
Who said what?
@g0njxa
Followers
5K
Following
5K
Media
979
Statuses
3K
ChatGPT says I'm a cyber researcher :) | donate πΈ to g0njxa.eth π | Bad student, enthusiast, defo not an expert DMs are open, feel free to reach! πΌβοΈπ£
Valencia, Spain πͺπΈ
Joined January 2023
StealC V2 issued an update recently:. Featuring enhanced app-bound decryption of browser password and cookies, and a panel Rest API for clients. Changelog ππ
StealC v2 infostealer updated recently:. featuring "decryption of Google Chrome v135 passwords". and also removing the thing we reported days before π
1
5
40
He replied backπ€·ββοΈ:. @saiyangod0x says: Why malware? Is your purpose to create or destroy?. Everyone has their own standards of morality, my belief is that without destroying something, something new will not be built. @vxdb says: How did you get into malware development?.
Some active malware coder has accepted to do a "Questions & Answers" for the infosec community. He has been active for some years, serving and developing malware to individuals and on traffer teams. What you will ask him? Share it in the comments!π£π.Soon in a blog.
5
2
31
RT @NexusFuzzy: I found a what I think novel approach which allowed me to list some of the content of #Lumma #Infostealer Command & Controlβ¦.
0
26
0
An Spanish πͺπΈ individual and MacOS user just lost over $62k in cryptocurrencies after being targeted by traffer scammers making them downloading an AMOS build from an already flagged fake project @VidoriumApp in a timestamp of ~2 hours. Sample from site available here:
2
16
50
Read about an ongoing malware campaign delivering "PayDay Loader" to Windows users and Poseidon Stealer to MacOS individuals on fake AI and software websites. A bit of malware analysis and threat hunting, thanks to @anyrun_app @urlscanio. π€ ππ.
5
16
62
After the announcement of seizure of some of the Lumma Stealer panel domains, new ones were opened shortly in the following hours. Please remember that the whole activity has not ceasedπ. /yuriy-andropov.com @ViriBack
0
1
12
After the announcement of seizure of some of the Lumma Stealer panel domains, new ones were opened shortly in the following hours. Please remember that the whole activity has not ceasedπ. /yuriy-andropov.com @ViriBack
First thoughts about #Lumma Stealer "disruption" (?):. There's no need in calling big names on something that (from what I've read and tested) has not happened in the magnitude I'm watching on the media. At the moment, Lumma still works, still has working C2s and *apparently* no
0
8
56
Let's have a look on the HTML content of one the seized Lumma panels before the seizure (/tsoi-zhiv.com). πMay 15th (normal).πMay 20th (changed). As we can see, the DOM content was modified to add this script. Someone messing
Lumma customers claim to have received this message on Telegram, apparently on Lumma customers group
5
5
58