Someone pointed out to me that the full infection chain is outlined in this article from @_CPResearch_
(I am not sure it's the same malware, but it does sound like it)
research.checkpoint.com/2026…
BlueMoon exploit kit allows to infect systems if a user opens a link via Chrome or Chromium based browsers via v8 sandbox escape and RCE on Windows.
proofpoint.com/us/blog/threa…
We are pleased to release tmp.0ut 5 Volume!
Get your viruses, rootkits, strange ELFs, weird machines, tiny files, cool art, and phresh beats here!!
tmpout.sh/5/
ALT tmp.0ut 5 Table of Contents - ANSI art featuring a list of 21 papers
When RE’ing #malware with LLMs, have the LLM also write helper scripts (string/payload decrypters and config extractors) and run these manually on the malware binaries. These make it much easier to validate the LLM's RE quickly and can help expose hallucinations.
Blog: "Bad advice and myths around malware prevention"
If you ever heard or said "visiting websites can't infect you", "PDFs aren't malicious" or "exploits are rare and always targeted" this article might be for you.
blog.gdatasoftware.com/2026/…#GDATATechBlog#GDATA
Do you remember the BlockBlasters Steam game that was used to steal from a man with cancer?
FBI arrested the threat actor
techspot.com/news/113163-fbi…
I asked a clanker to make me a prompt that I can use to generate images of malware, like literal pictures that represent malware such as the ones used in samplepedia, not PE images.
I got a warning for cyber abuse with threats to shut down my account o.O
I published an API tracer for kernel mode drivers using speakeasy emulation
AI notice: It's vibe-coded.
I manually analyzed ~20 drivers to verify and improve the output and tested with a corpus of ~100 drivers.
github.com/struppigel/hedgeh…
This seems to be a prevalent issue now: People vibe code security applications and the LLM generates real malware for testing.
The generated test files rely on real threat actor infrastructure to download or exfiltrate.
hxxps://github.com/DataDog/guarddog/blob/main/tests
Look like the dev told an LLM to generate test files for a Shai Hulud detection app.
The LLM complied and generated malicious test files.
github.com/Cobenian/shai-hul…