Delphos LabsDelphos Labs

Delphos Labs Blog

Featured
Jul 14, 2026

Threat Intel: libpsl-5.dll. A Sideloading DLL Padded to 55MB, Undetected by 60+ AV Engines for Six Days

The real payload is 3.3MB. The other 52MB is junk padding, appended to slip past scanners. Its code overlaps several known info-stealer families.

Evgeny Pinchuk
EP
Evgeny Pinchuk
Threat Intel: libpsl-5.dll. A Sideloading DLL Padded to 55MB, Undetected by 60+ AV Engines for Six DaysThreat Intel: libpsl-5.dll. A Sideloading DLL Padded to 55MB, Undetected by 60+ AV Engines for Six Days
Threat Intel: libpsl-5.dll. A Sideloading DLL Padded to 55MB, Undetected by 60+ AV Engines for Six Days thumbnailThreat Intel: libpsl-5.dll. A Sideloading DLL Padded to 55MB, Undetected by 60+ AV Engines for Six Days thumbnail
Security Research

Threat Intel: libpsl-5.dll. A Sideloading DLL Padded to 55MB, Undetected by 60+ AV Engines for Six Days

The real payload is 3.3MB. The other 52MB is junk padding, appended to slip past scanners. Its code overlaps several known info-stealer families.

Evgeny Pinchuk
EP
Evgeny PinchukJul 14, 2026
Threat Intel: ValleyRAT. A Zero-Detection Stager Classified 24 Hours Before Its First Signature thumbnailThreat Intel: ValleyRAT. A Zero-Detection Stager Classified 24 Hours Before Its First Signature thumbnail
Security Research

Threat Intel: ValleyRAT. A Zero-Detection Stager Classified 24 Hours Before Its First Signature

A Chinese-language ValleyRAT stager, zero AV detections, pulling a second-stage payload from AWS S3, classified in 5 minutes, 24 hours before first signature.

Evgeny Pinchuk
EP
Evgeny PinchukJul 14, 2026
fast16: From Stripped Binary to Sabotage Finding in Minutes thumbnailfast16: From Stripped Binary to Sabotage Finding in Minutes thumbnail
Security Research

fast16: From Stripped Binary to Sabotage Finding in Minutes

The Delphos Labs agent analyzed fast16, a 2005 nation-state sabotage framework, starting from two stripped binaries and no context.

Itai Liba
IL
Itai LibaJul 13, 2026
DirtyCBC: When Linux Kernel Decrypt-Before-MAC Turns Authenticated Encryption Into a Page-Cache Write thumbnailDirtyCBC: When Linux Kernel Decrypt-Before-MAC Turns Authenticated Encryption Into a Page-Cache Write thumbnail
Security Research

DirtyCBC: When Linux Kernel Decrypt-Before-MAC Turns Authenticated Encryption Into a Page-Cache Write

Linux kernel page-cache poisoning via AES-256 chosen-plaintext on the RxGK RESPONSE path and why authenticated encryption did not stop it.

Kamil Leoniak
KL
Kamil LeoniakMay 15, 2026
Introducing Delphos Labs: Securing the Software That Actually Runs thumbnailIntroducing Delphos Labs: Securing the Software That Actually Runs thumbnail
Company
Product

Introducing Delphos Labs: Securing the Software That Actually Runs

Revealing hidden threats in compiled software without source code.

David Dubick
DD
Caleb Fenton
CF
David Dubick, Caleb FentonMay 4, 2026

Company

About UsBlogSecurity Trust CenterBug Bounty ProgramVulnerability Research Policy

Account

Privacy PolicyTerms of Service

Help & Feedback

Contact SupportEmail Us

Social

LinkedInX

Copyright © 2026 Delphos Labs Inc.