Malware News
16.2K subscribers
1.64K photos
7 videos
130 files
8.3K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
aelassas/servy: Professional-Grade Windows Service Wrapper with Real-Time Monitoring

https://github.com/aelassas/servy

Servy lets you run any app as a native Windows service with full control over the working directory, startup type, process priority, CPU affinity, logging, health checks, environment variables, dependencies, pre-launch and post-launch hooks, pre-stop and post-stop hooks, and parameters.



🎖@malwr
Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, and a New Platform Called Night Dragon
Hunt.io and NetAskari trace a leaked Android RAT framework across 170 active servers, analyze the APK builder internals, and document a successor platform called Night Dragon targeting Chinese users.

https://hunt.io/blog/flying-eagle-android-rat-170-servers-night-dragon


🎖@malwr
OctLurk and SilkLurk: new Backdoors in Central Asia
Our experts discovered OctLurk and SilkLurk, backdoors operating primarily in memory, targeting Central Asia. They inject plugins to launch shells, scan networks, dump credentials, and keylogging.

https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/


🎖@malwr
ENISA Secure by Design and Default Playbook | ENISA
ENISA is the EU agency dedicated to enhancing cybersecurity in Europe. They offer guidance, tools, and resources to safeguard citizens and businesses from cyber threats.

https://www.enisa.europa.eu/publications/enisa-secure-by-design-and-default-playbook

https://www.enisa.europa.eu/sites/default/files/2026-07/ENISA_Secure_By_Design_and_Default_Playbook_v1.pdf

🎖@malwr
0xMR007/Lab4PurpleSec: Lab4PurpleSec is a modular Purple Team homelab combining a vulnerable Active Directory environment (GOAD), a Docker-based web DMZ, pfSense + Suricata, and a Wazuh SIEM. It provides a realistic, open-source training environment for web exploitation, pivoting, Active Directory attacks, and Blue Team detection.

https://github.com/0xMR007/Lab4PurpleSec


🎖@malwr
Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums
A malware campaign disguised as an “undetected” version of the Xeno Roblox script executor is directly affecting players

https://www.bitdefender.com/en-us/blog/labs/fake-xeno-roblox-discord-executor


🎖@malwr
kaandemir993/ShellcodeRunner-Anti-Forensic-Privilege-Escalation-Payload-Analysis: "Reverse engineering analysis of ShellcodeRunner, a malware that uses anti-forensic techniques, token manipulation for privilege escalation, and clipboard stealing payload. Includes .rdata API extraction and memory trace cleaning."

https://github.com/kaandemir993/ShellcodeRunner-Anti-Forensic-Privilege-Escalation-Payload-Analysis


🎖@malwr
Provisioning Packages
Windows Provisioning Packages are used by Administrators to deploy configuration scripts on Windows environments by using a container format. Threat actors with elevated privileges could abuse prov…

https://ipurple.team/2026/08/04/provisioning-packages/


🎖@malwr