Someone showed me this on Telegram. It is very silly. It is clearly masquerading as "Free GPT and Claude". Anyone with half a brain knows this is malicious, but people will still fall for it.
People asked what it is. I have some free time. I poked it with a stick,
People discussing it said it is XMRig. That is not entirely accurate. This is not XMRig. This is flagged as XMRig from Triage and VirusTotal because it does indeed drop XMRig, but it is much more than that. This is a (maybe new) information stealer packaged with XMRig as a double whammy.
This malware is interesting because of a few things:
1. It is position independent, they care enough to be evasive and strip out a majority of dependencies. This is usually indicative of more serious malware.
2. They .zip it delivers from the "Free GPT and Claude" is intentionally bloated (payload inflation). It is 97MB, which may evade a majority of anti-malware product (initially) due to it's large size. It packages itself with FFMpeg and various other audio codecs.
3. It accesses Microsoft Outlook e-mails, accesses Chrome stuff using the COM IElevationService, looks for any SFTP credentials
It (currently) does not have any matching YARA rules from AV vendors. The closest approximation is LummaStealer. My knowledge base on the Information Stealer scene is out-of-date (it changes a lot). However, on first initial glance this appears like a new information stealer. Again, this should be taken with a grain of salt.
It's also worth noting the domain it exfiltrates to does not appear in any malware reports. The domain is unique, and the payload does not match any existing YARA rules (it's behavioral characteristics do, but not a specific malware family), so this is actually a pretty interesting sample.
A lookup though shows this is an emerging malware campaign. It first appeared around the end of May. This is (probably) a known Threat Actor who has switched it up a bit (or it's MaaS, whatever though).
The malware appears online masquerading as various products.
- ecore-sourceproject
- LogiDA
- GPT_Claude_Free
- CortexSystems.v3.4.2.Stable
- TikTokBot-v2.2
- CortexLauncher
Funny enough, this malware would have been much, much, much, MUCH more evasive if they didn't package it with XMRig. VirusTotal and Triage immediately flagged it because after it establishes persistence, and steals any credentials on the machine, it pulls XMRig to turn into a cryptocurrency miner.
If they did not pull the XMRig binary this stealer would be much more quiet. I have no idea why they decided to burn their OPSEC with XMRig.
C2: dfwioeiofwr-dot-info
Payload (and associated families from the C2)
027d576c6b5512d661081aaeeeb8e611f95a469ccf5ba35e0a390e8814334d05
5dcc599cf48227e65ea49d2708d08704fd1cb7e3b89736718d0d8e557857c49c
5e8b40b0b7512e1a1355374fb0cf34bfdf1260ebdb80a353c8f9da2490beeed3
6a0c332296b017220fc2b522da653fce36a8a3c5c79de0200d61c5fc31eb89ce
a2f8ebf65d54a4d9c8b720d01da77ad796683f1a5b8bd3d08738d7df4365f8a
9d4aaa9842c947756b7c128c432292732098fb71d247ef0bce60368563572da3
c4caca93e2291c018e701c217b7d232c534e4dd142042a59aa4d32754ef3022a
People asked what it is. I have some free time. I poked it with a stick,
People discussing it said it is XMRig. That is not entirely accurate. This is not XMRig. This is flagged as XMRig from Triage and VirusTotal because it does indeed drop XMRig, but it is much more than that. This is a (maybe new) information stealer packaged with XMRig as a double whammy.
This malware is interesting because of a few things:
1. It is position independent, they care enough to be evasive and strip out a majority of dependencies. This is usually indicative of more serious malware.
2. They .zip it delivers from the "Free GPT and Claude" is intentionally bloated (payload inflation). It is 97MB, which may evade a majority of anti-malware product (initially) due to it's large size. It packages itself with FFMpeg and various other audio codecs.
3. It accesses Microsoft Outlook e-mails, accesses Chrome stuff using the COM IElevationService, looks for any SFTP credentials
It (currently) does not have any matching YARA rules from AV vendors. The closest approximation is LummaStealer. My knowledge base on the Information Stealer scene is out-of-date (it changes a lot). However, on first initial glance this appears like a new information stealer. Again, this should be taken with a grain of salt.
It's also worth noting the domain it exfiltrates to does not appear in any malware reports. The domain is unique, and the payload does not match any existing YARA rules (it's behavioral characteristics do, but not a specific malware family), so this is actually a pretty interesting sample.
A lookup though shows this is an emerging malware campaign. It first appeared around the end of May. This is (probably) a known Threat Actor who has switched it up a bit (or it's MaaS, whatever though).
The malware appears online masquerading as various products.
