Malware News
12.7K subscribers
1.63K photos
7 videos
130 files
7.78K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
dnstop – Monitor and display DNS server traffic on your network https://www.cyberciti.biz/faq/dnstop-monitor-bind-dns-server-dns-network-traffic-from-a-shell-prompt/ #Linux #Unix #FreeBSD
πŸ—£nixcraft


πŸŽ–@malwr
EclecticIQ researchers have identified a spear phishing campaign targeting Ukrainian government entities including the Foreign Intelligence Service of Ukraine (SZRU) and Security Service of Ukraine (SSU), likely conducted by APT group Gamaredon. https://blog.eclecticiq.com/exposed-web-panel-reveals-gamaredon-groups-automated-spear-phishing-campaigns
πŸ—£virusbtn


πŸŽ–@malwr
VirusTotal's trompi summarises the latest activity of the APT43 group based on the telemetry of its malware toolset, including geographical distribution, lookups, submissions, file types, detection ratios & efficacy of crowd-sourced YARA rules. https://blog.virustotal.com/2023/04/apt43-investigation-into-north-korean.html
πŸ—£virusbtn


πŸŽ–@malwr
I have finished my write-up on reversing the Cobalt Strike implementations of indirect syscalls. With thanks to @0xDISREL for suggesting I look at it and supplying a beacon and to @DuchyRE for tips about unpacking and structures.

https://github.com/dodo-sec/Malware-Analysis/blob/main/Cobalt%20Strike/Indirect%20Syscalls.md
πŸ—£dodo_sec


πŸŽ–@malwr
#VMware released a security update to address a vulnerability in Tools. A remote attacker could likely exploit the vulnerability to take control of an affected system. More at http://cisa.gov/news-events/alerts/2023/04/21/vmware-releases-security-update-aria-operations-logs. #Cybersecurity #InfoSec
πŸ—£CISACyber


πŸŽ–@malwr
Introducing VirusTotal Code Insight: empowering threat analysis with generative AI. This tool is based on Sec-PaLM (LLM) and helps explaining behavior of suspicious scripts. Code Insight is available now for all our users! More details by @bquintero: https://blog.virustotal.com/2023/04/introducing-virustotal-code-insight.html
πŸ—£virustotal


πŸŽ–@malwr
The AhnLab ASEC team analyse a recent coin miner distributed to Linux SSH servers that are being improperly managed. https://asec.ahnlab.com/ko/51680/
πŸ—£virusbtn


πŸŽ–@malwr
#yaradbg v0.0.3 is out

1⃣ New yara editor: syntax highlighting, showing evaluation res inline, autocomplete, ...
2⃣ You can upload pass-protected zip containing malware directly (pass must be" infected")

Not sure who uses it but ping if you do, enjoy :)

https://yaradbg.dev/
πŸ—£DissectMalware


πŸŽ–@malwr
πŸ‘3
Trend Micro's Don Ovid Ladores analyses recent updates to information stealer ViperSoftX. The new campaign uses DLL sideloading for its arrival & execution technique, a more sophisticated encryption method of byte remapping, & a monthly change in C2 server https://www.trendmicro.com/en_us/research/23/d/vipersoftx-updates-encryption-steals-data.html
πŸ—£virusbtn


πŸŽ–@malwr
The latest podcast from Check Point looks into Operation Silent Watch: several human rights activists in Azerbaijan received the same phishing email that delivered them spyware capable of causing significant harm to their personal and professional lives. https://research.checkpoint.com/2023/operation-silent-watch/
πŸ—£virusbtn


πŸŽ–@malwr
Check Point researchers reveal new findings about Educated Manticore - an activity cluster with a strong overlap with Phosphorus - which has improved its toolset, utilizing rarely seen techniques such as .NET executables constructed as Mixed Mode Assembly. https://research.checkpoint.com/2023/educated-manticore-iran-aligned-threat-actor-targeting-israel-via-improved-arsenal-of-tools/
πŸ—£virusbtn


πŸŽ–@malwr
Offensive Security Checklists

API testing
Binary Exploitation testing
Firewall testing
Insecure deserialization
Web and OT pentest

and more.

https://github.com/CyberSecurityUP/Offensivesecurity-Checklists

#pentest #cybersecurity
πŸ—£cyb_detective


πŸŽ–@malwr