marc_etienne_ Profile Banner
Marc-Etienne M.Léveillé Profile
Marc-Etienne M.Léveillé

@marc_etienne_

Followers
3K
Following
3K
Statuses
828

Security stuff @Google (Previously @ESETresearch). Montréal security: @NorthSec_io // @MontreHack. Father of two. VE2XME https://t.co/ahEQ1MJEaF

Montréal, Québec
Joined January 2010
Don't wanna be here? Send us removal request.
@marc_etienne_
Marc-Etienne M.Léveillé
4 months
I am looking forward to build stuff in Google TAG with new colleagues and wish ESET and its impressively good research team the best for the future,✌️.
3
0
15
@marc_etienne_
Marc-Etienne M.Léveillé
4 months
If you are curious about our research, and to understand how a botnet of Linux servers has been around for 15 years stealing credit cards and cryptocurrency, and mangling HTTP traffic, the paper is available here:
1
3
13
@marc_etienne_
Marc-Etienne M.Léveillé
6 months
RT @ESETresearch: It seems a malicious Pidgin plugin isn’t the only way the perpetrators are spreading malware. Cradle, an instant messagin…
0
19
0
@marc_etienne_
Marc-Etienne M.Léveillé
6 months
RT @ESETresearch: A few days ago, Pidgin Instant Messenger @impidgin published a notification about a malicious plugin (ScreenShareOTR) fou…
0
33
0
@marc_etienne_
Marc-Etienne M.Léveillé
7 months
RT @matthieu_faou: We are looking for a strategic threat intel analyst to join @ESETresearch. Interested in cyber-espionage and geopolitics…
0
42
0
@marc_etienne_
Marc-Etienne M.Léveillé
8 months
Looks like Apple’s dyld team implemented my suggested fix as-is 🙌 I’m guessing the change might not be backported to avoid breaking anything that might depend on the previous behaviour.
@patrickwardle
Patrick Wardle
8 months
Apple's macho_best_slice API worked for them but was broken for all else 🤦🏻‍♂️ I detailed this flaw in a blog post in Feb. & included a proposed fix (via @marc_etienne_) Reversing libdyld.dylib on macOS 15 (beta) we see that Apple has fixed it in exactly this proposed manner!🥹
Tweet media one
0
0
7
@marc_etienne_
Marc-Etienne M.Léveillé
8 months
RT @kenshirriff: To use the Montreal subway, you tap a paper ticket against the turnstile and it opens. But how does it work? And how can t…
0
2K
0
@marc_etienne_
Marc-Etienne M.Léveillé
9 months
@QuinnyPig I’m more worried about internal policies and who can access the data:
Tweet media one
0
0
1
@marc_etienne_
Marc-Etienne M.Léveillé
9 months
Today at 1pm EST I will be presenting @NorthSec_io some of our findings on Ebury, a server-side Linux botnet that compromised 400k servers in the last 15 years for financial gain. See you there or online! #nsec24
Tweet media one
@ESETresearch
ESET Research
9 months
#Breaking #ESETresearch releases a paper about Ebury, among the most advanced server-side Linux malware, which was deployed to 400,000 servers over the course of 15 years, primarily for financial gain. @marc_etienne_ 1/8
1
5
18
@marc_etienne_
Marc-Etienne M.Léveillé
9 months
This week we @ESETResearch published a very dense report on one of the most complex Linux server-side threat, Ebury. We uncovered some of the tactics used to monetize this huge botnet, and try to explain how this threat is able to stay under the radar.
@ESETresearch
ESET Research
9 months
#Breaking #ESETresearch releases a paper about Ebury, among the most advanced server-side Linux malware, which was deployed to 400,000 servers over the course of 15 years, primarily for financial gain. @marc_etienne_ 1/8
0
2
13
@marc_etienne_
Marc-Etienne M.Léveillé
9 months
RT @ESETresearch: #Breaking #ESETresearch releases a paper about Ebury, among the most advanced server-side Linux malware, which was deploy…
0
86
0
@marc_etienne_
Marc-Etienne M.Léveillé
10 months
RT @ESETresearch: #ESETResearch is releasing Nimfilt, an #IDAPro plugin to help reverse engineering #Nim malware – a language increasingly…
0
65
0
@marc_etienne_
Marc-Etienne M.Léveillé
11 months
@patrickwardle Thank you :) 🙏 I'm sure the whole @ESETresearch team will appreciate your comment, so I will pass it along. Most of the credit for this research goes to my colleagues @0xfmz and Anh Ho. I just helped a bit with the macOS part.
0
0
1
@marc_etienne_
Marc-Etienne M.Léveillé
1 year
Startup idea: WAF for VPN appliances
@cyb3rops
Florian Roth ⚡️
1 year
It can’t say it often enough: don’t expose your hardened VPN appliances to the Internet
0
0
2
@marc_etienne_
Marc-Etienne M.Léveillé
1 year
@0xfmz 🙌🏻
0
0
0
@marc_etienne_
Marc-Etienne M.Léveillé
1 year
@felixaime @4rchib4ld @ESETresearch @pypi Which make things... complicated.
0
0
1