Who said what?
@g0njxa
Followers
5K
Following
5K
Media
1K
Statuses
3K
ChatGPT says I'm a cyber researcher :) | donate πΈ to g0njxa.eth π | Bad student, enthusiast, defo not an expert DMs are open, feel free to reach! πΌβοΈπ£
Valencia, Spain πͺπΈ
Joined January 2023
In the past weeks I interviewed the staff from the major infostealers projects, a total of 7: Lumma,Raccoon,Meduza,Vidar,Amadey,StealC,Meta. Below you will find a short summary of this series that ends today, and also the ones who refused to talk. ππ https://t.co/MPtxQmstxI
g0njxa.medium.com
Consider this the end of a series that lasted a few weeks. I tried to contact almost everyone related to the infostealer ecosystem, that Iβ¦
6
20
121
Featuring one of the most cool interviews with a MacOS infostealer developer, because βmacOS is the safest system and has no viruses.β Collaboration with @osint_barbie ππ€© No more spoilers today, read now a interview with Phexia: https://t.co/3GFnN3n4Jg
g0njxa.medium.com
To completely understand whatβs going on in a market that has been growing in the last years I found mandatory to know which players areβ¦
3
19
76
A short interview with XFILES (also known by researchers as DeerStealer) π¦ Since 2021 on the playground, alledgelling offering multiple malware solution for both Windows but recently also MacOS π Read here ππ https://t.co/jbRTvTx6Wl
g0njxa.medium.com
To completely understand whatβs going on in a market that has been growing in the last years I found mandatory to know which players areβ¦
3
7
42
BTW good time to feature some past posts https://t.co/2G2Tzv3ZGO
https://t.co/ICrb7iZPqp
https://t.co/nC724ZaZZB
Have you ever seen a #Rhadamanthys panel? #Rhadamanthys Stealer offers a web-based panel hosted in the TOR network. Today you will be able to see a v0.5.0 panel. Here you can see how everything looks: (But make sure to check the analysis from @hasherezade first!) 1/3 π
0
0
8
1 week after the the operation on Rhadamanthys, it seems to be more disruptive than the one did on Lumma (which should be a good comparation) since the infostealer has not returned soon. So it seems we can start talking about another one missing on the Internet, at least for
First thoughts about #Rhadamanthys Stealer "disruption" (?) and what to expect in the next days with the current information as of November 13th: The same way I did with Lumma I want to share some words ( https://t.co/t5wpfVCa85) Leaving to one side from the discussion anything
2
10
36
Infostealers are a global issue and are feeding up other kind of crimes worldwide, its not a one country thing. You may see in the recent news (see video) how a major scam hub was blew out in Myanmar after being raided, 346 detained and +10.000 phones confiscated, the second
1
4
41
First thoughts about #Rhadamanthys Stealer "disruption" (?) and what to expect in the next days with the current information as of November 13th: The same way I did with Lumma I want to share some words ( https://t.co/t5wpfVCa85) Leaving to one side from the discussion anything
Confirmed rumours about targeting Rhadamanthys, customers messaged by Dutch Police, associated domains displaying a seized banner #Endgame π
0
11
49
Confirmed rumours about targeting Rhadamanthys, customers messaged by Dutch Police, associated domains displaying a seized banner #Endgame π
3
17
94
More rumours! (βοΈ?) Rhadamanthys customer message: Dear <redacted>, International law enforcement agencies have designated Rhadamanthys as a target under OPERATION ENDGAME. Our data points to your possible involvement with Rhadamanthys. This information has been recorded by
Multiple unknown affirmations of a major blow on Rhadamanthys Stealer infrastructure while admin urges to pause work and reinstall servers, and users reportedly finding problems to login into control panels Rhadamanthys main onion domains are unavailable as for now This is a
3
14
67
Multiple unknown affirmations of a major blow on Rhadamanthys Stealer infrastructure while admin urges to pause work and reinstall servers, and users reportedly finding problems to login into control panels Rhadamanthys main onion domains are unavailable as for now This is a
Rumors are spreading about a mayor #LawEnforcement operation against #Rhadamanthys #Stealer. @g0njxa and me have been monitoring the situation closely. -Rhada domains under active law enforcement control - Customers are adviced to delete all servers Image via club1337
4
16
92
Danabot is back recently as reported with new updates, see statements and demo video below: "We have launched a new version of the product with a global system update. Now users of the staff tariff can use our own loader, as well as a new bot installation system. There are a lot
Danabot has resurfaced with version 669 after nearly a 6 month hiatus following the Operation Endgame law enforcement actions in May. The current C2s are the following: 62.60.226[.]146:443 62.60.226[.]154:443 80.64.19[.]39:443
18
23
90
More #Grandoreiro targeting Spain πͺπΈπͺπΈ, impersonating Hospital @Hospital_FJD @quironsalud and a (fake? π) law firm. Using spoofed emails Deliver landing /vmi2895023.contaboserver.net >> /vmi2895024.contaboserver.net C2: 3.238.96.208:5874 nextgenpass.hopto[.]me Analysis:
New #Grandoreiro campaign impersonating AEAT (National Tax agency) geo target Spain πͺπΈπͺπΈ Deliver page /vmi2895604.contaboserver.net C2 44.192.48.117:7432 techscalemaster.privatizehealthinsurance[.]net Analysis: https://t.co/3ru4VkW9rK Samples: https://t.co/amkWkmbCsb
0
13
41
America needs you! Join U.S. Immigration and Customs Enforcement today.
