g0njxa Profile Banner
Who said what? Profile
Who said what?

@g0njxa

Followers
5K
Following
5K
Media
1K
Statuses
3K

ChatGPT says I'm a cyber researcher :) | donate πŸ’Έ to g0njxa.eth πŸ’– | Bad student, enthusiast, defo not an expert DMs are open, feel free to reach! πŸ˜Όβ˜‚οΈπŸŸ£

Valencia, Spain πŸ‡ͺπŸ‡Έ
Joined January 2023
Don't wanna be here? Send us removal request.
@g0njxa
Who said what?
2 years
In the past weeks I interviewed the staff from the major infostealers projects, a total of 7: Lumma,Raccoon,Meduza,Vidar,Amadey,StealC,Meta. Below you will find a short summary of this series that ends today, and also the ones who refused to talk. πŸ‘€πŸ‘‡ https://t.co/MPtxQmstxI
Tweet card summary image
g0njxa.medium.com
Consider this the end of a series that lasted a few weeks. I tried to contact almost everyone related to the infostealer ecosystem, that I…
6
20
121
@g0njxa
Who said what?
2 days
Featuring one of the most cool interviews with a MacOS infostealer developer, because β€œmacOS is the safest system and has no viruses.” Collaboration with @osint_barbie 🍎🀩 No more spoilers today, read now a interview with Phexia: https://t.co/3GFnN3n4Jg
Tweet card summary image
g0njxa.medium.com
To completely understand what’s going on in a market that has been growing in the last years I found mandatory to know which players are…
3
19
76
@g0njxa
Who said what?
5 days
A short interview with XFILES (also known by researchers as DeerStealer) 🦌 Since 2021 on the playground, alledgelling offering multiple malware solution for both Windows but recently also MacOS πŸ‘€ Read here πŸ‘‡πŸ‘‡ https://t.co/jbRTvTx6Wl
Tweet card summary image
g0njxa.medium.com
To completely understand what’s going on in a market that has been growing in the last years I found mandatory to know which players are…
3
7
42
@g0njxa
Who said what?
12 days
@g0njxa
Who said what?
2 years
Have you ever seen a #Rhadamanthys panel? #Rhadamanthys Stealer offers a web-based panel hosted in the TOR network. Today you will be able to see a v0.5.0 panel. Here you can see how everything looks: (But make sure to check the analysis from @hasherezade first!) 1/3 πŸ‘‡
0
0
8
@g0njxa
Who said what?
12 days
1 week after the the operation on Rhadamanthys, it seems to be more disruptive than the one did on Lumma (which should be a good comparation) since the infostealer has not returned soon. So it seems we can start talking about another one missing on the Internet, at least for
@g0njxa
Who said what?
20 days
First thoughts about #Rhadamanthys Stealer "disruption" (?) and what to expect in the next days with the current information as of November 13th: The same way I did with Lumma I want to share some words ( https://t.co/t5wpfVCa85) Leaving to one side from the discussion anything
2
10
36
@g0njxa
Who said what?
12 days
Infostealers are a global issue and are feeding up other kind of crimes worldwide, its not a one country thing. You may see in the recent news (see video) how a major scam hub was blew out in Myanmar after being raided, 346 detained and +10.000 phones confiscated, the second
1
4
41
@g0njxa
Who said what?
20 days
First thoughts about #Rhadamanthys Stealer "disruption" (?) and what to expect in the next days with the current information as of November 13th: The same way I did with Lumma I want to share some words ( https://t.co/t5wpfVCa85) Leaving to one side from the discussion anything
@g0njxa
Who said what?
20 days
Confirmed rumours about targeting Rhadamanthys, customers messaged by Dutch Police, associated domains displaying a seized banner #Endgame πŸ‰
0
11
49
@g0njxa
Who said what?
20 days
Confirmed rumours about targeting Rhadamanthys, customers messaged by Dutch Police, associated domains displaying a seized banner #Endgame πŸ‰
3
17
94
@g0njxa
Who said what?
