Osxninja/cybersecurity-projects: This repository contains the complete record of my three-year research journey, covering the project from foundational concepts to advanced-level development. It brings together the research, experiments, implementations, findings, and progress made throughout the project, providing a structured overview of the work from basic to advanced stages.
https://github.com/Osxninja/cybersecurity-projects
π@malwr
https://github.com/Osxninja/cybersecurity-projects
π@malwr
GitHub
GitHub - Osxninja/cybersecurity-projects: This repository contains the complete record of my three-year research journey, coveringβ¦
This repository contains the complete record of my three-year research journey, covering the project from foundational concepts to advanced-level development. It brings together the research, exper...
2026-08-07: Seven days of scans and probes and web traffic hitting my web server
https://www.malware-traffic-analysis.net/2026/08/07/index.html
π@malwr
https://www.malware-traffic-analysis.net/2026/08/07/index.html
π@malwr
2026-08-06: Remcos RAT (7.2.5 Pro) infection
https://www.malware-traffic-analysis.net/2026/08/06/index.html
π@malwr
https://www.malware-traffic-analysis.net/2026/08/06/index.html
π@malwr
KriyosArcane/TrustMeBro: Authenticode signature manipulation toolkit for Red Team operations and security research. Covers signature stealing, metadata cloning, SIP hijacking across 19 file types, WinVerifyTrust FinalPolicy bypass, PKCS#7 payload embedding, SIP execution surface implants, Smart App Control Bypass, and analyst-triggered persistence via OID handlers.
https://github.com/KriyosArcane/TrustMeBro
π@malwr
https://github.com/KriyosArcane/TrustMeBro
π@malwr
GitHub
GitHub - KriyosArcane/TrustMeBro: Authenticode signature manipulation toolkit for Red Team operations and security research. Coversβ¦
Authenticode signature manipulation toolkit for Red Team operations and security research. Covers signature stealing, metadata cloning, SIP hijacking across 19 file types, WinVerifyTrust FinalPolic...
DdUdle/ctxdebug: MCP-powered reverse engineering platform connecting WinDbg, IDA Pro & x64dbg with 160+ AI-accessible debugging and analysis tools.
https://github.com/DdUdle/ctxdebug
π@malwr
https://github.com/DdUdle/ctxdebug
π@malwr
GitHub
GitHub - DdUdle/ctxdebug: MCP-powered reverse engineering platform connecting WinDbg, IDA Pro & x64dbg with 160+ AI-accessibleβ¦
MCP-powered reverse engineering platform connecting WinDbg, IDA Pro & x64dbg with 160+ AI-accessible debugging and analysis tools. - DdUdle/ctxdebug
2026-08-10: Lumma Stealer or variant
https://www.malware-traffic-analysis.net/2026/08/10/index.html
π@malwr
https://www.malware-traffic-analysis.net/2026/08/10/index.html
π@malwr
NHCM-dev/JVMRTDP: A Java debugger & library which allows user and programmer to control remote JavaVMs
https://github.com/NHCM-dev/JVMRTDP
π@malwr
https://github.com/NHCM-dev/JVMRTDP
π@malwr
GitHub
GitHub - NHCM-dev/JVMRTDP: A Java debugger & library which allows user and programmer to control remote JavaVMs
A Java debugger & library which allows user and programmer to control remote JavaVMs - NHCM-dev/JVMRTDP
thomasxm/BOAZ_beta: Multilayered AV/EDR Evasion Framework (no longer actively maintained)
https://github.com/thomasxm/BOAZ_beta
π@malwr
https://github.com/thomasxm/BOAZ_beta
π@malwr
GitHub
GitHub - thomasxm/BOAZ_beta: Multilayered AV/EDR Evasion Framework (no longer actively maintained)
Multilayered AV/EDR Evasion Framework (no longer actively maintained) - thomasxm/BOAZ_beta
β€1
Shattering the Dream β When a Job Offer Becomes a Zero-Day Attack
https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/
π@malwr
https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/
π@malwr
Check Point Research
Shattering the Dream - When a Job Offer Becomes a Zero-Day Attack - Check Point Research
Key Points Introduction Since early 2026, Check Point Research has tracked a wave of the Operation Dream Job campaign. This wave primarily targeted the defense sector worldwide, with a particular emphasis on companies operating in the aerospace and aviationβ¦
π1
Inside a Russian-Speaking Operator's Ukrainian IP Camera Toolkit
A Russian-speaking operator's open directory exposed the tools used to exploit and watch Ukrainian IP cameras, alongside attempts to breach government and military sites.
https://hunt.io/blog/russian-speaking-operator-ukrainian-camera-toolkit
π@malwr
A Russian-speaking operator's open directory exposed the tools used to exploit and watch Ukrainian IP cameras, alongside attempts to breach government and military sites.
https://hunt.io/blog/russian-speaking-operator-ukrainian-camera-toolkit
π@malwr
hunt.io
Inside a Russian-Speaking Operator's Ukrainian IP Camera Toolkit
A Russian-speaking operator's open directory exposed the tools used to exploit and watch Ukrainian IP cameras, alongside attempts to breach government and military sites.
A sample uses EnumWindows to iterate through all top-level windows and checks the window class name against a list. If a match is found, it calls PostMessage with WM_CLOSE. What is the malware targeting?
