Mustang Panda targets India's government and energy sectors with ZOHOMURK and MINIRECON
Acronis Threat Research Unit (TRU) has been tracking two concurrent campaigns orchestrated by Mustang Panda targeting Indian government entities, delivering new malware implants and abusing Zoho WorkDrive, a legitimate cloud storage platform commonly used in the Indian government sector.
https://www.acronis.com/en/tru/posts/mustang-panda-targets-indias-government-and-energy-sectors/
🎖@malwr
Acronis Threat Research Unit (TRU) has been tracking two concurrent campaigns orchestrated by Mustang Panda targeting Indian government entities, delivering new malware implants and abusing Zoho WorkDrive, a legitimate cloud storage platform commonly used in the Indian government sector.
https://www.acronis.com/en/tru/posts/mustang-panda-targets-indias-government-and-energy-sectors/
🎖@malwr
Acronis
Mustang Panda targets India's government and energy sectors with ZOHOMURK and MINIRECON
Acronis Threat Research Unit (TRU) has been tracking two concurrent campaigns orchestrated by Mustang Panda targeting Indian government entities, delivering new malware implants and abusing Zoho WorkDrive, a legitimate cloud storage platform commonly used…
❤1
Chaelsoo/Hollow
https://github.com/Chaelsoo/Hollow
🎖@malwr
https://github.com/Chaelsoo/Hollow
hollow is a shellcode loader generator. You give it a raw shellcode binary and a profile, and it spits out a compiled Windows PE loader with your shellcode encrypted inside.
🎖@malwr
GitHub
GitHub - Chaelsoo/Hollow: A shellcode loader generator with support for multiple injection techniques, built for red team engagements.
A shellcode loader generator with support for multiple injection techniques, built for red team engagements. - Chaelsoo/Hollow
TuncorReUnion/TLAC-MODERN-LOCAL-ANTI-CHEAT-REUNIONED: This Anti-Cheat is local server based and fully open source. it's user space
https://github.com/TuncorReUnion/TLAC-MODERN-LOCAL-ANTI-CHEAT-REUNIONED
🎖@malwr
https://github.com/TuncorReUnion/TLAC-MODERN-LOCAL-ANTI-CHEAT-REUNIONED
🎖@malwr
GitHub
GitHub - TuncorReUnion/TLAC-MODERN-LOCAL-ANTI-CHEAT-REUNIONED: This Anti-Cheat is local server based and fully open source. it's…
This Anti-Cheat is local server based and fully open source. it's user space - TuncorReUnion/TLAC-MODERN-LOCAL-ANTI-CHEAT-REUNIONED
CitrixBleed To Infinity And Beyond (Citrix NetScaler Pre-Auth Memory Overread CVE-2026-8451)
Well, well, well - once again, the cat has dragged us in and spat us out.
Today, we find ourselves questioning the reality we sit within. Must it be so predictable, and why us? “But watchTowr, what do you mean?”
Well, if you’re here, you likely fit into one of
https://labs.watchtowr.com/citrixbleed-to-infinity-and-beyond-citrix-netscaler-pre-auth-memory-overread-cve-2026-8451/
🎖@malwr
Well, well, well - once again, the cat has dragged us in and spat us out.
Today, we find ourselves questioning the reality we sit within. Must it be so predictable, and why us? “But watchTowr, what do you mean?”
Well, if you’re here, you likely fit into one of
https://labs.watchtowr.com/citrixbleed-to-infinity-and-beyond-citrix-netscaler-pre-auth-memory-overread-cve-2026-8451/
🎖@malwr
watchTowr Labs
CitrixBleed To Infinity And Beyond (Citrix NetScaler Pre-Auth Memory Overread CVE-2026-8451)
Well, well, well - once again, the cat has dragged us in and spat us out.
Today, we find ourselves questioning the reality we sit within. Must it be so predictable, and why us? “But watchTowr, what do you mean?”
