Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel
The Chaos ransomware group uses new malware "msaRAT" that hijacks browsers. The malware doesn't communicate directly with C2 but connects through the browser. It enables arbitrary command execution while hiding the attacker's IP from victims via WebRTC over TURN.
https://blog.talosintelligence.com/chaos-msarat-living-off-the-browser-to-build-covert-c2-channel/
🎖@malwr
The Chaos ransomware group uses new malware "msaRAT" that hijacks browsers. The malware doesn't communicate directly with C2 but connects through the browser. It enables arbitrary command execution while hiding the attacker's IP from victims via WebRTC over TURN.
https://blog.talosintelligence.com/chaos-msarat-living-off-the-browser-to-build-covert-c2-channel/
🎖@malwr
Cisco Talos
Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel
The Chaos ransomware group uses new malware "msaRAT" that hijacks browsers. The malware doesn't communicate directly with C2 but connects through the browser. It enables arbitrary command execution while hiding the attacker's IP from victims via WebRTC over…
TAG-195 Upgrades MaaS Ecosystem with Modular Tools
Insikt Group identifies four new TAG-195 malware families, revealing an architectural transition toward modular, operator-driven tooling in the MaaS ecosystem
https://www.recordedfuture.com/research/tag-195-evolves-maas-ecosystem
https://assets.recordedfuture.com/insikt-report-pdfs/2026/cta-2026-0723.pdf
🎖@malwr
Insikt Group identifies four new TAG-195 malware families, revealing an architectural transition toward modular, operator-driven tooling in the MaaS ecosystem
https://www.recordedfuture.com/research/tag-195-evolves-maas-ecosystem
https://assets.recordedfuture.com/insikt-report-pdfs/2026/cta-2026-0723.pdf
🎖@malwr
Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged
An exposed open directory on a Hong Kong server revealed an autonomous AI agent running unattended, an unreported Go implant, and target-specific tooling used against Thailand's Ministry of Finance.
https://hunt.io/blog/thailand-ministry-finance-targeted-with-hermes-ai-agent
🎖@malwr
An exposed open directory on a Hong Kong server revealed an autonomous AI agent running unattended, an unreported Go implant, and target-specific tooling used against Thailand's Ministry of Finance.
https://hunt.io/blog/thailand-ministry-finance-targeted-with-hermes-ai-agent
🎖@malwr
hunt.io
Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged
An exposed open directory on a Hong Kong server revealed an autonomous AI agent running unattended, an unreported Go implant, and target-specific tooling used against Thailand's Ministry of Finance.
oxasploits/PacketSnitch: PacketSnitch is a network analysis platform that transforms packet captures into searchable, protocol-aware intelligence, helping security professionals, developers, and researchers rapidly uncover hosts, credentials, certificates, files, locations, protocols, anomalies, threat intel, and other actionable insights.
https://github.com/oxasploits/PacketSnitch
🎖@malwr
https://github.com/oxasploits/PacketSnitch
🎖@malwr
❤1
Analysis of Kimsuky's Attack on a South Korean Groupware Vendor Using a New Gomir Family Variant | Enki White Hat
Analysis of Kimsuky's Attack on a South Korean Groupware Vendor Using a New Gomir Family Variant
https://www.enki.co.kr/en/media-center/blog/analysis-of-kimsuky-s-attack-on-a-south-korean-groupware-vendor-using-a-new-gomir-family-variant
🎖@malwr
Analysis of Kimsuky's Attack on a South Korean Groupware Vendor Using a New Gomir Family Variant
https://www.enki.co.kr/en/media-center/blog/analysis-of-kimsuky-s-attack-on-a-south-korean-groupware-vendor-using-a-new-gomir-family-variant
🎖@malwr
www.enki.co.kr
Analysis of Kimsuky's Attack on a South Korean Groupware Vendor Using a New Gomir Family Variant | Enki White Hat
Windows Data Deduplication // Noir Trace Writeups
A Forensic Investigation into Windows Data Deduplication [The Vanishing File]
https://7h3kn0w3r.github.io/blog/windows-data-deduplication/
https://github.com/7h3kn0w3r/DedupInspector
🎖@malwr
A Forensic Investigation into Windows Data Deduplication [The Vanishing File]
https://7h3kn0w3r.github.io/blog/windows-data-deduplication/
https://github.com/7h3kn0w3r/DedupInspector
🎖@malwr
7h3kn0w3r.github.io
Windows Data Deduplication // Noir Trace Writeups
A Forensic Investigation into Windows Data Deduplication [The Vanishing File]
❤2
Inside a DPRK BlueNoroff ClickFix Kit | JUMPSEC
JUMPSEC threat intelligence reveals how Iran‑aligned MuddyWater uses Russian malware‑as‑a‑service and blockchain C2, blurring cybercrime and nation‑state espionage.
