I've reverse engineered the infamous NSO Group's Pegasus spyware for Android. Check out the article if you want to know how it implements its functionalities. https://t.co/Tj4tLV5IUU #pegasus#spyware#dfir
#Malware_analysis
1. Bandook RAT - C2 Traffic Analysis
https://t.co/tXXvPrbE1o
// IOC extraction, protocol analysis, and detection notes
2⃣. VELVET CHOLLIMA Infostealer Campaign
https://t.co/JRv7nggcCW
// Final payload is MoonPeak, a custom variant of the open-source XenoRAT malware
3⃣. Gentlemen RaaS
https://t.co/uPHFH9vzzY
// The group actively evaluates CVE-2024-55591-https://t.co/nQJG3gBkqI, CVE-2025-32433- https://t.co/tSxk6Rc6he, CVE-2025-33073- https://t.co/2T97IwM5wr and combines them with technique‑driven paths like backup and management‑controller abuse and NTLM relay workflows
I've discovered an organized traffer gang (likely of Russian origin) that targets Web3 employees and Crypto holders and published the research at https://t.co/4QReL6kg0P. #malware#threatintelligence#dfir
Hybrid Analysis reports an organised “traffer gang” targeting crypto holders and Web3 employees. The operation delivers malware via fake Electron apps, disguised as legitimate tools. https://t.co/jH2xu0VTAR
I've discovered an organized traffer gang (likely of Russian origin) that targets Web3 employees and Crypto holders and published the research at https://t.co/4QReL6kg0P. #malware#threatintelligence#dfir
A new two-stage malware is targeting crypto wallets, signed with a valid EV certificate to bypass security tools and steal sensitive data from Windows machines.
Here's how "LeakyInjector" and "LeakyStealer" work and how devs can protect themselves.
Thread ↓