IONSEC

Topic hub

Cyber research

Definition

Cyber threat research — is the systematic investigation of adversary tooling, infrastructure and behaviour — malware analysis, campaign attribution and technique documentation — carried out to make the resulting knowledge usable in defence.

We publish what we find. The analysts on a retainer are the same team that tracks state-sponsored actors and ships the open-source tooling, and what we see in the field shapes the hunts we run for clients — often before the technique is widely documented.

What we research

Our published work covers state-sponsored actors and the campaigns they run, wiper malware — including the campaign we track as Operation HANDALA — and the reverse engineering of specific tooling encountered in live intrusions. We write up the intrusions themselves as case studies where the client permits it, because a technique explained against a real timeline is far more useful than one described in the abstract.

Why a response firm publishes research

Research and response are the same work seen from two directions. A campaign taken apart in the lab produces the detection logic and hunting hypotheses used on the next engagement; an intrusion worked in the field produces the samples and infrastructure that become the next piece of research. Separating the two, as larger firms tend to, means the people who know the actor best are not the people on your call.

Where we present it

We present at GISEC Global, GPEC and HackExpo, brief international delegations on our wiper malware research, and sit in the Israel National Cyber Directorate MIRROR Forum alongside fourteen other Israeli incident response companies. Everything we publish is free to read and free to use, with no registration gate.

Everything we have published on cyber research

18 pieces of research, tooling and case-study work.