https://www.jumpsec.com/guides/inside-a-dprk-bluenoroff-clickfix-kit/
🎖@malwr
JUMPSEC threat intelligence reveals how Iran‑aligned MuddyWater uses Russian malware‑as‑a‑service and blockchain C2, blurring cybercrime and nation‑state espionage.
https://www.jumpsec.com/guides/inside-a-dprk-bluenoroff-clickfix-kit/
🎖@malwr
JUMPSEC
Inside a DPRK BlueNoroff ClickFix Kit | JUMPSEC
JUMPSEC researchers analyse an active BlueNoroff phishing kit used to impersonate Zoom and Microsoft Teams meetings, revealing source code, infrastructure, malware delivery and victim targeting techniques.
petrk94/smsviewer: A web-based application to parse, view, and manage SMS backup files (XML format) from "SMS Backup & Restore" with advanced features like phone number normalization, contact filtering, and conversation export.
https://github.com/petrk94/smsviewer
🎖@malwr
https://github.com/petrk94/smsviewer
🎖@malwr
GitHub
GitHub - petrk94/smsviewer: A web-based application to parse, view, and manage SMS backup files (XML format) from "SMS Backup &…
A web-based application to parse, view, and manage SMS backup files (XML format) from "SMS Backup & Restore" with advanced features like phone number normalization, contac...
haarisxk/Waypoint: A stealth-focused kernel-mode virtual HID mouse driver for Windows. Built with KMDF and VHF for precise, hardware-level input simulation using covert shared-memory IPC.
https://github.com/haarisxk/Waypoint
🎖@malwr
https://github.com/haarisxk/Waypoint
🎖@malwr
GitHub
GitHub - haarisxk/Waypoint: A stealth-focused kernel-mode virtual HID mouse driver for Windows. Built with KMDF and VHF for precise…
A stealth-focused kernel-mode virtual HID mouse driver for Windows. Built with KMDF and VHF for precise, hardware-level input simulation using covert shared-memory IPC. - haarisxk/Waypoint
❤1
nikaiw/VMkatz: Extract Windows credentials directly from VM memory snapshots and virtual disks
https://github.com/nikaiw/VMkatz
🎖@malwr
https://github.com/nikaiw/VMkatz
🎖@malwr
GitHub
GitHub - nikaiw/VMkatz: Extract Windows credentials directly from VM memory snapshots and virtual disks
Extract Windows credentials directly from VM memory snapshots and virtual disks - nikaiw/VMkatz
xec412/NocturneLdr: A CET-compatible Windows x64 loader that produces fully backed call stacks through runtime function table manipulation, code cave injection, and inverted function table collapse.
https://github.com/xec412/NocturneLdr
🎖@malwr
https://github.com/xec412/NocturneLdr
🎖@malwr
GitHub
GitHub - xec412/NocturneLdr: A CET-compatible Windows x64 loader that produces fully backed call stacks through runtime function…
A CET-compatible Windows x64 loader that produces fully backed call stacks through runtime function table manipulation, code cave injection, and inverted function table collapse. - xec412/NocturneLdr
warpedatom/OffsetInspect: PowerShell toolkit for AMSI/Defender detection-boundary analysis and static malware triage — maps byte offsets to detection triggers, plus YARA, entropy, string, and PE/imphash analysis. Companion to OffsetScan.
https://github.com/warpedatom/OffsetInspect
🎖@malwr
https://github.com/warpedatom/OffsetInspect
🎖@malwr
GitHub
GitHub - warpedatom/OffsetInspect: PowerShell toolkit for AMSI/Defender detection-boundary analysis and static malware triage maps…
PowerShell toolkit for AMSI/Defender detection-boundary analysis and static malware triage maps byte offsets to detection triggers, plus YARA, entropy, string, and PE/imphash analysis. Companion to...
