en
Feedback
Malware News

Malware News

Open in Telegram

The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ... Partner channel: @cveNotify For ads: https://telega.io/c/malwr

Show more

📈 Analytical overview of Telegram channel Malware News

Channel Malware News (@malwr) in the English language segment is an active participant. Currently, the community unites 16 243 subscribers, ranking 7 844 in the Technologies & Applications category and 2 332 in the USA region.

📊 Audience metrics and dynamics

Since its creation on невідомо, the project has demonstrated rapid growth, gathering an audience of 16 243 subscribers.

According to the latest data from 25 August, 2026, the channel demonstrates stable activity. Although there has been a change in the number of participants by 712 over the last 30 days and by 16 over the last 24 hours, overall reach remains high.

  • Verification status: Not verified
  • Engagement rate (ER): The average audience engagement rate is 3.49%. Within the first 24 hours after publication, content typically collects 2.11% reactions from the total number of subscribers.
  • Post reach: On average, each post receives 566 views. Within the first day, a publication typically gains 343 views.
  • Reactions and interaction: The audience actively supports content: the average number of reactions per post is 2.
  • Thematic interests: Content is focused on key topics such as threat, kernel, cve-2025, actor, attack.

📝 Description and content policy

The author describes the resource as a platform for expressing subjective opinions:
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ... Partner channel: @cveNotify For ads: https://telega.io/c/malwr

Thanks to the high frequency of updates (latest data received on 26 August, 2026), the channel maintains relevance and a high level of publication reach. Analytics show that the audience actively interacts with content, making it an important point of influence in the Technologies & Applications category.

16 243
Subscribers
+1624 hours
+1387 days
+71230 days
Attracting Subscribers
August '26
August '26
+596
in 3 channels
July '26
+806
in 2 channels
Get PRO
June '26
+700
in 0 channels
Get PRO
May '26
+637
in 0 channels
Get PRO
April '26
+476
in 1 channels
Get PRO
March '26
+257
in 0 channels
Get PRO
February '26
+324
in 1 channels
Get PRO
January '26
+348
in 0 channels
Get PRO
December '25
+397
in 0 channels
Get PRO
November '25
+412
in 0 channels
Get PRO
October '25
+188
in 0 channels
Get PRO
September '25
+95
in 2 channels
Get PRO
August '25
+45
in 0 channels
Get PRO
July '25
+51
in 0 channels
Get PRO
June '25
+46
in 1 channels
Get PRO
May '25
+31
in 1 channels
Get PRO
April '25
+56
in 0 channels
Get PRO
March '25
+22
in 0 channels
Get PRO
February '25
+36
in 0 channels
Get PRO
January '25
+34
in 1 channels
Get PRO
December '24
+457
in 0 channels
Get PRO
November '24
+1 858
in 3 channels
Get PRO
October '24
+980
in 0 channels
Get PRO
September '24
+1 070
in 1 channels
Get PRO
August '24
+957
in 2 channels
