#malware hunter & analyst. Opinions are my own.

Cold country
ExecuteMalware retweeted
First time experimenting with entirely local LLM's and reverse engineering work, and fairly impressed with the initial results. Qwen3.8-Flash-Next (@MiaAI_lab's recent Tensorfold recipe) and the @malcat4ever MCP made short work (~2 minutes on a DGX spark) of an old CS shellcode without any skills or specific prompting. The sample is admittedly simple, and frontier models handle it with ease, though seeing this all driven entirely locally is a cool experience. More to come as I work out which harnesses, model recipes and MCP's work best for this kind of thing.
1
6
17
1,634
ExecuteMalware retweeted
Fresh #unknown #stealer: app.any.run/tasks/c46c99a4-8… 1eb51e82267b2ea1d3216919dbac9d5297ca8565baf8e39ccfc07323136b1849 C:\Users\lakup\Documents\dev_tools\LARP HERE\Studio\client.pdb
1
3
12
649
ExecuteMalware retweeted
Good writeup. This looks like CNCMachineRMS RAT delivered via the BabaDeda crypter - SmartApeSG has been using the same crypter since at least Dec 2024, back then they were dropping Zebloader with it. Also sharing a config extractor for CNCMachineRMS 🙂 github.com/pandare9x/Configu…
New: Attackers are abusing ChatGPT's Custom GPT feature, luring victims in w/ the legit ChatGPT domain and then directing them to a ClickFix attack that: →Installs a malicious MSI →Uses DLL sideloading →Drops a RAT More from @JSemonSecurity @the_MarkOH: huntress.com/blog/chatgpt-cu…
2
5
41
2,262
ExecuteMalware retweeted
My new cheat sheet is out! This one helps malware analysts incorporate AI agents into their workflows, including how to spot an agent reporting a timed-out tool as having found nothing.
2
21
90
7,430
ExecuteMalware retweeted
Phishing activity in the past 7 days 🐟 Track latest #phishing threats in TI Lookup: intelligence.any.run/analysi… #TopPhishingThreats
3
6
1,069
ExecuteMalware retweeted
Check out these new testamonials from students completing the Advanced Malware Binary Triage course! 🤩
4
9
598
ExecuteMalware retweeted
We are now seeing version 4.3.8-alpha2 of ACRStealer: 64773e9b66825e3e3d653b730f2994eac6635d8166707d076371bb2ff2f7f434 C2: sync[.]canyonmere[.]cc Botnet: f1575b64-8492-4e8b-b102-4d26e8c70371
🦠ACRStealer remains under active development, with new versions appearing almost weekly. The latest variant by identified by ThreatLabz is 4.3.7-alpha2. IOCS are listed below. SHA256 hash: 769d06b54576c6beab2d33c7d4c05b679156c051652a843d6cc61de2cc9c58f9 CNCs: https://stream[.]echovale[.]cc https://145[.]249.109.147 DDR: https://telegra[.]ph/C-Introduction-08-21
1
7
18
1,610
ExecuteMalware retweeted
For those looking at the ps1 this should help.
1
3
493
ExecuteMalware retweeted
#remcos #powershell (albeit broken) #opendir at: https://delphiaonline\.top c2 dmsi.duckdns\.org:14642 9d9f149a0052999587be2078375bb4530b351f3cda1b343c7f81a5d13b02ac45
1
3
15
1,978
ExecuteMalware retweeted
🚨 #SmartLoader delivers additional payloads while gathering system information, establishing persistence, and maintaining C2 communication on compromised Windows systems. 👨‍💻 Explore how to detect and reduce your exposure: any.run/malware-trends/smart…
3
12
1,184
ExecuteMalware retweeted
New blog: OpenSUpdater Hides in Recompiled 7zip SFX #GDATATechblog @GDATA blog.gdatasoftware.com/2026/…
1
12
50
2,667
ExecuteMalware retweeted
⚠️ Malware pressure increased across the threat landscape last week, with RATs, stealers, and loaders all gaining activity at the same time. #AsyncRAT climbed 35%, while #Quasar, #DonutLoader, and #Lumma saw even sharper growth. 📌 Trend to watch: broad growth across established threats can increase investigation pressure across multiple threat types at once. SOC teams may need to rebalance detection and triage priorities as volumes rise. Monitor the malware driving today’s attacks: any.run/malware-trends/?utm_… #Top10Malware
4
10
2,052
ExecuteMalware retweeted
🏁 We’re off to the races. The Threat Hunting Labs competition runs September 25–27, 2026. ⏱️ You’ve got 4 hours. 🔎 Follow the evidence. 🎯 Make every query count. Good luck to everyone competing. Let the hunt begin! 🔥 ** PS: You can still register for the competition until 4 hours before the event ends - threathuntinglabs.com/compet…
2
9
12
1,591
ExecuteMalware retweeted
If you are doing #FlareOn this year and want to rank yourself against other 𝗵𝘂𝗺𝗮𝗻𝘀 we made an unofficial leaderboard. Honour system only, but it's something.
3
25
153
10,076
ExecuteMalware retweeted
🚨 A widely used placeholder domain from developer docs third-party[.]com is now serving a #ClickFix lure targeting Windows users. See analysis and collect #IOCs: app.any.run/tasks/f325fdb1-9… 👨‍💻 We analyzed the malicious script chain after ClickFix execution: app.any.run/tasks/e88d420c-1… Attack chain: ClickFix ➡️ elxxvvx[.]xyz/i/ ➡️ PowerShell loader saved as $env:TEMP\runner.ps1 ➡️ 120MB+ archive ➡️ patched draw[.]io[.]exe Electron app ➡️ chimefusion[.]com/u/ ➡️ ~4MB payload ➡️ HijackLoader ➡️ 158.94.209[.]188[:]3333 💡 ClickFix IOCs: hxxps[:]//third-party[.]com/ hxxps[:]//rhodesquality[.]com/about-rhodes/ hxxps[:]//kayoanime[.]com/ #ExploreWithANYRUN
1
5
32
2,684
ExecuteMalware retweeted
#asyncrat #darkcrystal #opendir at: https://interactions-according-reports-syndication\.trycloudflare.com https://periods-genetic-stones-government\.trycloudflare.com
2
9
30
4,365
ExecuteMalware retweeted
❗️ Across five key US industries, leading phishing threats target auth sessions & access tokens. Email is just the start: links, redirects, archives, PDFs, post-click activity create visibility gaps for SOCs. Explore 2026 data & mitigation strategies: any.run/cybersecurity-blog/p…
3
8
1,113
ExecuteMalware retweeted
Did you know that if you run Cowrie high interaction SSH and Telnet honeypot 🍯🐝, you can automatically submit malicious URLs caught by it to URLhaus 💡? If you aren't running a Cowrie honeypot yet, you may want to check it out: Project website: 🖥️ cowrie.org/ GitHub repository: 🖱️ github.com/cowrie/cowrie Malicious URLs caught by Cowrie honeypots: 🌐 urlhaus.abuse.ch/browse/tag/…
7
7
1,752