Teoderick Contreras's Blog Posts

Teoderick Contreras

I'm a Senior Threat Research Engineer on Splunk's Threat Research Team. I've been working in the cybersecurity industry for almost 12+ years. I primarily focus on malware reverse engineering/analysis, digital forensics and detection development.

Peeling Back the Layers: Inside Vidar - From Virtualized Code to Stolen Credentials
Security
15 Minute Read

Peeling Back the Layers: Inside Vidar - From Virtualized Code to Stolen Credentials

Explore how the Vidar info-stealer uses virtualized code, anti-analysis tactics, and sandbox evasion to hide its activity. Learn how to identify and detect Vidar in your environment using actionable Splunk TTPs and analytics.
Phantom Stealer Unmasked: Shellcode, Steganography, and Credential Theft
Security
15 Minute Read

Phantom Stealer Unmasked: Shellcode, Steganography, and Credential Theft

Unmask Phantom Stealer, a .NET credential-stealing threat, and explore its steganography, shellcode injection, and evasion tactics with 32 actionable Splunk detections.
Bundled to Steal: The Salat Stealer Campaign
Security
12 Minute Read

Bundled to Steal: The Salat Stealer Campaign

Learn how the Salat Stealer campaign uses Go-based surveillance and data exfiltration, and explore its infection chain and how to hunt for this threat using Splunk.
Behind the Code: The Layered Defense-Evasion of VIP Keylogger
Security
15 Minute Read

Behind the Code: The Layered Defense-Evasion of VIP Keylogger

The Splunk Threat Research Team analyzes the VIP Keylogger malware. Learn about its evasion tactics, including obfuscation and steganography, to improve your detection and threat-hunting strategies.
Behind the Walls: Techniques and Tactics in Castle RAT Client Malware
Security
10 Minute Read

Behind the Walls: Techniques and Tactics in Castle RAT Client Malware

Uncover CastleRAT malware's techniques (TTPs) and learn how to build Splunk detections using MITRE ATT&CK. Protect your network from this advanced RAT.
Hide Me Again: The Updated Multi-Payload .NET Steganography Loader That Includes Lokibot
Security
10 Minute Read

Hide Me Again: The Updated Multi-Payload .NET Steganography Loader That Includes Lokibot

An analysis on the updated .NET steganography loader delivering Lokibot malware, including evasion techniques, MITRE ATT&CK TTPs, and Splunk detections to enhance threat identification.