Malware News
16.2K subscribers
1.64K photos
7 videos
130 files
8.3K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums
A malware campaign disguised as an โ€œundetectedโ€ version of the Xeno Roblox script executor is directly affecting players

https://www.bitdefender.com/en-us/blog/labs/fake-xeno-roblox-discord-executor


๐ŸŽ–@malwr
kaandemir993/ShellcodeRunner-Anti-Forensic-Privilege-Escalation-Payload-Analysis: "Reverse engineering analysis of ShellcodeRunner, a malware that uses anti-forensic techniques, token manipulation for privilege escalation, and clipboard stealing payload. Includes .rdata API extraction and memory trace cleaning."

https://github.com/kaandemir993/ShellcodeRunner-Anti-Forensic-Privilege-Escalation-Payload-Analysis


๐ŸŽ–@malwr
Provisioning Packages
Windows Provisioning Packages are used by Administrators to deploy configuration scripts on Windows environments by using a container format. Threat actors with elevated privileges could abuse provโ€ฆ

https://ipurple.team/2026/08/04/provisioning-packages/


๐ŸŽ–@malwr
SMOKE#SCREEN: ScreenConnect RMM Abuse, Cloudflare Tunnels, and Trusted Software Lures
Securonix Threat Research: Analyze the SMOKE#SCREEN campaign abusing ScreenConnect RMM, Cloudflare Tunnels, and trusted software lures to gain persistent access across Windows and macOS.

https://www.securonix.com/blog/smoke-screen-screenconnect-rmm-abuse-cloudflare-tunnels/


๐ŸŽ–@malwr
The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2
An exposed open directory linked to The Gentlemen revealed EtherRAT, a Node.js backdoor that resolves rotating C2 domains through an Ethereum smart contract.

https://hunt.io/blog/the-gentlemen-etherrat-ethereum-smart-contract-c2


๐ŸŽ–@malwr
The-Arabi/Reverse-engineering-agent

https://github.com/The-Arabi/Reverse-engineering-agent

An autonomous, multi-agent reverse engineering research platform. It combines 5+ specialized AI analysis agents, a persistent knowledge base, structured multi-agent debate, LLM self-critique, RAG semantic search, and real tool integration (objdump, readelf, gdb, Ghidra, binwalk, tshark, radare2, โ€ฆ)



๐ŸŽ–@malwr
Developers in the Crosshairs: Fake AI Tools Deliver Infostealer
In April 2026, Netskope Threat Labs exposed a Malware-as-a-Service (MaaS) NodeJS infostealer delivered through the ClickFix social engineering technique.

https://www.netskope.com/jp/blog/developers-in-the-crosshairs-fake-ai-tools-deliver-infostealer


๐ŸŽ–@malwr
โค1
LockBit String Deobfuscation: Reversing Affine Cipher DLL Loading with Ghidra
Technical analysis of LockBit ransomware string obfuscation โ€” affine cipher, dynamic API resolution, and IAT evasion, reversed with Ghidra.

https://ginomaihuiri.github.io/lockbit-string-deobfuscation


๐ŸŽ–@malwr
derv82/wifit3: Wifite but USB-only & cross-platform.

https://github.com/derv82/wifit3

A wireless auditor that runs on Linux and Windows, comes with its own built-in drivers.



๐ŸŽ–@malwr
Binary Ninja - The Binary Hiding in Your Registry: Cracking Windows UCPD's Dynamic Rules
Binary Ninja is a modern reverse engineering platform with a scriptable and extensible decompiler.

https://binary.ninja/2026/08/04/ucpd-dynamic-rules.html


๐ŸŽ–@malwr
Forwarded from CVE Notify
๐Ÿšจ CVE-2026-59309
VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.

๐ŸŽ–@cveNotify
Forwarded from CVE Notify
๐Ÿšจ CVE-2026-59310
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

๐ŸŽ–@cveNotify