Skip to content
View n0xnull's full-sized avatar

Block or report n0xnull

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
n0xnull/README.md

Abil Khosim — NoxNull

Cybersecurity Specialist · Banking Sector · Indonesia

LinkedIn Medium


NoxNull — from nox non nulla: "appears empty, never is." Which is also how the malware I take apart works.

Penetration testing (mobile · web · API · server · network) and Android malware analysis, focused on the threats that actually reach Indonesian users — banking trojans, on-device fraud, and Accessibility Service abuse.

🔬 Research & Writing

Reverse Engineering Malware M-Pajak: Dari APK Palsu hingga Pengambilalihan Rekening Korban Jul 2026 · 11 min read · Bahasa Indonesia

Full reverse engineering of an Android banking trojan impersonating Indonesia's tax authority. Covers Accessibility Service keylogging, full-screen overlay disorientation, WebSocket-based remote control, and timestamp-derived C2 encryption — mapped to MITRE ATT&CK for Mobile, with concrete mitigations for financial app developers.

🛠️ Security Tooling

Project What it does Stack
Fathom Attack surface intelligence — subdomain discovery, Shadow IT detection, and takeover checks using only free, no-API-key sources. Python · PySide6
Flare Desktop GUI for Nmap with a Port Criticality Engine, plain-language remediation, and multi-sheet Excel reporting. Bilingual EN/ID. Python · PySide6
Tempest Cyber resilience simulation — attack scenarios and ransomware simulations with automated validation for security exercises. Python · TypeScript

🤝 Commissioned Work

Built on request, deployed for real use:

Project Built for Stack
BlueForge Defensive hardening competition platform — automated scoring and live leaderboards. Built at a university's request for judging a cybersecurity competition. Python · Next.js · Supabase
Cove Parental digital safety platform with consent-based monitoring and self-hosted deployment. Next.js · Supabase
Muster Enterprise attendance platform — GPS validation, face verification, shift management. Next.js · React Native

📌 Background

  • Cybersecurity Specialist, banking sector — penetration testing, malware analysis, security policy
  • Laboratory Coordinator (Electronics · Wireless Networks · Computer Networks), Universitas Dinamika
  • B.Tech, Universitas Dinamika

All tooling is released for authorized security testing and educational use only.

Pinned Loading

  1. Fathom Fathom Public

    🌊 Fathom — Attack Surface Intelligence, Made Simple. Discover subdomains, uncover Shadow IT, fingerprint technologies, and prioritize your external attack surface—no API keys required.

    Python 1

  2. Flare Flare Public

    🔥 Flare — Network Mapping, Made Obvious. A modern desktop GUI for Nmap featuring an intelligent Port Criticality Engine, plain-language remediation guidance, and professional multi-sheet Excel repo…

    Python

  3. Tempest Tempest Public

    🌩️ Tempest — Cyber Resilience Simulation Platform featuring realistic attack scenarios, ransomware simulations, and automated validation for security exercises.

    TypeScript

  4. BlueForge BlueForge Public

    ⚒️ BlueForge — Defensive Hardening Competition Platform with automated hardening verification, live scoring, and real-time leaderboards.

    Python

  5. Cove Cove Public

    🛡️ Cove — Parental Digital Safety Platform with real-time monitoring, location awareness, activity insights, and secure self-hosted deployment.

    TypeScript 1

  6. Muster Muster Public

    🧑‍💼 Enterprise attendance platform with GPS validation, face verification, shift management, and multi-organization support.

    TypeScript