Skip to content
HiveSecurity
  • Home
  • Blog
  • Tags
  • Vulnerabilities
    • Tools
    • Cheat Sheet
    • Security Guides
  • Contact
  • About
Esc
Type to search...
  • Home
  • Blog
  • Tags
  • Vulnerabilities
  • Resources
  • Tools
  • Cheat Sheet
  • Security Guides
  • Contact
  • About
← All tags Tag

Malware Analysis

36 articles

The Digital Parasite: How Attacker Tradecraft Evolved in 2026

Picus Labs found evasion, persistence and command-and-control techniques in eight of its 2026 top ten malware behaviors. What defenders can take from the data.

Updated 25 September 2026
Cybersecurity Lateral Movement MITRE ATT&CK

indexed-btree: The npm Malware That Waited for a Library Call

Checkmarx found malicious code hidden in an npm library method rather than an install script. Here's what the trigger means for dependency review and incident response.

24 September 2026
Supply Chain Malware Analysis Detection

WaterPlum Turns Job Interviews Into Developer Workstation Compromise

A joint law-enforcement advisory links fake technical interviews to 30,000 infected devices. The practical boundary is where an interview project runs.

23 September 2026
Social Engineering Malware Analysis Supply Chain

Rapuncel Infostealer: A Microsoft-Signed Driver Turns Against EDR

Rapuncel pairs fake GitHub downloads with a signed driver used to kill security processes. What defenders should monitor and why driver controls matter.

22 September 2026
Malware Analysis Blue Team Detection

When the Weapon Learns: How Nation-States Weaponized AI Across the Full Attack Chain

Google GTIG's May 2026 report documents a turning point: state actors now use AI to write zero-day exploits, build self-navigating backdoors, and poison the AI supply chain itself.

Updated 19 September 2026
Threat Intelligence Malware Analysis Red Team

UEFI Bootkits vs Firmware Implants: Persistence and Detection

Distinguish EFI partition bootkits from SPI flash implants. Learn what disk replacement removes, which evidence to collect, and how Secure Boot updates help.

Updated 19 September 2026
Malware Analysis Firmware Security Threat Intelligence

Sality Botnet Disruption: How Defenders Turned a P2P Network Against Itself

Inside the 2026 Sality disruption: peer-to-peer trust failures, the limits of botnet takedowns, and practical detection and recovery for Windows defenders.

18 September 2026
Malware Analysis Threat Intelligence Network Security

Forgotten Shims: How 11 Old Microsoft-Signed Files Break Secure Boot

ESET Research found 11 old UEFI shim bootloaders, all validly signed by Microsoft, that bypass Secure Boot on any system trusting Microsoft's third-party CA. CVE-2026-8863 and CVE-2026-10797 — no exploit chain required.

15 July 2026
Firmware Security Vulnerability CVE

AI-Built Browser Ransomware Abuses Chrome File Access

Check Point analyzed a DeepSeek-attributed ransomware sample that should not work from a browser tab. Most of it was fiction — except for one detail that mapped to a real Chromium API. No malware install required.

5 July 2026
Ransomware AI Security Web Security

Miasma and Mini Shai-Hulud: When npm Malware Learned to Persist in AI Coding Agents

Mini Shai-Hulud and Miasma show how supply chain malware can move from npm install-time execution into Claude Code hooks, VS Code tasks, and CI/CD persistence.

6 June 2026
Supply Chain Malware Analysis AI Security

The AI Evasion Lab

Sophos X-Ops uncovered a threat actor using Claude Opus 4.5 and Cursor IDE to build an automated, modular EDR evasion framework — 80 modules, 70+ techniques, tested against Sophos, CrowdStrike, and Defender.

3 June 2026
Malware Analysis Red Team Blue Team

Poisoned AI: How Hugging Face Became a Malware Distribution Platform

A fake OpenAI repo hit #1 trending on Hugging Face with 244K downloads in 18 hours. Here's every attack vector targeting AI model repositories — and how to defend against them.

