w1sdom Independent · since 1998 · operational

Quiet code.
Loud consequences. Low-level · Hardware · Kernel

Antonius (w1sdom) — independent low-level security researcher and hardware hacker, operating from Indonesia as bluedragonsec.com. A former 1990s 16-bit assembly virus writer, now focused on Linux kernel 7.0 internals, rootkit development, and CVE discovery. Twenty-seven years of uninterrupted offensive R&D.

27YEARS
offensive R&D
42REPOS
public github
04CVE
2026 catalogue
24RELS
packetstorm releases
i. About — the operator

A polymath, by deliberate design.

The rarest researcher is the one who refused to specialize narrowly. Low-level security overlaps with electronics, mathematics, mechatronics, and machine reasoning. Each domain sharpens the others.

KERNEL USER HARDWARE RESEARCH

Independent, since 1998.

I am Antonius, known publicly as w1sdom — an independent low-level security researcher and hardware hacker based in Tangerang, Indonesia. My work spans Linux kernel exploitation, rootkit development, hardware hacking, and vulnerability research on modern operating systems.

I have been continuously active in offensive R&D since 1998 — starting with 16-bit assembly virus research on MS-DOS, evolving through community work in the 2000s and 2010s, and now focused on the modern Linux kernel and hardware security frontier.

Everything I publish — code, write-ups, CVEs, the full archive — is reachable from bluedragonsec.com, my canonical home.

w1sdom sw0rdm4n ringlayer ev1lut10n robotsoft bluedragonsec
ii. Disciplines — what I do

Three crafts. One operator.

Low-level security is the intersection of kernel internals, hardware reality, and code that runs without abstractions. I practice all three.

i. Kernel land Linux kernel internals — SLUB allocator, the new sheaves caching architecture in 7.0, race conditions, UAF and double-free chains. Modern mitigation bypass: KASLR, SMEP, SMAP. SLUB sheaves UAF/DF
ii. User land Heap and stack corruption on hardened userland. Daemon and parser bug-class research. ROP / JOP chain construction, one-gadget exploitation on DNS servers, FTP daemons, parsers. heap stack ROP/JOP
iii. Hardware land Hardware hacking and tactical robotics. Embedded systems, sensor and biometric evasion, custom offensive hardware. Electronics work since 1996 — first-class discipline. embedded robotics biometric
iv. Rootkit development Loadable kernel module rootkits on modern Linux (5.x – 6.2 via ftrace hooking) and KLD rootkits on FreeBSD 13. Hide files, processes, ports; bind/reverse shell backdoors. LKM KLD ftrace
v. CVE discovery Original vulnerability research across Linux kernel, daemons, parsers. Four CVEs published in the 2026 catalogue; full archive across 24 PacketStorm releases since 2010. audit fuzz disclosure
iii. Arsenal — public code

Six pinned repositories.

Six pinned projects out of 42 public repositories on GitHub. From legendary archive code to active 2026 research — everything below is open source.

repo · 01

bds_lkm_ftrace

Ftrace-based Linux Loadable Kernel Module rootkit for kernel 5.x up to 6.2 on x86_64. Hides files, processes, bind & reverse shell ports. Privilege escalation. Modern Linux target.

39 9
LKM Rootkit
repo · 02

bds_freebsd

FreeBSD KLD rootkit for FreeBSD 13. Hides files, processes, ports; ships with a bind-shell backdoor. Developed manually by Antonius in 2023.

16 2
KLD Rootkit
repo · 03 · CVE

CVE-2026-23416 PoC

Proof-of-concept for CVE-2026-23416 — vulnerability discovered by Antonius. Affects Linux kernel 6.17 through 7.0-rc5. mm/mseal stale pointer after VMA merge.

8 1
CVE PoC
repo · 04 · frontier

slab-sheaf union state confusion

Technical research on a theoretical weaponization path for Linux kernel 7.0-rc7 memory corruption primitives via slab_sheaf union state confusion in the SLUB Sheaves architecture.

9 6
Kernel 7.0
repo · 05 · legend

xinyiquan-rc

Xingyiquan — a legendary Linux kernel rootkit for kernel 2.6 and 3.x. Developed by Antonius (sw0rdm4n / w1sdom) in 2014. Featured in academic literature and rootkit indices.

2 2
Archive · 2014
repo · 06 · archive

exploits collection

Legacy exploit collection — historical proofs-of-concept from the early career as ev1lut10n / sw0rdm4n. Includes the polkitd race-condition LPE released in 2011.

2 0
Archive
iv. Record — verified disclosures

CVE catalogue.

Public CVEs and responsibly-disclosed vulnerabilities, recent and archival. Full archive lives on bluedragonsec.com.

CVE-2026-23416 mm/mseal — stale curr_end pointer after VMA merge Medium Linux 6.17 – 7.0-rc5
CVE-2026-31429 Linux kernel — SLUB cross-cache confusion in net/bpf Medium Linux 6.3 – 6.12.82
CVE-2026-27831 rldns 1.3 — heap out-of-bounds read in DNS server Medium rldns 1.3
CVE-2026-30658 bftpd 6.4 — FTP daemon parsing bug Low bftpd 6.4
Disclosure LiteDNS — OOB read in DNS name parsing → DoS Medium LiteDNS
Disclosure BuptLab dns_relay — remote heap underflow Medium BuptLab relay
Archive · 2011 polkitd 0.96 — race condition local privilege escalation Archive polkitd 0.96
v. Trajectory — twenty-seven years

A continuous track. Uninterrupted.

From 16-bit assembly virus research in 1998 to kernel 7.0 exploitation in 2026.

1998
x86 ASM & 16-bit virus research
2003
SDF Lonestar · Solhack
2009
Devilzc0de · co-founder
2014
Xingyiquan rootkit · LKM
2023
bds_freebsd · KLD rootkit
2026
Kernel 7.0 · SLUB sheaves
vi. Channels — public footprint

Where to find me.

All channels are monitored. bluedragonsec.com is the canonical home — everything else points back there.

★ canonical · home
bluedragonsec.com
www.bluedragonsec.com
code · primary
GitHub primary
github.com/bluedragonsecurity
code · robotics
GitHub robotics
github.com/antoniusrobotsoft
writing
Medium @w1sdom
medium.com/@w1sdom
social
X / Twitter
x.com/bluedragonsec
professional
LinkedIn
linkedin.com/in/antonius-bluedragonsec
releases
PacketStorm #10292
packetstorm.news/files/author/10292
video · robotics
YouTube robotics
youtube.com/@antoniusringlayer
community
0x00sec @w1sdom
forum.0x00sec.org/u/w1sdom

Open for research
and serious engagement.

Available for vulnerability research collaboration, contract engagement, and international recruitment as a low-level specialist.