Latest posts

Malware News
24 Sept, 04:51
Part 2: Visual-layer hiding — Hawkeye Research Visual-layer anti-capture in DWM: CVisual::HasProtectedContent (bit 7 at +0x6A), vtable heap scan, HWND/PID attribution, and defender-side detection on Windows 10/11.https://hawkeye-leo.github.io/hawkeye/research/capture/02-visual-hiding/🎖@malwrhawkeye-leo.github.ioPart 2: Visual-layer hiding — Hawkeye ResearchVisual-layer anti-capture in DWM: CVisual::HasProtectedContent (bit 7 at +0x6A), vtable heap scan, HWND/PID attribution, and defender-side detection on Windows 10/11.
Malware News
23 Sept, 18:17
HimitsuShell/HimitsuShell: shell script protector (obfuscation, embedded interpreter, DRM) - invisible to kernel tracinghttps://github.com/HimitsuShell/HimitsuShell🎖@malwrGitHubGitHub - HimitsuShell/HimitsuShell: shell script protector (obfuscation, embedded interpreter, DRM) - invisible to kernel tracingshell script protector (obfuscation, embedded interpreter, DRM) - invisible to kernel tracing - HimitsuShell/HimitsuShell
Malware News
23 Sept, 09:49
Inside a multi stage toll fraud operation targeting PolandCERT Polska uncovered a toll fraud operation targeting Polish users through deceptive Meta advertisements and malicious applications distributed via Google Play. We preserved 1235 ads, linked 852 to 17 applications through code or infrastructure, reconstructed the complete execution chain, and observed live premium SMS and carrier billing tasking.https://cert.pl/en/posts/2026/09/tollfraud-analysis/🎖@malwrcert.plInside a multi stage toll fraud operation targeting PolandCERT Polska uncovered a toll fraud operation targeting Polish users through deceptive Meta advertisements and malicious applications distributed via Google Play. We preserved 1235 ads, linked 852 to 17 applications through code or infrastructure, reconstructed…
Malware News
23 Sept, 07:17
Windows Exploitation Techniques: Dangling COM Object Registrations This short blog post is about abusing a privilege escalation bug that Microsoft recently fixed in...https://projectzero.google/2026/09/windows-dangling-com.html🎖@malwrprojectzero.googleWindows Exploitation Techniques: Dangling COM Object RegistrationsThis short blog post is about abusing a privilege escalation bug that Microsoft recently fixed in...
Malware News
22 Sept, 15:20
The Closed Quorum: Inside the first reported autonomous AI C2 implantCLOSEDQUORUM, a malware binary discovered through Cisco Talos’ CAIRN project, exhibits fully autonomous command and control (C2). It represents a shift in effort displacement for attackers, in which expanding portions of the attack chain can be executed without operator involvement.https://blog.talosintelligence.com/the-closed-quorum-inside-the-first-reported-autonomous-ai-c2-implant/🎖@malwrCisco TalosThe Closed Quorum: Inside the first reported autonomous AI C2 implantCLOSEDQUORUM, a malware binary discovered through Cisco Talos’ CAIRN project, exhibits fully autonomous command and control (C2). It represents a shift in effort displacement for attackers, in which expanding portions of the attack chain can be executed without…
Malware News
21 Sept, 19:12
Dump Encoding Library The Windows Error Reporting Dump Encoding Library (WerEnc.dll) is a Microsoft signed DLL that can be abused by threat actors to encrypt their implant using a trusted Microsoft cryptographic impleme…https://ipurple.team/2026/09/21/dump-encoding-library/🎖@malwrPurple TeamDump Encoding LibraryThe Windows Error Reporting Dump Encoding Library (WerEnc.dll) is a Microsoft signed DLL that can be abused by threat actors to encrypt their implant using a trusted Microsoft cryptographic impleme…
Malware News
21 Sept, 19:12
MG1937/ASC: ASC is a super FAST Android decompiler front-end designed for Agents/Mobile Researchers.https://github.com/MG1937/ASC🎖@malwrGitHubGitHub - MG1937/ASC: ASC is a super FAST Android decompiler front-end designed for Agents/Mobile Researchers.ASC is a super FAST Android decompiler front-end designed for Agents/Mobile Researchers. - MG1937/ASC
Malware News
21 Sept, 09:52
NotRequiem/antidbg: A stealthy, fully syscalled C/C++ userland anti-debugging library for Windows, designed to protect software from reverse engineeringhttps://github.com/NotRequiem/antidbg🎖@malwrGitHubGitHub - NotRequiem/antidbg: A stealthy, fully syscalled C/C++ userland anti-debugging library for Windows, designed to protect…A stealthy, fully syscalled C/C++ userland anti-debugging library for Windows, designed to protect software from reverse engineering - NotRequiem/antidbg
Malware News
20 Sept, 17:37
2026-09-15: SmartApeSG ClickFix to unidentified RAT to MeshAgenthttps://www.malware-traffic-analysis.net/2026/09/15/index.html🎖@malwr
Malware News
20 Sept, 14:06
GrecAndrei/ida-pro-mcp: Local-first, deterministic MCP server for IDA Pro/Home: 109 strict-schema reverse-engineering operations, evidence-backed findings, and policy-gated IDB edits.https://github.com/GrecAndrei/ida-pro-mcp🎖@malwrGitHubGitHub - GrecAndrei/ida-pro-mcp: MCP server that gives LLM agents deterministic access to IDA Pro: decompilation with CFG/data…MCP server that gives LLM agents deterministic access to IDA Pro: decompilation with CFG/data-flow evidence, cross-references, local-embedding semantic search, and an evidence-backed findings works...
