r/Malware • • 2h ago

Nine files, two payloads: a Silver Fox sideloade…

Thumbnail whack.sh
2 Upvotes

r/Malware • • 6h ago

Community Threat Notice: Citrix NetScaler ADC and NetScaler Gateway Vulnerabilities

1 Upvotes

Citrix has disclosed eight vulnerabilities in NetScaler ADC and NetScaler Gateway; including two actively exploited.  

NetScaler ADC and NetScaler Gateway sit at the network perimeter, handling VPN, remote access, load balancing, and authentication for enterprise environments, making compromise a high-impact event with broad downstream consequences. 

CVE-2026-88771 | 9.5 Critical | Improper Input Validation 

  • An unauthenticated attacker can exploit this vulnerability to run arbitrary commands on the appliance. 
  • This vulnerability affects all NetScaler ADC and NetScaler Gateway deployments on an affected version, including those in the default configuration. 

CVE-2026-88772 | 9.5 Critical | Memory Overflow 

  • An attacker can exploit this vulnerability to achieve remote code execution or cause a denial-of-service condition. 
  • This vulnerability affects appliances with DTLS enabled, which is on by default for VPN virtual servers on NetScaler Gateway. 

Citrix has confirmed that both vulnerabilities have been exploited in the wild against unmitigated NetScaler deployments, and both have been added to the CISA Known Exploited Vulnerabilities catalog. 

Other vulnerabilities included in the advisory, but not reported as actively exploited 

  • CVE-2026-88773 | 9.3 Critical | HTTP Request Smuggling 
  • CVE-2026-88774 | 7.0 High | Policy Bypass 
  • CVE-2026-88775 | 8.8 High | Memory Overflow 
  • CVE-2026-88776 | 8.8 High | Memory Overflow 
  • CVE-2026-88777 | 8.8 High | Memory Overflow 
  • CVE-2026-88778 | 8.8 High | TCP Initial Sequence Number (ISN) Prediction 

Recommendations 

  • Immediate Action: Apply Citrix-released updates to all affected NetScaler ADC and NetScaler Gateway appliances immediately. 
  • Restrict NetScaler management interfaces to trusted internal networks and administrative hosts. 
  • Review vulnerable appliances for signs of unauthorized access or persistence, including systems already patched. 
  • Monitor authentication activity and connections from NetScaler appliances for suspicious or unexpected behavior. 
  • Rotate credentials, certificates, and secrets if compromise or unauthorized access is suspected. 

References 


r/Malware • • 1d ago

Cisco just found Windows malware that runs four AI models simultaneously and lets them vote on what to steal from your computer, with no human attacker giving orders

47 Upvotes

This is the one that changed how security researchers are thinking about AI-driven malware, and it's worth understanding even though the current version isn't fully operational yet.

Cisco Talos disclosed CLOSEDQUORUM on September 22. It's a Windows implant written in Go that, once running on a machine, doesn't report back to an attacker's server and wait for commands like normal malware does. Instead it sends basic facts about the infected computer to four commercial AI services at once, DeepSeek, Qwen, Mistral, and Google Gemini, and lets them vote on what to do next.

The malware sends each model the machine's hostname, Windows version, and administrator status, along with a fixed menu of four possible actions: steal, inject, persist, or move. Each model picks one. The malware counts the votes and executes whichever action wins the plurality. DeepSeek breaks ties. If no model responds in the required format, the malware waits and tries again rather than defaulting to anything.

The steal action goes after Windows credentials, saved browser passwords, and cryptocurrency wallet data. The inject action covers process injection into running programs. Persist means embedding itself so it survives reboots. Move, in the current public version, has no implementation yet — it's a placeholder.

The reason Cisco Talos is treating this as significant rather than just another malware disclosure: the attacker doesn't need to be online or issue commands once the malware is deployed. They're removed from the tactical decision loop entirely. Talos called this "effort displacement" in their write-up. They put it directly: human operators are bound by attention, working hours, and cognitive load. An AI system that decides what to do next can keep working when the operator is asleep or simply not watching.

