First time experimenting with entirely local LLM's and reverse engineering work, and fairly impressed with the initial results.
Qwen3.8-Flash-Next (@MiaAI_lab's recent Tensorfold recipe) and the @malcat4ever MCP made short work (~2 minutes on a DGX spark) of an old CS shellcode without any skills or specific prompting.
The sample is admittedly simple, and frontier models handle it with ease, though seeing this all driven entirely locally is a cool experience.
More to come as I work out which harnesses, model recipes and MCP's work best for this kind of thing.
Good writeup. This looks like CNCMachineRMS RAT delivered via the BabaDeda crypter - SmartApeSG has been using the same crypter since at least Dec 2024, back then they were dropping Zebloader with it.
Also sharing a config extractor for CNCMachineRMS 🙂
github.com/pandare9x/Configu…
New: Attackers are abusing ChatGPT's Custom GPT feature, luring victims in w/ the legit ChatGPT domain and then directing them to a ClickFix attack that:
→Installs a malicious MSI
→Uses DLL sideloading
→Drops a RAT
More from @JSemonSecurity@the_MarkOH: huntress.com/blog/chatgpt-cu…
My new cheat sheet is out! This one helps malware analysts incorporate AI agents into their workflows, including how to spot an agent reporting a timed-out tool as having found nothing.
We are now seeing version 4.3.8-alpha2 of ACRStealer: 64773e9b66825e3e3d653b730f2994eac6635d8166707d076371bb2ff2f7f434
C2: sync[.]canyonmere[.]cc
Botnet: f1575b64-8492-4e8b-b102-4d26e8c70371
🦠ACRStealer remains under active development, with new versions appearing almost weekly. The latest variant by identified by ThreatLabz is 4.3.7-alpha2.
IOCS are listed below.
SHA256 hash:
769d06b54576c6beab2d33c7d4c05b679156c051652a843d6cc61de2cc9c58f9
CNCs:
https://stream[.]echovale[.]cc
https://145[.]249.109.147
DDR: https://telegra[.]ph/C-Introduction-08-21
🚨 #SmartLoader delivers additional payloads while gathering system information, establishing persistence, and maintaining C2 communication on compromised Windows systems.
👨💻 Explore how to detect and reduce your exposure: any.run/malware-trends/smart…
⚠️ Malware pressure increased across the threat landscape last week, with RATs, stealers, and loaders all gaining activity at the same time. #AsyncRAT climbed 35%, while #Quasar, #DonutLoader, and #Lumma saw even sharper growth.
📌 Trend to watch: broad growth across established threats can increase investigation pressure across multiple threat types at once. SOC teams may need to rebalance detection and triage priorities as volumes rise.
Monitor the malware driving today’s attacks: any.run/malware-trends/?utm_…#Top10Malware
🏁 We’re off to the races.
The Threat Hunting Labs competition runs September 25–27, 2026.
⏱️ You’ve got 4 hours.
🔎 Follow the evidence.
🎯 Make every query count.
Good luck to everyone competing. Let the hunt begin! 🔥
** PS: You can still register for the competition until 4 hours before the event ends - threathuntinglabs.com/compet…
If you are doing #FlareOn this year and want to rank yourself against other 𝗵𝘂𝗺𝗮𝗻𝘀 we made an unofficial leaderboard. Honour system only, but it's something.
❗️ Across five key US industries, leading phishing threats target auth sessions & access tokens.
Email is just the start: links, redirects, archives, PDFs, post-click activity create visibility gaps for SOCs.
Explore 2026 data & mitigation strategies: any.run/cybersecurity-blog/p…
Did you know that if you run Cowrie high interaction SSH and Telnet honeypot 🍯🐝, you can automatically submit malicious URLs caught by it to URLhaus 💡? If you aren't running a Cowrie honeypot yet, you may want to check it out:
Project website:
🖥️ cowrie.org/
GitHub repository:
🖱️ github.com/cowrie/cowrie
Malicious URLs caught by Cowrie honeypots:
🌐 urlhaus.abuse.ch/browse/tag/…