Malware News
前往频道在 Telegram
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ... Partner channel: @cveNotify For ads: https://telega.io/c/malwr
显示更多📈 Telegram 频道 Malware News 的分析概览
频道 Malware News (@malwr) 英语 语言赛道中的 是活跃参与者。目前社区聚集了 16 114 名订阅者,在 技术与应用 类别中位列第 7 760,并在 美国 地区排名第 2 297 位。
📊 受众指标与增长动态
自 невідомо 创建以来,项目保持高速增长,吸引了 16 114 名订阅者。
根据 04 十月, 2026 的最新数据,频道保持稳定运转。过去 30 天订阅人数变化为 -129,过去 24 小时变化为 0,整体触达仍然可观。
- 认证状态: 未认证
- 互动率 (ER): 平均受众互动率为 4.57%。内容发布后 24 小时内通常能获得 2.10% 的反应,占订阅者总量。
- 帖子覆盖: 每篇帖子平均可获得 737 次浏览,首日通常累积 339 次浏览。
- 互动与反馈: 受众积极参与,单帖平均反应数为 1。
- 主题关注点: 内容集中在 threat, kernel, cve-2025, actor, attack 等核心主题上。
📝 描述与内容策略
作者将该频道定位为表达主观观点的平台:
“The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...
Partner channel: @cveNotify
For ads: https://telega.io/c/malwr”
凭借高频更新(最新数据采集于 05 十月, 2026),频道始终保持新鲜度与高覆盖。分析显示受众积极互动,使其成为 技术与应用 类别中的关键影响点。
16 114
订阅者
无数据24 小时
-367 天
-12930 天
数据加载中...
吸引订阅者
十月 '2610月 '26
十月 '26
+2
在0个频道中
九月 '26
+57
在0个频道中
Get PRO
八月 '26
+647
在3个频道中
Get PRO
七月 '26
+806
在2个频道中
Get PRO
六月 '26
+700
在0个频道中
Get PRO
五月 '26
+637
在0个频道中
Get PRO
四月 '26
+476
在1个频道中
Get PRO
三月 '26
+257
在0个频道中
Get PRO
二月 '26
+324
在1个频道中
Get PRO
一月 '26
+348
在0个频道中
Get PRO
十二月 '25
+397
在0个频道中
Get PRO
十一月 '25
+412
在0个频道中
Get PRO
十月 '25
+188
在0个频道中
Get PRO
九月 '25
+95
在2个频道中
Get PRO
八月 '25
+45
在0个频道中
Get PRO
七月 '25
+51
在0个频道中
Get PRO
六月 '25
+46
在1个频道中
Get PRO
五月 '25
+31
在1个频道中
Get PRO
四月 '25
+56
在0个频道中
Get PRO
三月 '25
+22
在0个频道中
Get PRO
二月 '25
+36
在0个频道中
Get PRO
一月 '25
+34
在1个频道中
Get PRO
十二月 '24
+457
在0个频道中
Get PRO
十一月 '24
+1 858
在3个频道中
Get PRO
十月 '24
+980
在0个频道中
Get PRO
九月 '24
+1 070
在1个频道中
Get PRO
八月 '24
+957
在2个频道中
Get PRO
七月 '24
+611
在1个频道中
Get PRO
六月 '24
+483
在0个频道中
Get PRO
五月 '24
+637
在0个频道中
Get PRO
四月 '24
+640
在1个频道中
Get PRO
三月 '24
+806
在2个频道中
Get PRO
二月 '24
+521
在1个频道中
Get PRO
一月 '24
+293
在0个频道中
Get PRO
十二月 '23
+361
在2个频道中
Get PRO
十一月 '23
+85
在2个频道中
Get PRO
十月 '23
+86
在1个频道中
Get PRO
九月 '23
+97
在0个频道中
Get PRO
八月 '23
+85
在0个频道中
Get PRO
七月 '23
+63
在0个频道中
Get PRO
六月 '23
+77
在0个频道中
Get PRO
五月 '23
+65
在0个频道中
Get PRO
四月 '23
+75
在0个频道中
Get PRO
三月 '23
+75
在0个频道中
Get PRO
二月 '23
+38
在0个频道中
Get PRO
一月 '23
+63
在0个频道中
Get PRO
十二月 '22
+99
在0个频道中
Get PRO
十一月 '22
+70
在0个频道中
Get PRO
十月 '22
+101
在0个频道中
Get PRO
九月 '22
+165
在0个频道中
Get PRO
八月 '22
+986
在0个频道中
Get PRO
七月 '22
+27
在0个频道中
Get PRO
六月 '22
+31
在0个频道中
Get PRO
五月 '22
+63
在0个频道中
Get PRO
四月 '22
+72
在0个频道中
Get PRO
三月 '22
+74
在0个频道中
Get PRO
二月 '22
+43
在0个频道中
Get PRO
一月 '22
+112
在0个频道中
Get PRO
十二月 '21
+99
在0个频道中
Get PRO
十一月 '21
+42
在0个频道中
Get PRO
