uk
Feedback
Malware News

Malware News

Відкрити в Telegram

The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ... Partner channel: @cveNotify For ads: https://telega.io/c/malwr

Показати більше

📈 Аналітичний огляд Telegram-каналу Malware News

Канал Malware News (@malwr) у мовному сегменті Англійська є активним учасником. На даний момент спільнота об'єднує 16 117 підписників, посідаючи 7 776 місце в категорії Технології та додатки та 2 298 місце у регіоні США.

📊 Показники аудиторії та динаміка

З моменту свого створення невідомо, проект продемонстрував стрімке зростання, зібравши аудиторію у 16 117 підписників.

За останніми даними від 05 жовтня, 2026, канал демонструє стабільну активність. Хоча за останні 30 днів спостерігається зміна кількості учасників на -129, а за останні 24 години на -7, загальне охоплення залишається високим.

  • Статус верифікації: Не верифікований
  • Рівень залученості (ER): Середній показник залученості аудиторії становить 4.56%. Протягом перших 24 годин після публікації контент зазвичай збирає 2.10% реакцій від загальної кількості підписників.
  • Охоплення публікацій: В середньому кожен допис отримує 734 переглядів. Протягом першої доби публікація в середньому набирає 339 переглядів.
  • Реакції та взаємодія: Аудиторія активно підтримує контент: середня кількість реакцій на один пост – 2.
  • Тематичні інтереси: Контент зосереджений навколо ключових тем, таких як threat, kernel, cve-2025, actor, attack.

📝 Опис та контентна політика

Автор описує ресурс як майданчик для висловлення суб'єктивної думки:
“The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ... Partner channel: @cveNotify For ads: https://telega.io/c/malwr”

Завдяки високій частоті оновлень (останні дані отримано 06 жовтня, 2026), канал підтримує актуальність та високий рівень охоплення публікацій. Аналітика показує, що аудиторія активно взаємодіє з контентом, що робить його важливою точкою впливу в категорії Технології та додатки.

16 117
Підписники
-724 години
-347 днів
-12930 днів
Архів дописів
morluto/rea: Reverse engineer anything with agents, from app behavior down to native binaries. https://github.com/morluto/rea 🎖@malwr

grisuno/LazyOwn: LazyOwn RedTeam/APT Framework is the first RedTeam Framework with an AI-powered C&C, featuring rootkits to conceal campaigns, undetectable malleable implants compatible with Windows/Linux/Mac OSX, and self-configuring backdoors. With its Web interface and powerful Console Client, it is the best combination for your Autonomous RedTeam/APT campaigns. https://github.com/grisuno/lazyown 🎖@malwr

AkaTorich/KernelFlirt: KernelFlirt is powerful kernel debugger. https://github.com/akatorich/kernelflirt 🎖@malwr

PaperCut MF Zero-Day Intrusion: Java Loader, Web Shell, and AdaptixC2 via CVE-2026-82078 and CVE-2026-81578 eSentire TRU details a PaperCut MF zero-day intrusion (CVE-2026-82078, CVE-2026-81578) using a Java loader, web shell, and trojanized Copilot binary to deploy AdaptixC2. https://www.esentire.com/blog/papercut-mf-zero-day-intrusion-java-loader-web-shell-and-adaptixc2-via-cve-2026-82078-and-cve-2026-81578 🎖@malwr

China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor Cisco Talos uncovered a cluster of activity we track as UAT-11587 targeting government and policy organizations across Asia, including in Taiwan, India, the Philippines, and Cambodia, to deliver a previously undocumented backdoor referred to as “Antino” in developer artifacts. https://blog.talosintelligence.com/china-nexus-uat-11587-targets-government-and-policy-organizations-across-asia-with-antino-backdoor/ 🎖@malwr

JoasASantos/Offensive-Security-AI-Models: Uncensored AI models or those fine-tuned for cybersecurity tasks. https://github.com/JoasASantos/Offensive-Security-AI-Models 🎖@malwr

