Malware News
12.7K subscribers
1.63K photos
7 videos
130 files
7.78K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
Offensive Security Checklists

API testing
Binary Exploitation testing
Firewall testing
Insecure deserialization
Web and OT pentest

and more.

https://github.com/CyberSecurityUP/Offensivesecurity-Checklists

#pentest #cybersecurity
πŸ—£cyb_detective


πŸŽ–@malwr
AhnLab researchers look into recent Tonto Team attack cases. The threat group targets mainly Asian countries and has been distributing Bisonal malware. https://asec.ahnlab.com/en/51746/
πŸ—£virusbtn


πŸŽ–@malwr
Jamf's Ferdous Saljooki (@malwarezoo) & Jaron Bradley (@jbradley89) write about the RustBucket malware used by the BlueNoroff APT group to target macOS users. https://www.jamf.com/blog/bluenoroff-apt-targets-macos-rustbucket-malware/
πŸ—£virusbtn


πŸŽ–@malwr
https://github.com/TheD1rkMtr/BlockOpenHandle
Block any Process to open HANDLE to your process , only SYTEM is allowed to open handle to your process ,with that you can avoid remote memory scanners
πŸ—£D1rkMtr


πŸŽ–@malwr
πŸ”₯1
A new #IDAPro Tutorial is out! This time we cover the Graph View. Watch it now 🌐 https://youtu.be/R1GKm-7WfCU

#IDAProTutorials #IDAPro #hexrays #LearningIDA
πŸ—£HexRaysSA


πŸŽ–@malwr
❀1
We've updated our Mobile Hacking cheatsheets!

https://github.com/randorisec/MobileHackingCheatSheet

#android #ios #cheatsheet #mobilesecurity #apps
πŸ—£RandoriSec


πŸŽ–@malwr
πŸ”₯1
ProcMon 3.93 supports configurable minifilter altitudes. This is great for teams that have to support minifilters! Thanks @markrussinovich!
πŸ—£GabrielLandau


πŸŽ–@malwr
Bitdefender's Martin Zugec shares recent insights about the tactics, techniques and procedures of the Charming Kitten group (APT35/APT42, Mint Sandstorm/PHOSPHORU), including unpacking a new piece of malware used by the group, named BellaCiao. https://www.bitdefender.com/blog/businessinsights/unpacking-bellaciao-a-closer-look-at-irans-latest-malware/
πŸ—£virusbtn


πŸŽ–@malwr
CloudSEK’s Threat Intelligence Research Team look into the details of the Daam Android malware distributed via trojanized applications. https://cloudsek.com/threatintelligence/copy-of-malware-intelligence-analysis-of-daam-android-malware
πŸ—£virusbtn


πŸŽ–@malwr
A Deep Dive into the Emotet Malware

Emotet is a trojan that is primarily spread through spam emails. During its lifecycle, it has gone through a few iterations. Early versions were delivered as a malicious JavaScript file.
https://www.fortinet.com/blog/threat-research/deep-dive-into-emotet-malware.html
πŸ—£InfosecMonk


πŸŽ–@malwr
πŸ”₯1
Elastic Security Labs' @DanielStepanic analyses the functionality and capabilities of LOBSHOT, an hVNC malware family spreading through Google Ads. https://www.elastic.co/security-labs/elastic-security-labs-discovers-lobshot-malware
πŸ—£virusbtn


πŸŽ–@malwr
Researchers from Palo Alto's Unit42 identified a new variant of the PingPull malware used by Alloy Taurus actors (aka GALLIUM, Softcell) & designed to target Linux systems. They also found Sword2033 backdoor samples linked to the same C2 infrastructure.
https://unit42.paloaltonetworks.com/alloy-taurus/
πŸ—£virusbtn


πŸŽ–@malwr
A keylogger/sniffer for the on-screen-keyboard? Sure, ETW is happy to help here with {4F768BE8-9C69-4BBC-87FC-95291D3F9D0C}😁
Enjoy the C source code, and the compiled exe, as usual - https://github.com/gtworek/PSBits/tree/master/ETW
πŸ—£0gtweet


πŸŽ–@malwr
NIST Cloud Computing Forensic Reference Architecture
Release Date: February 2023
Direct Download Link (PDF):
https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-201.ipd.pdf
For more unique resources and tools for the cyber community, please visit:
https://cyberstartupobservatory.com
#CyberSecurity #InfoSec #InformationSecurity
πŸ—£CyberSecOb


πŸŽ–@malwr