Delphos Labs’ cover photo
Delphos Labs

Delphos Labs

Computer and Network Security

Uncover advanced malware, embedded risks, & supply chain threats without source code. Powered by reverse engineering.

About us

We help security teams uncover what’s hidden in compiled code, no source required. From malware triage to third-party validation, our AI platform unlocks natural language summaries, detailed component manifests, and visibility into security mitigations.

Website
delphoslabs.com
Industry
Computer and Network Security
Company size
11-50 employees
Type
Privately Held
Founded
2024
Specialties
reverse engineering, binary analysis, malware analysis, vulnerability research, cybersecurity, AI security, Enterprise security, third-party risk management, supply chain security, software integrity, cloud security, security automation, threat hunting, and GRC

Employees at Delphos Labs

Updates

  • Delphos Labs reposted this

    New threat intel. The LastPass TIME team and Delphos identified and disrupted a multi-stage malware delivery campaign impersonating at least 40 companies on GitHub. The payload delivered a Microsoft-attested kernel driver that terminated 145 antivirus and EDR processes from kernel mode. It scored 0 out of 72 on VirusTotal as of August 20, unchanged since July 2025. Thanks to Mike Kosak and Stephanie (Keinz) Schneider on the LastPass TIME team for working this one with us. The driver is a renamed copy of CcProtect.sys, which LOLDrivers already catalogues as a BYOVD process killer, with public proof-of-concept code. Same product string, version, and submitter. The operators changed the filename to Alinubx.sys. That was the evasion. Detections keyed to the known name did not match, and renaming a file changes its bytes, so the SHA256 moved with it. A blocklist of known bad hashes does not have this one. From there it opens each target process with KernelMode access, which skips the user-mode access check and defeats Protected Process Light without touching EPROCESS bits. There is no exploit here. The process-kill interface is product functionality, exposed by a host-defense driver that Windows trusts. Same driver, same version, same submitter, one new filename. That was enough. Joint writeup with the LastPass TIME team, on the Delphos Labs blog. Hashes, hunt queries, the full CcProtect comparison, and the MSRC timeline are in the post. https://lnkd.in/ePTJDXPA

  • Delphos Labs reposted this

    One of our security researchers at Delphos Labs, Kamil Leoniak, triggered kernel memory corruption on Windows using a custom USB device and a user-mode stress PoC. Microsoft assigned CVE-2026-50321, classified it as a Windows USB Driver elevation of privilege rated Important, and shipped the fix on July 14. The path was surfaced during an automated Delphos review of Windows kernel drivers, then confirmed by hand. The bug is that the freed object reference stayed reachable long enough for another path to use it. WinUSB_FreePipe frees a pipe context and only nulls the shared pointer afterward. In that window the interface pipe array still contains a pointer to freed memory, and device-control IOCTLs dispatch on a WDF parallel queue under WdfSynchronizationScopeNone, so nothing serializes access to that array. 16 threads were enough. 12 calling pipe policy APIs, 4 toggling alternate settings. A policy call read the stale pointer and took a spinlock at offset 0x28 inside a freed 0xF0-byte NonPagedPool object. Without Special Pool that allocation stays mapped and reclaimable. With it, the page is unmapped and the machine bugchecks. Full writeup on the Delphos Labs blog, with the PoC on GitHub. https://lnkd.in/espxg87M

  • Delphos Labs reposted this

    Delphos Labs has been selected by AFWERX for an SBIR Phase I focused on AI-automated analysis of source-denied software artifacts. Air Force missions run on software drawn from a vast and complex supply chain, and much of it is closed source. That software has historically had to be taken largely on trust. When someone needs a real answer about one of those files, the work falls to a small number of reverse engineers. In this Phase I we're evaluating how to put that capability in the hands of many more Air Force analysts, across a far greater volume of software. Grateful to AFWERX and the Air Force Research Laboratory for the opportunity, and proud of the team that got us here. Delphos makes software understandable and auditable even without source code, allowing analysts to vet third-party software, investigate malware, and find vulnerabilities. We do that across compiled binaries, installers, software packages, Android applications, Chrome extensions, compressed archives, firmware, and other software artifacts. https://lnkd.in/g5h9RB6r

  • Delphos Labs reposted this

    New threat intel. 60+ AV engines called this file clean. The Delphos Labs platform called it ValleyRAT in five minutes, a full day before the first signature landed. A freshly uploaded Windows executable. The filename was the first tell: a Chinese-language lure translating roughly to "click here to visit the official Crab website," impersonating a real gaming platform. From the binary alone without sandbox detonation, prior signature, or threat intel feed, we identified it as a Chinese RAT stager. Static analysis and emulation surfaced networking imports, process creation, crypto primitives, and anti-analysis checks including debugger and VM detection. The behavioral chain confirmed it. The stager retrieves a ZIP archive from an AWS S3 bucket, extracts it, and drops a randomized-name second-stage executable, FQDSZYB.exe. String extraction returned the network indicators: the S3 payload URL, and briansclub[.]mx, a domain tied to carding forums, the C2 and update server. The vendors caught up 24 hours later, long enough for the stager to run. Writeup on the Delphos Labs blog. https://lnkd.in/e2BBPKmJ

  • View organization page for Delphos Labs

    804 followers

    Jonathan Looi's zero-based SOC is worth reading in full. He asks if Tier 1 gets automated, where does next generation cyber talent come from? Junior analysts get closer to real decisions, sooner. Malware analysis has long been gated behind expert reverse engineers with years of experience, which is why most teams escalate to the few who can. When our agent does the behavioral analysis and explains what a file actually does, with no source code, a junior analyst is looking at real evidence and forming a judgment early instead of waiting years for the chance. That extends the team you have rather than the headcount you hire. The call still belongs to a person. It just arrives faster, and across far more files.

