Advertisement
Polymorphic Phishing Page Analysis: JavaScript Obfuscation Flaws
Analysis of a polymorphic phishing page utilizing heavy JavaScript obfuscation and variable scope bugs that cause browser loops.
State of AI-Enabled Malware: Real-World Impact and Defenses
Unit 42 reports AI-enabled malware is primarily proof-of-concept, with minimal operational activity. Existing defenses effectively detect current threats.
AI-Powered Malware Analysis: Detecting Persistent Threats on Sensors
An analysis using Gemma4 with Ollama reveals high-volume malware downloads on DShield sensors, indicating persistent actor activity and critical compromise risks.
Recorded Future's Engine: Unifying Threat Intelligence Sources
Explore Recorded Future's unique collection engine, integrating technical, underground, and community intelligence for proactive threat defense and deeper insights.
Analyzing AutoIT Payload Injection Techniques in Modern Malware
Technical analysis of how threat actors use AutoIT scripts for process injection, leveraging memory management functions to execute malicious payloads in memory.
Dolphin X Malware: AI-Driven Target Prioritization & Defense
Analysis of Dolphin X, a new RAT utilizing AI to profile and rank victims, enabling threat actors to prioritize high-value targets for data exfiltration and further…
Advertisement
AI Models Fail at Nuclear Sabotage Malware Analysis Benchmark
New SentinelOne research reveals frontier AI models struggle with complex malware investigations, particularly those involving nuclear sabotage and industrial systems.
Ousaban Banking Trojan: Phishing Lures Target Iberian Bank Users
Ousaban, a Brazilian banking trojan, targets Windows users in Spain and Portugal via fake PDF phishing lures, aiming to steal financial credentials.
YARA-X 1.18.0 & 1.19.0 Release: Enhancing Malware Detection
YARA-X versions 1.18.0 and 1.19.0 bring key improvements and bug fixes, enhancing malware analysis and threat hunting capabilities for security professionals.
Malware Evades AI Analysis with 'Forbidden Text' Tactics
Threat actors embed 'forbidden' text in malware to confuse AI analysis tools, targeting bioinformatics and MCP developers.
MSI Malware Detection: Statistical Analysis for Base64 Payloads
Learn how to use statistical analysis to identify obfuscated Base64 payloads within malicious MSI files and improve your incident response capabilities.
Python-Based Infostealer Masked as PDF Targets Browser Credentials
Technical analysis of a PyInstaller-compiled infostealer using Discord webhooks to exfiltrate browser credentials, crypto wallets, and session tokens.
WordPress Sites Targeted by Malware Using Steam Profile Dead-Drops
Over 2,000 WordPress sites compromised in a campaign hiding C2 resolution data within Steam Community profiles. Technical breakdown of the evasion tactics.
NetSupport RAT Infection: How to Detect Unidentified Loader Exploits
Analyze the multi-stage infection chain of an unidentified loader delivering NetSupport RAT, featuring technical breakdowns of JavaScript and PowerShell TTPs.
Obfuscating Strings in C++ Implants: Detection and Analysis
Analyze how stack strings help malware authors evade static analysis. Explore the assembly-level mechanics and detection strategies for Windows implants.
Shai-Hulud Worm Code Leak: How Clones Threaten Developer Environments
The release of Shai-Hulud worm source code triggers a surge in self-replicating clones, targeting software developers and automated CI/CD pipelines.
Masjesu Botnet DDoS-for-Hire: Analysis of IoT Malware Campaigns
The Masjesu botnet targets IoT devices across multiple architectures to facilitate DDoS-for-hire services via Telegram, posing risks to global infrastructure.
Fileless Malware Registry Persistence Techniques Exposed
Analyzes how fileless malware leverages the Windows registry for persistence, minimizing filesystem footprint and complicating traditional detection.
PDF Incremental Updates: Detecting Hidden Malicious URLs
Discover how attackers use PDF incremental updates to obfuscate malicious URLs and learn forensic techniques to identify and extract hidden indicators.
GlassWorm Supply Chain Attack: 400+ Malicious Repos Identified
The GlassWorm campaign hits GitHub, npm, and VSCode marketplaces with over 400 malicious repositories. Learn to detect and mitigate this supply chain threat.
Analyzing Embedded ZIP Payloads in RTF Documents for Malware Analysis
Learn how to detect ZIP files in RTF documents and extract hex-encoded binary payloads using specialized forensic tools to identify hidden malware threats.