Malware News
15.8K subscribers
1.64K photos
7 videos
130 files
8.1K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
Blog post #3

In this blog, I cover the basics of the translation process of a virtual memory address into physical memory address as well as the PTE structure and usage of another WinAPI function with examples.

https://de-engineer.github.io/Virtual-Address-Translation-and-structure-of-PTE

#infosec
πŸ—£coder_rc


πŸŽ–@malwr
πŸ‘1
Updated my ScheduleRunner to include the "hiding scheduled task" technique used by Tarrask malware. This technique can literally make your scheduled task invisible from query tools and Task Scheduler.
https://github.com/netero1010/ScheduleRunner
πŸ—£netero_1010


πŸŽ–@malwr
This repository contains a Red team Offensive Security Exploitation Tool
which uses TOR and OnionShare as long with Meterpreter Session.

https://github.com/ToxicEnvelope/SetmPloit

ℹ️ Sent from one of our channel members

πŸŽ–@malwr
πŸ‘1
New Blog! Lessons from the Conti Leaks

https://blog.bushidotoken.net/2022/04/lessons-from-conti-leaks.html
πŸ—£BushidoToken


πŸŽ–@malwr
πŸ‘1
New Trend Micro data shows that Purple Fox operators are using trojanized software packages to trick users into downloading their payloads.

Read about #PurpleFox’s infection chain and learn about its new campaign here: https://research.trendmicro.com/36x6pPz
πŸ—£TrendMicroRSRCH


πŸŽ–@malwr
πŸ‘1
Sysmon's RegistryEvent (Value Set) https://i5c.us/d28558
πŸ—£sans_isc


πŸŽ–@malwr
The FBI, CISA & US Treasury Department have released a joint advisory to highlight the threat associated with cryptocurrency thefts & tactics used by a North Korean state-sponsored APT group (Lazarus/APT38/BlueNoroff/Stardust Chollima) since at least 2020 https://www.cisa.gov/uscert/ncas/alerts/aa22-108a
πŸ—£virusbtn


πŸŽ–@malwr
Emotet Loader Technical Analysis
https://nikpx.github.io/malware/analysis/2022/04/19/Emotet_Loader.html
πŸ—£xorsthingsv2


πŸŽ–@malwr
Wtf another RAT was released on GitHub.

58d577e0a9e182dc2fedede09dfb586cf62fb56cc36e2e5fecf4280d2395abfb

https://github.com/arsium/EagleMonitorRAT

malwrhunterteam probably skiddies will roll from LimeRAT to this shit?
πŸ—£fr0s7_


πŸŽ–@malwr
πŸ₯³πŸ₯³πŸ₯³BinAbsInspector (Binary Abstract Inspector)is a static analyzer for automated reverse engineering and scanning vulnerabilities in binaries, which is a long-term research project incubated at Keenlab.
https://github.com/KeenSecurityLab/BinAbsInspector
πŸ—£keen_lab


πŸŽ–@malwr
jadx 1.3.5 got this cool split view now so you can view multiple decompilations at once!

https://github.com/skylot/jadx/releases/tag/v1.3.5
πŸ—£leonjza


πŸŽ–@malwr
🀩2πŸ‘1πŸŽ‰1
You can plant an undetectable backdoor in any deep learning model
https://arxiv.org/abs/2204.06974
πŸ—£neuroecology


πŸŽ–@malwr
Video recordings from OffensiveCon 2022 are now online: https://www.youtube.com/c/OffensiveCon/videos
πŸ—£xorlgr


πŸŽ–@malwr
It took only 4 hours from initial access to domain-wide ransomware. "The payload was delivered within an ISO file; Containing two files, .dll and .lnk files, etc" So much to learn in this report with addition of diamond model info TheDFIRReport #dfir

https://thedfirreport.com/2022/04/25/quantum-ransomware/
πŸ—£r3nzsec


πŸŽ–@malwr