Malware News
16.2K subscribers
1.64K photos
7 videos
130 files
8.31K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
Six Minutes to Compromise: How ‘Patriot Bait’ Actor Used AI to Build and Deploy a C&C Botnet

TrendAI Research analyzed over 200 Gemini CLI session logs showing how a Russian-speaking threat actor used AI to run a live botnet, finishing a full C&C migration in six minutes while doing just 11% of the work himself.

https://www.trendmicro.com/en_us/research/26/g/actor-behind-patriot-bait-used-ai-to-deploy-c2-botnet.html


🎖@malwr
1
TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development
TuxBot v3 Evolution, an IoT botnet framework built with LLMs. Read our analysis of its cross-compiled binaries, C2 architecture and bugs.

https://unit42.paloaltonetworks.com/tuxbot-v3-evolution-iot-botnet/


🎖@malwr
Suspected Chinese Operators Use Claude Code and DeepSeek to Breach Government Systems Across Four Countries
An exposed open directory revealed a suspected Chinese campaign using Claude Code and DeepSeek-v4-pro to breach government systems in Afghanistan, Thailand, and Taiwan, with parallel probing of financial services worldwide.

https://hunt.io/blog/chinese-operators-claude-deepseek-government-intrusion


🎖@malwr
Anatomy of a CUDA Binary
When you compile a CUDA kernel, the final artifact is a cubin — a CUDA binary. It is a standard ELF64 file with NVIDIA-specific sections that encode everything the CUDA driver needs to load and launch a kernel: the machine code, the parameter layout, register allocation metadata, and a collection of attributes that have no public documentation.

https://hiraditya.github.io/posts/anatomy-of-a-cuda-binary/


🎖@malwr
2026-06-22: SHub Stealer infection (macOS)

https://www.malware-traffic-analysis.net/2026/06/22/index.html


🎖@malwr
2026-06-01: SmartApeSG ClickFix --> Unidentified RAT

https://www.malware-traffic-analysis.net/2026/06/01/index.html


🎖@malwr
11
One Man, One AI, One Fake Persona: Inside the 5-Year Influence and Fraud ‘Patriot Bait’ Campaign
A solo Russian-speaking threat actor ran a 5-year Telegram channel and, starting September 2025, used AI to automate its content, credential theft, and a cryptocurrency fraud scheme targeting American audiences.

https://www.trendmicro.com/en_us/research/26/e/inside-the-influence-and-fraud-patriot-bait-campaign.html


🎖@malwr
👍2
UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign
Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. and Europe since at least June 2025.

https://blog.talosintelligence.com/uat-11795-deploys-novel-starland-rat-and-bespoke-wldr-c2-implant-in-financially-motivated-campaign/


🎖@malwr
OkoBot framework infection chain
Kaspersky GReAT experts dissect the new OkoBot campaign targeting cryptocurrency users. This complex framework employs TookPS, exfiltrates seed phrases, monitors Chromium-based browsers, and installs various malware strains, including the Rilide stealer.

https://securelist.com/okobot-framework-targets-cryptocurrency-wallets/120660/


🎖@malwr
Windows AppResolver LPE: From AppContainer to SYSTEM
Exploit development for a Windows AppResolver authorization issue fixed in July 2026, from a zero-capability AppContainer to an interactive SYSTEM shell.

https://davidcarliez.github.io/blog/windows-appresolver-lpe-to-system/


🎖@malwr
Pixels to Payload: Dissecting a Four-Stage Bitmap-Steganography Dropper Delivering AsyncRAT
A technical teardown of a multi-stage .NET dropper chain that hides its loaders inside bitmap pixel channels, wraps an Eazfuscator crypter around an academic epidemiology simulator, and delivers AsyncRAT 0.5.8. Includes pixelchain, a keyless end-to-end chain extractor.

https://blog.threatuniverse.co.uk/posts/asyncrat-bitmap-steganography-dropper/


🎖@malwr
cookiengineer/godecompose: :construction: Experimental pattern-based decompiler for Go :construction:

https://github.com/cookiengineer/godecompose

Pattern-based decompiler for Go binaries. Recovers original Go source code by matching known compiler output patterns against disassembled machine code.



🎖@malwr
Reminder: We take ads

@SirMalware