OkoBot framework infection chain
Kaspersky GReAT experts dissect the new OkoBot campaign targeting cryptocurrency users. This complex framework employs TookPS, exfiltrates seed phrases, monitors Chromium-based browsers, and installs various malware strains, including the Rilide stealer.
https://securelist.com/okobot-framework-targets-cryptocurrency-wallets/120660/
🎖@malwr
Kaspersky GReAT experts dissect the new OkoBot campaign targeting cryptocurrency users. This complex framework employs TookPS, exfiltrates seed phrases, monitors Chromium-based browsers, and installs various malware strains, including the Rilide stealer.
https://securelist.com/okobot-framework-targets-cryptocurrency-wallets/120660/
🎖@malwr
Windows AppResolver LPE: From AppContainer to SYSTEM
Exploit development for a Windows AppResolver authorization issue fixed in July 2026, from a zero-capability AppContainer to an interactive SYSTEM shell.
https://davidcarliez.github.io/blog/windows-appresolver-lpe-to-system/
🎖@malwr
Exploit development for a Windows AppResolver authorization issue fixed in July 2026, from a zero-capability AppContainer to an interactive SYSTEM shell.
https://davidcarliez.github.io/blog/windows-appresolver-lpe-to-system/
🎖@malwr
David Carliez
Windows AppResolver LPE: From AppContainer to SYSTEM
Exploit development for a Windows AppResolver authorization issue fixed in July 2026, from a zero-capability AppContainer to an interactive SYSTEM shell.
helixmap/sigwood: Local-first, transparent threat hunting for the logs you already have: Zeek, Pi-hole, syslog, CloudTrail. Named technique behind every finding. No SIEM, no agent, no black box.
https://github.com/helixmap/sigwood
🎖@malwr
https://github.com/helixmap/sigwood
🎖@malwr
GitHub
GitHub - helixmap/sigwood: Local-first threat hunting for the logs you already have: Zeek, Pi-hole, syslog or the systemd journal…
Local-first threat hunting for the logs you already have: Zeek, Pi-hole, syslog or the systemd journal, CloudTrail. Every run names the technique behind each detector. No agent, no daemon, no black...
From Alert to Core Dump: Hunting Zeus Malware Using Suricata, Splunk, YARA, and Volatility
Malware analysis and threat hunting are critical skills for any modern SOC Analyst. To truly understand how adversaries operate, we must…
https://medium.com/@osamamamoussa/from-alert-to-core-dump-hunting-zeus-malware-using-suricata-splunk-yara-and-volatility-4ce18f517f87?sharedUserId=osamamamoussa
🎖@malwr
Malware analysis and threat hunting are critical skills for any modern SOC Analyst. To truly understand how adversaries operate, we must…
https://medium.com/@osamamamoussa/from-alert-to-core-dump-hunting-zeus-malware-using-suricata-splunk-yara-and-volatility-4ce18f517f87?sharedUserId=osamamamoussa
🎖@malwr
Medium
From Alert to Core Dump: Hunting Zeus Malware Using Suricata, Splunk, YARA, and Volatility
Malware analysis and threat hunting are critical skills for any modern SOC Analyst. To truly understand how adversaries operate, we must…
Pixels to Payload: Dissecting a Four-Stage Bitmap-Steganography Dropper Delivering AsyncRAT
A technical teardown of a multi-stage .NET dropper chain that hides its loaders inside bitmap pixel channels, wraps an Eazfuscator crypter around an academic epidemiology simulator, and delivers AsyncRAT 0.5.8. Includes pixelchain, a keyless end-to-end chain extractor.
https://blog.threatuniverse.co.uk/posts/asyncrat-bitmap-steganography-dropper/
🎖@malwr
A technical teardown of a multi-stage .NET dropper chain that hides its loaders inside bitmap pixel channels, wraps an Eazfuscator crypter around an academic epidemiology simulator, and delivers AsyncRAT 0.5.8. Includes pixelchain, a keyless end-to-end chain extractor.
