Loading video...

Video Failed to Load

Go Home

🛠️ AsmLdr Shellcode loader for Windows x64 environments. Execute encrypted payloads while minimizing detection by advanced antivirus software, endpoint detection and response (EDR) systems, sandboxes, and debuggers Try:

13,575 views • 9 months ago •via X (Twitter)

0 Comments

No comments available

Comments from the original post will appear here

Related Videos

⚠️ A defense evasion tool called ExEngine is being sold as a service, marketed as an AV/EDR killer that disables mainstream consumer security software including Windows Defender, Malwarebytes, Bitdefender, and Avast. The tool combines AV termination with a Ring-3 rootkit, UAC bypass, and decoy payload delivery to support stealthy initial access operations. ⠀ ‣ Threat Actor: ryewx1 ‣ Category: Defense Evasion Tool / Killer ‣ Offering: ExEngine AV/EDR Killer ‣ Industry: Malware Tooling ⠀ The seller claims ExEngine actively terminates security software rather than only obfuscating payloads, granting attackers a longer window of undetected operation. The tool supports Windows 10 and 11 builds and is sold per-build at $150 to $250. ⠀ Advertised capabilities: ⠀ ▪️ AV/EDR termination with primary and fallback techniques ▪️ UAC bypass with automatic privilege escalation ▪️ Ring-3 rootkit functionality to hide files, processes, registry keys, and network connections ▪️ Discord webhook logging for victim machine info and execution status ▪️ Secondary decoy payload (game/document/installer) to keep targets unaware ▪️ Persistence across reboots and logouts ▪️ Anti-VM and anti-debug detection with fake error message exit ▪️ Universal Windows 10/11 support, all payload types ⠀ Risk to defenders: ⠀ ▪️ Active termination of consumer AV products including Windows Defender means traditional endpoint protections cannot be relied on once ExEngine executes successfully ▪️ Decoy payload pattern is designed to delay user-driven incident reporting, lengthening attacker dwell time ▪️ Ring-3 rootkit hiding of files, processes, and network connections complicates incident response triage on compromised hosts ▪️ Discord webhook telemetry indicates the operator is targeting consumer and SMB victims at scale rather than running individual targeted campaigns ▪️ Sold per-build at low cost ($150 to $250), making it accessible to low-skill operators who can pair it with commodity stealers, RATs, or loaders

Dark Web Informer

23,210 views • 2 months ago

Kudos to Gujarat Police for revolutionizing law enforcement with cutting-edge technology! Gujarat Police is leveraging innovative technologies like night vision thermal detection drones, AI, real-time mapping, and human intelligence to transform policing in the state's remotest tribal district, Dahod. This forward-thinking approach has led to the successful detection of various cases. Some of the technologies being used include: •⁠ ⁠Night Vision Thermal Detection Drones: Equipped with thermal imaging cameras, these drones can track suspects in dark conditions and detect heat emitted by humans and animals. •⁠ ⁠AI-Powered Systems: Artificial intelligence is being used to analyze data, predict crime patterns, and identify high-crime areas, enabling police to allocate resources more effectively. •⁠ ⁠Real-Time Mapping: Advanced mapping technologies provide real-time information, enabling police to respond quickly and efficiently to emergencies •⁠ ⁠Human Intelligence: Trained personnel are working alongside technology to gather intelligence, conduct surveillance, and solve cases. The integration of these technologies has transformed policing in Dahod, making it a model for other districts to follow. Gujarat Police's commitment to innovation is truly commendable! Watch the inspiring story on India TV to learn more about Gujarat Police's groundbreaking initiatives! #GujaratPolice #PolicingWithTechnology #Innovation #LawEnforcement #Dahod #TransformingPolicing

