Kuba Gretzky (@mrgretzky) 's Twitter Profile
Kuba Gretzky

@mrgretzky

Offensive security tools developer. Malware dev, bedroom DJ & ex-MMO game hacker. Creator of Evilginx / Bartender @ BREAKDEV RED.
bsky: @mrgretzky.breakdev.org

ID: 730382759567499264

linkhttps://breakdev.org calendar_today11-05-2016 13:03:14

5,5K Tweet

15,15K Followers

691 Following

Maurice Heumann (@momo5502) 's Twitter Profile Photo

Holy shit :O After days of struggle, my emulator now runs in the browser 🙌 I managed to compile it to webassembly so that it can emulate 64 bit windows binaries right in your browser. Go try it out :D momo5502.github.io/emulator

Holy shit :O After days of struggle, my emulator now runs in the browser 🙌

I managed to compile it to webassembly so that it can emulate 64 bit windows binaries right in your browser.

Go try it out :D

momo5502.github.io/emulator
Kuba Gretzky (@mrgretzky) 's Twitter Profile Photo

🐣 HAPPY EASTER SALE 🐣 The Easter Bunny brought phish instead of chocolate this year - it's dropping 30% OFF the Evilginx Mastery course! Because nothing says "festive" like bypassing MFA and levelling up your phishing skills. 😈💻 🔗 academy.breakdev.org/evilginx-maste…

🐣 HAPPY EASTER SALE 🐣

The Easter Bunny brought phish instead of chocolate this year - it's dropping 30% OFF the Evilginx Mastery course!

Because nothing says "festive" like bypassing MFA and levelling up your phishing skills. 😈💻

🔗 academy.breakdev.org/evilginx-maste…
Gi7w0rm (@gi7w0rm) 's Twitter Profile Photo

So this just happend to me: gamerhorizon.com/2015/01/28/psa… 800 Gigs of Data gone. Years of work. Because the installer for @Bethesda @Elderscrolls Online decided to wipe the complete disk upon uninstall.

Kuba Gretzky (@mrgretzky) 's Twitter Profile Photo

Check out Dennis Kniep's novel take on the Device Code phishing attack. This attack enables attackers to phish users through a legitimate Microsoft domain, and remarkably, it can even phish FIDO2 MFA-protected accounts. 🔥🪝🐟 It's a feature, not a bug! 😀

Kuba Gretzky (@mrgretzky) 's Twitter Profile Photo

🪝 Here is what's coming in the Evilginx Pro 4.1 update, releasing in the upcoming weeks. 🛡️ Complete Google Safe Browsing (Enhanced protection) evasion 🔧 Complete proxy engine rewrite ✂️ URL path rewrite capability 🔣 HTML/JS obfuscation Get it here: evilginx.com

🪝 Here is what's coming in the Evilginx Pro 4.1 update, releasing in the upcoming weeks. 

🛡️ Complete Google Safe Browsing (Enhanced protection) evasion
🔧 Complete proxy engine rewrite
✂️ URL path rewrite capability
🔣 HTML/JS obfuscation

Get it here:
evilginx.com
𝙁 𝙀 𝙇 𝙄 𝙓 𝙈 (@felixm_pw) 's Twitter Profile Photo

With some guidance from DebugPrivilege I've found a way to easily dump clear text implants even while they sleep. Bad day for sleep obfuscation 💤 blog.felixm.pw/rude_awakening…

Kuba Gretzky (@mrgretzky) 's Twitter Profile Photo

‼️ Evilginx Pro 4.1 - Google Safe Browsing evasion 🛡️ I've just uploaded a short demo video demonstrating how Evilginx Pro is able to evade Enhanced protection in Google Chrome browser. The update is coming soon! 🔗 youtube.com/watch?v=6AJ6dY…

‼️ Evilginx Pro 4.1 - Google Safe Browsing evasion 🛡️

I've just uploaded a short demo video demonstrating how Evilginx Pro is able to evade Enhanced protection in Google Chrome browser.

The update is coming soon!

🔗 youtube.com/watch?v=6AJ6dY…
Atsika (@_atsika) 's Twitter Profile Photo

ProxyBlob is alive ! We’ve open-sourced our stealthy reverse SOCKS proxy over Azure Blob Storage that can help you operate in restricted environments 🔒 🌐 github.com/quarkslab/prox… Blog post for more details right below ⬇️

Kuba Gretzky (@mrgretzky) 's Twitter Profile Photo

‼️Evilginx Pro - Update 4.1 is OUT! 🔥 I'm happy to say I've released the first major update to Evilginx Pro today! 🥳 I appreciate your support. This update serves as a token of my gratitude. 💗 Fixes will come to community version later in future 🔗 evilginx.com

‼️Evilginx Pro - Update 4.1 is OUT! 🔥

I'm happy to say I've released the first major update to Evilginx Pro today! 🥳

I appreciate your support. This update serves as a token of my gratitude. 💗

Fixes will come to community version later in future

🔗 evilginx.com
Jonathan Peters (@cod3nym) 's Twitter Profile Photo

Stumbled over this new AMSI bypass. It works by manipulating the COM RPC communication used by AMSI to talk to AV engines. By hooking NdrClientCall3 which handles the RPC calls we can intercept AMSI scan requests before they reach the AV engine. I wrote a simplified version that

OrangeCon (@orangecon_nl) 's Twitter Profile Photo

All the Orangecon talks are now available on YouTube! (Re)watch the insightful talk on Kernel Driver Vulnerability Hunting by Jan Jaap here: youtu.be/39N9qJk55Ac?si…

Kuba Gretzky (@mrgretzky) 's Twitter Profile Photo

“You have to humanize [the cheat] to a degree where the advantage is imperceptible from what a human can do,” said Koskinas. “And once you’re there, you’re not really cheating enough to make it worth it for most users.” techcrunch.com/2025/05/03/how…

Roy Carrilho (@ruicarrilho5) 's Twitter Profile Photo

Here's a classic - Write your Own Virtual Machine! This guide teaches you how to make a virtual machine that can run 2048 or Roguelike from scratch, in C. This can teach you a lot on how computers work, and you can follow the guidelines to implement it in any language. Enjoy!

Here's a classic - Write your Own Virtual Machine! This guide teaches you how to make a virtual machine that can run 2048 or Roguelike from scratch, in C. This can teach you a lot on how computers work, and you can follow the guidelines to implement it in any language. Enjoy!
Alex (@xaitax) 's Twitter Profile Photo

🚀 Just dropped v0.5 of my Chrome App-Bound Encryption Decryption tool! Full user-mode (no admin), all path-validation bypasses, full cookie extraction (JSON 🍪) and stealth DLL injection. Chrome’s ABE is officially broken, works on Chrome, Edge & Brave. Anything else to tackle

🚀 Just dropped v0.5 of my Chrome App-Bound Encryption Decryption tool! Full user-mode (no admin), all path-validation bypasses, full cookie extraction (JSON 🍪) and stealth DLL injection. Chrome’s ABE is officially broken, works on Chrome, Edge & Brave. Anything else to tackle
LukHash (@lukhash) 's Twitter Profile Photo

Hey guys, some of you been asking if you can use the new album on your #Twitch streams. I can confirm 'Home Arcade' is 100% DMCA-safe, just like my other albums, so feel free to use it as background music. 👾 Just credit me in the description or give a shoutout.

Hey guys, some of you been asking if you can use the new album on your #Twitch streams. I can confirm 'Home Arcade' is 100% DMCA-safe, just like my other albums, so feel free to use it as background music. 👾 Just credit me in the description or give a shoutout.