十月 '21
+34
在0个频道中
Get PRO
九月 '21
+36
在0个频道中
Get PRO
八月 '21
+48
在0个频道中
Get PRO
七月 '21
+95
在0个频道中
Get PRO
六月 '21
+77
在0个频道中
Get PRO
五月 '21
+11
在0个频道中
Get PRO
四月 '21
+39
在0个频道中
Get PRO
三月 '21
+28
在0个频道中
Get PRO
二月 '21
+40
在0个频道中
Get PRO
一月 '21
+54
在0个频道中
Get PRO
十二月 '20
+938
在0个频道中
| 日期 | 订阅者增长 | 提及 | 频道 | |
| 05 十月 | 0 | |||
| 04 十月 | +1 | |||
| 03 十月 | +1 | |||
| 02 十月 | 0 | |||
| 01 十月 | 0 |
频道帖子
morluto/rea: Reverse engineer anything with agents, from app behavior down to native binaries.
https://github.com/morluto/rea
🎖@malwr
| 2 | grisuno/LazyOwn: LazyOwn RedTeam/APT Framework is the first RedTeam Framework with an AI-powered C&C, featuring rootkits to conceal campaigns, undetectable malleable implants compatible with Windows/Linux/Mac OSX, and self-configuring backdoors. With its Web interface and powerful Console Client, it is the best combination for your Autonomous RedTeam/APT campaigns.
https://github.com/grisuno/lazyown
🎖@malwr | 695 |
| 3 | AkaTorich/KernelFlirt: KernelFlirt is powerful kernel debugger.
https://github.com/akatorich/kernelflirt
🎖@malwr | 555 |
| 4 | PaperCut MF Zero-Day Intrusion: Java Loader, Web Shell, and AdaptixC2 via CVE-2026-82078 and CVE-2026-81578
eSentire TRU details a PaperCut MF zero-day intrusion (CVE-2026-82078, CVE-2026-81578) using a Java loader, web shell, and trojanized Copilot binary to deploy AdaptixC2.
https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578
🎖@malwr | 575 |
| 5 | China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor
Cisco Talos uncovered a cluster of activity we track as UAT-11587 targeting government and policy organizations across Asia, including in Taiwan, India, the Philippines, and Cambodia, to deliver a previously undocumented backdoor referred to as “Antino” in developer artifacts.
https://blog.talosintelligence.com/china-nexus-uat-11587-targets-government-and-policy-organizations-across-asia-with-antino-backdoor/
🎖@malwr | 554 |
| 6 | JoasASantos/Offensive-Security-AI-Models: Uncensored AI models or those fine-tuned for cybersecurity tasks.
https://github.com/JoasASantos/Offensive-Security-AI-Models
🎖@malwr | 628 |
| 7 | NeedyMantis: Unpacking a post-compromise malware family used in targeted operations | Microsoft Security Blog
Microsoft Threat Intelligence identified NeedyMantis, a modular post-compromise malware framework used in targeted intrusions that combines custom loaders, encrypted archives, and extensible components to maintain long-term access and support follow-on operations.