Get PRO
July '24
+611
in 1 channels
Get PRO
June '24
+483
in 0 channels
Get PRO
May '24
+637
in 0 channels
Get PRO
April '24
+640
in 1 channels
Get PRO
March '24
+806
in 2 channels
Get PRO
February '24
+521
in 1 channels
Get PRO
January '24
+293
in 0 channels
Get PRO
December '23
+361
in 2 channels
Get PRO
November '23
+85
in 2 channels
Get PRO
October '23
+86
in 1 channels
Get PRO
September '23
+97
in 0 channels
Get PRO
August '23
+85
in 0 channels
Get PRO
July '23
+63
in 0 channels
Get PRO
June '23
+77
in 0 channels
Get PRO
May '23
+65
in 0 channels
Get PRO
April '23
+75
in 0 channels
Get PRO
March '23
+75
in 0 channels
Get PRO
February '23
+38
in 0 channels
Get PRO
January '23
+63
in 0 channels
Get PRO
December '22
+99
in 0 channels
Get PRO
November '22
+70
in 0 channels
Get PRO
October '22
+101
in 0 channels
Get PRO
September '22
+165
in 0 channels
Get PRO
August '22
+986
in 0 channels
Get PRO
July '22
+27
in 0 channels
Get PRO
June '22
+31
in 0 channels
Get PRO
May '22
+63
in 0 channels
Get PRO
April '22
+72
in 0 channels
Get PRO
March '22
+74
in 0 channels
Get PRO
February '22
+43
in 0 channels
Get PRO
January '22
+112
in 0 channels
Get PRO
December '21
+99
in 0 channels
Get PRO
November '21
+42
in 0 channels
Get PRO
October '21
+34
in 0 channels
Get PRO
September '21
+36
in 0 channels
Get PRO
August '21
+48
in 0 channels
Get PRO
July '21
+95
in 0 channels
Get PRO
June '21
+77
in 0 channels
Get PRO
May '21
+11
in 0 channels
Get PRO
April '21
+39
in 0 channels
Get PRO
March '21
+28
in 0 channels
Get PRO
February '21
+40
in 0 channels
Get PRO
January '21
+54
in 0 channels
Get PRO
December '20
+938
in 0 channels
Date
Subscriber Growth
Mentions
Channels
26 August+16
25 August+18
24 August+23
23 August+15
22 August+21
21 August+24
20 August+24
19 August+17
18 August+22
17 August+13
16 August+15
15 August+23
14 August+38
13 August+29
12 August+28
11 August+30
10 August+15
09 August+20
08 August+27
07 August+21
06 August+25
05 August+24
04 August+20
03 August+34
02 August+34
01 August+20
Channel Posts
PPEE (puppy) 1.15 PPEE is a Professional PE file Explorer for reversers, malware researchers and those who want to statically inspect PE files in more detail
- Clustering/Similarity engine added (Hash data is stored locally in a sqlite db next to PPEE). Similar binaries are notified and grouped by color. - Multi-file supported with flexible tabs - Long-awaited Settings dialog added - File Information added in PPEE (Ported from FileInfo plugin) - Progressbar added for heavy jobs - Warning/Error dot added to the treeview items - AMD64 and ARM64 Exception Dir support - .Net/CLR parsing improved with edit capability - New debug types supported (FPO, MISC, BBT/RSRVD10, VC_FEAT, POGO, ILTCG, DLL_CHAR, PDB_CHECKSUM, EMDEDDED_PORTABLE_PDB, PERFMAP) with edit capability - UI is now DPI aware - WoW64 redirection support - PPEE is now faster (Highly refactored and unnecessary MFC, stdafx libraries removed from source code) - Windows XP supported - Bugfixes
https://mzrst.com/ 🎖@malwr

