petrk94/smsviewer: A web-based application to parse, view, and manage SMS backup files (XML format) from "SMS Backup & Restore" with advanced features like phone number normalization, contact filtering, and conversation export.
https://github.com/petrk94/smsviewer
🎖@malwr
https://github.com/petrk94/smsviewer
🎖@malwr
GitHub
GitHub - petrk94/smsviewer: A web-based application to parse, view, and manage SMS backup files (XML format) from "SMS Backup &…
A web-based application to parse, view, and manage SMS backup files (XML format) from "SMS Backup & Restore" with advanced features like phone number normalization, contac...
haarisxk/Waypoint: A stealth-focused kernel-mode virtual HID mouse driver for Windows. Built with KMDF and VHF for precise, hardware-level input simulation using covert shared-memory IPC.
https://github.com/haarisxk/Waypoint
🎖@malwr
https://github.com/haarisxk/Waypoint
🎖@malwr
GitHub
GitHub - haarisxk/Waypoint: A stealth-focused kernel-mode virtual HID mouse driver for Windows. Built with KMDF and VHF for precise…
A stealth-focused kernel-mode virtual HID mouse driver for Windows. Built with KMDF and VHF for precise, hardware-level input simulation using covert shared-memory IPC. - haarisxk/Waypoint
❤1
nikaiw/VMkatz: Extract Windows credentials directly from VM memory snapshots and virtual disks
https://github.com/nikaiw/VMkatz
🎖@malwr
https://github.com/nikaiw/VMkatz
🎖@malwr
GitHub
GitHub - nikaiw/VMkatz: Extract Windows credentials directly from VM memory snapshots and virtual disks
Extract Windows credentials directly from VM memory snapshots and virtual disks - nikaiw/VMkatz
xec412/NocturneLdr: A CET-compatible Windows x64 loader that produces fully backed call stacks through runtime function table manipulation, code cave injection, and inverted function table collapse.
https://github.com/xec412/NocturneLdr
🎖@malwr
https://github.com/xec412/NocturneLdr
🎖@malwr
GitHub
GitHub - xec412/NocturneLdr: A CET-compatible Windows x64 loader that produces fully backed call stacks through runtime function…
A CET-compatible Windows x64 loader that produces fully backed call stacks through runtime function table manipulation, code cave injection, and inverted function table collapse. - xec412/NocturneLdr
warpedatom/OffsetInspect: PowerShell toolkit for AMSI/Defender detection-boundary analysis and static malware triage — maps byte offsets to detection triggers, plus YARA, entropy, string, and PE/imphash analysis. Companion to OffsetScan.
https://github.com/warpedatom/OffsetInspect
🎖@malwr
https://github.com/warpedatom/OffsetInspect
🎖@malwr
GitHub
GitHub - warpedatom/OffsetInspect: PowerShell toolkit for AMSI/Defender detection-boundary analysis and static malware triage maps…
PowerShell toolkit for AMSI/Defender detection-boundary analysis and static malware triage maps byte offsets to detection triggers, plus YARA, entropy, string, and PE/imphash analysis. Companion to...
Accelerating EDR Evasion with LLM-Driven Analysis
SpecterOps reverse engineered Cortex XDR with LLMs to extract YARA rules, ML models, and behavioral detections.
https://specterops.io/blog/2026/06/29/llm-powered-edr-analysis/
🎖@malwr
SpecterOps reverse engineered Cortex XDR with LLMs to extract YARA rules, ML models, and behavioral detections.
https://specterops.io/blog/2026/06/29/llm-powered-edr-analysis/
🎖@malwr
SpecterOps
Accelerating EDR Evasion with LLM-Driven Analysis
SpecterOps reverse engineered Cortex XDR with LLMs to extract YARA rules, ML models, and behavioral detections.
