Malware News
16.2K subscribers
1.64K photos
7 videos
130 files
8.27K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution
Explore Unit 42 research on AI-enabled malware. Learn how existing behavioral detection and endpoint analytics stop AI-authored code before execution.

https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/


🎖@malwr
EncryptedSharedPreferences is Dead: Here's What You Should Use Instead - Include Security Research Blog
Android application developers often store sensitive data to disk, relying on physical device security and process isolation to prevent attackers from obtaining that data. This goes against security best practices, and doesn't take advantage of the latest tools made available by Google to mitigate the risk of locally-stored sensitive data. This post explores what those tools are, discusses previous (now deprecated) methods for securing data locally, and provides recommendations for what Android developers should do if storing sensitive data is unavoidable.

https://blog.includesecurity.com/2026/08/encryptedsharedpreferences-is-dead-heres-what-you-should-use-instead/


🎖@malwr
Fire Ant Evolves: From Hypervisors to Trusted Infrastructure | Sygnia
Discover Sygnia’s investigation into Fire Ant, an advanced cyber-espionage campaign breaching VMware ESXi, vCenter, and network appliances. Learn how the attackers bypassed traditional defenses with hypervisor-level persistence and stealth.

https://www.sygnia.co/blog/fire-ant-evolves-from-hypervisors-to-trusted-infrastructure/


🎖@malwr
Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode - Check Point Research
Research by: hasherezade Key Points Introduction JSCeal is a stealer delivered as compiled V8 bytecode (.jsc) and executed by a bundled Node.js runtime, targeting cryptocurrency applications (other vendors also tag it with the names WEEVILPROXY or MeadowLocust). Its campaign activity dates back to March 2024 [1]; Check Point Research has been tracking the malware since early […]

https://research.checkpoint.com/2026/breaking-the-seal-static-deobfuscation-of-jsceals-compiled-v8-bytecode/


🎖@malwr
Anatomy of BraZetsu: How Cybercriminals Fuel the Underground Ecosystem
Group-IB uncovers BraZetsu, a new Python-based Windows malware that serves as a master toolkit for Initial Access Brokers and powers a unique, AI-enhanced underground marketplace for commercializing compromised Iberian and Latin American targets.

https://www.group-ib.com/blog/brazetsu-ai-enhanced-iab-marketplace/


🎖@malwr
Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon - Check Point Research
Research by: Amit Yardeni Key Points Introduction Since mid-2025, Check Point Research has tracked a sustained campaign against Brazilian organizations. The tradecraft points to a Chinese-speaking cybercrime group connected to Earth Berberoka, an actor first documented targeting gambling sites across Asia. Once inside a victim, the group deploys a broad Linux toolkit: a custom downloader, several backdoors, […]

https://research.checkpoint.com/2026/gaming-the-system-how-a-chinese-speaking-actor-turned-brazilian-government-sites-into-an-seo-weapon/


🎖@malwr
Mirage Kitten switches to Node.js and JavaScript malware
Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.

https://securelist.com/mirage-kitten-new-backdoors-noderabbit-pollcat/121244/


🎖@malwr
Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity | Huntress
Huntress is tracking a pattern across multiple customer environments where rogue ScreenConnect clients repeatedly spawn the Windows Script Host to execute a series of four VBScript files.

https://www.huntress.com/blog/rogue-screenconnect-installations


🎖@malwr
Attack Cases in Korea Involving the Installation of Radmin and UltraVNC

The AhnLab SEcurity intelligence Center (ASEC) recently identified attack cases that exploited Radmin and UltraVNC. Although the Initial Intrusion method remains unknown, the attackers installed Radmin—a remote control tool—and then installed UltraVNC. The threat actors exploited the remote control tools to gain control of the infected systems and installed Netch and CCProxy to use the […]

https://asec.ahnlab.com/en/95230/


🎖@malwr
Contagious Interview: Trojanized macOS Installers
Jamf Threat Labs uncovers 14 trojanized macOS DMGs and PKGs tied to the DPRK-attributed Contagious Interview campaign. Learn more.

https://www.jamf.com/blog/contagious-interview-trojanized-macos-installers/


🎖@malwr
1
bikini/exploitarium: A single archive of public exploit PoCs and vulnerability research writeups. At the time I post these, none have been reported. Feel free to report them yourself and take credit for the CVE if handed out lulz. Please do not abuse these. I do this so to allure people into the field, and I've always found this is the most efficient way.

https://github.com/bikini/exploitarium


🎖@malwr