< ciso
brief />
Tag Banner

All news with #malware analysis tag

50 articles

SectopRAT variant hidden in legitimate Windows software

🛡️ The FortiGuard Incident Response team investigated a Windows intrusion where a SectopRAT .NET RAT was concealed inside a legitimate audio application. The malware used a tampered DLL and a multi-stage loader that extracted an encrypted payload from a DB file, initialized the .NET runtime in memory, and executed a heavily obfuscated RAT. The variant communicates over AES-encrypted channels with a hardcoded C2 and backup domains, supports 29 control commands, and steals browser, email, gaming, and cryptocurrency wallet credentials.
read more →

CAIRN: Metadata-First Hunting for AI Malware

🔍 Cisco Talos introduces CAIRN, a research toolkit for hunting and tracking AI-integrated malware using metadata artifacts like prompts, API endpoints, and keys. CAIRN operates without binary downloads, combining rule-based detection, semantic clustering, and relationship graphs to identify related families and infrastructure. The toolkit includes acquisition filters, a three-tier YARA ontology, and an explorer for pivoting from single samples to broader operational ecosystems.
read more →

Understanding JavaScript Obfuscation in Threats

🔎 This Talos blog post explains how obfuscated JavaScript transforms readable code into string arrays, encoded values, runtime decoders, and eval calls, making static reading ineffective. The author outlines common benign and malicious motivations for obfuscation and stresses safe handling: work on copies, avoid executing hostile scripts in useful environments, and use isolated analysis. The article introduces categories of techniques—string hiding, lookup tables, dynamic property access, dead code, runtime code generation, control-flow flattening, anti-analysis measures, and extreme forms like JSFuck—and offers practical counters like beautification, renaming, replacing execution sinks with logging, and using controlled runtime harnesses or headless browsers to recover payloads. It warns about automated obfuscators (npm packages) and Node-specific risks such as access to secrets, and emphasizes a structured, repeatable workflow that leverages tooling and AI on isolated snippets.
read more →

AI-Enabled Malware: Prevalence, Detection, and Trends

🛡️ Palo Alto Networks Unit 42 analyzed 405 AI-integrated malware samples to measure real-world prevalence and detection efficacy. The dataset spans proof-of-concept code, security testing submissions, and AI-branded malware, but only 12 samples appeared on Cortex XDR-protected endpoints. Existing layered defenses — including behavioral analytics, WildFire sandboxing, and endpoint telemetry — detected and blocked all observed production samples.
read more →

Source Code Leak Exposes Flying Eagle Android RAT

🛡️ Source code for the Flying Eagle Android RAT framework is circulating on criminal Telegram channels, with Hunt.io and researcher NetAskari tracing matching control panels and certificates to 170 internet servers. The toolkit is linked to a fake Chinese Public Security app that can capture payments, keystrokes, record screens, use cameras, and display phishing prompts for finance and government services. Chinese authorities urged removal, password changes, and reporting while investigators note the server count does not prove active infections.
read more →

Verify threat indicators before acting on feeds

🔍 The author recounts multiple cases where threat intelligence feeds and advisories mischaracterized malware or buried stronger indicators in machine-readable files. They describe a commercial feed mislabeling a Windows DonutLoader variant as the Linux Chalubo RAT, an official advisory whose PDF lacked stronger hashes present in the STIX bundle, and a CERT report with binary-level discrepancies. The piece stresses that labels and pipeline metadata are guesses until validated and urges analysts to open structured files and detonate samples when stakes are high.
read more →

Introduction to COM Usage by Windows Threats

🧭 This post introduces Component Object Model (COM) fundamentals and explains how analysts can identify and analyze COM usage in binaries. It covers GUIDs, CLSIDs, IIDs, ProgIDs, vtables, and activation APIs such as CoCreateInstance and CoCreateInstanceEx. The article highlights DCOM and COM security concepts, common Windows examples like Task Scheduler, and practical tools (e.g., OleView.NET) and workflows for reversing COM-dependent malware.
read more →

StealC and Amadey: Infostealer Ecosystem Disruption

🔍 Microsoft analyzes how infostealers like StealC and loaders such as Amadey fuel a commodified cybercrime economy by harvesting credentials, cookies, and tokens from unmanaged devices. The post details methods of delivery (SEO poisoning, malicious ads, ClickFix, phishing), StealC’s data collection and C2 behaviors, and how stolen logs are monetized. It also describes a coordinated takedown on June 24, 2026, by Microsoft DCU and partners that disrupted hundreds of domains and C2 servers.
read more →

Automating Disassembly with Local AI Agents

🛠️ This blog demonstrates using AI agents to automate a VB6 disassembler by exposing its parsed model through the Windows Running Object Table and providing an operator briefing plus auto-generated prototypes. The agent (Claude Code in the examples) binds to the COM object, runs scripts to extract P-code, reconstruct source, generate call graphs, and export function metadata to SQLite, all locally without uploading binaries. The approach decouples tool features from fixed menus, enables repeatable exhaustive analysis, and preserves sensitive data on the analyst's workstation.
read more →

Analysis of The Gentlemen self‑propagating ransomware

🛡️ This Microsoft Threat Intelligence blog dissects The Gentlemen, a Go-based RaaS that combines per-file ephemeral Curve25519/XChaCha20 encryption with aggressive self-propagation across networks. The post details operator models, command-line controls, speed modes, privilege elevation via scheduled tasks, and extensive defense-evasion steps including disabling Defender, deleting shadow copies, clearing logs, and terminating backup, database, virtualization, and EDR services. Practical mitigations, Defender detections, hunting queries, and IOCs are provided for defenders and incident responders.
read more →