Windows Persistence Forensics: Services, Scheduled Tasks, and Autoruns
A DFIR guide to Windows persistence forensics, including services, scheduled tasks, Run keys, autoruns, and what persistence artefacts can and can't prove.
https://sethenoka.com/persistence-artefacts-services-scheduled-tasks-and-intentional-longevity/
🎖@malwr
A DFIR guide to Windows persistence forensics, including services, scheduled tasks, Run keys, autoruns, and what persistence artefacts can and can't prove.
https://sethenoka.com/persistence-artefacts-services-scheduled-tasks-and-intentional-longevity/
🎖@malwr
Seth Enoka – DFIR
Windows Persistence Forensics: Services, Scheduled Tasks, and Autoruns
A DFIR guide to Windows persistence forensics, including services, scheduled tasks, Run keys, autoruns, and what persistence artefacts can and can't prove.
haarisxk/Waypoint: A stealth-focused kernel-mode virtual HID mouse driver for Windows. Built with KMDF and VHF for precise, hardware-level input simulation using covert shared-memory IPC.
https://github.com/haarisxk/Waypoint
🎖@malwr
https://github.com/haarisxk/Waypoint
🎖@malwr
GitHub
GitHub - haarisxk/Waypoint: A stealth-focused kernel-mode virtual HID mouse driver for Windows. Built with KMDF and VHF for precise…
A stealth-focused kernel-mode virtual HID mouse driver for Windows. Built with KMDF and VHF for precise, hardware-level input simulation using covert shared-memory IPC. - haarisxk/Waypoint
❤1
RustyWater: Reverse Engineering MuddyWater’s Rust Toolkit | 0xSec
https://0xsec.gitbook.io/0xsec/malware-analysis/2026-04-23-rustywater
🎖@malwr
https://0xsec.gitbook.io/0xsec/malware-analysis/2026-04-23-rustywater
🎖@malwr
0xsec.gitbook.io
RustyWater: Reverse Engineering MuddyWater’s Rust Toolkit | 0xSec
Random Windows Things Part 2: Unexpected Clipboard Data Behavior – Winsider Seminars & Solutions Inc.
https://windows-internals.com/random-windows-things-part-2-unexpected-clipboard-data-behavior/
🎖@malwr
https://windows-internals.com/random-windows-things-part-2-unexpected-clipboard-data-behavior/
🎖@malwr
PPEE (puppy) 1.14 is released
PPEE (puppy) is a Professional PE file Explorer for reversers, malware researchers and those who want to statically inspect PE files in more details
https://mzrst.com/
PPEE (puppy) is a Professional PE file Explorer for reversers, malware researchers and those who want to statically inspect PE files in more details
- Added another Filter/Search box for bottom listview
- Added section names in Strings and Data directories
- Show list of TLS callcbaks
- Reproducible build hash support
- Show more info about sections in section headers
- Rich Header product id detection extended
https://mzrst.com/
mzrst.com
PPEE - Professional PE Explorer
PPEE (puppy) is a Professional PE file Explorer for reversers, malware researchers and those who want to statically inspect PE files in more details
❤2
zshguy/tyrian-detection-pack: Sigma detections for real ATT&CK techniques, with a compiler that emits Wazuh, Splunk and Sentinel from one source. 36 rules, 33 techniques, MIT.
https://github.com/zshguy/tyrian-detection-pack
🎖@malwr
https://github.com/zshguy/tyrian-detection-pack
🎖@malwr
GitHub
GitHub - zshguy/tyrian-detection-pack: Sigma detections for real ATT&CK techniques, compiled to Wazuh, Splunk and Sentinel from…
Sigma detections for real ATT&CK techniques, compiled to Wazuh, Splunk and Sentinel from one source. 67 rules, 64 techniques, Windows + Linux, ATT&CK Navigator layer, MIT. - zshguy/...
The Telegram Malware Ecosystem
A 9,898-row intelligence collection built from Telegram bot tokens and chat IDs leaking out of malware on VirusTotal, enriched, clustered, and mined for attribution.
https://ransom-isac.org/blog/the-telegram-malware-ecosystem/
🎖@malwr
A 9,898-row intelligence collection built from Telegram bot tokens and chat IDs leaking out of malware on VirusTotal, enriched, clustered, and mined for attribution.
https://ransom-isac.org/blog/the-telegram-malware-ecosystem/
🎖@malwr
Ransom-ISAC
The Telegram Malware Ecosystem
A 9,898-row intelligence collection built from Telegram bot tokens and chat IDs leaking out of malware on VirusTotal.
