TAG-195 Upgrades MaaS Ecosystem with Modular Tools
Insikt Group identifies four new TAG-195 malware families, revealing an architectural transition toward modular, operator-driven tooling in the MaaS ecosystem
https://www.recordedfuture.com/research/tag-195-evolves-maas-ecosystem
https://assets.recordedfuture.com/insikt-report-pdfs/2026/cta-2026-0723.pdf
🎖@malwr
Insikt Group identifies four new TAG-195 malware families, revealing an architectural transition toward modular, operator-driven tooling in the MaaS ecosystem
https://www.recordedfuture.com/research/tag-195-evolves-maas-ecosystem
https://assets.recordedfuture.com/insikt-report-pdfs/2026/cta-2026-0723.pdf
🎖@malwr
Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged
An exposed open directory on a Hong Kong server revealed an autonomous AI agent running unattended, an unreported Go implant, and target-specific tooling used against Thailand's Ministry of Finance.
https://hunt.io/blog/thailand-ministry-finance-targeted-with-hermes-ai-agent
🎖@malwr
An exposed open directory on a Hong Kong server revealed an autonomous AI agent running unattended, an unreported Go implant, and target-specific tooling used against Thailand's Ministry of Finance.
https://hunt.io/blog/thailand-ministry-finance-targeted-with-hermes-ai-agent
🎖@malwr
hunt.io
Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged
An exposed open directory on a Hong Kong server revealed an autonomous AI agent running unattended, an unreported Go implant, and target-specific tooling used against Thailand's Ministry of Finance.
oxasploits/PacketSnitch: PacketSnitch is a network analysis platform that transforms packet captures into searchable, protocol-aware intelligence, helping security professionals, developers, and researchers rapidly uncover hosts, credentials, certificates, files, locations, protocols, anomalies, threat intel, and other actionable insights.
https://github.com/oxasploits/PacketSnitch
🎖@malwr
https://github.com/oxasploits/PacketSnitch
🎖@malwr
❤1
Analysis of Kimsuky's Attack on a South Korean Groupware Vendor Using a New Gomir Family Variant | Enki White Hat
Analysis of Kimsuky's Attack on a South Korean Groupware Vendor Using a New Gomir Family Variant
https://www.enki.co.kr/en/media-center/blog/analysis-of-kimsuky-s-attack-on-a-south-korean-groupware-vendor-using-a-new-gomir-family-variant
🎖@malwr
Analysis of Kimsuky's Attack on a South Korean Groupware Vendor Using a New Gomir Family Variant
https://www.enki.co.kr/en/media-center/blog/analysis-of-kimsuky-s-attack-on-a-south-korean-groupware-vendor-using-a-new-gomir-family-variant
🎖@malwr
www.enki.co.kr
Analysis of Kimsuky's Attack on a South Korean Groupware Vendor Using a New Gomir Family Variant | Enki White Hat
Windows Data Deduplication // Noir Trace Writeups
A Forensic Investigation into Windows Data Deduplication [The Vanishing File]
https://7h3kn0w3r.github.io/blog/windows-data-deduplication/
https://github.com/7h3kn0w3r/DedupInspector
🎖@malwr
A Forensic Investigation into Windows Data Deduplication [The Vanishing File]
https://7h3kn0w3r.github.io/blog/windows-data-deduplication/
https://github.com/7h3kn0w3r/DedupInspector
🎖@malwr
7h3kn0w3r.github.io
Windows Data Deduplication // Noir Trace Writeups
A Forensic Investigation into Windows Data Deduplication [The Vanishing File]
❤2
Inside a DPRK BlueNoroff ClickFix Kit | JUMPSEC
JUMPSEC threat intelligence reveals how Iran‑aligned MuddyWater uses Russian malware‑as‑a‑service and blockchain C2, blurring cybercrime and nation‑state espionage.
https://www.jumpsec.com/guides/inside-a-dprk-bluenoroff-clickfix-kit/
🎖@malwr
JUMPSEC threat intelligence reveals how Iran‑aligned MuddyWater uses Russian malware‑as‑a‑service and blockchain C2, blurring cybercrime and nation‑state espionage.
