<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Babadeda on marsomx</title><link>https://marsomx.github.io/tags/babadeda/</link><description>Recent content in Babadeda on marsomx</description><generator>Hugo -- gohugo.io</generator><language>en</language><managingEditor>s.liberatore@icloud.com (marsomx)</managingEditor><webMaster>s.liberatore@icloud.com (marsomx)</webMaster><copyright>© 2026 marsomx</copyright><lastBuildDate>Sun, 16 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://marsomx.github.io/tags/babadeda/index.xml" rel="self" type="application/rss+xml"/><item><title>BabaDeda Malware: Loader and RAT pack</title><link>https://marsomx.github.io/posts/babadeda-malware-analysis/</link><pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate><author>s.liberatore@icloud.com (marsomx)</author><guid>https://marsomx.github.io/posts/babadeda-malware-analysis/</guid><description>Following malware-traffic-analysys.net blogs about SmartApeSG ClickFix linked to unidentified RAT, i found overlaps with BabaDeda malware. The unidentified final playload appears to be the CNCMachineRMS RAT described by levelblue delivered by BabaDeda loader analyzed by Morphisec. Loader and RAT share same characteristic: API hashing algorithm, encrypted stack strings mechanism, peculiar storage config tree, custom Scripting Engine suggesting same malware toolkit</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://marsomx.github.io/posts/babadeda-malware-analysis/feature_babadeda-cover.png"/></item></channel></rss>