Malware News
16.2K subscribers
1.64K photos
7 videos
130 files
8.3K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
Malware News pinned «🚨 For advertising in the channel, contact @SirMalware»
Static Devirtualization of Tencent VM
Over the course of several months we have noticed an increased interest in Tencent VM obfuscation. We have had complete static devirtualization of this VM obfuscation for quite some time now and have noticed others have achieved similar deobfuscation results.

https://back.engineering/blog/31/07/2026/


πŸŽ–@malwr
πŸ”₯1
Inside the Falcon How CrowdStrike Catches You
A full reverse-engineering teardown of the CrowdStrike Falcon sensor: the six kernel callback sources, the WFP network engine, the file-system minifilter, the cspcm4 broker, the user-mode service (DNS / AMSI / browser / Identity Protection), and the cloud-loaded detection engine β€” plus every structural blind spot. How Falcon sees you, and where the seams are.

https://0xdbgman.github.io/posts/inside-the-falcon-how-crowdstrike-catches-you/


πŸŽ–@malwr
Turning Chrome Remote Desktop into Pure Red Team Ops
How to hide the Chrome Remote Desktop connection banner by patching a single dialog resource, then abuse host.json and MSI packaging to turn CRD into a quiet persistent access channel.

https://zerotracelab.com/blog/chrome-remote-desktop-red-ops


πŸŽ–@malwr
JoasASantos/NeuroPurple: The AI Autonomous SOC & Purple-Team Engine

https://github.com/JoasASantos/NeuroPurple


πŸŽ–@malwr
❀1
aelassas/servy: Professional-Grade Windows Service Wrapper with Real-Time Monitoring

https://github.com/aelassas/servy

Servy lets you run any app as a native Windows service with full control over the working directory, startup type, process priority, CPU affinity, logging, health checks, environment variables, dependencies, pre-launch and post-launch hooks, pre-stop and post-stop hooks, and parameters.



πŸŽ–@malwr
Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, and a New Platform Called Night Dragon
Hunt.io and NetAskari trace a leaked Android RAT framework across 170 active servers, analyze the APK builder internals, and document a successor platform called Night Dragon targeting Chinese users.

https://hunt.io/blog/flying-eagle-android-rat-170-servers-night-dragon


πŸŽ–@malwr
OctLurk and SilkLurk: new Backdoors in Central Asia
Our experts discovered OctLurk and SilkLurk, backdoors operating primarily in memory, targeting Central Asia. They inject plugins to launch shells, scan networks, dump credentials, and keylogging.

https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/


πŸŽ–@malwr
ENISA Secure by Design and Default Playbook | ENISA
ENISA is the EU agency dedicated to enhancing cybersecurity in Europe. They offer guidance, tools, and resources to safeguard citizens and businesses from cyber threats.

https://www.enisa.europa.eu/publications/enisa-secure-by-design-and-default-playbook

https://www.enisa.europa.eu/sites/default/files/2026-07/ENISA_Secure_By_Design_and_Default_Playbook_v1.pdf

πŸŽ–@malwr
0xMR007/Lab4PurpleSec: Lab4PurpleSec is a modular Purple Team homelab combining a vulnerable Active Directory environment (GOAD), a Docker-based web DMZ, pfSense + Suricata, and a Wazuh SIEM. It provides a realistic, open-source training environment for web exploitation, pivoting, Active Directory attacks, and Blue Team detection.

https://github.com/0xMR007/Lab4PurpleSec


πŸŽ–@malwr