Azr43lKn1ght/DFIR-LABS: DFIR LABS - A compilation of challenges that aims to provide practice in simple to advanced concepts in the following topics: Digital Forensics, Incident Response, Malware Analysis and Threat Hunting.
https://github.com/Azr43lKn1ght/DFIR-LABS
🎖@malwr
https://github.com/Azr43lKn1ght/DFIR-LABS
🎖@malwr
GitHub
GitHub - Azr43lKn1ght/DFIR-LABS: DFIR LABS - A compilation of challenges that aims to provide practice in simple to advanced concepts…
DFIR LABS - A compilation of challenges that aims to provide practice in simple to advanced concepts in the following topics: Digital Forensics, Incident Response, Malware Analysis and Threat Hunti...
evilele/iEDR: A minimized non-intrusive version of EDR Introspection
https://github.com/evilele/iEDR
🎖@malwr
https://github.com/evilele/iEDR
🎖@malwr
GitHub
GitHub - evilele/iEDR: A minimized non-intrusive version of EDR Introspection
A minimized non-intrusive version of EDR Introspection - evilele/iEDR
The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution
Explore Unit 42 research on AI-enabled malware. Learn how existing behavioral detection and endpoint analytics stop AI-authored code before execution.
https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/
🎖@malwr
Explore Unit 42 research on AI-enabled malware. Learn how existing behavioral detection and endpoint analytics stop AI-authored code before execution.
https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/
🎖@malwr
Unit 42
The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution
Explore Unit 42 research on AI-enabled malware. Learn how existing behavioral detection and endpoint analytics stop AI-authored code before execution.
Research
Long-Form Technical Research, Published Free
https://www.blackstormsecurity.com/research/
🎖@malwr
Long-Form Technical Research, Published Free
https://www.blackstormsecurity.com/research/
🎖@malwr
Blackstormsecurity
Research
Long-Form Technical Research, Published Free
❤1
Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode
https://research.checkpoint.com/2026/breaking-the-seal-static-deobfuscation-of-jsceals-compiled-v8-bytecode/
🎖@malwr
https://research.checkpoint.com/2026/breaking-the-seal-static-deobfuscation-of-jsceals-compiled-v8-bytecode/
🎖@malwr
Check Point Research
Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode - Check Point Research
Research by: hasherezade Key Points Introduction JSCeal is a stealer delivered as compiled V8 bytecode (.jsc) and executed by a bundled Node.js runtime, targeting cryptocurrency applications (other vendors also tag it with the names WEEVILPROXY or MeadowLocust).…
EncryptedSharedPreferences is Dead: Here's What You Should Use Instead - Include Security Research Blog
Android application developers often store sensitive data to disk, relying on physical device security and process isolation to prevent attackers from obtaining that data. This goes against security best practices, and doesn't take advantage of the latest tools made available by Google to mitigate the risk of locally-stored sensitive data. This post explores what those tools are, discusses previous (now deprecated) methods for securing data locally, and provides recommendations for what Android developers should do if storing sensitive data is unavoidable.
https://blog.includesecurity.com/2026/08/encryptedsharedpreferences-is-dead-heres-what-you-should-use-instead/
🎖@malwr
Android application developers often store sensitive data to disk, relying on physical device security and process isolation to prevent attackers from obtaining that data. This goes against security best practices, and doesn't take advantage of the latest tools made available by Google to mitigate the risk of locally-stored sensitive data. This post explores what those tools are, discusses previous (now deprecated) methods for securing data locally, and provides recommendations for what Android developers should do if storing sensitive data is unavoidable.
https://blog.includesecurity.com/2026/08/encryptedsharedpreferences-is-dead-heres-what-you-should-use-instead/
🎖@malwr
Include Security Research Blog
EncryptedSharedPreferences is Dead: Here's What You Should Use Instead - Include Security Research Blog
Android application developers often store sensitive data to disk, relying on physical device security and process isolation to prevent attackers from obtaining that data. This goes against security best practices, and doesn't take advantage of the latest…
Joe-Schmoe137/Printer-Snooper: A go program that will attempt to enumerate printer information and documents from existing print jobs via IPP.