https://www.microsoft.com/en-us/security/blog/2026/09/28/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations/
🎖@malwr | 553 |
| 8 | Uncovering a SectopRAT Variant Embedded in Legitimate Software | FortiGuard Labs
Analysis of a SectopRAT variant hidden in tampered legitimate software that steals credentials and enables remote system control…
https://www.fortinet.com/blog/threat-research/uncovering-a-sectoprat-variant-embedded-in-legitimate-software
🎖@malwr | 467 |
| 9 | TwoSevenOneT/InjectSetConsole: Proof of Concept for Process Code Injection Without Using WriteProcessMemory
https://github.com/TwoSevenOneT/InjectSetConsole
🎖@malwr | 422 |
| 10 | https://medium.com/@Root0ne/muddywaters-rented-arsenal-and-its-traces-in-the-russian-maas-market-d58965401f15
🎖@malwr | 434 |
| 11 | rPlayAI/rPlayHub: iPhone Mirroring for macOS and Linux — scrcpy for iOS and a cross-platform Device Hub clone. Mirror and control an iPhone (iOS 27+); Raspberry Pi and Windows next. Part of rPlay.
https://github.com/rPlayAI/rPlayHub
🎖@malwr | 508 |
| 12 | newliver666/apk-reverse: Suitable for Android APK reverse engineering analysis
https://github.com/newliver666/apk-reverse
An Agent Skill for Android APK reverse engineering, debloating, ad removal, surgical dex patching, repacking, and runtime/server analysis.
🎖@malwr | 636 |
| 13 | EDR Evasion: Process Injection Without WriteProcessMemory
Technique performs Windows process code injection by leveraging a Windows named pipe, it does not use VirtualAllocEx and WriteProcessMemory
https://www.zerosalarium.com/2026/09/edr-evasion-process-injection-without-WriteProcessMemory.html
🎖@malwr | 612 |
| 14 | nbs32k/LocalStranger: PoC for WinNotify, demonstrated through a driver mapper, and local privilege escalation.
https://github.com/nbs32k/LocalStranger
🎖@malwr | 617 |
| 15 | ngwg/ceasta: disassembler, decompiler and debugger in one, with a built-in mcp server: point an ai at a binary and it can debug it, not just read it. ida-style listing, pseudocode (f5), x64dbg-style debugger (windows and linux), binary diff, lua plugins. reads pe, elf and mach-o. runs on windows, linux and macos.
https://github.com/ngwg/ceasta
🎖@malwr | 619 |
| 16 | Kothamine malware uses Tailscale’s tailcat to evade network detection
Kothamine uses a legitimate Tailscale tool to receive attackers’ commands through an encrypted connection with no malicious domain to block.
https://www.malwarebytes.com/blog/threat-intel/2026/09/kothamine-malware-uses-tailscales-tailcat-to-evade-network-detection
🎖@malwr | 686 |
| 17 | Bypassing EDR with Local AI
How hard is it to bypass EDR in the modern times with AI? As it turns out, not very hard.
https://projectblack.io/blog/bypassing-edr-with-local-ai/
🎖@malwr | 781 |
| 18 | Part 2: Visual-layer hiding — Hawkeye Research
Visual-layer anti-capture in DWM: CVisual::HasProtectedContent (bit 7 at +0x6A), vtable heap scan, HWND/PID attribution, and defender-side detection on Windows 10/11.
https://hawkeye-leo.github.io/hawkeye/research/capture/02-visual-hiding/
🎖@malwr | 751 |
| 19 | HimitsuShell/HimitsuShell: shell script protector (obfuscation, embedded interpreter, DRM) - invisible to kernel tracing
https://github.com/HimitsuShell/HimitsuShell
🎖@malwr | 727 |
| 20 | Inside a multi stage toll fraud operation targeting Poland
CERT Polska uncovered a toll fraud operation targeting Polish users through deceptive Meta advertisements and malicious applications distributed via Google Play. We preserved 1235 ads, linked 852 to 17 applications through code or infrastructure, reconstructed the complete execution chain, and observed live premium SMS and carrier billing tasking.
https://cert.pl/en/posts/2026/09/tollfraud-analysis/
🎖@malwr | 685 |
