<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/tags/malware/best-of/2026/02" -->

---
title: Best Malware posts — February 2026 | daily.dev
description: The most upvoted Malware posts from February 2026, curated by the daily.dev community.
canonical: https://daily.dev/tags/malware/best-of/2026/02
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:url: https://daily.dev/tags/malware/best-of/2026/02
og:type: website
og:site_name: daily.dev
og:title: Best Malware posts — February 2026 | daily.dev
og:description: The most upvoted Malware posts from February 2026, curated by the daily.dev community.
og:image: https://media.daily.dev/image/upload/s--VAY5ToZt--/f_auto/v1724209435/public/daily.dev%20-%20open%20graph
---

# Best of Malware — February 2026

1. 1  
[](https://daily.dev/posts/malicious-go-crypto-module-steals-passwords-and-deploys-re--hubou1zfx "Malicious Go “crypto” Module Steals Passwords and Deploys Re...")  
Article  
![Avatar of socketdev](https://media.daily.dev/image/upload/s---oEn9czC--/f_auto/v1716187892/logos/socketdev)Socket · 28w  
Malicious Go “crypto” Module Steals Passwords and Deploys Re...  
Socket's Threat Research Team discovered a malicious Go module, github.com/xinfeisoft/crypto, impersonating the legitimate golang.org/x/crypto package. The backdoor was inserted into ssh/terminal/terminal.go's ReadPassword function, which captures passwords, exfiltrates them to attacker-controlled infrastructure, and executes a remote shell stager. The stager adds an SSH key for persistence, weakens iptables firewall rules, and downloads two disguised payloads — one of which is confirmed as the Rekoobe Linux backdoor linked to APT31\. The module used GitHub Raw as a rotating C2 pointer to avoid republishing. The Go module proxy now blocks the package with a 403 SECURITY ERROR after Socket's report. Defenders are advised to treat go.mod changes as security-sensitive, use dependency scanning in CI, and watch for curl|sh execution, authorized\_keys modifications, and iptables policy changes.  
59  
2
2. 2  
[](https://daily.dev/posts/unpatchable-how-chinese-hackers-hid-in-dell-vms-for-2-years-using-magic-packets--fzvlv90ci "Unpatchable? How Chinese Hackers Hid in Dell VMs for 2 Years Using "Magic Packets"")  
Article  
![Avatar of infosecwriteups](https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/f0dc21b5bbfd46fda36f7b4b53dd1705)InfoSec Write-ups · 29w  
Unpatchable? How Chinese Hackers Hid in Dell VMs for 2 Years Using "Magic Packets"  
CVE-2026-22769 (CVSS 10.0) exposes a critical flaw in Dell RecoverPoint for Virtual Machines appliances, exploited by Chinese state-sponsored group UNC6201 for nearly two years. The attack chain begins with hardcoded Apache Tomcat credentials, enabling deployment of the SLAYSTYLE web shell for root access. Attackers then pivot to advanced persistence techniques: 'Ghost NICs' (hot-plugged virtual network adapters bridged to separate VLANs to bypass firewalls) and 'Magic Packets' (Single Packet Authorization via iptables manipulation to hide backdoor ports from scanners). A new backdoor, GRIMBOLT, written in C# with Native AOT compilation, evades EDR tools by eliminating the JIT translation layer that security tools typically inspect. IOCs, remediation steps, and behavioral hunting queries are provided for defenders.  
29
3. 3  
[](https://daily.dev/posts/russia-is-hacking-zero-days-again-lhfkpxlpq "Russia is hacking zero-days again")  
Video  
![Avatar of johnhammond](https://media.daily.dev/image/upload/s--Oh7b_KW---/f_auto/v1729363281/logos/johnhammond)John Hammond · 29w  
Russia is hacking zero-days again  
Russian hacking group APT28 was observed exploiting a zero-day vulnerability in Microsoft Office (CVE-2026-21509) just one day after its disclosure, targeting Ukrainian government officials via malicious Word documents. The exploit leverages OLE object linking and embedding to trigger a WebDAV connection that downloads a shortcut file, executes shellcode hidden in a PNG file, performs COM hijacking, establishes persistence via scheduled tasks, and deploys Covenant C2 infrastructure using filen.io for command and control. A hands-on walkthrough demonstrates analyzing the malicious RTF file using REMnux, grep, xxd, strings, and a Python OLE scanning script to identify the WebDAV reference and matching CLS ID. Mitigation involves patching to Office 2021 or later, or applying registry key blocks for the relevant COM class IDs.  
26  
2

[See all Malware archives](/tags/malware/best-of)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@graph":[{"@type":"CollectionPage","@id":"https://daily.dev/tags/malware/best-of/2026/02#page","url":"https://daily.dev/tags/malware/best-of/2026/02","name":"Best Malware Posts — February 2026","description":"The most upvoted Malware posts from February 2026, curated by the daily.dev community.","isPartOf":{"@type":"WebSite","url":"https://daily.dev"}},{"@type":"ItemList","@id":"https://daily.dev/tags/malware/best-of/2026/02#items","numberOfItems":3,"itemListElement":[{"@type":"ListItem","position":1,"url":"https://daily.dev/posts/malicious-go-crypto-module-steals-passwords-and-deploys-re--hubou1zfx","name":"Malicious Go “crypto” Module Steals Passwords and Deploys Re..."},{"@type":"ListItem","position":2,"url":"https://daily.dev/posts/unpatchable-how-chinese-hackers-hid-in-dell-vms-for-2-years-using-magic-packets--fzvlv90ci","name":"Unpatchable? How Chinese Hackers Hid in Dell VMs for 2 Years Using \"Magic Packets\""},{"@type":"ListItem","position":3,"url":"https://daily.dev/posts/russia-is-hacking-zero-days-again-lhfkpxlpq","name":"Russia is hacking zero-days again"}]},{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Tags","item":"https://daily.dev/tags"},{"@type":"ListItem","position":3,"name":"Malware","item":"https://daily.dev/tags/malware"},{"@type":"ListItem","position":4,"name":"Best of","item":"https://daily.dev/tags/malware/best-of"},{"@type":"ListItem","position":5,"name":"February 2026"}]}]}
```

