HabrJuly 31, 2026🇷🇺Translated from Russian

Comprehensive Collection of Malware Analysis and Development Books Released for Security Researchers

A curated selection of books on malware analysis and development has been assembled, covering techniques for both creating and defending against malicious software across Windows, macOS, and Android platforms.

The collection begins with MalDev Academy Complete, a modular course on Windows malware development and offensive security. It guides readers from foundational topics such as C programming, Windows internals, and WinAPI to advanced subjects including PE files, memory manipulation, payload encryption, obfuscation, process injection, APC injection, and shellcode execution.

Its companion, MalDev Academy Extended Modules, expands on the core curriculum with specialized modules on Rust implementations, enhanced evasion tactics, and practical exercises designed to test deeper understanding of malware techniques.

The Art of Mac Malware by Patrick Wardle offers a practical guide to analyzing macOS threats. It covers infection vectors, persistence mechanisms, Mach-O binary analysis, dynamic debugging, and anti-analysis bypasses, concluding with a detailed case study of the EvilQuest malware.

The second volume focuses on building heuristic detection systems for macOS using Endpoint Security frameworks and code signing analysis to reduce false positives.

The Android Malware Handbook examines Android threats through static and dynamic analysis, feature extraction, and machine learning models for classifying banking trojans, ransomware, and spyware.

Classic references include Malware Analyst’s Cookbook, which provides recipes for classification, unpacking, memory forensics with Volatility, and rootkit detection, as well as Practical Malware Analysis, a foundational text on setting up isolated labs, using IDA Pro and WinDbg, and defeating packers and anti-debugging tricks.

The roundup concludes with Evasive Malware by Kyle Cucci, a field guide dedicated to analyzing samples that deliberately evade sandboxes, disassemblers, and forensic tools through context awareness and anti-forensics methods.

Related articles

AntiMalwareMalware & Botnets

Reconstructed Stuxnet Source Code Published on GitHub with Build Instructions

An unknown researcher has released a reconstructed version of the Stuxnet worm source code on GitHub, including reverse-engineering results and assembly instructions. Stuxnet was discovered in 2010 and is widely attributed to the joint US-Israeli Olympic Games operation targeting Iran's Natanz uranium enrichment facility. The malware specifically attacked Siemens industrial controllers by altering frequency converter operations to physically damage centrifuge rotors while falsifying operator displays. Propagation relied on USB drives, network shares, and a Windows Print Spooler vulnerability, combined with stolen Realtek and JMicron driver-signing certificates. The worm also injected itself into Siemens WinCC and Step 7 software to intercept communications with programmable logic controllers. Due to a flaw in its environment checks, Stuxnet escaped the target network and spread publicly before its built-in June 2012 self-destruct date. Researchers are advised to analyze the code only inside fully isolated virtual machines without network access.

AntiMalwareMalware & Botnets

Researchers Create 0-Click WeChat Worm That Hijacks Accounts via Incoming Calls

Security researchers at Calif have developed a 0-click worm capable of compromising WeChat accounts through incoming voice calls without any user interaction. The exploit requires only that the attacker already exists in the victim's contact list and works across Android and iOS devices. In demonstrations, an infected Android device called an iPhone to seize control of its WeChat account while the call continued ringing, after which the compromised iPhone targeted another Android device. The worm spreads automatically between trusted contacts, functioning like a classic network worm but using WeChat profiles as propagation nodes. Even if the victim answers or declines the call, the exploit can persist or be retried, for example during nighttime hours. After account takeover, attackers gain full control to read and send messages, make calls, and impersonate the owner, while the underlying smartphone itself remains unaffected. Tencent received notification in July, released patches in versions 8.0.77 for Android and 8.0.76 for iOS, and server-side blocking was confirmed by late August, with no real-world attacks observed so far.

HabrMalware & Botnets

Website Protection Against Bots: Six Years of Traffic Filtering Evolution from Behavioral Bots to Multi-Layer Analytics

The article traces the author's journey starting in 2020 when anomalous traffic from social networks began flooding websites, initially appearing as visits from Twitter, Instagram, YouTube, and VKontakte. Early attempts using .htaccess rules to block referrers failed as bots dynamically switched to direct or external domain transitions. Server-side JavaScript and cookie checks altered bot behavior but did not stop the flow, revealing that successful browser checks only confirm technical capability rather than human presence. IP blocking of ranges like 31.173.80.0/21 and 178.176.64.0/19 provided temporary relief until mobile proxies rotated addresses, exposing the limits of static blacklists. IPv6 adoption further demonstrated how address-family-specific rules quickly become obsolete. Fingerprint spoofing and constant rotation of digital prints made single-signal identification unreliable. The core lesson emphasizes real-time filtering at the edge over post-hoc analytics exclusion to prevent bots from reaching the web server at all.

HabrMalware & Botnets

Drama RAT: Advanced Android Banking Trojan with RAT Capabilities Analyzed by Positive Technologies

Positive Technologies researchers have detailed Drama RAT, a sophisticated Android banking trojan distributed via phishing messages in messengers and disguised as VPN services or banking apps. The malware uses droppers that request installation of fake updates, then deliver a full-featured payload capable of stealing credentials, recording screens, and performing overlay attacks. Drama RAT automatically grants itself Accessibility permissions while hiding the process behind opaque overlays and employs multiple persistence mechanisms including AlarmManager alarms and Doze mode bypass. Communication occurs primarily over mTLS WebSocket with a fallback CDN channel, while anti-analysis features include over 1200 junk artifacts, broken AndroidManifest.xml, Frida hooking detection, and per-class string obfuscation. The trojan supports keylogging, SMS interception, VNC screen sharing, microphone and camera recording without indicators, and participation in DDoS attacks. Positive Technologies notes that removal is extremely difficult without ADB or safe mode because the malware redirects users away from settings screens.