Malware News
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ... Partner channel: @cveNotify For ads: https://telega.io/c/malwr
Show more📈 Analytical overview of Telegram channel Malware News
Channel Malware News (@malwr) in the English language segment is an active participant. Currently, the community unites 15 446 subscribers, ranking 8 295 in the Technologies & Applications category and 2 462 in the USA region.
📊 Audience metrics and dynamics
Since its creation on невідомо, the project has demonstrated rapid growth, gathering an audience of 15 446 subscribers.
According to the latest data from 23 July, 2026, the channel demonstrates stable activity. Although there has been a change in the number of participants by 707 over the last 30 days and by 30 over the last 24 hours, overall reach remains high.
- Verification status: Not verified
- Engagement rate (ER): The average audience engagement rate is 3.91%. Within the first 24 hours after publication, content typically collects 2.21% reactions from the total number of subscribers.
- Post reach: On average, each post receives 604 views. Within the first day, a publication typically gains 341 views.
- Reactions and interaction: The audience actively supports content: the average number of reactions per post is 2.
- Thematic interests: Content is focused on key topics such as threat, kernel, cve-2025, actor, attack.
📝 Description and content policy
The author describes the resource as a platform for expressing subjective opinions:
“The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...
Partner channel: @cveNotify
For ads: https://telega.io/c/malwr”
Thanks to the high frequency of updates (latest data received on 24 July, 2026), the channel maintains relevance and a high level of publication reach. Analytics show that the audience actively interacts with content, making it an important point of influence in the Technologies & Applications category.
Data loading in progress...
| Date | Subscriber Growth | Mentions | Channels | |
| 24 July | +15 | |||
| 23 July | +35 | |||
| 22 July | +20 | |||
| 21 July | +23 | |||
| 20 July | +18 | |||
| 19 July | +20 | |||
| 18 July | +35 | |||
| 17 July | +24 | |||
| 16 July | +11 | |||
| 15 July | +37 | |||
| 14 July | +37 | |||
| 13 July | +38 | |||
| 12 July | +16 | |||
| 11 July | +18 | |||
| 10 July | +21 | |||
| 09 July | +27 | |||
| 08 July | +8 | |||
| 07 July | +20 | |||
| 06 July | +25 | |||
| 05 July | +30 | |||
| 04 July | +16 | |||
| 03 July | +31 | |||
| 02 July | +29 | |||
| 01 July | +20 |
| 2 | oxasploits/PacketSnitch: PacketSnitch is a network analysis platform that transforms packet captures into searchable, protocol-aware intelligence, helping security professionals, developers, and researchers rapidly uncover hosts, credentials, certificates, files, locations, protocols, anomalies, threat intel, and other actionable insights.
https://github.com/oxasploits/PacketSnitch
🎖@malwr | 313 |
| 3 | Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged
An exposed open directory on a Hong Kong server revealed an autonomous AI agent running unattended, an unreported Go implant, and target-specific tooling used against Thailand's Ministry of Finance.
https://hunt.io/blog/thailand-ministry-finance-targeted-with-hermes-ai-agent
🎖@malwr | 409 |
| 4 | TAG-195 Upgrades MaaS Ecosystem with Modular Tools
Insikt Group identifies four new TAG-195 malware families, revealing an architectural transition toward modular, operator-driven tooling in the MaaS ecosystem
https://www.recordedfuture.com/research/tag-195-evolves-maas-ecosystem
https://assets.recordedfuture.com/insikt-report-pdfs/2026/cta-2026-0723.pdf
🎖@malwr | 407 |
| 5 | Thanks guys for the gift 🙏❤️
@SirMalware | 457 |
| 6 | Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel
The Chaos ransomware group uses new malware "msaRAT" that hijacks browsers. The malware doesn't communicate directly with C2 but connects through the browser. It enables arbitrary command execution while hiding the attacker's IP from victims via WebRTC over TURN.
https://blog.talosintelligence.com/chaos-msarat-living-off-the-browser-to-build-covert-c2-channel/
🎖@malwr | 458 |
| 7 | Six Minutes to Compromise: How ‘Patriot Bait’ Actor Used AI to Build and Deploy a C&C Botnet
TrendAI™ Research analyzed over 200 Gemini CLI session logs showing how a Russian-speaking threat actor used AI to run a live botnet, finishing a full C&C migration in six minutes while doing just 11% of the work himself.
