Threats Tagged 'malware analysis'
View all threats tagged with 'malware analysis'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'malware analysis'
Click on any threat for detailed analysis and mitigation recommendations
The report details a malware attack on a large Polish organization involving fake CAPTCHA techniques. It describes the initial infection vector, where users were tricked into running malicious code through a Windows+R shortcut. The analysis covers two main malware families: Latrodectus (version 2.3) and Supper. The report provides technical details on the malware's functionality, communication protocols, and persistence mechanisms. It also includes indicators of compromise, such as C2 server IP addresses and file hashes. The authors emphasize the importance of employee education and monitoring for unusual events to mitigate such threats. Join the discussion | AlienVault OTX General | 02/19/2026, 15:26:28 UTC Added: 02/19/2026, 18:01:12 UTC |
This detailed technical analysis dissects the Vietnamese Stealer malware, a Python-based info stealer using Telegram as C2, employing DLL sideloading, multi-layer obfuscation, and anti-analysis techniques including taunts to security researchers. The report provides a chronological investigation with indicators of compromise, attack chain details, and attribution insights, valuable for defenders tracking Vietnamese threat actors and similar campaigns. Join the discussion | Community Curated | 01/26/2026, 08:18:39 UTC Added: 01/26/2026, 08:18:39 UTC |
This report describes how generative AI techniques were utilized to accelerate the reverse engineering of XLoader malware, specifically version 8.0. By combining cloud-based static analysis of IDA exported data with dynamic checks, researchers rapidly unpacked encrypted code, deobfuscated API calls, and decrypted strings and domain names. The analysis uncovered three distinct function encryption schemes and a complex domain generation algorithm used by XLoader. The AI-assisted approach significantly reduced analysis time from days to hours, enabling faster extraction of indicators of compromise (IoCs). Despite AI's assistance, human expertise remained essential for overcoming the most sophisticated protections. The report highlights that generative AI can serve as a force multiplier for malware analysis, though malware authors may adapt their techniques in response. The threat is assessed as medium severity, with no known exploits in the wild currently. Several IoCs including hashes and suspicious domains are provided for detection and blocking. Join the discussion | AlienVault OTX General | 11/03/2025, 14:28:33 UTC Added: 11/03/2025, 20:00:46 UTC |
This tutorial provides an in-depth analysis of a malware infection chain using shellcode generated by the Donut tool. It covers various stages of the attack, including initial download, trace concealment, and final payload delivery. The tutorial aims to familiarize readers with common analysis tools like dnSpy, IDA Pro, x64dbg, and ProcessHacker, while demonstrating both static and dynamic analysis techniques. It highlights malware behaviors such as dynamic API resolution, process injection, and AMSI bypassing. The excerpt focuses on analyzing an unknown function in the shellcode, explaining PC-relative addressing and position-independent code techniques used by malware to access resources. Join the discussion | AlienVault OTX General | 08/14/2025, 14:10:20 UTC Added: 08/14/2025, 15:32:50 UTC |
Showing 1 to 4 of 4 results