OffsetZer0
Offensive researchAnalysisDevelopment

Trust Relay: a PWA alternative to cloned-login phishing
How I used a genuine PWA install as the trust cue, then handed the user to real Google OAuth instead of cloning the login page.
Reproducing the Coldcard Entropy Exploit Without Owning a Coldcard
How I reconstructed the Coldcard entropy failure without physical hardware, built an emulator and CUDA-assisted scanner, and stopped with a partial, zero-hit result rather than overstating what the model proved.
Creating a Google Phishlet for Evilginx
How I created a phishlet for Google's authentication flow for Evilginx, covering the 11 subdomains, 20+ session cookies, and the JavaScript injection needed to handle Google's streaming push channel.
Hermit Android Surveillanceware
Two post-disclosure Hermit Android builds from the same operator campaign show a thin dropper, deleted runtime modules, core-brokered Android privileges, and a stage-2 protobuf crypto protocol.
Apnea: a full-memory sleep obfuscation engine for Linux
Building a Linux sleep-obfuscation engine with full-image ChaCha20 encryption, raw syscalls, and a userland ELF loader.
Coruna iOS Exploit Kit
Reverse engeenering of the government-grade iOS exploit kit identified by GTIG in February 2025.


