<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>AnkhCorp</title><link>https://ankhcorp.github.io/</link><description>Recent content on AnkhCorp</description><generator>Hugo</generator><language>en</language><atom:link href="https://ankhcorp.github.io/index.xml" rel="self" type="application/rss+xml"/><item><title>How I Built Snoop: An OSINT Tool for Tracking Users Across the Internet</title><link>https://ankhcorp.github.io/journal/how-i-built-snoop/</link><pubDate>Mon, 21 Sep 2026 00:00:00 +0000</pubDate><guid>https://ankhcorp.github.io/journal/how-i-built-snoop/</guid><description>Tracking usernames across multiple platforms is one of the most common tasks in OSINT. It seems simple, but platforms are constantly changing their behavior, removing error codes, blocking automated requests, and hiding useful network responses. Because of this, many well-known tools end up breaking or returning false positives.
That’s exactly why I built Snoop — a lightweight, focused user enumeration tool that uses an unconventional approach: leveraging third-party services to restore the ability to detect a user’s existence through HTTP responses.</description></item><item><title>TheGentlemen Ransomware: Threat Overview and Analysis</title><link>https://ankhcorp.github.io/journal/thegentlemen-ransomware-threat-overview-and-analysis/</link><pubDate>Tue, 07 Apr 2026 00:00:00 +0000</pubDate><guid>https://ankhcorp.github.io/journal/thegentlemen-ransomware-threat-overview-and-analysis/</guid><description>Threat Context The Gentlemen is a ransomware group that carries out numerous attacks around the world and has recently attracted notable attention, especially due to the concentration of victims in countries with lower cybersecurity maturity.
They remain active, with their first appearance around mid-2025.
Primary Nation Targets:
US, Brazil, Thailand and India Primary Industry Targets:
Logistics, Manufacturing, Financial Services, and Healthcare First Known Victim:
JN Aceros (Peru) on 06/30/2025 The core of TheGentlemen is a system of unique keys generated for each victim at the time of the attack.</description></item><item><title>Cyrillic Phishing: When a Domain Looks Legit</title><link>https://ankhcorp.github.io/journal/cyrillic-phishing-homograph-attack/</link><pubDate>Tue, 13 Jan 2026 00:00:00 +0000</pubDate><guid>https://ankhcorp.github.io/journal/cyrillic-phishing-homograph-attack/</guid><description>An Apple developer — someone who had spent ten years reading the company’s official emails, the kind of person who clicks nothing — nearly fell for a phishing message recently. Not because the email was well written. It wasn&amp;rsquo;t. The domain just looked right.
He did the one thing most people don&amp;rsquo;t: inspected it character by character. One of the letters wasn&amp;rsquo;t from the alphabet it claimed to be.
The &amp;lsquo;a&amp;rsquo; that isn&amp;rsquo;t an &amp;lsquo;a&amp;rsquo; Latin a is U+0061.</description></item></channel></rss>