29 May 2026
Supply Chain AI Security Malware Analysis

DFIR 2026: Memory Forensics, Windows Artifacts, and Incident Response

Memory forensics, Windows event artifacts, and IR methodology — from initial alert to post-incident report. Tools, commands, and playbooks included.

Updated 18 May 2026
Blue Team Incident Response Digital Forensics

LOLBins in 2026: How Attackers Use Windows Against Itself

79% of attacks in 2024 used no malware. Certutil, mshta, rundll32 — execution, persistence, and evasion via Windows built-ins. Detection rules included.

Updated 18 May 2026
Red Team Blue Team Detection

Windows Attack Techniques 2026: BYOVD, ClickFix, and C2 over Cloud

BYOVD EDR evasion, ClickFix delivery, C2 over cloud services — how modern Windows attackers operate in 2026, and the detection logic to catch them.

Updated 18 May 2026
Red Team Blue Team Malware Analysis

Unmasking TeamPCP: The Supply Chain Saboteurs and the Trails They Left Behind

TeamPCP has compromised hundreds of open-source packages and stolen half a million credentials. But their OPSEC is leaking — and someone is already hunting them.

15 May 2026
Threat Intelligence Supply Chain Attribution

CallPhantom: How 28 Fake Apps Collected Payments for Data That Never Existed

ESET uncovered CallPhantom — 28 Android apps with 7.3M downloads that sold fabricated call histories. A deep dive into the fraud mechanics, billing bypass, and how to protect yourself.

8 May 2026
Malware Analysis Threat Intelligence Mobile Security

The World's Most Dangerous Hacking Teams: A Guide to Nation-State APT Groups

Meet the elite state-sponsored hacking groups that stole billions, blacked out cities, and infiltrated governments. Who they are, what they want, and how they operate in 2026.

7 May 2026
Threat Intelligence Cybersecurity Malware Analysis

AutoHotkey Malware Loaders: How Attackers Weaponize Automation Scripts

AutoHotkey isn't just for productivity scripts — attackers use it as a stealthy malware loader. Learn how AHK-based campaigns work and how to detect them.

7 May 2026
Malware Analysis Detection Red Team

Browser Vendors Fail Users: Millions Infected, Zero Notifications Sent

840,000 GhostPoster victims, 3.2M+ in GitLab campaign, 4.3M+ in ShadyPanda—browser vendors removed extensions but never told users. Self-regulation failed.

7 May 2026
Cybersecurity Supply Chain Malware Analysis

BYOVD: How Attackers Use Legitimate Drivers to Kill Your Security Tools

BYOVD (Bring Your Own Vulnerable Driver) lets attackers reach the Windows kernel using signed, legitimate drivers — and then silently kill your EDR before ransomware drops.

7 May 2026
Red Team Blue Team Malware Analysis

Cobalt Strike Detection & Hunting: A Defender's Playbook

How to detect Cobalt Strike beacons in your environment — network fingerprints, process injection patterns, Sigma rules, and practical hunting queries for blue teams.

7 May 2026
Blue Team Cobalt Strike Threat Hunting

Invisible Characters as an Attack Vector

Unicode's invisible characters are being weaponized — hiding malicious code in repositories, hijacking AI agents, and bypassing security reviews without leaving a trace visible to human eyes.

7 May 2026
Cybersecurity Web Security Red Team

Kimwolf Botnet: 2 Million Hijacked Devices Reshaping Threat Landscape

The Kimwolf botnet has compromised over 2 million devices worldwide by exploiting residential proxy networks and unsecured Android TV boxes. Here's what threat intelligence reveals about its infrastructure, tactics, and how to defend against it.

