Malware News
12.7K subscribers
1.63K photos
7 videos
130 files
7.78K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
Introducing VirusTotal Code Insight: empowering threat analysis with generative AI. This tool is based on Sec-PaLM (LLM) and helps explaining behavior of suspicious scripts. Code Insight is available now for all our users! More details by @bquintero: https://blog.virustotal.com/2023/04/introducing-virustotal-code-insight.html
πŸ—£virustotal


πŸŽ–@malwr
The AhnLab ASEC team analyse a recent coin miner distributed to Linux SSH servers that are being improperly managed. https://asec.ahnlab.com/ko/51680/
πŸ—£virusbtn


πŸŽ–@malwr
#yaradbg v0.0.3 is out

1⃣ New yara editor: syntax highlighting, showing evaluation res inline, autocomplete, ...
2⃣ You can upload pass-protected zip containing malware directly (pass must be" infected")

Not sure who uses it but ping if you do, enjoy :)

https://yaradbg.dev/
πŸ—£DissectMalware


πŸŽ–@malwr
πŸ‘3
Trend Micro's Don Ovid Ladores analyses recent updates to information stealer ViperSoftX. The new campaign uses DLL sideloading for its arrival & execution technique, a more sophisticated encryption method of byte remapping, & a monthly change in C2 server https://www.trendmicro.com/en_us/research/23/d/vipersoftx-updates-encryption-steals-data.html
πŸ—£virusbtn


πŸŽ–@malwr
The latest podcast from Check Point looks into Operation Silent Watch: several human rights activists in Azerbaijan received the same phishing email that delivered them spyware capable of causing significant harm to their personal and professional lives. https://research.checkpoint.com/2023/operation-silent-watch/
πŸ—£virusbtn


πŸŽ–@malwr
Check Point researchers reveal new findings about Educated Manticore - an activity cluster with a strong overlap with Phosphorus - which has improved its toolset, utilizing rarely seen techniques such as .NET executables constructed as Mixed Mode Assembly. https://research.checkpoint.com/2023/educated-manticore-iran-aligned-threat-actor-targeting-israel-via-improved-arsenal-of-tools/
πŸ—£virusbtn


πŸŽ–@malwr
Offensive Security Checklists

API testing
Binary Exploitation testing
Firewall testing
Insecure deserialization
Web and OT pentest

and more.

https://github.com/CyberSecurityUP/Offensivesecurity-Checklists

#pentest #cybersecurity
πŸ—£cyb_detective


πŸŽ–@malwr
AhnLab researchers look into recent Tonto Team attack cases. The threat group targets mainly Asian countries and has been distributing Bisonal malware. https://asec.ahnlab.com/en/51746/
πŸ—£virusbtn


πŸŽ–@malwr
Jamf's Ferdous Saljooki (@malwarezoo) & Jaron Bradley (@jbradley89) write about the RustBucket malware used by the BlueNoroff APT group to target macOS users. https://www.jamf.com/blog/bluenoroff-apt-targets-macos-rustbucket-malware/
πŸ—£virusbtn


πŸŽ–@malwr
https://github.com/TheD1rkMtr/BlockOpenHandle
Block any Process to open HANDLE to your process , only SYTEM is allowed to open handle to your process ,with that you can avoid remote memory scanners
πŸ—£D1rkMtr


πŸŽ–@malwr
πŸ”₯1
A new #IDAPro Tutorial is out! This time we cover the Graph View. Watch it now 🌐 https://youtu.be/R1GKm-7WfCU

#IDAProTutorials #IDAPro #hexrays #LearningIDA
πŸ—£HexRaysSA


πŸŽ–@malwr
❀1
We've updated our Mobile Hacking cheatsheets!

https://github.com/randorisec/MobileHackingCheatSheet

#android #ios #cheatsheet #mobilesecurity #apps
πŸ—£RandoriSec


πŸŽ–@malwr
πŸ”₯1
ProcMon 3.93 supports configurable minifilter altitudes. This is great for teams that have to support minifilters! Thanks @markrussinovich!
πŸ—£GabrielLandau


πŸŽ–@malwr