21 days
More rumours! (βŒ›οΈ?) Rhadamanthys customer message: Dear <redacted>, International law enforcement agencies have designated Rhadamanthys as a target under OPERATION ENDGAME. Our data points to your possible involvement with Rhadamanthys. This information has been recorded by
@g0njxa
Who said what?
22 days
Multiple unknown affirmations of a major blow on Rhadamanthys Stealer infrastructure while admin urges to pause work and reinstall servers, and users reportedly finding problems to login into control panels Rhadamanthys main onion domains are unavailable as for now This is a
3
14
67
@g0njxa
Who said what?
22 days
Multiple unknown affirmations of a major blow on Rhadamanthys Stealer infrastructure while admin urges to pause work and reinstall servers, and users reportedly finding problems to login into control panels Rhadamanthys main onion domains are unavailable as for now This is a
@Gi7w0rm
Gi7w0rm
22 days
Rumors are spreading about a mayor #LawEnforcement operation against #Rhadamanthys #Stealer. @g0njxa and me have been monitoring the situation closely. -Rhada domains under active law enforcement control - Customers are adviced to delete all servers Image via club1337
4
16
92
@g0njxa
Who said what?
22 days
Danabot is back recently as reported with new updates, see statements and demo video below: "We have launched a new version of the product with a global system update. Now users of the staff tariff can use our own loader, as well as a new bot installation system. There are a lot
@Threatlabz
Zscaler ThreatLabz
23 days
Danabot has resurfaced with version 669 after nearly a 6 month hiatus following the Operation Endgame law enforcement actions in May. The current C2s are the following: 62.60.226[.]146:443 62.60.226[.]154:443 80.64.19[.]39:443
18
23
90
@g0njxa
Who said what?
26 days
More #Grandoreiro targeting Spain πŸ‡ͺπŸ‡ΈπŸ‡ͺπŸ‡Έ, impersonating Hospital @Hospital_FJD @quironsalud and a (fake? πŸ˜‚) law firm. Using spoofed emails Deliver landing /vmi2895023.contaboserver.net >> /vmi2895024.contaboserver.net C2: 3.238.96.208:5874 nextgenpass.hopto[.]me Analysis:
@g0njxa
Who said what?
26 days
New #Grandoreiro campaign impersonating AEAT (National Tax agency) geo target Spain πŸ‡ͺπŸ‡ΈπŸ‡ͺπŸ‡Έ Deliver page /vmi2895604.contaboserver.net C2 44.192.48.117:7432 techscalemaster.privatizehealthinsurance[.]net Analysis: https://t.co/3ru4VkW9rK Samples: https://t.co/amkWkmbCsb
0
13
41
@ICEgov
U.S. Immigration and Customs Enforcement
3 months
America needs you! Join U.S. Immigration and Customs Enforcement today.
2K
3K
19K
@g0njxa
Who said what?
26 days
New #Grandoreiro campaign impersonating AEAT (National Tax agency) geo target Spain πŸ‡ͺπŸ‡ΈπŸ‡ͺπŸ‡Έ Deliver page /vmi2895604.contaboserver.net C2 44.192.48.117:7432 techscalemaster.privatizehealthinsurance[.]net Analysis: https://t.co/3ru4VkW9rK Samples: https://t.co/amkWkmbCsb
@g0njxa
Who said what?
27 days
#Grandoreiro Geo target πŸ‡ͺπŸ‡ΈπŸ‡ͺπŸ‡Έ November 2025 Email > Landing download > ISO > .vbs > Grandoreiro Analysis: https://t.co/m1CqgaTM89 IOCs: launchboosthub.myactivedirectory[.]com 3.231.226.146:5871 growthmodelabs.net-freaks[.]com 44.192.46.125:7432
0
8
30
@g0njxa
Who said what?
