REMnux® is a free Linux toolkit for reverse-engineering and analyzing malware. Follow this account, managed by @lennyzeltser, for #REMnux updates and news.
Testing the new GPT-5.4 inside REMnux with real malicious artifacts, memory dumps, and the custom analysis skill I built for it.
Honestly… this is next level.
The speed at which it pivots through artifacts, correlates behavior, and surfaces relevant findings is something I haven’t seen before.
Still early testing, but very impressive so far.
As also mentioned by @malwrhunterteam , the actor also signed a copy of Microsoft's OLEVIEW.exe.
I analyzed it with the new MCP in @REMnux and this is what it found:
It found that there was a PNG, and after the PNG was another fake PNG, which was an encrypted payload.
1/5
#Ubuntu-Based REMnux 8 #Linux Toolkit for Malware Analysis Is Out Now to Celebrate the Project's 15th Anniversary https://t.co/pllhya1gtJ
@REMnux#OpenSource
Nice! It did a good job with this FUD Webex installer signed by "LAKESIDE TRANSMISSION INC."
40adf1aaa86dbe99cafa24fcfc7847fac976fc3d01d07cc6a774970028bbffdd
Now if only I could convince Microsoft to finally revoke this certificate.
REMnux based on Ubuntu 24.04 (Noble) is available now, along with a new, more resilient installer. Available as prebuilt VMs for VMware, Proxmox and VirtualBox, as well as a Docker container. Get your malware analysis toolkit from https://t.co/ztNfHgnq9O.
The new @REMnux MCP server lets AI analyze malware using the REMnux toolkit. I was surprised at the depth of investigation it delivers. Most of my time went into capturing how I approach malware analysis and providing AI the right guidance at the right time, so it can think and adapt as it works.
https://t.co/SRgIUJV304
REMnux based on Ubuntu 24.04 (Noble) is available now, along with a new, more resilient installer. Available as prebuilt VMs for VMware, Proxmox and VirtualBox, as well as a Docker container. Get your malware analysis toolkit from https://t.co/ztNfHgnq9O.
#MalwareAnalysis tip: Inetsim is a network simulator for malware analysis. You can host your own files/payloads in inetsim really easily. I had to do this today to analyze a shellcode implant that was no longer hosted on its staging domain.
Here is how to do this 👇
Continuing with the videos introducing key analysis distributions for malware analysis and reverse engineering - next up is @REMnux 👇
📽️ https://t.co/cHbNWphLVf
I'll discuss what is, why/when I use it and how to get started.
If you get an error when trying to upgrade REMnux, this might be due to an issue with SaltStack, which we've been working to address. One way around it is to manually install the latest REMnux installer, then try running "remnux upgrade" again: https://t.co/EB24Zww1WT