https://www.jumpsec.com/guides/inside-a-dprk-bluenoroff-clickfix-kit/
🎖@malwr
JUMPSEC
Inside a DPRK BlueNoroff ClickFix Kit | JUMPSEC
JUMPSEC researchers analyse an active BlueNoroff phishing kit used to impersonate Zoom and Microsoft Teams meetings, revealing source code, infrastructure, malware delivery and victim targeting techniques.
petrk94/smsviewer: A web-based application to parse, view, and manage SMS backup files (XML format) from "SMS Backup & Restore" with advanced features like phone number normalization, contact filtering, and conversation export.
https://github.com/petrk94/smsviewer
🎖@malwr
https://github.com/petrk94/smsviewer
🎖@malwr
GitHub
GitHub - petrk94/smsviewer: A web-based application to parse, view, and manage SMS backup files (XML format) from "SMS Backup &…
A web-based application to parse, view, and manage SMS backup files (XML format) from "SMS Backup & Restore" with advanced features like phone number normalization, contac...
haarisxk/Waypoint: A stealth-focused kernel-mode virtual HID mouse driver for Windows. Built with KMDF and VHF for precise, hardware-level input simulation using covert shared-memory IPC.
https://github.com/haarisxk/Waypoint
🎖@malwr
https://github.com/haarisxk/Waypoint
🎖@malwr
GitHub
GitHub - haarisxk/Waypoint: A stealth-focused kernel-mode virtual HID mouse driver for Windows. Built with KMDF and VHF for precise…
A stealth-focused kernel-mode virtual HID mouse driver for Windows. Built with KMDF and VHF for precise, hardware-level input simulation using covert shared-memory IPC. - haarisxk/Waypoint
❤1
nikaiw/VMkatz: Extract Windows credentials directly from VM memory snapshots and virtual disks
https://github.com/nikaiw/VMkatz
🎖@malwr
https://github.com/nikaiw/VMkatz
🎖@malwr
GitHub
GitHub - nikaiw/VMkatz: Extract Windows credentials directly from VM memory snapshots and virtual disks
Extract Windows credentials directly from VM memory snapshots and virtual disks - nikaiw/VMkatz
xec412/NocturneLdr: A CET-compatible Windows x64 loader that produces fully backed call stacks through runtime function table manipulation, code cave injection, and inverted function table collapse.
https://github.com/xec412/NocturneLdr
🎖@malwr
https://github.com/xec412/NocturneLdr
🎖@malwr
GitHub
GitHub - xec412/NocturneLdr: A CET-compatible Windows x64 loader that produces fully backed call stacks through runtime function…
A CET-compatible Windows x64 loader that produces fully backed call stacks through runtime function table manipulation, code cave injection, and inverted function table collapse. - xec412/NocturneLdr
warpedatom/OffsetInspect: PowerShell toolkit for AMSI/Defender detection-boundary analysis and static malware triage — maps byte offsets to detection triggers, plus YARA, entropy, string, and PE/imphash analysis. Companion to OffsetScan.
https://github.com/warpedatom/OffsetInspect
🎖@malwr
https://github.com/warpedatom/OffsetInspect
🎖@malwr
GitHub
GitHub - warpedatom/OffsetInspect: PowerShell toolkit for AMSI/Defender detection-boundary analysis and static malware triage maps…
PowerShell toolkit for AMSI/Defender detection-boundary analysis and static malware triage maps byte offsets to detection triggers, plus YARA, entropy, string, and PE/imphash analysis. Companion to...
Accelerating EDR Evasion with LLM-Driven Analysis
SpecterOps reverse engineered Cortex XDR with LLMs to extract YARA rules, ML models, and behavioral detections.
https://specterops.io/blog/2026/06/29/llm-powered-edr-analysis/
🎖@malwr
SpecterOps reverse engineered Cortex XDR with LLMs to extract YARA rules, ML models, and behavioral detections.
https://specterops.io/blog/2026/06/29/llm-powered-edr-analysis/
🎖@malwr
SpecterOps
Accelerating EDR Evasion with LLM-Driven Analysis
SpecterOps reverse engineered Cortex XDR with LLMs to extract YARA rules, ML models, and behavioral detections.