https://www.trendmicro.com/en_us/research/26/g/actor-behind-patriot-bait-used-ai-to-deploy-c2-botnet.html
🎖@malwr | 449 |
| 8 | PE OopsSec: Mind your PE, guard your OPSEC
PE-OopsSec helps red teams, pentesters, and game developers give their payloads a final once‑over before putting them into the real world
https://www.zerosalarium.com/2026/07/pe-oopssec-mind-your-pe-guard-your-opsec.html
🎖@malwr | 368 |
| 9 | Device Code Phishing: Turning a Convenience Feature Into an MFA Bypass
Device code phishing abuses a legitimate authentication feature designed for devices with limited input capabilities. This article breaks down how the technique works, examines a recent observed case, and outlines the layered security measures organizations can implement.
https://www.trendmicro.com/en_us/research/26/g/device-code-phishing.html
🎖@malwr | 472 |
| 10 | CVE-2026-50458: Finding a UAF in the Windows Brokering File System
On Tuesday, July 14, Microsoft released the largest Patch Tuesday update in its history, fixing more than 600 vulnerabilities. A bug I reported to Microsoft on May 17 was patched as CVE-2026-50458 in this release, so I am publishing the writeup I wrote at the time, while the details were still fresh. I hope you enjoy it!
https://rotcee.github.io/posts/CVE-2026-50458-finding-a-UAF-in-windows-brokering-file-system/
🎖@malwr | 478 |
| 11 | JVBotelho/skewrun: Active Directory time discovery protocols for red teams. Stealthy extraction via Kerberos, SMB, NTLM, and CLDAP.
https://github.com/JVBotelho/skewrun
🎖@malwr | 525 |
| 12 | Reminder: We take ads
@SirMalware | 724 |
| 13 | Fake games spread stealers with RenPy Loader, MSBuild and EtherHiding
https://www.malwarebytes.com/blog/threat-intel/2026/07/fake-games-spread-stealers-with-renpy-loader-msbuild-and-etherhiding
🎖@malwr | 877 |
| 14 | cookiengineer/godecompose: :construction: Experimental pattern-based decompiler for Go :construction:
https://github.com/cookiengineer/godecompose
Pattern-based decompiler for Go binaries. Recovers original Go source code by matching known compiler output patterns against disassembled machine code.
🎖@malwr | 901 |
| 15 | Pixels to Payload: Dissecting a Four-Stage Bitmap-Steganography Dropper Delivering AsyncRAT
A technical teardown of a multi-stage .NET dropper chain that hides its loaders inside bitmap pixel channels, wraps an Eazfuscator crypter around an academic epidemiology simulator, and delivers AsyncRAT 0.5.8. Includes pixelchain, a keyless end-to-end chain extractor.
https://blog.threatuniverse.co.uk/posts/asyncrat-bitmap-steganography-dropper/
🎖@malwr | 863 |
| 16 | From Alert to Core Dump: Hunting Zeus Malware Using Suricata, Splunk, YARA, and Volatility
Malware analysis and threat hunting are critical skills for any modern SOC Analyst. To truly understand how adversaries operate, we must…
https://medium.com/@osamamamoussa/from-alert-to-core-dump-hunting-zeus-malware-using-suricata-splunk-yara-and-volatility-4ce18f517f87?sharedUserId=osamamamoussa
🎖@malwr | 773 |
| 17 | helixmap/sigwood: Local-first, transparent threat hunting for the logs you already have: Zeek, Pi-hole, syslog, CloudTrail. Named technique behind every finding. No SIEM, no agent, no black box.
https://github.com/helixmap/sigwood
🎖@malwr | 734 |
| 18 | Windows AppResolver LPE: From AppContainer to SYSTEM
Exploit development for a Windows AppResolver authorization issue fixed in July 2026, from a zero-capability AppContainer to an interactive SYSTEM shell.
https://davidcarliez.github.io/blog/windows-appresolver-lpe-to-system/
🎖@malwr | 684 |
| 19 | OkoBot framework infection chain
Kaspersky GReAT experts dissect the new OkoBot campaign targeting cryptocurrency users. This complex framework employs TookPS, exfiltrates seed phrases, monitors Chromium-based browsers, and installs various malware strains, including the Rilide stealer.
https://securelist.com/okobot-framework-targets-cryptocurrency-wallets/120660/
🎖@malwr | 766 |
| 20 | UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign
Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. and Europe since at least June 2025.
https://blog.talosintelligence.com/uat-11795-deploys-novel-starland-rat-and-bespoke-wldr-c2-implant-in-financially-motivated-campaign/
🎖@malwr | 840 |
