uk
Feedback
MalDev Academy

MalDev Academy

Відкрити в Telegram

A comprehensive module-based malware development course providing fundamental to advanced level knowledge Site: https://maldevacademy.com Twitter: https://twitter.com/maldevacademy Contact : @internetwar This is NOT official page

Показати більше
310
Підписники
Немає даних24 години
Немає даних7 днів
Немає даних30 днів
Архів дописів
3 New challenges uploaded: - Fibers For Shellcode Execution - Anti-Analysis: Domain-Joined Check - Custom GetProcAddress: Compile-Time Hash Obfuscation

New challenge along with it’s code solution is dropping tonight. Creating a compile-time hashing function to easily hide stri
New challenge along with it’s code solution is dropping tonight. Creating a compile-time hashing function to easily hide strings inside your binary.

Update 7 - November - Malware Directory Placement - Utilizing Fibers For Payload Execution - TLS Callbacks For Anti-Debugging Update 8 - January - Threadless Injection - Module Stomping - Module Overloading - Process Hollowing Update 9 - Feburary - Ghost Process Injection - Herpaderping Process Injection - Transacted Hollowing - Ghostly Hollowing - Herpaderply Hollowing

Custom implementations of Transacted Hollowing, Ghostly Hollowing, and Herpaderply Hollowing. Coming soon!
Custom implementations of Transacted Hollowing, Ghostly Hollowing, and Herpaderply Hollowing. Coming soon!

Update 6 has been posted. These are pretty large and complex modules. - Local PE Execution - Reflective DLL Injection - PeFluctuation (in-memory encryption) - Building a PE Packer Update 7 tentatively for November is: - DLL Proxying - Utilizing Fibers For Payload Execution - TLS Callbacks For Anti-Debugging

Injecting Mimikatz into a remote process.
Injecting Mimikatz into a remote process.

Testing the PE Packer against MDE. Packed Mimikatz running as expected. Update 6 will teach you to build your own PE packer.
Testing the PE Packer against MDE. Packed Mimikatz running as expected. Update 6 will teach you to build your own PE packer.

New shellcode development challenge up on the website
New shellcode development challenge up on the website

Custom reflective loader in the works for October’s update 🔥
Custom reflective loader in the works for October’s update 🔥

PeFluctuation is a technique designed to hide PE files in memory. The images show PeFluctuation in action, hiding Mimikatz in
+1
PeFluctuation is a technique designed to hide PE files in memory. The images show PeFluctuation in action, hiding Mimikatz in memory and evading both pe-sieve and moneta. PeFluctuation module will be included in update 6.

Our EXE loader is now available to everyone on GitHub: https://github.com/Maldev-Academy/MaldevAcademyLdr.1 We'll be uploading more repositories on our GitHub in the future.

Local PE Injection for update 6 is in the works.
Local PE Injection for update 6 is in the works.

September update is out. This one is heavy on AV & EDR evasion. - Introduction to Havoc C&C - Building an evasive DLL payload loader - Introduction to DLL sideloading - Practical DLL sideloading example - DLL sideloading for EDR evasion - Bring your own vulnerable driver (BYOVD)

Maldev Academy DLL Loader vs Crowdstrike The DLL loader is for Maldev members. But we're also publishing an EXE version of th
Maldev Academy DLL Loader vs Crowdstrike The DLL loader is for Maldev members. But we're also publishing an EXE version of the loader on our GitHub for anyone to use. https://github.com/Maldev-Academy

Process injecting the EDR process? Yes! Bring Your Own Vulnerable Driver (BYOVD) coming up soon.
Process injecting the EDR process? Yes! Bring Your Own Vulnerable Driver (BYOVD) coming up soon.

Upcoming DLL loader capabilities
Upcoming DLL loader capabilities

Last week’s challenge was to implement a “kill date” for a malware. The solution has been posted now! As a reminder you can s
Last week’s challenge was to implement a “kill date” for a malware. The solution has been posted now! As a reminder you can submit your challenge to be featured in the upcoming weeks.

Lots of DLL side-loading action in the next update!
Lots of DLL side-loading action in the next update!

Our latest module shows the implementation of Digital Rights Management (DRM) within the malware. Once executed on a machine,
Our latest module shows the implementation of Digital Rights Management (DRM) within the malware. Once executed on a machine, the malware will not execute on any other machine. This can potentially be effective against AV/EDR automatic sample submission.

Injecting shellcode into Microsoft Defender from the kernel. Update 5 is looking 🔥🔥
Injecting shellcode into Microsoft Defender from the kernel. Update 5 is looking 🔥🔥