Developers in the Crosshairs: Fake AI Tools Deliver Infostealer
In April 2026, Netskope Threat Labs exposed a Malware-as-a-Service (MaaS) NodeJS infostealer delivered through the ClickFix social engineering technique.
https://www.netskope.com/jp/blog/developers-in-the-crosshairs-fake-ai-tools-deliver-infostealer
🎖@malwr
In April 2026, Netskope Threat Labs exposed a Malware-as-a-Service (MaaS) NodeJS infostealer delivered through the ClickFix social engineering technique.
https://www.netskope.com/jp/blog/developers-in-the-crosshairs-fake-ai-tools-deliver-infostealer
🎖@malwr
Netskope
Developers in the Crosshairs: Fake AI Tools Deliver Infostealer
In April 2026, Netskope Threat Labs exposed a Malware-as-a-Service (MaaS) NodeJS infostealer delivered through the ClickFix social engineering technique.
❤1
pulpul-s/HWall: Linux hardware inventory and live sensor monitor
https://github.com/pulpul-s/HWall
🎖@malwr
https://github.com/pulpul-s/HWall
🎖@malwr
GitHub
GitHub - pulpul-s/HWall: Linux hardware inventory and live sensor monitor
Linux hardware inventory and live sensor monitor. Contribute to pulpul-s/HWall development by creating an account on GitHub.
LockBit String Deobfuscation: Reversing Affine Cipher DLL Loading with Ghidra
Technical analysis of LockBit ransomware string obfuscation — affine cipher, dynamic API resolution, and IAT evasion, reversed with Ghidra.
https://ginomaihuiri.github.io/lockbit-string-deobfuscation
🎖@malwr
Technical analysis of LockBit ransomware string obfuscation — affine cipher, dynamic API resolution, and IAT evasion, reversed with Ghidra.
https://ginomaihuiri.github.io/lockbit-string-deobfuscation
🎖@malwr
Aldair Maihuiri
LockBit String Deobfuscation: Reversing Affine Cipher DLL Loading with Ghidra
Technical analysis of LockBit ransomware string obfuscation — affine cipher, dynamic API resolution, and IAT evasion, reversed with Ghidra.
derv82/wifit3: Wifite but USB-only & cross-platform.
https://github.com/derv82/wifit3
🎖@malwr
https://github.com/derv82/wifit3
A wireless auditor that runs on Linux and Windows, comes with its own built-in drivers.
🎖@malwr
GitHub
GitHub - derv82/wifit3: Wifite but USB-only & cross-platform.
Wifite but USB-only & cross-platform. Contribute to derv82/wifit3 development by creating an account on GitHub.
Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases (Larva-26005) - ASEC
https://asec.ahnlab.com/en/94847/
🎖@malwr
https://asec.ahnlab.com/en/94847/
🎖@malwr
ASEC
Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases (Larva-26005) - ASEC
Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases (Larva-26005) ASEC
CodeRiper/memforge: Cross-platform, high-performance process memory acquisition and digital forensics (DFIR) triage suite written in pure Rust.
https://github.com/CodeRiper/memforge
🎖@malwr
https://github.com/CodeRiper/memforge
🎖@malwr
GitHub
GitHub - CodeRiper/memforge: Cross-platform, high-performance process memory acquisition and digital forensics (DFIR) triage suite…
Cross-platform, high-performance process memory acquisition and digital forensics (DFIR) triage suite written in pure Rust. - CodeRiper/memforge
Point Wild Exclusive: Dissecting Vanta Stealer, a Python-Based Cross-Platform Information Theft Malware | Point Wild
Point Wild
https://www.pointwild.com/threat-intelligence/point-wild-exclusive-dissecting-vanta-stealer-a-python-based-cross-platform-information-theft-malware/
🎖@malwr
Point Wild
https://www.pointwild.com/threat-intelligence/point-wild-exclusive-dissecting-vanta-stealer-a-python-based-cross-platform-information-theft-malware/
🎖@malwr
Point Wild
Point Wild Exclusive: Dissecting Vanta Stealer, a Python-Based Cross-Platform Information Theft Malware | Point Wild
Reverse engineering a miner malware
Introduction I wanted a reverse engineering project, so I decided to analyse a piece of real malware.
https://gustavvising.se/2026/07/17/reverse-engineering-a-miner-malware.html
🎖@malwr
Introduction I wanted a reverse engineering project, so I decided to analyse a piece of real malware.
https://gustavvising.se/2026/07/17/reverse-engineering-a-miner-malware.html
🎖@malwr
Gustav Vising
Reverse engineering a miner malware
Introduction I wanted a reverse engineering project, so I decided to analyse a piece of real malware.
