Skip to content
View n0xnull's full-sized avatar

Block or report n0xnull

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
n0xnull/README.md

Abil Khosim — NoxNull

Cybersecurity Specialist · Banking Sector · Indonesia

LinkedIn Medium


NoxNull — from nox non nulla: "appears empty, never is." Which is also how the malware I take apart works.

Penetration testing (mobile · web · API · server · network) and Android malware analysis, focused on the threats that actually reach Indonesian users — banking trojans, on-device fraud, and Accessibility Service abuse.

🇮🇩 Baca profil ini dalam Bahasa Indonesia

Tentang

Saya adalah Cybersecurity Specialist di sektor perbankan Indonesia, berfokus pada penetration testing (mobile · web · API · server · jaringan) dan analisis malware Android — khususnya ancaman yang nyata menyasar pengguna Indonesia: banking trojan, penipuan on-device, dan penyalahgunaan Accessibility Service.

Riset & Tulisan

Mengulik Malware yang Menyamar Jadi Aplikasi Undangan Pernikahan: Kasus Nyata Indonesia Sep 2026 · Bahasa Indonesia

Analisis malware Android yang beredar di Indonesia dengan modus menyamar sebagai undangan pernikahan digital (APK). Mencakup teknik Accessibility Service abuse, pencurian SMS OTP, dan pola distribusi via WhatsApp.


Reverse Engineering Malware M-Pajak: Dari APK Palsu hingga Pengambilalihan Rekening Jul 2026 · Bahasa Indonesia

Reverse engineering lengkap trojan perbankan Android yang menyamar sebagai aplikasi pajak resmi Indonesia. Mencakup keylogging via Accessibility Service, overlay layar penuh, kendali jarak jauh via WebSocket, dan enkripsi C2 berbasis timestamp.

Tooling Keamanan

Proyek Fungsi Stack
Fathom Intelijen attack surface — penemuan subdomain, deteksi Shadow IT, dan cek subdomain takeover tanpa API key. Python · PySide6
Flare GUI desktop untuk Nmap dengan Port Criticality Engine, saran remediasi, dan laporan Excel. Bilingual ID/EN. Python · PySide6
Cascade Pipeline rekon bug bounty — 9 tool (subfinder, amass, nuclei, dll.) dalam satu klik, dengan Priority Engine. Python · PySide6
Mirage Detektor peniruan merek & scam — cari domain typosquat, sertifikat baru, nomor palsu, dan halaman phishing. Python · PySide6
Tempest Monitoring endpoint security self-hosted — agen Go di endpoint Windows, konsol web, respons jarak jauh. Go · Next.js

Proyek Berbasis Pesanan

Proyek Dibangun untuk Stack
BlueForge Platform kompetisi hardening defensif — penilaian otomatis dan papan skor live. Python · Next.js · Supabase
Cove Platform keamanan digital untuk orang tua — monitoring berbasis persetujuan, self-hosted. Next.js · Supabase
Muster Platform presensi enterprise — validasi GPS, verifikasi wajah, manajemen shift. Next.js · React Native

Latar Belakang

  • Cybersecurity Specialist, sektor perbankan — penetration testing, analisis malware, kebijakan keamanan
  • Koordinator Laboratorium (Elektronika · Jaringan Nirkabel · Jaringan Komputer), Universitas Dinamika
  • S1 Teknik Komputer, Universitas Dinamika

🔬 Research & Writing

Mengulik Malware yang Menyamar Jadi Aplikasi Undangan Pernikahan: Kasus Nyata Indonesia Sep 2026 · ~10 min read · Bahasa Indonesia

Analysis of an Android malware campaign circulating in Indonesia, disguised as a digital wedding invitation APK distributed via WhatsApp. Covers Accessibility Service abuse for OTP theft, SMS interception, and the social-engineering distribution chain that makes it effective against non-technical targets.


Reverse Engineering Malware M-Pajak: Dari APK Palsu hingga Pengambilalihan Rekening Korban Jul 2026 · 11 min read · Bahasa Indonesia

Full reverse engineering of an Android banking trojan impersonating Indonesia's tax authority. Covers Accessibility Service keylogging, full-screen overlay disorientation, WebSocket-based remote control, and timestamp-derived C2 encryption — mapped to MITRE ATT&CK for Mobile, with concrete mitigations for financial app developers.

🛠️ Security Tooling

Project What it does Stack
Fathom Attack surface intelligence — subdomain discovery, Shadow IT detection, and takeover checks using only free, no-API-key sources. Python · PySide6
Flare Desktop GUI for Nmap with a Port Criticality Engine, plain-language remediation, and multi-sheet Excel reporting. Bilingual EN/ID. Python · PySide6
Cascade Bug bounty recon pipeline — nine tools (subfinder, amass, nuclei, and more) in one managed flow, with a Priority Engine that ranks every finding. Python · PySide6
Mirage Brand impersonation & scam detector — finds typosquat domains, fresh SSL certificates, fake phone numbers, phishing pages, and spoofed social accounts pretending to be your brand. Python · PySide6
Tempest Self-hosted endpoint security monitoring — lightweight Go agent on Windows endpoints, real-time console, and remote response actions. Go · Next.js

🤝 Commissioned Work

Built on request, deployed for real use:

Project Built for Stack
BlueForge Defensive hardening competition platform — automated scoring and live leaderboards. Built at a university's request for judging a cybersecurity competition. Python · Next.js · Supabase
Cove Parental digital safety platform with consent-based monitoring and self-hosted deployment. Next.js · Supabase
Muster Enterprise attendance platform — GPS validation, face verification, shift management. Next.js · React Native

📌 Background

  • Cybersecurity Specialist, banking sector — penetration testing, malware analysis, security policy
  • Laboratory Coordinator (Electronics · Wireless Networks · Computer Networks), Universitas Dinamika
  • B.Eng. Computer Engineering, Universitas Dinamika

All tooling is released for authorized security testing and educational use only.

Pinned Loading

  1. Fathom Fathom Public

    🌊 Fathom — Attack Surface Intelligence, Made Simple. Discover subdomains, uncover Shadow IT, fingerprint technologies, and prioritize your external attack surface—no API keys required.

    Python 1

  2. Flare Flare Public

    🔥 Flare — Network Mapping, Made Obvious. A modern desktop GUI for Nmap featuring an intelligent Port Criticality Engine, plain-language remediation guidance, and professional multi-sheet Excel repo…

    Python

  3. Tempest Tempest Public

    🌩️ Tempest — Cyber Resilience Simulation Platform featuring realistic attack scenarios, ransomware simulations, and automated validation for security exercises.

    TypeScript

  4. Cascade Cascade Public

    🪜 Cascade — Bug Bounty Recon Pipeline. One-click orchestration of subfinder, amass, httpx, gau, katana, ffuf, nuclei, wafw00f & gowitness with a Priority Engine that ranks every finding by severity…

    Python

  5. Mirage Mirage Public

    🏜️ Mirage — Brand Impersonation & Scam Detector. Finds look-alike domains, phishing pages, fake WhatsApp/CS numbers and fake social accounts that use your brand, then helps you validate, report and…

    Python