Malware News
15.8K subscribers
1.64K photos
7 videos
130 files
8.1K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
GitLab XSS Via Autocomplete Results

Overview The SonicWall Capture Labs threat research team became aware of a cross-site scripting vulnerability in GitLab, assessed its impact and developed mitigation measures. GitLab, an open-source code-sharing platform, published an advisory on this vulnerability

https://blog.sonicwall.com/en-us/2024/04/gitlab-xss-via-autocomplete-results/


🎖@malwr
Brokewell – Unknown Malware family Discovered to target Banking Applications

Brokewell is a new mobile malware targeting the banking industry. It includes a dropper with Android 13+ bypass capability. Victims are lured through phishing pages posing as browser updates. The malware can steal data, control devices remotely, and has specific commands for actions. The threat actor, identified as "Baron Samedit," also developed a bypass tool. Threat Fabric has published a comprehensive report on this malware.

https://hackhunting.com/2024/04/26/brokewell-unknown-malware-family-discovered-to-target-banking-applications/


🎖@malwr
Zombieware: Malware That Never Dies...
Self-replicating malware, long abandoned by its operators, continues to contribute significant volume and noise to malware feeds. We investigate this trend, which we refer to as Zombieware.

https://blog.unpac.me/2024/04/25/zombieware/


🎖@malwr
luijait/DarkGPT: DarkGPT is an OSINT assistant based on GPT-4-200K (recommended use) designed to perform queries on leaked databases, thus providing an artificial intelligence assistant that can be useful in your traditional OSINT processes.

https://github.com/luijait/DarkGPT


🎖@malwr
Embed A Malicious Executable in a Normal PDF or EXE | by Sam Rothlisberger | Medium
Today we’re going to show how to create a malicious executable that looks like a PDF, word doc, or web browser executable with the functionality of the normal file/program, but also our embedded…

https://medium.com/@sam.rothlisberger/embed-a-malicious-executable-in-a-normal-pdf-or-exe-81ee5339707e


🎖@malwr
Nightmare: One Byte to ROP // Deep Dive Edition - HackMD
# Nightmare: One Byte to ROP // Deep Dive Edition ## Introduction In this write-up, we'll discuss ho

https://hackmd.io/@pepsipu/ry-SK44pt


🎖@malwr
Hunting for a Sliver in a haystack
Explore how the Sliver framework is used by threat actors for covert control and information gathering. Learn about detection methods and hunting tactics in this insightful post.

https://www.huntandhackett.com/blog/hunting-for-a-sliver


🎖@malwr

Debugging Stop 0x76 – PROCESS_HAS_LOCKED_PAGES | Machines Can Think

PROCESS_HAS_LOCKED_PAGES (76) Caused by a driver not cleaning up correctly after an I/O. Arguments: Arg1: 0000000000000000, Locked memory pages found in process being terminated. Arg2: fffffa800b1a4060, Process address. Arg3: 0000000000000004, Number of locked pages. Arg4: 0000000000000000, Pointer to driver stacks (if enabled) or 0 if not. Issue a !search over all of physical memory for…

https://bsodtutorials.wordpress.com/2024/04/10/debugging-stop-0x76-process_has_locked_pages/


🎖@malwr
1👍1
👍1