<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" href="/feed.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
        <title>Malbear Labs</title>
        <description>Non-profit threat research built to help everyone defending against the dark arts.</description>
        <link>https://malbearlabs.com/</link>
        <atom:link href="https://malbearlabs.com/feed.xml" rel="self" type="application/rss+xml"/>
        <pubDate>Wed, 09 Sep 2026 11:37:17 -0400</pubDate>
        <lastBuildDate>Wed, 09 Sep 2026 11:37:17 -0400</lastBuildDate>
        <generator>Jekyll v4.4.1</generator>
        
            <item>
                <title>Shadow HVNC and Shadow Loader: The Kit That Protects Its License Better Than Its Customers</title>
                
                <description>&lt;p&gt;&lt;a href=&quot;https://malbearlabs.com/posts/shadow-hvnc-and-shadow-loader-the-kit-that-protects-its-license-better-than-its-customers&quot;&gt;&lt;img src=&quot;https://malbearlabs.com/images/medium/shadow-hvnc-and-shadow-loader-the-kit-that-protects-its-license-better-than-its-customers/01.png&quot; alt=&quot;Shadow HVNC and Shadow Loader: The Kit That Protects Its License Better Than Its Customers&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Ransomware gets the headlines because it&amp;apos;s loud: it kicks the door wide open, encrypts everything, and leaves a &amp;quot;love&amp;quot; note, and the bill for the week or...&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://malbearlabs.com/posts/shadow-hvnc-and-shadow-loader-the-kit-that-protects-its-license-better-than-its-customers&quot;&gt;Read the full write-up on malbearlabs.com →&lt;/a&gt;&lt;/p&gt;</description>
                <pubDate>Mon, 17 Aug 2026 20:08:37 -0400</pubDate>
                <link>https://malbearlabs.com/posts/shadow-hvnc-and-shadow-loader-the-kit-that-protects-its-license-better-than-its-customers</link>
                <guid isPermaLink="true">https://malbearlabs.com/posts/shadow-hvnc-and-shadow-loader-the-kit-that-protects-its-license-better-than-its-customers</guid>
                
                <category>Cybercrime</category>
                
                <category>Threat Intelligence</category>
                
                <category>Malware Analysis</category>
                
                <category>Malware</category>
                
                <category>Go</category>
                
            </item>
        
            <item>
                <title>Weyhro C2: Because Ransomware Wasn’t Paying the Bills Anymore</title>
                
                <description>&lt;p&gt;&lt;a href=&quot;https://malbearlabs.com/posts/weyhro-c2-because-ransomware-wasnt-paying-the-bills-anymore&quot;&gt;&lt;img src=&quot;https://malbearlabs.com/images/medium/weyhro-c2-because-ransomware-wasnt-paying-the-bills-anymore/01.png&quot; alt=&quot;Weyhro C2: Because Ransomware Wasn’t Paying the Bills Anymore&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;A teardown of Weyhro C2, a new command-and-control framework advertised on a cybercrime forum as an &amp;quot;advanced pentesting toolkit.&amp;quot;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://malbearlabs.com/posts/weyhro-c2-because-ransomware-wasnt-paying-the-bills-anymore&quot;&gt;Read the full write-up on malbearlabs.com →&lt;/a&gt;&lt;/p&gt;</description>
                <pubDate>Fri, 05 Dec 2025 01:37:12 -0500</pubDate>
                <link>https://malbearlabs.com/posts/weyhro-c2-because-ransomware-wasnt-paying-the-bills-anymore</link>
                <guid isPermaLink="true">https://malbearlabs.com/posts/weyhro-c2-because-ransomware-wasnt-paying-the-bills-anymore</guid>
                
                <category>Cybersecurity</category>
                
                <category>Malware</category>
                
                <category>Cybercrime</category>
                
                <category>Threat Intelligence</category>
                
            </item>
        
            <item>
                <title>Autopsy of a Failed Stealer: StealC v2</title>
                
                <description>&lt;p&gt;&lt;a href=&quot;https://malbearlabs.com/posts/autopsy-of-a-failed-stealer-stealc-v2&quot;&gt;&lt;img src=&quot;https://malbearlabs.com/images/medium/autopsy-of-a-failed-stealer-stealc-v2/01.png&quot; alt=&quot;Autopsy of a Failed Stealer: StealC v2&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;StealC is one of the well-known stealers written in C++ that has been active since 2022. In April 2025 after the release of the StealC v2 version, the...&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://malbearlabs.com/posts/autopsy-of-a-failed-stealer-stealc-v2&quot;&gt;Read the full write-up on malbearlabs.com →&lt;/a&gt;&lt;/p&gt;</description>
                <pubDate>Thu, 10 Apr 2025 17:29:33 -0400</pubDate>
                <link>https://malbearlabs.com/posts/autopsy-of-a-failed-stealer-stealc-v2</link>
                <guid isPermaLink="true">https://malbearlabs.com/posts/autopsy-of-a-failed-stealer-stealc-v2</guid>
                
