Through the Lens of MDR: Analysis of KongTuke’s ClickFix Abuse of Compromised WordPress Sites
Our analysis of an active KongTuke campaign deploying modeloRAT — malware capable of reconnaissance, command execution, and persistent access — through compromised WordPress sites and fake CAPTCHA lures shows that the group still operates this delivery chain in parallel with the newer CrashFix technique.
https://www.trendmicro.com/en_us/research/26/c/kongtuke-clickfix-abuse-of-compromised-wordpress-sites.html
🎖@malwr
Our analysis of an active KongTuke campaign deploying modeloRAT — malware capable of reconnaissance, command execution, and persistent access — through compromised WordPress sites and fake CAPTCHA lures shows that the group still operates this delivery chain in parallel with the newer CrashFix technique.
https://www.trendmicro.com/en_us/research/26/c/kongtuke-clickfix-abuse-of-compromised-wordpress-sites.html
🎖@malwr
Trend Micro
Through the Lens of MDR: Analysis of KongTuke’s ClickFix Abuse of Compromised WordPress Sites
Our analysis of an active KongTuke campaign deploying modeloRAT — malware capable of reconnaissance, command execution, and persistent access — through compromised WordPress sites and fake CAPTCHA lures shows that the group still operates this delivery chain…
❤1
Technical Analysis of GoGRPC | ThreatLabz
A threat actor likely associated with ransomware is using Microsoft Teams vishing and Quick Assist to deliver new backdoors and proxy tools.
https://www.zscaler.com/blogs/security-research/helpdesk-hijackers-teams-vishing-quick-assist-and-gogrpc-backdoor
🎖@malwr
A threat actor likely associated with ransomware is using Microsoft Teams vishing and Quick Assist to deliver new backdoors and proxy tools.
https://www.zscaler.com/blogs/security-research/helpdesk-hijackers-teams-vishing-quick-assist-and-gogrpc-backdoor
🎖@malwr
Zscaler
Technical Analysis of GoGRPC | ThreatLabz
A threat actor likely associated with ransomware is using Microsoft Teams vishing and Quick Assist to deliver new backdoors and proxy tools.
https://core-jmp.org/2026/07/sakdriver-reversing-kernel-driver-rootkit/
🎖@malwr
A reverse-engineering walkthrough of SakDriver, a Windows kernel-mode rootkit first mistaken for a Cobalt Strike Beacon. It patches ETW, hides processes via DKOM, masquerades as a minifilter and a fake Microsoft service, and — most notably — receives C2 commands through the Windows registry. Includes the full recovered command table, IOCs and a matching YARA figure.
🎖@malwr
core-jmp
SakDriver: Reversing a Windows Kernel Driver Rootkit
A reverse-engineering walkthrough of SakDriver, a Windows kernel-mode rootkit first mistaken for a Cobalt Strike Beacon. It patches ETW, hides processes via DKOM, masquerades as a minifilter and a fake Microsoft service, and — most notably — receives C2 commands…
[Joint Cybersecurity Advisory] Operation Double Barrel (The Relationship Between a State-Sponsored Threat Actor and the Gunra Ransomware Group) - ASEC
https://asec.ahnlab.com/en/94696/
https://image.ahnlab.com/atip/content/file/20260730/[AhnLab]Operation%20Double%20Barrel(ENG)(2026.07.30).pdf
🎖@malwr
https://asec.ahnlab.com/en/94696/
https://image.ahnlab.com/atip/content/file/20260730/[AhnLab]Operation%20Double%20Barrel(ENG)(2026.07.30).pdf
🎖@malwr
ASEC
[Joint Cybersecurity Advisory] Operation Double Barrel (The Relationship Between a State-Sponsored Threat Actor and the Gunra Ransomware…
[Joint Cybersecurity Advisory] Operation Double Barrel (The Relationship Between a State-Sponsored Threat Actor and the Gunra Ransomware Group) ASEC
Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit | Proofpoint US
Threat Research would like to thank the Proofpoint Cloudmark Authority team for their collaboration. Key Findings On 22 July 2026, one day prior to Proofpoint’s recent joint release
https://www.proofpoint.com/us/blog/threat-insight/cleaning-out-inboxes-ta488-comes-outlook-another-half-click-exploit
🎖@malwr
Threat Research would like to thank the Proofpoint Cloudmark Authority team for their collaboration. Key Findings On 22 July 2026, one day prior to Proofpoint’s recent joint release
https://www.proofpoint.com/us/blog/threat-insight/cleaning-out-inboxes-ta488-comes-outlook-another-half-click-exploit
🎖@malwr
Proofpoint
Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit | Proofpoint US
Threat Research would like to thank the Proofpoint Cloudmark Authority team for their collaboration. Key Findings On 22 July 2026, one day prior to Proofpoint’s recent joint release
❤1
Kuna — an agent-first decompiler
Kuna is a self-refining decompiler built to be used by agents: loosely based on Ghidra's decompiler, written in Rust, and runnable from the CLI, inside Ghidra, or entirely in the browser.
