es
Feedback
Malware News

Malware News

Ir al canal en Telegram

The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ... Partner channel: @cveNotify For ads: https://telega.io/c/malwr

Mostrar más

📈 Análisis del canal de Telegram Malware News

El canal Malware News (@malwr) en el segmento lingüístico de Inglés es un actor destacado. Actualmente la comunidad reúne a 16 252 suscriptores, ocupando la posición 7 777 en la categoría Tecnologías y Aplicaciones y el puesto 2 307 en la región EEUU.

📊 Métricas de audiencia y dinámica

Desde su creación el невідомо, el proyecto ha mostrado un crecimiento acelerado, reuniendo a 16 252 suscriptores.

Según los últimos datos del 26 agosto, 2026, el canal mantiene una actividad estable. En los últimos 30 días la variación de miembros fue de 706, y en las últimas 24 horas de 15, conservando un alto alcance.

  • Estado de verificación: No verificado
  • Tasa de interacción (ER): El promedio de interacción de la audiencia es 3.50%. Durante las primeras 24 horas tras publicar, el contenido suele obtener 2.13% de reacciones respecto al total de suscriptores.
  • Alcance de las publicaciones: Cada publicación recibe en promedio 569 visualizaciones. En el primer día suele acumular 346 visualizaciones.
  • Reacciones e interacción: La audiencia responde de forma activa: el promedio de reacciones por publicación es 1.
  • Intereses temáticos: El contenido se centra en temas clave como threat, kernel, cve-2025, actor, attack.

📝 Descripción y política de contenido

El autor describe el recurso como un espacio para expresar opiniones subjetivas:
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ... Partner channel: @cveNotify For ads: https://telega.io/c/malwr

Gracias a la alta frecuencia de actualizaciones (últimos datos recibidos el 27 agosto, 2026), el canal mantiene la vigencia y un amplio alcance. La analítica demuestra que la audiencia interactúa activamente con el contenido, lo que lo convierte en un punto de referencia dentro de la categoría Tecnologías y Aplicaciones.

16 252
Suscriptores
+1524 horas
+1387 días
+70630 días

Carga de datos en curso...

