⤷ Title: DreamWalkers: New Reflective Shellcode Loader Spoofs Call Stacks & Supports .NET for EDR Evasion
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 07 Jul 2025 03:11:10 +0000
════════════════════════
⌗ Tags: #Open Source Tool #.NET #Call Stack Spoofing #cybersecurity #DreamWalkers #EDR Bypass #malware #Position Independent Code #Reflective Loading #Research Project #shellcode loader
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 07 Jul 2025 03:11:10 +0000
════════════════════════
⌗ Tags: #Open Source Tool #.NET #Call Stack Spoofing #cybersecurity #DreamWalkers #EDR Bypass #malware #Position Independent Code #Reflective Loading #Research Project #shellcode loader
Penetration Testing Tools
DreamWalkers: New Reflective Shellcode Loader Spoofs Call Stacks & Supports .NET for EDR Evasion
DreamWalkers Reflective shellcode loader inspired by MemoryModule and Donut, with advanced call stack spoofing and .NET support. Unlike traditional call stack spoofing, which often fails within reflectively loaded modules due to missing unwind metadata, DreamWalkers…
⤷ Title: Kimsuky APT Escalates Cyberespionage with Stealthy LNK Files & Reflective Malware Payloads
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 05 Aug 2025 00:01:08 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT #Cyberespionage #cybersecurity #Kimsuky #LNK Files #malware #North Korea #Reflective DLL Injection #south korea
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 05 Aug 2025 00:01:08 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT #Cyberespionage #cybersecurity #Kimsuky #LNK Files #malware #North Korea #Reflective DLL Injection #south korea
Daily CyberSecurity
Kimsuky APT Escalates Cyberespionage with Stealthy LNK Files & Reflective Malware Payloads
A new report reveals Kimsuky, a North Korea-linked APT, is using sophisticated LNK files and reflective payloads to infiltrate systems and conduct cyberespionage against South Korean targets.
⤷ Title: Maranhão Stealer: A New Malware Hijacks Gamers’ PCs Through Pirated Games
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Sep 2025 01:53:31 +0000
════════════════════════
⌗ Tags: #Malware #Cybercrime #Cyble #gaming community #Infostealer #malware #Maranhão Stealer #pirated software #Reflective DLL Injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Sep 2025 01:53:31 +0000
════════════════════════
⌗ Tags: #Malware #Cybercrime #Cyble #gaming community #Infostealer #malware #Maranhão Stealer #pirated software #Reflective DLL Injection
Daily CyberSecurity
Maranhão Stealer: A New Malware Hijacks Gamers' PCs Through Pirated Games
A new report reveals Maranhão Stealer, a new malware targeting the gaming community through pirated software and cheats. It steals crypto, credentials, and data.
⤷ Title: Lazarus Group’s New ScoringMathTea RAT Uses Reflective Plugin Loader and Custom Polyalphabetic Crypto for Espionage
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:39:19 +0000
════════════════════════
⌗ Tags: #Malware #API hashing #cyber_espionage #Lazarus Group #Polyalphabetic Cipher #rat #Reflective DLL Injection #ScoringMathTea #TEA/XTEA
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:39:19 +0000
════════════════════════
⌗ Tags: #Malware #API hashing #cyber_espionage #Lazarus Group #Polyalphabetic Cipher #rat #Reflective DLL Injection #ScoringMathTea #TEA/XTEA
Daily CyberSecurity
Lazarus Group's New ScoringMathTea RAT Uses Reflective Plugin Loader and Custom Polyalphabetic Crypto for Espionage
A deep-dive on Lazarus’s ScoringMathTea RAT reveals a full reflective DLL injection system, TEA/XTEA C2 encryption, and a polyalphabetic cipher for API hashing—a highly evasive tool for espionage.
⤷ Title: Itch.io Targeted: Lumma Stealer Deployed Via Fake Updates and Reflective Node.js Loader
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 10 Dec 2025 00:16:55 +0000
════════════════════════
⌗ Tags: #Malware #Game Update Lure #information stealer #Itch.io #Lumma Stealer #Nexe #Node.js #reflective loading
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 10 Dec 2025 00:16:55 +0000
════════════════════════
⌗ Tags: #Malware #Game Update Lure #information stealer #Itch.io #Lumma Stealer #Nexe #Node.js #reflective loading
Daily CyberSecurity
Itch.io Targeted: Lumma Stealer Deployed Via Fake Updates and Reflective Node.js Loader
A Lumma Stealer campaign is using fake update lures on Itch.io. The malware uses a Node.js-compiled executable and a reflective loading technique to steal passwords and crypto wallets.
⤷ Title: The Typosquatting Trap: Fake Telegram Portal Delivers Stealthy Memory-Resident Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 20 Mar 2026 02:03:28 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #infosec #Malware Analysis #Memory_Resident Payload #reflective loading #social engineering #Telegram malware #threat intelligence #Typosquatting #Windows Defender Bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 20 Mar 2026 02:03:28 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #infosec #Malware Analysis #Memory_Resident Payload #reflective loading #social engineering #Telegram malware #threat intelligence #Typosquatting #Windows Defender Bypass
Daily CyberSecurity
The Typosquatting Trap: Fake Telegram Portal Delivers Stealthy Memory-Resident Malware
Researchers uncover a fake Telegram site distributing stealthy, memory-resident malware that bypasses Windows Defender. Always verify your download URLs.
⤷ Title: Fileless Remcos RAT Hijacks Trusted Windows Tools
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 07 Apr 2026 01:01:57 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #Fileless Malware #infosec #javascript #Lat61 #LOLBins #Malware Analysis #phishing #powershell #Reflective Loader #Remcos RAT #Remote Access Trojan
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 07 Apr 2026 01:01:57 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #Fileless Malware #infosec #javascript #Lat61 #LOLBins #Malware Analysis #phishing #powershell #Reflective Loader #Remcos RAT #Remote Access Trojan
Daily CyberSecurity
Fileless Remcos RAT Hijacks Trusted Windows Tools
Researchers unmask a fileless Remcos RAT campaign using obfuscated JS and LOLBins to hijack systems in-memory. See the technical breakdown from Lat61.