user avatar
Virus Bulletin
@virusbtn
Security information portal, testing and certification body. Organisers of the annual Virus Bulletin conference. @[email protected]
Oxfordshire, UK
Born July 1, 1989
Joined February 2010
  • Pinned
    user avatar
    📣 The VB2026 programme is live! Three days. Many voices. One Seville. 🇪🇸 Explore the sessions, speakers and ideas shaping this year’s event, and start planning your VB2026 experience. 📍 Seville, Spain 📅 14–16 October 2026 View the full programme 👉 virusbulletin.com/conference/vb2…
  • user avatar
    Check Point Research demonstrates how generative AI can speed up reverse engineering from days to hours by exporting IDA data to ChatGPT for deep static analysis. research.checkpoint.com/2025/generativ…
  • user avatar
    Sophos researchers discovered that attackers had booted their target computers into Safe Mode to execute the Avos Locker ransomware. The reason? Many, if not most, endpoint security products do not run in Safe Mode. news.sophos.com/en-us/2021/12/…
  • user avatar
    AT&T Alien Labs has recently discovered a cluster of Linux ELF executables with low rates of detection in VirusTotal. The files were identified as modifications of the open-source PRISM backdoor used by multiple threat actors in various campaigns. cybersecurity.att.com/blogs/labs-res…
  • user avatar
    The latest blog post from JPCERT/CC explains the details of, and countermeasures against, a new technique used in an attack that occurred in July, which bypasses detection by embedding a malicious Word file into a PDF file. blogs.jpcert.or.jp/en/2023/08/mal…
  • user avatar
    Hunt.io Threat Research details AdaptixC2, a lightweight open-source C2 with multi-protocol communication, advanced evasion, and BOF-based extensibility, confirming 102 active servers in the wild. hunt.io/blog/adaptixc2…
  • user avatar
    Unit 42 researchers look at the most commonly used TLDs in malicious domains. unit42.paloaltonetworks.com/top-level-doma…
  • user avatar
    Sophos lists details of attacker behaviour and impact as well as the tactics, techniques and procedures (TTPs) seen in the wild in 2020/2021. news.sophos.com/en-us/2021/05/…
  • user avatar
    Sophos analysts have uncovered a new ransomware that calls itself Epsilon Red. The ransomware is written in Go and is preceded by a set of unique PowerShell scripts that prepare the ground for the file-encryption routine. news.sophos.com/en-us/2021/05/…
  • user avatar
    Sophos has updated the story of the CVE-2021-40444 exploit, which triggers a Word document to deliver an infection without using macros. The attack was only successful on unpatched Windows systems. news.sophos.com/en-us/2021/12/…
  • user avatar
    Mandiant has published guidance for organizations on how to protect against a destructive attack. The recommendations include common techniques used by threat actors for initial access, reconnaissance, privilege escalation & mission objectives. mandiant.com/resources/prot…
  • user avatar
    McAfee researchers have discovered a new technique that downloads and executes malicious DLLs (Zloader) without any malicious code present in the initial spammed attachment macro. mcafee.com/blogs/other-bl…
  • user avatar
    A list of 50 CyberChef recipes and curated links for malware analysis has been shared by @mattnotmax. github.com/mattnotmax/cyb…
  • user avatar
    Splunk researchers look into the tactics, techniques and procedures employed by APT29 in a recent campaign. The attack chain begins with a spear-phishing email leading to the delivery of the WINELOADER backdoor. splunk.com/en_us/blog/sec…