Malware News
15.8K subscribers
1.64K photos
7 videos
130 files
8.1K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
Fake Windows Explorer Installs a Crypto Miner

Overview This week the SonicWall Capture Labs threat research team came across a sample purporting to be Windows Explorer. At a glance, everything checks out – it uses the legitimate Windows Explorer icon and the

https://blog.sonicwall.com/en-us/2024/04/fake-windows-explorer-installs-a-crypto-miner/


🎖@malwr
CrushFTP Server-Side Template Injection (SSTI)

Overview SonicWall Capture Labs threat research team became aware of a fully unauthenticated server-side template injection vulnerability within CrushFTP, assessed its impact, and developed mitigation measures. CrushFTP is an enterprise file transfer tool. Such tools

https://blog.sonicwall.com/en-us/2024/05/crushftp-server-side-template-injection-ssti/


🎖@malwr
FIN7 Abusing Malicious MSIX Packages To Deliver NetSupport RAT | by rewscel | May, 2024 | Medium
A quick introduction to the group: FIN7 is a Russian advanced persistent threat (APT) group with financial motive. The criminal group has several techniques they utilize for initial access, but in…

https://rewscel.medium.com/fin7-abusing-malicious-msix-packages-to-deliver-netsupport-rat-09962fdf33ef


🎖@malwr
It’s Morphin’ Time: Self-Modifying Code Sections with WriteProcessMemory for EDR Evasion | by Thiago Peixoto | Apr, 2024 | Medium
An EDR can identify malicious activity within a process through mechanisms such as kernel callbacks and userland hooks on commonly used Windows API functions exploited by malware. In the case of…

https://revflash.medium.com/its-morphin-time-self-modifying-code-sections-with-writeprocessmemory-for-edr-evasion-9bf9e7b7dced


🎖@malwr
🔥1
New “Goldoon” Botnet Targeting D-Link Devices | FortiGuard Labs
FortiGuard Labs discovered the new botnet “Goldoon” targeting D-Link devices through related vulnerability CVE-2015-2051. Learn more.


https://www.fortinet.com/blog/threat-research/new-goldoon-botnet-targeting-d-link-devices


🎖@malwr
1
TargetCompany Ransomware Group Installs Mallox Ransomware on Vulnerable MS-SQL Servers

The TargetCompany ransomware group was discovered in June 2021, targeting improperly managed MS-SQL servers with malware variants such as Mallox ransomware. Using brute force and dictionary attacks, threat actors install Remocs RAT and remote screen control malware. The final stage involves installing Mallox ransomware, impacting file encryption and system functions. ASEC researchers have published a comprehensive report. Mitigation involves upgrading servers and enhancing password security. Indicators of Compromise are provided.

https://hackhunting.com/2024/05/03/targetcompany-ransomware-group-installs-mallox-ransomware-on-vulnerable-ms-sql-servers/


🎖@malwr
Flutter Windows Thick Client SSL Pinning Bypass | by Sourav Kalal | May, 2024 | Medium
Learn to bypass SSL Pinning in Flutter Windows Thick Client Application using Frida and Reverse Engineering. Also, find ouhow to configure Flutter for proxy.

https://blog.souravkalal.tech/flutter-windows-thick-client-ssl-pinning-bypass-492389ae1218


🎖@malwr
“Dirty Stream” Attack : Android Apps with 4 Billion Installations are Affected

Mobile devices, especially Android, are targeted by hackers due to security vulnerabilities. Researchers at Microsoft discovered a Path Traversal attack that allows threat actors to overwrite files and execute arbitrary code in popular Android apps, like Xiaomi's File Manager. Developers should follow security guidelines and use Android Lint to avoid such vulnerabilities.

https://hackhunting.com/2024/05/04/dirty-stream-attack-android-apps-with-4-billion-installations-are-affected/


🎖@malwr
Custom Shellcode Creation in x64 | s4dbrd’s blog
Investigating custom shellcode creation on x64 Windows architectures, also understanding the calling convention in order to obtain a reverse shell

https://s4dbrd.com/shellcode-creation-in-x64/


🎖@malwr
👍1🔥1
URB Excalibur: Virtual USB Controller Attack leading to Virtual Machine Escape in all VMware Platforms

At Black Hat Asia 2024, researchers unveiled "URB Excalibur," a Virtual Machine Escape vulnerability affecting VMware. The vulnerability, assigned CVE-2022-31705, allows for control over the hypervisor and potential network escape. Exploitation techniques and control of the Routing Information Protocol were demonstrated, exposing critical security risks. Various USB controller vulnerabilities were also highlighted.

https://hackhunting.com/2024/05/05/urb-excalibur-virtual-usb-controller-attack-leading-to-virtual-machine-escape-in-all-vmware-platforms/


🎖@malwr
👍3
Hackers Distribute RokRAT LNK Files Pretending as a Certificate

A new campaign distributing RokRAT malware targets South Korean and North Korean-related users. LNK files with legitimate names contain PowerShell commands, malicious PE data, and script codes. The malware acts as a backdoor, using cloud APIs to collect and send user information to attacker-controlled cloud servers hosted in pCloud, Yandex, and Dropbox. Numerous malicious activities and potential threat actor email addresses have been uncovered. Users in South Korea are advised to exercise caution, and further details are available in a report by ASEC researchers. Indicators of compromise include file detections and specific hashes.

https://hackhunting.com/2024/05/07/hackers-distribute-rokrat-lnk-files-pretending-as-a-certificate/


🎖@malwr
Formbook Malware Analysis – CyberForensics
In the ever-evolving world, the art of forging genuine connections remains timeless. Whether it’s with colleagues, clients, or partners, establishing a genuine rapport paves the way for collaborative success.

https://cyber-forensics.blog/2024/05/06/formbook-analysis/


🎖@malwr
👍1