https://github.com/Joe-Schmoe137/Printer-Snooper
🎖@malwr
https://github.com/Joe-Schmoe137/Printer-Snooper
🎖@malwr
GitHub
GitHub - Joe-Schmoe137/Printer-Snooper: A go program that will attempt to enumerate printer information and documents from existing…
A go program that will attempt to enumerate printer information and documents from existing print jobs via IPP. - Joe-Schmoe137/Printer-Snooper
🎉1
Fire Ant Evolves: From Hypervisors to Trusted Infrastructure | Sygnia
Discover Sygnia’s investigation into Fire Ant, an advanced cyber-espionage campaign breaching VMware ESXi, vCenter, and network appliances. Learn how the attackers bypassed traditional defenses with hypervisor-level persistence and stealth.
https://www.sygnia.co/blog/fire-ant-evolves-from-hypervisors-to-trusted-infrastructure/
🎖@malwr
Discover Sygnia’s investigation into Fire Ant, an advanced cyber-espionage campaign breaching VMware ESXi, vCenter, and network appliances. Learn how the attackers bypassed traditional defenses with hypervisor-level persistence and stealth.
https://www.sygnia.co/blog/fire-ant-evolves-from-hypervisors-to-trusted-infrastructure/
🎖@malwr
Sygnia
Fire Ant Evolves: From Hypervisors to Trusted Infrastructure
First reported in 2025, Fire Ant remained active into 2026. Explore how the threat actor expanded beyond hypervisors into trusted infrastructure, compromising routers, authentication systems, and Linux management hosts to maintain covert access, collect credentials…
Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode - Check Point Research
Research by: hasherezade Key Points Introduction JSCeal is a stealer delivered as compiled V8 bytecode (.jsc) and executed by a bundled Node.js runtime, targeting cryptocurrency applications (other vendors also tag it with the names WEEVILPROXY or MeadowLocust). Its campaign activity dates back to March 2024 [1]; Check Point Research has been tracking the malware since early […]
https://research.checkpoint.com/2026/breaking-the-seal-static-deobfuscation-of-jsceals-compiled-v8-bytecode/
🎖@malwr
Research by: hasherezade Key Points Introduction JSCeal is a stealer delivered as compiled V8 bytecode (.jsc) and executed by a bundled Node.js runtime, targeting cryptocurrency applications (other vendors also tag it with the names WEEVILPROXY or MeadowLocust). Its campaign activity dates back to March 2024 [1]; Check Point Research has been tracking the malware since early […]
https://research.checkpoint.com/2026/breaking-the-seal-static-deobfuscation-of-jsceals-compiled-v8-bytecode/
🎖@malwr
Check Point Research
Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode - Check Point Research
Research by: hasherezade Key Points Introduction JSCeal is a stealer delivered as compiled V8 bytecode (.jsc) and executed by a bundled Node.js runtime, targeting cryptocurrency applications (other vendors also tag it with the names WEEVILPROXY or MeadowLocust).…
Anatomy of BraZetsu: How Cybercriminals Fuel the Underground Ecosystem
Group-IB uncovers BraZetsu, a new Python-based Windows malware that serves as a master toolkit for Initial Access Brokers and powers a unique, AI-enhanced underground marketplace for commercializing compromised Iberian and Latin American targets.
https://www.group-ib.com/blog/brazetsu-ai-enhanced-iab-marketplace/
🎖@malwr
Group-IB uncovers BraZetsu, a new Python-based Windows malware that serves as a master toolkit for Initial Access Brokers and powers a unique, AI-enhanced underground marketplace for commercializing compromised Iberian and Latin American targets.
https://www.group-ib.com/blog/brazetsu-ai-enhanced-iab-marketplace/
🎖@malwr
Group-IB
Anatomy of BraZetsu: How Cybercriminals Fuel the Underground Ecosystem
Group-IB uncovers BraZetsu, a new Python-based Windows malware that serves as a master toolkit for Initial Access Brokers and powers a unique, AI-enhanced underground marketplace for commercializing compromised Iberian and Latin American targets.
Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon - Check Point Research
Research by: Amit Yardeni Key Points Introduction Since mid-2025, Check Point Research has tracked a sustained campaign against Brazilian organizations. The tradecraft points to a Chinese-speaking cybercrime group connected to Earth Berberoka, an actor first documented targeting gambling sites across Asia. Once inside a victim, the group deploys a broad Linux toolkit: a custom downloader, several backdoors, […]
https://research.checkpoint.com/2026/gaming-the-system-how-a-chinese-speaking-actor-turned-brazilian-government-sites-into-an-seo-weapon/
🎖@malwr
Research by: Amit Yardeni Key Points Introduction Since mid-2025, Check Point Research has tracked a sustained campaign against Brazilian organizations. The tradecraft points to a Chinese-speaking cybercrime group connected to Earth Berberoka, an actor first documented targeting gambling sites across Asia. Once inside a victim, the group deploys a broad Linux toolkit: a custom downloader, several backdoors, […]
https://research.checkpoint.com/2026/gaming-the-system-how-a-chinese-speaking-actor-turned-brazilian-government-sites-into-an-seo-weapon/
🎖@malwr
Check Point Research
Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon - Check Point Research
Research by: Amit Yardeni Key Points Introduction Since mid-2025, Check Point Research has tracked a sustained campaign against Brazilian organizations. The tradecraft points to a Chinese-speaking cybercrime group connected to Earth Berberoka, an actor f…
Hunting macOS Amnesia Stealer in Elastic
Following Amnesia Stealer through macOS endpoint telemetry in Elastic.
https://jasonphang98.github.io/posts/amnesia-stealer/
🎖@malwr
Following Amnesia Stealer through macOS endpoint telemetry in Elastic.
https://jasonphang98.github.io/posts/amnesia-stealer/
🎖@malwr
Jason
Hunting macOS Amnesia Stealer in Elastic
Following Amnesia Stealer through macOS endpoint telemetry in Elastic.
Mirage Kitten switches to Node.js and JavaScript malware
Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.
https://securelist.com/mirage-kitten-new-backdoors-noderabbit-pollcat/121244/
🎖@malwr
Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.
https://securelist.com/mirage-kitten-new-backdoors-noderabbit-pollcat/121244/
🎖@malwr
IndAlok/rzweb: A complete browser-based reverse engineering platform built on Rizin, running entirely client-side via WebAssembly.
https://github.com/indalok/rzweb
🎖@malwr
https://github.com/indalok/rzweb
🎖@malwr
GitHub
GitHub - IndAlok/rzweb: A complete browser-based reverse engineering platform built on Rizin, running entirely client-side via…
A complete browser-based reverse engineering platform built on Rizin, running entirely client-side via WebAssembly. - IndAlok/rzweb
❤3
MSNightmare/FalconFlank: Crowdstrike Falcon 0day Privilege Escalation Vulnerability
https://github.com/MSNightmare/FalconFlank
🎖@malwr
https://github.com/MSNightmare/FalconFlank
🎖@malwr
GitHub
GitHub - MSNightmare/FalconFlank: Crowdstrike Falcon 0day Privilege Escalation Vulnerability
Crowdstrike Falcon 0day Privilege Escalation Vulnerability - MSNightmare/FalconFlank
❤3
Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity | Huntress
Huntress is tracking a pattern across multiple customer environments where rogue ScreenConnect clients repeatedly spawn the Windows Script Host to execute a series of four VBScript files.
https://www.huntress.com/blog/rogue-screenconnect-installations
🎖@malwr
Huntress is tracking a pattern across multiple customer environments where rogue ScreenConnect clients repeatedly spawn the Windows Script Host to execute a series of four VBScript files.