Well, if you’re here, you likely fit into…
Today, we find ourselves questioning the reality we sit within. Must it be so predictable, and why us? “But watchTowr, what do you mean?”
Well, if you’re here, you likely fit into…
youssefnoob003/SindriKit: A foundational C library for building operationally credible offensive capabilities
https://github.com/youssefnoob003/SindriKit
🎖@malwr
https://github.com/youssefnoob003/SindriKit
🎖@malwr
GitHub
GitHub - youssefnoob003/SindriKit: A foundational C library for building operationally credible offensive capabilities
A foundational C library for building operationally credible offensive capabilities - youssefnoob003/SindriKit
RadonCoding/binsafe: Obfuscator for compiled 64-bit portable executables.
https://github.com/RadonCoding/binsafe
🎖@malwr
https://github.com/RadonCoding/binsafe
🎖@malwr
GitHub
GitHub - RadonCoding/binsafe: Obfuscator for compiled 64-bit portable executables.
Obfuscator for compiled 64-bit portable executables. - RadonCoding/binsafe
Doctor Web’s Q2 2026 review of virus activity on mobile devices
https://news.drweb.com/show/?i=15274&lng=en&c=5
🎖@malwr
https://news.drweb.com/show/?i=15274&lng=en&c=5
🎖@malwr
Iran-Nexus TAG-182 Disseminates MarkiRAT Surveillance Tool
Discover how Iranian-nexus threat cluster TAG-182 uses MarkiRAT malware and fake VPN/media apps to conduct cyber surveillance operations against domestic targets.
https://www.recordedfuture.com/research/nexus-tag182-disseminates-markirat
https://assets.recordedfuture.com/insikt-report-pdfs/2026/cta-ir-2026-0701.pdf
🎖@malwr
Discover how Iranian-nexus threat cluster TAG-182 uses MarkiRAT malware and fake VPN/media apps to conduct cyber surveillance operations against domestic targets.
https://www.recordedfuture.com/research/nexus-tag182-disseminates-markirat
https://assets.recordedfuture.com/insikt-report-pdfs/2026/cta-ir-2026-0701.pdf
🎖@malwr
greit0n/malwarebazaar-downloader: Pull MalwareBazaar samples into an isolated AV-testing lab — safe-by-design CLI + glassmorphic desktop GUI (mbdl).
https://github.com/greit0n/malwarebazaar-downloader
🎖@malwr
https://github.com/greit0n/malwarebazaar-downloader
🎖@malwr
GitHub
GitHub - greit0n/malwarebazaar-downloader: Pull MalwareBazaar samples into an isolated AV-testing lab — safe-by-design CLI + glassmorphic…
Pull MalwareBazaar samples into an isolated AV-testing lab — safe-by-design CLI + glassmorphic desktop GUI (mbdl). - greit0n/malwarebazaar-downloader
Context Engineering | Compaction & Agent Memory for Automated Malware Analysis
Compaction cut input tokens 86% across long-running agent evals with no quality loss. Context discipline matters as much as model selection.
https://www.sentinelone.com/labs/context-engineering-compaction-agent-memory-for-automated-malware-analysis/
🎖@malwr
Compaction cut input tokens 86% across long-running agent evals with no quality loss. Context discipline matters as much as model selection.
https://www.sentinelone.com/labs/context-engineering-compaction-agent-memory-for-automated-malware-analysis/
🎖@malwr
SentinelOne
Context Engineering | Compaction & Agent Memory for Automated Malware Analysis
Compaction cut input tokens 86% across long-running agent evals with no quality loss. Context discipline matters as much as model selection.
