MalDev | GaK3r
رفتن به کانال در Telegram
Delve into advanced malware development, injection methods, BoFs exploitation, and cybersecurity research. Join a community of experts! Русский свинка 🐽 теряйтесь нахуй
نمایش بیشترکشور مشخص نشده استفناوری و برنامهها44 960
727
مشترکین
+324 ساعت
+47 روز
+1330 روز
در حال بارگیری داده...
کانالهای مشابه
هیچ دادهای
مشکلی وجود دارد؟ لطفاً صفحه را تازه کنید یا با مدیر پشتیبانی ما تماس بگیرید.
ابر برچسبها
اشارات ورودی و خروجی
---
---
---
---
---
---
جذب مشترکین
ژوئیه '26
ژوئیه '26
+18
در 0 کانالها
ژوئن '26
+18
در 0 کانالها
Get PRO
مه '26
+17
در 0 کانالها
Get PRO
آوریل '26
+10
در 0 کانالها
Get PRO
مارس '26
+11
در 0 کانالها
Get PRO
فوریه '26
+16
در 0 کانالها
Get PRO
ژانویه '26
+76
در 1 کانالها
Get PRO
دسامبر '25
+32
در 0 کانالها
Get PRO
نوامبر '25
+42
در 1 کانالها
Get PRO
اکتبر '25
+31
در 0 کانالها
Get PRO
سپتامبر '25
+353
در 1 کانالها
Get PRO
اوت '250
در 2 کانالها
Get PRO
ژوئیه '25
+186
در 1 کانالها
| تاریخ | رشد مشترکین | اشارات | کانالها | |
| 29 ژوئیه | +3 | |||
| 28 ژوئیه | +1 | |||
| 27 ژوئیه | +1 | |||
| 26 ژوئیه | +1 | |||
| 25 ژوئیه | +1 | |||
| 24 ژوئیه | 0 | |||
| 23 ژوئیه | 0 | |||
| 22 ژوئیه | 0 | |||
| 21 ژوئیه | 0 | |||
| 20 ژوئیه | +1 | |||
| 19 ژوئیه | 0 | |||
| 18 ژوئیه | +1 | |||
| 17 ژوئیه | 0 | |||
| 16 ژوئیه | +1 | |||
| 15 ژوئیه | 0 | |||
| 14 ژوئیه | 0 | |||
| 13 ژوئیه | +1 | |||
| 12 ژوئیه | 0 | |||
| 11 ژوئیه | +1 | |||
| 10 ژوئیه | 0 | |||
| 09 ژوئیه | 0 | |||
| 08 ژوئیه | 0 | |||
| 07 ژوئیه | 0 | |||
| 06 ژوئیه | 0 | |||
| 05 ژوئیه | +1 | |||
| 04 ژوئیه | 0 | |||
| 03 ژوئیه | 0 | |||
| 02 ژوئیه | +3 | |||
| 01 ژوئیه | +2 |
پستهای کانال
| 2 | FalkonC2 is Getting Ridiculously Stealthy
🛡️ Flare Research breaks down FalkonC2 — a commercial C2 framework written from scratch in C++/MASM64, built around sub-35 KB memory-only stubs with zero disk footprint and no CRT dependencies. Rotemelli2 targets enterprise EDR/XDR, rotating 17 private C2 servers with full domain burn every 72 hours, falling back across HTTP/HTTPS (MM4 + ChaCha20), DNS tunneling and ICMP beacons. Highlights: RMM Loader Nohost abusing renamed ScreenConnect/Datto/SimpleHelp for silent Defender bypass and SYSTEM escalation, a Ring0 “BSOD Screen Disrupter” that blinds responders mid-investigation via HVNC, QuickBooks/Sage50 profiling for automated exfil, and Chrome token theft. Full write-up with leaked Tor dashboard telemetry and defensive recommendations: https://flare.io/learn/resources/blog/falkonc2 🚀
https://flare.io/learn/resources/blog/falkonc2
🔗 Link
🕹Subscribe to MalDev | GaK3r | 160 |
| 3 | https://x.com/fried_rice/status/2080200610985689222?s=46 | 181 |
| 4 | CET-Compliant Callstack Spoofing via Thread Pool Enum Callback Trampolining
🛡️ New research shows a CET‑compliant call‑stack spoofing trick that hijacks Windows thread‑pool enum callbacks as syscall trampolines—bypassing EDR stack telemetry while keeping Intel shadow‑stack invariants intact.
