zshguy/tyrian-detection-pack: Sigma detections for real ATT&CK techniques, with a compiler that emits Wazuh, Splunk and Sentinel from one source. 36 rules, 33 techniques, MIT.
https://github.com/zshguy/tyrian-detection-pack
🎖@malwr
https://github.com/zshguy/tyrian-detection-pack
🎖@malwr
GitHub
GitHub - zshguy/tyrian-detection-pack: Sigma detections for real ATT&CK techniques, compiled to Wazuh, Splunk and Sentinel from…
Sigma detections for real ATT&CK techniques, compiled to Wazuh, Splunk and Sentinel from one source. 67 rules, 64 techniques, Windows + Linux, ATT&CK Navigator layer, MIT. - zshguy/...
The Telegram Malware Ecosystem
A 9,898-row intelligence collection built from Telegram bot tokens and chat IDs leaking out of malware on VirusTotal, enriched, clustered, and mined for attribution.
https://ransom-isac.org/blog/the-telegram-malware-ecosystem/
🎖@malwr
A 9,898-row intelligence collection built from Telegram bot tokens and chat IDs leaking out of malware on VirusTotal, enriched, clustered, and mined for attribution.
https://ransom-isac.org/blog/the-telegram-malware-ecosystem/
🎖@malwr
Ransom-ISAC
The Telegram Malware Ecosystem
A 9,898-row intelligence collection built from Telegram bot tokens and chat IDs leaking out of malware on VirusTotal.
https://www.catonetworks.com/blog/cato-ctrl-silverfox-evolves/
Cato CTRL™ Threat Research: SilverFox Evolves: Abuse of New Drivers and Trusted Software Hijacking Enable Remote Access with ValleyRAT in Japan
🎖@malwr
Cato CTRL™ Threat Research: SilverFox Evolves: Abuse of New Drivers and Trusted Software Hijacking Enable Remote Access with ValleyRAT in Japan
🎖@malwr
Case Study: Targeted Attack Case on an MS-SQL Server Involving the Installation of GotoHTTP and SoftEther VPN - ASEC
Case Study: Targeted Attack Case on an MS-SQL Server Involving the Installation of GotoHTTP and SoftEther VPN ASEC
https://asec.ahnlab.com/en/94685/
🎖@malwr
Case Study: Targeted Attack Case on an MS-SQL Server Involving the Installation of GotoHTTP and SoftEther VPN ASEC
https://asec.ahnlab.com/en/94685/
🎖@malwr
ASEC
Case Study: Targeted Attack Case on an MS-SQL Server Involving the Installation of GotoHTTP and SoftEther VPN - ASEC
Case Study: Targeted Attack Case on an MS-SQL Server Involving the Installation of GotoHTTP and SoftEther VPN ASEC
Tengu: A Modernized Mirai That Doesn’t Want to Leave
Analysis of tengu, an advanced Mirai-derived IoT malware family with encrypted C2, proxy support, DDoS capabilities, persistence, anti-analysis, and self-defense features.
https://www.nozominetworks.com/blog/tengu-a-modernized-mirai-that-doesnt-want-to-leave
🎖@malwr
Analysis of tengu, an advanced Mirai-derived IoT malware family with encrypted C2, proxy support, DDoS capabilities, persistence, anti-analysis, and self-defense features.
https://www.nozominetworks.com/blog/tengu-a-modernized-mirai-that-doesnt-want-to-leave
🎖@malwr
Nozominetworks
Tengu: A Modernized Mirai That Doesn’t Want to Leave
Analysis of tengu, an advanced Mirai-derived IoT malware family with encrypted C2, proxy support, DDoS capabilities, persistence, anti-analysis, and self-defense features.
Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident
We’re on a journey to advance and democratize artificial intelligence through open source and open science.
https://huggingface.co/blog/agent-intrusion-technical-timeline
🎖@malwr
We’re on a journey to advance and democratize artificial intelligence through open source and open science.
https://huggingface.co/blog/agent-intrusion-technical-timeline
🎖@malwr
huggingface.co
Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident
We’re on a journey to advance and democratize artificial intelligence through open source and open science.
❤1
Through the Lens of MDR: Analysis of KongTuke’s ClickFix Abuse of Compromised WordPress Sites
Our analysis of an active KongTuke campaign deploying modeloRAT — malware capable of reconnaissance, command execution, and persistent access — through compromised WordPress sites and fake CAPTCHA lures shows that the group still operates this delivery chain in parallel with the newer CrashFix technique.
https://www.trendmicro.com/en_us/research/26/c/kongtuke-clickfix-abuse-of-compromised-wordpress-sites.html
🎖@malwr
Our analysis of an active KongTuke campaign deploying modeloRAT — malware capable of reconnaissance, command execution, and persistent access — through compromised WordPress sites and fake CAPTCHA lures shows that the group still operates this delivery chain in parallel with the newer CrashFix technique.