- ecore-sourceproject
- LogiDA
- GPT_Claude_Free
- CortexSystems.v3.4.2.Stable
- TikTokBot-v2.2
- CortexLauncher
Funny enough, this malware would have been much, much, much, MUCH more evasive if they didn't package it with XMRig. VirusTotal and Triage immediately flagged it because after it establishes persistence, and steals any credentials on the machine, it pulls XMRig to turn into a cryptocurrency miner.
If they did not pull the XMRig binary this stealer would be much more quiet. I have no idea why they decided to burn their OPSEC with XMRig.
C2: dfwioeiofwr-dot-info
Payload (and associated families from the C2)
027d576c6b5512d661081aaeeeb8e611f95a469ccf5ba35e0a390e8814334d05
5dcc599cf48227e65ea49d2708d08704fd1cb7e3b89736718d0d8e557857c49c
5e8b40b0b7512e1a1355374fb0cf34bfdf1260ebdb80a353c8f9da2490beeed3
6a0c332296b017220fc2b522da653fce36a8a3c5c79de0200d61c5fc31eb89ce
a2f8ebf65d54a4d9c8b720d01da77ad796683f1a5b8bd3d08738d7df4365f8a
9d4aaa9842c947756b7c128c432292732098fb71d247ef0bce60368563572da3
c4caca93e2291c018e701c217b7d232c534e4dd142042a59aa4d32754ef3022a
π₯105β€34π12π€£10π₯°5π―4π±2π’2
This is a tricky question and, in a bit of irony, there is a kind of like ... an unspoken ... or poorly documented philosophy of malware development. You kind of learn tricks of the trade as you write malware and witness malware campaigns operating in the wild.
tl;dr idk it depends on wtf ur doing bro
non-tl;dr
To be direct, malware that works is not necessarily good malware. You can write a simple Windows batch script that deletes every file in an important directory and (technically) this would be "wiper" malware. This does not make it good, or sophisticated.
Additionally, what defines "good" has changed over time. There tends to be trends with malware development. Malware tricks that used to work in the 90's are old news. Malware tricks from 2025 are old news (sort of). However, some malware tricks from the 90's are still applicable and can still be evasive.
It's weird.
You'll also see old tricks the 90's suddenly reappear and catch everyone off guard because... people simply forgot it even existed... The trick is usually only identified from industry veterans (or as the kids say, "unc" or "old heads") who are also surprised the trick has re-emerged. What's old is new. What's old is also old. What's new will eventually be old.
Anyway, "good malware" also depends on the objective. State-sponsored malware (malware written by governments, or written for government or military usage) has extremely strict rules of engagement (usually, not always, but usually). State-sponsored is usually extremely narrow in scope and designed for a very small and limited audience. State-sponsored may not necessarily be super advanced and cutting edge, but because it is so narrow in scope it is difficult to identify.
Conversely, financially motivated Threat Actors (malware developed for ... crime ...) is usually designed to be ass blasted in your face and sprayed across the internet.
Financially motivated Threat Actors will typically (if it's "good malware") design malware to be modular. In other words, because it is being blasted all over the internet it will be detected quickly, hence their malware needs to be broken down into almost like ... plugins ... and they need to have it so their malware can quickly replace one segment of code with another (and quickly).
If you've ever seen racing like NASCAR or F1, you'll notice vehicles can be torn apart in basically seconds and re-assembled, parts effortlessly replaced so it can quickly get back in the race. Likewise, modular malware needs to be able to change quickly to avoid it's inevitable detection. If you're curious, look up TrickBot, Emotet, or QakBot. They kind of defined what it means to be modular. They also kind of gave birth to what's known as "MaaS" (Malware-as-a-Service).
State-sponsored Threat Actors malware is trickier because it needs to be designed for a target. For example, when the United States (allegedly) targeted the Chinese government (allegedly) as APT NightEagle (allegedly) the malware was developed to work almost exclusively for specific Chinese infrastructure and (allegedly) contained exploits which would work in ideal scenarios which (allegedly) were that of Chinese critical infrastructure.
This can also be seen with what the Russian government alleges the United States and Israel (allegedly) did with Operation Triangulation whereas the malware (allegedly) only worked for specific sets of hardware (allegedly). Furthermore, this can also (allegedly) be seen with the United States (allegedly) purchasing cell phone malware from Israeli companies (allegedly) which were developed and sold to ICE (allegedly) to spy on people critical of ICE (allegedly).
These companies are called NSO Group and Intellexa Alliance.
Of course, the United States and Israel government vehemently deny the allegations from the Chinese and Russian government.
Okay, I have to stop writing and schizo ranting for the time being. I have to go back to watching a baby and stuff.
tl;dr idk it depends on wtf ur doing bro
non-tl;dr
To be direct, malware that works is not necessarily good malware. You can write a simple Windows batch script that deletes every file in an important directory and (technically) this would be "wiper" malware. This does not make it good, or sophisticated.