Atraer Suscriptores
agosto '26
agosto '26
+605
en 3 canales
julio '26
+806
en 2 canales
Get PRO
junio '26
+700
en 0 canales
Get PRO
mayo '26
+637
en 0 canales
Get PRO
abril '26
+476
en 1 canales
Get PRO
marzo '26
+257
en 0 canales
Get PRO
febrero '26
+324
en 1 canales
Get PRO
enero '26
+348
en 0 canales
Get PRO
diciembre '25
+397
en 0 canales
Get PRO
noviembre '25
+412
en 0 canales
Get PRO
octubre '25
+188
en 0 canales
Get PRO
septiembre '25
+95
en 2 canales
Get PRO
agosto '25
+45
en 0 canales
Get PRO
julio '25
+51
en 0 canales
Get PRO
junio '25
+46
en 1 canales
Get PRO
mayo '25
+31
en 1 canales
Get PRO
abril '25
+56
en 0 canales
Get PRO
marzo '25
+22
en 0 canales
Get PRO
febrero '25
+36
en 0 canales
Get PRO
enero '25
+34
en 1 canales
Get PRO
diciembre '24
+457
en 0 canales
Get PRO
noviembre '24
+1 858
en 3 canales
Get PRO
octubre '24
+980
en 0 canales
Get PRO
septiembre '24
+1 070
en 1 canales
Get PRO
agosto '24
+957
en 2 canales
Get PRO
julio '24
+611
en 1 canales
Get PRO
junio '24
+483
en 0 canales
Get PRO
mayo '24
+637
en 0 canales
Get PRO
abril '24
+640
en 1 canales
Get PRO
marzo '24
+806
en 2 canales
Get PRO
febrero '24
+521
en 1 canales
Get PRO
enero '24
+293
en 0 canales
Get PRO
diciembre '23
+361
en 2 canales
Get PRO
noviembre '23
+85
en 2 canales
Get PRO
octubre '23
+86
en 1 canales
Get PRO
septiembre '23
+97
en 0 canales
Get PRO
agosto '23
+85
en 0 canales
Get PRO
julio '23
+63
en 0 canales
Get PRO
junio '23
+77
en 0 canales
Get PRO
mayo '23
+65
en 0 canales
Get PRO
abril '23
+75
en 0 canales
Get PRO
marzo '23
+75
en 0 canales
Get PRO
febrero '23
+38
en 0 canales
Get PRO
enero '23
+63
en 0 canales
Get PRO
diciembre '22
+99
en 0 canales
Get PRO
noviembre '22
+70
en 0 canales
Get PRO
octubre '22
+101
en 0 canales
Get PRO
septiembre '22
+165
en 0 canales
Get PRO
agosto '22
+986
en 0 canales
Get PRO
julio '22
+27
en 0 canales
Get PRO
junio '22
+31
en 0 canales
Get PRO
mayo '22
+63
en 0 canales
Get PRO
abril '22
+72
en 0 canales
Get PRO
marzo '22
+74
en 0 canales
Get PRO
febrero '22
+43
en 0 canales
Get PRO
enero '22
+112
en 0 canales
Get PRO
diciembre '21
+99
en 0 canales
Get PRO
noviembre '21
+42
en 0 canales
Get PRO
octubre '21
+34
en 0 canales
Get PRO
septiembre '21
+36
en 0 canales
Get PRO
agosto '21
+48
en 0 canales
Get PRO
julio '21
+95
en 0 canales
Get PRO
junio '21
+77
en 0 canales
Get PRO
mayo '21
+11
en 0 canales
Get PRO
abril '21
+39
en 0 canales
Get PRO
marzo '21
+28
en 0 canales
Get PRO
febrero '21
+40
en 0 canales
Get PRO
enero '21
+54
en 0 canales
Get PRO
diciembre '20
+938
en 0 canales
Fecha
Crecimiento de Suscriptores
Menciones
Canales
27 agosto+9
26 agosto+16
25 agosto+18
24 agosto+23
23 agosto+15
22 agosto+21
21 agosto+24
20 agosto+24
19 agosto+17
18 agosto+22
17 agosto+13
16 agosto+15
15 agosto+23
14 agosto+38
13 agosto+29
12 agosto+28
11 agosto+30
10 agosto+15
09 agosto+20
08 agosto+27
07 agosto+21
06 agosto+25
05 agosto+24
04 agosto+20
03 agosto+34
02 agosto+34
01 agosto+20
Publicaciones del Canal
PPEE (puppy) 1.15 PPEE is a Professional PE file Explorer for reversers, malware researchers and those who want to statically inspect PE files in more detail
- Clustering/Similarity engine added (Hash data is stored locally in a sqlite db next to PPEE). Similar binaries are notified and grouped by color. - Multi-file supported with flexible tabs - Long-awaited Settings dialog added - File Information added in PPEE (Ported from FileInfo plugin) - Progressbar added for heavy jobs - Warning/Error dot added to the treeview items - AMD64 and ARM64 Exception Dir support - .Net/CLR parsing improved with edit capability - New debug types supported (FPO, MISC, BBT/RSRVD10, VC_FEAT, POGO, ILTCG, DLL_CHAR, PDB_CHECKSUM, EMDEDDED_PORTABLE_PDB, PERFMAP) with edit capability - UI is now DPI aware - WoW64 redirection support - PPEE is now faster (Highly refactored and unnecessary MFC, stdafx libraries removed from source code) - Windows XP supported - Bugfixes
https://mzrst.com/ 🎖@malwr