    If you were building a SOC from scratch today, knowing what AI can already do, would you hire a single Tier 1 analyst? — In zero-based budgeting, every expense needs to be justified. What if we applied that thinking to SOC hiring? It would require rethinking the entire org chart, starting from zero and justifying every role against what AI can do. Despite the "agentic everything" marketing at BlackHat, cybersecurity hasn't had the agentic overhaul software engineering has. But startups like Andesite (AI SOC analyst), Dropzone AI (AI SOC analyst), Nebulock (AI threat hunting), Armadin (AI pen testing), and Delphos Labs (AI malware analysis) are automating real pieces of the secops workflow, and improving daily. (All In-Q-Tel portcos!) AI currently excels at well-scoped cybersecurity tasks (such as triaging previously-seen alerts, writing Splunk queries, web app pen testing) and still struggles with long-horizon work requiring chained judgement calls. At the current rate of AI capability gains, I expect to see those long-horizon tasks become reliably automatable soon. Here's my zero-based SOC: - Tier 1 / Tier 2 Analysts: out. Yes, I know. I’ve been hearing that Tier 1 SOC roles are dead for 5+ years (SOAR, XDR, XSOAR...). But the difference now is that agents have the reasoning that SOAR never did. Tier 1 analyst was my first job in cyber, so I don't say this lightly. Open to counterarguments. - Tier 3 Analysts: in, higher demand. This is the SOC’s equivalent of the Staff software engineer, reviewing work produced by junior employees, except the junior employees are now agents. Their judgement, developed over years of experience, will be 10x'd. - Threat Hunters / Detection Engineers: still in, but fewer. Humans stay creative on hunt hypotheses and write the specs. Agents implement detection-as-code and grind through the queries. - Incident responders: in, but fewer. Agents accelerate the forensics, a human still directs them and runs the incident with legal and comms. - Malware Analysts and Red Teamers: in, but fewer, both heavily augmented by agents, with humans reserved for edge cases and oversight. - AI Security Engineers: new role. Someone has to build and maintain the agents, tools, and context. These individuals must be fluent in both SOC workflows and AI engineering (building agents, evals, skills, and tools). Overall, I believe there will be fewer humans doing rote work, and much more leverage for experienced professionals managing agents. Most existing SOC roles won’t necessarily disappear, but they’ll all start to meld into agent management and agent engineering. Two open questions: - More jobs or fewer? My guess: fewer defenders needed per org, but AI-accelerated attackers may drive total demand back up. - If Tier 1 gets automated, where does the next generation of cyber talent come from? I don't have a good answer to this one, and it's a question every other field is wrestling with for entry level roles.

  • Delphos Labs reposted this

    On the side lines of the AI Cyber Alliance meet-up yesterday in Tyson’s Corner, some of our nation’s top defenders discussed this attack. For example we had technical leadership from the TAC there - amongst our nation’s leaders at this very subject. Thankful to Aaron Boteler from CloudCurrent who works w DeepTempo at the TAC for attending and sharing his expertise and sparking at least a few deeper conversations. Of course Joseph Szczerba who helped the nation respond to Colonial Pipeline while a leader at the FBI was one of our speakers. Thank you Joe for your heartfelt, funny and inspirational talk and for adding your expertise to many of the side conversations that sparked. The event was Chatham House so who said what is 🤐 FWIW - I know the tech I demo’d and that Joe and team build at Delphos Labs and that of others like CloudCurrent can help. We are proving it every day. I’m most excited about the community itself forming. Instead of paying CISOs to play golf w us at Vegas we are open sourcing our tech and demonstrating it in no BS meet ups. 😇 That said - the more you learn about our vulnerabilities and the pace at which our admittedly overwhelmed local decision makers are moving the more you loose sleep at night and find yourself wanting to SCREAM - look here, we can help, ask the TAC they’ll show you it all working in amazing ranges. Talk to the TAC they are 1000% in the fight to help. Talk to your local telco there is a chance they know first hand too and others. This is that scream. And also a thank you to our speakers and diverse set of attendees ranging from students to very senior protectors of our nation. There were more than a few investors and fellow builders in the room too. A special shout out to JTEK Data Solutions who is in the fight as well with systems and expertise and provided again their excellent facilities. Together we win - but we’ve got to move much much faster. Links to the AI Cyber Alliance below. Please consider sharing a talk - Boston, NYC, DC, SF and other locations all soon to be announced, w/ your help. 🤞🤝💪🏽

