vx_herm1t Profile Banner
herm1t Profile
herm1t

@vx_herm1t

Followers
5K
Following
3K
Media
246
Statuses
851

Демократична Сокира Ukrainian Cyber Alliance VX Heaven

Joined November 2020
Don't wanna be here? Send us removal request.
@vx_herm1t
herm1t
5 months
The Russian internet provider Nodex in St. Petersburg was completely looted and wiped. Data exfiltrated, while the empty equipment without backups was left to them
Tweet media one
16
245
2K
@vx_herm1t
herm1t
2 years
Just hacked into ru ransomware gang confluence :-)
Tweet media one
46
162
1K
@vx_herm1t
herm1t
2 years
PMC Wagner has announced that they have taken down the satellite provider Dozor-Teleport and damaged user terminals. Their rivalry with the RU MoD is manifesting in an unusual way. This is the second major satellite provider breach after Viasat
Tweet media one
30
357
1K
@vx_herm1t
herm1t
2 years
Tweet media one
8
58
727
@vx_herm1t
herm1t
3 years
just look who's back!
Tweet media one
10
109
471
@vx_herm1t
herm1t
10 months
@a__tkachuk Авжеж (і це не жарт)
Tweet media one
11
13
462
@vx_herm1t
herm1t
4 years
CIA's Hive backdoor listens all traffic waiting for the encrypted packet which will trigger reverse shell. This will stress load the CPU on target. Right thing to do is to set up BPF-filter on socket (marker is x * 1/x == 1):
Tweet media one
4
100
397
@vx_herm1t
herm1t
2 years
According to monitoring, Dozor is still down, and among their clients are Northern Fleet ships, a nuclear power plant, military units of the Ministry of Defense and the FSB in very remote locations. It is nice to see russians fighting amongst themselves.
Tweet media one
4
47
312
@vx_herm1t
herm1t
7 months
We took down the Tver administration's network. Dozens of virtual machines, backup storage, websites, email, hundreds of workstations – all wiped out. They have nothing left. The internet is down, phones aren’t working, even the parking system is dead
Tweet media one
Tweet media two
Tweet media three
Tweet media four
10
30
274
@vx_herm1t
herm1t
2 years
Trigone. The servers of the Trigona ransomware gang has been exfiltrated and wiped out by @UCA_ruhate_ Welcome to the world you created for others!
Tweet media one
10
63
269
@vx_herm1t
herm1t
2 years
The restoration of the core network may take from several days to several weeks, while reprogramming user equipment and fully restoring the service can take months (picture from internal dozor wiki published by hackers)
Tweet media one
4
34
225
@vx_herm1t
herm1t
2 years
I think that finding firmware for equipment in the midst of Arctic ice will not be easy
Tweet media one
3
12
188
@vx_herm1t
herm1t
2 years
The fact that wagneritte hackers started to 'work on ru' is simply priceless
Tweet media one
1
14
167
@vx_herm1t
herm1t
2 years
Where is the nearest Cisco consultant around here?
Tweet media one
1
12
149
@vx_herm1t
herm1t
5 months
Tweet media one
Tweet media two
Tweet media three
Tweet media four
5
8
180
@vx_herm1t
herm1t
5 months
They confirmed: "Last night, an attack was carried out on our infra (presumably from Ukraine). The network has been destroyed. We are restoring it from backups. There are no timelines or forecasts at the moment. Our priority is to first restore telephony and the call center"
Tweet media one
2
7
172
@vx_herm1t
herm1t
4 months
In the XZ backdoor a bitmap-trie is used for searching strings. But the simplest way to serialize the tree is to record it as S-expression. And if the branches are shuffled, we get polymorphism as a side effect
Tweet media one
6
36
171
@vx_herm1t
herm1t
3 years
Я знаю, все ждут постов, команд и все такое. Постов достаточно. Лучшая команду - от местного тро - какой хуйни не творить (список). И. Мы ищем доступ. Не ддос, не инфо, не дефейсы, этим есть кому заниматься. Доступы. И уже ищем. Это будет не быстро, не зрелищно, но неотвратимо.