                <category>Reverse Engineering</category>
                
                <category>Malware</category>
                
                <category>Stealer</category>
                
                <category>Cybersecurity</category>
                
            </item>
        
            <item>
                <title>The Wagmi Manual: Copy, Paste, and Profit</title>
                
                <description>&lt;p&gt;&lt;a href=&quot;https://malbearlabs.com/posts/the-wagmi-manual-copy-paste-and-profit&quot;&gt;&lt;img src=&quot;https://malbearlabs.com/images/medium/the-wagmi-manual-copy-paste-and-profit/01.png&quot; alt=&quot;The Wagmi Manual: Copy, Paste, and Profit&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;First promoted as the “Triple Culture” Team and later rebranded as the Wagmi Team, this traffer group has been operating since at least, early 2023. One...&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://malbearlabs.com/posts/the-wagmi-manual-copy-paste-and-profit&quot;&gt;Read the full write-up on malbearlabs.com →&lt;/a&gt;&lt;/p&gt;</description>
                <pubDate>Sat, 05 Apr 2025 14:56:43 -0400</pubDate>
                <link>https://malbearlabs.com/posts/the-wagmi-manual-copy-paste-and-profit</link>
                <guid isPermaLink="true">https://malbearlabs.com/posts/the-wagmi-manual-copy-paste-and-profit</guid>
                
                <category>Cybercrime</category>
                
                <category>Scam</category>
                
                <category>Crypto</category>
                
                <category>Malware</category>
                
            </item>
        
            <item>
                <title>Advancing Through the Cyberfront, LegionLoader Commander</title>
                
                <description>&lt;p&gt;&lt;a href=&quot;https://malbearlabs.com/posts/advancing-through-the-cyberfront-legionloader-commander&quot;&gt;&lt;img src=&quot;https://malbearlabs.com/images/medium/advancing-through-the-cyberfront-legionloader-commander/01.png&quot; alt=&quot;Advancing Through the Cyberfront, LegionLoader Commander&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;LegionLoader is a downloader malware written in C/C++ that first appeared in the wild in 2019. It is also known by other names, including Satacom and...&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://malbearlabs.com/posts/advancing-through-the-cyberfront-legionloader-commander&quot;&gt;Read the full write-up on malbearlabs.com →&lt;/a&gt;&lt;/p&gt;</description>
                <pubDate>Mon, 30 Dec 2024 13:06:29 -0500</pubDate>
                <link>https://malbearlabs.com/posts/advancing-through-the-cyberfront-legionloader-commander</link>
                <guid isPermaLink="true">https://malbearlabs.com/posts/advancing-through-the-cyberfront-legionloader-commander</guid>
                
                <category>Reverse Engineering</category>
                
                <category>Cybersecurity</category>
                
                <category>Malware Analysis</category>
                
                <category>Malware</category>
                
            </item>
        
            <item>
                <title>Hearts Stolen, Wallets Emptied: Insights into CryptoLove Traffer’s Team</title>
                
                <description>&lt;p&gt;&lt;a href=&quot;https://malbearlabs.com/posts/hearts-stolen-wallets-emptied-insights-into-cryptolove-traffers-team&quot;&gt;&lt;img src=&quot;https://malbearlabs.com/images/medium/hearts-stolen-wallets-emptied-insights-into-cryptolove-traffers-team/01.png&quot; alt=&quot;Hearts Stolen, Wallets Emptied: Insights into CryptoLove Traffer’s Team&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;This blog was written in collaboration with @g0njxa ❤ Together, we will explore the CryptoLove traffer’s team and look into their methods of operation.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://malbearlabs.com/posts/hearts-stolen-wallets-emptied-insights-into-cryptolove-traffers-team&quot;&gt;Read the full write-up on malbearlabs.com →&lt;/a&gt;&lt;/p&gt;</description>
                <pubDate>Wed, 27 Nov 2024 17:10:17 -0500</pubDate>
                <link>https://malbearlabs.com/posts/hearts-stolen-wallets-emptied-insights-into-cryptolove-traffers-team</link>
                <guid isPermaLink="true">https://malbearlabs.com/posts/hearts-stolen-wallets-emptied-insights-into-cryptolove-traffers-team</guid>
                
                <category>Malware</category>
                
                <category>Cybercrime</category>
                
                <category>Malware Analysis</category>
                
                <category>Cybersecurity</category>
                
            </item>
        
            <item>
                <title>Who Ordered the SMOKEDHAM? Backdoor Delicacies in the Wild</title>
                