❤1
Reverse Engineering Warframe’s Anti-Cheat System
Warframe is the hit MMO game by Digital Extremes which is adored by many, being a curious Reverse Engineer I thought why not have a go at…
https://medium.com/@ssushruth2003/reverse-engineering-warframes-anti-cheat-system-aae5e6272a4b
🎖@malwr
Warframe is the hit MMO game by Digital Extremes which is adored by many, being a curious Reverse Engineer I thought why not have a go at…
https://medium.com/@ssushruth2003/reverse-engineering-warframes-anti-cheat-system-aae5e6272a4b
🎖@malwr
Medium
Reverse Engineering Warframe’s Anti-Cheat System
Warframe is the hit MMO game by Digital Extremes which is adored by many, being a curious Reverse Engineer I thought why not have a go at…
Fake Google and Cloudflare verification pages spread multiple malware families
https://www.malwarebytes.com/blog/threat-intel/2026/07/fake-google-and-cloudflare-verification-pages-spread-multiple-malware-families
🎖@malwr
https://www.malwarebytes.com/blog/threat-intel/2026/07/fake-google-and-cloudflare-verification-pages-spread-multiple-malware-families
🎖@malwr
Malwarebytes
Fake Google and Cloudflare verification pages spread multiple malware families
We uncovered ClickFix attacks using fake Google and Cloudflare pages to deliver everything from infostealers to a newly discovered malware loader.
Win x64 Shellcode â Part 2: TEB, PEB and List of Loaded Modules
In the previous part, we explained why shellcode cannot use statically written addresses of Windows API functions. The solution lies in the structures that Windows maintains directly in the memory of each process. Today we will look at them closely.
Prerequisites Before reading this part, it is advisable to read and understand the previous part. At the same time, it is highly advisable to have at least a basic understanding of what virtual memory and a pointer are.
https://proteqtum.com/posts/02-win-x64-shellcode-teb-peb_en/
🎖@malwr
In the previous part, we explained why shellcode cannot use statically written addresses of Windows API functions. The solution lies in the structures that Windows maintains directly in the memory of each process. Today we will look at them closely.
Prerequisites Before reading this part, it is advisable to read and understand the previous part. At the same time, it is highly advisable to have at least a basic understanding of what virtual memory and a pointer are.
https://proteqtum.com/posts/02-win-x64-shellcode-teb-peb_en/
🎖@malwr
proteqtum
Win x64 Shellcode – Part 2: TEB, PEB and List of Loaded Modules
In the previous part, we explained why shellcode cannot use statically written addresses of Windows API functions. The solution lies in the structures that Windows maintains directly in the memory of each process. Today we will look at them closely.
Prerequisites…
Prerequisites…
How I broke Rhysida ransomware encryption
Rhysida derives every per-file AES key from a PRNG seeded with the encryption timestamp. Recover the timestamp and you regenerate every key. A reverse-engineering walkthrough and a minimal decryptor.
https://sigreturn.com/blog/rhysida-analysis-decryption/
🎖@malwr
Rhysida derives every per-file AES key from a PRNG seeded with the encryption timestamp. Recover the timestamp and you regenerate every key. A reverse-engineering walkthrough and a minimal decryptor.
https://sigreturn.com/blog/rhysida-analysis-decryption/
🎖@malwr
Sigreturn
How I broke Rhysida ransomware encryption
Rhysida derives every per-file AES key from a PRNG seeded with the encryption timestamp. Recover the timestamp and you regenerate every key. A reverse-engineering walkthrough and a minimal decryptor.
Rhacknarok/hacksguard: A blazingly fast, multi-threaded TUI malware analysis tool built in Rust. Features deep PE parsing, YARA scanning, and heuristic risk scoring.
https://github.com/Rhacknarok/hacksguard
🎖@malwr
https://github.com/Rhacknarok/hacksguard
🎖@malwr
GitHub
GitHub - Rhacknarok/hacksguard: A blazingly fast, multi-threaded TUI malware analysis tool built in Rust. Features deep PE parsing…
A blazingly fast, multi-threaded TUI malware analysis tool built in Rust. Features deep PE parsing, YARA scanning, and heuristic risk scoring. - Rhacknarok/hacksguard