2
MmMapIoSpace Returns NULL: Tracing the Real Kernel Mechanism Through ntoskrnl Tracing exactly why MmMapIoSpace returns NULL on Windows 11 past the commonly cited explanations and into undocumented page table ownership checks inside the kernel. https://sibouzitoun.tech/articles/mmmapiospace-returns-null-tracing-the-real-kernel-mechanism-through-ntoskrnlexe/ 🎖@malwr
335
3
https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-237a 🎖@malwr
380
4
Handle Redirect Welcome to this new Medium post. In this one we will see how to redirect a handle’s kernel object pointer to a different EPROCESS, getting… https://medium.com/@s12deff/handle-redirect-549902e6d868 🎖@malwr
382
5
Local Privilege Escalation To System In Wibu-Systems CodeMeter Application | Shelltrail This research post describes the process of finding and exploiting a local privilege escalation in the Wibu-Systems CodeMeter application https://shelltrail.com/research/local-privilege-escalation-to-system-in-wibu-systems-codemeter-application 🎖@malwr
478
6
jyatesdotdev/wd-smart-reader: macOS CLI tool for reading SMART data from WD external drives (MyBook, Elements) via SES diagnostic pages. Works on Apple Silicon, no kernel extensions needed. https://github.com/jyatesdotdev/wd-smart-reader 🎖@malwr
459
7
Malware development trick 63: modifying PE version metadata and icon. Simple C example ﷽ https://cocomelonc.github.io/malware/2026/08/24/malware-tricks-63.html 🎖@malwr
443
8
Manic: Blend between Banking Malware & Spyware Manic is a newly identified Android malware family with broad surveillance and remote-control capabilities, introducing an unusual Wi‑Fi mesh technique. https://www.threatfabric.com/blogs/manic-blend-between-banking-malware-and-spyware 🎖@malwr
403
9
daniomass/SliverMirage: Crystal Palace PICO loader for Sliver C2 dual-layer AMSI bypass, ETW silencing, AES-256-CBC encrypted payloads, 6 delivery variants https://github.com/daniomass/SliverMirage 🎖@malwr
335
10
The Citizen Lab Bad Connection: Uncovering Global Telecom Exploitation by Covert Surveillance Actors Our investigation uncovers two sophisticated telecom surveillance campaigns and, for the first time, links real-world attack traffic to mobile operator signalling infrastructure. The findings expose how suspected commercial surveillance vendors (CSVs) exploit the global telecom interconnect ecosystem, leverage private operator networks, and conduct covert location tracking operations that can persist undetected for years. https://citizenlab.ca/research/uncovering-global-telecom-exploitation-by-covert-surveillance-actors/ 🎖@malwr
313
11
Inside the Falcon How CrowdStrike Catches You A full reverse-engineering teardown of the CrowdStrike Falcon sensor: the six kernel callback sources, the WFP network engine, the file-system minifilter, the cspcm4 broker, the user-mode service (DNS / AMSI / browser / Identity Protection), and the cloud-loaded detection engine — plus every structural blind spot. How Falcon sees you, and where the seams are. https://0xdbgman.github.io/posts/inside-the-falcon-how-crowdstrike-catches-you/ 🎖@malwr
330
12
Your executable is a SQLite database I have been probably obsessed with two things in the last few years: Nix as a tool to explore innovative ideas that require the capability to rebuild the world and replacing ELF with SQLite as an executable format. You might have noticed that these two ideas are well suited to each other. https://fzakaria.com/2026/08/23/your-executable-is-a-sqlite-database 🎖@malwr
436
13
Tracking PavinLoader across ClickFix and fake download campaigns We found PavinLoader being used across ClickFix, fake software, and RenPy campaigns to deliver Amatera Stealer and other malware. https://www.malwarebytes.com/blog/threat-intel/2026/08/tracking-pavinloader-across-clickfix-and-fake-download-campaigns 🎖@malwr
478
14
Text Template Text template files can contain C# or Visual Basic code that could be compiled and executed at build time. Threat actors can create or modify .tt files to execute code in the context of a trusted p… https://ipurple.team/2026/08/24/text-template/ 🎖@malwr
443
15
Reverse Engineering a 0day used Against EDRs https://medium.com/@jehadbudagga/reverse-engineering-a-0day-used-against-crowdstrike-edr-a5ea1fbe3fd4 🎖@malwr
454
16
Inside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asia | Enki White Hat Inside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asia https://www.enki.co.kr/en/media-center/blog/inside-kimsuky-s-abuse-of-legitimate-remote-control-tools-across-northeast-asia 🎖@malwr
407
17
SLEEPWALKER: A Passive Backdoor With Its Own Command Language Losing access to VirusTotal Intelligence at the start of the year was surprisingly productive. Unable to hunt for interesting new malware, I stopped adding to my “TODO” pile and finally worked through my backlog from last year. That led to a detailed examination of BeheMOF as well as the discovery of this malware. Upon closer inspection, a sample that did not seem too noteworthy at first turned out to have a distinctive design once I looked under the hood: a passive backdoor that opens no obvious listening port and carries no payload inside itself. It waits in memory doing nothing at all until one specifically crafted network packet reaches the machine, which is why I am calling it SLEEPWALKER. https://r136a1.dev/2026/08/24/sleepwalker-a-passive-backdoor-with-its-own-command-language/ 🎖@malwr
384
18
Fairy Law: Abusing MicrosoftSignedOnly Welcome to this new Medium post. In this one we will see how a legitimate Windows process mitigation policy can be abused to globally… https://medium.com/@s12deff/fairy-law-abusing-microsoftsignedonly-8d35018bc99f 🎖@malwr
424
19
Auditing Microsoft Defender and Intune Configuration Changes Microsoft is clearly moving toward a more unified security operations experience within the Defender portal. Over the last few years, we have seen Microsoft bring more security capabilities together under the Defender platform. Instead of working with completely separate portals... https://jeffreyappel.nl/auditing-microsoft-defender-and-intune-configuration-changes/ 🎖@malwr
504
20
tracebyte8/SysTrace: SysTrace - Linux System Call Monitor using PTRACE API , It traces system calls, monitors process, file, network, and memory activity, detects suspicious behavior, and generates detailed security reports. https://github.com/tracebyte8/SysTrace 🎖@malwr
1 097