Malware News
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ... Partner channel: @cveNotify For ads: https://telega.io/c/malwr
Ko'proq ko'rsatish📈 Telegram kanali Malware News analitikasi
Malware News (@malwr) Ingliz til segmentidagi kanali faol ishtirokchi. Hozirda hamjamiyat 16 243 obunachidan iborat bo'lib, Texnologiyalar & Aralashmalar toifasida 7 844-o'rinni va AQSH mintaqasida 2 332-o'rinni egallagan.
📊 Auditoriya ko‘rsatkichlari va dinamika
невідомо sanasidan buyon loyiha tez o‘sib, 16 243 obunachiga ega bo‘ldi.
25 Avgust, 2026 dagi oxirgi ma’lumotlarga ko‘ra kanal barqaror faollikka ega. Oxirgi 30 kunda obunachilar soni 712 ga, so‘nggi 24 soatda esa 16 ga o‘zgardi va umumiy qamrov yuqori darajada qolmoqda.
- Tasdiqlash holati: Tasdiqlanmagan
- Jalb etish (ER): Auditoriya o‘rtacha 3.49% darajada jalb etiladi. Nashrdan keyingi dastlabki 24 soatda kontent odatda umumiy obunachilar sonining 2.11% ini tashkil etuvchi reaksiyalarni to‘playdi.
- Post qamrovi: Har bir post o‘rtacha 566 marta ko‘riladi; birinchi sutkada odatda 343 ta ko‘rish yig‘iladi.
- Reaksiyalar va o‘zaro ta’sir: Auditoriya faol: har bir postga o‘rtacha 2 ta reaksiya keladi.
- Tematik yo‘nalishlar: Kontent threat, kernel, cve-2025, actor, attack kabi asosiy mavzularga jamlangan.
📝 Tavsif va kontent siyosati
Muallif resursni shaxsiy fikrni ifoda etish maydoni sifatida ta’riflaydi:
“The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...
Partner channel: @cveNotify
For ads: https://telega.io/c/malwr”
Yuqori yangilanish chastotasi (oxirgi ma’lumot 26 Avgust, 2026 da olingan) sababli kanal doimo dolzarb va katta qamrovli bo‘lib qoladi. Analitika auditoriya kontent bilan faol hamkorlik qilishini, uni Texnologiyalar & Aralashmalar toifasidagi muhim ta’sir nuqtasiga aylantirishini ko‘rsatadi.
Ma'lumot yuklanmoqda...
| Sana | Obunachilarni jalb qilish | Esdaliklar | Kanallar | |
| 26 Avgust | +16 | |||
| 25 Avgust | +18 | |||
| 24 Avgust | +23 | |||
| 23 Avgust | +15 | |||
| 22 Avgust | +21 | |||
| 21 Avgust | +24 | |||
| 20 Avgust | +24 | |||
| 19 Avgust | +17 | |||
| 18 Avgust | +22 | |||
| 17 Avgust | +13 | |||
| 16 Avgust | +15 | |||
| 15 Avgust | +23 | |||
| 14 Avgust | +38 | |||
| 13 Avgust | +29 | |||
| 12 Avgust | +28 | |||
| 11 Avgust | +30 | |||
| 10 Avgust | +15 | |||
| 09 Avgust | +20 | |||
| 08 Avgust | +27 | |||
| 07 Avgust | +21 | |||
| 06 Avgust | +25 | |||
| 05 Avgust | +24 | |||
| 04 Avgust | +20 | |||
| 03 Avgust | +34 | |||
| 02 Avgust | +34 | |||
| 01 Avgust | +20 |
- Clustering/Similarity engine added (Hash data is stored locally in a sqlite db next to PPEE). Similar binaries are notified and grouped by color. - Multi-file supported with flexible tabs - Long-awaited Settings dialog added - File Information added in PPEE (Ported from FileInfo plugin) - Progressbar added for heavy jobs - Warning/Error dot added to the treeview items - AMD64 and ARM64 Exception Dir support - .Net/CLR parsing improved with edit capability - New debug types supported (FPO, MISC, BBT/RSRVD10, VC_FEAT, POGO, ILTCG, DLL_CHAR, PDB_CHECKSUM, EMDEDDED_PORTABLE_PDB, PERFMAP) with edit capability - UI is now DPI aware - WoW64 redirection support - PPEE is now faster (Highly refactored and unnecessary MFC, stdafx libraries removed from source code) - Windows XP supported - Bugfixeshttps://mzrst.com/ 🎖@malwr
| 2 | MmMapIoSpace Returns NULL: Tracing the Real Kernel Mechanism Through ntoskrnl
Tracing exactly why MmMapIoSpace returns NULL on Windows 11 past the commonly cited explanations and into undocumented page table ownership checks inside the kernel.
https://sibouzitoun.tech/articles/mmmapiospace-returns-null-tracing-the-real-kernel-mechanism-through-ntoskrnlexe/
🎖@malwr | 221 |
| 3 | https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-237a
🎖@malwr | 311 |
| 4 | Handle Redirect
Welcome to this new Medium post. In this one we will see how to redirect a handle’s kernel object pointer to a different EPROCESS, getting…
https://medium.com/@s12deff/handle-redirect-549902e6d868
🎖@malwr | 316 |
| 5 | Local Privilege Escalation To System In Wibu-Systems CodeMeter Application | Shelltrail
This research post describes the process of finding and exploiting a local privilege escalation in the Wibu-Systems CodeMeter application
https://shelltrail.com/research/local-privilege-escalation-to-system-in-wibu-systems-codemeter-application
🎖@malwr | 440 |
| 6 | jyatesdotdev/wd-smart-reader: macOS CLI tool for reading SMART data from WD external drives (MyBook, Elements) via SES diagnostic pages. Works on Apple Silicon, no kernel extensions needed.
