Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums
A malware campaign disguised as an โundetectedโ version of the Xeno Roblox script executor is directly affecting players
https://www.bitdefender.com/en-us/blog/labs/fake-xeno-roblox-discord-executor
๐@malwr
A malware campaign disguised as an โundetectedโ version of the Xeno Roblox script executor is directly affecting players
https://www.bitdefender.com/en-us/blog/labs/fake-xeno-roblox-discord-executor
๐@malwr
Bitdefender
Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums
A malware campaign disguised as an โundetectedโ version of the Xeno Roblox script executor is directly affecting players
Meowmycks/EkkoNtProtect: Arbitrary NtProtectVirtualMemory calls from Ekko-style timer-based sleep obfuscation using internal ntdll functions
https://github.com/Meowmycks/EkkoNtProtect
๐@malwr
https://github.com/Meowmycks/EkkoNtProtect
๐@malwr
GitHub
GitHub - Meowmycks/EkkoNtProtect: Use NtProtectVirtualMemory in Ekko timers without needing to use stack pivoting or other RSPโฆ
Use NtProtectVirtualMemory in Ekko timers without needing to use stack pivoting or other RSP shifting tricks - Meowmycks/EkkoNtProtect
Rusty Bootkit - Windows UEFI Bootkit in Rust (Codename: RedLotus)
https://memn0ps.github.io/rusty-windows-uefi-bootkit/
๐@malwr
https://memn0ps.github.io/rusty-windows-uefi-bootkit/
๐@malwr
memN0ps
Rusty Bootkit - Windows UEFI Bootkit in Rust (Codename: RedLotus)
https://socradar.io/blog/doublecup-clickfix-loader-devicemanager-rats/
Introducing DOUBLECUP, a ClickFix Loader Delivering CountLoader and DeviceManager RATs
๐@malwr
Introducing DOUBLECUP, a ClickFix Loader Delivering CountLoader and DeviceManager RATs
๐@malwr
SOCRadarยฎ Cyber Intelligence Inc.
Introducing DOUBLECUP, a ClickFix Loader Delivering CountLoader and DeviceManager RATs
SOCRadarโs Threat Research Unit (STRU) identified and analyzed DOUBLECUP, a Russian Loader-as-a-Service (LaaS) for ClickFix campaigns. Operating...
kaandemir993/ShellcodeRunner-Anti-Forensic-Privilege-Escalation-Payload-Analysis: "Reverse engineering analysis of ShellcodeRunner, a malware that uses anti-forensic techniques, token manipulation for privilege escalation, and clipboard stealing payload. Includes .rdata API extraction and memory trace cleaning."
https://github.com/kaandemir993/ShellcodeRunner-Anti-Forensic-Privilege-Escalation-Payload-Analysis
๐@malwr
https://github.com/kaandemir993/ShellcodeRunner-Anti-Forensic-Privilege-Escalation-Payload-Analysis
๐@malwr
GitHub
GitHub - kaandemir993/ShellcodeRunner-Anti-Forensic-Privilege-Escalation-Payload-Analysis: "Reverse engineering analysis of ShellcodeRunnerโฆ
"Reverse engineering analysis of ShellcodeRunner, a malware that uses anti-forensic techniques, token manipulation for privilege escalation, and clipboard stealing payload. Includes .rdata...
Provisioning Packages
Windows Provisioning Packages are used by Administrators to deploy configuration scripts on Windows environments by using a container format. Threat actors with elevated privileges could abuse provโฆ
https://ipurple.team/2026/08/04/provisioning-packages/
๐@malwr
Windows Provisioning Packages are used by Administrators to deploy configuration scripts on Windows environments by using a container format. Threat actors with elevated privileges could abuse provโฆ
https://ipurple.team/2026/08/04/provisioning-packages/
๐@malwr
Purple Team
Provisioning Packages
Windows Provisioning Packages are used by Administrators to deploy configuration scripts on Windows environments by using a container format. Threat actors with elevated privileges could abuse provโฆ
SMOKE#SCREEN: ScreenConnect RMM Abuse, Cloudflare Tunnels, and Trusted Software Lures
Securonix Threat Research: Analyze the SMOKE#SCREEN campaign abusing ScreenConnect RMM, Cloudflare Tunnels, and trusted software lures to gain persistent access across Windows and macOS.
