Malware News
16.2K subscribers
1.64K photos
7 videos
130 files
8.31K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
From EtherHiding to a native RAT: ClickFix on new-blog.artlist[.]io
Static teardown of a ClickFix chain on new-blog.artlist[.]io, from Polygon EtherHiding and PowerShell delivery to a manually mapped native Windows RAT.

https://www.derp.ca/research/artlist-clickfix-native-rat/


🎖@malwr
The serpent’s tongue: Luring the Python out of its den
This blog examines the full lifecycle of a Python package, from hosting on repositories such as PyPI or custom web servers, through source and wheel distribution formats, to the final installation into virtual or system-wide Python environments.

https://blog.talosintelligence.com/the-serpents-tongue-luring-the-python-out-of-its-den/


🎖@malwr
AgentRE-Bench
AI agents can write code. Can they reverse engineer it? AgentRE-Bench evaluates compiled-binary reverse engineering with deterministic scoring.

https://www.agentre-bench.ai/

https://github.com/agentrebench/AgentRE-Bench

AgentRE-Bench gives an LLM agent a compiled ELF binary and a set of Linux static analysis tools (strings, objdump, readelf, etc.), then measures how well it can identify C2 infrastructure, encoding schemes, anti-analysis techniques, and communication protocols — all without human guidance.


🎖@malwr
DomainTools Investigations | Threat Intelligence Report: The Pro-Iran Hacktivist Ecosystem 2026
Threat Intelligence Report: The Pro-Iran Hacktivist Ecosystem 2026

https://dti.domaintools.com/research/threat-intelligence-report-the-pro-iran-hacktivist-ecosystem-2026


🎖@malwr
WallabyDesigns/windows-telemetry-guard

https://github.com/WallabyDesigns/windows-telemetry-guard

A reversible Windows 10/11 telemetry and tracking hardening toolkit, from Wallaby Designs. Everything it changes is recorded in a timestamped backup first, so Revert restores your machine to exactly the state it was in before Apply.



🎖@malwr
Six Minutes to Compromise: How ‘Patriot Bait’ Actor Used AI to Build and Deploy a C&C Botnet

TrendAI Research analyzed over 200 Gemini CLI session logs showing how a Russian-speaking threat actor used AI to run a live botnet, finishing a full C&C migration in six minutes while doing just 11% of the work himself.

https://www.trendmicro.com/en_us/research/26/g/actor-behind-patriot-bait-used-ai-to-deploy-c2-botnet.html


🎖@malwr
1
TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development
TuxBot v3 Evolution, an IoT botnet framework built with LLMs. Read our analysis of its cross-compiled binaries, C2 architecture and bugs.

https://unit42.paloaltonetworks.com/tuxbot-v3-evolution-iot-botnet/


🎖@malwr
Suspected Chinese Operators Use Claude Code and DeepSeek to Breach Government Systems Across Four Countries
An exposed open directory revealed a suspected Chinese campaign using Claude Code and DeepSeek-v4-pro to breach government systems in Afghanistan, Thailand, and Taiwan, with parallel probing of financial services worldwide.

https://hunt.io/blog/chinese-operators-claude-deepseek-government-intrusion


🎖@malwr
Anatomy of a CUDA Binary
When you compile a CUDA kernel, the final artifact is a cubin — a CUDA binary. It is a standard ELF64 file with NVIDIA-specific sections that encode everything the CUDA driver needs to load and launch a kernel: the machine code, the parameter layout, register allocation metadata, and a collection of attributes that have no public documentation.

https://hiraditya.github.io/posts/anatomy-of-a-cuda-binary/


🎖@malwr
2026-06-22: SHub Stealer infection (macOS)

https://www.malware-traffic-analysis.net/2026/06/22/index.html


🎖@malwr
2026-06-01: SmartApeSG ClickFix --> Unidentified RAT

https://www.malware-traffic-analysis.net/2026/06/01/index.html


🎖@malwr
11
One Man, One AI, One Fake Persona: Inside the 5-Year Influence and Fraud ‘Patriot Bait’ Campaign
A solo Russian-speaking threat actor ran a 5-year Telegram channel and, starting September 2025, used AI to automate its content, credential theft, and a cryptocurrency fraud scheme targeting American audiences.

https://www.trendmicro.com/en_us/research/26/e/inside-the-influence-and-fraud-patriot-bait-campaign.html


🎖@malwr
👍2
UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign
Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. and Europe since at least June 2025.

https://blog.talosintelligence.com/uat-11795-deploys-novel-starland-rat-and-bespoke-wldr-c2-implant-in-financially-motivated-campaign/


🎖@malwr