16 300подписчиков сейчас
Публикации всего: 113
Carry-On Compromise: TA4922 Packs PackClient | Proofpoint US
Key Findings Proofpoint identified a command and control (C2) framework called PackClient sold on Telegram. It is being used by at least one threat actor, Chinese-speaking TA4922. With
https://www.proofpoint.com/us/blog/threat-insight/carry-compromise-ta4922-packs-packclient
🎖@malwr
a fake resume invoked China's defence-tech elite, then installed VShell
A fake resume claimed an applicant from one of China's Seven Sons of National Defence, then delivered a Go loader, SNOWLIGHT and a 4.65 MB fileless VShell payload.
https://blog.himanshuanand.com/2026/08/a-fake-resume-invoked-chinas-defence-tech-elite-then-installed-vshell/
🎖@malwr
gcarmix/HexWalk: Hex Viewer/Editor/Analyzer compatible with Linux/Windows/MacOS
https://github.com/gcarmix/hexwalk
🎖@malwr
talha-nazeef-ahmed/RPC-Triage: A zero-symbol static analysis engine that extracts and mathematically ranks the Windows RPC attack surface using an AHP-based risk model.
https://github.com/talha-nazeef-ahmed/RPC-Triage
🎖@malwr
PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure
Acronis Threat Research Unit (TRU) has identified an ongoing campaign delivering a previously undocumented custom backdoor against Afghan telecom providers and South Asian critical infrastructure organizations. The backdoor, tracked as PATCHCORD, is a compiled C/C++ implant delivered through sector-specific lures, including fake VPN installers impersonating Afghan Telecom (AFTEL) and telecom management tools.
https://www.acronis.com/en/tru/posts/patchcord-new-malware-cluster-targets-afghan-telecom-and-south-asian-critical-infrastructure/
🎖@malwr
Philippine Nuclear Agency and Naval Contractor Targeted by Suspected Chinese-Speaking Operator Using Known Vulnerabilities
An exposed staging server reveals ownCloud pre-signed URL abuse against a Philippine nuclear agency and exploitation of a naval contractor's WordPress website.
https://hunt.io/blog/chinese-speaking-operator-philippine-nuclear-naval-contractor
🎖@malwr
karankantaria/binviz: Binary visualiser and triage tool — entropy, byte-class and Hilbert surfaces, dot plots and control-flow graphs over one shared address-space model.
https://github.com/karankantaria/binviz
🎖@malwr
PPEE (puppy) 1.15
PPEE is a Professional PE file Explorer for reversers, malware researchers and those who want to statically inspect PE files in more detail
- Clustering/Similarity engine added (Hash data is stored locally in a sqlite db next to PPEE). Similar binaries are notified and grouped by color.
- Multi-file supported with flexible tabs
- Long-awaited Settings dialog added
- File Information added in PPEE (Ported from FileInfo plugin)
- Progressbar added for heavy jobs
- Warning/Error dot added to the treeview items
- AMD64 and ARM64 Exception Dir support
- .Net/CLR parsing improved with edit capability
- New debug types supported (FPO, MISC, BBT/RSRVD10, VC_FEAT, POGO, ILTCG, DLL_CHAR, PDB_CHECKSUM, EMDEDDED_PORTABLE_PDB, PERFMAP) with edit capability
- UI is now DPI aware
- WoW64 redirection support
- PPEE is now faster (Highly refactored and unnecessary MFC, stdafx libraries removed from source code)
- Windows XP supported
- Bugfixes
https://mzrst.com/
🎖@malwr
MmMapIoSpace Returns NULL: Tracing the Real Kernel Mechanism Through ntoskrnl
Tracing exactly why MmMapIoSpace returns NULL on Windows 11 past the commonly cited explanations and into undocumented page table ownership checks inside the kernel.
https://sibouzitoun.tech/articles/mmmapiospace-returns-null-tracing-the-real-kernel-mechanism-through-ntoskrnlexe/
🎖@malwr