https://www.securonix.com/blog/smoke-screen-screenconnect-rmm-abuse-cloudflare-tunnels/
๐@malwr
Securonix Threat Research: Analyze the SMOKE#SCREEN campaign abusing ScreenConnect RMM, Cloudflare Tunnels, and trusted software lures to gain persistent access across Windows and macOS.
https://www.securonix.com/blog/smoke-screen-screenconnect-rmm-abuse-cloudflare-tunnels/
๐@malwr
Securonix
SMOKE#SCREEN: ScreenConnect RMM Abuse, Cloudflare Tunnels, and Trusted Software Lures
Securonix Threat Research: Analyze the SMOKE#SCREEN campaign abusing ScreenConnect RMM, Cloudflare Tunnels, and trusted software lures to gain persistent access across Windows and macOS.
The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2
An exposed open directory linked to The Gentlemen revealed EtherRAT, a Node.js backdoor that resolves rotating C2 domains through an Ethereum smart contract.
https://hunt.io/blog/the-gentlemen-etherrat-ethereum-smart-contract-c2
๐@malwr
An exposed open directory linked to The Gentlemen revealed EtherRAT, a Node.js backdoor that resolves rotating C2 domains through an Ethereum smart contract.
https://hunt.io/blog/the-gentlemen-etherrat-ethereum-smart-contract-c2
๐@malwr
hunt.io
The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2
An exposed open directory linked to The Gentlemen revealed EtherRAT, a Node.js backdoor that resolves rotating C2 domains through an Ethereum smart contract.
The-Arabi/Reverse-engineering-agent
https://github.com/The-Arabi/Reverse-engineering-agent
๐@malwr
https://github.com/The-Arabi/Reverse-engineering-agent
An autonomous, multi-agent reverse engineering research platform. It combines 5+ specialized AI analysis agents, a persistent knowledge base, structured multi-agent debate, LLM self-critique, RAG semantic search, and real tool integration (objdump, readelf, gdb, Ghidra, binwalk, tshark, radare2, โฆ)
๐@malwr
GitHub
GitHub - The-Arabi/Reverse-engineering-agent
Contribute to The-Arabi/Reverse-engineering-agent development by creating an account on GitHub.
Developers in the Crosshairs: Fake AI Tools Deliver Infostealer
In April 2026, Netskope Threat Labs exposed a Malware-as-a-Service (MaaS) NodeJS infostealer delivered through the ClickFix social engineering technique.
https://www.netskope.com/jp/blog/developers-in-the-crosshairs-fake-ai-tools-deliver-infostealer
๐@malwr
In April 2026, Netskope Threat Labs exposed a Malware-as-a-Service (MaaS) NodeJS infostealer delivered through the ClickFix social engineering technique.
https://www.netskope.com/jp/blog/developers-in-the-crosshairs-fake-ai-tools-deliver-infostealer
๐@malwr
Netskope
Developers in the Crosshairs: Fake AI Tools Deliver Infostealer
In April 2026, Netskope Threat Labs exposed a Malware-as-a-Service (MaaS) NodeJS infostealer delivered through the ClickFix social engineering technique.
โค1
pulpul-s/HWall: Linux hardware inventory and live sensor monitor
https://github.com/pulpul-s/HWall
๐@malwr
https://github.com/pulpul-s/HWall
๐@malwr
GitHub
GitHub - pulpul-s/HWall: Linux hardware inventory and live sensor monitor
Linux hardware inventory and live sensor monitor. Contribute to pulpul-s/HWall development by creating an account on GitHub.
