en
Feedback
Malware News

Malware News

Open in Telegram

The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ... Partner channel: @cveNotify For ads: https://telega.io/c/malwr

Show more

πŸ“ˆ Analytical overview of Telegram channel Malware News

Channel Malware News (@malwr) in the English language segment is an active participant. Currently, the community unites 16 117 subscribers, ranking 7 776 in the Technologies & Applications category and 2 298 in the USA region.

πŸ“Š Audience metrics and dynamics

Since its creation on Π½Π΅Π²Ρ–Π΄ΠΎΠΌΠΎ, the project has demonstrated rapid growth, gathering an audience of 16 117 subscribers.

According to the latest data from 05 October, 2026, the channel demonstrates stable activity. Although there has been a change in the number of participants by -129 over the last 30 days and by -7 over the last 24 hours, overall reach remains high.

  • Verification status: Not verified
  • Engagement rate (ER): The average audience engagement rate is 4.56%. Within the first 24 hours after publication, content typically collects 2.10% reactions from the total number of subscribers.
  • Post reach: On average, each post receives 734 views. Within the first day, a publication typically gains 339 views.
  • Reactions and interaction: The audience actively supports content: the average number of reactions per post is 2.
  • Thematic interests: Content is focused on key topics such as threat, kernel, cve-2025, actor, attack.

πŸ“ Description and content policy

The author describes the resource as a platform for expressing subjective opinions:
β€œThe latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ... Partner channel: @cveNotify For ads: https://telega.io/c/malwr”

Thanks to the high frequency of updates (latest data received on 06 October, 2026), the channel maintains relevance and a high level of publication reach. Analytics show that the audience actively interacts with content, making it an important point of influence in the Technologies & Applications category.

16 117
Subscribers
-724 hours
-347 days
-12930 days
Attracting Subscribers
Oct '26
October '26
+5
in 0 channels
September '26
+57
in 0 channels
Get PRO
August '26
+647
in 3 channels
Get PRO
July '26
+806
in 2 channels
Get PRO
June '26
+700
in 0 channels
Get PRO
May '26
+637
in 0 channels
Get PRO
April '26
+476
in 1 channels
Get PRO
March '26
+257
in 0 channels
Get PRO
February '26
+324
in 1 channels
Get PRO
January '26
+348
in 0 channels
Get PRO
December '25
+397
in 0 channels
Get PRO
November '25
+412
in 0 channels
Get PRO
October '25
+188
in 0 channels
Get PRO
September '25
+95
in 2 channels
Get PRO
August '25
+45
in 0 channels
Get PRO
July '25
+51
in 0 channels
Get PRO
June '25
+46
in 1 channels
Get PRO
May '25
+31
in 1 channels
Get PRO
April '25
+56
in 0 channels
Get PRO
March '25
+22
in 0 channels
Get PRO
February '25
+36
in 0 channels
Get PRO
January '25
+34
in 1 channels
Get PRO
December '24
+457
in 0 channels
Get PRO
November '24
+1 858
in 3 channels
Get PRO
October '24
+980
in 0 channels
Get PRO
September '24
+1 070
in 1 channels
Get PRO
August '24
+957
in 2 channels
Get PRO
July '24
+611
in 1 channels
Get PRO
June '24
+483
in 0 channels
Get PRO
May '24
+637
in 0 channels
Get PRO
April '24
+640
in 1 channels
Get PRO
March '24
+806
in 2 channels
Get PRO
February '24
+521
in 1 channels
Get PRO
January '24
+293
in 0 channels
Get PRO
December '23
+361
in 2 channels
Get PRO
November '23
+85
in 2 channels
Get PRO
October '23
+86
in 1 channels
Get PRO
September '23
+97
in 0 channels
Get PRO
August '23
+85
in 0 channels
Get PRO
July '23
+63
in 0 channels
Get PRO
June '23
+77
in 0 channels
Get PRO
May '23
+65
in 0 channels
Get PRO
April '23
+75
in 0 channels
Get PRO
March '23
+75
in 0 channels
Get PRO
February '23
+38
in 0 channels
Get PRO
January '23
+63
in 0 channels
Get PRO
December '22
+99
in 0 channels
Get PRO
November '22
+70
in 0 channels
Get PRO
October '22
+101
in 0 channels
Get PRO
September '22
+165
in 0 channels
Get PRO
August '22
+986
in 0 channels
Get PRO
July '22
+27
in 0 channels
Get PRO
June '22
+31
in 0 channels
Get PRO
May '22
+63
in 0 channels
Get PRO
April '22
+72
in 0 channels
Get PRO
March '22
+74
in 0 channels
Get PRO
February '22
+43
in 0 channels
Get PRO
January '22
+112
in 0 channels
Get PRO
December '21
+99
in 0 channels
Get PRO
November '21
+42
in 0 channels
Get PRO
October '21
+34
in 0 channels
Get PRO
September '21
+36
in 0 channels
Get PRO
August '21
+48
in 0 channels
Get PRO
July '21
+95
in 0 channels
Get PRO
June '21
+77
in 0 channels
Get PRO
May '21
+11
in 0 channels
Get PRO
April '21
+39
in 0 channels
Get PRO
March '21
+28
in 0 channels
Get PRO
February '21
+40
in 0 channels
Get PRO
January '21
+54
in 0 channels
Get PRO
December '20
+938
in 0 channels
Date
Subscriber Growth
Mentions
Channels
06 October+3
05 October0
04 October+1
03 October+1
02 October0
01 October0
Channel Posts
morluto/rea: Reverse engineer anything with agents, from app behavior down to native binaries. https://github.com/morluto/rea πŸŽ–@malwr

