Malware News
15.8K subscribers
1.64K photos
7 videos
130 files
8.1K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
luijait/DarkGPT: DarkGPT is an OSINT assistant based on GPT-4-200K (recommended use) designed to perform queries on leaked databases, thus providing an artificial intelligence assistant that can be useful in your traditional OSINT processes.

https://github.com/luijait/DarkGPT


πŸŽ–@malwr
Embed A Malicious Executable in a Normal PDF or EXE | by Sam Rothlisberger | Medium
Today we’re going to show how to create a malicious executable that looks like a PDF, word doc, or web browser executable with the functionality of the normal file/program, but also our embedded…

https://medium.com/@sam.rothlisberger/embed-a-malicious-executable-in-a-normal-pdf-or-exe-81ee5339707e


πŸŽ–@malwr
Nightmare: One Byte to ROP // Deep Dive Edition - HackMD
# Nightmare: One Byte to ROP // Deep Dive Edition ## Introduction In this write-up, we'll discuss ho

https://hackmd.io/@pepsipu/ry-SK44pt


πŸŽ–@malwr
Hunting for a Sliver in a haystack
Explore how the Sliver framework is used by threat actors for covert control and information gathering. Learn about detection methods and hunting tactics in this insightful post.

https://www.huntandhackett.com/blog/hunting-for-a-sliver


πŸŽ–@malwr

Debugging Stop 0x76 – PROCESS_HAS_LOCKED_PAGES | Machines Can Think

PROCESS_HAS_LOCKED_PAGES (76) Caused by a driver not cleaning up correctly after an I/O. Arguments: Arg1: 0000000000000000, Locked memory pages found in process being terminated. Arg2: fffffa800b1a4060, Process address. Arg3: 0000000000000004, Number of locked pages. Arg4: 0000000000000000, Pointer to driver stacks (if enabled) or 0 if not. Issue a !search over all of physical memory for…

https://bsodtutorials.wordpress.com/2024/04/10/debugging-stop-0x76-process_has_locked_pages/


πŸŽ–@malwr
❀1πŸ‘1
πŸ‘1
Android Remote Access Trojan Equipped to Harvest Credentials

Overview The SonicWall Capture Labs threat research team has been regularly sharing information about malware targeting Android devices. We’ve encountered similar RAT samples before, but this one includes extra commands and phishing attacks designed to

https://blog.sonicwall.com/en-us/2024/04/android-remote-access-trojan-equipped-to-harvest-credentials/


πŸŽ–@malwr
SideCopy: A Threat Actor targeting Indian Defense and Armed Forces Personnel for a Long Time

There have been several instances where Pakistani threat actors targeted the Indian Government and allied organizations for cyber espionage and other malicious activities. One such threat activity is the Operation SideCopy in which the threat actors had been specifically targeting Indian Defense and Army Forces personnel since 2019. These threat actors have been evolving continuously […]

https://hackhunting.com/2024/04/30/sidecopy-a-threat-actor-targeting-indian-defense-and-armed-forces-personnel-for-a-long-time/


πŸŽ–@malwr
(The) Postman Carries Lots of Secrets β—† Truffle Security Co.
Postman, the popular API testing platform, hosts the largest collection of public APIs. Unfortunately, it’s become one of the largest public sources of leaked secrets. We estimate over 4,000 live credentials are currently leaking publicly on Postman for a variety of popular SaaS and cloud providers.


https://trufflesecurity.com/blog/postman-carries-lots-of-secrets


πŸŽ–@malwr
Router Roulette: Cybercriminals and Nation-States Sharing Compromised Networks

This blog entry aims to highlight the dangers of internet-facing routers and elaborate on Pawn Storm's exploitation of EdgeRouters, complementing the FBI's advisory from February 27, 2024.

https://www.trendmicro.com/en_us/research/24/e/router-roulette.html


πŸŽ–@malwr
Docker Hub Hosted a Massive 3 Million Imageless Repositories for Phishing Campaigns

Docker Hub is a platform hosting docker images for applications and allows developers to develop, collaborate, and distribute docker images publicly. Investigations revealed millions of empty repositories, with 2.81 million used for malware campaigns. Threat actors used metadata to redirect users to deceptive websites. Users are advised to use "Trusted Content" docker repositories to avoid these attacks.

https://hackhunting.com/2024/05/01/docker-hub-hosted-a-massive-3-million-imageless-repositories-for-phishing-campaigns/


πŸŽ–@malwr