Malware News
16.2K subscribers
1.64K photos
7 videos
130 files
8.3K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
Inside the OS-Aware Phishing Kit Profiling Your Device
A sophisticated phishing kit reads victim operating systems to deploy tailored attacks—from fake RMM installs to live AiTM credential harvesting.

https://blog.knowbe4.com/inside-os-aware-phishing-kit-profiling-your-device


🎖@malwr
zhaoxuya520/reverse-skill: Reverse Engineering / Authorized Penetration Testing / Security Research Skill Router Pack AI-powered routing + On-demand toolchain bootstrapping + Self-evolving knowledge base Supports Claude Code, Kiro, Cursor, Cline, and other AI coding clients 逆向/渗透/安全技能路由包 - AI 自动路由 + 按需自举工具链 + 自动进化经验库 | 支持 Claude Code / Kiro / Cursor / Cline 等代码 AI 客户端

https://github.com/zhaoxuya520/reverse-skill#about


🎖@malwr
1
2026-7-31: SmartApeSG ClickFix campaign pushes unidentified RAT

https://www.malware-traffic-analysis.net/2026/07/31/index.html


🎖@malwr
2
2026-07-31: Seven days of scans and probes and web traffic hitting my web server

https://www.malware-traffic-analysis.net/2026/07/31/index2.html


🎖@malwr
1
zyekhabdul/volatility3-ai-triage

https://github.com/zyekhabdul/volatility3-ai-triage

volatility3-ai-triage performs high-utility memory triage by executing Volatility 3 plugins in parallel, cross-correlating raw memory artifacts across plugins, detecting advanced 2026 evasion techniques, and generating deterministic SIEM JSON / STIX 2.1 Threat Intel alongside executive Markdown & HTML Triage Reports via Local LLMs (Ollama) or Cloud APIs (Gemini, OpenAI).



🎖@malwr
🚨 For advertising in the channel, contact @SirMalware
👎31
Malware News pinned «🚨 For advertising in the channel, contact @SirMalware»
Static Devirtualization of Tencent VM
Over the course of several months we have noticed an increased interest in Tencent VM obfuscation. We have had complete static devirtualization of this VM obfuscation for quite some time now and have noticed others have achieved similar deobfuscation results.

https://back.engineering/blog/31/07/2026/


🎖@malwr
🔥1
Inside the Falcon How CrowdStrike Catches You
A full reverse-engineering teardown of the CrowdStrike Falcon sensor: the six kernel callback sources, the WFP network engine, the file-system minifilter, the cspcm4 broker, the user-mode service (DNS / AMSI / browser / Identity Protection), and the cloud-loaded detection engine — plus every structural blind spot. How Falcon sees you, and where the seams are.

https://0xdbgman.github.io/posts/inside-the-falcon-how-crowdstrike-catches-you/


🎖@malwr
Turning Chrome Remote Desktop into Pure Red Team Ops
How to hide the Chrome Remote Desktop connection banner by patching a single dialog resource, then abuse host.json and MSI packaging to turn CRD into a quiet persistent access channel.

https://zerotracelab.com/blog/chrome-remote-desktop-red-ops


🎖@malwr
JoasASantos/NeuroPurple: The AI Autonomous SOC & Purple-Team Engine

https://github.com/JoasASantos/NeuroPurple


🎖@malwr
1
aelassas/servy: Professional-Grade Windows Service Wrapper with Real-Time Monitoring

https://github.com/aelassas/servy

Servy lets you run any app as a native Windows service with full control over the working directory, startup type, process priority, CPU affinity, logging, health checks, environment variables, dependencies, pre-launch and post-launch hooks, pre-stop and post-stop hooks, and parameters.



🎖@malwr