Malware News
12.7K subscribers
1.63K photos
7 videos
130 files
7.78K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
As promised earlier today, here is my writeup about a recent #Gozi campaign that was targeting the ๐Ÿ‡ฎ๐Ÿ‡น audience.

Covering geofence payloads handle, jscript.encode script, shellcodes analysis, APC Injection and much more!

Have fun :)

https://0xtoxin-labs.gitbook.io/malware-analysis/malware-analysis/gozi-italian-shellcode-dance
๐Ÿ—ฃ0xToxin


๐ŸŽ–@malwr
Nice blog post on using Qiling framework for automatically unpack ELF executables

https://kernemporium.github.io/posts/unpacking/

#qiling #infosec #reverseengineering #learning
๐Ÿ—ฃ0xor0ne


๐ŸŽ–@malwr
โค1๐Ÿ‘1
Weโ€™ve just published a short #IDAPro tutorial about the #Disassembly window. Watch it now ๐ŸŒ https://youtu.be/cgELfAUg8C4

#IDAProTutorials #IDAPro #hexrays #LearningIDA
๐Ÿ—ฃHexRaysSA


๐ŸŽ–@malwr
Android Attack: Reversing React Native Applications
https://securityqueens.co.uk/android-attack-reversing-react-native-applications/
๐Ÿ—ฃpentest_swissky


๐ŸŽ–@malwr
Happy to announce the release of my JADX dynamic scripting plugin, JADXecute. Now you write and share scripts to automate your Android APK analysis! #ReverseEngineering

https://github.com/LaurieWired/JADXecute
๐Ÿ—ฃlauriewired


๐ŸŽ–@malwr
Here's a short blog on using Frida to write and bypass detections for your TTPs. We can use good ol' userland hooking + JavaScript bindings to avoid writing complex kernel code, which lets us quickly develop test cases and improve our techniques.

https://passthehashbrowns.github.io/using-frida-for-rapid-detection-testing
๐Ÿ—ฃpassthehashbrwn


๐ŸŽ–@malwr
Icicle is a multi architecture emulation framework designed for firmware fuzzing.
Very interesting research work

Paper: https://arxiv.org/pdf/2301.13346.pdf
github repo (pre-release): https://github.com/icicle-emu/icicle

#fuzzing #firmware #infosec #cybersecurity
๐Ÿ—ฃ0xor0ne


๐ŸŽ–@malwr
โค1
How to Create a Virtual Hacking Lab: The Ultimate Hacker Setup
๐Ÿ—ฃflacao9

Nice article and how I did my approach to learning. Gotta love VirtualBox.

Another approach too for specific service testing is creating a vuln testbed service using docker. It's a lot lighter than a full VM.
๐Ÿ‘คFolsgaardSE

This is all manual work, which is fine, but you could use the Red Team Attack Lab or the game of thrones lab
๐Ÿ‘คProud-Tap6586


๐ŸŽ–@malwr
New YouTube channel with IDAPython tutorial series [wip](https://www.youtube.com/@allthingsida)
๐Ÿ—ฃ0xeb


๐ŸŽ–@malwr
๐Ÿ‘2
ZeusCloud - an open-source cloud security platform
Sharing something we're in the early innings of developing: https://github.com/Zeus-Labs/ZeusCloud

Have heard from many devops friends that they often get charged w/ managing security. Hope to get your feedback on if this would be helpful!

ZeusCloud is an open-source cloud security platform that thinks like an attacker! ZeusCloud works by:

1. Identifying risks across your cloud environments (e.g. misconfigurations, identity weakness, vulnerabilities, etc.)
2. Prioritizing those risks based on toxic risk combinations an attacker may exploit.
3. Remediating by giving step by step instructions on how to fix the risk findings.
4. Monitoring compliance - track your PCI DSS, SOC 2, GDPR, CIS goals.

So far, weโ€™ve added misconfiguration checks and common identity-based attack paths for AWS. Up next on our roadmap are network/access graph visualizations of your entire cloud environment, vulnerability scanning, and secret scanning!

Check out our GitHub (Licensed Apache 2.0): https://github.com/Zeus-Labs/ZeusCloud

Play around with our Sandbox environment: https://demo.zeuscloud.io

Get Started (free/self-hosted): https://docs.zeuscloud.io/introduction/get-started
๐Ÿ—ฃVariousAd5147

This looks very cool! Is there a way to add exclusions to rules?
๐Ÿ‘คthescrambler1979

This is quite interesting. I've had something a bit similar in mind but instead I will take a better look and check if I could just contribute here.
๐Ÿ‘คpuputtiap

This product is similar to Selefra, https://github.com/selefra/selefra
๐Ÿ‘คDisastrous_Pie7425


๐ŸŽ–@malwr