Researchers Disrupt Glassworm's Resilient Botnet C2

🛡️ CrowdStrike, Google, and The Shadowserver Foundation coordinated to disrupt the Glassworm botnet by simultaneously takedown of four resilient C2 channels. The threat abused Solana blockchain memo fields, the BitTorrent DHT, Google Calendar events, and traditional VPS-hosted servers to persist and evade mitigation. Active campaigns targeted developers via malicious OpenVSX and VS Code extensions and later poisoned GitHub and npm artifacts. Infected hosts now beacon to a CrowdStrike-controlled IP and YARA rules have been published to detect compromise.
read more →

Analysis: Fast16 Malware Targeted Nuclear Simulations

🔎 Symantec and Carbon Black confirm the Lua-based fast16 malware was a pre-Stuxnet sabotage tool designed to corrupt nuclear weapons testing simulations. The threat specifically targets high-explosive runs in LS-DYNA and AUTODYN, activating only when simulated material density reaches ~30 g/cm³. With 101 hook rules organized into 9–10 groups, the framework tracked software versions and spread laterally while avoiding some security products, indicating a methodical, long-running operation.
read more →

Critical Flaw Turns Vect Ransomware into Data Wiper

⚠ Check Point Research discovered a critical implementation bug in Vect 2.0 that causes files larger than 131,072 bytes (128 KB) to be permanently destroyed rather than recoverably encrypted. The ransomware uses raw ChaCha20-IETF without the Poly1305 MAC and a faulty nonce-handling routine that discards three of four decryption nonces, effectively turning the RaaS into a wiper across Windows, Linux and ESXi variants. Researchers also identified multiple additional coding and design errors that undermine the group's RaaS ambitions and affiliate program.
read more →

VECT 2.0 Ransomware Bug Destroys Large Files in Enterprises

⚠️ VECT 2.0 ransomware contains a nonce-handling defect that overwrites per-chunk nonces when encrypting files, leaving only the final nonce saved. As a result, files larger than about 128 KB are partially unrecoverable — roughly only the last quarter can be decrypted — causing the malware to act like a wiper for many enterprise assets. Check Point researchers report the flaw affects Windows, Linux and ESXi builds and means victims cannot recover corrupted data even if they pay.
read more →

Fast16 Sabotage Malware Discovered Predating Stuxnet

🔎 SentinelOne researchers have identified a sabotage-focused malware framework from around 2005 that predates Stuxnet by at least five years. The investigation uncovered a service binary (svcmgmt.exe) embedding a Lua 5.0 VM and a boot-start kernel driver (fast16.sys) that intercepts and patches executables at the storage layer. Fast16 acted as a wormable carrier with multiple 'wormlet' payloads, targeted Windows 2000/XP file shares using weak credentials, and included environmental checks to avoid specific security software. The framework was designed to corrupt outputs from engineering and simulation suites, and was later referenced in the Shadow Brokers leak.
read more →

CISA Malware Analysis: FIRESTARTER Backdoor on Cisco

🔒 CISA and the U.K. NCSC analyzed a sample of the FIRESTARTER Linux ELF backdoor affecting Cisco Firepower and Secure Firewall devices running ASA/FTD. The agency assesses the malware provides persistent remote access, installs a hook into LINA to execute arbitrary shellcode, and can survive firmware updates and reboots. CISA provides YARA rules for detection and directs U.S. FCEB agencies to collect and submit core dumps per V1: ED 25-03, and to await further guidance.
read more →

Automated Magic Packet Generation from BPF Filters

🛡️ Cloudflare demonstrates an automated method to reverse-engineer classic BPF socket filters and generate the exact “magic” packets that trigger stealthy Linux backdoors. By combining symbolic execution with the Z3 theorem prover and translating the resulting constraints into concrete byte values, the approach reduces manual analysis of complex BPF bytecode from hours or days to seconds. The team uses scapy to assemble crafted packets and has open-sourced the filterforge tool to accelerate threat research and detection.
read more →

Transparent COM Instrumentation for Malware Analysis

🔍 Cisco Talos introduces DispatchLogger, an open-source DLL that transparently instruments late-bound COM (IDispatch) interactions to enhance malware analysis visibility. The tool hooks COM instantiation APIs and returns proxy objects that forward calls while logging method names, parameters, return values, and object relationships. It supports recursive wrapping, enumerator proxies, and moniker handling to reveal high-level automation events often missed by low-level API tracing. Deployment requires injecting the DLL into target processes and preserves COM lifetime and threading semantics.
read more →

Threatsday Bulletin: Speed, Deception, and New Vectors

🔔 Recent signals show attackers moving faster and hiding in plain sight. Kali Linux added an integration with Anthropic's Claude via the Model Context Protocol to translate natural-language prompts into technical commands, enabling AI-assisted command execution in a red‑team distro. Censys analyzed ResidentBat, an Android spyware implant used for mass surveillance that exfiltrates audio, messages and files. Alongside Bitpanda-themed phishing, ClickFix-based macOS stealers, ActiveMQ-enabled LockBit intrusions and a widespread WinRAR patch lag, these developments underscore shrinking breakout times, improved cloaking and persistent patching gaps that defenders must address.
read more →

CISA Updates RESURGE Malware Analysis, Highlights Stealth

🔒 CISA released an updated Malware Analysis Report detailing new findings on RESURGE, a sophisticated implant that exploits vulnerabilities to establish covert SSH-based command-and-control access. The update shows advanced network-level evasion, forged TLS certificates, and authentication techniques that allow RESURGE to remain dormant on Ivanti Connect Secure devices until an operator connects, evading routine scans. CISA publishes IOCs, detection signatures, and directs use of mitigation guidance for CVE-2025-0282 to aid defenders.
read more →