Analysis of Bincrypter and gsocket (gs-netcat): Artifacts extracted from a real compromise
Introduction Recently, in a Linux server compromise, the TA used a gsocket binary as a reverse shell tunnel. The compromise started with a WordPress site affected by CVE-2026-18322 and the attacke...