https://github.com/jyatesdotdev/wd-smart-reader
🎖@malwr | 427 |
| 7 | Malware development trick 63: modifying PE version metadata and icon. Simple C example
﷽
https://cocomelonc.github.io/malware/2026/08/24/malware-tricks-63.html
🎖@malwr | 417 |
| 8 | Manic: Blend between Banking Malware & Spyware
Manic is a newly identified Android malware family with broad surveillance and remote-control capabilities, introducing an unusual Wi‑Fi mesh technique.
https://www.threatfabric.com/blogs/manic-blend-between-banking-malware-and-spyware
🎖@malwr | 376 |
| 9 | daniomass/SliverMirage: Crystal Palace PICO loader for Sliver C2 dual-layer AMSI bypass, ETW silencing, AES-256-CBC encrypted payloads, 6 delivery variants
https://github.com/daniomass/SliverMirage
🎖@malwr | 320 |
| 10 | The Citizen Lab Bad Connection: Uncovering Global Telecom Exploitation by Covert Surveillance Actors
Our investigation uncovers two sophisticated telecom surveillance campaigns and, for the first time, links real-world attack traffic to mobile operator signalling infrastructure. The findings expose how suspected commercial surveillance vendors (CSVs) exploit the global telecom interconnect ecosystem, leverage private operator networks, and conduct covert location tracking operations that can persist undetected for years.
https://citizenlab.ca/research/uncovering-global-telecom-exploitation-by-covert-surveillance-actors/
🎖@malwr | 293 |
| 11 | Inside the Falcon How CrowdStrike Catches You
A full reverse-engineering teardown of the CrowdStrike Falcon sensor: the six kernel callback sources, the WFP network engine, the file-system minifilter, the cspcm4 broker, the user-mode service (DNS / AMSI / browser / Identity Protection), and the cloud-loaded detection engine — plus every structural blind spot. How Falcon sees you, and where the seams are.
https://0xdbgman.github.io/posts/inside-the-falcon-how-crowdstrike-catches-you/
🎖@malwr | 310 |
| 12 | Your executable is a SQLite database
I have been probably obsessed with two things in the last few years: Nix as a tool to explore innovative ideas that require the capability to rebuild the world and replacing ELF with SQLite as an executable format. You might have noticed that these two ideas are well suited to each other.
https://fzakaria.com/2026/08/23/your-executable-is-a-sqlite-database
🎖@malwr | 426 |
| 13 | Tracking PavinLoader across ClickFix and fake download campaigns
We found PavinLoader being used across ClickFix, fake software, and RenPy campaigns to deliver Amatera Stealer and other malware.
https://www.malwarebytes.com/blog/threat-intel/2026/08/tracking-pavinloader-across-clickfix-and-fake-download-campaigns
🎖@malwr | 459 |
| 14 | Text Template
Text template files can contain C# or Visual Basic code that could be compiled and executed at build time. Threat actors can create or modify .tt files to execute code in the context of a trusted p…
https://ipurple.team/2026/08/24/text-template/
🎖@malwr | 420 |
| 15 | Reverse Engineering a 0day used Against EDRs
https://medium.com/@jehadbudagga/reverse-engineering-a-0day-used-against-crowdstrike-edr-a5ea1fbe3fd4
🎖@malwr | 421 |
| 16 | Inside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asia | Enki White Hat
Inside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asia
https://www.enki.co.kr/en/media-center/blog/inside-kimsuky-s-abuse-of-legitimate-remote-control-tools-across-northeast-asia
🎖@malwr | 374 |
| 17 | SLEEPWALKER: A Passive Backdoor With Its Own Command Language
Losing access to VirusTotal Intelligence at the start of the year was surprisingly productive. Unable to hunt for interesting new malware, I stopped adding to my âTODOâ pile and finally worked through my backlog from last year. That led to a detailed examination of BeheMOF as well as the discovery of this malware. Upon closer inspection, a sample that did not seem too noteworthy at first turned out to have a distinctive design once I looked under the hood: a passive backdoor that opens no obvious listening port and carries no payload inside itself. It waits in memory doing nothing at all until one specifically crafted network packet reaches the machine, which is why I am calling it SLEEPWALKER.
https://r136a1.dev/2026/08/24/sleepwalker-a-passive-backdoor-with-its-own-command-language/
🎖@malwr | 355 |
| 18 | Fairy Law: Abusing MicrosoftSignedOnly
Welcome to this new Medium post. In this one we will see how a legitimate Windows process mitigation policy can be abused to globally…
https://medium.com/@s12deff/fairy-law-abusing-microsoftsignedonly-8d35018bc99f
🎖@malwr | 414 |
| 19 | Auditing Microsoft Defender and Intune Configuration Changes
Microsoft is clearly moving toward a more unified security operations experience within the Defender portal. Over the last few years, we have seen Microsoft bring more security capabilities together under the Defender platform. Instead of working with completely separate portals...
https://jeffreyappel.nl/auditing-microsoft-defender-and-intune-configuration-changes/
🎖@malwr | 491 |
| 20 | tracebyte8/SysTrace: SysTrace - Linux System Call Monitor using PTRACE API , It traces system calls, monitors process, file, network, and memory activity, detects suspicious behavior, and generates detailed security reports.
https://github.com/tracebyte8/SysTrace
🎖@malwr | 1 041 |