https://kuna.noelo.org/
🎖@malwr
Kuna is a self-refining decompiler built to be used by agents: loosely based on Ghidra's decompiler, written in Rust, and runnable from the CLI, inside Ghidra, or entirely in the browser.
https://kuna.noelo.org/
🎖@malwr
kuna.noelo.org
Kuna — an agent-first decompiler
Kuna is a self-refining decompiler built to be used by agents: loosely based on Ghidra's decompiler, written in Rust, and runnable from the CLI, inside Ghidra, or entirely in the browser.
icedracon/adhammer: Active Directory security-assessment toolkit in Rust — PingCastle-class audit + authorized red-team validation, on a from-scratch DCE/RPC · NTLM · SMB2 · Kerberos stack. One static binary, from Kali or Windows.
https://github.com/icedracon/adhammer
🎖@malwr
https://github.com/icedracon/adhammer
🎖@malwr
GitHub
GitHub - icedracon/adhammer: Active Directory security assessment in Rust: directory discovery, Tier-0 path analysis, supported…
Active Directory security assessment in Rust: directory discovery, Tier-0 path analysis, supported validation, and evidence reporting. - icedracon/adhammer
👍1
iamsopotatoe-coder/TinyLoad: PE packer/crypter for Windows. compresses and encrypts executables with a custom virtual machine into a self extracting stub.
https://github.com/iamsopotatoe-coder/TinyLoad
🎖@malwr
https://github.com/iamsopotatoe-coder/TinyLoad
🎖@malwr
GitHub
GitHub - iamsopotatoe-coder/TinyLoad: Open source Windows x64 PE packer and crypter. Compresses and encrypts executables with a…
Open source Windows x64 PE packer and crypter. Compresses and encrypts executables with a custom virtual machine into a self extracting stub. - iamsopotatoe-coder/TinyLoad
Inside the OS-Aware Phishing Kit Profiling Your Device
A sophisticated phishing kit reads victim operating systems to deploy tailored attacks—from fake RMM installs to live AiTM credential harvesting.
https://blog.knowbe4.com/inside-os-aware-phishing-kit-profiling-your-device
🎖@malwr
A sophisticated phishing kit reads victim operating systems to deploy tailored attacks—from fake RMM installs to live AiTM credential harvesting.
https://blog.knowbe4.com/inside-os-aware-phishing-kit-profiling-your-device
🎖@malwr
Knowbe4
Inside the OS-Aware Phishing Kit Profiling Your Device
A sophisticated phishing kit reads victim operating systems to deploy tailored attacks—from fake RMM installs to live AiTM credential harvesting.
zhaoxuya520/reverse-skill: Reverse Engineering / Authorized Penetration Testing / Security Research Skill Router Pack AI-powered routing + On-demand toolchain bootstrapping + Self-evolving knowledge base Supports Claude Code, Kiro, Cursor, Cline, and other AI coding clients 逆向/渗透/安全技能路由包 - AI 自动路由 + 按需自举工具链 + 自动进化经验库 | 支持 Claude Code / Kiro / Cursor / Cline 等代码 AI 客户端
https://github.com/zhaoxuya520/reverse-skill#about
🎖@malwr
https://github.com/zhaoxuya520/reverse-skill#about
🎖@malwr
GitHub
GitHub - zhaoxuya520/reverse-skill: Reverse Engineering / Authorized Penetration Testing / Security Research Skill Router Pack…
Reverse Engineering / Authorized Penetration Testing / Security Research Skill Router Pack AI-powered routing + On-demand toolchain bootstrapping + Self-evolving knowledge base Supports Claude Cod...
❤1
tmm35/ScheduledSpy: A command line process execution monitor for Windows.
https://github.com/tmm35/ScheduledSpy
🎖@malwr
https://github.com/tmm35/ScheduledSpy
🎖@malwr
GitHub
GitHub - tmm35/WindowsExecutionMonitor: A command line process execution monitor for Windows.
