Malware News
前往频道在 Telegram
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ... Partner channel: @cveNotify For ads: https://telega.io/c/malwr
显示更多📈 Telegram 频道 Malware News 的分析概览
频道 Malware News (@malwr) 英语 语言赛道中的 是活跃参与者。目前社区聚集了 16 243 名订阅者,在 技术与应用 类别中位列第 7 844,并在 美国 地区排名第 2 332 位。
📊 受众指标与增长动态
自 невідомо 创建以来,项目保持高速增长,吸引了 16 243 名订阅者。
根据 25 八月, 2026 的最新数据,频道保持稳定运转。过去 30 天订阅人数变化为 712,过去 24 小时变化为 16,整体触达仍然可观。
- 认证状态: 未认证
- 互动率 (ER): 平均受众互动率为 3.49%。内容发布后 24 小时内通常能获得 2.11% 的反应,占订阅者总量。
- 帖子覆盖: 每篇帖子平均可获得 566 次浏览,首日通常累积 343 次浏览。
- 互动与反馈: 受众积极参与,单帖平均反应数为 2。
- 主题关注点: 内容集中在 threat, kernel, cve-2025, actor, attack 等核心主题上。
📝 描述与内容策略
作者将该频道定位为表达主观观点的平台:
“The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...
Partner channel: @cveNotify
For ads: https://telega.io/c/malwr”
凭借高频更新(最新数据采集于 26 八月, 2026),频道始终保持新鲜度与高覆盖。分析显示受众积极互动,使其成为 技术与应用 类别中的关键影响点。
16 243
订阅者
+1624 小时
+1387 天
+71230 天
数据加载中...
吸引订阅者
八月 '26
八月 '26
+588
在3个频道中
七月 '26
+806
在2个频道中
Get PRO
六月 '26
+700
在0个频道中
Get PRO
五月 '26
+637
在0个频道中
Get PRO
四月 '26
+476
在1个频道中
Get PRO
三月 '26
+257
在0个频道中
Get PRO
二月 '26
+324
在1个频道中
Get PRO
一月 '26
+348
在0个频道中
Get PRO
十二月 '25
+397
在0个频道中
Get PRO
十一月 '25
+412
在0个频道中
Get PRO
十月 '25
+188
在0个频道中
Get PRO
九月 '25
+95
在2个频道中
Get PRO
八月 '25
+45
在0个频道中
Get PRO
七月 '25
+51
在0个频道中
Get PRO
六月 '25
+46
在1个频道中
Get PRO
五月 '25
+31
在1个频道中
Get PRO
四月 '25
+56
在0个频道中
Get PRO
三月 '25
+22
在0个频道中
Get PRO
二月 '25
+36
在0个频道中
Get PRO
一月 '25
+34
在1个频道中
Get PRO
十二月 '24
+457
在0个频道中
Get PRO
十一月 '24
+1 858
在3个频道中
Get PRO
十月 '24
+980
在0个频道中
Get PRO
九月 '24
+1 070
在1个频道中
Get PRO
八月 '24
+957
在2个频道中
Get PRO
七月 '24
+611
在1个频道中
Get PRO
六月 '24
+483
在0个频道中
Get PRO
五月 '24
+637
在0个频道中
Get PRO
四月 '24
+640
在1个频道中
Get PRO
三月 '24
+806
在2个频道中
Get PRO
二月 '24
+521
在1个频道中
Get PRO
一月 '24
+293
在0个频道中
Get PRO
十二月 '23
+361
在2个频道中
Get PRO
十一月 '23
+85
在2个频道中
Get PRO
十月 '23
+86
在1个频道中
Get PRO
九月 '23
+97
在0个频道中
Get PRO
八月 '23
+85
在0个频道中
Get PRO
七月 '23
+63
在0个频道中
Get PRO
六月 '23
+77
在0个频道中
Get PRO
五月 '23
+65
在0个频道中
Get PRO
四月 '23
+75
在0个频道中
Get PRO
三月 '23
+75
在0个频道中
Get PRO
二月 '23
+38
在0个频道中
Get PRO
一月 '23
+63
在0个频道中
Get PRO
十二月 '22
+99
在0个频道中
Get PRO
十一月 '22
+70
在0个频道中
Get PRO
十月 '22
+101
在0个频道中
Get PRO
九月 '22
+165
在0个频道中
Get PRO
八月 '22
+986
在0个频道中
Get PRO
七月 '22
+27
在0个频道中
Get PRO
六月 '22
+31
在0个频道中
Get PRO
五月 '22
+63
在0个频道中
Get PRO
四月 '22
+72
在0个频道中
Get PRO
三月 '22
+74
在0个频道中
Get PRO
二月 '22
+43
在0个频道中
Get PRO
一月 '22
+112
在0个频道中
Get PRO
十二月 '21
+99
在0个频道中
Get PRO
十一月 '21
+42
在0个频道中
Get PRO
十月 '21
+34
在0个频道中
Get PRO
九月 '21
+36
在0个频道中
Get PRO
八月 '21
+48
在0个频道中
Get PRO
七月 '21
+95
在0个频道中
Get PRO
六月 '21
+77
在0个频道中
Get PRO
五月 '21
+11
在0个频道中
Get PRO
四月 '21
+39
在0个频道中
Get PRO
三月 '21
+28
在0个频道中
Get PRO
二月 '21
+40
在0个频道中
Get PRO
一月 '21
+54
在0个频道中
Get PRO
十二月 '20
+938
在0个频道中
| 日期 | 订阅者增长 | 提及 | 频道 | |
| 26 八月 | +8 | |||
| 25 八月 | +18 | |||
| 24 八月 | +23 | |||