2
grisuno/LazyOwn: LazyOwn RedTeam/APT Framework is the first RedTeam Framework with an AI-powered C&C, featuring rootkits to conceal campaigns, undetectable malleable implants compatible with Windows/Linux/Mac OSX, and self-configuring backdoors. With its Web interface and powerful Console Client, it is the best combination for your Autonomous RedTeam/APT campaigns. https://github.com/grisuno/lazyown πŸŽ–@malwr
753
3
AkaTorich/KernelFlirt: KernelFlirt is powerful kernel debugger. https://github.com/akatorich/kernelflirt πŸŽ–@malwr
600
4
PaperCut MF Zero-Day Intrusion: Java Loader, Web Shell, and AdaptixC2 via CVE-2026-82078 and CVE-2026-81578 eSentire TRU details a PaperCut MF zero-day intrusion (CVE-2026-82078, CVE-2026-81578) using a Java loader, web shell, and trojanized Copilot binary to deploy AdaptixC2. https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578 πŸŽ–@malwr
613
5
China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor Cisco Talos uncovered a cluster of activity we track as UAT-11587 targeting government and policy organizations across Asia, including in Taiwan, India, the Philippines, and Cambodia, to deliver a previously undocumented backdoor referred to as β€œAntino” in developer artifacts. https://blog.talosintelligence.com/china-nexus-uat-11587-targets-government-and-policy-organizations-across-asia-with-antino-backdoor/ πŸŽ–@malwr
593
6
JoasASantos/Offensive-Security-AI-Models: Uncensored AI models or those fine-tuned for cybersecurity tasks. https://github.com/JoasASantos/Offensive-Security-AI-Models πŸŽ–@malwr
635
7
NeedyMantis: Unpacking a post-compromise malware family used in targeted operations | Microsoft Security Blog Microsoft Threat Intelligence identified NeedyMantis, a modular post-compromise malware framework used in targeted intrusions that combines custom loaders, encrypted archives, and extensible components to maintain long-term access and support follow-on operations. https://www.microsoft.com/en-us/security/blog/2026/09/28/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations/ πŸŽ–@malwr
556
8
Uncovering a SectopRAT Variant Embedded in Legitimate Software | FortiGuard Labs Analysis of a SectopRAT variant hidden in tampered legitimate software that steals credentials and enables remote system control… https://www.fortinet.com/blog/threat-research/uncovering-a-sectoprat-variant-embedded-in-legitimate-software πŸŽ–@malwr
470
9
TwoSevenOneT/InjectSetConsole: Proof of Concept for Process Code Injection Without Using WriteProcessMemory https://github.com/TwoSevenOneT/InjectSetConsole πŸŽ–@malwr
425
10
https://medium.com/@Root0ne/muddywaters-rented-arsenal-and-its-traces-in-the-russian-maas-market-d58965401f15 πŸŽ–@malwr
436
11
