Malware News
15.8K subscribers
1.64K photos
7 videos
130 files
8.1K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
For the new year I started a new blog post series on HyperGuard: PatchGuard’s lesser-known sibling:
https://windows-internals.com/hyperguard-secure-kernel-patch-guard-part-1-skpg-initialization/
πŸ—£yarden_shafir


πŸŽ–@malwr
Happy New Year! 🎊🎈 πŸŽ‰
Happy New Bug! πŸ›πŸœπŸž
https://bugs.chromium.org/p/project-zero/issues/detail?id=2223

https://bugs.chromium.org/p/project-zero/issues/detail?id=2235
πŸ—£natashenka


πŸŽ–@malwr
I published a new blog post on β€œAutomated RE of Kernel Configurations”:

This also includes the release of a new BN plugin (link in blog post).
https://zznop.com/2022/01/02/automated-re-of-kernel-build-configs/
πŸ—£zznop_


πŸŽ–@malwr
Automated RE of Kernel Configurations
πŸ—£zznop_

Pretty nice but seems to be somewhat manual process. I think somewhere on Twitter(?) I saw an idea of bruteforcing/bisecting the kconfig by building multiple variations of the kernel with different kconfig settings and comparing it against the image you have.
πŸ‘€igor_sk


πŸŽ–@malwr
WHAT?! πŸ˜‚
If you provide /FS:FILESYSTEM parameter to the format[.]com utility, the resulting process will try to load ("U"+FILESYSTEM).DLL using the default search path...
The weirdest custom DLL launcher I have meet so far :D
πŸ—£0gtweet


πŸŽ–@malwr
https://adcb-kyc-update.netlify[.]app/
πŸ—£malwrhunterteam
#phishing

πŸŽ–@malwr
Introducing inject-assembly! Execute a .NET assembly in any existing process, including your current Beacon, and retrieve the output!
- Patches Environment.Exit()
- PE header stomping
- Random pipe name generation
- No blocking of the current Beacon
https://github.com/kyleavery/inject-assembly
πŸ—£kyleavery_


πŸŽ–@malwr
πŸ”₯2