NeedyMantis: Unpacking a post-compromise malware family used in targeted operations | Microsoft Security Blog Microsoft Threat Intelligence identified NeedyMantis, a modular post-compromise malware framework used in targeted intrusions that combines custom loaders, encrypted archives, and extensible components to maintain long-term access and support follow-on operations. https://www.microsoft.com/en-us/security/blog/2026/09/28/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations/ 🎖@malwr

Uncovering a SectopRAT Variant Embedded in Legitimate Software | FortiGuard Labs Analysis of a SectopRAT variant hidden in tampered legitimate software that steals credentials and enables remote system control… https://www.fortinet.com/blog/threat-research/uncovering-a-sectoprat-variant-embedded-in-legitimate-software 🎖@malwr

TwoSevenOneT/InjectSetConsole: Proof of Concept for Process Code Injection Without Using WriteProcessMemory https://github.com/TwoSevenOneT/InjectSetConsole 🎖@malwr

rPlayAI/rPlayHub: iPhone Mirroring for macOS and Linux — scrcpy for iOS and a cross-platform Device Hub clone. Mirror and control an iPhone (iOS 27+); Raspberry Pi and Windows next. Part of rPlay. https://github.com/rPlayAI/rPlayHub 🎖@malwr

newliver666/apk-reverse: Suitable for Android APK reverse engineering analysis https://github.com/newliver666/apk-reverse An Agent Skill for Android APK reverse engineering, debloating, ad removal, surgical dex patching, repacking, and runtime/server analysis. 🎖@malwr

EDR Evasion: Process Injection Without WriteProcessMemory Technique performs Windows process code injection by leveraging a Windows named pipe, it does not use VirtualAllocEx and WriteProcessMemory https://www.zerosalarium.com/2026/09/edr-evasion-process-injection-without-WriteProcessMemory.html 🎖@malwr

nbs32k/LocalStranger: PoC for WinNotify, demonstrated through a driver mapper, and local privilege escalation. https://github.com/nbs32k/LocalStranger 🎖@malwr

ngwg/ceasta: disassembler, decompiler and debugger in one, with a built-in mcp server: point an ai at a binary and it can debug it, not just read it. ida-style listing, pseudocode (f5), x64dbg-style debugger (windows and linux), binary diff, lua plugins. reads pe, elf and mach-o. runs on windows, linux and macos. https://github.com/ngwg/ceasta 🎖@malwr

Kothamine malware uses Tailscale’s tailcat to evade network detection Kothamine uses a legitimate Tailscale tool to receive attackers’ commands through an encrypted connection with no malicious domain to block. https://www.malwarebytes.com/blog/threat-intel/2026/09/kothamine-malware-uses-tailscales-tailcat-to-evade-network-detection 🎖@malwr

Bypassing EDR with Local AI How hard is it to bypass EDR in the modern times with AI? As it turns out, not very hard. https://projectblack.io/blog/bypassing-edr-with-local-ai/ 🎖@malwr

Part 2: Visual-layer hiding — Hawkeye Research Visual-layer anti-capture in DWM: CVisual::HasProtectedContent (bit 7 at +0x6A), vtable heap scan, HWND/PID attribution, and defender-side detection on Windows 10/11. https://hawkeye-leo.github.io/hawkeye/research/capture/02-visual-hiding/ 🎖@malwr

HimitsuShell/HimitsuShell: shell script protector (obfuscation, embedded interpreter, DRM) - invisible to kernel tracing https://github.com/HimitsuShell/HimitsuShell 🎖@malwr

Inside a multi stage toll fraud operation targeting Poland CERT Polska uncovered a toll fraud operation targeting Polish users through deceptive Meta advertisements and malicious applications distributed via Google Play. We preserved 1235 ads, linked 852 to 17 applications through code or infrastructure, reconstructed the complete execution chain, and observed live premium SMS and carrier billing tasking. https://cert.pl/en/posts/2026/09/tollfraud-analysis/ 🎖@malwr