Dive into the methodology, timeline of syscall evasion, and the underlying mechanics (RtlVirtualUnwind, TEB tricks, etc.) in the full write‑up: https://mrtiz.github.io/cet-callstack-spoofing-thread-pool-trampoline 🚀
https://mrtiz.github.io/cet-callstack-spoofing-thread-pool-trampoline
🔗 Link
🕹Subscribe to MalDev | GaK3r | 205 |
| 5 | https://github.com/Astharot15/COMLoaderAstharot/ | 312 |
| 6 | Accelerating EDR Evasion with LLM-Driven Analysis
SpecterOps (Adam Chester) shows how a dead-simple LLM harness running in a loop—GPT‑5.5‑Cyber in Codex with Binary Ninja exposed over MCP—reverse engineers Palo Alto’s Cortex XDR to pull out its YARA rules, behavioral detections (DSE/BIOC, CLIPS), and local ML models, auto-generating the Python decryption tooling and evasion test harnesses along the way. No multi-agent orchestration—just Codex, Binary Ninja, and a while loop.
🔗 Link
https://specterops.io/blog/2026/06/29/llm-powered-edr-analysis
🕹Subscribe to MalDev | GaK3r | 457 |
| 7 | WindowsSentinel
WindowsSentinel is a lightweight C# utility that continuously monitors key Windows system events—such as file, process, and registry changes—and logs them in real‑time for easy auditing and troubleshooting.
🔗 Link
🕹Subscribe to MalDev | GaK3r | 409 |
| 8 | Mini Shai-Hulud / Miasma / Hades
🚨 Malware is now weaponizing your own AI scanner against you.
A new wave of worms — Mini Shai-Hulud, Miasma, and Hades — ship with a fake “CLASSIFIED BRIEFING” header stuffed with nuclear & bioweapon design text, placed as a non-executing JavaScript comment at the top of _index.js. The point isn’t to run anything — it’s to trip the safety refusals of LLM-based malware triage so the scanner bails before it ever reaches the obfuscated Hades payload below. Refusal → false negative → package ships clean. The campaign targets bioinformatics and MCP developers, with newer variants using .pth loaders and native extensions to drop Bun-powered stealers that scrape GCP, Azure, and CI/CD secrets on install.
This is second-order alignment blindspots turned into a real-world evasion primitive. Lesson for anyone building an AI analysis pipeline: separate untrusted sample content from instructions, and never let a refusal silently equal “benign.”
👉 Full breakdown: https://socket.dev/blog/mini-shai-hulud-miasma-and-hades-worms-target-bioinformatics-and-mcp-developers-via-malicious
🔗 Link
🕹Subscribe to MalDev | GaK3r | 383 |
| 9 | بدون متن... | 36 |
| 10 | HijackLibs.net
🚨 DLL Hijacking just got a lot easier to track (and exploit).
HijackLibs.net is a curated database mapping vulnerable executables to exploitable DLLs—complete with metadata for defenders to detect attacks and red teamers to plan operations. It covers key techniques like DLL Sideloading, Phantom DLL Hijacking, and Search Order Hijacking—all critical for modern threat hunting and red teaming.
👉 Dive in: https://hijacklibs.net
https://hijacklibs.net
🔗 Link
🕹Subscribe to MalDev | GaK3r | 412 |
| 11 | HijackLibs.net
🚨 DLL Hijacking just got way easier to track—and exploit.
HijackLibs.net is a curated database mapping vulnerable executables to exploitable DLLs—perfect for red teamers hunting attack paths or defenders spotting suspicious load patterns. With clear breakdowns of sideloading, phantom hijacking, and search-order abuse (T1574.001), it’s the go-to resource for mastering this stealthy, often undetected technique.
👉 Dive in: https://hijacklibs.net
https://hijacklibs.net
🔗 Link
🕹Subscribe to MalDev | GaK3r | 1 |
