PS C:\Users\malbear > whoami /all

Malbear Labs

We have one mission.

Research. We reverse the threat before it reaches you.

Fight. We turn that research into pressure on the people behind it.

Educate. Because the best defense isn’t just a tool - it’s someone who knows what they are looking at.

Windows PowerShell
PS C:\Users\malbear> whoami /all
name:     "Malbear Labs"
email:    "info@malbearlabs.com"
focus:    ["Malware Reversing", "Threat Hunting", "CTI", "Incident Response", "OSINT"]
status:   AVAILABLE 
Type a command and press [ENTER] | try: help, about, contact, interests
> more posts
Shadow HVNC and Shadow Loader: The Kit That Protects Its License Better Than Its Customers

Shadow HVNC and Shadow Loader: The Kit That Protects Its License Better Than Its Customers

Ransomware gets the headlines because it's loud: it kicks the door wide open, encrypts everything, and leaves a "love" note, and the bill for the week or...

Weyhro C2: Because Ransomware Wasn’t Paying the Bills Anymore

Weyhro C2: Because Ransomware Wasn’t Paying the Bills Anymore

A teardown of Weyhro C2, a new command-and-control framework advertised on a cybercrime forum as an "advanced pentesting toolkit."

Autopsy of a Failed Stealer: StealC v2

Autopsy of a Failed Stealer: StealC v2

StealC is one of the well-known stealers written in C++ that has been active since 2022. In April 2025 after the release of the StealC v2 version, the...

The Wagmi Manual: Copy, Paste, and Profit

The Wagmi Manual: Copy, Paste, and Profit

First promoted as the “Triple Culture” Team and later rebranded as the Wagmi Team, this traffer group has been operating since at least, early 2023. One...

Advancing Through the Cyberfront, LegionLoader Commander

Advancing Through the Cyberfront, LegionLoader Commander

LegionLoader is a downloader malware written in C/C++ that first appeared in the wild in 2019. It is also known by other names, including Satacom and...

Hearts Stolen, Wallets Emptied: Insights into CryptoLove Traffer’s Team

Hearts Stolen, Wallets Emptied: Insights into CryptoLove Traffer’s Team

This blog was written in collaboration with @g0njxa ❤ Together, we will explore the CryptoLove traffer’s team and look into their methods of operation.

Who Ordered the SMOKEDHAM? Backdoor Delicacies in the Wild

Who Ordered the SMOKEDHAM? Backdoor Delicacies in the Wild

The SMOKEDHAM backdoor has been active since 2019 and has been observed being distributed by the threat actor Mandiant identifies as UNC2465. This...

The Abuse of ITarian RMM by Dolphin Loader

The Abuse of ITarian RMM by Dolphin Loader

Looking into the abuse of ITarian RMM and introducing Dolphin Loader

The GlorySprout or a Failed Clone of Taurus Stealer

The GlorySprout or a Failed Clone of Taurus Stealer

GlorySprout malware analysis

Malbear Labs is a non-profit threat research collective. We exist to help everyone defending against the dark arts.

We take malware apart to understand how it actually works, and we don’t keep what we learn to ourselves. We publish it and teach it, so it reaches the people who have to make the call at 3 AM.

Most defenses don’t fail because the tooling was missing. They fail because someone was looking straight at the evidence and didn’t know what they were seeing.

Whether you want to collaborate, need help with an investigation, or you are under attack right now, reach out at info@malbearlabs.com or find us on X at @MalbearLabs.

Malware Reversing
Threat Hunting
CTI
Incident Response
OSINT

Zero spam. Unsubscribe anytime.

--email

By subscribing you agree that we process your data to send you our newsletter. No third parties, no ads. Ever.