Skip to content

OffsetZer0

Offensive researchAnalysisDevelopment

A child facing a tower of surveillance screens
0x00Research

Trust Relay: a PWA alternative to cloned-login phishing

How I used a genuine PWA install as the trust cue, then handed the user to real Google OAuth instead of cloning the login page.

10 min read
Read article
0x01Research

Reproducing the Coldcard Entropy Exploit Without Owning a Coldcard

How I reconstructed the Coldcard entropy failure without physical hardware, built an emulator and CUDA-assisted scanner, and stopped with a partial, zero-hit result rather than overstating what the model proved.

25 min read
Read article
0x02Development

Creating a Google Phishlet for Evilginx

How I created a phishlet for Google's authentication flow for Evilginx, covering the 11 subdomains, 20+ session cookies, and the JavaScript injection needed to handle Google's streaming push channel.

YAML
T1557.001T1539T1111
Read article
0x03Research

Hermit Android Surveillanceware

Two post-disclosure Hermit Android builds from the same operator campaign show a thin dropper, deleted runtime modules, core-brokered Android privileges, and a stage-2 protobuf crypto protocol.

24 min read
T1407T1406T1512
Read article
0x04Development

Apnea: a full-memory sleep obfuscation engine for Linux

Building a Linux sleep-obfuscation engine with full-image ChaCha20 encryption, raw syscalls, and a userland ELF loader.

C17 min read
Read article
0x05Research

Coruna iOS Exploit Kit

Reverse engeenering of the government-grade iOS exploit kit identified by GTIG in February 2025.

60 min read
T1190T1059.007T1140
Read article