Malware News
13K subscribers
1.63K photos
7 videos
130 files
7.78K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
This media is not supported in your browser
VIEW IN TELEGRAM
❀5
.NET Malware 101: Analyzing the .NET Executable File Structure

Welcome to our deep dive into the world of .NET malware reverse engineering. As a security researcher or analyst, you’re likely aware that the .NET framework, famed for its ability to enable rapid and robust application development, is a double-edged sword. The same features that make it attractive to legitimate developers also make it a...

https://intezer.com/blog/incident-response/intro-to-malware-net-executable-file/


πŸŽ–@malwr
❀1
CVE-2024-21412: DarkGate Operators Exploit Microsoft Windows SmartScreen Bypass in Zero-Day Campaign

In addition to our Water Hydra APT zero day analysis, the Zero Day Initiative (ZDI) observed a DarkGate campaign which we discovered in mid-January 2024 where DarkGate operators exploited CVE-2024-21412.

https://www.trendmicro.com/en_us/research/24/c/cve-2024-21412--darkgate-operators-exploit-microsoft-windows-sma.html


πŸŽ–@malwr
πŸ‘1
Threat actors leverage document publishing sites for ongoing credential and session token theft

Talos IR has responded to several recent incidents in which threat actors used legitimate digital document publishing sites such as Publuu and Marq to host phishing documents as part of ongoing credential and session harvesting attacks.

https://blog.talosintelligence.com/threat-actors-leveraging-document-publishing-sites/


πŸŽ–@malwr
The Anatomy of an ALPHA SPIDER Ransomware Attack

ALPHA SPIDER is the adversary behind the development and operation of the Alphv ransomware as a service (RaaS). Over the last year, ALPHA SPIDER affiliates have been leveraging a variety of novel techniques as part of their ransomware operations. CrowdStrike Services has observed techniques such as the usage of NTFS Alternate Data Streams for hiding...

https://www.crowdstrike.com/blog/anatomy-of-alpha-spider-ransomware/


πŸŽ–@malwr
πŸ‘2
2024-03-06: Pikabot infection leads to Meduza Stealer

https://www.malware-traffic-analysis.net/2024/03/06/index.html


πŸŽ–@malwr
2024-03-14: AsyncRAT and XWorm infection

https://www.malware-traffic-analysis.net/2024/03/14/index.html


πŸŽ–@malwr
The LockBit story: Why the ransomware affiliate model can turn takedowns into disruptions

Talos explores the recent law enforcement takedown of LockBit, a prolific ransomware group that claimed to resume their operations 7 days later.

https://blog.talosintelligence.com/ransomware-affiliate-model/


πŸŽ–@malwr
πŸ‘1
Hello everybody. I'm sorry for inconvenience. To keep our channel up, I have to pay for server and services. For that, we need financial support. If channel members could kindly donate in BTC, I will not post any ads in the channel.

Sincerely,
@SirMalware


πŸŽ–@malwr
πŸ‘7
Healthcare still a prime target for cybercrime gangs – Week in security with Tony Anscombe

Healthcare organizations remain firmly in attackers' crosshairs, representing 20 percent of all victims of ransomware attacks among critical infrastructure entities in the US in 2023

https://www.welivesecurity.com/en/videos/healthcare-target-cybercrime-week-security-tony-anscombe/


πŸŽ–@malwr
Earth Krahang Exploits Intergovernmental Trust to Launch Cross-Government Attacks

Since early 2022, we have been monitoring an APT campaign that targets several government entities worldwide, with a strong focus in Southeast Asia, but also seen targeting Europe, America, and Africa.

https://www.trendmicro.com/en_us/research/24/c/earth-krahang.html


πŸŽ–@malwr