New Russian Translations of Leading Cybersecurity Books on Ethical Hacking, Reverse Engineering, Malware Analysis, and Privacy Released
A well-known Russian-language cybersecurity library has released a substantial batch of new translations of leading English books on ethical hacking, bug bounty hunting, reverse engineering, malware analysis, and privacy.
The project, which continues the long-running series “Materials on Hacking in Russian,” focuses on translating high-quality resources and hosting them on the Hackbooks site. The latest update adds more than a dozen titles that span web application security, network discovery, protocol exploitation, binary analysis, and defensive techniques.
Web Application Security and Bug Hunting
Web Hacking 101: How to Make Money Hacking Ethically presents more than thirty real-world vulnerability disclosures, covering HTML injection, XSS, CSRF, open redirects, remote code execution, and business logic flaws, each accompanied by attack classification, original reports, bounty amounts, and key takeaways.
Real-World Bug Hunting: A Field Guide to Web Hacking by Peter Yaworski walks readers through rewarded vulnerability reports, dedicating chapters to XSS, CSRF, SSRF, SQL injection, XXE, subdomain takeover, IDOR, OAuth issues, race conditions, and logic errors while also explaining how to select bug bounty programs and write effective reports.
Network Security and Protocol Analysis
The official Nmap Network Scanning guide covers host and service detection, firewall and IDS evasion, performance tuning, and automation via the Nmap Scripting Engine, with practical scenarios for network inventory, penetration testing, rogue access point discovery, and worm response.
Attacking Network Protocols: A Hacker’s Guide to Capture, Analysis, and Exploitation teaches traffic capture, modification, and replay, followed by static and dynamic analysis, protocol reverse engineering, custom proxy and dissector development, fuzzing, debugging, memory corruption exploitation, authentication bypass, and denial-of-service techniques.
Reverse Engineering and Binary Analysis
Reverse Engineering for Beginners is a large free textbook that teaches assembly reading and logic reconstruction, illustrating how C and C++ constructs appear after compilation, covering function calls, stack, memory, optimizations, system APIs, multiple architectures, and operating systems.
How to Approach Binary File Format Analysis explains encodings, endianness, numbers, flags, structures, alignment, signatures, and headers, offering a practical workflow using histograms, string searches, section extraction, and pattern matching for digital forensics, malware analysis, data recovery, and converter development.
Privacy, Surveillance, and Cryptography
Obfuscation: A User’s Guide for Privacy and Protest explores creating ambiguous or misleading data to resist mass surveillance, drawing examples from WWII chaff, social media bots, and search query masking tools while discussing technical and ethical limits.
Gigabytes of Power by Kiwi Bird connects societal and technological history with growing state and corporate control, covering mass surveillance, biometrics, cryptography, GSM and satellite TV hacking, propaganda, and counter-terrorism restrictions.
Crypto Wars: The Fight for Privacy in the Digital Age traces fifty years of conflict between privacy advocates and governments, examining debates around DES, academic freedom, crypto export controls, key escrow, and post-Snowden developments.
Windows Security and Malware Analysis
Windows Security Internals: A Deep Dive into Windows Authentication, Authorization, and Auditing by James Forshaw details kernel and user-mode security mechanisms including access tokens, security descriptors, rights checking, auditing, SAM, Active Directory, NTLM, and Kerberos, with PowerShell examples for hands-on exploration.
Practical Malware Analysis: The Hands-On Guide to Dissecting Malicious Software guides readers through the full malware investigation lifecycle—from initial file inspection to logic reconstruction—using static and dynamic analysis, disassemblers, debuggers, memory forensics, network behavior, packers, and shellcode, reinforced by laboratory exercises.
Evasive Malware: A Field Guide to Detecting, Analyzing, and Defeating Advanced Threats focuses on malware that detects virtual machines, sandboxes, and analysis tools, covering anti-disassembly and anti-debugging methods, process injection, rootkits, fileless techniques, packers, obfuscation, and laboratory setup recommendations.
Fuzzing and Automated Testing
The Fuzzing Book is an interactive textbook demonstrating random, mutational, grey-box, grammar-based, search-based, and symbolic fuzzing, complete with executable Python examples and Jupyter notebooks that readers can run while studying.
