Malware News
15.8K subscribers
1.64K photos
7 videos
130 files
8.1K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
Dissecting REMCOS RAT: An in-depth analysis of a widespread 2024 malware, Part Three — Elastic Security Labs
In previous articles in this multipart series, malware researchers on the Elastic Security Labs team dove into the REMCOS execution flow. In this article, you’ll learn more about REMCOS configuration structure and its C2 commands.

https://www.elastic.co/security-labs/dissecting-remcos-rat-part-three


🎖@malwr
JavaScript Debugging with Maglev Compiler | by VXRL | Medium
Other than fuzzing for vulnerabilities of our previous blogpost, it would be good to understand how Maglev compiler works via debugging. In the following article, we are going to briefly introduce…

https://vxrl.medium.com/javascript-debugging-with-maglev-compiler-6b2a26cb1a3a


🎖@malwr
CrowdStrike Enhances Cloud Asset Visualization to Accelerate Risk Prioritization

The massive increase in cloud adoption has driven adversaries to focus their efforts on cloud environments — a shift that led to cloud intrusions increasing by 75% in 2023, emphasizing the need for stronger cloud security. Larger scale leads to larger risk. As organizations increase their quantity of cloud assets, their attack surface grows. Each...

https://www.crowdstrike.com/blog/enhanced-cloud-asset-visualization/


🎖@malwr
Russia-Linked CopyCop Uses LLMs to Weaponize Influence Content at Scale

Insikt Group shares research on CopyCop: a Russian-linked network using AI for disinformation to influence US, UK, and French politics. Dive into the details.

https://www.recordedfuture.com/russia-linked-copycop-uses-llms-to-weaponize-influence-content-at-scale


🎖@malwr
Doctor Web’s annual virus activity review for 2023

https://news.drweb.com/show/?i=14851&lng=en&c=5


🎖@malwr
Exploring the Depths of SolarMarker's Multi-tiered Infrastructure

Uncover SolarMarker’s multi-tiered infrastructure and its impact on sectors like education, healthcare, and government. Learn more.

https://www.recordedfuture.com/exploring-the-depths-of-solarmarkers-multi-tiered-infrastructure


🎖@malwr
XWiki Remote Code Execution Vulnerability

Overview The SonicWall Capture Labs threat research team became aware of CVE-2024-31984, which is a code injection vulnerability in XWiki’s management of space titles and has a critical CVSS score of 9.9. After assessing the

https://blog.sonicwall.com/en-us/2024/05/xwiki-remote-code-execution-vulnerability/


🎖@malwr
GitCaught: Threat Actor Leverages GitHub Repository for Malicious Infrastructure

Discover how Russian-speaking hackers leverage GitHub to host malware disguised as legitimate software. Explore the campaign, implications, and protection strategies.

https://www.recordedfuture.com/gitcaught-threat-actor-leverages-github-repository-for-malicious-infrastructure


🎖@malwr
Remcos Is Pairing with PrivateLoader to Extend Its Capabilities

Overview This week, the SonicWall Capture Labs threat research team investigated a sample of the RemcosRAT that uses a PrivateLoader module to provide additional data and persistence on the victim’s machine. By installing VB scripts,

https://blog.sonicwall.com/en-us/2024/05/remcos-is-pairing-with-privateloader-to-extend-its-capabilities/


🎖@malwr
MICROSOFT SECURITY BULLETIN COVERAGE FOR MAY 2024

Overview Microsoft’s May 2024 Patch Tuesday has 59 vulnerabilities, 25 of which are Remote Code Execution vulnerabilities. The SonicWall Capture Labs threat research team has analyzed and addressed Microsoft’s security advisories for the month of

https://blog.sonicwall.com/en-us/2024/05/microsoft-security-bulletin-coverage-for-may-2024/


🎖@malwr