Malware News
15.8K subscribers
1.64K photos
7 videos
130 files
8.1K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
Doctor Web’s Q2 2026 virus activity review

https://news.drweb.com/show/?i=15275&lng=en&c=5


🎖@malwr
Iran-Nexus TAG-182 Disseminates MarkiRAT Surveillance Tool

Discover how Iranian-nexus threat cluster TAG-182 uses MarkiRAT malware and fake VPN/media apps to conduct cyber surveillance operations against domestic targets.

https://www.recordedfuture.com/research/nexus-tag182-disseminates-markirat

https://assets.recordedfuture.com/insikt-report-pdfs/2026/cta-ir-2026-0701.pdf


🎖@malwr
Win x64 Shellcode – Part 2: TEB, PEB and List of Loaded Modules
In the previous part, we explained why shellcode cannot use statically written addresses of Windows API functions. The solution lies in the structures that Windows maintains directly in the memory of each process. Today we will look at them closely.
Prerequisites Before reading this part, it is advisable to read and understand the previous part. At the same time, it is highly advisable to have at least a basic understanding of what virtual memory and a pointer are.

https://proteqtum.com/posts/02-win-x64-shellcode-teb-peb_en/


🎖@malwr
How I broke Rhysida ransomware encryption
Rhysida derives every per-file AES key from a PRNG seeded with the encryption timestamp. Recover the timestamp and you regenerate every key. A reverse-engineering walkthrough and a minimal decryptor.

https://sigreturn.com/blog/rhysida-analysis-decryption/


🎖@malwr
Accelerating EDR Evasion with LLM-Driven Analysis
SpecterOps reverse engineered Cortex XDR with LLMs to extract YARA rules, ML models, and behavioral detections.

https://specterops.io/blog/2026/06/29/llm-powered-edr-analysis/


🎖@malwr
The Gentlemen RaaS: rapid growth and a new ransomware variant
Kaspersky researchers analyze incidents related to The Gentlemen RaaS group, disclose their tools and TTPs, and find a new ransomware variant.

https://securelist.com/the-gentlemen-raas/120447/


🎖@malwr
OSIRIS — The Open-Source Palantir Alternative | Live Flights, CCTV, Satellites & OSINT Tools
Track 10K+ aircraft, 2K satellites & worldwide CCTV on a 3D globe. Run Nmap, DNS, WHOIS & threat intel scans from your browser. 20+ live intelligence feeds. Free. Open source.

https://osirisai.live/


🎖@malwr
This media is not supported in your browser
VIEW IN TELEGRAM
15👏1
xTeardx/diaphora-mcp

https://github.com/xTeardx/diaphora-mcp

Diaphora MCP is an MCP (Model Context Protocol) server for automated binary diffing. It connects Diaphora (the diffing engine) and IDA Pro (the disassembler) via the MCP protocol, allowing AI agents (such as Claude Code) to perform binary file comparison, find security patches, and analyze changes.


🎖@malwr