rPlayAI/rPlayHub: iPhone Mirroring for macOS and Linux β€” scrcpy for iOS and a cross-platform Device Hub clone. Mirror and control an iPhone (iOS 27+); Raspberry Pi and Windows next. Part of rPlay. https://github.com/rPlayAI/rPlayHub πŸŽ–@malwr
508
12
newliver666/apk-reverse: Suitable for Android APK reverse engineering analysis https://github.com/newliver666/apk-reverse An Agent Skill for Android APK reverse engineering, debloating, ad removal, surgical dex patching, repacking, and runtime/server analysis. πŸŽ–@malwr
649
13
EDR Evasion: Process Injection Without WriteProcessMemory Technique performs Windows process code injection by leveraging a Windows named pipe, it does not use VirtualAllocEx and WriteProcessMemory https://www.zerosalarium.com/2026/09/edr-evasion-process-injection-without-WriteProcessMemory.html πŸŽ–@malwr
662
14
nbs32k/LocalStranger: PoC for WinNotify, demonstrated through a driver mapper, and local privilege escalation. https://github.com/nbs32k/LocalStranger πŸŽ–@malwr
630
15
ngwg/ceasta: disassembler, decompiler and debugger in one, with a built-in mcp server: point an ai at a binary and it can debug it, not just read it. ida-style listing, pseudocode (f5), x64dbg-style debugger (windows and linux), binary diff, lua plugins. reads pe, elf and mach-o. runs on windows, linux and macos. https://github.com/ngwg/ceasta πŸŽ–@malwr
637
16
Kothamine malware uses Tailscale’s tailcat to evade network detection Kothamine uses a legitimate Tailscale tool to receive attackers’ commands through an encrypted connection with no malicious domain to block. https://www.malwarebytes.com/blog/threat-intel/2026/09/kothamine-malware-uses-tailscales-tailcat-to-evade-network-detection πŸŽ–@malwr
697
17
Bypassing EDR with Local AI How hard is it to bypass EDR in the modern times with AI? As it turns out, not very hard. https://projectblack.io/blog/bypassing-edr-with-local-ai/ πŸŽ–@malwr
788
18
Part 2: Visual-layer hiding β€” Hawkeye Research Visual-layer anti-capture in DWM: CVisual::HasProtectedContent (bit 7 at +0x6A), vtable heap scan, HWND/PID attribution, and defender-side detection on Windows 10/11. https://hawkeye-leo.github.io/hawkeye/research/capture/02-visual-hiding/ πŸŽ–@malwr
756
19
HimitsuShell/HimitsuShell: shell script protector (obfuscation, embedded interpreter, DRM) - invisible to kernel tracing https://github.com/HimitsuShell/HimitsuShell πŸŽ–@malwr
733
20
Inside a multi stage toll fraud operation targeting Poland CERT Polska uncovered a toll fraud operation targeting Polish users through deceptive Meta advertisements and malicious applications distributed via Google Play. We preserved 1235 ads, linked 852 to 17 applications through code or infrastructure, reconstructed the complete execution chain, and observed live premium SMS and carrier billing tasking. https://cert.pl/en/posts/2026/09/tollfraud-analysis/ πŸŽ–@malwr
690