<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Trellix on Aswath's Blog</title><link>https://aswath-a.github.io/trellix/</link><description>Recent content in Trellix on Aswath's Blog</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><lastBuildDate>Mon, 24 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://aswath-a.github.io/trellix/index.xml" rel="self" type="application/rss+xml"/><item><title>Technical Deep Dive: The Monero Mining Campaign</title><link>https://aswath-a.github.io/trellix/monero-mining-campaign/</link><pubDate>Tue, 17 Feb 2026 00:00:00 +0000</pubDate><guid>https://aswath-a.github.io/trellix/monero-mining-campaign/</guid><description>&lt;div style="border-left: 4px solid #268bd2; padding: 0.6em 1em; margin-bottom: 1.8em; border-radius: 2px;">
&lt;strong>Originally published on the
&lt;a href="https://www.trellix.com/blogs/research/technical-deep-dive-the-monero-mining-campaign/" target="_blank" rel="noopener">Trellix Research Blog&lt;/a>
&amp;mdash; Feb 17, 2026&lt;/strong>&lt;br>
&lt;small>
&lt;a href="https://web.archive.org/web/*/https://www.trellix.com/blogs/research/technical-deep-dive-the-monero-mining-campaign/" target="_blank" rel="noopener">Wayback Machine archive&lt;/a>
&amp;nbsp;&amp;middot;&amp;nbsp;
&lt;a href="https://aswath-a.github.io/publications/monero-mining-campaign.pdf">Download PDF backup&lt;/a>
&lt;/small>
&lt;/div>
&lt;p>A granular look at an infection cluster identified in late 2025 — tracing the attackers&amp;rsquo; tradecraft, tooling, and operational security posture from the initial social-engineering lure all the way to the execution of privileged instruction sets in Ring 0.&lt;/p></description></item><item><title>The Ghost in the Machine: Unmasking CrazyHunter's Stealth Tactics</title><link>https://aswath-a.github.io/trellix/crazyhunter-stealth-tactics/</link><pubDate>Tue, 06 Jan 2026 00:00:00 +0000</pubDate><guid>https://aswath-a.github.io/trellix/crazyhunter-stealth-tactics/</guid><description>&lt;div style="border-left: 4px solid #268bd2; padding: 0.6em 1em; margin-bottom: 1.8em; border-radius: 2px;">
&lt;strong>Originally published on the
&lt;a href="https://www.trellix.com/blogs/research/the-ghost-in-the-machine-crazyhunters-stealth-tactics/" target="_blank" rel="noopener">Trellix Research Blog&lt;/a>
&amp;mdash; Jan 6, 2026&lt;/strong>&lt;br>
&lt;small>
&lt;a href="https://web.archive.org/web/*/https://www.trellix.com/blogs/research/the-ghost-in-the-machine-crazyhunters-stealth-tactics/" target="_blank" rel="noopener">Wayback Machine archive&lt;/a>
&amp;nbsp;&amp;middot;&amp;nbsp;
&lt;a href="https://aswath-a.github.io/publications/crazyhunter-stealth-tactics.pdf">Download PDF backup&lt;/a>
&lt;/small>
&lt;/div>
&lt;p>An in-depth analysis of CrazyHunter ransomware — a fork of the Prince ransomware that surfaced in mid-2024 — examining its network compromise techniques, anti-malware evasion mechanisms, and the full attack flow used against Taiwan healthcare systems.&lt;/p></description></item></channel></rss>