Accelerating EDR Evasion with LLM-Driven Analysis
SpecterOps reverse engineered Cortex XDR with LLMs to extract YARA rules, ML models, and behavioral detections.
https://specterops.io/blog/2026/06/29/llm-powered-edr-analysis/
🎖@malwr
SpecterOps reverse engineered Cortex XDR with LLMs to extract YARA rules, ML models, and behavioral detections.
https://specterops.io/blog/2026/06/29/llm-powered-edr-analysis/
🎖@malwr
SpecterOps
Accelerating EDR Evasion with LLM-Driven Analysis
SpecterOps reverse engineered Cortex XDR with LLMs to extract YARA rules, ML models, and behavioral detections.
Windows Persistence Forensics: Services, Scheduled Tasks, and Autoruns
A DFIR guide to Windows persistence forensics, including services, scheduled tasks, Run keys, autoruns, and what persistence artefacts can and can't prove.
https://sethenoka.com/persistence-artefacts-services-scheduled-tasks-and-intentional-longevity/
🎖@malwr
A DFIR guide to Windows persistence forensics, including services, scheduled tasks, Run keys, autoruns, and what persistence artefacts can and can't prove.
https://sethenoka.com/persistence-artefacts-services-scheduled-tasks-and-intentional-longevity/
🎖@malwr
Seth Enoka – DFIR
Windows Persistence Forensics: Services, Scheduled Tasks, and Autoruns
A DFIR guide to Windows persistence forensics, including services, scheduled tasks, Run keys, autoruns, and what persistence artefacts can and can't prove.
haarisxk/Waypoint: A stealth-focused kernel-mode virtual HID mouse driver for Windows. Built with KMDF and VHF for precise, hardware-level input simulation using covert shared-memory IPC.
https://github.com/haarisxk/Waypoint
🎖@malwr
https://github.com/haarisxk/Waypoint
🎖@malwr
GitHub
GitHub - haarisxk/Waypoint: A stealth-focused kernel-mode virtual HID mouse driver for Windows. Built with KMDF and VHF for precise…
A stealth-focused kernel-mode virtual HID mouse driver for Windows. Built with KMDF and VHF for precise, hardware-level input simulation using covert shared-memory IPC. - haarisxk/Waypoint
❤1
RustyWater: Reverse Engineering MuddyWater’s Rust Toolkit | 0xSec
https://0xsec.gitbook.io/0xsec/malware-analysis/2026-04-23-rustywater
🎖@malwr
https://0xsec.gitbook.io/0xsec/malware-analysis/2026-04-23-rustywater
🎖@malwr
0xsec.gitbook.io
RustyWater: Reverse Engineering MuddyWater’s Rust Toolkit | 0xSec
Random Windows Things Part 2: Unexpected Clipboard Data Behavior – Winsider Seminars & Solutions Inc.
https://windows-internals.com/random-windows-things-part-2-unexpected-clipboard-data-behavior/
🎖@malwr
https://windows-internals.com/random-windows-things-part-2-unexpected-clipboard-data-behavior/
🎖@malwr
PPEE (puppy) 1.14 is released
PPEE (puppy) is a Professional PE file Explorer for reversers, malware researchers and those who want to statically inspect PE files in more details
https://mzrst.com/
PPEE (puppy) is a Professional PE file Explorer for reversers, malware researchers and those who want to statically inspect PE files in more details
- Added another Filter/Search box for bottom listview
- Added section names in Strings and Data directories
- Show list of TLS callcbaks
- Reproducible build hash support
- Show more info about sections in section headers
- Rich Header product id detection extended
https://mzrst.com/
mzrst.com
PPEE - Professional PE Explorer
PPEE (puppy) is a Professional PE file Explorer for reversers, malware researchers and those who want to statically inspect PE files in more details
❤2
zshguy/tyrian-detection-pack: Sigma detections for real ATT&CK techniques, with a compiler that emits Wazuh, Splunk and Sentinel from one source. 36 rules, 33 techniques, MIT.
https://github.com/zshguy/tyrian-detection-pack
🎖@malwr
https://github.com/zshguy/tyrian-detection-pack
🎖@malwr
GitHub
GitHub - zshguy/tyrian-detection-pack: Sigma detections for real ATT&CK techniques, compiled to Wazuh, Splunk and Sentinel from…
Sigma detections for real ATT&CK techniques, compiled to Wazuh, Splunk and Sentinel from one source. 67 rules, 64 techniques, Windows + Linux, ATT&CK Navigator layer, MIT. - zshguy/...