Malware News
前往频道在 Telegram
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ... Partner channel: @cveNotify For ads: https://telega.io/c/malwr
显示更多📈 Telegram 频道 Malware News 的分析概览
频道 Malware News (@malwr) 英语 语言赛道中的 是活跃参与者。目前社区聚集了 15 367 名订阅者,在 技术与应用 类别中位列第 8 337,并在 美国 地区排名第 2 466 位。
📊 受众指标与增长动态
自 невідомо 创建以来,项目保持高速增长,吸引了 15 367 名订阅者。
根据 20 七月, 2026 的最新数据,频道保持稳定运转。过去 30 天订阅人数变化为 715,过去 24 小时变化为 16,整体触达仍然可观。
- 认证状态: 未认证
- 互动率 (ER): 平均受众互动率为 4.17%。内容发布后 24 小时内通常能获得 2.26% 的反应,占订阅者总量。
- 帖子覆盖: 每篇帖子平均可获得 640 次浏览,首日通常累积 347 次浏览。
- 互动与反馈: 受众积极参与,单帖平均反应数为 1。
- 主题关注点: 内容集中在 threat, kernel, cve-2025, actor, attack 等核心主题上。
📝 描述与内容策略
作者将该频道定位为表达主观观点的平台:
“The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...
Partner channel: @cveNotify
For ads: https://telega.io/c/malwr”
凭借高频更新(最新数据采集于 21 七月, 2026),频道始终保持新鲜度与高覆盖。分析显示受众积极互动,使其成为 技术与应用 类别中的关键影响点。
15 367
订阅者
+1624 小时
+1747 天
+71530 天
数据加载中...
吸引订阅者
七月 '26
七月 '26
+489
在1个频道中
六月 '26
+700
在0个频道中
Get PRO
五月 '26
+637
在0个频道中
Get PRO
四月 '26
+476
在1个频道中
Get PRO
三月 '26
+257
在0个频道中
Get PRO
二月 '26
+324
在1个频道中
Get PRO
一月 '26
+348
在0个频道中
Get PRO
十二月 '25
+397
在0个频道中
Get PRO
十一月 '25
+412
在0个频道中
Get PRO
十月 '25
+188
在0个频道中
Get PRO
九月 '25
+95
在2个频道中
Get PRO
八月 '25
+45
在0个频道中
Get PRO
七月 '25
+51
在0个频道中
Get PRO
六月 '25
+46
在1个频道中
Get PRO
五月 '25
+31
在1个频道中
Get PRO
四月 '25
+56
在0个频道中
Get PRO
三月 '25
+22
在0个频道中
Get PRO
二月 '25
+36
在0个频道中
Get PRO
一月 '25
+34
在1个频道中
Get PRO
十二月 '24
+457
在0个频道中
Get PRO
十一月 '24
+1 858
在3个频道中
Get PRO
十月 '24
+980
在0个频道中
Get PRO
九月 '24
+1 070
在1个频道中
Get PRO
八月 '24
+957
在2个频道中
Get PRO
七月 '24
+611
在1个频道中
Get PRO
六月 '24
+483
在0个频道中
Get PRO
五月 '24
+637
在0个频道中
Get PRO
四月 '24
+640
在1个频道中
Get PRO
三月 '24
+806
在2个频道中
Get PRO
二月 '24
+521
在1个频道中
Get PRO
一月 '24
+293
在0个频道中
Get PRO
十二月 '23
+361
在2个频道中
Get PRO
十一月 '23
+85
在2个频道中
Get PRO
十月 '23
+86
在1个频道中
Get PRO
九月 '23
+97
在0个频道中
Get PRO
八月 '23
+85
在0个频道中
Get PRO
七月 '23
+63
在0个频道中
Get PRO
六月 '23
+77
在0个频道中
Get PRO
五月 '23
+65
在0个频道中
Get PRO
四月 '23
+75
在0个频道中
Get PRO
三月 '23
+75
在0个频道中
Get PRO
二月 '23
+38
在0个频道中
Get PRO
一月 '23
+63
在0个频道中
Get PRO
十二月 '22
+99
在0个频道中
Get PRO
十一月 '22
+70
在0个频道中
Get PRO
十月 '22
+101
在0个频道中
Get PRO
九月 '22
+165
在0个频道中
Get PRO
八月 '22
+986
在0个频道中
Get PRO
七月 '22
+27
在0个频道中
Get PRO
六月 '22
+31
在0个频道中
Get PRO
五月 '22
+63
在0个频道中
Get PRO
四月 '22
+72
在0个频道中
Get PRO
三月 '22
+74
在0个频道中
Get PRO
二月 '22
+43
在0个频道中
Get PRO
一月 '22
+112
在0个频道中
Get PRO
十二月 '21
+99
在0个频道中
Get PRO
十一月 '21
+42
在0个频道中
Get PRO
十月 '21
+34
在0个频道中
Get PRO
九月 '21
+36
在0个频道中
Get PRO
八月 '21
+48
在0个频道中
Get PRO
七月 '21
+95