| 23 八月 | +15 | |||
| 22 八月 | +21 | |||
| 21 八月 | +24 | |||
| 20 八月 | +24 | |||
| 19 八月 | +17 | |||
| 18 八月 | +22 | |||
| 17 八月 | +13 | |||
| 16 八月 | +15 | |||
| 15 八月 | +23 | |||
| 14 八月 | +38 | |||
| 13 八月 | +29 | |||
| 12 八月 | +28 | |||
| 11 八月 | +30 | |||
| 10 八月 | +15 | |||
| 09 八月 | +20 | |||
| 08 八月 | +27 | |||
| 07 八月 | +21 | |||
| 06 八月 | +25 | |||
| 05 八月 | +24 | |||
| 04 八月 | +20 | |||
| 03 八月 | +34 | |||
| 02 八月 | +34 | |||
| 01 八月 | +20 |
频道帖子
Local Privilege Escalation To System In Wibu-Systems CodeMeter Application | Shelltrail
This research post describes the process of finding and exploiting a local privilege escalation in the Wibu-Systems CodeMeter application
https://shelltrail.com/research/local-privilege-escalation-to-system-in-wibu-systems-codemeter-application
🎖@malwr
| 2 | jyatesdotdev/wd-smart-reader: macOS CLI tool for reading SMART data from WD external drives (MyBook, Elements) via SES diagnostic pages. Works on Apple Silicon, no kernel extensions needed.
https://github.com/jyatesdotdev/wd-smart-reader
🎖@malwr | 317 |
| 3 | Malware development trick 63: modifying PE version metadata and icon. Simple C example
﷽
https://cocomelonc.github.io/malware/2026/08/24/malware-tricks-63.html
🎖@malwr | 362 |
| 4 | Manic: Blend between Banking Malware & Spyware
Manic is a newly identified Android malware family with broad surveillance and remote-control capabilities, introducing an unusual Wi‑Fi mesh technique.
https://www.threatfabric.com/blogs/manic-blend-between-banking-malware-and-spyware
🎖@malwr | 330 |
| 5 | daniomass/SliverMirage: Crystal Palace PICO loader for Sliver C2 dual-layer AMSI bypass, ETW silencing, AES-256-CBC encrypted payloads, 6 delivery variants
https://github.com/daniomass/SliverMirage
🎖@malwr | 275 |
| 6 | The Citizen Lab Bad Connection: Uncovering Global Telecom Exploitation by Covert Surveillance Actors
Our investigation uncovers two sophisticated telecom surveillance campaigns and, for the first time, links real-world attack traffic to mobile operator signalling infrastructure. The findings expose how suspected commercial surveillance vendors (CSVs) exploit the global telecom interconnect ecosystem, leverage private operator networks, and conduct covert location tracking operations that can persist undetected for years.
https://citizenlab.ca/research/uncovering-global-telecom-exploitation-by-covert-surveillance-actors/
🎖@malwr | 250 |
| 7 | Inside the Falcon How CrowdStrike Catches You
A full reverse-engineering teardown of the CrowdStrike Falcon sensor: the six kernel callback sources, the WFP network engine, the file-system minifilter, the cspcm4 broker, the user-mode service (DNS / AMSI / browser / Identity Protection), and the cloud-loaded detection engine — plus every structural blind spot. How Falcon sees you, and where the seams are.