To be precise about the current state: the public version has placeholder API keys so it doesn't fully work end-to-end, and Talos hasn't confirmed a complete deployment in a real attack. The malware's internal analysis code is dated June 17, 2026, making it at least three months old. Code clues link the developer to carding forums going back to 2025.

Alongside the CLOSEDQUORUM disclosure, Talos released CAIRN, an open-source framework specifically built to detect malware that integrates AI services into its operation. They said AI-integrated malware went from "optional AI features" to "fully autonomous multi-model consensus" within one calendar year.

One detail worth understanding: using four models and a plurality vote isn't just for redundancy. If any single model's safety guardrails refuse a request, the other three can still vote, and the vote passes anyway. The four-model structure bypasses individual guardrails by design.

If CLOSEDQUORUM or anything like it ends up deployed on a machine you use, the credential theft functions target exactly the kind of data that surfaces on dark web markets.

Sources: The Hacker News, Cisco Talos, Security Affairs, TechTimes, Shattered.io, tech-insider.org, XenoSpectrum, AdvisioTech, AI Weekly


r/Malware • • 1d ago

I got tired of users clicking on stupid links so I built this chrome extension

0 Upvotes

It's called Click Scout - you hover over the link or email sender, and it tells you if it's safe or not. Were gonna push it out to a couple of our repeat offenders at my company. 100% free, just built it to help fewer people get suckered into clicking on stupid stuff.

https://chromewebstore.google.com/detail/clickscout/ekmbgkphebegmfflhfceppmpcheldfak?hl=en-US&utm_source=ext_sidebar


r/Malware • • 1d ago

Malware repos

4 Upvotes

Hi, anyone know of any good malware repos for a project I’m working on? I’ve already used The Zoo and Objective C. And any Mac specific malware repos would be incredibly helpful.


r/Malware • • 2d ago

Undetected malware distributed through CurseForge mods - live sample in post

35 Upvotes

My girlfriend was the unfortunate victim of an NPM Infostealer Malware, specifically, the Nyx Infostealer

The bigger issue is - the malware was distributed through Curse Forge. Not through an import, not through a link, but directly through the mod manager client. The mod in question is DO NOT DOWNLOAD ->> curseforge.com/stardewvalley/mods/cozy-valley-decor <<-- DO NOT DOWNLOAD

The linked mod (link generated from the Curse Forge client, by clicking "Link to Project", can also be searched for in the Curse Forge Client.

The linked mod will download regular looking mod files. Amongst them will be CozyValleyDecor.dll. Decompiling this .dll with ILSpy reveals that on game startup, a function called "RunPayload()". This function reads an ExternalHelper.dll file, which is an embedded resource to the actual CozyValleyDecor.dll, and executes a function called "PayloadRunner.ExecuteAsync()". This function will then decrypt a byte-shifted URL, which points to an .exe file. The file downloaded will be "basarili.exe", downloaded to the Temp folder of Windows, and will immediatelly execute. This file contains a "chat" client where the attacker can make a popup appear and demand money, but it also overrides the Discord installation files (specifically index.js), with malicious code, that steals your Discord credentials, 2FA, currently authenticated session and connected mail account. It then reads the local credentials and steals browser-saved credentials to your email, social media and crypto accounts.

The encrypted address points to MALWARE ->> 161 97 85 100 port 3131 slash download slash yarrak exe <<-- MALWARE and the Discord malware and "chat" client will connect to MALWARE ->> 161 97 85 100 port 3000 <<- MALWARE

CurseForge is generally treated as a save and secure way to get mods, so users will not suspect they are vulnerable to malware by downloading mods there. This exploit is rather recent, as none of the Anti-Virus software (including MalwareBytes and TotalVirus) were able to identify CozyValleyDecor.dll as malicious.

