g0njxa Profile Banner
Who said what? Profile
Who said what?

@g0njxa

Followers
5K
Following
5K
Media
979
Statuses
3K

ChatGPT says I'm a cyber researcher :) | donate πŸ’Έ to g0njxa.eth πŸ’– | Bad student, enthusiast, defo not an expert DMs are open, feel free to reach! πŸ˜Όβ˜‚οΈπŸŸ£

Valencia, Spain πŸ‡ͺπŸ‡Έ
Joined January 2023
Don't wanna be here? Send us removal request.
@g0njxa
Who said what?
2 years
In the past weeks I interviewed the staff from the major infostealers projects, a total of 7: Lumma,Raccoon,Meduza,Vidar,Amadey,StealC,Meta. Below you will find a short summary of this series that ends today, and also the ones who refused to talk. πŸ‘€πŸ‘‡.
4
20
110
@g0njxa
Who said what?
10 days
StealC V2 issued an update recently:. Featuring enhanced app-bound decryption of browser password and cookies, and a panel Rest API for clients. Changelog πŸ‘‡πŸ‘‡
Tweet media one
Tweet media two
Tweet media three
@g0njxa
Who said what?
2 months
StealC v2 infostealer updated recently:. featuring "decryption of Google Chrome v135 passwords". and also removing the thing we reported days before 😜
Tweet media one
Tweet media two
1
5
40
@g0njxa
Who said what?
10 days
He replied backπŸ€·β€β™‚οΈ:. @saiyangod0x says: Why malware? Is your purpose to create or destroy?. Everyone has their own standards of morality, my belief is that without destroying something, something new will not be built. @vxdb says: How did you get into malware development?.
@g0njxa
Who said what?
1 month
Some active malware coder has accepted to do a "Questions & Answers" for the infosec community. He has been active for some years, serving and developing malware to individuals and on traffer teams. What you will ask him? Share it in the comments!πŸ“£πŸ“.Soon in a blog.
5
2
31
@g0njxa
Who said what?
13 days
Just been across interesting signed MSI files creating persistence via VMI and hiding a C2 server on a Ethereum Smart Contract (sending botnet information), also installing Anydesk for Remote Access. Detonation: Stages: .(Photo 1) MSI file drops Anydesk
Tweet media one
Tweet media two
Tweet media three
1
8
46
@g0njxa
Who said what?
16 days
Read about "Meowsterio" - The comeback of an OG traffer's group and it's own malware campaign targeting crypto users worldwide. Featuring the use of ClickOnce applications to bypass Windows SmartScreen without using EV certificates βš™οΈ. Read now πŸ‘‡πŸ‘‡:.
3
11
34
@g0njxa
Who said what?
16 days
RT @NexusFuzzy: I found a what I think novel approach which allowed me to list some of the content of #Lumma #Infostealer Command & Control….
0
26
0
@g0njxa
Who said what?
25 days
An Spanish πŸ‡ͺπŸ‡Έ individual and MacOS user just lost over $62k in cryptocurrencies after being targeted by traffer scammers making them downloading an AMOS build from an already flagged fake project @VidoriumApp in a timestamp of ~2 hours. Sample from site available here:
Tweet media one
Tweet media two
2
16
50
@g0njxa
Who said what?
29 days
RT @fofabot: Exciting news!πŸ₯³πŸ₯³.We've launched FOFA AI beta ver, an automatical attack surface discovery platform powered by AI Agents. If i….
0
15
0
@g0njxa
Who said what?
30 days
The infamous CC and access market "BidenCash" apparently had its domain seized by Law Enforcement in the past hours, the store is allegedly down. Clearnet domain "/bidencash.asia" and onion (which now redirects to "/bidencash.usssdomainseizure.com") displays a seizure banner.
Tweet media one
Tweet media two
Tweet media three
0
11
49
@g0njxa
Who said what?
1 month
Some active malware coder has accepted to do a "Questions & Answers" for the infosec community. He has been active for some years, serving and developing malware to individuals and on traffer teams. What you will ask him? Share it in the comments!πŸ“£πŸ“.Soon in a blog.
11
8
54
@g0njxa
Who said what?
1 month
Read about an ongoing malware campaign delivering "PayDay Loader" to Windows users and Poseidon Stealer to MacOS individuals on fake AI and software websites. A bit of malware analysis and threat hunting, thanks to @anyrun_app @urlscanio. πŸ€ πŸ‘‡πŸ‘‡.
5
16
62
@g0njxa
Who said what?
1 month
Message from the administrator of Lumma Stealer on the forums about the recent eventsπŸ•ŠοΈπŸ‘€
Tweet media one
Tweet media two
@g0njxa
Who said what?
1 month
Apparent new message from LE about the Lumma Stealer situation πŸ‘‡πŸ‘‡
Tweet media one
Tweet media two
Tweet media three
7
33
164
@g0njxa
Who said what?
1 month
Apparent new message from LE about the Lumma Stealer situation πŸ‘‡πŸ‘‡
Tweet media one
Tweet media two
Tweet media three
@g0njxa
Who said what?
1 month
Lumma customers claim to have received this message on Telegram, apparently on Lumma customers group
Tweet media one
Tweet media two
0
12
83
@g0njxa
Who said what?
1 month
ping @ViriBack more #Lumma Stealer πŸ•ŠοΈ. /fedor-dostoevskiy.com/login
Tweet media one
Tweet media two
@g0njxa
Who said what?
1 month
After the announcement of seizure of some of the Lumma Stealer panel domains, new ones were opened shortly in the following hours. Please remember that the whole activity has not ceasedπŸ‘€. /yuriy-andropov.com @ViriBack
Tweet media one
Tweet media two
0
1
12
@g0njxa
Who said what?
1 month
After the announcement of seizure of some of the Lumma Stealer panel domains, new ones were opened shortly in the following hours. Please remember that the whole activity has not ceasedπŸ‘€. /yuriy-andropov.com @ViriBack
Tweet media one
Tweet media two
@g0njxa
Who said what?
1 month
First thoughts about #Lumma Stealer "disruption" (?):. There's no need in calling big names on something that (from what I've read and tested) has not happened in the magnitude I'm watching on the media. At the moment, Lumma still works, still has working C2s and *apparently* no
Tweet media one
Tweet media two
Tweet media three
0
8
56
@g0njxa
Who said what?
1 month
Let's have a look on the HTML content of one the seized Lumma panels before the seizure (/tsoi-zhiv.com). πŸ‘‰May 15th (normal).πŸ‘‰May 20th (changed). As we can see, the DOM content was modified to add this script. Someone messing
Tweet media one
@g0njxa
Who said what?
1 month
Lumma customers claim to have received this message on Telegram, apparently on Lumma customers group
Tweet media one
Tweet media two
5
5
58
@g0njxa
Who said what?
1 month
Lumma customers claim to have received this message on Telegram, apparently on Lumma customers group
Tweet media one
Tweet media two
@g0njxa
Who said what?
1 month
Seems like some #Lumma Stealer panels have started to display a banner of seizure. /tsoi-zhiv.com./anna-akhmatova.com
Tweet media one
Tweet media two
7
36
227