https://blog.threatuniverse.co.uk/posts/asyncrat-bitmap-steganography-dropper/
🎖@malwr
Rhys Downing
Pixels to Payload: Dissecting a Four-Stage Bitmap-Steganography Dropper Delivering AsyncRAT
A technical teardown of a multi-stage .NET dropper chain that hides its loaders inside bitmap pixel channels, wraps an Eazfuscator crypter around an academic epidemiology simulator, and delivers AsyncRAT 0.5.8. Includes pixelchain, a keyless end-to-end chain…
cookiengineer/godecompose: :construction: Experimental pattern-based decompiler for Go :construction:
https://github.com/cookiengineer/godecompose
🎖@malwr
https://github.com/cookiengineer/godecompose
Pattern-based decompiler for Go binaries. Recovers original Go source code by matching known compiler output patterns against disassembled machine code.
🎖@malwr
GitHub
GitHub - cookiengineer/godecompose: :construction: Experimental pattern-based decompiler for Go :construction:
:construction: Experimental pattern-based decompiler for Go :construction: - cookiengineer/godecompose
Fake games spread stealers with RenPy Loader, MSBuild and EtherHiding
https://www.malwarebytes.com/blog/threat-intel/2026/07/fake-games-spread-stealers-with-renpy-loader-msbuild-and-etherhiding
🎖@malwr
https://www.malwarebytes.com/blog/threat-intel/2026/07/fake-games-spread-stealers-with-renpy-loader-msbuild-and-etherhiding
🎖@malwr
Malwarebytes
Fake games spread stealers with RenPy Loader, MSBuild and EtherHiding
We look into how attackers are using the legitimate Ren'Py game engine to spread a malware loader that ultimately delivers Amatera Stealer.
JVBotelho/skewrun: Active Directory time discovery protocols for red teams. Stealthy extraction via Kerberos, SMB, NTLM, and CLDAP.
https://github.com/JVBotelho/skewrun
🎖@malwr
https://github.com/JVBotelho/skewrun
🎖@malwr
GitHub
GitHub - JVBotelho/skewrun: Active Directory time discovery protocols for red teams. Stealthy extraction via Kerberos, SMB, NTLM…
Active Directory time discovery protocols for red teams. Stealthy extraction via Kerberos, SMB, NTLM, and CLDAP. - JVBotelho/skewrun
CVE-2026-50458: Finding a UAF in the Windows Brokering File System
On Tuesday, July 14, Microsoft released the largest Patch Tuesday update in its history, fixing more than 600 vulnerabilities. A bug I reported to Microsoft on May 17 was patched as CVE-2026-50458 in this release, so I am publishing the writeup I wrote at the time, while the details were still fresh. I hope you enjoy it!
https://rotcee.github.io/posts/CVE-2026-50458-finding-a-UAF-in-windows-brokering-file-system/
🎖@malwr
On Tuesday, July 14, Microsoft released the largest Patch Tuesday update in its history, fixing more than 600 vulnerabilities. A bug I reported to Microsoft on May 17 was patched as CVE-2026-50458 in this release, so I am publishing the writeup I wrote at the time, while the details were still fresh. I hope you enjoy it!
https://rotcee.github.io/posts/CVE-2026-50458-finding-a-UAF-in-windows-brokering-file-system/
🎖@malwr
Rotce’s Blog
CVE-2026-50458: Finding a UAF in the Windows Brokering File System
On Tuesday, July 14, Microsoft released the largest Patch Tuesday update in its history, fixing more than 600 vulnerabilities. A bug I reported to Microsoft on May 17 was patched as CVE-2026-50458 in this release, so I am publishing the writeup I wrote at…
Device Code Phishing: Turning a Convenience Feature Into an MFA Bypass
Device code phishing abuses a legitimate authentication feature designed for devices with limited input capabilities. This article breaks down how the technique works, examines a recent observed case, and outlines the layered security measures organizations can implement.
