Malware News
СтатистикаThe latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ... Partner channel: @cveNotify For ads: https://telega.io/c/malwr
- Последний пост
- 23:38
- Последнее чтение
- 11:51
- Постов за неделю
- 35
- Всего постов
- 42
- Тип
- открытый
- Язык
- английский
- Категория
- Новости и СМИ
- В каталоге с
- 12 авг.
- 1/24сутки в ленте
- 442
- 1/48двое суток
- 506
- 1/72трое суток
- 545
Медиана по постам, которые мы застали свежими и померили через сутки.
Посты
sensepost/pipetap: A Windows Named Pipe Multi-tool / Proxy https://github.com/sensepost/pipetap 🎖@malwr
smol-machines/smolvm: Portable, lightweight, self-contained virtual machine. https://github.com/smol-machines/smolvm 🎖@malwr
Using Emulation Against Anti-Reverse Engineering Techniques | FortiGuard Labs In this blog post, the FortiGuard Labs team reviews how to use emulation against anti-reverse engineering techniques using the Pandora ransomware as an example. Learn more. https://www.fortinet.com/blog/threat-research/Using-emulation-against-anti-reverse-engineering-techniques 🎖@malwr
r3nzsec/irflow-timeline: DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt, process inspection, lateral movement tracking, persistence detection, and VirusTotal enrichment. https://github.com/r3nzsec/irflow-timeline 🎖@malwr
https://www.sophos.com/en-us/blog/deno-case-studies 🎖@malwr
PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure Acronis Threat Research Unit (TRU) has identified an ongoing campaign delivering a previously undocumented custom backdoor against Afghan telecom providers and South Asian critical infrastructure organizations. The backdoor, tracked as PATCHCORD, is a compiled C/C++ implant delivered through sector-specific lures, including fake VPN installers impersonating Afghan Telecom (AFTEL) and telecom management tools. https://www.acronis.com/en/tru/posts/patchcord-new-malware-cluster-targets-afghan-telecom-and-south-asian-critical-infrastructure/ 🎖@malwr
CoolClient backdoor goes deeper: HoneyMyte adds Windows kernel rootkit Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts. https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/ 🎖@malwr
AmnesiaStealer: macOS Infostealer That Hijacks Browsers Jamf Threat Labs uncovers a macOS infostealer that steals keychain data and browser credentials, and hijacks live browser sessions. https://www.jamf.com/blog/amnesia-stealer-macos-infostealer-clickfix/ 🎖@malwr
видео или голосовое, без подписи
Signed ClickOnce delivers two stealers and RAT - Have I Been Squatted Fake Web3 interview campaign delivering signed ClickOnce, NeedleStealer, a Rust stealer, and a Go hVNC RAT on Windows in July 2026. https://haveibeensquatted.com/blog/from-fake-interview-to-signed-clickonce-three-payload-windows-chain 🎖@malwr
D7EAD/mkPIVM: Generate polymorphic, position-independent virtual machines (PIVMs) from arbitrary x86/x64 shellcode. https://github.com/D7EAD/mkPIVM 🎖@malwr
JM00NJ/ICMP-Ghost-A-Fileless-x64-Assembly-C2-Agent: A fileless C2 framework written in pure x64 Linux Assembly with zero libc dependencies. Features dynamic protocol pivoting between raw ICMP sockets and DNS (UDP/53) via in-memory VTable manipulation. 100% direct syscalls, no disk writes, and strict mathematical packet authentication. https://github.com/JM00NJ/ICMP-Ghost-A-Fileless-x64-Assembly-C2-Agent 🎖@malwr
Applied Reverse Engineering: Crude T&E for Control-Flow Tracing - Reverse Engineering The idea of inducing faults with sentinels by patching code sections at runtime predates most of us — it’s one of the oldest tricks in systems programming. Fault injection for code tracing goes back to early software emulation and debugging in the 80s and 90s. Single-stepping via the trap flag dates to the 8086 (1976) […] https://revers.engineering/applied-re-crude-te-for-control-flow-tracing/ 🎖@malwr
From P-Code to GNN: extract binary code semantics - Quarkslab's blog pcode_graph is a Python library, published by Quarkslab, suitable to build semantic graphs from binary code. We present how to use it to detect function similarities in binaries. https://blog.quarkslab.com/from-p-code-to-gnn-extract-binary-code-semantics.html 🎖@malwr
When You Pay the Ransom - Taking Apart an Interlock ESXi Decryptor | Maldbg - Malware Analysis Blog Taking apart a freshly compiled Interlock ESXi decryptor, and what it reveals about how the encryptor works. https://maldbg.com/interlock-esxi-decryptor-internals 🎖@malwr
skyisoway/Null-API-Hook: API Hooking for Windows x64 https://github.com/skyisoway/Null-API-Hook 🎖@malwr
Malware Crypting Services and the Threat Actors Who Sell Them Insikt Group analyzes 24 threat actors selling malware crypting services. Learn about their evasion techniques, market dynamics, and how defenders can prioritize behavioral detection over static analysis. https://www.recordedfuture.com/research/malware-crypting-services-threat-actors 🎖@malwr
Zydak/LeetObfuscator: LLVM based obfuscator https://github.com/Zydak/LeetObfuscator A very simple obfuscator for C/C++ x64 and x86 code 🎖@malwr
Dissecting the JWR phishing framework Cisco Talos recently identified an undocumented phishing framework, internally branded "JWR" by its developer, built to convincingly impersonate checkout and login pages across major payment and shopping platforms. https://blog.talosintelligence.com/dissecting-the-jwr-phishing-framework/ 🎖@malwr
2026-08-12: SmartApeSG ClickFix leads to two RATs https://www.malware-traffic-analysis.net/2026/08/12/index.html 🎖@malwr