ArticleXSS2Shell: One Failed Login to PHP on the ServerCVE-2026-64638 is a reflected XSS on the WordPress login page — the finding most teams close as medium. Six gadgets sit between it and a PHP shell, and every one of them was already in core. Here is the chain, the log signatures, and what to harden after you patch.Aug 2026 · 14 minArticleXSS2Shell: מניסיון התחברות כושל אחד ועד PHP על השרתCVE-2026-64638 היא חולשת XSS מוחזר בעמוד ההתחברות של וורדפרס — בדיוק הממצא שרוב הצוותים סוגרים כבינוני. בין החולשה הזו לבין הרצת PHP על השרת עומדים שישה שלבים נוספים, וכולם כבר היו בליבת המערכת. הנה השרשרת המלאה, חתימות הזיהוי בלוגים, וההקשחה שצריך לעשות אחרי העדכון.Aug 2026 · 15 minArticleCoercion to krbtgt: NTLM Relay and ADCS ESC8 in 2026A full ESC8 walkthrough against a lab domain, then the forensic reconstruction — why the certificate serial, not the source IP, is the artifact that ties the whole chain together.Jul 2026 · 15 minToolsTikun13 Checker – כלי קוד פתוח לבדיקת יישום תיקון 13Tikun13 Checker הוא כלי קוד פתוח, מבוסס דפדפן, שפותח על ידי IONSEC כדי לסייע לארגונים בישראל ליישם את דרישות תיקון 13 לחוק הגנת הפרטיות.Aug 2025 · 2 minCase StudyWhen Research Meets RealityHow Threat-Actor Campaigns Cast a Shadow on Legitimate npm Binaries (and What IONSEC IR Sees in the wild)Jul 2025 · 8 minCase StudyHow a Weaponized Zoom Installer Opened the Door for BlueNoroffIONSEC investigates a BlueNoroff intrusion that began with a weaponized Zoom installer, combining deepfakes, social engineering and evasive scripting.Jul 2025 · 8 minCase StudyIranian Threat Actor Hijacks DNSקבוצת התקיפה האיראנית פתח אלקודס פרצה לרשם דומיינים ישראלי ושינתה רשומות DNS ו-MX של יותר מ-1,000 דומיינים, והפנתה אותם לשרת זדוני ולדף תעמולה.Jul 2025 · 9 minNewsIONSEC at the IMPROVATE CISO SummitTwo months ago, IONSEC had the privilege of participating in the CISO Summit by IMPROVATE — a premier platform for connecting with Israel’s leading cybersecurity executives and security professionals.Jun 2025 · 1 minNewsLIVE from GISEC Global 2025 – Israeli PavilionIONSEC is proud to showcase an exclusive preview of our next-generation Digital Forensics and Incident Response (DFIR) platform at GISEC Global 2025, one of the world’s premier cybersecurity events in Dubai.May 2025 · 1 minArticleWhy Malware Analysis Training is Vital: Lessons from Real-World Cyber AttacksPicture this: airport metal detectors efficiently catch large, obvious weapons, but small components slip through unnoticed. Once inside, attackers assemble them into a complete weapon.Dec 2024 · 1 minNewsIONSEC at HackExpo 2024 – Breach at the FrontlineAt HackExpo 2024, IONSEC CEO Nir Halfon shared practical strategies for responding to exploits in fintech first-party applications under live pressure.Nov 2024 · 3 minBlogReverse Engineering GodPotato (MSASCui.exe)Privilege escalation is a critical technique employed by attackers to gain unauthorized access to higher system privileges, often leading to significant security breaches.Nov 2024 · 4 minBlogClearing the Mist: Unveiling Fog RansomwareA full analysis of the Fog Ransomware Group: the malware it deploys, the TTPs it relies on to infiltrate high-tech firms, and how defenders can disrupt it.Aug 2024 · 5 minNewsIONSEC Joins the 3rd MIRROR Forum with INCDOn June 28, IONSEC proudly participated in the third MIRROR Forum — a unique gathering of 15 Incident Response (IR) companies across Israel, convened by the Israel National Cyber Directorate (INCD).Jun 2024 · 1 minNewsIONSEC Shares Wiper Malware Research with Czech Delegation in IsraelIONSEC hosted a Czech delegation in Israel to present our Wiper malware research, including the campaign we track as Operation HANDALA.Jun 2024 · 1 minNewsIONSEC at GPEC 2024 – Showcasing APT Research on the Global StageWow — what a journey GPEC (General Police Equipment Exhibition & Conference) was this year. Standing among 471 exhibitors from 32 different countries was nothing short of inspiring. The scale, the diversity, and the energy of the event made it a true highlight of 2024.May 2024 · 2 minBlogSovaTeam - New State-Sponsored APTHow IONSEC and White-Hat traced the Sova Team threat actor through a ransom note to uncover a state-sponsored APT operating past strict security controls.Mar 2024 · 8 minBlogסקירה מודיעינית 2024 #OpIsraelIONSEC הינה חברת בוטיק לשירותי אבטחת מידע ותגובה לאירועי סייבר (24/7) העוסקת במחקר ותגובה לאיומים מתקדמים ומספקת פתרונות אבטחה מותאמים אישית לחברות ברחבי העולם.Mar 2024 · 10 min

Common questions

What is cyber threat research?

Cyber threat research is the systematic investigation of adversary tooling, infrastructure and behaviour — reverse engineering malware, mapping command and control infrastructure, attributing campaigns to actors, and documenting techniques. Its purpose is to convert what an adversary does into detection logic and hunting hypotheses defenders can use.

What is an APT?

An APT, or advanced persistent threat, is a well-resourced adversary — usually state-sponsored or state-aligned — that targets a specific organization and maintains access over an extended period rather than seeking immediate financial gain. The defining characteristics are persistence, operational discipline, and a willingness to spend months on a single target.

What is wiper malware?

Wiper malware is designed to destroy data irrecoverably rather than to encrypt it for ransom. It is often disguised as ransomware — presenting a ransom note for data that no longer exists — because the disguise buys time and confuses the initial response. Recovery depends entirely on backups that were isolated from the affected environment.

What is Operation HANDALA?

Operation HANDALA is the name IONSEC uses for a wiper malware campaign it has tracked and published research on, and which it has briefed to international delegations including a Czech delegation hosted in Israel. The research is published in full on the IONSEC resources section.

Is IONSEC research free to read?

Yes. All IONSEC threat research and all six of its DFIR tools are published without a registration gate, paywall or lead-capture form.

Talk to the team that does the work

The people who publish the research above are the people who take your escalations.