https://www.trendmicro.com/en_us/research/26/g/device-code-phishing.html
🎖@malwr
Device code phishing abuses a legitimate authentication feature designed for devices with limited input capabilities. This article breaks down how the technique works, examines a recent observed case, and outlines the layered security measures organizations can implement.
https://www.trendmicro.com/en_us/research/26/g/device-code-phishing.html
🎖@malwr
Trend Micro
Device Code Phishing: Turning a Convenience Feature Into an MFA Bypass
Device code phishing abuses a legitimate authentication feature designed for devices with limited input capabilities. This article breaks down how the technique works, examines a recent observed case, and outlines the layered security measures organizations…
PE OopsSec: Mind your PE, guard your OPSEC
PE-OopsSec helps red teams, pentesters, and game developers give their payloads a final once‑over before putting them into the real world
https://www.zerosalarium.com/2026/07/pe-oopssec-mind-your-pe-guard-your-opsec.html
🎖@malwr
PE-OopsSec helps red teams, pentesters, and game developers give their payloads a final once‑over before putting them into the real world
https://www.zerosalarium.com/2026/07/pe-oopssec-mind-your-pe-guard-your-opsec.html
🎖@malwr
Zerosalarium
PE OopsSec: Mind your PE, guard your OPSEC
PE-OopsSec helps red teams, pentesters, and game developers give their payloads a final once‑over before putting them into the real world
Six Minutes to Compromise: How ‘Patriot Bait’ Actor Used AI to Build and Deploy a C&C Botnet
TrendAI™ Research analyzed over 200 Gemini CLI session logs showing how a Russian-speaking threat actor used AI to run a live botnet, finishing a full C&C migration in six minutes while doing just 11% of the work himself.
https://www.trendmicro.com/en_us/research/26/g/actor-behind-patriot-bait-used-ai-to-deploy-c2-botnet.html
🎖@malwr
TrendAI™ Research analyzed over 200 Gemini CLI session logs showing how a Russian-speaking threat actor used AI to run a live botnet, finishing a full C&C migration in six minutes while doing just 11% of the work himself.
https://www.trendmicro.com/en_us/research/26/g/actor-behind-patriot-bait-used-ai-to-deploy-c2-botnet.html
🎖@malwr
Trend Micro
Six Minutes to Compromise: How ‘Patriot Bait’ Actor Used AI to Build and Deploy a C&C Botnet
TrendAI™ Research analyzed over 200 Gemini CLI session logs showing how a Russian-speaking threat actor used AI to run a live botnet, finishing a full C&C migration in six minutes while doing just 11% of the work himself.
Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel
The Chaos ransomware group uses new malware "msaRAT" that hijacks browsers. The malware doesn't communicate directly with C2 but connects through the browser. It enables arbitrary command execution while hiding the attacker's IP from victims via WebRTC over TURN.
https://blog.talosintelligence.com/chaos-msarat-living-off-the-browser-to-build-covert-c2-channel/
🎖@malwr
The Chaos ransomware group uses new malware "msaRAT" that hijacks browsers. The malware doesn't communicate directly with C2 but connects through the browser. It enables arbitrary command execution while hiding the attacker's IP from victims via WebRTC over TURN.
https://blog.talosintelligence.com/chaos-msarat-living-off-the-browser-to-build-covert-c2-channel/
🎖@malwr
Cisco Talos
Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel
The Chaos ransomware group uses new malware "msaRAT" that hijacks browsers. The malware doesn't communicate directly with C2 but connects through the browser. It enables arbitrary command execution while hiding the attacker's IP from victims via WebRTC over…
TAG-195 Upgrades MaaS Ecosystem with Modular Tools
Insikt Group identifies four new TAG-195 malware families, revealing an architectural transition toward modular, operator-driven tooling in the MaaS ecosystem
https://www.recordedfuture.com/research/tag-195-evolves-maas-ecosystem
https://assets.recordedfuture.com/insikt-report-pdfs/2026/cta-2026-0723.pdf
🎖@malwr
Insikt Group identifies four new TAG-195 malware families, revealing an architectural transition toward modular, operator-driven tooling in the MaaS ecosystem
https://www.recordedfuture.com/research/tag-195-evolves-maas-ecosystem
https://assets.recordedfuture.com/insikt-report-pdfs/2026/cta-2026-0723.pdf
🎖@malwr
Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged
An exposed open directory on a Hong Kong server revealed an autonomous AI agent running unattended, an unreported Go implant, and target-specific tooling used against Thailand's Ministry of Finance.