https://www.trendmicro.com/en_us/research/26/c/kongtuke-clickfix-abuse-of-compromised-wordpress-sites.html
🎖@malwr
Trend Micro
Through the Lens of MDR: Analysis of KongTuke’s ClickFix Abuse of Compromised WordPress Sites
Our analysis of an active KongTuke campaign deploying modeloRAT — malware capable of reconnaissance, command execution, and persistent access — through compromised WordPress sites and fake CAPTCHA lures shows that the group still operates this delivery chain…
❤1
Technical Analysis of GoGRPC | ThreatLabz
A threat actor likely associated with ransomware is using Microsoft Teams vishing and Quick Assist to deliver new backdoors and proxy tools.
https://www.zscaler.com/blogs/security-research/helpdesk-hijackers-teams-vishing-quick-assist-and-gogrpc-backdoor
🎖@malwr
A threat actor likely associated with ransomware is using Microsoft Teams vishing and Quick Assist to deliver new backdoors and proxy tools.
https://www.zscaler.com/blogs/security-research/helpdesk-hijackers-teams-vishing-quick-assist-and-gogrpc-backdoor
🎖@malwr
Zscaler
Technical Analysis of GoGRPC | ThreatLabz
A threat actor likely associated with ransomware is using Microsoft Teams vishing and Quick Assist to deliver new backdoors and proxy tools.
https://core-jmp.org/2026/07/sakdriver-reversing-kernel-driver-rootkit/
🎖@malwr
A reverse-engineering walkthrough of SakDriver, a Windows kernel-mode rootkit first mistaken for a Cobalt Strike Beacon. It patches ETW, hides processes via DKOM, masquerades as a minifilter and a fake Microsoft service, and — most notably — receives C2 commands through the Windows registry. Includes the full recovered command table, IOCs and a matching YARA figure.
🎖@malwr
core-jmp
SakDriver: Reversing a Windows Kernel Driver Rootkit
A reverse-engineering walkthrough of SakDriver, a Windows kernel-mode rootkit first mistaken for a Cobalt Strike Beacon. It patches ETW, hides processes via DKOM, masquerades as a minifilter and a fake Microsoft service, and — most notably — receives C2 commands…
[Joint Cybersecurity Advisory] Operation Double Barrel (The Relationship Between a State-Sponsored Threat Actor and the Gunra Ransomware Group) - ASEC
https://asec.ahnlab.com/en/94696/
https://image.ahnlab.com/atip/content/file/20260730/[AhnLab]Operation%20Double%20Barrel(ENG)(2026.07.30).pdf
🎖@malwr
https://asec.ahnlab.com/en/94696/
https://image.ahnlab.com/atip/content/file/20260730/[AhnLab]Operation%20Double%20Barrel(ENG)(2026.07.30).pdf
🎖@malwr
ASEC
[Joint Cybersecurity Advisory] Operation Double Barrel (The Relationship Between a State-Sponsored Threat Actor and the Gunra Ransomware…
[Joint Cybersecurity Advisory] Operation Double Barrel (The Relationship Between a State-Sponsored Threat Actor and the Gunra Ransomware Group) ASEC
Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit | Proofpoint US
Threat Research would like to thank the Proofpoint Cloudmark Authority team for their collaboration. Key Findings On 22 July 2026, one day prior to Proofpoint’s recent joint release
https://www.proofpoint.com/us/blog/threat-insight/cleaning-out-inboxes-ta488-comes-outlook-another-half-click-exploit
🎖@malwr
Threat Research would like to thank the Proofpoint Cloudmark Authority team for their collaboration. Key Findings On 22 July 2026, one day prior to Proofpoint’s recent joint release
https://www.proofpoint.com/us/blog/threat-insight/cleaning-out-inboxes-ta488-comes-outlook-another-half-click-exploit
🎖@malwr
Proofpoint
Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit | Proofpoint US
Threat Research would like to thank the Proofpoint Cloudmark Authority team for their collaboration. Key Findings On 22 July 2026, one day prior to Proofpoint’s recent joint release
❤1
Kuna — an agent-first decompiler
Kuna is a self-refining decompiler built to be used by agents: loosely based on Ghidra's decompiler, written in Rust, and runnable from the CLI, inside Ghidra, or entirely in the browser.
https://kuna.noelo.org/
🎖@malwr
Kuna is a self-refining decompiler built to be used by agents: loosely based on Ghidra's decompiler, written in Rust, and runnable from the CLI, inside Ghidra, or entirely in the browser.
https://kuna.noelo.org/
🎖@malwr
kuna.noelo.org
Kuna — an agent-first decompiler
Kuna is a self-refining decompiler built to be used by agents: loosely based on Ghidra's decompiler, written in Rust, and runnable from the CLI, inside Ghidra, or entirely in the browser.
icedracon/adhammer: Active Directory security-assessment toolkit in Rust — PingCastle-class audit + authorized red-team validation, on a from-scratch DCE/RPC · NTLM · SMB2 · Kerberos stack. One static binary, from Kali or Windows.