2K
3K
19K
New #Grandoreiro campaign impersonating AEAT (National Tax agency) geo target Spain πͺπΈπͺπΈ Deliver page /vmi2895604.contaboserver.net C2 44.192.48.117:7432 techscalemaster.privatizehealthinsurance[.]net Analysis: https://t.co/3ru4VkW9rK Samples: https://t.co/amkWkmbCsb
#Grandoreiro Geo target πͺπΈπͺπΈ November 2025 Email > Landing download > ISO > .vbs > Grandoreiro Analysis: https://t.co/m1CqgaTM89 IOCs: launchboosthub.myactivedirectory[.]com 3.231.226.146:5871 growthmodelabs.net-freaks[.]com 44.192.46.125:7432
0
8
30
#Grandoreiro Geo target πͺπΈπͺπΈ November 2025 Email > Landing download > ISO > .vbs > Grandoreiro Analysis: https://t.co/m1CqgaTM89 IOCs: launchboosthub.myactivedirectory[.]com 3.231.226.146:5871 growthmodelabs.net-freaks[.]com 44.192.46.125:7432
β οΈ#INCIBEaviso | No es #Iberdrola quien estΓ‘ enviando estos correos. Si necesitas acceder a tu factura, accede mediante la #app o su web oficial. Visita el aviso para saber mΓ‘s: https://t.co/O1qb3bF55r
#AvisosDeSeguridad #CiudadanΓa
1
15
36
GIVEAWAY UPDATE! πβ₯οΈπ€ The winner has been selected and itβs @0x2asec π Apologies for the few days delay in announcing β it took us a bit longer to contact and get the books shipped (PS. Vol I & II of The Art of Mac Malware by @patrickwardle are already on their way π¦)
GIVEAWAY TIME! πβ₯οΈπ€ In case you missed the opportunity to grab yours, celebrating the success of #OBTS V8 in Ibiza πͺπΈ @objective_see (@andyrozen), and special thanks to @osint_barbie, we will be holding a giveaway of @patrickwardle "The art of Mac Malware" books - Vol. I
0
3
17
A interview with AURA stealer, a new emerging malware solution to have a look over the next months Read now here ππ https://t.co/H1QsGAHn2g
g0njxa.medium.com
To completely understand whatβs going on in a market that has been growing in the last years I found mandatory to know which players areβ¦
2
7
41
Reports of the detainment of three people behind the infamous Meduza Stealer (interviewed back in 2023 - https://t.co/TIo21TlJVE) in the Moscow region, Russia π·πΊ, accused of "gain unauthorized access to data of one of the institutions in the Astrakhan region in May of this year"
3
7
54
The bulk of the void that AMOS fading left into the MacOS MaaS infostealers is already being filled by other solutions such as MacSync (interviewed by @osint_barbie and I recently: https://t.co/cKrFyqBQlZ), who allegedly want to be "at AMOS level by the end of the year". In
A interview with recently rebranded MacSync, also known as Mac.c Stealer by mentalpositive. Colab with @osint_barbie π€ An emerging, cheaper and trendy MaaS solution for MacOS environments which usage is increasing in the last months. Read now ππ€: https://t.co/BAwQinOEdn
4
16
46
Currently seeing a surge on #CastleLoader malware being delivered through fake websites impersonating software used in enterprise environments such as Zabbix or RVTools (see photo 1 & 2). IOCS below πΎπ Please note that this campaign uses the same exact template lures of
2
25
85
GIVEAWAY TIME! πβ₯οΈπ€ In case you missed the opportunity to grab yours, celebrating the success of #OBTS V8 in Ibiza πͺπΈ @objective_see (@andyrozen), and special thanks to @osint_barbie, we will be holding a giveaway of @patrickwardle "The art of Mac Malware" books - Vol. I
4
9
49