Malware News
12.7K subscribers
1.63K photos
7 videos
130 files
7.78K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
I really enjoyed these reverse engineering articles by Rick Osgood @rickoooooo that explain step by step how to achieve arbitrary code execution by radio ๐Ÿคฉ
#APRS #infosec #hacking

https://www.coalfire.com/the-coalfire-blog/hacking-ham-radio-winaprs-part1
๐Ÿ—ฃG4lile0


๐ŸŽ–@malwr
New polymorphic techniques pushed to Revenant.

Rev now uses the python build script to generate C code at build time, compile randomly different binaries, and combine runtime polymorphic patches to give better obfuscation

Check it out!
https://github.com/0xTriboulet/Revenant

@deadvolvo
๐Ÿ—ฃ0xTriboulet


๐ŸŽ–@malwr
๐Ÿ”ฅ1
Nice research by Maciej Domanski (@trailofbits) on cURL command line interface fuzzing and vulnerabilties

https://blog.trailofbits.com/2023/02/14/curl-audit-fuzzing-libcurl-command-line-interface/

#fuzzing
๐Ÿ—ฃ0xor0ne


๐ŸŽ–@malwr
MinHash-based Code Relationship & Investigation Toolkit (MCRIT), a framework created by the Cyber Analysis & Defense team from Fraunhofer FKIE institute to simplify the application of the MinHash algorithm in the context of code similarity.
https://github.com/fkie-cad/mcritweb
#Botconf2023
๐Ÿ—ฃRequiem_fr


๐ŸŽ–@malwr
๐Ÿ”ฅ2
Reverse Engineering Tofsee Spambot to find vaccine - Malware Lead @RaashidBhatt discloses two vaccines and a network-based kill switch. First up, it's part one, how to inject a malware vaccine into the binary file.๐Ÿ‘‡
https://hubs.ly/Q01LkdrX0

#MalwareVaccine #Spambot #Tofsee
๐Ÿ—ฃSpamhausTech


๐ŸŽ–@malwr
Check it out! WinDbg has just released out of preview, out of the Windows store and (what I worked on) with Time Travel Debugging support for ARM64. http://aka.ms/windbg
๐Ÿ—ฃTheJCAB


๐ŸŽ–@malwr
๐Ÿ‘1
Revizor automatically detects microarchitectural leakage in CPUs, speeding up discovery of vulnerabilities that previously required persistent hacking and painstaking manual labor. This new tool helps the industry protect customers from risk: https://msft.it/6013gHEGd
๐Ÿ—ฃMSFTResearch


๐ŸŽ–@malwr
Celebrating the 10th anniversary of releasing Noriben!

https://github.com/Rurik/Noriben

What started as a way to make filemon/regmon/procmon analysis easier for work mentoring has turned into an awesome automated tool I've used for large-scale ransomware analysis, and more.
๐Ÿ—ฃbbaskin


๐ŸŽ–@malwr
IOCs available...

Threat actors strive to cause Tax Day headaches https://rodtrent.com/j7j

#MicrosoftSentinel #MicrosoftDefender #M365D #Cybersecurity #MicrosoftSecurity #Security #MicrosoftThreatIntelligence
๐Ÿ—ฃrodtrent


๐ŸŽ–@malwr
๐Ÿ˜1
โœ…โœ…โœ… Forward posts to the other groups โœ…โœ…โœ…
Malware News pinned ยซโœ…โœ…โœ… Forward posts to the other groups โœ…โœ…โœ…ยป