https://www.huntress.com/blog/rogue-screenconnect-installations
🎖@malwr
Huntress
Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity | Huntress
Huntress is tracking a pattern across multiple customer environments where rogue ScreenConnect clients repeatedly spawn the Windows Script Host to execute a series of four VBScript files.
matthart1983/netwatch: Real-time network diagnostics in your terminal. One command, zero config, instant visibility.
https://github.com/matthart1983/netwatch
🎖@malwr
https://github.com/matthart1983/netwatch
🎖@malwr
GitHub
GitHub - matthart1983/netwatch: Real-time network diagnostics in your terminal. One command, zero config, instant visibility.
Real-time network diagnostics in your terminal. One command, zero config, instant visibility. - matthart1983/netwatch
mytechnotalent/Reverse-Engineering: A FREE comprehensive reverse engineering tutorial covering x86, x64, 32-bit/64-bit ARM, 8-bit AVR and 32-bit RISC-V architectures.
https://github.com/mytechnotalent/Reverse-Engineering
🎖@malwr
https://github.com/mytechnotalent/Reverse-Engineering
🎖@malwr
GitHub
GitHub - mytechnotalent/Reverse-Engineering: A FREE comprehensive reverse engineering tutorial covering x86, x64, 32-bit/64-bit…
A FREE comprehensive reverse engineering tutorial covering x86, x64, 32-bit/64-bit ARM, 8-bit AVR and 32-bit RISC-V architectures. - mytechnotalent/Reverse-Engineering
Attack Cases in Korea Involving the Installation of Radmin and UltraVNC
The AhnLab SEcurity intelligence Center (ASEC) recently identified attack cases that exploited Radmin and UltraVNC. Although the Initial Intrusion method remains unknown, the attackers installed Radmin—a remote control tool—and then installed UltraVNC. The threat actors exploited the remote control tools to gain control of the infected systems and installed Netch and CCProxy to use the […]
https://asec.ahnlab.com/en/95230/
🎖@malwr
The AhnLab SEcurity intelligence Center (ASEC) recently identified attack cases that exploited Radmin and UltraVNC. Although the Initial Intrusion method remains unknown, the attackers installed Radmin—a remote control tool—and then installed UltraVNC. The threat actors exploited the remote control tools to gain control of the infected systems and installed Netch and CCProxy to use the […]
https://asec.ahnlab.com/en/95230/
🎖@malwr
ASEC
Attack Cases in Korea Involving the Installation of Radmin and UltraVNC - ASEC
Attack Cases in Korea Involving the Installation of Radmin and UltraVNC ASEC
Contagious Interview: Trojanized macOS Installers
Jamf Threat Labs uncovers 14 trojanized macOS DMGs and PKGs tied to the DPRK-attributed Contagious Interview campaign. Learn more.
https://www.jamf.com/blog/contagious-interview-trojanized-macos-installers/
🎖@malwr
Jamf Threat Labs uncovers 14 trojanized macOS DMGs and PKGs tied to the DPRK-attributed Contagious Interview campaign. Learn more.
https://www.jamf.com/blog/contagious-interview-trojanized-macos-installers/
🎖@malwr
❤1
bikini/exploitarium: A single archive of public exploit PoCs and vulnerability research writeups. At the time I post these, none have been reported. Feel free to report them yourself and take credit for the CVE if handed out lulz. Please do not abuse these. I do this so to allure people into the field, and I've always found this is the most efficient way.
https://github.com/bikini/exploitarium
🎖@malwr
https://github.com/bikini/exploitarium
🎖@malwr
GitHub
GitHub - bikini/exploitarium: A single archive of public exploit PoCs and vulnerability research writeups. At the time I post these…
A single archive of public exploit PoCs and vulnerability research writeups. At the time I post these, none have been reported. Feel free to report them yourself and take credit for the CVE if hand...