logo

Vibeware: More than bad vibes for AppSec

ID: c04a59ea-a215-5c91-b682-5be1beab2069

STIX ID: report--c04a59ea-a215-5c91-b682-5be1beab2069

Feed Name: ReversingLabs Blog

Threat Score
70/100

Date Published: 2026-04-16

Date Updated: 2026-05-01

Author: John P. Mello Jr.

...
...

The report describes how Pakistan-based APT36 has pivoted to ‘vibeware’—AI-generated, mass-produced malware compiled in niche languages (e.g., Nim, Zig, Crystal, Rust) and leveraging trusted cloud services (Slack, Discord, Supabase, Google Sheets) as C2—to overwhelm detection and triage capacity; it provides examples of multi-implant deployments per endpoint, explains the evasion and denial-of-detection strategy, and recommends defenses such as behavioral detection, outbound controls, application allow-listing, zero-trust, and supply-chain verification.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.