https://github.com/icedracon/adhammer
🎖@malwr
https://github.com/icedracon/adhammer
🎖@malwr
GitHub
GitHub - icedracon/adhammer: Active Directory security assessment in Rust: directory discovery, Tier-0 path analysis, supported…
Active Directory security assessment in Rust: directory discovery, Tier-0 path analysis, supported validation, and evidence reporting. - icedracon/adhammer
👍1
iamsopotatoe-coder/TinyLoad: PE packer/crypter for Windows. compresses and encrypts executables with a custom virtual machine into a self extracting stub.
https://github.com/iamsopotatoe-coder/TinyLoad
🎖@malwr
https://github.com/iamsopotatoe-coder/TinyLoad
🎖@malwr
GitHub
GitHub - iamsopotatoe-coder/TinyLoad: Open source Windows x64 PE packer and crypter. Compresses and encrypts executables with a…
Open source Windows x64 PE packer and crypter. Compresses and encrypts executables with a custom virtual machine into a self extracting stub. - iamsopotatoe-coder/TinyLoad
Inside the OS-Aware Phishing Kit Profiling Your Device
A sophisticated phishing kit reads victim operating systems to deploy tailored attacks—from fake RMM installs to live AiTM credential harvesting.
https://blog.knowbe4.com/inside-os-aware-phishing-kit-profiling-your-device
🎖@malwr
A sophisticated phishing kit reads victim operating systems to deploy tailored attacks—from fake RMM installs to live AiTM credential harvesting.
https://blog.knowbe4.com/inside-os-aware-phishing-kit-profiling-your-device
🎖@malwr
Knowbe4
Inside the OS-Aware Phishing Kit Profiling Your Device
A sophisticated phishing kit reads victim operating systems to deploy tailored attacks—from fake RMM installs to live AiTM credential harvesting.
zhaoxuya520/reverse-skill: Reverse Engineering / Authorized Penetration Testing / Security Research Skill Router Pack AI-powered routing + On-demand toolchain bootstrapping + Self-evolving knowledge base Supports Claude Code, Kiro, Cursor, Cline, and other AI coding clients 逆向/渗透/安全技能路由包 - AI 自动路由 + 按需自举工具链 + 自动进化经验库 | 支持 Claude Code / Kiro / Cursor / Cline 等代码 AI 客户端
https://github.com/zhaoxuya520/reverse-skill#about
🎖@malwr
https://github.com/zhaoxuya520/reverse-skill#about
🎖@malwr
GitHub
GitHub - zhaoxuya520/reverse-skill: Reverse Engineering / Authorized Penetration Testing / Security Research Skill Router Pack…
Reverse Engineering / Authorized Penetration Testing / Security Research Skill Router Pack AI-powered routing + On-demand toolchain bootstrapping + Self-evolving knowledge base Supports Claude Cod...
❤1
tmm35/ScheduledSpy: A command line process execution monitor for Windows.
https://github.com/tmm35/ScheduledSpy
🎖@malwr
https://github.com/tmm35/ScheduledSpy
🎖@malwr
GitHub
GitHub - tmm35/WindowsExecutionMonitor: A command line process execution monitor for Windows.
A command line process execution monitor for Windows. - tmm35/WindowsExecutionMonitor
jobehi/macos-process-killer: A simple tool for a simple task
https://github.com/jobehi/macos-process-killer
🎖@malwr
https://github.com/jobehi/macos-process-killer
🎖@malwr
GitHub
GitHub - jobehi/macos-process-killer: A simple tool for a simple task
A simple tool for a simple task. Contribute to jobehi/macos-process-killer development by creating an account on GitHub.
bsmensah-ctrl/DLL-Injection-Lab: Simulate and detect the full DLL-injection telemetry chain—no VM, no admin, zero live processes touched. ATT&CK T1055.001 · JSONL · SARIF
https://github.com/bsmensah-ctrl/DLL-Injection-Lab
🎖@malwr
https://github.com/bsmensah-ctrl/DLL-Injection-Lab
🎖@malwr
GitHub
GitHub - bsmensah-ctrl/DLL-Injection-Lab: 🧪 Simulate and detect the full DLL-injection telemetry chain—no VM, no admin, zero live…
🧪 Simulate and detect the full DLL-injection telemetry chain—no VM, no admin, zero live processes touched. ATT&CK T1055.001 · JSONL · SARIF - bsmensah-ctrl/DLL-Injection-Lab
ANTIPHISHING PANEL
Free Software Suricata rules frequently updated with phishing threat vectors.
https://julioliraup.github.io/AT/
🎖@malwr
Free Software Suricata rules frequently updated with phishing threat vectors.
https://julioliraup.github.io/AT/
🎖@malwr
Antiphishing
Antiphishing Threat Intelligence Panel | Suricata
Threat Intelligence and Suricata detection rules for phishing across DNS, TLS and HTTP.