8
26
145
@vx_herm1t
herm1t
2 years
@netblocks
NetBlocks
2 years
⚠️ Confirmed: Metrics show a disruption to satellite internet provider Dozor-Teleport which supplies Russia's FSB, Gazprom, Rosatom and military installations; the incident comes amid a wave of cyberattacks by a group claiming affiliation with Wagner PMC 🛰️📉
Tweet media one
2
16
102
@vx_herm1t
herm1t
4 years
i missed the zines, and glad that there is the. new one
Tweet media one
3
26
111
@vx_herm1t
herm1t
1 year
Meanwhile, we won in court, which ruled that we have no connection to the hacking of ODS airport, and that the police must return all seized items
Tweet media one
7
17
110
@vx_herm1t
herm1t
3 years
My fellow hackers an security pros you could help us here in Ukraine to #StopRussia If you knew any vulns in russian systems, contact me or @UCA_ruhate_ Together we will make Russia pay a heavy price.
10
27
90
@vx_herm1t
herm1t
2 years
Agreement between FSB and Dozortel
Tweet media one
2
7
79
@vx_herm1t
herm1t
2 years
@olliecarroll Butthurt of so called "good russians" clearly shows that our enemy is the entire russian nation, drown too deep in their jingoistic exceptionalism, so the NAFO black joke is indeed a good one.
1
3
86
@vx_herm1t
herm1t
4 years
ShadowBrokers or scam?
Tweet media one
6
26
87
@vx_herm1t
herm1t
2 years
dd'ing NSPK/Mir payment system twelve hours after the breach while admins watching top
Tweet media one
3
9
87
@vx_herm1t
herm1t
2 years
Dumping the "Russian Post"
Tweet media one
2
9
85
@vx_herm1t
herm1t
3 years
Ukrainian authorities prohibit citizens from using Starlink to maintain internet censorship. @elonmusk, JFYI
Tweet media one
10
22
83
@vx_herm1t
herm1t
10 months
C.A.S locked down russian identity provider Avanpost
Tweet media one
2
14
86
@vx_herm1t
herm1t
7 months
2
18
79
@vx_herm1t
herm1t
2 years
Mir payment system
Tweet media one
2
13
78
@vx_herm1t
herm1t
3 years
"Ukraine does not conduct offensive cyber operations but does conduct defensive ones"
Tweet media one
3
13
75
@vx_herm1t
herm1t
7 months
Tweet media one
Tweet media two
Tweet media three
Tweet media four
2
3
70
@vx_herm1t
herm1t
2 years
Інтерв'ю для ДОУ щодо атаки, захисту, хакерів та зловредної федерації.
4
10
70
@vx_herm1t
herm1t
1 year
Russian military mortgage service went down. hoster as well We saved call records the rest gone
Tweet media one
3
11
65
@vx_herm1t
herm1t
3 years
Rostelecom called ongoing cyber attacks on Russia "unprecedented" and "never seen before". That's just the beginning. Russia wanted to turn back the history and will return to stone age instead.
2
17
64
@vx_herm1t
herm1t
7 months
Tver admins (assessing the damage):.- We have some brandy somewhere. - Not enough
Tweet media one
2
2
68
@vx_herm1t
herm1t
2 years
1
11
53
@vx_herm1t
herm1t
1 year
Smart Consulting, which was developing software for government services in thirty regions of russia, was targeted by the Ukrainian Hacker Group
Tweet media one
6
10
62
@vx_herm1t
herm1t
2 years
Moscow-based provider Infotel, which facilitated communication between banks and the Central Bank of russia, has experienced an unexpected failure
4
13
62
@vx_herm1t
herm1t
4 years
just because I'm paranoid doesn't mean they're not out to get me. a bit chilling, less chilling than "Government-backed attack alerts" (seen 'em too)
Tweet media one
5
9
53
@vx_herm1t
herm1t
3 years
Unidentified persons posted data (possibly) stolen from the state portal Diia on RaidForums. And it looks real :-(
Tweet media one
5
28
61
@vx_herm1t
herm1t
8 months
Sanctioned russian company "PSB Innovations and Investements" (miltech) was hacked by UHG
Tweet media one
Tweet media two
2
11
62
@vx_herm1t
herm1t
4 years
I am not able to compete with @netspooky's 82 bytes ELF, but here is my version (84 bytes)
Tweet media one
2
9
57
@vx_herm1t
herm1t
2 years
Tweet media one
3
0
53
@vx_herm1t
herm1t
2 years
@Cyberknow20 An addition to your collection.