在0个频道中
Get PRO
六月 '21
+77
在0个频道中
Get PRO
五月 '21
+11
在0个频道中
Get PRO
四月 '21
+39
在0个频道中
Get PRO
三月 '21
+28
在0个频道中
Get PRO
二月 '21
+40
在0个频道中
Get PRO
一月 '21
+54
在0个频道中
Get PRO
十二月 '20
+938
在0个频道中
| 日期 | 订阅者增长 | 提及 | 频道 | |
| 21 七月 | +8 | |||
| 20 七月 | +18 | |||
| 19 七月 | +20 | |||
| 18 七月 | +35 | |||
| 17 七月 | +24 | |||
| 16 七月 | +11 | |||
| 15 七月 | +37 | |||
| 14 七月 | +37 | |||
| 13 七月 | +38 | |||
| 12 七月 | +16 | |||
| 11 七月 | +18 | |||
| 10 七月 | +21 | |||
| 09 七月 | +27 | |||
| 08 七月 | +8 | |||
| 07 七月 | +20 | |||
| 06 七月 | +25 | |||
| 05 七月 | +30 | |||
| 04 七月 | +16 | |||
| 03 七月 | +31 | |||
| 02 七月 | +29 | |||
| 01 七月 | +20 |
频道帖子
| 2 | Fake games spread stealers with RenPy Loader, MSBuild and EtherHiding
https://www.malwarebytes.com/blog/threat-intel/2026/07/fake-games-spread-stealers-with-renpy-loader-msbuild-and-etherhiding
🎖@malwr | 440 |
| 3 | cookiengineer/godecompose: :construction: Experimental pattern-based decompiler for Go :construction:
https://github.com/cookiengineer/godecompose
Pattern-based decompiler for Go binaries. Recovers original Go source code by matching known compiler output patterns against disassembled machine code.
🎖@malwr | 605 |
| 4 | Pixels to Payload: Dissecting a Four-Stage Bitmap-Steganography Dropper Delivering AsyncRAT
A technical teardown of a multi-stage .NET dropper chain that hides its loaders inside bitmap pixel channels, wraps an Eazfuscator crypter around an academic epidemiology simulator, and delivers AsyncRAT 0.5.8. Includes pixelchain, a keyless end-to-end chain extractor.
https://blog.threatuniverse.co.uk/posts/asyncrat-bitmap-steganography-dropper/
🎖@malwr | 577 |
| 5 | From Alert to Core Dump: Hunting Zeus Malware Using Suricata, Splunk, YARA, and Volatility
Malware analysis and threat hunting are critical skills for any modern SOC Analyst. To truly understand how adversaries operate, we must…
https://medium.com/@osamamamoussa/from-alert-to-core-dump-hunting-zeus-malware-using-suricata-splunk-yara-and-volatility-4ce18f517f87?sharedUserId=osamamamoussa
🎖@malwr | 520 |
| 6 | helixmap/sigwood: Local-first, transparent threat hunting for the logs you already have: Zeek, Pi-hole, syslog, CloudTrail. Named technique behind every finding. No SIEM, no agent, no black box.
https://github.com/helixmap/sigwood
🎖@malwr | 558 |
| 7 | Windows AppResolver LPE: From AppContainer to SYSTEM
Exploit development for a Windows AppResolver authorization issue fixed in July 2026, from a zero-capability AppContainer to an interactive SYSTEM shell.
