1. X
  2. Gen Threat Labs
Log inSign up
Gen Threat Labs
574 posts
Image
user avatar
Gen Threat Labs
@GenThreatLabs
A global network of #cybersecurity researchers at Gen, protecting nearly 500M people through our Cyber Safety brands - @Norton, @Avast, @LifeLock & more.
Prague, Czech Republic
gendigital.com/blog/news/inno…
Joined May 2017
26
Following
4,615
Followers
RepliesRepliesMediaMedia

New to X?

Sign up now to get your own personalized timeline!

Create account

By signing up, you agree to the Terms of Service and Privacy Policy, including Cookie Use.

Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
Don't miss what's happening
People on X are the first to know.
Log inSign up
  • user avatar
    Gen Threat Labs
    @GenThreatLabs
    Oct 2, 2024
    🚨 New #rootkit alert! We've discovered #Snapekit, a sophisticated rootkit targeting Arch Linux (6.10.2-arch1-1 x86_64). It hooks 21 syscalls, hides its payload, and evades detection by dropping in user space while dodging analysis tools & debuggers. Stay vigilant! #ThreatIntel
    Image
    400K0400K
  • user avatar
    Gen Threat Labs
    @GenThreatLabs
    Sep 27, 2022
    📣 Let's start a new era of #YARA debugging together! Introducing YARI, an interactive debugger and a new addition to our #opensource family github.com/avast/yari. Learn more in the blog post by @KastakMatej: engineering.avast.io/yari-a-new-era…
    Image
    00:00
  • user avatar
    Gen Threat Labs
    @GenThreatLabs
    Aug 10, 2022
    📢We don't just use #YARA at Avast, we contribute to the community too! Our latest addition is that we are making our YARA Language Server (#YLS) #opensource github.com/avast/yls. Learn how you can start using it in the blog post by @KastakMatej: engineering.avast.io/yls-first-step…
  • user avatar
    Gen Threat Labs
    @GenThreatLabs
    Nov 4, 2021
    #YARA is a tool (but also a language and even more) helping malware researchers to identify and classify malware samples (virustotal.github.io/yara/). We benefit from YARA at Avast, but we also give back to the community. Here you can find some of our recent contributions (🧵👇)
  • user avatar
    Gen Threat Labs
    @GenThreatLabs
    Oct 2, 2024
    Replying to @GenThreatLabs
    1️⃣ Snapekit is distributed with a dropper in user space that detects a wide array of analysis and debugging tools such as Cuckoo, JoeSandbox, Hybrid-Analysis, Frida, Ghidra, IDA Pro, and many more. If any are present, it sets a flag to alter behavior. 2️⃣ Upon execution, Snapekit
    19K019K
  • user avatar
    Gen Threat Labs
    @GenThreatLabs
    Feb 28, 2024
    Lazarus is back with a new variant of their infamous FudModule rootkit! Ditching their old BYOVD techniques, Lazarus upgraded to exploiting a much stealthier admin-to-kernel zero-day for CVE-2024-21338 (addressed in the February Patch Tuesday update). decoded.avast.io/janvojtesek/la…
    18K018K
  • user avatar
    Gen Threat Labs
    @GenThreatLabs
    Feb 24, 2022
    On top of the #HermeticWiper (x.com/ESETresearch/s…) there is also a new golang-based ransomware roaming in #Ukraine waters. virustotal.com/gui/file/4dc13…
    Image
    Image
    user avatar
    ESET Research
    @ESETresearch
    Feb 23, 2022
    Breaking. #ESETResearch discovered a new data wiper malware used in Ukraine today. ESET telemetry shows that it was installed on hundreds of machines in the country. This follows the DDoS attacks against several Ukrainian websites earlier today 1/n
  • user avatar
    Gen Threat Labs
    @GenThreatLabs
    Jun 3, 2022
    Malware signed by stolen certificates is using #Follina vulnerability to spread evil #AsyncRAT into the #Palau paradise. Seems targeted. Read more on #AvastDecoded decoded.avast.io/threatintel/ou…
  • user avatar
    Gen Threat Labs
    @GenThreatLabs
    Jul 21, 2022
    Candiru is back at it again, exploiting browser #0day in the Middle East. Read our latest blog post for more details about our discovery of CVE-2022-2294, a #vulnerability that affected Chrome, Edge, Safari, and others. decoded.avast.io/janvojtesek/th…
  • user avatar
    Gen Threat Labs
    @GenThreatLabs
    Jul 8, 2021
    We've just published our first in a new blog series on how threat actors abuse #CobaltStrike. Decoding Cobalt Strike: Understanding Payloads explains how to analyze Cobalt Strike payloads for malicious activity. decoded.avast.io/threatintel/de…
  • user avatar
    Gen Threat Labs
    @GenThreatLabs
    Sep 12, 2023
    📢The second post from Know Your YARA Rules is out. Today, we will look into more tips on improving the scanning performance 📈, and maybe we will motivate you to rewrite your #YARA rules. #AvastEngineering engineering.avast.io/know-your-yara…
    23K023K
  • user avatar
    Gen Threat Labs
    @GenThreatLabs
    Feb 8, 2023
    A #dota2 exploit discovered in the wild! Like #gta5, #dota2 was also recently afflicted by a remote code execution exploit. Read our latest research blog to learn how a V8 bug from 2021 was exploited in the game to attack custom game mode players. decoded.avast.io/janvojtesek/do…
    23K023K
  • user avatar
    Gen Threat Labs
    @GenThreatLabs
    Mar 3, 2022
    Decrypted: Avast releases a #free #decryptor for #HermeticRansom #ransomware (aka #PartyTicket) which we previously discovered spreading in Ukrainian networks together with #HermeticWiper decoded.avast.io/threatresearch… #AvastDecoded #HelpingUkraine
  • user avatar
    Gen Threat Labs
    @GenThreatLabs
    Jul 1, 2022
    We are introducing our latest improvements to the #YARA project: signature parsing and verification, .NET type reconstruction, and Telfhash calculation. engineering.avast.io/making-yara-be…
    Image