Community links 🔗✨ Telegram Group: t.me/HyperDbg Discord Server: discord.gg/anSPsGUtzN Matrix Group: matrix.to/#/#hyperdbg-discus… Mastodon: infosec.exchange/@hyperdbg

ALT Simpsons Homer GIF

1
1
11
7,042
It's been a while since we passed 4K GitHub stars ⭐️ And more good news: HyperDbg's kernel-mode drivers now build on #Linux! 🐧 After successfully getting the user-mode components compiled, thanks to @MaxRaulea, we're now moving on to... github.com/HyperDbg/HyperDbg…
Made with AI
1
6
39
1,787
... debugging, implementing, and testing cross-platform functionality. Step by step, we’re getting closer to running HyperDbg on Linux! 🐧🐧🐧
3
189
HyperDbg retweeted
This one is really crazy. They're spreading malware disguised as a hypervisor debugger through a vibe-coded website, vt01[.]com. If you download it, it's malware. The sad part is that they're comparing it with @HyperDbg. 👀
> be me > get dm > its my friend @Intel80x86 > author of @HyperDbg > wtf i love him > open message > "smelly i got goop" > wtf i love goop > "i found malware campaign" > wtf i love malware campaigns > "The Threat Actor(s) have created a website which is specifically tailored to malware analysts, or reverse engineers, who utilize hypervisor-based frameworks. Their malware campaign appears to have begun about 8 days ago. I became aware of the issue when their "product" compared themselves to HyperDbg. Their website is clearly vibe coded, however parts appear to be in Mandarin" > wtf theyre targeting people who like goop > sends url to website > vt01[.]com > look inside > lol ai slop > go to download page > vt01[.]com/en/download > immediately flagged as malware by firefox > allow download plz > split nanosecond touches the disk > windows: OMFG MALWARE!!! > ??? this malware STINKS > sha256: 5934d1a64afd62e7d1badb81e8613e01efe9cf9c7d6748271c6d0761e3b11eb7 > look inside > delphi, weird PE sections > throw into triage > YARA rules IMMEDIATELY identify the malware family > XRed > wtf is XRed? > cant remember any family named XRed > December, 2025: XRed impersonates Indian Ministry of Finance and Income Tax Department > December, 2025: XRed targets US and UK companies that do business in India > March, 2025: XRed targets manufacturing companies in the United Kingdom > May, 2025: Threat Actors compromise ProColored, their driver update was compromised to push XRed > July, 2025: Threat Actors compromise video game mouse company, push malware to video game players who use EndGame Gear for gaming this is strange goop
6
22
3,136
HyperDbg retweeted
> be me > get dm > its my friend @Intel80x86 > author of @HyperDbg > wtf i love him > open message > "smelly i got goop" > wtf i love goop > "i found malware campaign" > wtf i love malware campaigns > "The Threat Actor(s) have created a website which is specifically tailored to malware analysts, or reverse engineers, who utilize hypervisor-based frameworks. Their malware campaign appears to have begun about 8 days ago. I became aware of the issue when their "product" compared themselves to HyperDbg. Their website is clearly vibe coded, however parts appear to be in Mandarin" > wtf theyre targeting people who like goop > sends url to website > vt01[.]com > look inside > lol ai slop > go to download page > vt01[.]com/en/download > immediately flagged as malware by firefox > allow download plz > split nanosecond touches the disk > windows: OMFG MALWARE!!! > ??? this malware STINKS > sha256: 5934d1a64afd62e7d1badb81e8613e01efe9cf9c7d6748271c6d0761e3b11eb7 > look inside > delphi, weird PE sections > throw into triage > YARA rules IMMEDIATELY identify the malware family > XRed > wtf is XRed? > cant remember any family named XRed > December, 2025: XRed impersonates Indian Ministry of Finance and Income Tax Department > December, 2025: XRed targets US and UK companies that do business in India > March, 2025: XRed targets manufacturing companies in the United Kingdom > May, 2025: Threat Actors compromise ProColored, their driver update was compromised to push XRed > July, 2025: Threat Actors compromise video game mouse company, push malware to video game players who use EndGame Gear for gaming this is strange goop
24
33
1,056
37,213
HyperDbg v0.23 is released!💫 This release adds support for floating-point variables in the script engine & introduces the new 'ucpuid' command, which displays selected CPUID leaves, interprets and maps them to the processor-defined flags. Check it out: github.com/HyperDbg/HyperDbg…
1
8
19
1,837
This version also brings Linux support for compiling user-mode code. Alongside these new features, this release includes numerous bug fixes and code quality improvements. Happy debugging! 🌺🌼🌻
1
5
301
Major milestone in bringing HyperDbg to Linux! 🐧 Huge thanks to @MaxRaulea, all HyperDbg user-mode modules now compile on Linux. 🎉🪐💫 Next step is porting the kernel modules...
6
19
1,796
HyperDbg v0.22 is released! 💫 Apart from bringing bug fixes, major progress toward porting HyperDbg for #Linux, HyperDbg now supports structures in the script engine. This version also introduces new commands to display linked lists. Check it out: github.com/HyperDbg/HyperDbg…
1
3
12
1,234
Need to debug interrupts, faults, or exceptions? HyperDbg has plenty of commands to help! Use `!exception` to intercept exceptions (the first 32 entries of the IDT) and `!interrupt` to intercept interrupts (IDT entries 32–255). (1/4)
1
2
14
1,490
If you want to create (inject) artificial interrupts, HyperDbg provides a variety of functions for that as well. Check it out: (3/4)
1
3
300
HyperDbg retweeted
A list hook like this is a reminder of how much deep knowledge modern systems demand. It demands a solid understanding of: >CPU architecture and privileged instructions >Paging and EPT >VMX/VT-x and the VMCS >Windows kernel internals >Exception handling and interrupt delivery
5
26
1,873
HyperDbg !epthook command can be used inside Hyper-V Windows Server 2025 VM. (Testing patches)
5
40
2,554
HyperDbg retweeted
Part 4 of the hypervisor based game cheat series is up. This part gets into why hypervisor based game cheats are hard in practice. What has to stay current across per vCPU VMCS and VMCB state. Why SMP turns a clean demo into a distributed state problem. How EPT and NPT views go stale across TLBs, VPID, ASID, PCID, and sibling cores. Why interrupts, APIC, AVIC, SynIC, posted interrupts, timers, MSR bitmaps, debug state, PMU state, and branch tracing all become part of the cheat mechanics. Also touched on nested Hyper-V, VBS, VTL, HVCI, SEV-SNP, and TDX as boundary lessons. No actual cheat code. The point is to understand what a hypervisor based cheat would need the machine to keep coherent before any game-facing feature can work. As always, really really grateful to @Intel80x86 @HyperDbg for the great HyperDbg work on hardware assisted debugging, EPT hidden hooks, transparent memory hooks, and monitor style tracing. Also grateful to memN0ps, DarthTon, Gbps, jonomango, Panicos Karkallis, Jorge Blasco Alis, and the researchers behind HECKLER, WeSee, RMPocalypse, and Fabricked for the excellent public work that helped shape this part. Couldn’t tag everyone without knowing all of their X accounts. My apologies. 🙏 Give it a light read if this area is interesting. If anything looks wrong, feedback is always welcome. 😇 kernullist.github.io/kernull…
15
65
3,296