Malware News
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ... Partner channel: @cveNotify For ads: https://telega.io/c/malwr
Больше📈 Аналитический обзор Telegram-канала Malware News
Канал Malware News (@malwr) языкового сегмента Английский является активным участником. Сейчас сообщество объединяет 16 117 подписчиков, занимая 7 776 место в категории Технологии и приложения и 2 298 место в регионе США.
📊 Показатели аудитории и динамика
С момента создания невідомо проект демонстрирует стремительный рост, собрав аудиторию из 16 117 подписчиков.
Согласно последним данным от 05 октября, 2026, канал показывает стабильную активность. За последние 30 дней изменение числа участников составило -129, а за последние 24 часа — -7, при этом общий охват остаётся высоким.
- Статус верификации: Не верифицирован
- Уровень вовлечённости (ER): Средний показатель вовлечённости аудитории составляет 4.56%. В первые 24 часа после публикации контент обычно набирает 2.10% реакций от общего числа подписчиков.
- Охват публикаций: В среднем каждый пост получает 734 просмотров. В течение первых суток публикация набирает 339 просмотров.
- Реакции и взаимодействия: Аудитория активно поддерживает контент: среднее количество реакций на один пост — 2.
- Тематические интересы: Контент сосредоточен на ключевых темах, таких как threat, kernel, cve-2025, actor, attack.
📝 Описание и контентная политика
Автор описывает ресурс как площадку для выражения субъективного мнения:
“The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...
Partner channel: @cveNotify
For ads: https://telega.io/c/malwr”
Благодаря высокой частоте обновлений (последние данные получены 06 октября, 2026) канал поддерживает актуальность и высокий уровень охвата публикаций. Аналитика показывает, что аудитория активно взаимодействует с контентом, что делает его важной точкой влияния в категории Технологии и приложения.
Загрузка данных...
| Дата | Привлечение подписчиков | Упоминания | Каналы | |
| 06 октября | +3 | |||
| 05 октября | 0 | |||
| 04 октября | +1 | |||
| 03 октября | +1 | |||
| 02 октября | 0 | |||
| 01 октября | 0 |
| 2 | grisuno/LazyOwn: LazyOwn RedTeam/APT Framework is the first RedTeam Framework with an AI-powered C&C, featuring rootkits to conceal campaigns, undetectable malleable implants compatible with Windows/Linux/Mac OSX, and self-configuring backdoors. With its Web interface and powerful Console Client, it is the best combination for your Autonomous RedTeam/APT campaigns.
https://github.com/grisuno/lazyown
🎖@malwr | 753 |
| 3 | AkaTorich/KernelFlirt: KernelFlirt is powerful kernel debugger.
https://github.com/akatorich/kernelflirt
🎖@malwr | 600 |
| 4 | PaperCut MF Zero-Day Intrusion: Java Loader, Web Shell, and AdaptixC2 via CVE-2026-82078 and CVE-2026-81578
eSentire TRU details a PaperCut MF zero-day intrusion (CVE-2026-82078, CVE-2026-81578) using a Java loader, web shell, and trojanized Copilot binary to deploy AdaptixC2.
https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578
🎖@malwr | 613 |
| 5 | China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor
Cisco Talos uncovered a cluster of activity we track as UAT-11587 targeting government and policy organizations across Asia, including in Taiwan, India, the Philippines, and Cambodia, to deliver a previously undocumented backdoor referred to as “Antino” in developer artifacts.
https://blog.talosintelligence.com/china-nexus-uat-11587-targets-government-and-policy-organizations-across-asia-with-antino-backdoor/
🎖@malwr | 593 |
| 6 | JoasASantos/Offensive-Security-AI-Models: Uncensored AI models or those fine-tuned for cybersecurity tasks.
https://github.com/JoasASantos/Offensive-Security-AI-Models
🎖@malwr | 635 |
| 7 | NeedyMantis: Unpacking a post-compromise malware family used in targeted operations | Microsoft Security Blog
Microsoft Threat Intelligence identified NeedyMantis, a modular post-compromise malware framework used in targeted intrusions that combines custom loaders, encrypted archives, and extensible components to maintain long-term access and support follow-on operations.
