Malware News
16.2K subscribers
1.64K photos
7 videos
130 files
8.3K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
2026-08-09: Traffic Analysis Exercise - First to Last

https://www.malware-traffic-analysis.net/2026/08/09/index.html


πŸŽ–@malwr
Poly0n/WinGuard: WinGuard

https://github.com/Poly0n/WinGuard

A User-Mode Windows Threat Detection Tool Inspired by EDR Techniques, To Help Monitor And Log Any Suspicious Activity On Your PC.



πŸŽ–@malwr
Osxninja/cybersecurity-projects: This repository contains the complete record of my three-year research journey, covering the project from foundational concepts to advanced-level development. It brings together the research, experiments, implementations, findings, and progress made throughout the project, providing a structured overview of the work from basic to advanced stages.

https://github.com/Osxninja/cybersecurity-projects


πŸŽ–@malwr
2026-08-07: Seven days of scans and probes and web traffic hitting my web server

https://www.malware-traffic-analysis.net/2026/08/07/index.html


πŸŽ–@malwr
2026-08-06: Remcos RAT (7.2.5 Pro) infection

https://www.malware-traffic-analysis.net/2026/08/06/index.html


πŸŽ–@malwr
KriyosArcane/TrustMeBro: Authenticode signature manipulation toolkit for Red Team operations and security research. Covers signature stealing, metadata cloning, SIP hijacking across 19 file types, WinVerifyTrust FinalPolicy bypass, PKCS#7 payload embedding, SIP execution surface implants, Smart App Control Bypass, and analyst-triggered persistence via OID handlers.

https://github.com/KriyosArcane/TrustMeBro


πŸŽ–@malwr
Inside a Russian-Speaking Operator's Ukrainian IP Camera Toolkit
A Russian-speaking operator's open directory exposed the tools used to exploit and watch Ukrainian IP cameras, alongside attempts to breach government and military sites.

https://hunt.io/blog/russian-speaking-operator-ukrainian-camera-toolkit


πŸŽ–@malwr
A sample uses EnumWindows to iterate through all top-level windows and checks the window class name against a list. If a match is found, it calls PostMessage with WM_CLOSE. What is the malware targeting?
Final Results
33%
Preventing user intervention during ransomware execution
28%
Identifying and terminating sandbox monitoring tools
11%
Closing explorer.exe windows to force a shell restart
28%
Terminating security software windows to disable user interaction
Dynamic Analysis of VEH Dispatch and Exception-Context RIP Modification Using ROP Gadgets in ntdll.dll
Reverse engineering ntdll's VEH dispatch chain, RtlDispatchException, and RtlRestoreContext to understand VEHguard internals.

https://mooofin.github.io/portfolio/blog/vehguard.html?latex=1


πŸŽ–@malwr
Binary Ninja - The Binary Hiding in Your Registry: Cracking Windows UCPD's Dynamic Rules
Binary Ninja is a modern reverse engineering platform with a scriptable and extensible decompiler.

https://binary.ninja/2026/08/04/ucpd-dynamic-rules.html


πŸŽ–@malwr
2026-08-12: SmartApeSG ClickFix leads to two RATs

https://www.malware-traffic-analysis.net/2026/08/12/index.html


πŸŽ–@malwr
Dissecting the JWR phishing framework

Cisco Talos recently identified an undocumented phishing framework, internally branded "JWR" by its developer, built to convincingly impersonate checkout and login pages across major payment and shopping platforms.

https://blog.talosintelligence.com/dissecting-the-jwr-phishing-framework/


πŸŽ–@malwr