Final Results
33%
Preventing user intervention during ransomware execution
28%
Identifying and terminating sandbox monitoring tools
11%
Closing explorer.exe windows to force a shell restart
28%
Terminating security software windows to disable user interaction
Dynamic Analysis of VEH Dispatch and Exception-Context RIP Modification Using ROP Gadgets in ntdll.dll
Reverse engineering ntdll's VEH dispatch chain, RtlDispatchException, and RtlRestoreContext to understand VEHguard internals.
https://mooofin.github.io/portfolio/blog/vehguard.html?latex=1
π@malwr
Reverse engineering ntdll's VEH dispatch chain, RtlDispatchException, and RtlRestoreContext to understand VEHguard internals.
https://mooofin.github.io/portfolio/blog/vehguard.html?latex=1
π@malwr
mooofin.github.io
Dynamic Analysis of VEH Dispatch and Exception-Context RIP Modification Using ROP Gadgets in ntdll.dll
Reverse engineering ntdll's VEH dispatch chain, RtlDispatchException, and RtlRestoreContext to understand VEHguard internals.
Binary Ninja - The Binary Hiding in Your Registry: Cracking Windows UCPD's Dynamic Rules
Binary Ninja is a modern reverse engineering platform with a scriptable and extensible decompiler.
https://binary.ninja/2026/08/04/ucpd-dynamic-rules.html
π@malwr
Binary Ninja is a modern reverse engineering platform with a scriptable and extensible decompiler.
https://binary.ninja/2026/08/04/ucpd-dynamic-rules.html
π@malwr
Binary Ninja
Binary Ninja - The Binary Hiding in Your Registry: Cracking Windows UCPD's Dynamic Rules
Binary Ninja is a modern reverse engineering platform with a scriptable and extensible decompiler.
2026-08-12: SmartApeSG ClickFix leads to two RATs
https://www.malware-traffic-analysis.net/2026/08/12/index.html
π@malwr
https://www.malware-traffic-analysis.net/2026/08/12/index.html
π@malwr
Dissecting the JWR phishing framework
Cisco Talos recently identified an undocumented phishing framework, internally branded "JWR" by its developer, built to convincingly impersonate checkout and login pages across major payment and shopping platforms.
https://blog.talosintelligence.com/dissecting-the-jwr-phishing-framework/
π@malwr
Cisco Talos recently identified an undocumented phishing framework, internally branded "JWR" by its developer, built to convincingly impersonate checkout and login pages across major payment and shopping platforms.
https://blog.talosintelligence.com/dissecting-the-jwr-phishing-framework/
π@malwr
Cisco Talos
Dissecting the JWR phishing framework
Cisco Talos recently identified an undocumented phishing framework, internally branded "JWR" by its developer, built to convincingly impersonate checkout and login pages across major payment and shopping platforms.
Zydak/LeetObfuscator: LLVM based obfuscator
https://github.com/Zydak/LeetObfuscator
π@malwr
https://github.com/Zydak/LeetObfuscator
A very simple obfuscator for C/C++ x64 and x86 code
π@malwr
GitHub
GitHub - Zydak/LeetObfuscator: LLVM based obfuscator
LLVM based obfuscator. Contribute to Zydak/LeetObfuscator development by creating an account on GitHub.
π₯1
Malware Crypting Services and the Threat Actors Who Sell Them
Insikt Group analyzes 24 threat actors selling malware crypting services. Learn about their evasion techniques, market dynamics, and how defenders can prioritize behavioral detection over static analysis.
https://www.recordedfuture.com/research/malware-crypting-services-threat-actors
π@malwr
Insikt Group analyzes 24 threat actors selling malware crypting services. Learn about their evasion techniques, market dynamics, and how defenders can prioritize behavioral detection over static analysis.
https://www.recordedfuture.com/research/malware-crypting-services-threat-actors
π@malwr
Recordedfuture
Malware Crypting Services and the Threat Actors Who Sell Them
Insikt Group analyzes 24 threat actors selling malware crypting services. Learn about their evasion techniques, market dynamics, and how defenders can prioritize behavioral detection over static analysis.
skyisoway/Null-API-Hook: API Hooking for Windows x64
https://github.com/skyisoway/Null-API-Hook
π@malwr
https://github.com/skyisoway/Null-API-Hook
π@malwr
GitHub
GitHub - skyisoway/Null-API-Hook: API Hooking for Windows x64
API Hooking for Windows x64 . Contribute to skyisoway/Null-API-Hook development by creating an account on GitHub.
π₯1
When You Pay the Ransom - Taking Apart an Interlock ESXi Decryptor | Maldbg - Malware Analysis Blog
Taking apart a freshly compiled Interlock ESXi decryptor, and what it reveals about how the encryptor works.
https://maldbg.com/interlock-esxi-decryptor-internals
π@malwr
Taking apart a freshly compiled Interlock ESXi decryptor, and what it reveals about how the encryptor works.
https://maldbg.com/interlock-esxi-decryptor-internals
π@malwr
Maldbg
When You Pay the Ransom - Taking Apart an Interlock ESXi Decryptor | Maldbg - Malware Analysis Blog
Taking apart a freshly compiled Interlock ESXi decryptor, and what it reveals about how the encryptor works.
From P-Code to GNN: extract binary code semantics - Quarkslab's blog
pcode_graph is a Python library, published by Quarkslab, suitable to build semantic graphs from binary code. We present how to use it to detect function similarities in binaries.
https://blog.quarkslab.com/from-p-code-to-gnn-extract-binary-code-semantics.html
π@malwr
pcode_graph is a Python library, published by Quarkslab, suitable to build semantic graphs from binary code. We present how to use it to detect function similarities in binaries.
https://blog.quarkslab.com/from-p-code-to-gnn-extract-binary-code-semantics.html
π@malwr
Quarkslab
From P-Code to GNN: extract binary code semantics - Quarkslab's blog
pcode_graph is a Python library, published by Quarkslab, suitable to build semantic graphs from binary code. We present how to use it to detect function similarities in binaries.