⤷ Title: VAD Stomping from Kernel R/W Primitive
════════════════════════
𐀪 Author: S12 - 0x12Dark Development
════════════════════════
ⴵ Time: Tue, 11 Aug 2026 21:15:00 GMT
════════════════════════
⌗ Tags: #hacking #pentesting #malware #cybersecurity #infosec
════════════════════════
𐀪 Author: S12 - 0x12Dark Development
════════════════════════
ⴵ Time: Tue, 11 Aug 2026 21:15:00 GMT
════════════════════════
⌗ Tags: #hacking #pentesting #malware #cybersecurity #infosec
Medium
VAD Stomping from Kernel R/W Primitive
Welcome to this new Medium post. In this one we will see how to walk the Windows VAD tree from a kernel R/W primitive, and how to abuse…
⤷ Title: macOS ClickFix Campaign Hides Its Lure Behind a Fingerprinting Gate
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 12 Aug 2026 07:30:46 +0000
════════════════════════
⌗ Tags: #Malware #AMOS #Atomic Stealer #ClickFix #Infostealer #macOS #MacSync #TDS
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 12 Aug 2026 07:30:46 +0000
════════════════════════
⌗ Tags: #Malware #AMOS #Atomic Stealer #ClickFix #Infostealer #macOS #MacSync #TDS
Daily CyberSecurity
macOS ClickFix Campaign Hides Its Lure Behind a Fingerprinting Gate
At a glance Malware family Atomic Stealer (AMOS) and MacSync infostealers Threat actor Unnamed operator running a Traffic Distribution System (attribution not stated) Target or victims Genuine mac…
⤷ Title: Another Morning, Another RAT Kiddie | SillyGoXLR
════════════════════════
𐀪 Author: 0xRushy
════════════════════════
ⴵ Time: Wed, 12 Aug 2026 08:35:26 GMT
════════════════════════
⌗ Tags: #cybersecurity #penetration_testing #malware_analysis #discord
════════════════════════
𐀪 Author: 0xRushy
════════════════════════
ⴵ Time: Wed, 12 Aug 2026 08:35:26 GMT
════════════════════════
⌗ Tags: #cybersecurity #penetration_testing #malware_analysis #discord
Medium
Another Morning, Another RAT Kiddie | SillyGoXLR
Yesterday, I tweeted asking people to share malware samples with me for analysis, for personal reasons.
⤷ Title: ChainDrop npm Worm Hits 400+ Packages via Blockchain C2
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 07:29:07 +0000
════════════════════════
⌗ Tags: #Malware #Blockchain C2 #ChainDrop #CI/CD security #npm Worm #supply chain attack #Unit 42
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 07:29:07 +0000
════════════════════════
⌗ Tags: #Malware #Blockchain C2 #ChainDrop #CI/CD security #npm Worm #supply chain attack #Unit 42
Daily CyberSecurity
ChainDrop npm Worm Hits 400+ Packages via Blockchain C2
At a glance Malware family ChainDrop (Shai-Hulud code lineage) Threat actor Unattributed; possible link to TeamPCP (not confirmed) Targets Developer workstations, CI pipelines, cloud environments …
⤷ Title: Fake Zoom Installer Drops Overlord RAT on macOS
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 06:29:05 +0000
════════════════════════
⌗ Tags: #Malware #.NET malware #fake Zoom installer #Jamf Threat Labs #macOS Malware #Overlord RAT
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 06:29:05 +0000
════════════════════════
⌗ Tags: #Malware #.NET malware #fake Zoom installer #Jamf Threat Labs #macOS Malware #Overlord RAT
Daily CyberSecurity
Fake Zoom Installer Drops Overlord RAT on macOS
At a glance Malware family Overlord (open-source RAT framework) Threat actor Unattributed (suspected DPRK links noted, not confirmed) Target macOS and Windows users Delivery vector Fake Zoom insta…
⤷ Title: Process Parameter Poisoning
════════════════════════
𐀪 Author: S12 - 0x12Dark Development
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 21:51:17 GMT
════════════════════════
⌗ Tags: #infosec #malware #hacking #pentesting #cybersecurity
════════════════════════
𐀪 Author: S12 - 0x12Dark Development
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 21:51:17 GMT
════════════════════════
⌗ Tags: #infosec #malware #hacking #pentesting #cybersecurity
Medium
Process Parameter Poisoning
Welcome to this new Medium post. In this one we will see Process Parameter Poisoning, a process injection technique published by SensePost…
⤷ Title: Gunra Ransomware Hits Critical Infrastructure, CISA Warns
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 14 Aug 2026 07:07:04 +0000
════════════════════════
⌗ Tags: #Malware #CISA #Conti #Double Extortion #Gunra Ransomware #ransomware #StopRansomware
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 14 Aug 2026 07:07:04 +0000
════════════════════════
⌗ Tags: #Malware #CISA #Conti #Double Extortion #Gunra Ransomware #ransomware #StopRansomware
Daily CyberSecurity
Gunra Ransomware Hits Critical Infrastructure, CISA Warns
At a glance Malware family Gunra ransomware (RaaS, Conti-derived) Threat actor Gunra operators and affiliates, also branded Golden Community Targets Government and critical infrastructure across f…
⤷ Title: Apple Sends Mercenary Spyware Alerts to Users in 110+ Countries
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 03:15:44 +0000
════════════════════════
⌗ Tags: #Malware #Apple #iPhone security #Lockdown Mode #Mercenary Spyware #NSO Group #Pegasus #spyware
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 03:15:44 +0000
════════════════════════
⌗ Tags: #Malware #Apple #iPhone security #Lockdown Mode #Mercenary Spyware #NSO Group #Pegasus #spyware
Daily CyberSecurity
Apple Sends Mercenary Spyware Alerts to Users in 110+ Countries
Apple operates a telemetry-based threat detection system that continuously monitors device signals for indicators of compromise. When evidence of a targeted attack surfaces, the company issues dir…
⤷ Title: WindRelay and SpyNote RAT Combo Turns Android Into NFC Card Relay for Bank Fraud
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 07:19:09 +0000
════════════════════════
⌗ Tags: #Malware #Android malware #Bank Fraud #Group_IB #NFC Relay #Remote Access Trojan #SpyNote #WindRelay
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 07:19:09 +0000
════════════════════════
⌗ Tags: #Malware #Android malware #Bank Fraud #Group_IB #NFC Relay #Remote Access Trojan #SpyNote #WindRelay
Information Security News
WindRelay and SpyNote RAT Combo Turns Android Into NFC Card Relay for Bank Fraud
A single phone call with a fraudster can now result, within the same session, in a loan taken out in the victim’s name and unauthorized purchases charged to their bank card. Researchers at G…
⤷ Title: Reverse Engineering ValleyRAT: From Initial Access to C2
════════════════════════
𐀪 Author: CHANDRA KANT BAURI
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 12:54:15 GMT
════════════════════════
⌗ Tags: #cybersecurity #infosec #malware_analysis #reverse_engineering #malware
════════════════════════
𐀪 Author: CHANDRA KANT BAURI
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 12:54:15 GMT
════════════════════════
⌗ Tags: #cybersecurity #infosec #malware_analysis #reverse_engineering #malware
Medium
Reverse Engineering ValleyRAT: From Initial Access to C2
MalOps.io Challenge Write-up Tracing persistence, encrypted payloads, shellcode execution, security bypasses, and C2 infrastructure