29 Jul 2026, 21:48 UTC136 views4 reactionsread 8 August 2026 Photo
The Post-Ex Tech Tree: Four Ages of Payload Execution
Every generation of post-exploitation tooling was shaped by a different constraint. Lay it out as a tech tree and the pattern is hard to miss.
Dark Age — Purpose (1995–2010). Payloads did one thing. A shellcode array was the whole product: position-independent, hand-tuned, disposable. The fork in the road appears here — native code on one side, interpreted on the …
🔥3👍1
25 Jul 2026, 14:19 UTC237 views4 reactionsread 8 August 2026 FalkonC2 is Getting Ridiculously Stealthy
🛡️ Flare Research breaks down FalkonC2 — a commercial C2 framework written from scratch in C++/MASM64, built around sub-35 KB memory-only stubs with zero disk footprint and no CRT dependencies. Rotemelli2 targets enterprise EDR/XDR, rotating 17 private C2 servers with full domain burn every 72 hours, falling back across HTTP/HTTPS (MM4 + ChaCha20), DNS tunneling and ICMP beac…
🔥4
23 Jul 2026, 13:49 UTC239 views3 reactionsread 8 August 2026 kimi k3 also did a zero-click arbitrary command execution in Telegram Desktop and iOS app (aslr pinned, one gadget away from full rce).
https://x.com/fried_rice/status/2080200610985689222
❤🔥3
22 Jul 2026, 12:07 UTC253 views3 reactionsread 8 August 2026 CET-Compliant Callstack Spoofing via Thread Pool Enum Callback Trampolining
🛡️ New research shows a CET‑compliant call‑stack spoofing trick that hijacks Windows thread‑pool enum callbacks as syscall trampolines—bypassing EDR stack telemetry while keeping Intel shadow‑stack invariants intact.
Dive into the methodology, timeline of syscall evasion, and the underlying mechanics (RtlVirtualUnwind, TEB tricks, etc.) in t…
❤2❤🔥1
13 Jul 2026, 23:03 UTC366 views1 reactionsread 8 August 2026 https://github.com/Astharot15/COMLoaderAstharot/
🕹Subscribe to MalDev | GaK3r
❤🔥1
30 Jun 2026, 15:39 UTC476 views3 reactionsread 8 August 2026 Photo
Accelerating EDR Evasion with LLM-Driven Analysis
SpecterOps (Adam Chester) shows how a dead-simple LLM harness running in a loop—GPT‑5.5‑Cyber in Codex with Binary Ninja exposed over MCP—reverse engineers Palo Alto’s Cortex XDR to pull out its YARA rules, behavioral detections (DSE/BIOC, CLIPS), and local ML models, auto-generating the Python decryption tooling and evasion test harnesses along the way. No multi-age…
❤🔥2👏1
17 Jun 2026, 13:00 UTC525 views3 reactionsread 8 August 2026 WindowsSentinel
WindowsSentinel is a lightweight C# utility that continuously monitors key Windows system events—such as file, process, and registry changes—and logs them in real‑time for easy auditing and troubleshooting.
🔗 Link
🕹Subscribe to MalDev | GaK3r
👍2❤1
12 Jun 2026, 17:37 UTC542 viewsread 8 August 2026 Photo
Mini Shai-Hulud / Miasma / Hades
🚨 Malware is now weaponizing your own AI scanner against you.
A new wave of worms — Mini Shai-Hulud, Miasma, and Hades — ship with a fake “CLASSIFIED BRIEFING” header stuffed with nuclear & bioweapon design text, placed as a non-executing JavaScript comment at the top of _index.js. The point isn’t to run anything — it’s to trip the safety refusals of LLM-based malware triage so the …
1 Jun 2026, 14:43 UTC564 views1 reactionsread 8 August 2026 Photo
HijackLibs.net
🚨 DLL Hijacking just got a lot easier to track (and exploit).
HijackLibs.net is a curated database mapping vulnerable executables to exploitable DLLs—complete with metadata for defenders to detect attacks and red teamers to plan operations. It covers key techniques like DLL Sideloading, Phantom DLL Hijacking, and Search Order Hijacking—all critical for modern threat hunting and red teaming.
👉 Dive i…
❤🔥1
31 Mar 2026, 15:05 UTC811 views2 reactionsread 8 August 2026 Claude Code Source Code Leaked Online
While publishing the packages, someone at Anthropic made a ✨slight miscalculation✨. An obfuscated cli.js build ended up in the public npm package alongside a full cli.js.map—something that definitely shouldn't have been there. Essentially, anyone who installed or downloaded the package could easily reconstruct the source code using the sourcemap.
Naturally, the code spread across…
❤🔥2
26 Jan 2026, 09:14 UTC≈1,010 views4 reactionsread 8 August 2026 Photo
Hacking Humans: Social Engineering and the Psychology - SpecterOps
🚀 Dive into the mind‑game of cyber‑attacks! In “Hacking Humans: Social Engineering and the Psychology,” John Wotton shows how the real breach starts the moment an employee decides “Who belongs here?” – from OSINT sleuthing to exploiting decision‑making patterns. 📖
https://specterops.io/blog/2026/01/23/hacking-humans-social-engineering-and-the-psycho…
❤🔥2👏1🔥1
14 Jan 2026, 11:29 UTC≈3,760 views5 reactionsread 8 August 2026 Photo
CVE-2025-54918-POC
This GitHub project provides a proof-of-concept (POC) and technical demonstration for CVE-2025-54918, showcasing a security vulnerability in a system or application. It is intended for researchers and developers to understand the exploit mechanism and assess potential risks.
🔗 Link
🕹Subscribe to MalDev | GaK3r
❤5
Showing the 12 most recent of 20 posts we hold for @gak3r. View and reaction counts are the latest single reading for each post, not a live figure, and a recent post is still accumulating both. A view count marked ≈ was rounded by Telegram before we ever saw it — t.me prints views in full below 1,000 and to three significant figures above, so ≈1,200,000 means somewhere between 1,150,000 and 1,249,999. Unmarked counts are exact. Text is reproduced from the public post preview and truncated for length.