Malware News
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ... Partner channel: @cveNotify For ads: https://telega.io/c/malwr
نمایش بیشتر📈 تحلیل کانال تلگرام Malware News
کانال Malware News (@malwr) در بخش زبانی انگلیسی بازیگری فعال است. در حال حاضر جامعه شامل 15 349 مشترک است و جایگاه 8 353 را در دسته فناوری و برنامهها و رتبه 2 475 را در منطقه الولايات المتحدة الأمريكية دارد.
📊 شاخصهای مخاطب و پویایی
از زمان ایجاد در невідомо، پروژه رشد سریعی داشته و 15 349 مشترک جذب کرده است.
بر اساس آخرین دادهها در تاریخ 19 ژوئیه, 2026، کانال فعالیت پایداری دارد. در ۳۰ روز گذشته تغییر اعضا برابر 729 و در ۲۴ ساعت گذشته برابر 17 بوده و همچنان دسترسی گستردهای حفظ شده است.
- وضعیت تأیید: تأیید نشده
- نرخ تعامل (ER): میانگین تعامل مخاطب 4.17% است و در ۲۴ ساعت نخست پس از انتشار، محتوا معمولاً 2.28% واکنش نسبت به کل مشترکان کسب میکند.
- دسترسی پستها: هر پست به طور میانگین 640 بازدید دریافت میکند. در اولین روز معمولاً 350 بازدید جمعآوری میشود.
- واکنشها و تعامل: مخاطبان بهطور فعال حمایت میکنند؛ میانگین واکنش به هر پست 1 است.
- علایق موضوعی: محتوا بر موضوعات کلیدی مانند threat, kernel, cve-2025, actor, attack تمرکز دارد.
📝 توضیح و سیاست محتوایی
نویسنده این فضا را محل بیان دیدگاههای شخصی توصیف میکند:
“The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...
Partner channel: @cveNotify
For ads: https://telega.io/c/malwr”
به لطف بهروزرسانیهای پرتکرار (آخرین داده در تاریخ 20 ژوئیه, 2026)، کانال همواره بهروز و دارای دسترسی بالاست. تحلیلها نشان میدهد مخاطبان بهطور فعال با محتوا تعامل دارند و آن را به نقطه اثرگذاری مهم در دسته فناوری و برنامهها تبدیل کردهاند.
در حال بارگیری داده...
| تاریخ | رشد مشترکین | اشارات | کانالها | |
| 20 ژوئیه | +5 | |||
| 19 ژوئیه | +20 | |||
| 18 ژوئیه | +35 | |||
| 17 ژوئیه | +24 | |||
| 16 ژوئیه | +11 | |||
| 15 ژوئیه | +37 | |||
| 14 ژوئیه | +37 | |||
| 13 ژوئیه | +38 | |||
| 12 ژوئیه | +16 | |||
| 11 ژوئیه | +18 | |||
| 10 ژوئیه | +21 | |||
| 09 ژوئیه | +27 | |||
| 08 ژوئیه | +8 | |||
| 07 ژوئیه | +20 | |||
| 06 ژوئیه | +25 | |||
| 05 ژوئیه | +30 | |||
| 04 ژوئیه | +16 | |||
| 03 ژوئیه | +31 | |||
| 02 ژوئیه | +29 | |||
| 01 ژوئیه | +20 |
Pattern-based decompiler for Go binaries. Recovers original Go source code by matching known compiler output patterns against disassembled machine code.
🎖@malwr| 2 | Pixels to Payload: Dissecting a Four-Stage Bitmap-Steganography Dropper Delivering AsyncRAT
A technical teardown of a multi-stage .NET dropper chain that hides its loaders inside bitmap pixel channels, wraps an Eazfuscator crypter around an academic epidemiology simulator, and delivers AsyncRAT 0.5.8. Includes pixelchain, a keyless end-to-end chain extractor.
https://blog.threatuniverse.co.uk/posts/asyncrat-bitmap-steganography-dropper/
🎖@malwr | 422 |
| 3 | From Alert to Core Dump: Hunting Zeus Malware Using Suricata, Splunk, YARA, and Volatility
Malware analysis and threat hunting are critical skills for any modern SOC Analyst. To truly understand how adversaries operate, we must…
https://medium.com/@osamamamoussa/from-alert-to-core-dump-hunting-zeus-malware-using-suricata-splunk-yara-and-volatility-4ce18f517f87?sharedUserId=osamamamoussa
🎖@malwr | 374 |
| 4 | helixmap/sigwood: Local-first, transparent threat hunting for the logs you already have: Zeek, Pi-hole, syslog, CloudTrail. Named technique behind every finding. No SIEM, no agent, no black box.
https://github.com/helixmap/sigwood
🎖@malwr | 478 |
| 5 | Windows AppResolver LPE: From AppContainer to SYSTEM
Exploit development for a Windows AppResolver authorization issue fixed in July 2026, from a zero-capability AppContainer to an interactive SYSTEM shell.
