Malware News
16.2K subscribers
1.64K photos
7 videos
130 files
8.31K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
One Man, One AI, One Fake Persona: Inside the 5-Year Influence and Fraud ‘Patriot Bait’ Campaign
A solo Russian-speaking threat actor ran a 5-year Telegram channel and, starting September 2025, used AI to automate its content, credential theft, and a cryptocurrency fraud scheme targeting American audiences.

https://www.trendmicro.com/en_us/research/26/e/inside-the-influence-and-fraud-patriot-bait-campaign.html


🎖@malwr
👍2
UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign
Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. and Europe since at least June 2025.

https://blog.talosintelligence.com/uat-11795-deploys-novel-starland-rat-and-bespoke-wldr-c2-implant-in-financially-motivated-campaign/


🎖@malwr
OkoBot framework infection chain
Kaspersky GReAT experts dissect the new OkoBot campaign targeting cryptocurrency users. This complex framework employs TookPS, exfiltrates seed phrases, monitors Chromium-based browsers, and installs various malware strains, including the Rilide stealer.

https://securelist.com/okobot-framework-targets-cryptocurrency-wallets/120660/


🎖@malwr
Windows AppResolver LPE: From AppContainer to SYSTEM
Exploit development for a Windows AppResolver authorization issue fixed in July 2026, from a zero-capability AppContainer to an interactive SYSTEM shell.

https://davidcarliez.github.io/blog/windows-appresolver-lpe-to-system/


🎖@malwr
Pixels to Payload: Dissecting a Four-Stage Bitmap-Steganography Dropper Delivering AsyncRAT
A technical teardown of a multi-stage .NET dropper chain that hides its loaders inside bitmap pixel channels, wraps an Eazfuscator crypter around an academic epidemiology simulator, and delivers AsyncRAT 0.5.8. Includes pixelchain, a keyless end-to-end chain extractor.

https://blog.threatuniverse.co.uk/posts/asyncrat-bitmap-steganography-dropper/


🎖@malwr
cookiengineer/godecompose: :construction: Experimental pattern-based decompiler for Go :construction:

https://github.com/cookiengineer/godecompose

Pattern-based decompiler for Go binaries. Recovers original Go source code by matching known compiler output patterns against disassembled machine code.



🎖@malwr
Reminder: We take ads

@SirMalware
CVE-2026-50458: Finding a UAF in the Windows Brokering File System
On Tuesday, July 14, Microsoft released the largest Patch Tuesday update in its history, fixing more than 600 vulnerabilities. A bug I reported to Microsoft on May 17 was patched as CVE-2026-50458 in this release, so I am publishing the writeup I wrote at the time, while the details were still fresh. I hope you enjoy it!

https://rotcee.github.io/posts/CVE-2026-50458-finding-a-UAF-in-windows-brokering-file-system/


🎖@malwr
Device Code Phishing: Turning a Convenience Feature Into an MFA Bypass

Device code phishing abuses a legitimate authentication feature designed for devices with limited input capabilities. This article breaks down how the technique works, examines a recent observed case, and outlines the layered security measures organizations can implement.

https://www.trendmicro.com/en_us/research/26/g/device-code-phishing.html


🎖@malwr
Six Minutes to Compromise: How ‘Patriot Bait’ Actor Used AI to Build and Deploy a C&C Botnet
TrendAI Research analyzed over 200 Gemini CLI session logs showing how a Russian-speaking threat actor used AI to run a live botnet, finishing a full C&C migration in six minutes while doing just 11% of the work himself.

https://www.trendmicro.com/en_us/research/26/g/actor-behind-patriot-bait-used-ai-to-deploy-c2-botnet.html


🎖@malwr
Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel

The Chaos ransomware group uses new malware "msaRAT" that hijacks browsers. The malware doesn't communicate directly with C2 but connects through the browser. It enables arbitrary command execution while hiding the attacker's IP from victims via WebRTC over TURN.

https://blog.talosintelligence.com/chaos-msarat-living-off-the-browser-to-build-covert-c2-channel/


🎖@malwr
Thanks guys for the gift 🙏❤️

@SirMalware
3
TAG-195 Upgrades MaaS Ecosystem with Modular Tools

Insikt Group identifies four new TAG-195 malware families, revealing an architectural transition toward modular, operator-driven tooling in the MaaS ecosystem

https://www.recordedfuture.com/research/tag-195-evolves-maas-ecosystem

https://assets.recordedfuture.com/insikt-report-pdfs/2026/cta-2026-0723.pdf


🎖@malwr