MalDev Academy
Open in Telegram
A comprehensive module-based malware development course providing fundamental to advanced level knowledge Site: https://maldevacademy.com Twitter: https://twitter.com/maldevacademy Contact : @internetwar This is NOT official page
Show more310
Subscribers
No data24 hours
No data7 days
No data30 days
Posts Archive
3 New challenges uploaded:
- Fibers For Shellcode Execution
- Anti-Analysis: Domain-Joined Check
- Custom GetProcAddress: Compile-Time Hash Obfuscation
New challenge along with it’s code solution is dropping tonight.
Creating a compile-time hashing function to easily hide strings inside your binary.
Update 7 - November
- Malware Directory Placement
- Utilizing Fibers For Payload Execution
- TLS Callbacks For Anti-Debugging
Update 8 - January
- Threadless Injection
- Module Stomping
- Module Overloading
- Process Hollowing
Update 9 - Feburary
- Ghost Process Injection
- Herpaderping Process Injection
- Transacted Hollowing
- Ghostly Hollowing
- Herpaderply Hollowing
Custom implementations of Transacted Hollowing, Ghostly Hollowing, and Herpaderply Hollowing.
Coming soon!
Update 6 has been posted. These are pretty large and complex modules.
- Local PE Execution
- Reflective DLL Injection
- PeFluctuation (in-memory encryption)
- Building a PE Packer
Update 7 tentatively for November is:
- DLL Proxying
- Utilizing Fibers For Payload Execution
- TLS Callbacks For Anti-Debugging
Testing the PE Packer against MDE. Packed Mimikatz running as expected.
Update 6 will teach you to build your own PE packer.
PeFluctuation is a technique designed to hide PE files in memory.
The images show PeFluctuation in action, hiding Mimikatz in memory and evading both pe-sieve and moneta.
PeFluctuation module will be included in update 6.
Our EXE loader is now available to everyone on GitHub:
https://github.com/Maldev-Academy/MaldevAcademyLdr.1
We'll be uploading more repositories on our GitHub in the future.
September update is out. This one is heavy on AV & EDR evasion.
- Introduction to Havoc C&C
- Building an evasive DLL payload loader
- Introduction to DLL sideloading
- Practical DLL sideloading example
- DLL sideloading for EDR evasion
- Bring your own vulnerable driver (BYOVD)
Maldev Academy DLL Loader vs Crowdstrike
The DLL loader is for Maldev members. But we're also publishing an EXE version of the loader on our GitHub for anyone to use.
https://github.com/Maldev-Academy
Process injecting the EDR process? Yes!
Bring Your Own Vulnerable Driver (BYOVD) coming up soon.
Last week’s challenge was to implement a “kill date” for a malware.
The solution has been posted now!
As a reminder you can submit your challenge to be featured in the upcoming weeks.
Our latest module shows the implementation of Digital Rights Management (DRM) within the malware.
Once executed on a machine, the malware will not execute on any other machine.
This can potentially be effective against AV/EDR automatic sample submission.
Injecting shellcode into Microsoft Defender from the kernel.
Update 5 is looking 🔥🔥
