Huntress's Andrew Brandt writes about a less known RMM called Tiflux, which is being used in a growing number of attacks that aim to establish persistence, transmit screenshots, and run commands to collect system profiling information. https://t.co/d9rsbC56xO
#Malware#Mispadu 🇧🇷
Se volvieron tan vagos que ya no esconden la infra de spam
Apuntando a 🇦🇷
Site opendir
hxxps://uglmkt.com/
Link mail (redirige a sitio que descarga Zip+hta)
hxxps://u.to/RmN7Ig
hxxps://u.to/YmN7Ig
hxxps://u.to/h2N7Ig
hxxps://u.to/xGN7Ig
hxxps://u.to/9GN7Ig
#APT#Kimsuky
Kimsuky distributed malware is disguised as ESET Update.
Mutex : GoogleUpdate_01
ae986dd436082fb9a7fec397c8b6e717
general-second.org-help[.]com
#VirusTotal has a special field for mutexes (mutexes_created) in their Yara plugin. You can basically hunt for mutex references in the malware behaviors. I have found this useful on several occasions.
Here is an example hunt for common Remcos mutexes:
REMnux based on Ubuntu 24.04 (Noble) is available now, along with a new, more resilient installer. Available as prebuilt VMs for VMware, Proxmox and VirtualBox, as well as a Docker container. Get your malware analysis toolkit from https://t.co/ztNfHgnq9O.
Checked out the new website (https://t.co/6mhn9Od1ni) for "Rootkits and Bootkits: Reversing Modern Malware and Next Generation Threats" by @vxradius , @sergeybratus and me.
The new book is in progress, stay tuned!
🚀You can now search for malware families, releases, techniques, and code snippets, including archives on Malware Gallery: https://t.co/GxON85HUXh
#InfoSec#Malware#DFIR
Getting started with Linux kernel internals and modules development
"The Linux Kernel Module Programming Guide"
https://t.co/TTPKOJr3J1
#Linux#cybersecurity
🚨 I've put together my first #cheat#sheet around #maldocs, you can download a PDF version from 👇
✅ https://t.co/iruVT35nFh
Covers the tools, common commands, and other information you need to know when analyzing malicious documents, such as Word, OneNote and PDF.