<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Malware-Analysis on CuraSec</title><link>https://curasec.metacog.co.kr/tags/malware-analysis/</link><description>Recent content in Malware-Analysis on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 01 Sep 2026 15:28:52 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/malware-analysis/index.xml" rel="self" type="application/rss+xml"/><item><title>UAC-0099 embeds LLM-disrupting prompts in malware to blind AI analysis</title><link>https://curasec.metacog.co.kr/insights/2026-09-01-russia-aligned-uac-0099-plants-nuclear-weapon-prompt-in-malw/</link><pubDate>Tue, 01 Sep 2026 15:28:52 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-09-01-russia-aligned-uac-0099-plants-nuclear-weapon-prompt-in-malw/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> GuardBreaker shows that AI-assisted malware scanning can be manipulated at the artifact level; no patch or config change is needed today, but engineers building AI-augmented security pipelines should understand this evasion class.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> Review any AI/LLM-assisted triage or malware-analysis workflows and add a mandatory human-review layer for suspected APT samples — do not treat LLM output as authoritative when analyzing artifacts from sophisticated actors.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Adversaries are now actively engineering around AI-assisted defenses; file this as context for future AI-tool procurement and policy decisions around over-reliance on LLM-based analysis in SOC operations.&lt;/li>
&lt;/ul></description></item><item><title>SANS ISC: Malicious PE file compiler statistics overview</title><link>https://curasec.metacog.co.kr/insights/2026-08-28-some-malicious-pe-stats-thu-aug-27th/</link><pubDate>Fri, 28 Aug 2026 21:21:40 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-28-some-malicious-pe-stats-thu-aug-27th/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Compiler and PE header metadata distributions across malicious samples can inform triage heuristics; useful background for analysts who build or tune static detection rules, but yields no immediate detection action.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>SANS ISC: Testing Gemma4/Ollama for malware hash analysis via DShield</title><link>https://curasec.metacog.co.kr/insights/2026-08-13-using-gemma4-with-ollama-testing-file-hash-analysis-and-reco/</link><pubDate>Thu, 13 Aug 2026 11:57:16 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-13-using-gemma4-with-ollama-testing-file-hash-analysis-and-reco/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Practical walkthrough of using a local LLM to enrich malware hashes against VirusTotal and CyberGordon — worth evaluating if you&amp;rsquo;re building AI-assisted triage pipelines, but no patch or configuration action required.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Demonstrates an accessible approach to AI-assisted hash triage using Ollama and Gemma4 locally; useful context for analysts evaluating LLM integration into enrichment workflows, but yields no immediate detection or hunt action.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Malaika: LLM Multi-Agent Framework for Android Malware Behavior Analysis</title><link>https://curasec.metacog.co.kr/insights/2026-07-13-malaika-understanding-malware-through-tri-grounded-agentic-r/</link><pubDate>Mon, 13 Jul 2026 14:30:14 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-13-malaika-understanding-malware-through-tri-grounded-agentic-r/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Academic research on grounded agentic reasoning for malware behavior reconstruction; no immediate engineering action, but the tri-grounding approach (domain, semantics, knowledge) is worth noting when evaluating LLM-assisted code-analysis tooling.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Malaika&amp;rsquo;s behavior-reconstruction framing — connecting sparse program evidence to auditable behavioral conclusions — could inform how teams structure LLM-assisted malware triage workflows, though no detection or hunt action is available from this paper alone.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item></channel></rss>