Binary Ninja - The Binary Hiding in Your Registry: Cracking Windows UCPD's Dynamic Rules
Binary Ninja is a modern reverse engineering platform with a scriptable and extensible decompiler.
https://binary.ninja/2026/08/04/ucpd-dynamic-rules.html
🎖@malwr
Binary Ninja is a modern reverse engineering platform with a scriptable and extensible decompiler.
https://binary.ninja/2026/08/04/ucpd-dynamic-rules.html
🎖@malwr
Binary Ninja
Binary Ninja - The Binary Hiding in Your Registry: Cracking Windows UCPD's Dynamic Rules
Binary Ninja is a modern reverse engineering platform with a scriptable and extensible decompiler.
Forwarded from CVE Notify
🚨 CVE-2026-59309
VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.
🎖@cveNotify
VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.
🎖@cveNotify
Forwarded from CVE Notify
🚨 CVE-2026-59310
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
🎖@cveNotify
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
🎖@cveNotify
NeverSight/NeverC: The AI-friendly C23 compiler for security research, built on LLVM
https://github.com/NeverSight/NeverC
🎖@malwr
https://github.com/NeverSight/NeverC
🎖@malwr
GitHub
GitHub - NeverSight/NeverC: The AI-friendly C23 compiler for security research, built on LLVM [WIP]
The AI-friendly C23 compiler for security research, built on LLVM [WIP] - NeverSight/NeverC
CILFI: Automatic Function Identification in .NET Binaries
There is a specific stage of grief every .NET reverse-engineer goes through when writing the next .NET deobfuscator or config extractor. It is the realization you have to write yet another ugly pattern-matching algorithm to find the exact same string decryptor, VM opcode handler, or C2 connection initializer functions to extract obfuscator configurations or IoCs.
https://blog.washi.dev/posts/cilfi/
🎖@malwr
There is a specific stage of grief every .NET reverse-engineer goes through when writing the next .NET deobfuscator or config extractor. It is the realization you have to write yet another ugly pattern-matching algorithm to find the exact same string decryptor, VM opcode handler, or C2 connection initializer functions to extract obfuscator configurations or IoCs.
https://blog.washi.dev/posts/cilfi/
🎖@malwr
Washi
CILFI: Automatic Function Identification in .NET Binaries
There is a specific stage of grief every .NET reverse-engineer goes through when writing the next .NET deobfuscator or config extractor. It is the realization you have to write yet another ugly pattern-matching algorithm to find the exact same string decryptor…
Malware Development Essentials for Operators
Today’s post is a full pipeline walkthrough from a MessageBoxA call all the way to a kernel rootkit doing DKOM process hiding and callback abuse. Dynamic function loading, PEB walking, IAT hooking, process hollowing, DLL injection, shellcode encryption, APC injection all of it, with code.
https://f00crew.org/0x33
🎖@malwr
Today’s post is a full pipeline walkthrough from a MessageBoxA call all the way to a kernel rootkit doing DKOM process hiding and callback abuse. Dynamic function loading, PEB walking, IAT hooking, process hollowing, DLL injection, shellcode encryption, APC injection all of it, with code.
https://f00crew.org/0x33
🎖@malwr
samugit83/redamon: An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with zero human intervention.