https://hunt.io/blog/thailand-ministry-finance-targeted-with-hermes-ai-agent
🎖@malwr
An exposed open directory on a Hong Kong server revealed an autonomous AI agent running unattended, an unreported Go implant, and target-specific tooling used against Thailand's Ministry of Finance.
https://hunt.io/blog/thailand-ministry-finance-targeted-with-hermes-ai-agent
🎖@malwr
hunt.io
Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged
An exposed open directory on a Hong Kong server revealed an autonomous AI agent running unattended, an unreported Go implant, and target-specific tooling used against Thailand's Ministry of Finance.
oxasploits/PacketSnitch: PacketSnitch is a network analysis platform that transforms packet captures into searchable, protocol-aware intelligence, helping security professionals, developers, and researchers rapidly uncover hosts, credentials, certificates, files, locations, protocols, anomalies, threat intel, and other actionable insights.
https://github.com/oxasploits/PacketSnitch
🎖@malwr
https://github.com/oxasploits/PacketSnitch
🎖@malwr
❤1
Analysis of Kimsuky's Attack on a South Korean Groupware Vendor Using a New Gomir Family Variant | Enki White Hat
Analysis of Kimsuky's Attack on a South Korean Groupware Vendor Using a New Gomir Family Variant
https://www.enki.co.kr/en/media-center/blog/analysis-of-kimsuky-s-attack-on-a-south-korean-groupware-vendor-using-a-new-gomir-family-variant
🎖@malwr
Analysis of Kimsuky's Attack on a South Korean Groupware Vendor Using a New Gomir Family Variant
https://www.enki.co.kr/en/media-center/blog/analysis-of-kimsuky-s-attack-on-a-south-korean-groupware-vendor-using-a-new-gomir-family-variant
🎖@malwr
www.enki.co.kr
Analysis of Kimsuky's Attack on a South Korean Groupware Vendor Using a New Gomir Family Variant | Enki White Hat
Windows Data Deduplication // Noir Trace Writeups
A Forensic Investigation into Windows Data Deduplication [The Vanishing File]
https://7h3kn0w3r.github.io/blog/windows-data-deduplication/
https://github.com/7h3kn0w3r/DedupInspector
🎖@malwr
A Forensic Investigation into Windows Data Deduplication [The Vanishing File]
https://7h3kn0w3r.github.io/blog/windows-data-deduplication/
https://github.com/7h3kn0w3r/DedupInspector
🎖@malwr
7h3kn0w3r.github.io
Windows Data Deduplication // Noir Trace Writeups
A Forensic Investigation into Windows Data Deduplication [The Vanishing File]
❤2
Inside a DPRK BlueNoroff ClickFix Kit | JUMPSEC
JUMPSEC threat intelligence reveals how Iran‑aligned MuddyWater uses Russian malware‑as‑a‑service and blockchain C2, blurring cybercrime and nation‑state espionage.
https://www.jumpsec.com/guides/inside-a-dprk-bluenoroff-clickfix-kit/
🎖@malwr
JUMPSEC threat intelligence reveals how Iran‑aligned MuddyWater uses Russian malware‑as‑a‑service and blockchain C2, blurring cybercrime and nation‑state espionage.
https://www.jumpsec.com/guides/inside-a-dprk-bluenoroff-clickfix-kit/
🎖@malwr
JUMPSEC
Inside a DPRK BlueNoroff ClickFix Kit | JUMPSEC
JUMPSEC researchers analyse an active BlueNoroff phishing kit used to impersonate Zoom and Microsoft Teams meetings, revealing source code, infrastructure, malware delivery and victim targeting techniques.