Malware News
16.2K subscribers
1.64K photos
7 videos
130 files
8.31K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
Random Windows Things Part 2: Unexpected Clipboard Data Behavior – Winsider Seminars & Solutions Inc.
https://windows-internals.com/random-windows-things-part-2-unexpected-clipboard-data-behavior/


🎖@malwr
PPEE (puppy) 1.14 is released

PPEE (puppy) is a Professional PE file Explorer for reversers, malware researchers and those who want to statically inspect PE files in more details
- Added another Filter/Search box for bottom listview
- Added section names in Strings and Data directories
- Show list of TLS callcbaks
- Reproducible build hash support
- Show more info about sections in section headers
- Rich Header product id detection extended


https://mzrst.com/
2
The Telegram Malware Ecosystem
A 9,898-row intelligence collection built from Telegram bot tokens and chat IDs leaking out of malware on VirusTotal, enriched, clustered, and mined for attribution.

https://ransom-isac.org/blog/the-telegram-malware-ecosystem/


🎖@malwr
https://www.catonetworks.com/blog/cato-ctrl-silverfox-evolves/

Cato CTRL Threat Research: SilverFox Evolves: Abuse of New Drivers and Trusted Software Hijacking Enable Remote Access with ValleyRAT in Japan


🎖@malwr
Case Study: Targeted Attack Case on an MS-SQL Server Involving the Installation of GotoHTTP and SoftEther VPN - ASEC
Case Study: Targeted Attack Case on an MS-SQL Server Involving the Installation of GotoHTTP and SoftEther VPN ASEC

https://asec.ahnlab.com/en/94685/


🎖@malwr
Tengu: A Modernized Mirai That Doesn’t Want to Leave
Analysis of tengu, an advanced Mirai-derived IoT malware family with encrypted C2, proxy support, DDoS capabilities, persistence, anti-analysis, and self-defense features.

https://www.nozominetworks.com/blog/tengu-a-modernized-mirai-that-doesnt-want-to-leave


🎖@malwr
Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident
We’re on a journey to advance and democratize artificial intelligence through open source and open science.

https://huggingface.co/blog/agent-intrusion-technical-timeline


🎖@malwr
1
Through the Lens of MDR: Analysis of KongTuke’s ClickFix Abuse of Compromised WordPress Sites

Our analysis of an active KongTuke campaign deploying modeloRAT — malware capable of reconnaissance, command execution, and persistent access — through compromised WordPress sites and fake CAPTCHA lures shows that the group still operates this delivery chain in parallel with the newer CrashFix technique.

https://www.trendmicro.com/en_us/research/26/c/kongtuke-clickfix-abuse-of-compromised-wordpress-sites.html


🎖@malwr
1
https://core-jmp.org/2026/07/sakdriver-reversing-kernel-driver-rootkit/

A reverse-engineering walkthrough of SakDriver, a Windows kernel-mode rootkit first mistaken for a Cobalt Strike Beacon. It patches ETW, hides processes via DKOM, masquerades as a minifilter and a fake Microsoft service, and — most notably — receives C2 commands through the Windows registry. Includes the full recovered command table, IOCs and a matching YARA figure.



🎖@malwr
Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit | Proofpoint US
Threat Research would like to thank the Proofpoint Cloudmark Authority team for their collaboration. Key Findings On 22 July 2026, one day prior to Proofpoint’s recent joint release

https://www.proofpoint.com/us/blog/threat-insight/cleaning-out-inboxes-ta488-comes-outlook-another-half-click-exploit


🎖@malwr
1
Kuna — an agent-first decompiler
Kuna is a self-refining decompiler built to be used by agents: loosely based on Ghidra's decompiler, written in Rust, and runnable from the CLI, inside Ghidra, or entirely in the browser.

https://kuna.noelo.org/


🎖@malwr
icedracon/adhammer: Active Directory security-assessment toolkit in Rust — PingCastle-class audit + authorized red-team validation, on a from-scratch DCE/RPC · NTLM · SMB2 · Kerberos stack. One static binary, from Kali or Windows.

https://github.com/icedracon/adhammer


🎖@malwr
👍1
Inside the OS-Aware Phishing Kit Profiling Your Device
A sophisticated phishing kit reads victim operating systems to deploy tailored attacks—from fake RMM installs to live AiTM credential harvesting.

https://blog.knowbe4.com/inside-os-aware-phishing-kit-profiling-your-device


🎖@malwr
zhaoxuya520/reverse-skill: Reverse Engineering / Authorized Penetration Testing / Security Research Skill Router Pack AI-powered routing + On-demand toolchain bootstrapping + Self-evolving knowledge base Supports Claude Code, Kiro, Cursor, Cline, and other AI coding clients 逆向/渗透/安全技能路由包 - AI 自动路由 + 按需自举工具链 + 自动进化经验库 | 支持 Claude Code / Kiro / Cursor / Cline 等代码 AI 客户端

https://github.com/zhaoxuya520/reverse-skill#about


🎖@malwr
1