Malware News
12.7K subscribers
1.63K photos
7 videos
130 files
7.78K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
CTI researcher @BushidoToken looks at a financially motivated Kenyan threat actor. GreenMwizi set up 12 fake Booking[.]com Twitter accounts targeting users who make public complaints, the aim being to socially engineer them into sending funds via Remitly. https://blog.bushidotoken.net/2023/05/greenmwizi-kenyan-scamming-campaign.html
๐Ÿ—ฃvirusbtn


๐ŸŽ–@malwr
ESET has released its Q4 2022 ยญ- Q1 2023 APT Activity Report, which summarizes the activities of selected advanced persistent threat (APT) groups that were observed, investigated & analysed by ESET's researchers during that period. https://www.welivesecurity.com/2023/05/09/eset-apt-activity-report-q42022-q12023/
๐Ÿ—ฃvirusbtn


๐ŸŽ–@malwr
As a #Reverse #Engineering enthusiast, I recently wrote a configuration extractor using Python to decrypt data encrypted by Qbot malware. With this code, I can easily extract the strings from the decrypted data and analyze the malware's configuration

https://github.com/FarghlyMal/QBotConfig-Extractor/blob/main/Config%20Extractor.py
๐Ÿ—ฃFarghlyMal


๐ŸŽ–@malwr
โค1
Funny shit you find when hex editing a camera firmware file :
๐Ÿ—ฃalexbloor


๐ŸŽ–@malwr
โค1๐Ÿ˜1
McAfee's Anandeshwar Unnikrishnan analyses recent GULoader campaigns in which NSIS-based installers, delivered via email as malspam, use plugin libraries to execute the GU shellcode on the victim system. https://www.mcafee.com/blogs/other-blogs/mcafee-labs/guloader-campaigns-a-deep-dive-analysis-of-a-highly-evasive-shellcode-based-loader/
๐Ÿ—ฃvirusbtn


๐ŸŽ–@malwr