
threat-research-and-intelligence
BlackBerry Threat Research & Intelligence

BlackBerry Threat Research & Intelligence

🇺🇦 Windows driver with usermode interface which can hide processes, file-system and registry objects, protect processes and etc

A tool to detect and crash Cuckoo Sandbox

Spoof file icons and extensions in Windows

RustyWater represents the main payload and the backbone of the entire adversarial operation in Static Kitten group attacks.

Randomly changes Win32/64 PE Files for 'safer' uploading to malware and sandbox sites.

A framework that create an advanced stealthy dropper that bypass most AVs and have a lot of tricks

Script to create templates to use with VirtualBox to make vm detection harder


C++ tool that patches Windows API calls to bypass sandbox RAM size checks, enabling malware to evade detection in isolated analysis environments.

👁🗨 This script will simulate fake processes of analysis sandbox/VM software that some malware will try to avoid.

Anti Virtulization, Anti Debugging, AntiVM, Anti Virtual Machine, Anti Debug, Anti Sandboxie, Anti Sandbox, VM Detect package. Windows ONLY.

BlackLotus UEFI Windows Bootkit

c++ fully undetected shellcode launcher ;)

A PowerShell script that attempts to help malware analysts hide their Windows VirtualBox Windows VM's from malware that may be trying to evade…

AppLocker-Based EDR Neutralization

Malformed ZIP archive that evades antivirus detection by declaring Method=0 (stored) while containing DEFLATE-compressed payload.