Malware News
16.2K subscribers
1.64K photos
7 videos
130 files
8.3K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
Through the Lens of MDR: Analysis of KongTuke’s ClickFix Abuse of Compromised WordPress Sites

Our analysis of an active KongTuke campaign deploying modeloRAT — malware capable of reconnaissance, command execution, and persistent access — through compromised WordPress sites and fake CAPTCHA lures shows that the group still operates this delivery chain in parallel with the newer CrashFix technique.

https://www.trendmicro.com/en_us/research/26/c/kongtuke-clickfix-abuse-of-compromised-wordpress-sites.html


🎖@malwr
1
https://core-jmp.org/2026/07/sakdriver-reversing-kernel-driver-rootkit/

A reverse-engineering walkthrough of SakDriver, a Windows kernel-mode rootkit first mistaken for a Cobalt Strike Beacon. It patches ETW, hides processes via DKOM, masquerades as a minifilter and a fake Microsoft service, and — most notably — receives C2 commands through the Windows registry. Includes the full recovered command table, IOCs and a matching YARA figure.



🎖@malwr
Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit | Proofpoint US
Threat Research would like to thank the Proofpoint Cloudmark Authority team for their collaboration. Key Findings On 22 July 2026, one day prior to Proofpoint’s recent joint release

https://www.proofpoint.com/us/blog/threat-insight/cleaning-out-inboxes-ta488-comes-outlook-another-half-click-exploit


🎖@malwr
1
Kuna — an agent-first decompiler
Kuna is a self-refining decompiler built to be used by agents: loosely based on Ghidra's decompiler, written in Rust, and runnable from the CLI, inside Ghidra, or entirely in the browser.

https://kuna.noelo.org/


🎖@malwr
icedracon/adhammer: Active Directory security-assessment toolkit in Rust — PingCastle-class audit + authorized red-team validation, on a from-scratch DCE/RPC · NTLM · SMB2 · Kerberos stack. One static binary, from Kali or Windows.

https://github.com/icedracon/adhammer


🎖@malwr
👍1
Inside the OS-Aware Phishing Kit Profiling Your Device
A sophisticated phishing kit reads victim operating systems to deploy tailored attacks—from fake RMM installs to live AiTM credential harvesting.

https://blog.knowbe4.com/inside-os-aware-phishing-kit-profiling-your-device


🎖@malwr
zhaoxuya520/reverse-skill: Reverse Engineering / Authorized Penetration Testing / Security Research Skill Router Pack AI-powered routing + On-demand toolchain bootstrapping + Self-evolving knowledge base Supports Claude Code, Kiro, Cursor, Cline, and other AI coding clients 逆向/渗透/安全技能路由包 - AI 自动路由 + 按需自举工具链 + 自动进化经验库 | 支持 Claude Code / Kiro / Cursor / Cline 等代码 AI 客户端

https://github.com/zhaoxuya520/reverse-skill#about


🎖@malwr
1
2026-7-31: SmartApeSG ClickFix campaign pushes unidentified RAT

https://www.malware-traffic-analysis.net/2026/07/31/index.html


🎖@malwr
2
2026-07-31: Seven days of scans and probes and web traffic hitting my web server

https://www.malware-traffic-analysis.net/2026/07/31/index2.html


🎖@malwr
1
zyekhabdul/volatility3-ai-triage

https://github.com/zyekhabdul/volatility3-ai-triage

volatility3-ai-triage performs high-utility memory triage by executing Volatility 3 plugins in parallel, cross-correlating raw memory artifacts across plugins, detecting advanced 2026 evasion techniques, and generating deterministic SIEM JSON / STIX 2.1 Threat Intel alongside executive Markdown & HTML Triage Reports via Local LLMs (Ollama) or Cloud APIs (Gemini, OpenAI).



🎖@malwr
🚨 For advertising in the channel, contact @SirMalware
👎31
Malware News pinned «🚨 For advertising in the channel, contact @SirMalware»
Static Devirtualization of Tencent VM
Over the course of several months we have noticed an increased interest in Tencent VM obfuscation. We have had complete static devirtualization of this VM obfuscation for quite some time now and have noticed others have achieved similar deobfuscation results.

https://back.engineering/blog/31/07/2026/


🎖@malwr
🔥1
Inside the Falcon How CrowdStrike Catches You
A full reverse-engineering teardown of the CrowdStrike Falcon sensor: the six kernel callback sources, the WFP network engine, the file-system minifilter, the cspcm4 broker, the user-mode service (DNS / AMSI / browser / Identity Protection), and the cloud-loaded detection engine — plus every structural blind spot. How Falcon sees you, and where the seams are.

https://0xdbgman.github.io/posts/inside-the-falcon-how-crowdstrike-catches-you/


🎖@malwr