https://www.microsoft.com/en-us/security/blog/2026/09/28/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations/
🎖@malwr | 556 |
| 8 | Uncovering a SectopRAT Variant Embedded in Legitimate Software | FortiGuard Labs
Analysis of a SectopRAT variant hidden in tampered legitimate software that steals credentials and enables remote system control…
https://www.fortinet.com/blog/threat-research/uncovering-a-sectoprat-variant-embedded-in-legitimate-software
🎖@malwr | 470 |
| 9 | TwoSevenOneT/InjectSetConsole: Proof of Concept for Process Code Injection Without Using WriteProcessMemory
https://github.com/TwoSevenOneT/InjectSetConsole
🎖@malwr | 425 |
| 10 | https://medium.com/@Root0ne/muddywaters-rented-arsenal-and-its-traces-in-the-russian-maas-market-d58965401f15
🎖@malwr | 436 |
| 11 | rPlayAI/rPlayHub: iPhone Mirroring for macOS and Linux — scrcpy for iOS and a cross-platform Device Hub clone. Mirror and control an iPhone (iOS 27+); Raspberry Pi and Windows next. Part of rPlay.
https://github.com/rPlayAI/rPlayHub
🎖@malwr | 508 |
| 12 | newliver666/apk-reverse: Suitable for Android APK reverse engineering analysis
https://github.com/newliver666/apk-reverse
An Agent Skill for Android APK reverse engineering, debloating, ad removal, surgical dex patching, repacking, and runtime/server analysis.
🎖@malwr | 649 |
| 13 | EDR Evasion: Process Injection Without WriteProcessMemory
Technique performs Windows process code injection by leveraging a Windows named pipe, it does not use VirtualAllocEx and WriteProcessMemory
https://www.zerosalarium.com/2026/09/edr-evasion-process-injection-without-WriteProcessMemory.html
🎖@malwr | 662 |
| 14 | nbs32k/LocalStranger: PoC for WinNotify, demonstrated through a driver mapper, and local privilege escalation.
https://github.com/nbs32k/LocalStranger
🎖@malwr | 630 |
| 15 | ngwg/ceasta: disassembler, decompiler and debugger in one, with a built-in mcp server: point an ai at a binary and it can debug it, not just read it. ida-style listing, pseudocode (f5), x64dbg-style debugger (windows and linux), binary diff, lua plugins. reads pe, elf and mach-o. runs on windows, linux and macos.
https://github.com/ngwg/ceasta
🎖@malwr | 637 |
| 16 | Kothamine malware uses Tailscale’s tailcat to evade network detection
Kothamine uses a legitimate Tailscale tool to receive attackers’ commands through an encrypted connection with no malicious domain to block.
https://www.malwarebytes.com/blog/threat-intel/2026/09/kothamine-malware-uses-tailscales-tailcat-to-evade-network-detection
🎖@malwr | 697 |
| 17 | Bypassing EDR with Local AI
How hard is it to bypass EDR in the modern times with AI? As it turns out, not very hard.
https://projectblack.io/blog/bypassing-edr-with-local-ai/
🎖@malwr | 788 |
| 18 | Part 2: Visual-layer hiding — Hawkeye Research
Visual-layer anti-capture in DWM: CVisual::HasProtectedContent (bit 7 at +0x6A), vtable heap scan, HWND/PID attribution, and defender-side detection on Windows 10/11.
https://hawkeye-leo.github.io/hawkeye/research/capture/02-visual-hiding/
🎖@malwr | 756 |
| 19 | HimitsuShell/HimitsuShell: shell script protector (obfuscation, embedded interpreter, DRM) - invisible to kernel tracing
https://github.com/HimitsuShell/HimitsuShell
🎖@malwr | 733 |
| 20 | Inside a multi stage toll fraud operation targeting Poland
CERT Polska uncovered a toll fraud operation targeting Polish users through deceptive Meta advertisements and malicious applications distributed via Google Play. We preserved 1235 ads, linked 852 to 17 applications through code or infrastructure, reconstructed the complete execution chain, and observed live premium SMS and carrier billing tasking.
https://cert.pl/en/posts/2026/09/tollfraud-analysis/
🎖@malwr | 690 |