2
1
45
@vx_herm1t
herm1t
3 months
Sample data from carmoney 1k records, full set is 12TB of highly senitive PII, photos, credit cards and credit histories
Tweet media one
Tweet media two
Tweet media three
1
3
63
@vx_herm1t
herm1t
3 years
I like this design of the website of the Donetsk railway
Tweet media one
3
7
53
@vx_herm1t
herm1t
3 years
Found next to a blown up jeep.
Tweet media one
5
6
57
@vx_herm1t
herm1t
3 years
We at @UCA_ruhate_ have hacked one of the most important departments in Russia - the prison one. Let's start with "FSIN-Letter". Each letter has both the sender and recipient, and as you can see by the numbers, we have a lot of such letters. Sample
Tweet media one
2
11
46
@vx_herm1t
herm1t
3 months
Did they did some? If so, this is a new, unknown type of offensive in military science – completely harmless and undetectable by the enemy :-)
Tweet media one
4
6
56
@vx_herm1t
herm1t
5 months
@netblocks
NetBlocks
5 months
ℹ️ Confirmed: Metrics show that connectivity has collapsed on Russian internet operator Nodex, as the company reports a cyberattack from Ukraine resulting the destruction of its networks; the incident affecting fixed-line and mobile services is ongoing 📉
Tweet media one
1
3
55
@vx_herm1t
herm1t
3 years
Unlike russian blitzcringe, cyber is day-to-day job to seed disruption, deception and disorder in russia. Geo-fencing will not stop us.
Tweet media one
2
9
46
@vx_herm1t
herm1t
1 year
Today something "goes wrong" with
Tweet media one
Tweet media two
Tweet media three
2
3
50
@vx_herm1t
herm1t
4 years
The bug in the ukrainian state portal "Diia" allows you to specify any date in the vaccination certificate
Tweet media one
2
16
47
@vx_herm1t
herm1t
5 months
3
3
50
@vx_herm1t
herm1t
2 years
@BackAndAlive @Portmonecomua Пока больше похоже на киберпиздеж.
2
0
46
@vx_herm1t
herm1t
3 years
Tweet media one
2
1
45
@vx_herm1t
herm1t
4 years
If I were the author of ransomware I would read inodes directly from the file system's device. Just tried it on XFS, a few hundreds lines and it's damn fast.
3
2
45
@vx_herm1t
herm1t
3 years
FIDONet and UNIX-VIRUS mailing list archives @silviocesare
Tweet media one
4
18
47
@vx_herm1t
herm1t
4 years
@leonidragozin The same Menendez who once said that life in Donetsk is getting better because "the bodies are removed on time".
1
3
37
@vx_herm1t
herm1t
3 years
Russian bots in TG trying to pretend they are ukrainians. Extremely funny :-) #підлогакраїни
Tweet media one
4
2
38
@vx_herm1t
herm1t
3 years
Xaknet and Killnet are so upset by the failures of the Russian army that they hacked and mined Putin's Ferris wheel
6
7
37
@vx_herm1t
herm1t
4 months
Jia wanted stealth both in file and in memory. As funny as it sounds, this negatively impacted performance. If he had used a generating automaton instead, maybe no one noticed. And the code would be much simpler
Tweet media one
1
1
42
@vx_herm1t
herm1t
10 months
Four hundred VMs went down, 300G+ of data exfiltrated
Tweet media one
1
3
40
@vx_herm1t
herm1t
1 year
Russians constantly complain about "leaks" happening to them, everything breaking, falling apart, and malfunctioning. And we, at the Ukrainian Cyber Alliance, have encountered a significant problem as a result. We are running out of storage space . .
1
13
40
@vx_herm1t
herm1t
1 year
National cryptostandards will not help ruskiez with moskva1 passwords
Tweet media one
1
2
35
@vx_herm1t
herm1t
3 years
@EP_President @bert_hu_bert @Europarl_EN There is nothing “sophisticated” in ddos.
2
0
33
@vx_herm1t
herm1t
4 years
So called "cyberweapon" is extremely boring and bug-ridden. It's a miracle that spooks are able to achieve their goals with such lame malware :-).
1
2
37
@vx_herm1t
herm1t
1 year
welcomes muscovites to Crocus Hall
Tweet media one
1
5
35
@vx_herm1t
herm1t
5 months
@VZhora The result of years long efforts to improve security and resilience together with international partners. Vast experience. International cooperation. Oh, wait. .
