |
| # | Blog / Zine | Title | Language | Link |
|---|---|---|---|---|
| 1 | Bitso Quetzal Team | Disrupting an APT Phishing Campaign | English | https://quetzalteam.substack.com/p/evilslack |
| 2 | Bitso Quetzal Team | Drainers as a Service | English | https://quetzalteam.substack.com/p/drainers |
| 3 | Bitso Quetzal Team | Docks Malware | English | https://quetzalteam.substack.com/p/docks |
| 4 | Bitso Quetzal Team | Malware & Taxes | English | https://quetzalteam.substack.com/p/malware-and-taxes |
| 5 | Bitso Quetzal Team | Your Ad Here | English | https://quetzalteam.substack.com/p/your-ad-here |
| 6 | PagedOut Issue #4 | Malicious Fungible Tokens | English | https://pagedout.institute/download/PagedOut_004_beta1.pdf |
| 7 | PagedOut Issue #4 | Drainers | English | https://pagedout.institute/download/PagedOut_004_beta1.pdf |
| 8 | Bitso Quetzal Team | Profiling and Burning a DaaS campaign | English | https://quetzal.bitso.com/p/it-never-drains-but-it-pours |
| 9 | Phrack Issue #71 | Riding with the Chollimas | English | http://phrack.org/issues/71/3.html#article |
| 10 | Bitso Quetzal Team | Wallet Inspector | English | https://quetzal.bitso.com/p/wallet-inspector |
| 11 | Bitso Quetzal Team | Drainer Autopsies | English | https://quetzal.bitso.com/p/drainers-autopsies |
| 12 | tmp.Out #3 | QRLog Malware Analysis | English | https://tmpout.sh/3/ |
| 13 | Bitso Quetzal Team | Stealing Christmas | English | https://quetzal.bitso.com/p/stealing-christmas |
| 14 | Bitso Quetzal Team | A Phishing Trip | English | https://quetzal.bitso.com/p/a-phishing-trip |
| 15 | ANY.RUN Blog | InvisibleFerret Technical Analysis | English | https://any.run/cybersecurity-blog/invisibleferret-malware-analysis/ |
| 16 | ANY.RUN Blog | Zhong Stealer Technical Analysis | English | https://any.run/cybersecurity-blog/zhong-stealer-malware-analysis/ |
| 17 | PagedOut Issue #6 | Contagious Interview | English | https://pagedout.institute/download/PagedOut_006.pdf |
| 18 | ANY.RUN Blog | PE32 Ransomware Analysis | English | https://any.run/cybersecurity-blog/pe32-ransomware-analysis/ |
| 19 | ANY.RUN Blog | Mamona Ransomware Analysis | English | https://any.run/cybersecurity-blog/mamona-ransomware-analysis/ |
| 20 | ANY.RUN Blog | OtterCookie Technical Analysis | English | https://any.run/cybersecurity-blog/ottercookie-malware-analysis/ |
| 21 | Bitso Quetzal Team | Interview with the Chollima | English | https://quetzal.bitso.com/p/interview-with-the-chollima |
| 22 | Bitso Quetzal Team | Interview with the Chollima 2 | English | https://quetzal.bitso.com/p/interview-with-the-chollima-ii |
| 23 | ANY.RUN Blog | DEVMAN Ransomware Sample Analysis | English | https://any.run/cybersecurity-blog/devman-ransomware-analysis/ |
| 24 | ANY.RUN Blog | PyLangGhostRAT Sample Analysis | English | https://any.run/cybersecurity-blog/pylangghost-malware-analysis/ |
| 25 | HackRead | CoinMarketCap Spear-Phishing Campaign | English | https://hackread.com/fake-coinmarketcap-journalists-crypto-executives-spear-phishing/ |
| 26 | Bitso Quetzal Team | AMOS Stealer Dissection | English | https://quetzal.bitso.com/p/todays-host-amos-stealer |
| 27 | HackRead | Fake Empire Podcast Infects Crypto Influencers with AMOS Stealer | English | https://hackread.com/fake-empire-podcast-invites-crypto-macos-amos-stealer/ |
| 28 | ANY.RUN Blog | FunkSec Ransomware Sample Analysis | English | https://any.run/cybersecurity-blog/funklocker-malware-analysis/ |
| 29 | Bitso Quetzal Team | Interview with the Chollima 3 | English | https://quetzal.bitso.com/p/interview-with-the-chollima-iii |
| 30 | HackRead | North Korean Hackers Caught on Video Using AI Filters in Fake Job Interviews | English | https://hackread.com/north-korean-hackers-video-ai-filter-fake-job-interview/ |
| 31 | Bitso Quetzal Team | Interview with the Chollima 4 | English | https://quetzal.bitso.com/p/interview-with-the-chollima-iv |
| 32 | BlockThreat | Interview with the Chollima 3 | English | https://newsletter.blockthreat.io/p/blockthreat-week-44-2025 |
| 33 | MeFiltraron | Análisis de BellaCiao | Spanish | https://news.mefiltraron.com/p/edicion-especial-bellaciao |
| 34 | Bitso Quetzal Team | Interview with the Chollima 5 | English | https://quetzal.bitso.com/p/interview-with-the-chollima-v |
| 35 | Bitso Quetzal Team | Interview with the Chollima 6 | English | https://quetzal.bitso.com/p/interview-with-the-chollima-vi |
| 36 | ANYRUN | Recording Famous Chollima | English | https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation/ |
| # | Title | Language | Link |
|---|---|---|---|
| 1 | Chaotic Ruby | English | http://books.apple.com/us/book/chaotic-ruby/id6739544400 |
| # | Interview | Language | Link |
|---|---|---|---|
| 1 | Vice Society | English & Spanish | https://github.com/mauroeldritch/vicesociety |
| 2 | Dark Vault | English & Spanish | https://github.com/mauroeldritch/darkvault |
| 3 | G0DHAND | Spanish | https://mefiltraron.com/interviews#G0DHAND |
| 4 | Stormous | Spanish | https://mefiltraron.com/interviews#stormous |
| Link |
|---|
| See Press Releases |