https://www.catonetworks.com/blog/cato-ctrl-silverfox-evolves/
Cato CTRL™ Threat Research: SilverFox Evolves: Abuse of New Drivers and Trusted Software Hijacking Enable Remote Access with ValleyRAT in Japan
🎖@malwr
Cato CTRL™ Threat Research: SilverFox Evolves: Abuse of New Drivers and Trusted Software Hijacking Enable Remote Access with ValleyRAT in Japan
🎖@malwr
Case Study: Targeted Attack Case on an MS-SQL Server Involving the Installation of GotoHTTP and SoftEther VPN - ASEC
Case Study: Targeted Attack Case on an MS-SQL Server Involving the Installation of GotoHTTP and SoftEther VPN ASEC
https://asec.ahnlab.com/en/94685/
🎖@malwr
Case Study: Targeted Attack Case on an MS-SQL Server Involving the Installation of GotoHTTP and SoftEther VPN ASEC
https://asec.ahnlab.com/en/94685/
🎖@malwr
ASEC
Case Study: Targeted Attack Case on an MS-SQL Server Involving the Installation of GotoHTTP and SoftEther VPN - ASEC
Case Study: Targeted Attack Case on an MS-SQL Server Involving the Installation of GotoHTTP and SoftEther VPN ASEC
Tengu: A Modernized Mirai That Doesn’t Want to Leave
Analysis of tengu, an advanced Mirai-derived IoT malware family with encrypted C2, proxy support, DDoS capabilities, persistence, anti-analysis, and self-defense features.
https://www.nozominetworks.com/blog/tengu-a-modernized-mirai-that-doesnt-want-to-leave
🎖@malwr
Analysis of tengu, an advanced Mirai-derived IoT malware family with encrypted C2, proxy support, DDoS capabilities, persistence, anti-analysis, and self-defense features.
https://www.nozominetworks.com/blog/tengu-a-modernized-mirai-that-doesnt-want-to-leave
🎖@malwr
Nozominetworks
Tengu: A Modernized Mirai That Doesn’t Want to Leave
Analysis of tengu, an advanced Mirai-derived IoT malware family with encrypted C2, proxy support, DDoS capabilities, persistence, anti-analysis, and self-defense features.
Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident
We’re on a journey to advance and democratize artificial intelligence through open source and open science.
https://huggingface.co/blog/agent-intrusion-technical-timeline
🎖@malwr
We’re on a journey to advance and democratize artificial intelligence through open source and open science.
https://huggingface.co/blog/agent-intrusion-technical-timeline
🎖@malwr
huggingface.co
Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident
We’re on a journey to advance and democratize artificial intelligence through open source and open science.
❤1
Through the Lens of MDR: Analysis of KongTuke’s ClickFix Abuse of Compromised WordPress Sites
Our analysis of an active KongTuke campaign deploying modeloRAT — malware capable of reconnaissance, command execution, and persistent access — through compromised WordPress sites and fake CAPTCHA lures shows that the group still operates this delivery chain in parallel with the newer CrashFix technique.
https://www.trendmicro.com/en_us/research/26/c/kongtuke-clickfix-abuse-of-compromised-wordpress-sites.html
🎖@malwr
Our analysis of an active KongTuke campaign deploying modeloRAT — malware capable of reconnaissance, command execution, and persistent access — through compromised WordPress sites and fake CAPTCHA lures shows that the group still operates this delivery chain in parallel with the newer CrashFix technique.
https://www.trendmicro.com/en_us/research/26/c/kongtuke-clickfix-abuse-of-compromised-wordpress-sites.html
🎖@malwr
Trend Micro
Through the Lens of MDR: Analysis of KongTuke’s ClickFix Abuse of Compromised WordPress Sites
Our analysis of an active KongTuke campaign deploying modeloRAT — malware capable of reconnaissance, command execution, and persistent access — through compromised WordPress sites and fake CAPTCHA lures shows that the group still operates this delivery chain…
❤1
Technical Analysis of GoGRPC | ThreatLabz
A threat actor likely associated with ransomware is using Microsoft Teams vishing and Quick Assist to deliver new backdoors and proxy tools.
https://www.zscaler.com/blogs/security-research/helpdesk-hijackers-teams-vishing-quick-assist-and-gogrpc-backdoor
🎖@malwr
A threat actor likely associated with ransomware is using Microsoft Teams vishing and Quick Assist to deliver new backdoors and proxy tools.
https://www.zscaler.com/blogs/security-research/helpdesk-hijackers-teams-vishing-quick-assist-and-gogrpc-backdoor
🎖@malwr
Zscaler
Technical Analysis of GoGRPC | ThreatLabz
A threat actor likely associated with ransomware is using Microsoft Teams vishing and Quick Assist to deliver new backdoors and proxy tools.