2
MmMapIoSpace Returns NULL: Tracing the Real Kernel Mechanism Through ntoskrnl Tracing exactly why MmMapIoSpace returns NULL on Windows 11 past the commonly cited explanations and into undocumented page table ownership checks inside the kernel. https://sibouzitoun.tech/articles/mmmapiospace-returns-null-tracing-the-real-kernel-mechanism-through-ntoskrnlexe/ 🎖@malwr
221
3
https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-237a 🎖@malwr
311
4
Handle Redirect Welcome to this new Medium post. In this one we will see how to redirect a handle’s kernel object pointer to a different EPROCESS, getting… https://medium.com/@s12deff/handle-redirect-549902e6d868 🎖@malwr
316
5
Local Privilege Escalation To System In Wibu-Systems CodeMeter Application | Shelltrail This research post describes the process of finding and exploiting a local privilege escalation in the Wibu-Systems CodeMeter application https://shelltrail.com/research/local-privilege-escalation-to-system-in-wibu-systems-codemeter-application 🎖@malwr
440
6
jyatesdotdev/wd-smart-reader: macOS CLI tool for reading SMART data from WD external drives (MyBook, Elements) via SES diagnostic pages. Works on Apple Silicon, no kernel extensions needed. https://github.com/jyatesdotdev/wd-smart-reader 🎖@malwr
427
7
Malware development trick 63: modifying PE version metadata and icon. Simple C example ﷽ https://cocomelonc.github.io/malware/2026/08/24/malware-tricks-63.html 🎖@malwr
417
8
Manic: Blend between Banking Malware & Spyware Manic is a newly identified Android malware family with broad surveillance and remote-control capabilities, introducing an unusual Wi‑Fi mesh technique. https://www.threatfabric.com/blogs/manic-blend-between-banking-malware-and-spyware 🎖@malwr
376
9
daniomass/SliverMirage: Crystal Palace PICO loader for Sliver C2 dual-layer AMSI bypass, ETW silencing, AES-256-CBC encrypted payloads, 6 delivery variants https://github.com/daniomass/SliverMirage 🎖@malwr
320
10
The Citizen Lab Bad Connection: Uncovering Global Telecom Exploitation by Covert Surveillance Actors Our investigation uncovers two sophisticated telecom surveillance campaigns and, for the first time, links real-world attack traffic to mobile operator signalling infrastructure. The findings expose how suspected commercial surveillance vendors (CSVs) exploit the global telecom interconnect ecosystem, leverage private operator networks, and conduct covert location tracking operations that can persist undetected for years. https://citizenlab.ca/research/uncovering-global-telecom-exploitation-by-covert-surveillance-actors/ 🎖@malwr
293
11
Inside the Falcon How CrowdStrike Catches You A full reverse-engineering teardown of the CrowdStrike Falcon sensor: the six kernel callback sources, the WFP network engine, the file-system minifilter, the cspcm4 broker, the user-mode service (DNS / AMSI / browser / Identity Protection), and the cloud-loaded detection engine — plus every structural blind spot. How Falcon sees you, and where the seams are. https://0xdbgman.github.io/posts/inside-the-falcon-how-crowdstrike-catches-you/ 🎖@malwr
310
12
Your executable is a SQLite database I have been probably obsessed with two things in the last few years: Nix as a tool to explore innovative ideas that require the capability to rebuild the world and replacing ELF with SQLite as an executable format. You might have noticed that these two ideas are well suited to each other. https://fzakaria.com/2026/08/23/your-executable-is-a-sqlite-database 🎖@malwr
426
13
Tracking PavinLoader across ClickFix and fake download campaigns We found PavinLoader being used across ClickFix, fake software, and RenPy campaigns to deliver Amatera Stealer and other malware. https://www.malwarebytes.com/blog/threat-intel/2026/08/tracking-pavinloader-across-clickfix-and-fake-download-campaigns 🎖@malwr
459
14
Text Template Text template files can contain C# or Visual Basic code that could be compiled and executed at build time. Threat actors can create or modify .tt files to execute code in the context of a trusted p… https://ipurple.team/2026/08/24/text-template/ 🎖@malwr
420
15
Reverse Engineering a 0day used Against EDRs https://medium.com/@jehadbudagga/reverse-engineering-a-0day-used-against-crowdstrike-edr-a5ea1fbe3fd4 🎖@malwr
421
16
Inside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asia | Enki White Hat Inside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asia https://www.enki.co.kr/en/media-center/blog/inside-kimsuky-s-abuse-of-legitimate-remote-control-tools-across-northeast-asia 🎖@malwr
374
17
SLEEPWALKER: A Passive Backdoor With Its Own Command Language Losing access to VirusTotal Intelligence at the start of the year was surprisingly productive. Unable to hunt for interesting new malware, I stopped adding to my “TODO” pile and finally worked through my backlog from last year. That led to a detailed examination of BeheMOF as well as the discovery of this malware. Upon closer inspection, a sample that did not seem too noteworthy at first turned out to have a distinctive design once I looked under the hood: a passive backdoor that opens no obvious listening port and carries no payload inside itself. It waits in memory doing nothing at all until one specifically crafted network packet reaches the machine, which is why I am calling it SLEEPWALKER. https://r136a1.dev/2026/08/24/sleepwalker-a-passive-backdoor-with-its-own-command-language/ 🎖@malwr
355
18
Fairy Law: Abusing MicrosoftSignedOnly Welcome to this new Medium post. In this one we will see how a legitimate Windows process mitigation policy can be abused to globally… https://medium.com/@s12deff/fairy-law-abusing-microsoftsignedonly-8d35018bc99f 🎖@malwr
414
19
Auditing Microsoft Defender and Intune Configuration Changes Microsoft is clearly moving toward a more unified security operations experience within the Defender portal. Over the last few years, we have seen Microsoft bring more security capabilities together under the Defender platform. Instead of working with completely separate portals... https://jeffreyappel.nl/auditing-microsoft-defender-and-intune-configuration-changes/ 🎖@malwr
491
20
tracebyte8/SysTrace: SysTrace - Linux System Call Monitor using PTRACE API , It traces system calls, monitors process, file, network, and memory activity, detects suspicious behavior, and generates detailed security reports. https://github.com/tracebyte8/SysTrace 🎖@malwr
1 041