Malware News
15.7K subscribers
1.64K photos
7 videos
130 files
8.08K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
Blog: Detecting Karakurt – an extortion focused threat actor by NCC Group's Cyber Incident Response Team members - Simon Biggs, Richard Footman and Michael Mullen -
https://research.nccgroup.com/2022/02/17/detecting-karakurt-an-extortion-focused-threat-actor/ #Karakurt
πŸ—£NCCGroupInfosec


πŸŽ–@malwr
Added 2 PoCs for HackSys Extreme Vulnerable Driver to KernelWritePoCs.
One tries to get SYSTEM with SeCreateTokenPrivilege.
The other tries to get SYSTEM by secondary logon feature with SeCreateTokenPrivilege and SeImpersonatePrivilege.

https://github.com/daem0nc0re/PrivFu#KernelWritePoCs
πŸ—£daem0nc0re


πŸŽ–@malwr
Faking a positive COVID Test : https://labs.f-secure.com/blog/faking-a-positive-covid-test credits @Yogehi
πŸ—£binitamshah


πŸŽ–@malwr
My #BinaryNinja plugin obfuscation_detection can now identify uncommon instruction sequences (such as MBAs or weird calculations) based on stochastic n-gram analysis. Right now the feature works for x86-64; an architecture-agnostic version follows soon.

https://github.com/mrphrazer/obfuscation_detection/
πŸ—£mr_phrazer


πŸŽ–@malwr
malware-and-exploitdev-resources : It serves as a list of resources, and other things that aid in malware analysis / dev and exploit dev
https://github.com/evilbuffer/malware-and-exploitdev-resources
πŸ—£binitamshah


πŸŽ–@malwr
πŸ‘1
curl-impersonate : A special compilation of curl that makes it impersonate Chrome & Firefox : https://github.com/lwthiker/curl-impersonate

Making curl impersonate Firefox : https://lwthiker.com/reversing/2022/02/17/curl-impersonate-firefox.html

Impersonating Chrome, too : https://lwthiker.com/reversing/2022/02/20/impersonating-chrome-too.html
πŸ—£binitamshah


πŸŽ–@malwr
Make a USB Rubber Ducky with less than $3

'The best thing is, USB Rubber Ducky is not detected as a flash drive, but as a keyboard.'

#infosec #redteam #pentest

https://infosecwriteups.com/make-usb-rubber-ducky-with-less-than-3-fa72dac9e4de
πŸ—£CyberWarship


πŸŽ–@malwr
#Emotet strikes with new TTPs 🚨

Project X elevated to Project Y

#DFIR analysis report covers the new infection flow:

Initial Access
Execution
Privilege Escalation
Persistence
Defense Evasion
https://www.cynet.com/attack-techniques-hands-on/new-wave-of-emotet-when-project-x-turns-into-y/
πŸ—£Max_Mal_


πŸŽ–@malwr