https://github.com/samugit83/redamon
🎖@malwr
https://github.com/samugit83/redamon
🎖@malwr
GitHub
GitHub - samugit83/redamon: An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance…
An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with zero human intervention. - samugit83/redamon
Impersonation, Click Hijacking, and TDS: Inside a Malware Distribution Ecosystem
https://research.checkpoint.com/2026/impersonation-click-hijacking-and-tds-inside-a-malware-distribution-ecosystem/
🎖@malwr
https://research.checkpoint.com/2026/impersonation-click-hijacking-and-tds-inside-a-malware-distribution-ecosystem/
🎖@malwr
Check Point Research
Impersonation, Click Hijacking, and TDS: Inside a Malware Distribution Ecosystem - Check Point Research
Research by: Alexey Bukhteyev Key Takeaways Introduction When we search Google for a popular piece of software, we usually click the first result, sometimes without even looking at the rest, because official project sites tend to rank highest and appear near…
Malware-Research-Hub/README.en.md at main · darama22/Malware-Research-Hub
https://github.com/darama22/Malware-Research-Hub/blob/main/README.en.md
🎖@malwr
https://github.com/darama22/Malware-Research-Hub/blob/main/README.en.md
🎖@malwr
GitHub
Malware-Research-Hub/README.en.md at main · darama22/Malware-Research-Hub
Self-contained malware research hub: curated catalog of 80 families (1971-2024) + 2,764 real encrypted samples, indexed and searchable. Local Flask app, bilingual. - darama22/Malware-Research-Hub
When Agentic Glue Melts: Exploiting Cloudflare Code Mode and Workers
https://research.checkpoint.com/2026/when-agentic-glue-melts/
🎖@malwr
https://research.checkpoint.com/2026/when-agentic-glue-melts/
🎖@malwr
Check Point Research
When Agentic Glue Melts: Exploiting Cloudflare Code Mode and Workers - Check Point Research
By Yarden Porat, Check Point Research Key Points The short version We set out to break Cloudflare Code Mode, and ended up breaking Cloudflare Workers too. We did both by targeting workerd, the runtime beneath both: an in-process sandbox that relies entirely…
Windows tcpip.sys ICMP Timestamp Bug: EnableICMPTimestampRep=0 Registry Bypass & RFC 792 Violation | Kernel RE
EnableICMPTimestampRep=0 does not suppress ICMP Timestamp Replies (Type 14) on Windows 11. Ghidra RE of tcpip.sys 10.0.26100.8457 confirms Ipv4pHandleTimestampRequest generates T14 unconditionally, plus a second bug: Receive/Transmit timestamps written little-endian in violation of RFC 792. Only effective mitigation: WFP firewall rule.
https://netacoding.com/posts/windows-icmp-timestamp-bugs/
🎖@malwr
EnableICMPTimestampRep=0 does not suppress ICMP Timestamp Replies (Type 14) on Windows 11. Ghidra RE of tcpip.sys 10.0.26100.8457 confirms Ipv4pHandleTimestampRequest generates T14 unconditionally, plus a second bug: Receive/Transmit timestamps written little-endian in violation of RFC 792. Only effective mitigation: WFP firewall rule.
https://netacoding.com/posts/windows-icmp-timestamp-bugs/
🎖@malwr
Netacoding | Cybersecurity, Assembly & Network Research
Windows tcpip.sys ICMP Timestamp Bug: EnableICMPTimestampRep=0 Registry Bypass & RFC 792 Violation | Kernel RE
EnableICMPTimestampRep=0 does not suppress ICMP Timestamp Replies (Type 14) on Windows 11. Ghidra RE of tcpip.sys 10.0.26100.8457 confirms Ipv4pHandleTimestampRequest generates T14 unconditionally, plus a second bug: Receive/Transmit timestamps written little…
LockBit 5.0 Linux Malware Analysis: ChaCha20 + Curve25519 Offline Encryption, strace Evasion & IOCs
Full reverse engineering of LockBit 5.0 Linux (LINUX Locker v1.01 amd64): offline-capable ChaCha20+Curve25519 encryption, strace anti-analysis evasion, aggressive free space wiping, and zero network activity during encryption. eBPF dynamic tracing, Ghidra static RE, triple-confirmed network behavior, and complete IOC list.
https://netacoding.com/posts/lockbit5-analysis/
🎖@malwr
Full reverse engineering of LockBit 5.0 Linux (LINUX Locker v1.01 amd64): offline-capable ChaCha20+Curve25519 encryption, strace anti-analysis evasion, aggressive free space wiping, and zero network activity during encryption. eBPF dynamic tracing, Ghidra static RE, triple-confirmed network behavior, and complete IOC list.
https://netacoding.com/posts/lockbit5-analysis/
🎖@malwr
Netacoding | Cybersecurity, Assembly & Network Research
LockBit 5.0 Linux Malware Analysis: ChaCha20 + Curve25519 Offline Encryption, strace Evasion & IOCs
Full reverse engineering of LockBit 5.0 Linux (LINUX Locker v1.01 amd64): offline-capable ChaCha20+Curve25519 encryption, strace anti-analysis evasion, aggressive free space wiping, and zero network activity during encryption. eBPF dynamic tracing, Ghidra…