Malcat
@malcat4ever
http://malcat.fr, a hexadecimal editor / disassembler / decompiler for #malware analysis, #DFIR and #SOC.
If you want to follow the development of malcat outside of X, we have other accounts: @malcat4ever.bsky.social @malcat.infosec.exchange You can also join our discord: discord.gg/Pf3s2ZKqtU
Join us on Tuesday, July 29th, at 14:00 EST for a special live stream with Renaud Tabary from @malcat4ever where we will explore and perform live malware triage with Malcat! twitch.tv/InvokeReversing
#Kesakode DB has been updated to 1.0.36 ! * 9 new malware families * 70 extended malware signatures * 37 new malicious samples in database * 11440 new library objects seen * 120k new clean programs whitelisted * 17M new unique functions * 3M new unique strings
Hey all! As promised, here's the in-depth analysis @JershMagersh from @InvokeReversing and I did of the malware strain that's been spreading through NPM in the last few days following a successful phish. We present to you: Scavenger. c-b.io/2025-07-20+-+I…
If you need to identify #malware quickly, give #malcat a try: its Kesakode code identification is fast and can even work offline! More info: doc.malcat.fr/analysis/kesak…
This isn't a type of malware we already know about. The threat actors made it themselves. It gets its instructions through Discord. I'm putting a picture below that shows the desktop of the person who created this malware. They're calling the malware 'Minecraft Rat'.
You can now check your strings in #malcat against an online library of #Malpedia FLOSSed strings. Just copy this plugin, courtesy of @push_pnx : github.com/malpedia/malpe…

#Malcat 0.9.10 is out! State-of-the-art CFG recovery, MIPS disassembler & decompiler and many UI improvements; malcat.fr/blog/0910-is-o…
Malcat version 0.9.9 is out! Check out the new offline version of Kesakode for blazing-fast (unpacked) #malware identification across 2000+ families. Also python 3.13 support (& disassembler), new file parsers & improved UI: malcat.fr/blog/099-is-ou…
In the next version of #malcat, we will include an _offline_ smaller #kesakode database which will only contain conflict-free malware signatures. This will be fast and run with every analysis. You can always get the full deal (clean + lib) afterwards with an online query.

🔍New Video: Antivirus myths 🔗 youtube.com/watch?v=4DolQT… Or why these sentences are wrong: ➡️ AVs use mostly pattern signatures ➡️ AI is a new defense technique ➡️ defense techniques must focus on high detection rate ➡️ behavior signatures are heuristic and patterns are not
You'll soon be able to export Malcat's view to files: ● Summary report as HTML+ SVG ● Proximity & call graph views as SVG or PNG ● Struct/hex/disasm views as HTML ● Strings, symbols, intel, kesakode and other views as CSV

Malcat 0.9.8 is out! You'll find a lot of QoL improvements, improved API and more doc. More infos: malcat.fr/blog/098-is-ou…