Windows Persistence Forensics: Services, Scheduled Tasks, and Autoruns
A DFIR guide to Windows persistence forensics, including services, scheduled tasks, Run keys, autoruns, and what persistence artefacts can and can't prove.
https://sethenoka.com/persistence-artefacts-services-scheduled-tasks-and-intentional-longevity/
🎖@malwr
A DFIR guide to Windows persistence forensics, including services, scheduled tasks, Run keys, autoruns, and what persistence artefacts can and can't prove.
https://sethenoka.com/persistence-artefacts-services-scheduled-tasks-and-intentional-longevity/
🎖@malwr
Seth Enoka – DFIR
Windows Persistence Forensics: Services, Scheduled Tasks, and Autoruns
A DFIR guide to Windows persistence forensics, including services, scheduled tasks, Run keys, autoruns, and what persistence artefacts can and can't prove.
haarisxk/Waypoint: A stealth-focused kernel-mode virtual HID mouse driver for Windows. Built with KMDF and VHF for precise, hardware-level input simulation using covert shared-memory IPC.
https://github.com/haarisxk/Waypoint
🎖@malwr
https://github.com/haarisxk/Waypoint
🎖@malwr
GitHub
GitHub - haarisxk/Waypoint: A stealth-focused kernel-mode virtual HID mouse driver for Windows. Built with KMDF and VHF for precise…
A stealth-focused kernel-mode virtual HID mouse driver for Windows. Built with KMDF and VHF for precise, hardware-level input simulation using covert shared-memory IPC. - haarisxk/Waypoint
❤1
RustyWater: Reverse Engineering MuddyWater’s Rust Toolkit | 0xSec
https://0xsec.gitbook.io/0xsec/malware-analysis/2026-04-23-rustywater
🎖@malwr
https://0xsec.gitbook.io/0xsec/malware-analysis/2026-04-23-rustywater
🎖@malwr
0xsec.gitbook.io
RustyWater: Reverse Engineering MuddyWater’s Rust Toolkit | 0xSec
Random Windows Things Part 2: Unexpected Clipboard Data Behavior – Winsider Seminars & Solutions Inc.
https://windows-internals.com/random-windows-things-part-2-unexpected-clipboard-data-behavior/
🎖@malwr
https://windows-internals.com/random-windows-things-part-2-unexpected-clipboard-data-behavior/
🎖@malwr
PPEE (puppy) 1.14 is released
PPEE (puppy) is a Professional PE file Explorer for reversers, malware researchers and those who want to statically inspect PE files in more details
https://mzrst.com/
PPEE (puppy) is a Professional PE file Explorer for reversers, malware researchers and those who want to statically inspect PE files in more details
- Added another Filter/Search box for bottom listview
- Added section names in Strings and Data directories
- Show list of TLS callcbaks
- Reproducible build hash support
- Show more info about sections in section headers
- Rich Header product id detection extended
https://mzrst.com/
mzrst.com
PPEE - Professional PE Explorer
PPEE (puppy) is a Professional PE file Explorer for reversers, malware researchers and those who want to statically inspect PE files in more details
❤2
zshguy/tyrian-detection-pack: Sigma detections for real ATT&CK techniques, with a compiler that emits Wazuh, Splunk and Sentinel from one source. 36 rules, 33 techniques, MIT.
https://github.com/zshguy/tyrian-detection-pack
🎖@malwr
https://github.com/zshguy/tyrian-detection-pack
🎖@malwr
GitHub
GitHub - zshguy/tyrian-detection-pack: Sigma detections for real ATT&CK techniques, compiled to Wazuh, Splunk and Sentinel from…
Sigma detections for real ATT&CK techniques, compiled to Wazuh, Splunk and Sentinel from one source. 67 rules, 64 techniques, Windows + Linux, ATT&CK Navigator layer, MIT. - zshguy/...
The Telegram Malware Ecosystem
A 9,898-row intelligence collection built from Telegram bot tokens and chat IDs leaking out of malware on VirusTotal, enriched, clustered, and mined for attribution.
https://ransom-isac.org/blog/the-telegram-malware-ecosystem/
🎖@malwr
A 9,898-row intelligence collection built from Telegram bot tokens and chat IDs leaking out of malware on VirusTotal, enriched, clustered, and mined for attribution.
https://ransom-isac.org/blog/the-telegram-malware-ecosystem/
🎖@malwr
Ransom-ISAC
The Telegram Malware Ecosystem
A 9,898-row intelligence collection built from Telegram bot tokens and chat IDs leaking out of malware on VirusTotal.