Malware News
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ... Partner channel: @cveNotify For ads: https://telega.io/c/malwr
Show more📈 Analytical overview of Telegram channel Malware News
Channel Malware News (@malwr) in the English language segment is an active participant. Currently, the community unites 16 179 subscribers, ranking 7 744 in the Technologies & Applications category and 2 304 in the USA region.
📊 Audience metrics and dynamics
Since its creation on невідомо, the project has demonstrated rapid growth, gathering an audience of 16 179 subscribers.
According to the latest data from 14 September, 2026, the channel demonstrates stable activity. Although there has been a change in the number of participants by 147 over the last 30 days and by -6 over the last 24 hours, overall reach remains high.
- Verification status: Not verified
- Engagement rate (ER): The average audience engagement rate is 3.72%. Within the first 24 hours after publication, content typically collects 1.93% reactions from the total number of subscribers.
- Post reach: On average, each post receives 602 views. Within the first day, a publication typically gains 313 views.
- Reactions and interaction: The audience actively supports content: the average number of reactions per post is 1.
- Thematic interests: Content is focused on key topics such as threat, kernel, cve-2025, actor, attack.
📝 Description and content policy
The author describes the resource as a platform for expressing subjective opinions:
“The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...
Partner channel: @cveNotify
For ads: https://telega.io/c/malwr”
Thanks to the high frequency of updates (latest data received on 15 September, 2026), the channel maintains relevance and a high level of publication reach. Analytics show that the audience actively interacts with content, making it an important point of influence in the Technologies & Applications category.
Data loading in progress...
| Date | Subscriber Growth | Mentions | Channels | |
| 15 September | 0 | |||
| 14 September | 0 | |||
| 13 September | +2 | |||
| 12 September | +7 | |||
| 11 September | 0 | |||
| 10 September | 0 | |||
| 09 September | 0 | |||
| 08 September | 0 | |||
| 07 September | 0 | |||
| 06 September | +2 | |||
| 05 September | 0 | |||
| 04 September | +3 | |||
| 03 September | +1 | |||
| 02 September | 0 | |||
| 01 September | 0 |
| 2 | bombinisecurity/bombini: eBPF Security Monitoring and Sandboxing Agent Based on Aya
https://github.com/bombinisecurity/bombini
🎖@malwr | 302 |
| 3 | Idov31/Silverseal: Silverseal is a Linux framework containing a bootkit, rootkit loader and a rootkit
https://github.com/Idov31/Silverseal
🎖@malwr | 278 |
| 4 | LumosLab-Innovation/OpenHunterAI: Local-first AI red team for web, API, and LLM application security. Attacker-style reasoning, evidence-backed findings, and skills for AI coding agents.
https://github.com/LumosLab-Innovation/OpenHunterAI
🎖@malwr | 364 |
| 5 | The Harness Matters: Cutting AI Reverse-Engineering Tokens by 33%
A controlled AgentRE-Bench comparison shows how Reverser Space used 33% fewer tokens and 35% fewer analysis calls without a meaningful score loss.
https://reverser.space/blog/the-harness-matters-ai-reverse-engineering/
🎖@malwr | 430 |
| 6 | Black God Linux — Offensive Security, Re-Engineered
Purpose-built for speed and automation. 300+ tools, 5.4x faster recon velocity, and native Apple Silicon hardware acceleration.
https://sabarishyuvasri8-del.github.io/black-god-linux/
🎖@malwr | 359 |
| 7 | Ilias1988/LOLBins-Reference: A unified, interactive reference for Living Off The Land Binaries (LOLBAS & GTFOBins). Features a dynamic payload builder (LHOST/LPORT), real-time search, MITRE ATT&CK mapping, and auto-updates from official sources.
https://livingofftheland.dev/
https://github.com/Ilias1988/LOLBins-Reference
🎖@malwr | 488 |
| 8 | Decompilation Book
Build a decompiler to understand one. A chapter-by-chapter walk from RV32I machine code back to readable C, with the working Python implementation open beside you.
https://decompilation.education/
🎖@malwr | 537 |
| 9 | Once in a BlueMoon: Multiple State-Aligned Threat Actors Rapidly Adopt Novel Exploit Chain Using Chrome and Windows Zero-Days | Proofpoint US
Analyst note: Proofpoint uses the UNK_ designator to define clusters of activity that are still developing and have not been observed for long enough to receive a numerical TA designation.
https://www.proofpoint.com/us/blog/threat-insight/once-bluemoon-multiple-state-aligned-threat-actors-rapidly-adopt-novel-exploit
🎖@malwr | 447 |
| 10 | Casbaneiro: A Banking Trojan with Distributed Data-Receiving Servers | FortiGuard Labs
FortiGuard Labs examines how a new Casbaneiro campaign targeting Latin America uses geofencing and distributed servers to evade analysis and detection…
https://www.fortinet.com/blog/threat-research/casbaneiro-a-banking-trojan-with-distributed-data-receiving-servers
🎖@malwr | 359 |
| 11 | AsyncRAT Delivered via AutoIT: Full Chain Analysis | Point Wild
Point Wild
https://www.pointwild.com/threat-intelligence/asyncrat-delivered-via-autoit-full-chain-analysis/
🎖@malwr | 323 |
| 12 | Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure
An investigation into how cybercriminals used YouTube gaming lures and SEO poisoning to deliver multi-payload malware to enterprise networks.
https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/
🎖@malwr | 339 |
| 13 | matheus-git/binkit: A modular toolbox for analyzing, disassembling, and patching binary formats.
https://github.com/matheus-git/binkit/
🎖@malwr | 388 |
| 14 | SnailSploit/Claude-Red: claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SKILL.md file that primes Claude with expert-level methodology for a specific attack surface — from SQLi to shellcode, EDR evasion to exploit development.
https://github.com/SnailSploit/Claude-Red
🎖@malwr | 457 |
| 15 | 2026-09-11: Traffic analysis exercise - Kongtuke Rebuke!
https://www.malware-traffic-analysis.net/2026/09/11/index.html
🎖@malwr | 457 |
| 16 | https://www-cdn.anthropic.com/e50be2e51e7695dc4b1366a37a245a597377d3b5/Anthropic-Detecting-and-countering-091026.pdf
Detecting and countering misuse of AI
September 2026
🎖@malwr | 460 |
| 17 | PirusPoker/ghidra-ai-copilot: AI reverse-engineering assistant for Ghidra - analyze functions with Claude, right inside the tool.
https://github.com/PirusPoker/ghidra-ai-copilot
🎖@malwr | 522 |
| 18 | Windows Kernel Pool Internals
Good morning! In today’s blog post we’re going to dive into a topic that has interested me for quite some time, the Windows kernel pool. It’s a topic that tends to have “scarce” documentation online and can be somewhat intricate. That’s precisely why it has captured my attention from the beginning.
https://r0keb.github.io/posts/Windows-Kernel-Pool-Internals/
🎖@malwr | 488 |
| 19 | Userland Guard Page Neutralization
Welcome to this new Medium post. In this one, we are going to look at two very simple ways to bypass or evade Guard Pages placed within our…
https://medium.com/@s12deff/userland-guard-page-neutralization-f121c012de49
🎖@malwr | 409 |
| 20 | Magisk — Android customization suite providing root access (MagiskSU), systemless module installation, boot image unpacking/repacking, and Zygisk runtime code injection for advanced device modification. | Kitploit
Android customization suite providing root access (MagiskSU), systemless module installation, boot image unpacking/repacking, and Zygisk runtime code injection for advanced device modification.
https://kitploit.com/en/tools/github/topjohnwu/magisk
🎖@malwr | 334 |
