Malware News
15.8K subscribers
1.64K photos
7 videos
130 files
8.12K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
Accelerating EDR Evasion with LLM-Driven Analysis
SpecterOps reverse engineered Cortex XDR with LLMs to extract YARA rules, ML models, and behavioral detections.

https://specterops.io/blog/2026/06/29/llm-powered-edr-analysis/


🎖@malwr
The Gentlemen RaaS: rapid growth and a new ransomware variant
Kaspersky researchers analyze incidents related to The Gentlemen RaaS group, disclose their tools and TTPs, and find a new ransomware variant.

https://securelist.com/the-gentlemen-raas/120447/


🎖@malwr
OSIRIS — The Open-Source Palantir Alternative | Live Flights, CCTV, Satellites & OSINT Tools
Track 10K+ aircraft, 2K satellites & worldwide CCTV on a 3D globe. Run Nmap, DNS, WHOIS & threat intel scans from your browser. 20+ live intelligence feeds. Free. Open source.

https://osirisai.live/


🎖@malwr
This media is not supported in your browser
VIEW IN TELEGRAM
15👏1
xTeardx/diaphora-mcp

https://github.com/xTeardx/diaphora-mcp

Diaphora MCP is an MCP (Model Context Protocol) server for automated binary diffing. It connects Diaphora (the diffing engine) and IDA Pro (the disassembler) via the MCP protocol, allowing AI agents (such as Claude Code) to perform binary file comparison, find security patches, and analyze changes.


🎖@malwr
Windows Service
Windows Services are a common target for adversaries because they provide a reliable mechanism for executing code with elevated privileges, maintaining persistence, and blending malicious activity …

https://ipurple.team/2026/07/06/windows-service/


🎖@malwr
ItsMehRAWRXD/RawrXDA: RawrXDA

https://github.com/ItsMehRAWRXD/RawrXDA

This is a complete PE32+ writer and machine code emitter implemented in pure x64 MASM assembly with zero dependencies and no CRT usage. It generates runnable Windows executables from scratch.


🎖@malwr
ridgelinecyberdefence/Enterprise-Detection-Engineering: Production-validated detection queries and hunting artifacts across 9 platforms (KQL, Sigma, Splunk, Athena, PowerShell, Velociraptor, YARA, Suricata, osquery). Each with triggers, false positives, tuning guidance, and validation steps.

https://github.com/ridgelinecyberdefence/Enterprise-Detection-Engineering


🎖@malwr
FuturesLab/Binvariants

https://github.com/FuturesLab/Binvariants

This repository provides the source code for Binvariants: a prototype fuzzing framework that leverages register-level likely invariant violations for fuzzing binaries.


🎖@malwr
I'm Building a Secure USB Drive That Hides Itself
This article was written by a human, for humans. Link to support this project.
Many places don't respect privacy laws, in certain situations you …

https://rootkitlabs.com/2026/06/22/I%27m-Building-a-Secure-USB-Drive/


🎖@malwr
Vidar Infostealer Being Spread through Phishing Emails

1. Overview First identified in 2018, Vidar operates under a Malware-as-a-Service (MaaS) model and continues to be distributed through various attack cases to this day. AhnLab SEcurity intelligence Center (ASEC) has been monitoring cases of Vidar distribution targeting Korea, and this report summarizes the Vidar distribution cases identified in the first half of 2026.    […]

https://asec.ahnlab.com/en/94363/


🎖@malwr
1
UAT-7810 continues building ORB networks using new malware

Talos’ latest findings on UAT-7810 indicate that the threat actor continues to develop their custom-made malware.

https://blog.talosintelligence.com/uat-7810/


🎖@malwr
Claude Code Is Steganographically Marking Requests
I inspected Claude Code for privacy reasons and found hidden system prompt markers based on API base URL and timezone.

https://thereallo.dev/blog/claude-code-prompt-steganography


🎖@malwr