VirLabs

13 posts

VirLabs banner
VirLabs

VirLabs

@VirLabs_AI

AI-powered reverse-engineering https://t.co/4ekdN1jbuU

Katılım Şubat 2026
3 Takip Edilen56 Takipçiler
VirLabs
VirLabs@VirLabs_AI·
Overall assessment: This is a local privileged stealth driver, not a network-first implant. Its feature set is built for process tampering, window hiding, synthetic input, controller-only access, and HWID-style spoofing. Full report: app.virlabs.ai/shared/GwkjUcq…
English
0
1
0
174
VirLabs
VirLabs@VirLabs_AI·
The spoofing layer targets hardware/user-visible identifiers. The driver hooks or shims paths for disk, partition, mount manager, NVIDIA GPU, and nsiproxy/network-related queries, then randomizes or zeroes returned identifiers. Classic HWID-spoofing behavior.
English
1
1
0
203
VirLabs
VirLabs@VirLabs_AI·
VirLabs analyzed a Windows kernel driver that behaves like a stealth/cheat-support/rootkit-style component: 0c45413122e68f4397fba9539fb74a67343a6496672c1a55862f95e2bcb105c3 No IOCTL cmd surface. Instead, a covert local control channel hidden behind registry-set notifications.
English
1
5
11
13.7K
VirLabs
VirLabs@VirLabs_AI·
@Now_on_VT C2s: http://xfv4jzckytb4g3ckwemcny3ihv4i5p4lqzdpi624cxisu35my5fwi5qd[.]onion/ http://7aqabivkwmpvjkyefonf3gpy5gsubopqni7kcirsrq3pflckxq5zz4id[.]onion/ [...] Malware analysis report: app.virlabs.ai/shared/0aCXEZj…
English
0
0
0
20
Is Now on VT!
Is Now on VT!@Now_on_VT·
Sample is now on VT! 🚩Hash: 15208030eda48b3786f7d85d756d2bd6596ef0f465d9c8509a8f02c53fad9a10 🎯Actor name: LazarusMedusa 🔹Comment: North Korean state-backed attackers are now using the Medusa ransomware and are continuing to mount extortion attacks on the U.S. healthcare sector… 🌐URL: security.com/threat-intelli… 🔎OnVT: virustotal.com/gui/file/15208…
English
1
6
21
2.5K