LockBit String Deobfuscation: Reversing Affine Cipher DLL Loading with Ghidra
Technical analysis of LockBit ransomware string obfuscation โ affine cipher, dynamic API resolution, and IAT evasion, reversed with Ghidra.
https://ginomaihuiri.github.io/lockbit-string-deobfuscation
๐@malwr
Technical analysis of LockBit ransomware string obfuscation โ affine cipher, dynamic API resolution, and IAT evasion, reversed with Ghidra.
https://ginomaihuiri.github.io/lockbit-string-deobfuscation
๐@malwr
Aldair Maihuiri
LockBit String Deobfuscation: Reversing Affine Cipher DLL Loading with Ghidra
Technical analysis of LockBit ransomware string obfuscation โ affine cipher, dynamic API resolution, and IAT evasion, reversed with Ghidra.
derv82/wifit3: Wifite but USB-only & cross-platform.
https://github.com/derv82/wifit3
๐@malwr
https://github.com/derv82/wifit3
A wireless auditor that runs on Linux and Windows, comes with its own built-in drivers.
๐@malwr
GitHub
GitHub - derv82/wifit3: Wifite but USB-only & cross-platform.
Wifite but USB-only & cross-platform. Contribute to derv82/wifit3 development by creating an account on GitHub.
Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases (Larva-26005) - ASEC
https://asec.ahnlab.com/en/94847/
๐@malwr
https://asec.ahnlab.com/en/94847/
๐@malwr
ASEC
Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases (Larva-26005) - ASEC
Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases (Larva-26005) ASEC
CodeRiper/memforge: Cross-platform, high-performance process memory acquisition and digital forensics (DFIR) triage suite written in pure Rust.
https://github.com/CodeRiper/memforge
๐@malwr
https://github.com/CodeRiper/memforge
๐@malwr
GitHub
GitHub - CodeRiper/memforge: Cross-platform, high-performance process memory acquisition and digital forensics (DFIR) triage suiteโฆ
Cross-platform, high-performance process memory acquisition and digital forensics (DFIR) triage suite written in pure Rust. - CodeRiper/memforge
Point Wild Exclusive: Dissecting Vanta Stealer, a Python-Based Cross-Platform Information Theft Malware | Point Wild
Point Wild
https://www.pointwild.com/threat-intelligence/point-wild-exclusive-dissecting-vanta-stealer-a-python-based-cross-platform-information-theft-malware/
๐@malwr
Point Wild
https://www.pointwild.com/threat-intelligence/point-wild-exclusive-dissecting-vanta-stealer-a-python-based-cross-platform-information-theft-malware/
๐@malwr
Point Wild
Point Wild Exclusive: Dissecting Vanta Stealer, a Python-Based Cross-Platform Information Theft Malware | Point Wild
Reverse engineering a miner malware
Introduction I wanted a reverse engineering project, so I decided to analyse a piece of real malware.
https://gustavvising.se/2026/07/17/reverse-engineering-a-miner-malware.html
๐@malwr
Introduction I wanted a reverse engineering project, so I decided to analyse a piece of real malware.
https://gustavvising.se/2026/07/17/reverse-engineering-a-miner-malware.html
๐@malwr
Gustav Vising
Reverse engineering a miner malware
Introduction I wanted a reverse engineering project, so I decided to analyse a piece of real malware.
Binary Ninja - The Binary Hiding in Your Registry: Cracking Windows UCPD's Dynamic Rules
Binary Ninja is a modern reverse engineering platform with a scriptable and extensible decompiler.
https://binary.ninja/2026/08/04/ucpd-dynamic-rules.html
๐@malwr
Binary Ninja is a modern reverse engineering platform with a scriptable and extensible decompiler.
https://binary.ninja/2026/08/04/ucpd-dynamic-rules.html
๐@malwr
Binary Ninja
Binary Ninja - The Binary Hiding in Your Registry: Cracking Windows UCPD's Dynamic Rules
Binary Ninja is a modern reverse engineering platform with a scriptable and extensible decompiler.
Forwarded from CVE Notify
๐จ CVE-2026-59309
VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.
๐@cveNotify
VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.
๐@cveNotify
Forwarded from CVE Notify
๐จ CVE-2026-59310
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
๐@cveNotify
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
๐@cveNotify
NeverSight/NeverC: The AI-friendly C23 compiler for security research, built on LLVM
https://github.com/NeverSight/NeverC
๐@malwr
https://github.com/NeverSight/NeverC
๐@malwr
GitHub
GitHub - NeverSight/NeverC: The AI-friendly C23 compiler for security research, built on LLVM [WIP]
The AI-friendly C23 compiler for security research, built on LLVM [WIP] - NeverSight/NeverC