Malware News
16.2K subscribers
1.64K photos
7 videos
130 files
8.31K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
Inside the Falcon How CrowdStrike Catches You
A full reverse-engineering teardown of the CrowdStrike Falcon sensor: the six kernel callback sources, the WFP network engine, the file-system minifilter, the cspcm4 broker, the user-mode service (DNS / AMSI / browser / Identity Protection), and the cloud-loaded detection engine โ€” plus every structural blind spot. How Falcon sees you, and where the seams are.

https://0xdbgman.github.io/posts/inside-the-falcon-how-crowdstrike-catches-you/


๐ŸŽ–@malwr
Turning Chrome Remote Desktop into Pure Red Team Ops
How to hide the Chrome Remote Desktop connection banner by patching a single dialog resource, then abuse host.json and MSI packaging to turn CRD into a quiet persistent access channel.

https://zerotracelab.com/blog/chrome-remote-desktop-red-ops


๐ŸŽ–@malwr
JoasASantos/NeuroPurple: The AI Autonomous SOC & Purple-Team Engine

https://github.com/JoasASantos/NeuroPurple


๐ŸŽ–@malwr
โค1
aelassas/servy: Professional-Grade Windows Service Wrapper with Real-Time Monitoring

https://github.com/aelassas/servy

Servy lets you run any app as a native Windows service with full control over the working directory, startup type, process priority, CPU affinity, logging, health checks, environment variables, dependencies, pre-launch and post-launch hooks, pre-stop and post-stop hooks, and parameters.



๐ŸŽ–@malwr
Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, and a New Platform Called Night Dragon
Hunt.io and NetAskari trace a leaked Android RAT framework across 170 active servers, analyze the APK builder internals, and document a successor platform called Night Dragon targeting Chinese users.

https://hunt.io/blog/flying-eagle-android-rat-170-servers-night-dragon


๐ŸŽ–@malwr
OctLurk and SilkLurk: new Backdoors in Central Asia
Our experts discovered OctLurk and SilkLurk, backdoors operating primarily in memory, targeting Central Asia. They inject plugins to launch shells, scan networks, dump credentials, and keylogging.

https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/


๐ŸŽ–@malwr
ENISA Secure by Design and Default Playbook | ENISA
ENISA is the EU agency dedicated to enhancing cybersecurity in Europe. They offer guidance, tools, and resources to safeguard citizens and businesses from cyber threats.

https://www.enisa.europa.eu/publications/enisa-secure-by-design-and-default-playbook

https://www.enisa.europa.eu/sites/default/files/2026-07/ENISA_Secure_By_Design_and_Default_Playbook_v1.pdf

๐ŸŽ–@malwr
0xMR007/Lab4PurpleSec: Lab4PurpleSec is a modular Purple Team homelab combining a vulnerable Active Directory environment (GOAD), a Docker-based web DMZ, pfSense + Suricata, and a Wazuh SIEM. It provides a realistic, open-source training environment for web exploitation, pivoting, Active Directory attacks, and Blue Team detection.

https://github.com/0xMR007/Lab4PurpleSec


๐ŸŽ–@malwr
Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums
A malware campaign disguised as an โ€œundetectedโ€ version of the Xeno Roblox script executor is directly affecting players

https://www.bitdefender.com/en-us/blog/labs/fake-xeno-roblox-discord-executor


๐ŸŽ–@malwr