https://davidcarliez.github.io/blog/windows-appresolver-lpe-to-system/
🎖@malwr | 428 |
| 6 | OkoBot framework infection chain
Kaspersky GReAT experts dissect the new OkoBot campaign targeting cryptocurrency users. This complex framework employs TookPS, exfiltrates seed phrases, monitors Chromium-based browsers, and installs various malware strains, including the Rilide stealer.
https://securelist.com/okobot-framework-targets-cryptocurrency-wallets/120660/
🎖@malwr | 562 |
| 7 | UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign
Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. and Europe since at least June 2025.
https://blog.talosintelligence.com/uat-11795-deploys-novel-starland-rat-and-bespoke-wldr-c2-implant-in-financially-motivated-campaign/
🎖@malwr | 631 |
| 8 | IDA 9.4 | Hex-Rays Docs
https://docs.hex-rays.com/release-notes/9_4
🎖@malwr | 562 |
| 9 | Schich/Lucky-Spark: A stealthy stager designed for shellcode payloads staged with http/https like Sliver, or on github raw.
https://github.com/Schich/Lucky-Spark
🎖@malwr | 568 |
| 10 | ProfessorQuantumUniverse/Veto: A nice Virus Total Android Client.
https://github.com/ProfessorQuantumUniverse/Veto
🎖@malwr | 479 |
| 11 | One Man, One AI, One Fake Persona: Inside the 5-Year Influence and Fraud ‘Patriot Bait’ Campaign
A solo Russian-speaking threat actor ran a 5-year Telegram channel and, starting September 2025, used AI to automate its content, credential theft, and a cryptocurrency fraud scheme targeting American audiences.
https://www.trendmicro.com/en_us/research/26/e/inside-the-influence-and-fraud-patriot-bait-campaign.html
🎖@malwr | 390 |
| 12 | endgamec2framework/endgame: ENDGAME C2 FRAMEWORK — AI-powered command and control for professional red team operations
https://github.com/endgamec2framework/endgame
🎖@malwr | 341 |
| 13 | 2026-06-01: SmartApeSG ClickFix --> Unidentified RAT
https://www.malware-traffic-analysis.net/2026/06/01/index.html
🎖@malwr | 337 |
| 14 | 2026-06-22: SHub Stealer infection (macOS)
https://www.malware-traffic-analysis.net/2026/06/22/index.html
🎖@malwr | 353 |
| 15 | Anatomy of a CUDA Binary
When you compile a CUDA kernel, the final artifact is a cubin — a CUDA binary. It is a standard ELF64 file with NVIDIA-specific sections that encode everything the CUDA driver needs to load and launch a kernel: the machine code, the parameter layout, register allocation metadata, and a collection of attributes that have no public documentation.
https://hiraditya.github.io/posts/anatomy-of-a-cuda-binary/
🎖@malwr | 384 |
| 16 | Suspected Chinese Operators Use Claude Code and DeepSeek to Breach Government Systems Across Four Countries
An exposed open directory revealed a suspected Chinese campaign using Claude Code and DeepSeek-v4-pro to breach government systems in Afghanistan, Thailand, and Taiwan, with parallel probing of financial services worldwide.
https://hunt.io/blog/chinese-operators-claude-deepseek-government-intrusion
🎖@malwr | 378 |
| 17 | Bind Link Abuse: One Windows Feature, Many Ways to Blind Your EDR
I’d like to thank my coauthors, Andrei-Marius Muntea, Andrei Mermeze, Radu-Marian Portase, and Vlad Lazar, for their invaluable contributions to this research.
https://www.bitdefender.com/en-us/blog/businessinsights/bind-link-abuses-windows-feature-edr-evasion-technique
🎖@malwr | 397 |
| 18 | TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development
TuxBot v3 Evolution, an IoT botnet framework built with LLMs. Read our analysis of its cross-compiled binaries, C2 architecture and bugs.
https://unit42.paloaltonetworks.com/tuxbot-v3-evolution-iot-botnet/
🎖@malwr | 465 |
| 19 | Six Minutes to Compromise: How ‘Patriot Bait’ Actor Used AI to Build and Deploy a C&C Botnet
TrendAI™ Research analyzed over 200 Gemini CLI session logs showing how a Russian-speaking threat actor used AI to run a live botnet, finishing a full C&C migration in six minutes while doing just 11% of the work himself.
https://www.trendmicro.com/en_us/research/26/g/actor-behind-patriot-bait-used-ai-to-deploy-c2-botnet.html
🎖@malwr | 487 |
| 20 | I Detonated Real Ransomware in a VM. Hereâs the Forensic Trail It Left. - Freedium
Static analysis hit a wall immediately. The only way to understand this malware was to actually let it run.
https://freedium-mirror.cfd/https://osintteam.blog/i-detonated-real-ransomware-in-a-vm-heres-the-forensic-trail-it-left-8a386d32d3f3
🎖@malwr | 468 |
