Malware News
16.2K subscribers
1.64K photos
7 videos
130 files
8.3K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
llnl/OGhidra: OGhidra bridges Large Language Models (LLMs) via Ollama with the Ghidra reverse engineering platform, enabling AI-driven binary analysis through natural language. Interact with Ghidra using conversational queries and automate complex reverse engineering workflows.

https://github.com/llnl/OGhidra


πŸŽ–@malwr
2026-08-09: Traffic Analysis Exercise - First to Last

https://www.malware-traffic-analysis.net/2026/08/09/index.html


πŸŽ–@malwr
Poly0n/WinGuard: WinGuard

https://github.com/Poly0n/WinGuard

A User-Mode Windows Threat Detection Tool Inspired by EDR Techniques, To Help Monitor And Log Any Suspicious Activity On Your PC.



πŸŽ–@malwr
Osxninja/cybersecurity-projects: This repository contains the complete record of my three-year research journey, covering the project from foundational concepts to advanced-level development. It brings together the research, experiments, implementations, findings, and progress made throughout the project, providing a structured overview of the work from basic to advanced stages.

https://github.com/Osxninja/cybersecurity-projects


πŸŽ–@malwr
2026-08-07: Seven days of scans and probes and web traffic hitting my web server

https://www.malware-traffic-analysis.net/2026/08/07/index.html


πŸŽ–@malwr
2026-08-06: Remcos RAT (7.2.5 Pro) infection

https://www.malware-traffic-analysis.net/2026/08/06/index.html


πŸŽ–@malwr
KriyosArcane/TrustMeBro: Authenticode signature manipulation toolkit for Red Team operations and security research. Covers signature stealing, metadata cloning, SIP hijacking across 19 file types, WinVerifyTrust FinalPolicy bypass, PKCS#7 payload embedding, SIP execution surface implants, Smart App Control Bypass, and analyst-triggered persistence via OID handlers.

https://github.com/KriyosArcane/TrustMeBro


πŸŽ–@malwr
Inside a Russian-Speaking Operator's Ukrainian IP Camera Toolkit
A Russian-speaking operator's open directory exposed the tools used to exploit and watch Ukrainian IP cameras, alongside attempts to breach government and military sites.

https://hunt.io/blog/russian-speaking-operator-ukrainian-camera-toolkit


πŸŽ–@malwr
A sample uses EnumWindows to iterate through all top-level windows and checks the window class name against a list. If a match is found, it calls PostMessage with WM_CLOSE. What is the malware targeting?
Final Results
33%
Preventing user intervention during ransomware execution
28%
Identifying and terminating sandbox monitoring tools
11%
Closing explorer.exe windows to force a shell restart
28%
Terminating security software windows to disable user interaction
Dynamic Analysis of VEH Dispatch and Exception-Context RIP Modification Using ROP Gadgets in ntdll.dll
Reverse engineering ntdll's VEH dispatch chain, RtlDispatchException, and RtlRestoreContext to understand VEHguard internals.

https://mooofin.github.io/portfolio/blog/vehguard.html?latex=1


πŸŽ–@malwr
Binary Ninja - The Binary Hiding in Your Registry: Cracking Windows UCPD's Dynamic Rules
Binary Ninja is a modern reverse engineering platform with a scriptable and extensible decompiler.

https://binary.ninja/2026/08/04/ucpd-dynamic-rules.html


πŸŽ–@malwr
2026-08-12: SmartApeSG ClickFix leads to two RATs

https://www.malware-traffic-analysis.net/2026/08/12/index.html


πŸŽ–@malwr