                <description>&lt;p&gt;&lt;a href=&quot;https://malbearlabs.com/posts/who-ordered-the-smokedham-backdoor-delicacies-in-the-wild&quot;&gt;&lt;img src=&quot;https://malbearlabs.com/images/medium/who-ordered-the-smokedham-backdoor-delicacies-in-the-wild/01.png&quot; alt=&quot;Who Ordered the SMOKEDHAM? Backdoor Delicacies in the Wild&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;The SMOKEDHAM backdoor has been active since 2019 and has been observed being distributed by the threat actor Mandiant identifies as UNC2465. This...&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://malbearlabs.com/posts/who-ordered-the-smokedham-backdoor-delicacies-in-the-wild&quot;&gt;Read the full write-up on malbearlabs.com →&lt;/a&gt;&lt;/p&gt;</description>
                <pubDate>Fri, 22 Nov 2024 15:42:28 -0500</pubDate>
                <link>https://malbearlabs.com/posts/who-ordered-the-smokedham-backdoor-delicacies-in-the-wild</link>
                <guid isPermaLink="true">https://malbearlabs.com/posts/who-ordered-the-smokedham-backdoor-delicacies-in-the-wild</guid>
                
                <category>Malware</category>
                
                <category>Cybercrime</category>
                
                <category>Cybersecurity</category>
                
                <category>Malware Analysis</category>
                
            </item>
        
            <item>
                <title>The Abuse of ITarian RMM by Dolphin Loader</title>
                
                <description>&lt;p&gt;&lt;a href=&quot;https://malbearlabs.com/posts/the-abuse-of-itarian-rmm-by-dolphin-loader&quot;&gt;&lt;img src=&quot;https://malbearlabs.com/images/DolphinLoader/dolphin_header.jpg&quot; alt=&quot;The Abuse of ITarian RMM by Dolphin Loader&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Looking into the abuse of ITarian RMM and introducing Dolphin Loader&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://malbearlabs.com/posts/the-abuse-of-itarian-rmm-by-dolphin-loader&quot;&gt;Read the full write-up on malbearlabs.com →&lt;/a&gt;&lt;/p&gt;</description>
                <pubDate>Fri, 16 Aug 2024 00:01:35 -0400</pubDate>
                <link>https://malbearlabs.com/posts/the-abuse-of-itarian-rmm-by-dolphin-loader</link>
                <guid isPermaLink="true">https://malbearlabs.com/posts/the-abuse-of-itarian-rmm-by-dolphin-loader</guid>
                
                <category>Malware Analysis</category>
                
                <category>Loader</category>
                
                <category>Dolphin Loader</category>
                
                <category>AutoIt</category>
                
            </item>
        
            <item>
                <title>The GlorySprout or a Failed Clone of Taurus Stealer</title>
                
                <description>&lt;p&gt;&lt;a href=&quot;https://malbearlabs.com/posts/the-glorysprout-stealer-or-a-failed-clone-of-taurus-stealer&quot;&gt;&lt;img src=&quot;https://malbearlabs.com/images/GlorySprout/beansprout.jpeg&quot; alt=&quot;The GlorySprout or a Failed Clone of Taurus Stealer&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;GlorySprout malware analysis&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://malbearlabs.com/posts/the-glorysprout-stealer-or-a-failed-clone-of-taurus-stealer&quot;&gt;Read the full write-up on malbearlabs.com →&lt;/a&gt;&lt;/p&gt;</description>
                <pubDate>Sat, 16 Mar 2024 08:01:35 -0400</pubDate>
                <link>https://malbearlabs.com/posts/the-glorysprout-stealer-or-a-failed-clone-of-taurus-stealer</link>
                <guid isPermaLink="true">https://malbearlabs.com/posts/the-glorysprout-stealer-or-a-failed-clone-of-taurus-stealer</guid>
                
                <category>Malware Analysis</category>
                
                <category>Stealer</category>
                
                <category>GlorySprout</category>
                
                <category>C++</category>
                
            </item>
        
            <item>
                <title>From Russia With Code: Disarming Atomic Stealer</title>
                
                <description>&lt;p&gt;&lt;a href=&quot;https://malbearlabs.com/posts/atomic-stealer-amos&quot;&gt;&lt;img src=&quot;https://malbearlabs.com/images/AtomicStealer/atomic-stealer-badass1.JPG&quot; alt=&quot;From Russia With Code: Disarming Atomic Stealer&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Technical Analysis of Atomic Stealer&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://malbearlabs.com/posts/atomic-stealer-amos&quot;&gt;Read the full write-up on malbearlabs.com →&lt;/a&gt;&lt;/p&gt;</description>
                <pubDate>Mon, 15 Jan 2024 16:02:35 -0500</pubDate>
                <link>https://malbearlabs.com/posts/atomic-stealer-amos</link>
                <guid isPermaLink="true">https://malbearlabs.com/posts/atomic-stealer-amos</guid>
                
                <category>Malware Analysis</category>
                
                <category>Stealer</category>
                
                <category>Atomic Stealer</category>
                
                <category>macOS</category>
                
                <category>Go</category>
                
            </item>
        
    </channel>
</rss>