27 days
#Grandoreiro Geo target πŸ‡ͺπŸ‡ΈπŸ‡ͺπŸ‡Έ November 2025 Email > Landing download > ISO > .vbs > Grandoreiro Analysis: https://t.co/m1CqgaTM89 IOCs: launchboosthub.myactivedirectory[.]com 3.231.226.146:5871 growthmodelabs.net-freaks[.]com 44.192.46.125:7432
@osiseguridad
Oficina de Seguridad del Internauta
28 days
⚠️#INCIBEaviso | No es #Iberdrola quien estÑ enviando estos correos. Si necesitas acceder a tu factura, accede mediante la #app o su web oficial. Visita el aviso para saber mÑs: https://t.co/O1qb3bF55r #AvisosDeSeguridad #Ciudadanía
1
15
36
@osint_barbie
xiu
27 days
GIVEAWAY UPDATE! 🍎β™₯️🀘 The winner has been selected and it’s @0x2asec πŸŽ‰ Apologies for the few days delay in announcing – it took us a bit longer to contact and get the books shipped (PS. Vol I & II of The Art of Mac Malware by @patrickwardle are already on their way πŸ“¦)
@g0njxa
Who said what?
1 month
GIVEAWAY TIME! 🍎β™₯️🀘 In case you missed the opportunity to grab yours, celebrating the success of #OBTS V8 in Ibiza πŸ‡ͺπŸ‡Έ @objective_see (@andyrozen), and special thanks to @osint_barbie, we will be holding a giveaway of @patrickwardle "The art of Mac Malware" books - Vol. I
0
3
17
@g0njxa
Who said what?
30 days
A interview with AURA stealer, a new emerging malware solution to have a look over the next months Read now here πŸ‘‡πŸ“š https://t.co/H1QsGAHn2g
Tweet card summary image
g0njxa.medium.com
To completely understand what’s going on in a market that has been growing in the last years I found mandatory to know which players are…
2
7
41
@g0njxa
Who said what?
1 month
Reports of the detainment of three people behind the infamous Meduza Stealer (interviewed back in 2023 - https://t.co/TIo21TlJVE) in the Moscow region, Russia πŸ‡·πŸ‡Ί, accused of "gain unauthorized access to data of one of the institutions in the Astrakhan region in May of this year"
3
7
54
@moonlock_lab
Moonlock Lab
1 month
1/ Sometimes the best hunts start with a simple share. A few strings from an updated #MacSync #macOS malware, dropped casually by @g0njxa, led us to the FUD file, which appears to be a dropper πŸ‘‡
1
11
52
@g0njxa
Who said what?
1 month
The bulk of the void that AMOS fading left into the MacOS MaaS infostealers is already being filled by other solutions such as MacSync (interviewed by @osint_barbie and I recently: https://t.co/cKrFyqBQlZ), who allegedly want to be "at AMOS level by the end of the year". In
@g0njxa
Who said what?
3 months
A interview with recently rebranded MacSync, also known as Mac.c Stealer by mentalpositive. Colab with @osint_barbie 🀠 An emerging, cheaper and trendy MaaS solution for MacOS environments which usage is increasing in the last months. Read now πŸŽπŸ€–: https://t.co/BAwQinOEdn
4
16
46
@g0njxa
Who said what?
1 month
Currently seeing a surge on #CastleLoader malware being delivered through fake websites impersonating software used in enterprise environments such as Zabbix or RVTools (see photo 1 & 2). IOCS below πŸ‘ΎπŸ”Ž Please note that this campaign uses the same exact template lures of
2
25
85
@g0njxa
Who said what?
1 month
GIVEAWAY TIME! 🍎β™₯️🀘 In case you missed the opportunity to grab yours, celebrating the success of #OBTS V8 in Ibiza πŸ‡ͺπŸ‡Έ @objective_see (@andyrozen), and special thanks to @osint_barbie, we will be holding a giveaway of @patrickwardle "The art of Mac Malware" books - Vol. I
4
9
49