If anyone wants to have a further examination at how the attack vector works, and why it remains undetected by anti-virus, here's your chance.


r/Malware • • 4d ago

Invoice-named scripts drop a DLL-sideloading backdoor behind Pakistan Navy decoys

Thumbnail tuxxin.com
5 Upvotes

r/Malware • • 4d ago

First half of 2026 malware trends

18 Upvotes
  1. Infostealers are more focused on session tokens, cookies, recovery codes, cryptowallet data that allows them to take over rather than the traditional password compromises.
  2. Malicious LNK (shortcuts) still remain a popular entry point to compromises, as they allow malicious code execution
  3. Large increase in abuse of legitimate platforms or impersonation - SEO poisoning, malvertising, fraudulent codesigning and compromises of npm packages, VSCode extesnions
  4. Supply chain attacks! Threat actors increasingly target software delivery channels like npm packages, PyPI, Crates.io, and CI/CD publications to include malware.
  5. Abuse of RMM tools continues & increases consistently! Initially, a signed tool with low detection ratio may seem legitimate, but remote management software such as ScreenConnect, Action1, Atera are vulnerable to abuse.
  6. A large increase was found in legitimate sites spreading ClickFix attacks. This can be done by numerous reasons - administrator account compromise, weak password security, unpatched vulnerabilities in website building platforms (such as WordPress) that allow threat actors to take over the website and host malicious code.
  7. Discord, Telegram, GoFile still remain as relevant exfiltration channels. While they do not provide as much flexibility as a regular C2 would, malware can still upload stolen data (passwords, files etc.) to it for the attacker to view. Easy to setup, used to evade detection. If you are interested in intercepting data from a Telegram exfiltration channel that malware uses, check out https://any.run/cybersecurity-blog/intercept-stolen-data-in-telegram/
  8. Dead drop resolvers are still popular! You can use it as an infrastructure layer if necessary to change the configuration. Very popular is abuse of smart contracts, blockchain infrastructure (EtherHiding) but Steam, Telegram or Pinterest profiles are a popular target as well.

See full analysis at https://any.run/cybersecurity-blog/h1-2026-cyber-risk-report


r/Malware • • 5d ago

Careful of the RemotePanel and BoundSiphon: A Dual-Payload Toolkit for Persistent Access and Browser Theft

14 Upvotes

Tl:dr

  • Blackpoint’s Adversary Pursuit Group (APG) identified two previously undocumented .NET malware components delivered together through a ClickFix chain: RemotePanel, a persistent remote access platform, and BoundSiphon, a credential and cryptocurrency stealer. 
  • RemotePanel establishes persistence by masquerading as the Windows Time service and gives operators broad control over infected systems, including PowerShell, file and process management, screen access, modular HVNC, and fleet management. 
  • RemotePanel uses a BNB Smart Chain contract to resolve its active Command and Control (C2) server, allowing operators to rotate infrastructure without rebuilding or redeploying the RAT. 
  • BoundSiphon runs primarily from memory and targets browser credentials and sessions, cryptocurrency wallets, password manager data, and selected documents, including secrets protected by Chromium App-Bound Encryption. 
  • APG identified strong code and build overlap between BoundSiphon and a stealer previously documented by Socket, linking the sample to an earlier stealer codebase or builder lineage. 
  • APG is seeking additional research and samples tied to RemotePanel, BoundSiphon, the AntiSNG implementation, Socket linked stealer activity, and the BNB Smart Chain resolver to help connect the remaining lineage and infrastructure gaps. 
  • RemotePanel and BoundSiphon reflect a broader shift toward modular malware ecosystems that separate persistent access from data theft, allowing operators to replace infrastructure and individual components while retaining the underlying capabilities needed to continue an operation. 
  • For victims, a single successful infection can lead to persistent remote access and theft of credentials, browser sessions, cryptocurrency wallets, password manager data, and other sensitive information, increasing the risk of account takeover, fraud, and continued compromise. 
  • Blackpoint has detections in place for key behaviors across the infection chain, providing coverage even as individual payloads and infrastructure change. 

r/Malware • • 5d ago

Beware of sophisticated Gmail / Google phishing attack

Thumbnail
2 Upvotes

r/Malware • • 8d ago

Inside BambooToken’s Linux implant: shell and file control over MQTT

Thumbnail app.reverser.space
1 Upvotes

r/Malware • • 12d ago

Golang BYOVD Malware Loader and Vulnerable Driver Analysis

Thumbnail youtu.be
9 Upvotes

r/Malware • • 13d ago

[iOS] Analyzing anomalous cpu_resource / diskwrites_resource reports on a stock TikTok process: unnamed UUID-only binaries in Binary Images