1
1
36
@vx_herm1t
herm1t
3 years
Ministry of digital transformation used bot farm to flood my post about possible leak from Diia state app. Their embarrassment looks like confirmation of breach an leak
Tweet media one
2
6
35
@vx_herm1t
herm1t
3 years
C.A.S and DF broke into 1C
Tweet media one
3
8
33
@vx_herm1t
herm1t
1 year
UHG posted a sample from five hundred databases from which holds a third of the hosting market in Russia
Tweet media one
2
6
32
@vx_herm1t
herm1t
2 years
Tweet media one
2
0
34
@vx_herm1t
herm1t
2 years
@joetidy because they're so lame that they cannot do any harm beyond ddos anyway :-).
2
1
32
@vx_herm1t
herm1t
3 years
"highly sophisticated state-aligned ddos-botnet" #legion #vera
Tweet media one
1
5
31
@vx_herm1t
herm1t
3 years
btw, if one need to open a port without modifying the firewall rules, there is nice nf_register_net_hook function.
0
3
31
@vx_herm1t
herm1t
2 years
Героям слава!.
1
3
31
@vx_herm1t
herm1t
1 year
went down
Tweet media one
3
4
31
@vx_herm1t
herm1t
4 months
We are exhausted by c pointers
Tweet media one
1
0
31
@vx_herm1t
herm1t
1 year
A new useful book on my shelf because our russophobia is insufficient yet (thanks @alcomystic)
Tweet media one
1
2
31
@vx_herm1t
herm1t
8 months
LOL! :-)
Tweet media one
3
1
31
@vx_herm1t
herm1t
2 years
@shashj @ddd1ms Who kbiws? If the hack wasn't so significant, I wouldn't have posted it at all, because I consider the wagnerittes as bloody pigs.
2
0
26
@vx_herm1t
herm1t
11 months
There are two types of companies: those that already know they are attack vector, and those that have not yet realized it.
1
3
30
@vx_herm1t
herm1t
3 years
Got my hardware back
Tweet media one
3
1
31
@vx_herm1t
herm1t
2 years
@ddd1ms Well, let's see what the Wagner press service would say.
2
0
24
@vx_herm1t
herm1t
2 years
According to Russia Today, we are using SBU to wage war on Russia. What a wonderful nahryuk :-)
Tweet media one
5
6
29
@vx_herm1t
herm1t
4 months
One could use Vyssotsky rotating hash in bloom filter to find neccessary imports in symbol table
Tweet media one
2
5
29
@vx_herm1t
herm1t
3 years
@UCA_ruhate_ really like places where generals, ministers and press secretaries show documents at the entrance. I think that this person does not need to be introduced. While our counterparts are doxing lockheed, we will hack a bit through the russian "decision-making centers".
Tweet media one
1
6
25
@vx_herm1t
herm1t
3 years
Groups C.A.S., UCA and DF take responsibility for hacking the CSTO
Tweet media one
3
7
28
@vx_herm1t
herm1t
3 years
Вы кстати можете поучаствовать в ДДоС-атаках (сделали ребята из DC) или пораскидывать по заберебрику ссылки на двухсотых захватчиков
0
13
28
@vx_herm1t
herm1t
2 years
Just to show that we are deep inside russian networks, techspec of their USV
Tweet media one
1
7
28
@vx_herm1t
herm1t
3 years
Happy Data Privacy Day!
Tweet media one
1
3
26
@vx_herm1t
herm1t
2 years
One hundred years of modern crypto and special services and finally this :-)
Tweet media one
3
2
26
@vx_herm1t
herm1t
2 years
I have been asked to assist with the purchase of 0/N-days (not for criminal activities). I am ready to act as an escrow. The client is ready to spent up to one and a half million. If you have something, drop me a line with you contact here or in TG (herm1t_ruh8).
1
14
22
@vx_herm1t
herm1t
2 years
load shared object from memory, sort of
Tweet media one
0
3
25
@vx_herm1t
herm1t
2 years
Backups are gone.
Tweet media one
1
0
24
@vx_herm1t
herm1t
4 years
btw, routine for self-removal in Hive will never work as intended due to ETXTBSY, one need to unmap running executable first before wiping
1
2
23
@vx_herm1t
herm1t
2 years
@vxunderground LOL! "Zip archiving and encryption using XOR method, which eliminates the possibility of reading archive files by third parties even knowing the password, for example, by intercepting data transmitted over a communication channel or when a user loses removable media"
Tweet media one
4
2
22