A command line process execution monitor for Windows. - tmm35/WindowsExecutionMonitor
jobehi/macos-process-killer: A simple tool for a simple task
https://github.com/jobehi/macos-process-killer
🎖@malwr
https://github.com/jobehi/macos-process-killer
🎖@malwr
GitHub
GitHub - jobehi/macos-process-killer: A simple tool for a simple task
A simple tool for a simple task. Contribute to jobehi/macos-process-killer development by creating an account on GitHub.
bsmensah-ctrl/DLL-Injection-Lab: Simulate and detect the full DLL-injection telemetry chain—no VM, no admin, zero live processes touched. ATT&CK T1055.001 · JSONL · SARIF
https://github.com/bsmensah-ctrl/DLL-Injection-Lab
🎖@malwr
https://github.com/bsmensah-ctrl/DLL-Injection-Lab
🎖@malwr
GitHub
GitHub - bsmensah-ctrl/DLL-Injection-Lab: 🧪 Simulate and detect the full DLL-injection telemetry chain—no VM, no admin, zero live…
🧪 Simulate and detect the full DLL-injection telemetry chain—no VM, no admin, zero live processes touched. ATT&CK T1055.001 · JSONL · SARIF - bsmensah-ctrl/DLL-Injection-Lab
ANTIPHISHING PANEL
Free Software Suricata rules frequently updated with phishing threat vectors.
https://julioliraup.github.io/AT/
🎖@malwr
Free Software Suricata rules frequently updated with phishing threat vectors.
https://julioliraup.github.io/AT/
🎖@malwr
Antiphishing
Antiphishing Threat Intelligence Panel | Suricata
Threat Intelligence and Suricata detection rules for phishing across DNS, TLS and HTTP.
2026-7-31: SmartApeSG ClickFix campaign pushes unidentified RAT
https://www.malware-traffic-analysis.net/2026/07/31/index.html
🎖@malwr
https://www.malware-traffic-analysis.net/2026/07/31/index.html
🎖@malwr
❤2
2026-07-31: Seven days of scans and probes and web traffic hitting my web server
https://www.malware-traffic-analysis.net/2026/07/31/index2.html
🎖@malwr
https://www.malware-traffic-analysis.net/2026/07/31/index2.html
🎖@malwr
❤1
zyekhabdul/volatility3-ai-triage
https://github.com/zyekhabdul/volatility3-ai-triage
🎖@malwr
https://github.com/zyekhabdul/volatility3-ai-triage
volatility3-ai-triage performs high-utility memory triage by executing Volatility 3 plugins in parallel, cross-correlating raw memory artifacts across plugins, detecting advanced 2026 evasion techniques, and generating deterministic SIEM JSON / STIX 2.1 Threat Intel alongside executive Markdown & HTML Triage Reports via Local LLMs (Ollama) or Cloud APIs (Gemini, OpenAI).
🎖@malwr
GitHub
GitHub - zyekhabdul/volatility3-ai-triage: 🤖 AI-powered automated memory forensics & triage pipeline integrated with Volatility…
🤖 AI-powered automated memory forensics & triage pipeline integrated with Volatility 3 for rapid incident response. - zyekhabdul/volatility3-ai-triage
Static Devirtualization of Tencent VM
Over the course of several months we have noticed an increased interest in Tencent VM obfuscation. We have had complete static devirtualization of this VM obfuscation for quite some time now and have noticed others have achieved similar deobfuscation results.
https://back.engineering/blog/31/07/2026/
🎖@malwr
Over the course of several months we have noticed an increased interest in Tencent VM obfuscation. We have had complete static devirtualization of this VM obfuscation for quite some time now and have noticed others have achieved similar deobfuscation results.
https://back.engineering/blog/31/07/2026/
🎖@malwr
aftermathlabs.net
Static Devirtualization of Tencent VM
Over the course of several months we have noticed an increased interest in Tencent VM obfuscation. We have had complete static devirtualization of this VM obfuscation for quite some time now and have noticed others have achieved similar deobfuscation results.
🔥1
Inside the Falcon How CrowdStrike Catches You
A full reverse-engineering teardown of the CrowdStrike Falcon sensor: the six kernel callback sources, the WFP network engine, the file-system minifilter, the cspcm4 broker, the user-mode service (DNS / AMSI / browser / Identity Protection), and the cloud-loaded detection engine — plus every structural blind spot. How Falcon sees you, and where the seams are.
https://0xdbgman.github.io/posts/inside-the-falcon-how-crowdstrike-catches-you/
🎖@malwr
A full reverse-engineering teardown of the CrowdStrike Falcon sensor: the six kernel callback sources, the WFP network engine, the file-system minifilter, the cspcm4 broker, the user-mode service (DNS / AMSI / browser / Identity Protection), and the cloud-loaded detection engine — plus every structural blind spot. How Falcon sees you, and where the seams are.
https://0xdbgman.github.io/posts/inside-the-falcon-how-crowdstrike-catches-you/
🎖@malwr
DbgMan
Inside the Falcon How CrowdStrike Catches You
A full reverse-engineering teardown of the CrowdStrike Falcon sensor: the six kernel callback sources, the WFP network engine, the file-system minifilter, the cspcm4 broker, the user-mode service (DNS / AMSI / browser / Identity Protection), and the cloud…