Shadow HVNC and Shadow Loader: The Kit That Protects Its License Better Than Its Customers
Ransomware gets the headlines because it's loud: it kicks the door wide open, encrypts everything, and leaves a "love" note, and the bill for the week or...
We have one mission.
Research. We reverse the threat before it reaches you.
Fight. We turn that research into pressure on the people behind it.
Educate. Because the best defense isn’t just a tool - it’s someone who knows what they are looking at.
Ransomware gets the headlines because it's loud: it kicks the door wide open, encrypts everything, and leaves a "love" note, and the bill for the week or...
A teardown of Weyhro C2, a new command-and-control framework advertised on a cybercrime forum as an "advanced pentesting toolkit."
StealC is one of the well-known stealers written in C++ that has been active since 2022. In April 2025 after the release of the StealC v2 version, the...
First promoted as the “Triple Culture” Team and later rebranded as the Wagmi Team, this traffer group has been operating since at least, early 2023. One...
LegionLoader is a downloader malware written in C/C++ that first appeared in the wild in 2019. It is also known by other names, including Satacom and...
This blog was written in collaboration with @g0njxa ❤ Together, we will explore the CryptoLove traffer’s team and look into their methods of operation.
The SMOKEDHAM backdoor has been active since 2019 and has been observed being distributed by the threat actor Mandiant identifies as UNC2465. This...
Looking into the abuse of ITarian RMM and introducing Dolphin Loader
GlorySprout malware analysis
Malbear Labs is a non-profit threat research collective. We exist to help everyone defending against the dark arts.
We take malware apart to understand how it actually works, and we don’t keep what we learn to ourselves. We publish it and teach it, so it reaches the people who have to make the call at 3 AM.
Most defenses don’t fail because the tooling was missing. They fail because someone was looking straight at the evidence and didn’t know what they were seeing.
Whether you want to collaborate, need help with an investigation, or you are under attack right now, reach out at info@malbearlabs.com or find us on X at @MalbearLabs.
New malware breakdowns, threat research, and IOCs. No fluff, just the analysis.
→ Zero spam. Unsubscribe anytime.
By subscribing you agree that we process your data to send you our newsletter. No third parties, no ads. Ever.