    • No alternative text description for this image
  • Two days out. Thursday in Tysons is Chatham House rules. No recordings, no transcripts. Our CISO Joseph Szczerba, formerly Senior Executive in the FBI's Cyber Division, is on stage with Evan Powell of DeepTempo. Registration is still open. https://lnkd.in/e9r45Uu8

    This week is a fun one - I'm in DC and speaking on Thursday. Tomorrow John Van Lowe is speaking in Boston. In both cases our fellow speakers are 🔥 Boston: https://lnkd.in/eJU6iX5b Alissa Valentina Knight is speaking. Amongst other things Assail built a purpose built model for red team and offense. Build a purpose built model?! Alissa has led red teams for national defense and is a globally recognized expert. And here in DC: https://lnkd.in/e9r45Uu8 Joseph Szczerba is speaking. Amongst other things, he led efforts at the FBI to counter state sponsored cyber attacks. He is now CISO at Delphos Labs which is at the forefront of using AI to deeply and quickly understand malware and other attacks. Come grab free beer and pizza. At least in DC this will be Chatham House rules so the organizers will not be sharing the videos. Get to know more about AI in cyber by going beyond the abstract, and seeing real world use cases implemented at scale. Looks like both sessions are filling up. Yes, that's a nano banana image, not actually a photo of a previous AI in Cyber meet-up, though it captures the vibe.

    • No alternative text description for this image
  • View organization page for Delphos Labs

    804 followers

    Hugging Face incident post-mortem is out, from the Cloud Security Alliance, CISO Community with SANS, [un]prompted, RSAC, Knostic, & FIRST. Edited by Gadi Evron & David B. Cross, with Delphos Labs CISO Joseph Szczerba among the contributing authors.

    View profile for Gadi Evron

    We are releasing the post-mortem for the Hugging Face incident, written by hundreds of members of the CSA CISO community over the weekend, and reviewed by the Hugging Face team. In the document: - Our best, if initial, understanding of what happened at Hugging Face - Our combined recommendations on how the incident affects security program building, from detection engineering to strategy. While it is written as a standalone document, it should be treated as an update to the "Building a Mythos-ready security program" paper, with lessons learned from the incident. Link: https://lnkd.in/db6Weesj (There is a free download link if you don't have an account) This is our second Expedited Strategy Briefing, a joint community effort involving multiple industry organizations: Cloud Security Alliance, SANS Institute, [un]prompted, RSAC Conference, Knostic, and FIRST. Many thanks go to the Hugging Face team, and specifically to Thomas Wolf, Hugo Larcher, and Adrien Carreira. They not only chose to share openly, but did so within days of the incident, contributing significantly to our collective defense. They've shown us how it's done, and we should follow their example. I'd also like to thank my co-editor for this effort, David B. Cross, CISO of Atlassian. And the authors of the paper: Rich Mogull, Rob T. Lee, Sounil Yu, Maxim K., Mike Johnson, Jen Easterly, Jim Reavis, Ariel Litvin, Michael Colao, Gary Hayslip, and Sergej Epp. And extra thanks to Sergej Epp, who helped make this happen. My personal ask: Many contributing authors worked over the weekend, and LinkedIn won't let me tag them all (I will do my best in the comments). So, as a favor for me, could you go over the list of contributors, see whom you might know, and send them a note of thanks? Last but definitely not least, thank you to the people behind the scenes, Courtney Stiven, Noelle Sheck, Jenn Elston, John Yeoh, Illena Armstrong, and Ryan Gifford for all you do.

    • No alternative text description for this image
  • On July 30th, we'll be at the AI Cyber Alliance Meetup in Tysons, Virginia. Our CISO, Joseph Szczerba, will share insights from the front lines of national cybersecurity. He'll speak alongside Evan Powell, Founder & CEO, DeepTempo. Before joining Delphos Labs, Joe was a Senior Executive in the FBI's Cyber Division, where he: → Defended against advanced nation-state cyber attacks → Led analysis of sophisticated threats to critical infrastructure → Played a key leadership role in the FBI's CISO Academy If you're working where AI meets cybersecurity, come say hello. Register on Luma: https://lnkd.in/gwPMrTAb

  • Delphos Labs reposted this

    New threat intel. A credential stealer took the name of libpsl-5.dll, a Windows library of approximately 200KB, and inflated itself to 55MB. Zero detections across 60+ AV engines when we analyzed it. The Delphos Labs platform pulled it apart on day one; the automated run took 8 minutes, with no human intervention. The vendors did not catch up for six days. The bloated size is the primary evasion mechanism. The real code ends at about 3.3MB. The other 52MB is a single four-byte pattern repeated across the entire overlay, sitting outside every PE section and outside the image the Windows loader maps. The loader never reads it. It executes nothing. Its only job is to push the file past the size most engines and sandboxes scan. No signatures. Detection came from structural and behavioral anomalies: the size mismatch, plus an import table pairing process injection with network enumeration. Nothing a suffix-list library would do. Its code overlaps several known info-stealer families. Writeup on the Delphos Labs blog. https://lnkd.in/eBTwSHBT

Similar pages

Browse jobs