Malware News
16.2K subscribers
1.64K photos
7 videos
130 files
8.31K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
Analysis of Kimsuky's Attack on a South Korean Groupware Vendor Using a New Gomir Family Variant | Enki White Hat
Analysis of Kimsuky's Attack on a South Korean Groupware Vendor Using a New Gomir Family Variant

https://www.enki.co.kr/en/media-center/blog/analysis-of-kimsuky-s-attack-on-a-south-korean-groupware-vendor-using-a-new-gomir-family-variant


🎖@malwr
Inside a DPRK BlueNoroff ClickFix Kit | JUMPSEC
JUMPSEC threat intelligence reveals how Iran‑aligned MuddyWater uses Russian malware‑as‑a‑service and blockchain C2, blurring cybercrime and nation‑state espionage.

https://www.jumpsec.com/guides/inside-a-dprk-bluenoroff-clickfix-kit/


🎖@malwr
As a reminder: We take ads

@SirMalware
Accelerating EDR Evasion with LLM-Driven Analysis
SpecterOps reverse engineered Cortex XDR with LLMs to extract YARA rules, ML models, and behavioral detections.

https://specterops.io/blog/2026/06/29/llm-powered-edr-analysis/


🎖@malwr
Random Windows Things Part 2: Unexpected Clipboard Data Behavior – Winsider Seminars & Solutions Inc.
https://windows-internals.com/random-windows-things-part-2-unexpected-clipboard-data-behavior/


🎖@malwr
PPEE (puppy) 1.14 is released

PPEE (puppy) is a Professional PE file Explorer for reversers, malware researchers and those who want to statically inspect PE files in more details
- Added another Filter/Search box for bottom listview
- Added section names in Strings and Data directories
- Show list of TLS callcbaks
- Reproducible build hash support
- Show more info about sections in section headers
- Rich Header product id detection extended


https://mzrst.com/
2
The Telegram Malware Ecosystem
A 9,898-row intelligence collection built from Telegram bot tokens and chat IDs leaking out of malware on VirusTotal, enriched, clustered, and mined for attribution.

https://ransom-isac.org/blog/the-telegram-malware-ecosystem/


🎖@malwr
https://www.catonetworks.com/blog/cato-ctrl-silverfox-evolves/

Cato CTRL Threat Research: SilverFox Evolves: Abuse of New Drivers and Trusted Software Hijacking Enable Remote Access with ValleyRAT in Japan


🎖@malwr
Case Study: Targeted Attack Case on an MS-SQL Server Involving the Installation of GotoHTTP and SoftEther VPN - ASEC
Case Study: Targeted Attack Case on an MS-SQL Server Involving the Installation of GotoHTTP and SoftEther VPN ASEC

https://asec.ahnlab.com/en/94685/


🎖@malwr
Tengu: A Modernized Mirai That Doesn’t Want to Leave
Analysis of tengu, an advanced Mirai-derived IoT malware family with encrypted C2, proxy support, DDoS capabilities, persistence, anti-analysis, and self-defense features.

https://www.nozominetworks.com/blog/tengu-a-modernized-mirai-that-doesnt-want-to-leave


🎖@malwr