This repository contains YARA rules for detecting potentially dangerous patterns in code and configuration files.
Those files have been generated from the information shared in the following blogposts: Suspicious files that may be related to the latest UNC4899 hack of Safe/ByBit