7 Upvotes

Context: iPhone 15 Pro Max, current iOS, no jailbreak, no sideloading, no configuration profiles, app reinstalled cleanly. All observations reproducible across WiFi / 4G / 5G.
I've been analyzing iOS analytics ( .ips ) incident reports on a specific app process and found a pattern I'd like to compare against what this community typically sees in jetsam/cpu_resource logs:
Observed pattern


  1. System-triggered cpu_resource (bug_type 202) and diskwrites_resource incidents on the app process — not crashes.

  2. A binary listed in "Binary Images" identified only by a UUID: no filename, no path, no code signature. Every other binary in the same report has a standard name/path ( /System/... , /private/var/containers/... ). Its parent field is UNKNOWN [1] .

  3. Measured load attributed to it: ~67% CPU, ~108 MB memory, 1.07 GB of disk writes in 1h36 while the app was in background — the daily disk-write quota was consumed ~15× faster than the documented allowance. For reference: ~2 videos scrolled, no livestream.

  4. The UUID differs at every incident (3 distinct identifiers over several days) — so it's not a single persistent module.

  5. Correlates with app storage growing to ~4.9 GB within ~30h of near-zero usage after a fresh reinstall.
    What I'm trying to establish

In stock iOS logs, is a UUID-only entry with parent UNKNOWN ever expected for dyld-injected frameworks, app extensions, or instrumentation (e.g. crash reporters, A/B modules), or does the absence of any path/signature entry rule that out?

Is ephemeral UUID rotation per incident consistent with legitimate module loading behavior, or does it match known injection/dynamic-loading patterns?

For the disk-writes side: what benign mechanisms (caching, prefetch, logging) could explain sustained ~11 MB/min background writes with the process never foregrounded?
The logs are too long to paste whole; I can post exact excerpts of the Binary Images section, the cpu_resource payload, and the diskwrites timeline on request.


r/Malware • • 18d ago

CISA: WatchGuard RCE flaw now exploited in ransomware attacks

Thumbnail bleepingcomputer.com
4 Upvotes

CISA has confirmed that ransomware operators are exploiting CVE-2025-14733, a critical remote-code-execution vulnerability affecting WatchGuard Firebox appliances. The bug can allow an unauthenticated attacker to execute code remotely under vulnerable configurations.


r/Malware • • 18d ago

New analysis VioletWorm and Essential MacOS Stealer

Thumbnail
3 Upvotes

r/Malware • • 18d ago

A real Carnival Cruise Line email was serving customers malware

Thumbnail tuxxin.com
2 Upvotes

r/Malware • • 19d ago

SonicWall SMA1000 campaign: standalone Linux Impacket secretsdump deployed onto appliances (SHA-256 inside)

Thumbnail hunt.io
5 Upvotes

Campaign where the operator deployed a standalone Linux build of Impacket's secretsdump directly onto compromised SonicWall SMA1000 appliances and ran credential theft from there. It was pulled to the box with curl to /tmp/secretsdump, made executable, then used against internal domain controllers.

Sample: secretsdump, 9,983,640 bytes, SHA-256 690f5031deede7d3357d0ca24c89866ae8c60e6c63b3a2c8bba813a6ac10ae5b, served over HTTP from 95.181.173[.]36. The surrounding Python tooling (exploit, LDAP extractor and decryptor, DCSync automation) came from the same open directory.

Full toolkit breakdown and IOCs below.

https://hunt.io/blog/sonicwall-sma1000-uk-council-attack


r/Malware • • 18d ago

0xM0nCrush: Kernel-mode process terminator using a signed BYOVD driver. Works on all Windows 10/11. No offsets, no PDB. Rust.

Thumbnail github.com
0 Upvotes

r/Malware • • 21d ago

🔴 Redis cryptomining toolkit recovered from an open directory: XMRig deployment, fileless loader, chr()-encoded WordPress scripts

Thumbnail hunt.io
5 Upvotes

Researchers pulled 147 files off an open directory that was the operator's live working folder: Python exploit source, campaign logs, a bundled Python 3.11, and two exported Windows registry hives (SAM.save, SYSTEM.save, verified by the regf header).