Malware News
18 Sept, 08:10
Beware the SparroWock: The backdoor that bites, the commands that catchESET researchers document SparroWocky, the new flagship backdoor of the FamousSparrow APT grouphttps://www.welivesecurity.com/en/eset-research/beware-sparrowock-backdoor-bites-commands-catch/🎖@malwrWelivesecurityBeware the SparroWock: The backdoor that bites, the commands that catchESET researchers document SparroWocky, the new flagship backdoor of the FamousSparrow APT group
Malware News
17 Sept, 14:41
Operation RapidRust: New APT36 Malware Tools | ThreatLabz ThreatLabz analyzes Operation RapidRust, an APT36 campaign targeting government and defense organizations in India and Afghanistan using new malware tooling.https://www.zscaler.com/blogs/security-research/operation-rapidrust-apt36-deploys-rustyshade-rustymove-psnatch-and🎖@malwrZscalerOperation RapidRust: New APT36 Malware Tools | ThreatLabzThreatLabz analyzes Operation RapidRust, an APT36 campaign targeting government and defense organizations in India and Afghanistan using new malware tooling.
Malware News
17 Sept, 11:21
Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI useRansomware incidents in Japan rose 4.7% year over year. The Gentlemen was the most active group, with leak-site listings more than doubling from January to July. Qilin ranked second and appeared to use AI, while SMEs with capital under JPY 1 billion represented 80% of victims.https://blog.talosintelligence.com/ransomware-incidents-in-japan-in-the-first-half-of-2026/🎖@malwrCisco TalosRansomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's…Ransomware incidents in Japan rose 4.7% year over year. The Gentlemen was the most active group, with leak-site listings more than doubling from January to July. Qilin ranked second and appeared to use AI, while SMEs with capital under JPY 1 billion represented…
Malware News
16 Sept, 17:30
SilkParasite Infrastructure: SpiceRAT Servers Tied to Energy and Government Targets Across Central Asia Hunt.io SpiceRAT detections identified shared infrastructure artifacts across malware families in Bitdefenderâs SilkParasite report, connecting servers to Central Asian energy, government, and telecom targets.https://hunt.io/blog/silkparasite-spicerat-central-asia-infrastructure🎖@malwrhunt.ioSilkParasite Infrastructure: SpiceRAT Servers Tied to Energy and Government Targets Across Central AsiaHunt.io SpiceRAT detections identified shared infrastructure artifacts across malware families in Bitdefender’s SilkParasite report, connecting servers to Central Asian energy, government, and telecom targets.
Malware News
16 Sept, 12:58
cloudflare/security-audit-skill: A coding-agent skill for multi-phase security audits with independently verified, machine-readable findingshttps://github.com/cloudflare/security-audit-skill🎖@malwrGitHubGitHub - cloudflare/security-audit-skill: A coding-agent skill for multi-phase security audits with independently verified, machine…A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings - cloudflare/security-audit-skill
Malware News
15 Sept, 14:06
Tajin Group: Guarantee Marketplace Vendor Involved in Phishing and Chinese Money Laundering GroupAnalyze Tajin Group's role in phishing and Chinese money laundering. Discover how this Telegram-based vendor exploits payment gateways and adapts its financial fraud operations.https://www.recordedfuture.com/research/tajin-group-gurantee-marketplacehttps://assets.recordedfuture.com/insikt-report-pdfs/2026/cta-2026-0915.pdf🎖@malwr
Malware News
15 Sept, 07:00
bombinisecurity/bombini: eBPF Security Monitoring and Sandboxing Agent Based on Ayahttps://github.com/bombinisecurity/bombini🎖@malwrGitHubGitHub - bombinisecurity/bombini: eBPF Security Monitoring and Sandboxing Agent Based on AyaeBPF Security Monitoring and Sandboxing Agent Based on Aya - bombinisecurity/bombini
Malware News
15 Sept, 06:56
Idov31/Silverseal: Silverseal is a Linux framework containing a bootkit, rootkit loader and a rootkithttps://github.com/Idov31/Silverseal🎖@malwrGitHubGitHub - Idov31/Silverseal: Silverseal is a Linux framework containing a bootkit, rootkit loader and a rootkitSilverseal is a Linux framework containing a bootkit, rootkit loader and a rootkit - Idov31/Silverseal
Malware News
14 Sept, 18:54
LumosLab-Innovation/OpenHunterAI: Local-first AI red team for web, API, and LLM application security. Attacker-style reasoning, evidence-backed findings, and skills for AI coding agents.https://github.com/LumosLab-Innovation/OpenHunterAI🎖@malwrGitHubGitHub - LumosLab-Innovation/OpenHunterAI: Local-first AI red team for web, API, and LLM application security. Attacker-style reasoning…Local-first AI red team for web, API, and LLM application security. Attacker-style reasoning, evidence-backed findings, and skills for AI coding agents. - LumosLab-Innovation/OpenHunterAI
Malware News
14 Sept, 12:01
The Harness Matters: Cutting AI Reverse-Engineering Tokens by 33% A controlled AgentRE-Bench comparison shows how Reverser Space used 33% fewer tokens and 35% fewer analysis calls without a meaningful score loss.https://reverser.space/blog/the-harness-matters-ai-reverse-engineering/🎖@malwrreverser.spaceThe Harness Matters: Cutting AI Reverse-Engineering Tokens by 33%A controlled AgentRE-Bench comparison shows how Reverser Space used 33% fewer tokens and 35% fewer analysis calls without a meaningful score loss.
Related Channels
Other channels in the same section of the catalogue.