https://0xdbgman.github.io/posts/inside-the-falcon-how-crowdstrike-catches-you/
🎖@malwr | 255 |
| 8 | Your executable is a SQLite database
I have been probably obsessed with two things in the last few years: Nix as a tool to explore innovative ideas that require the capability to rebuild the world and replacing ELF with SQLite as an executable format. You might have noticed that these two ideas are well suited to each other.
https://fzakaria.com/2026/08/23/your-executable-is-a-sqlite-database
🎖@malwr | 395 |
| 9 | Tracking PavinLoader across ClickFix and fake download campaigns
We found PavinLoader being used across ClickFix, fake software, and RenPy campaigns to deliver Amatera Stealer and other malware.
https://www.malwarebytes.com/blog/threat-intel/2026/08/tracking-pavinloader-across-clickfix-and-fake-download-campaigns
🎖@malwr | 443 |
| 10 | Text Template
Text template files can contain C# or Visual Basic code that could be compiled and executed at build time. Threat actors can create or modify .tt files to execute code in the context of a trusted p…
https://ipurple.team/2026/08/24/text-template/
🎖@malwr | 404 |
| 11 | Reverse Engineering a 0day used Against EDRs
https://medium.com/@jehadbudagga/reverse-engineering-a-0day-used-against-crowdstrike-edr-a5ea1fbe3fd4
🎖@malwr | 416 |
| 12 | Inside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asia | Enki White Hat
Inside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asia
https://www.enki.co.kr/en/media-center/blog/inside-kimsuky-s-abuse-of-legitimate-remote-control-tools-across-northeast-asia
🎖@malwr | 359 |
| 13 | SLEEPWALKER: A Passive Backdoor With Its Own Command Language
Losing access to VirusTotal Intelligence at the start of the year was surprisingly productive. Unable to hunt for interesting new malware, I stopped adding to my âTODOâ pile and finally worked through my backlog from last year. That led to a detailed examination of BeheMOF as well as the discovery of this malware. Upon closer inspection, a sample that did not seem too noteworthy at first turned out to have a distinctive design once I looked under the hood: a passive backdoor that opens no obvious listening port and carries no payload inside itself. It waits in memory doing nothing at all until one specifically crafted network packet reaches the machine, which is why I am calling it SLEEPWALKER.
https://r136a1.dev/2026/08/24/sleepwalker-a-passive-backdoor-with-its-own-command-language/
🎖@malwr | 344 |
| 14 | Fairy Law: Abusing MicrosoftSignedOnly
Welcome to this new Medium post. In this one we will see how a legitimate Windows process mitigation policy can be abused to globally…
https://medium.com/@s12deff/fairy-law-abusing-microsoftsignedonly-8d35018bc99f
🎖@malwr | 397 |
| 15 | Auditing Microsoft Defender and Intune Configuration Changes
Microsoft is clearly moving toward a more unified security operations experience within the Defender portal. Over the last few years, we have seen Microsoft bring more security capabilities together under the Defender platform. Instead of working with completely separate portals...
https://jeffreyappel.nl/auditing-microsoft-defender-and-intune-configuration-changes/
🎖@malwr | 483 |
| 16 | tracebyte8/SysTrace: SysTrace - Linux System Call Monitor using PTRACE API , It traces system calls, monitors process, file, network, and memory activity, detects suspicious behavior, and generates detailed security reports.
https://github.com/tracebyte8/SysTrace
🎖@malwr | 1 006 |
| 17 | Fantastic clear-text passwords and where to collect them (Part 2 - Windows) | dfir.ch
Technical blog by Stephan Berger (@malmoeb)
https://dfir.ch/posts/fantastic_passwords_windows/
🎖@malwr | 481 |
| 18 | Developing an undetected debugger on Windows - Part 1 [Theory]
Part 1 – Theory
https://vollragm.github.io/posts/developing-veh-debugger/
🎖@malwr | 467 |
| 19 | N4D Mesh Controller: New infrastructure, a UPX-packed agent labeled "go-titan," and how to hunt for it | Datadog Security Labs
Datadog Security Research executed a newer N4D Mesh Controller sample in isolated microVMs, uncovering rotated infrastructure, a UPX-packed go-titan agent, MCP tool abuse in action, and direct runtime evidence of multi-service scanning and persistence.
https://securitylabs.datadoghq.com/articles/n4d-mesh-controller-go-titan-new-infrastructure-hunting/
🎖@malwr | 566 |
| 20 | First Android malware targeting automotive head units
Kaspersky expert has discovered new Android malware designed to serve ads and build a proxy botnet. It's delivered through legitimate software for DoFun head units.
https://securelist.com/android-head-unit-malware/121106/
🎖@malwr | 521 |