Readers are encouraged to explore the full collection on Hackbooks and share the resources with the community. The translations significantly lower the barrier for Russian-speaking professionals and students seeking authoritative material on information security, reverse engineering, and antivirus research.
Related articles
Censys Exposes DarkSword iOS Exploit Platform and Coruna Crypto Wallet Stealer
Censys has disclosed the inner workings of DarkSword, a commercial platform that sells remote access to iOS devices, along with its associated malware Coruna that targets cryptocurrency wallet recovery keys. The infrastructure was exposed between September 15 and 17, allowing researchers to analyze the full attack chain starting from a WebKit and JavaScriptCore exploit delivered through the browser. After escaping the Safari sandbox and reaching the kernel, the platform deploys three layers including a flag, controller, and main implant. Coruna then scans the device for BIP39-compliant seed phrases stored in photos and Apple Notes across 19 targeted wallet applications such as MetaMask, Phantom, Trust Wallet, Coinbase, Exodus, imToken, Bitpie, and BitKeep. The exposed server contained 11 victim recovery keys, 179 directories of extracted data, and 75 operator accounts, indicating a structured commercial operation with agent accounts, commissions, and device quotas. Confirmed infections affect devices running iOS 16.1 and 16.3.1, while Apple has extended patches to additional iOS 18 devices. Maintaining updated iOS versions remains the primary defense against this threat.
How Malware Evades Sandboxes: Detection Techniques and Defense Strategies
Sandboxes have become a standard tool for analyzing suspicious files delivered via email, websites, messengers, and cloud storage. Modern malware often avoids detection by identifying virtual environments rather than directly attacking the sandbox. Techniques include checking for virtualization artifacts, system parameters, hardware signatures, network indicators, user activity, and timing delays. Reports such as Picus Red Report 2026 show technique T1497 returning to the top five most common MITRE ATT&CK methods. Examples like Blitz, GootLoader, and LummaC2 demonstrate environment checks and behavioral evasion. Effective defense requires combining multiple analysis methods, realistic sandbox profiles, pre-delivery inspection, and integration with other security controls.
Realtek Jungle SDK Flaw CVE-2021-35394 Fuels Cling Botnet Spread Across Routers
Researchers at Nozomi Networks have observed a sharp rise in exploitation attempts against CVE-2021-35394, a critical remote code execution vulnerability in the Realtek Jungle SDK. The flaw, rated 9.8 on the CVSS scale and disclosed five years ago, is being used to deploy the Cling botnet on routers and video recorders. The affected SDK is embedded in products from multiple vendors, leaving large numbers of devices exposed because firmware updates are rarely applied. Cling carries exploits for seven distinct vulnerabilities targeting Realtek, Linksys, MVPower, TBK, LB-LINK, FiberHome and China Mobile hardware. Once installed, the malware performs recursive scanning, spreads like a worm, manipulates TCP tunnels and proxies, and participates in DDoS attacks. Its command-and-control channel hides instructions inside STUN protocol transaction IDs, impersonating legitimate responses from Google public STUN servers. FortiGuard Labs has confirmed the findings and tracks the variant as ClingSTUN.
Attackers Abuse Legitimate Microsoft Defender Exclusions to Conceal Malware
Huntress researchers have detailed an evasion technique in which threat actors avoid disabling Microsoft Defender entirely. Instead, they create targeted exclusions for specific folders or file extensions, allowing malware to operate undetected while the protection status remains apparently active. These exclusions are configured through PowerShell commands, Windows Management Instrumentation, Group Policy, or direct registry modifications, all requiring administrator privileges after initial compromise. A registry key named HideExclusionsFromLocalAdmins can further conceal the list of exclusions from local administrators viewing the interface. The approach has been linked to campaigns involving GootKit in 2019, WhisperGate in 2022 that excluded the entire C: drive, and Muddled Libra in 2024. Defenders are advised to monitor registry changes directly, as this bypasses interface hiding, and to flag exclusions of entire drives or common directories such as temporary and downloads folders.