
react-cve-2025-55182
Analysis of malware found on a server compromised via CVE-2025-55182, including obfuscated dropper, C2 communication, persistence mechanisms, and…

Analysis of malware found on a server compromised via CVE-2025-55182, including obfuscated dropper, C2 communication, persistence mechanisms, and…

An Interactive Binary Patching Plugin for IDA Pro

Educational Proof-of-Concept for the CVE-2022-30190 (Follina) vulnerability.

Creation of multiple Malware tools consisting of evasion, enumeration and exploitation

Collection of various malicious functionality to aid in malware development

Research code & papers from members of vx-underground.

A technique of hiding malicious shellcode via Shannon encoding.

Decrypted content of odd.tar.xz.gpg, swift.tar.xz.gpg and windows.tar.xz.gpg

PE loader with various shellcode injection techniques

A Nim implementation of reflective PE-Loading from memory

NCC Group's analysis and exploitation of CVE-2017-8759 along with further refinements

Some Rust program I wrote while learning Malware Development

Reproduction of CVE-2023-34312 using two malicious DLL files to exploit QQ and TIM messaging applications for security research and testing.

A proof of concept for CVE-2022-30190 (Follina).

Two versions of CVE-2017-8759 exploits

Rig Exploit for CVE-2018-8174 As with its previous campaigns, Rig’s Seamless campaign uses malvertising. In this case, the malvertisements have a…

Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321)

Patch PE, ELF, Mach-O binaries with shellcode new version in development, available only to sponsors