Harsh Sanghavi

40,915 views • 1 year ago

🚨 THREAT INTELLIGENCE ALERT 🚨 The tool 🇨🇳 KernelGhost820 is being actively sold on the underground market for US$ 2,500, complete with full source code. This is a professional-grade suite with an intuitive graphical interface and six advanced modules, specifically designed for EDR evasion and sophisticated ransomware operations with efficient lateral movement: • EDR Removal Engine: Automatically detects and terminates more than 40 security products (including CrowdStrike, SentinelOne, Microsoft Defender, Kaspersky, and others). Supports Kernel, UserMode, and NTDLL termination modes, kernel driver loading for protected processes, disabling Windows Defender, and blocking telemetry connections. • Ransomware Module: Dual encryption using AES256CBC + RSA2048, supporting over 70 file types (documents, images, databases, backups, etc.). Automatically deletes Volume Shadow Copies to prevent recovery, generates custom ransom notes with Bitcoin addresses and contact emails, and changes the desktop wallpaper. • Remote Operations & Mass Deployment: Connects to remote devices on the local network via WMI (requires username and password). Scans installed software on target hosts, performs process termination, and enables one-click full tool deployment. Includes full-network scanning for open SMB port 445 with real-time progress tracking. • Detailed Process Manager and full Operation Logger (exportable to TXT). This tool significantly lowers the technical barrier for advanced ransomware actors targeting corporate environments. Immediate monitoring recommendations: • Evaluate the resilience of your EDR/XDR controls against kernel-mode bypass techniques • Intensify monitoring of anomalous SMB (port 445) traffic and WMI connections • Strengthen network segmentation and the principle of least privilege Our team is actively tracking this tool and any emerging variants. #ThreatIntelligence #Ransomware #EDRBypass #CyberSecurity #InfoSec #CyberThreat

Clandestine

40,619 views • 3 months ago

🇮🇷 Iran’s Ballistic Missile Arsenal and the Regional Counter Strategy Fateh Series (SRBM) The Fateh family represents Iran’s core short range ballistic missile capability. These missiles use solid fuel, allowing rapid launch with minimal preparation time. Estimated range is around 300 km, designed for battlefield and regional targets. Later variants emphasize higher accuracy through improved guidance and terminal maneuvering, making them more difficult to intercept than older systems. Sejjil (MRBM) Sejjil is a two stage, solid fuel medium range ballistic missile with an estimated range of 2,000 to 2,500 km. Its solid fuel design significantly improves survivability by reducing launch detection time. Sejjil is intended as a strategic missile capable of reaching targets across the Middle East, including major military bases and infrastructure. Kheibar Shekan (Advanced MRBM) Kheibar Shekan is a newer generation solid fuel missile with a reported range of around 1,450 km. It features a maneuverable reentry vehicle, enabling mid course and terminal phase adjustments to complicate interception. This missile is optimized to penetrate modern missile defense systems rather than relying purely on range or payload. Why these missiles challenge air and missile defenses? Solid fuel propulsion shortens warning time. Maneuverable reentry vehicles reduce interception probability. High speed terminal phases compress response windows. When launched in salvos, these missiles are designed to stress and saturate defensive systems. How regional and allied forces aim to counter this threat Surrounding states and allied bases rely on layered missile defense. Patriot PAC 3 MSE addresses short range and terminal phase threats. THAAD provides high altitude interception against medium range missiles. Israeli systems such as Arrow complement regional coverage. Early warning radars, space based sensors, and shared command networks extend detection and response time. Base hardening, dispersal of assets, and redundancy reduce damage if interception fails. Intelligence driven preemptive strike capability remains a key deterrent factor. Strategic assessment Iran’s missile program emphasizes survivability and defense penetration rather than sheer numbers. In response, regional allies focus on integration, layered defense, and intelligence dominance. The outcome in any future conflict would likely depend less on individual missiles and more on coordination, saturation levels, and decision speed.. Can layered missile defense realistically stay ahead of evolving maneuverable ballistic threats?

Defense Intelligence

22,048 views • 5 months ago

How do you create your payloads in 2025? At MSec Operations we prefer to use DLL sideloading for EDR evasion. This technique allows our malicious code to run within a signed, legitimate executable. Combining this technique with other useful techniques will provide stable execution to fly under the radar. 🛸 The following video demonstrates the use of #RustPack to create such a payload in just a few seconds. The command line usage shows that our input payload is a simple unmodified Apollo C2 executable. We want to clone all the exported functions from the original Windows wininet.dll to create our own library with the same name. The execution of the payload will be delayed by ~5 seconds in this case, without using the Win32 sleep function, but by performing random calculations. ⏲️ Hardware breakpoints are used to bypass the Antimalware Scan Interface (AMSI). Without an AMSI bypass, Apollo would be flagged as a C# assembly when loaded. 🎓 Our payload will only fire on a domain joined system, this basically prevents it from running in e.g. sandbox environments. 🤠 Last but not least, in this example, the encrypted payload itself is stored in a separate file on the target system and not even in the same folder as our malicious DLL. Anyone analysing just the DLL will never be able to find out what the payload is. Automatic sample submissions for cloud analysis usually only upload the executable or DLL, emulators won't see the real payload either. 🤠 Tired of creating such payloads yourself? With #RustPack it's really easy, and payloads always look completely different, even if the same payload is packed twice to avoid signature-based detection Contact us via info[at] for more information! 👍

MSec Operations

26,037 views • 1 year ago