Malware News
16.2K subscribers
1.64K photos
7 videos
130 files
8.31K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
AMSI Provider
The Antimalware Scan Interface (AMSI) is a Microsoft control that directs PowerShell content to the installed antimalware engine or EDR to conduct a scan and identify malicious indicators. However,…

https://ipurple.team/2026/07/13/amsi-provider/


🎖@malwr
Unfit to Boot: Breaking U-Boot's FIT Signature Verification | Binarly
The Binarly Research team has identified six new security vulnerabilities within U-Boot’s FIT (Flattened Image Tree) Signature Verification mechanism, a critical component for maintaining the Root of Trust in firmware. These flaws, affecting stable releases dating back to v2013.07, range from denial-of-service (DoS) conditions to potential arbitrary code execution during the processing of untrusted FIT images. This blog post details the technical nature of these vulnerabilities, demonstrating how they can be exploited, and discusses the coordinated disclosure process with the U-Boot maintainers that resulted in upstream patches. Understanding these risks is essential for firmware security, as compromising the initial bootloader can bypass security checks for all subsequent stages of the boot chain.

https://www.binarly.io/blog/unfit-to-boot-breaking-u-boots-fit-signature-verification


🎖@malwr
SindriKit 1.4.0: Stealth Execution with COFF Object Loading and Injection
How SindriKit's new COFF loader and injection orchestrator enable seamless execution of Beacon Object Files (BOFs) both locally and remotely.

https://sibouzitoun.tech/articles/sindrikit-v1o4/


🎖@malwr
2
Kratos PhaaS Targets US and EU Companies
Discover how Kratos PhaaS threatens Microsoft 365 accounts and how ANY.RUN helps security teams reduce fraud risk, speed detection, and contain compromise.

https://any.run/cybersecurity-blog/kratos-phaas-account-takeover/


🎖@malwr
How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist | Hudson Rock
How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist A shared research investigation…

https://www.hudsonrock.com/blog/how-an-infostealer-infection-led-to-a-sophisticated-clickfix-campaign-at-artlist


🎖@malwr
From EtherHiding to a native RAT: ClickFix on new-blog.artlist[.]io
Static teardown of a ClickFix chain on new-blog.artlist[.]io, from Polygon EtherHiding and PowerShell delivery to a manually mapped native Windows RAT.

https://www.derp.ca/research/artlist-clickfix-native-rat/


🎖@malwr
The serpent’s tongue: Luring the Python out of its den
This blog examines the full lifecycle of a Python package, from hosting on repositories such as PyPI or custom web servers, through source and wheel distribution formats, to the final installation into virtual or system-wide Python environments.

https://blog.talosintelligence.com/the-serpents-tongue-luring-the-python-out-of-its-den/


🎖@malwr
AgentRE-Bench
AI agents can write code. Can they reverse engineer it? AgentRE-Bench evaluates compiled-binary reverse engineering with deterministic scoring.

https://www.agentre-bench.ai/

https://github.com/agentrebench/AgentRE-Bench

AgentRE-Bench gives an LLM agent a compiled ELF binary and a set of Linux static analysis tools (strings, objdump, readelf, etc.), then measures how well it can identify C2 infrastructure, encoding schemes, anti-analysis techniques, and communication protocols — all without human guidance.


🎖@malwr
DomainTools Investigations | Threat Intelligence Report: The Pro-Iran Hacktivist Ecosystem 2026
Threat Intelligence Report: The Pro-Iran Hacktivist Ecosystem 2026

https://dti.domaintools.com/research/threat-intelligence-report-the-pro-iran-hacktivist-ecosystem-2026


🎖@malwr
WallabyDesigns/windows-telemetry-guard

https://github.com/WallabyDesigns/windows-telemetry-guard

A reversible Windows 10/11 telemetry and tracking hardening toolkit, from Wallaby Designs. Everything it changes is recorded in a timestamped backup first, so Revert restores your machine to exactly the state it was in before Apply.



🎖@malwr
Six Minutes to Compromise: How ‘Patriot Bait’ Actor Used AI to Build and Deploy a C&C Botnet

TrendAI Research analyzed over 200 Gemini CLI session logs showing how a Russian-speaking threat actor used AI to run a live botnet, finishing a full C&C migration in six minutes while doing just 11% of the work himself.

https://www.trendmicro.com/en_us/research/26/g/actor-behind-patriot-bait-used-ai-to-deploy-c2-botnet.html


🎖@malwr
1
TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development
TuxBot v3 Evolution, an IoT botnet framework built with LLMs. Read our analysis of its cross-compiled binaries, C2 architecture and bugs.

https://unit42.paloaltonetworks.com/tuxbot-v3-evolution-iot-botnet/


🎖@malwr
Suspected Chinese Operators Use Claude Code and DeepSeek to Breach Government Systems Across Four Countries
An exposed open directory revealed a suspected Chinese campaign using Claude Code and DeepSeek-v4-pro to breach government systems in Afghanistan, Thailand, and Taiwan, with parallel probing of financial services worldwide.

https://hunt.io/blog/chinese-operators-claude-deepseek-government-intrusion


🎖@malwr
Anatomy of a CUDA Binary
When you compile a CUDA kernel, the final artifact is a cubin — a CUDA binary. It is a standard ELF64 file with NVIDIA-specific sections that encode everything the CUDA driver needs to load and launch a kernel: the machine code, the parameter layout, register allocation metadata, and a collection of attributes that have no public documentation.

https://hiraditya.github.io/posts/anatomy-of-a-cuda-binary/


🎖@malwr
2026-06-22: SHub Stealer infection (macOS)

https://www.malware-traffic-analysis.net/2026/06/22/index.html


🎖@malwr