7 May 2026
Cybersecurity Malware Analysis Threat Intelligence

Trust Me, I'm a Shortcut: How LNK Files Lie to Windows Explorer

Windows .lnk shortcut files can show one target while silently executing another. Discover five spoofing techniques including CVE-2025-9491, how attackers exploit them, and how to detect them.

7 May 2026
Red Team Blue Team Windows Security

macOS Offensive Security: How Attackers Exploit Apple's Unique Attack Surface

TCC bypass, Keychain theft, Launch Agent persistence, dylib hijacking — how attackers target macOS and how defenders detect them. Attack→Detect with real commands.

7 May 2026
Red Team Blue Team Detection

The Package You Trusted: How the Axios Supply Chain Attack Happened

On March 31, 2026, a trusted npm package with 400 million monthly downloads was backdoored for three hours. Here's how it worked and why it keeps happening.

7 May 2026
Cybersecurity Supply Chain Malware Analysis

NTFS Alternate Data Streams: How Attackers Hide in Plain Sight

NTFS Alternate Data Streams let attackers hide executables inside innocent-looking files. Learn how ADS works, how malware uses it, and how to detect it with PowerShell, Sysinternals, and Sysmon.

7 May 2026
Red Team Blue Team Windows Security

OpenClaw: How the Viral AI Agent Became 2026's First Major Security Crisis

OpenClaw went from 0 to 180,000 GitHub stars in weeks — and then came the RCE, 30,000 exposed instances, and a supply chain attack poisoning its entire skill marketplace.

7 May 2026
Cybersecurity Malware Analysis Supply Chain

State-Sponsored Threat Actors 2026: Who They Are and What They Do

A threat intelligence deep-dive into the world's most dangerous state-sponsored APT groups — their identities, motivations, campaigns, and tradecraft in 2026.

7 May 2026
Threat Intelligence APT Nation-State

When Your Defender Becomes the Attacker: How Trusted Windows Processes Get Weaponized

Windows Defender and other high-privilege system processes are increasingly targeted by attackers. Learn how security tools become attack surfaces — and what you can do about it.

7 May 2026
Windows Security Privilege Escalation Cybersecurity

Xanthorox AI: When the Attacker's AI Goes Dark

Xanthorox is an offline, modular AI attack platform with five specialized models — and it needs no cloud, no API, and leaves no traditional IoCs. Here's what defenders need to know.

7 May 2026
Cybersecurity Malware Analysis AI Security

Zombie ZIP: How a Malformed Archive Header Blinds 98% of Antivirus Engines

CVE-2026-0866 — a single two-byte header manipulation causes 50 of 51 AV engines to scan compressed noise instead of the actual payload. Technical breakdown, attack scenarios, and detection.

7 May 2026
Malware Analysis Red Team Detection

Memory Forensics with Volatility 3: What Attackers Leave Behind

How attackers hide in RAM using fileless malware and process injection — and how defenders use Volatility 3 to find them. Practical DFIR workflow with real commands.

30 April 2026
Malware Analysis Blue Team Detection

Cookie-Controlled PHP Webshells: A Stealthy Tradecraft in Linux Hosting Environments

Microsoft's Defender team uncovered a clever attacker technique: PHP webshells that stay completely dormant until activated by a secret HTTP cookie. Here's how it works — and how to catch it.

4 April 2026
Web Security Red Team Blue Team

Telegram as a C2 Server: How It Works and How to Detect It

Attackers use Telegram's Bot API as command-and-control infrastructure — no Telegram install needed on the victim machine. Here's the mechanics, real-world examples, and blue team detection strategies.

23 March 2026
Cybersecurity Blue Team Malware Analysis
HiveSecurity

Offensive thinking. Defensive expertise.

Content
  • Home
  • Blog
  • Tags
  • Vulnerabilities
Resources
  • Tools
  • Cheat Sheet
  • Security Guides
Company
  • Contact
  • About
  • RSS
  • Privacy
  • Security Policy

© 2026 Hive Security. All rights reserved.

Built with zero trust & least privilege