https://davidcarliez.github.io/blog/windows-appresolver-lpe-to-system/
🎖@malwr | 497 |
| 8 | OkoBot framework infection chain
Kaspersky GReAT experts dissect the new OkoBot campaign targeting cryptocurrency users. This complex framework employs TookPS, exfiltrates seed phrases, monitors Chromium-based browsers, and installs various malware strains, including the Rilide stealer.
https://securelist.com/okobot-framework-targets-cryptocurrency-wallets/120660/
🎖@malwr | 607 |
| 9 | UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign
Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. and Europe since at least June 2025.
https://blog.talosintelligence.com/uat-11795-deploys-novel-starland-rat-and-bespoke-wldr-c2-implant-in-financially-motivated-campaign/
🎖@malwr | 686 |
| 10 | IDA 9.4 | Hex-Rays Docs
https://docs.hex-rays.com/release-notes/9_4
🎖@malwr | 598 |
| 11 | Schich/Lucky-Spark: A stealthy stager designed for shellcode payloads staged with http/https like Sliver, or on github raw.
https://github.com/Schich/Lucky-Spark
🎖@malwr | 596 |
| 12 | ProfessorQuantumUniverse/Veto: A nice Virus Total Android Client.
https://github.com/ProfessorQuantumUniverse/Veto
🎖@malwr | 502 |
| 13 | One Man, One AI, One Fake Persona: Inside the 5-Year Influence and Fraud ‘Patriot Bait’ Campaign
A solo Russian-speaking threat actor ran a 5-year Telegram channel and, starting September 2025, used AI to automate its content, credential theft, and a cryptocurrency fraud scheme targeting American audiences.
https://www.trendmicro.com/en_us/research/26/e/inside-the-influence-and-fraud-patriot-bait-campaign.html
🎖@malwr | 408 |
| 14 | endgamec2framework/endgame: ENDGAME C2 FRAMEWORK — AI-powered command and control for professional red team operations
https://github.com/endgamec2framework/endgame
🎖@malwr | 392 |
| 15 | 2026-06-01: SmartApeSG ClickFix --> Unidentified RAT
https://www.malware-traffic-analysis.net/2026/06/01/index.html
🎖@malwr | 364 |
| 16 | 2026-06-22: SHub Stealer infection (macOS)
https://www.malware-traffic-analysis.net/2026/06/22/index.html
🎖@malwr | 391 |
| 17 | Anatomy of a CUDA Binary
When you compile a CUDA kernel, the final artifact is a cubin — a CUDA binary. It is a standard ELF64 file with NVIDIA-specific sections that encode everything the CUDA driver needs to load and launch a kernel: the machine code, the parameter layout, register allocation metadata, and a collection of attributes that have no public documentation.
https://hiraditya.github.io/posts/anatomy-of-a-cuda-binary/
🎖@malwr | 434 |
| 18 | Suspected Chinese Operators Use Claude Code and DeepSeek to Breach Government Systems Across Four Countries
An exposed open directory revealed a suspected Chinese campaign using Claude Code and DeepSeek-v4-pro to breach government systems in Afghanistan, Thailand, and Taiwan, with parallel probing of financial services worldwide.
https://hunt.io/blog/chinese-operators-claude-deepseek-government-intrusion
🎖@malwr | 407 |
| 19 | Bind Link Abuse: One Windows Feature, Many Ways to Blind Your EDR
I’d like to thank my coauthors, Andrei-Marius Muntea, Andrei Mermeze, Radu-Marian Portase, and Vlad Lazar, for their invaluable contributions to this research.
https://www.bitdefender.com/en-us/blog/businessinsights/bind-link-abuses-windows-feature-edr-evasion-technique
🎖@malwr | 421 |
| 20 | TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development
TuxBot v3 Evolution, an IoT botnet framework built with LLMs. Read our analysis of its cross-compiled binaries, C2 architecture and bugs.
https://unit42.paloaltonetworks.com/tuxbot-v3-evolution-iot-botnet/
🎖@malwr | 483 |