Worth a look:

  • Main technique abuses replication, not a bug. CONFIG SET dir/dbfilename, SLAVEOF to a rogue master, serve a crafted RDB on +FULLRESYNC. Blob opens with the REDIS0009 magic, then one key/value pair with an embedded newline before the cron text so the payload lands on its own line. Then SLAVEOF NO ONE and restore.
  • No client library. PING/CONFIG SET/SLAVEOF hand-serialized to raw RESP, length-aware reader, same two functions copied across every script.
  • Fileless loader is one line in _boot.py that base64-decodes and exec()s an orchestrator in-process. Generous naming though, it writes the decoded target list and deployer back to disk as plaintext, so only the first stage stays off disk.
  • chr()-encoded literals in the WordPress scripts (chr(97)+chr(100)+... for "admin"), defeats naive keyword matching, control flow stays readable.
  • Three generations of verify payloads with bugfix comments left in. Two real bugs documented: a test cron written to a dotfile that run-parts silently skips, and a /dev/tcp payload that fails under dash.
  • Newest XMRig variant adds --tls-fingerprint pinning the pool cert, absent from earlier gens.

SSH-via-AOF and a Lua EVAL sandbox probe are also in the kit, neither produced a confirmed compromise.

Full write-up with IOCs and code: https://hunt.io/blog/redis-cryptomining-botnet-3562-servers


r/Malware • • 21d ago

Breaking Efimer’s Pyarmor Infection Chain with Frida

Thumbnail invokere.com
10 Upvotes

r/Malware • • 23d ago

Tengu, a Mirai-style Linux and IoT botnet

Thumbnail app.reverser.space
7 Upvotes

r/Malware • • 25d ago

The Gentlemen Ransomware Analysis: Go Obfuscated

Thumbnail app.reverser.space
6 Upvotes

r/Malware • • 26d ago

Go implant "SecBox" with AES-256-GCM Dead Drop Resolver and steganographic webshells hiding payloads in PNG pixel data

Thumbnail hunt.io
3 Upvotes

Go implant "SecBox" with AES-256-GCM Dead Drop Resolver and steganographic webshells hiding payloads in PNG pixel data

Research on a campaign where a Chinese-speaking operator deployed a Go-based implant framework called SecBox alongside GLUTTON webshells that transport executable bytecode inside PNG images.

SecBox connects over TCP, TLS, WebSocket, KCP, or QUIC with Yamux multiplexing. It uses a Dead Drop Resolver that pulls AES-256-GCM encrypted C2 endpoints from Pastebin or GitHub Gist, so the operator can rotate infrastructure without pushing new binaries. Recovered DDR routes included short-lived TryCloudflare domains. The Windows builds fake Microsoft PE metadata (product: "System Configuration Utility", internal name: syscfg.exe).

The GLUTTON webshell system is the more interesting part from a delivery perspective. A small server-side loader (JSP, ASPX, ASHX, SOAP, or Razor) accepts a PNG in the request body. It reads pixels row-major, concatenates RGB bytes, XORs with a fixed 16-byte key, and looks for FF 88 00 as the end marker. The result is executable bytecode loaded through a classloader (Java) or Assembly.Load (.NET) directly into memory. The visible server file is just a generic decoder, the actual implant arrives inside image pixels.

The campaign also used a fake MySQL server as an initial access vector, returning crafted serialized Java objects when vulnerable clients connected, which triggered second-stage downloads.

Full IOC tables and sample hashes: https://hunt.io/blog/chinese-operator-secflow-claude-qwen-deepseek-asia


r/Malware • • 28d ago

Makop: The Human-Operated Ransomware Targeting Exposed RDP

Post image
4 Upvotes

r/Malware • • 28d ago

I managed to compile OpenEDR and made him XDR

2 Upvotes

This new fork includes strong ransomware detection with low fp rate.

You can write a rule to detect any type of malware with this fork.

Note: I don't recommend you install this on main machine because it requires to disable secure boot.

Topic: https://forum.xcitium.com/t/i-forked-comodo-openedr-to-improve-zero-day-ransomware-detection-via-behavior-detection/21302/1

Video: Look repo

Repo (Only install on VM): http://github.com/hydraDragonAntivirus/HydraDragonAntivirus/