Malware News
16.2K subscribers
1.64K photos
7 videos
130 files
8.31K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel

The Chaos ransomware group uses new malware "msaRAT" that hijacks browsers. The malware doesn't communicate directly with C2 but connects through the browser. It enables arbitrary command execution while hiding the attacker's IP from victims via WebRTC over TURN.

https://blog.talosintelligence.com/chaos-msarat-living-off-the-browser-to-build-covert-c2-channel/


🎖@malwr
Thanks guys for the gift 🙏❤️

@SirMalware
3
TAG-195 Upgrades MaaS Ecosystem with Modular Tools

Insikt Group identifies four new TAG-195 malware families, revealing an architectural transition toward modular, operator-driven tooling in the MaaS ecosystem

https://www.recordedfuture.com/research/tag-195-evolves-maas-ecosystem

https://assets.recordedfuture.com/insikt-report-pdfs/2026/cta-2026-0723.pdf


🎖@malwr
Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged
An exposed open directory on a Hong Kong server revealed an autonomous AI agent running unattended, an unreported Go implant, and target-specific tooling used against Thailand's Ministry of Finance.

https://hunt.io/blog/thailand-ministry-finance-targeted-with-hermes-ai-agent


🎖@malwr
oxasploits/PacketSnitch: PacketSnitch is a network analysis platform that transforms packet captures into searchable, protocol-aware intelligence, helping security professionals, developers, and researchers rapidly uncover hosts, credentials, certificates, files, locations, protocols, anomalies, threat intel, and other actionable insights.

https://github.com/oxasploits/PacketSnitch


🎖@malwr
1
Analysis of Kimsuky's Attack on a South Korean Groupware Vendor Using a New Gomir Family Variant | Enki White Hat
Analysis of Kimsuky's Attack on a South Korean Groupware Vendor Using a New Gomir Family Variant

https://www.enki.co.kr/en/media-center/blog/analysis-of-kimsuky-s-attack-on-a-south-korean-groupware-vendor-using-a-new-gomir-family-variant


🎖@malwr
Inside a DPRK BlueNoroff ClickFix Kit | JUMPSEC
JUMPSEC threat intelligence reveals how Iran‑aligned MuddyWater uses Russian malware‑as‑a‑service and blockchain C2, blurring cybercrime and nation‑state espionage.

https://www.jumpsec.com/guides/inside-a-dprk-bluenoroff-clickfix-kit/


🎖@malwr
As a reminder: We take ads

@SirMalware
Accelerating EDR Evasion with LLM-Driven Analysis
SpecterOps reverse engineered Cortex XDR with LLMs to extract YARA rules, ML models, and behavioral detections.

https://specterops.io/blog/2026/06/29/llm-powered-edr-analysis/


🎖@malwr
Random Windows Things Part 2: Unexpected Clipboard Data Behavior – Winsider Seminars & Solutions Inc.
https://windows-internals.com/random-windows-things-part-2-unexpected-clipboard-data-behavior/


🎖@malwr
PPEE (puppy) 1.14 is released

PPEE (puppy) is a Professional PE file Explorer for reversers, malware researchers and those who want to statically inspect PE files in more details
- Added another Filter/Search box for bottom listview
- Added section names in Strings and Data directories
- Show list of TLS callcbaks
- Reproducible build hash support
- Show more info about sections in section headers
- Rich Header product id detection extended


https://mzrst.com/
2