Chasing a ClickFix campaign down the blockchain
From a compromised law firm site to a loader that abuses trusted infrastructure — payload logic held in contract storage, staged through a CDN and WebDAV over HTTPS, ending in a trojanized installer.
Offensive Security Engineer at Secuna. I get paid to find the path from a single foothold to everything that matters, then write it down clearly enough to fix.
Web applications, internal networks, Active Directory. Off the clock: threat intelligence, on-chain malware tracking, and running a community for people trying to break into this field.
The surface I work across, and the shape these engagements usually take. Findings belong to the client, so none appear here — the techniques are the part I can talk about.
Authentication, authorization, and everything the server takes on trust
Full assessments against production web applications and APIs: mapping the real attack surface, then working the places where server-side checks are missing rather than the places a scanner points at. Most of what matters lives in authorization logic — object references, tenant boundaries, role assignment, session lifetime.
Every engagement ends in a report a developer can act on, and a retest that proves the fix actually held.
From one authenticated foothold to the objects that actually matter
Internal assessments where the question isn't whether a host is vulnerable, but how far a single set of valid credentials gets you. Directory misconfiguration beats missing patches nearly every time: delegation settings, certificate templates, signing requirements, ACLs nobody has audited since the domain was built.
CRTO and CRTA back this track, and the reporting is where it earns its keep — a graph of who can reach what, not a list of CVEs.
Exported components, and secrets that were only ever hidden
Static and dynamic analysis of Android apps, worked through the Mobile Hacking Lab challenges and written up in full. Exported activities and receivers that accept input from any installed app, values that reach a shell unquoted, and keys that obfuscation only made harder to read, not harder to extract.
Writeups for the IoT Connect, Cyclic Scanner and Strings labs are linked in the next section.
adb root · frida-server · Burp CAFollowing a live campaign until the infrastructure runs out
Independent tracking of an active ClickFix operation that stores its loader in smart contract storage. There is no host to seize and no domain to sinkhole, and rotating the payload costs the operator one transaction — so the analysis moves on-chain instead.
Decoding setter transactions rebuilds the command-and-control rotation history in order, which is the part a takedown request can't touch. Published in full; the macOS variant is still open.
eth_call → payloadThreat intelligence, mobile labs and certification notes, under the ghostwirez handle.
From a compromised law firm site to a loader that abuses trusted infrastructure — payload logic held in contract storage, staged through a CDN and WebDAV over HTTPS, ending in a trojanized installer.
Working an exported component that trusts input from any app on the device, from manifest review through to a working proof of concept.
A filename that reaches a shell unquoted, which makes naming the file the exploit. Command execution in the app's own context.
Recovering encryption keys from a running process with Frida and fridump, after the static route turned out to be the long way round.
An honest account of preparing for and passing Certified Red Team Operator — what the lab time is worth, and what I'd study differently.
The longer-form notebook: lab setups, tooling that earned a place in the workflow, and the research that isn't finished enough to publish yet.
Red team heavy, all hands-on exams. The hatched ones are the current reading list, not a wish list.
Offensive Security Engineer
Web application and internal network penetration testing, end to end: scoping, exploitation, the report, and the retest that proves the fix held.
Software Engineer
Built software before breaking it for a living. Reading a codebase the way its maintainer does is still the shortest route to a finding.
Lead Network & Security Engineer · internship
First time on the defensive side of a live network, which is still where a lot of my instincts about what actually gets noticed come from.
BS Computer Engineering, Caloocan · magna cum laude
Elsewhere
I started CyberwireZ because the fastest way to get good at this is in a room with other people trying to get good at it.
As Hack The Box Philippines Ambassador I run meetups, hands-on workshops and campus sessions — mostly for people making a first serious attempt at offensive security, which is where I was not that long ago. Organising something and need a speaker or a lab track? Ask.
Meetups
Regular CyberwireZ and HTB Philippines gatherings
Workshops
Hands-on sessions, including Linux fundamentals on campus
Conferences
CyberwireZ turns up — BSides Manila and friends
Speakers
Booking talks and village sessions with the local scene