Malware News
15.8K subscribers
1.64K photos
7 videos
130 files
8.1K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
Hunting for a Sliver in a haystack
Explore how the Sliver framework is used by threat actors for covert control and information gathering. Learn about detection methods and hunting tactics in this insightful post.

https://www.huntandhackett.com/blog/hunting-for-a-sliver


🎖@malwr

Debugging Stop 0x76 – PROCESS_HAS_LOCKED_PAGES | Machines Can Think

PROCESS_HAS_LOCKED_PAGES (76) Caused by a driver not cleaning up correctly after an I/O. Arguments: Arg1: 0000000000000000, Locked memory pages found in process being terminated. Arg2: fffffa800b1a4060, Process address. Arg3: 0000000000000004, Number of locked pages. Arg4: 0000000000000000, Pointer to driver stacks (if enabled) or 0 if not. Issue a !search over all of physical memory for…

https://bsodtutorials.wordpress.com/2024/04/10/debugging-stop-0x76-process_has_locked_pages/


🎖@malwr
1👍1
👍1
Android Remote Access Trojan Equipped to Harvest Credentials

Overview The SonicWall Capture Labs threat research team has been regularly sharing information about malware targeting Android devices. We’ve encountered similar RAT samples before, but this one includes extra commands and phishing attacks designed to

https://blog.sonicwall.com/en-us/2024/04/android-remote-access-trojan-equipped-to-harvest-credentials/


🎖@malwr
SideCopy: A Threat Actor targeting Indian Defense and Armed Forces Personnel for a Long Time

There have been several instances where Pakistani threat actors targeted the Indian Government and allied organizations for cyber espionage and other malicious activities. One such threat activity is the Operation SideCopy in which the threat actors had been specifically targeting Indian Defense and Army Forces personnel since 2019. These threat actors have been evolving continuously […]

https://hackhunting.com/2024/04/30/sidecopy-a-threat-actor-targeting-indian-defense-and-armed-forces-personnel-for-a-long-time/


🎖@malwr
(The) Postman Carries Lots of Secrets ◆ Truffle Security Co.
Postman, the popular API testing platform, hosts the largest collection of public APIs. Unfortunately, it’s become one of the largest public sources of leaked secrets. We estimate over 4,000 live credentials are currently leaking publicly on Postman for a variety of popular SaaS and cloud providers.


https://trufflesecurity.com/blog/postman-carries-lots-of-secrets


🎖@malwr
Router Roulette: Cybercriminals and Nation-States Sharing Compromised Networks

This blog entry aims to highlight the dangers of internet-facing routers and elaborate on Pawn Storm's exploitation of EdgeRouters, complementing the FBI's advisory from February 27, 2024.

https://www.trendmicro.com/en_us/research/24/e/router-roulette.html


🎖@malwr
Docker Hub Hosted a Massive 3 Million Imageless Repositories for Phishing Campaigns

Docker Hub is a platform hosting docker images for applications and allows developers to develop, collaborate, and distribute docker images publicly. Investigations revealed millions of empty repositories, with 2.81 million used for malware campaigns. Threat actors used metadata to redirect users to deceptive websites. Users are advised to use "Trusted Content" docker repositories to avoid these attacks.

https://hackhunting.com/2024/05/01/docker-hub-hosted-a-massive-3-million-imageless-repositories-for-phishing-campaigns/


🎖@malwr
Fake Windows Explorer Installs a Crypto Miner

Overview This week the SonicWall Capture Labs threat research team came across a sample purporting to be Windows Explorer. At a glance, everything checks out – it uses the legitimate Windows Explorer icon and the

https://blog.sonicwall.com/en-us/2024/04/fake-windows-explorer-installs-a-crypto-miner/


🎖@malwr
CrushFTP Server-Side Template Injection (SSTI)

Overview SonicWall Capture Labs threat research team became aware of a fully unauthenticated server-side template injection vulnerability within CrushFTP, assessed its impact, and developed mitigation measures. CrushFTP is an enterprise file transfer tool. Such tools

https://blog.sonicwall.com/en-us/2024/05/crushftp-server-side-template-injection-ssti/


🎖@malwr
FIN7 Abusing Malicious MSIX Packages To Deliver NetSupport RAT | by rewscel | May, 2024 | Medium
A quick introduction to the group: FIN7 is a Russian advanced persistent threat (APT) group with financial motive. The criminal group has several techniques they utilize for initial access, but in…

https://rewscel.medium.com/fin7-abusing-malicious-msix-packages-to-deliver-netsupport-rat-09962fdf33ef


🎖@malwr
It’s Morphin’ Time: Self-Modifying Code Sections with WriteProcessMemory for EDR Evasion | by Thiago Peixoto | Apr, 2024 | Medium
An EDR can identify malicious activity within a process through mechanisms such as kernel callbacks and userland hooks on commonly used Windows API functions exploited by malware. In the case of…

https://revflash.medium.com/its-morphin-time-self-modifying-code-sections-with-writeprocessmemory-for-edr-evasion-9bf9e7b7dced


🎖@malwr
🔥1