Additionally, what defines "good" has changed over time. There tends to be trends with malware development. Malware tricks that used to work in the 90's are old news. Malware tricks from 2025 are old news (sort of). However, some malware tricks from the 90's are still applicable and can still be evasive.
It's weird.
You'll also see old tricks the 90's suddenly reappear and catch everyone off guard because... people simply forgot it even existed... The trick is usually only identified from industry veterans (or as the kids say, "unc" or "old heads") who are also surprised the trick has re-emerged. What's old is new. What's old is also old. What's new will eventually be old.
Anyway, "good malware" also depends on the objective. State-sponsored malware (malware written by governments, or written for government or military usage) has extremely strict rules of engagement (usually, not always, but usually). State-sponsored is usually extremely narrow in scope and designed for a very small and limited audience. State-sponsored may not necessarily be super advanced and cutting edge, but because it is so narrow in scope it is difficult to identify.
Conversely, financially motivated Threat Actors (malware developed for ... crime ...) is usually designed to be ass blasted in your face and sprayed across the internet.
Financially motivated Threat Actors will typically (if it's "good malware") design malware to be modular. In other words, because it is being blasted all over the internet it will be detected quickly, hence their malware needs to be broken down into almost like ... plugins ... and they need to have it so their malware can quickly replace one segment of code with another (and quickly).
If you've ever seen racing like NASCAR or F1, you'll notice vehicles can be torn apart in basically seconds and re-assembled, parts effortlessly replaced so it can quickly get back in the race. Likewise, modular malware needs to be able to change quickly to avoid it's inevitable detection. If you're curious, look up TrickBot, Emotet, or QakBot. They kind of defined what it means to be modular. They also kind of gave birth to what's known as "MaaS" (Malware-as-a-Service).
State-sponsored Threat Actors malware is trickier because it needs to be designed for a target. For example, when the United States (allegedly) targeted the Chinese government (allegedly) as APT NightEagle (allegedly) the malware was developed to work almost exclusively for specific Chinese infrastructure and (allegedly) contained exploits which would work in ideal scenarios which (allegedly) were that of Chinese critical infrastructure.
This can also be seen with what the Russian government alleges the United States and Israel (allegedly) did with Operation Triangulation whereas the malware (allegedly) only worked for specific sets of hardware (allegedly). Furthermore, this can also (allegedly) be seen with the United States (allegedly) purchasing cell phone malware from Israeli companies (allegedly) which were developed and sold to ICE (allegedly) to spy on people critical of ICE (allegedly).
These companies are called NSO Group and Intellexa Alliance.
Of course, the United States and Israel government vehemently deny the allegations from the Chinese and Russian government.
Okay, I have to stop writing and schizo ranting for the time being. I have to go back to watching a baby and stuff.
β€92π₯°21π₯13π2π’1π―1π€£1π1
vx-underground
This is a tricky question and, in a bit of irony, there is a kind of like ... an unspoken ... or poorly documented philosophy of malware development. You kind of learn tricks of the trade as you write malware and witness malware campaigns operating in theβ¦
I love writing "allegedly" in these. It makes me giggle. The United States will be caught red handed and they're like, "nah, wasn't me" and everyone in cybersecurity is like, "damn..." then nothing happens.
Silly NSA and CIA doing silly stuff
Silly NSA and CIA doing silly stuff
π€£99π₯°15β€6π2π€2π₯1π1π’1π―1
Watching UFC 250 Freedom
They just announced Meta, with something from Mark Zuckerberg, are gifting Meta Glasses to every veteran who has poor eye sight or is blind
I don't trust it. I don't trust Zuckerberg. I don't trust the government.
They just announced Meta, with something from Mark Zuckerberg, are gifting Meta Glasses to every veteran who has poor eye sight or is blind
I don't trust it. I don't trust Zuckerberg. I don't trust the government.
β€115π28π―26π€11π4π€£3π₯°2π€2π’1
vx-underground
Arch Linux is still having supply-chain attacks and other misc. security issues. This is devastating to the over 25 people who use Arch as a daily driver.
I'm not going to lie: I've basically completely tuned out this Arch Linux supply chain attack stuff. I'm being dead ass serious when I say I can't FATHOM this having a widespread impact.
Seriously, this is your target? Nerds who compile kernels for fun? Wtf?
Seriously, this is your target? Nerds who compile kernels for fun? Wtf?
π€£117π’11π€9β€7π2π₯°1π1
Novo Nordisk has been compromised. Novo Nordisk has confirmed the compromise.
Novo Nordisk is the company that became famous after producing weight loss drugs like Ozempic and Wegovy
The Threat Actor(s) responsible for the attack has been playfully extorting Novo Nordisk (they're not being playful) and have unveiled some details regarding what was stolen.
Interestingly, it appears Novo Nordisk has it's own internal AI thing because some of the data stolen was stuff from their internal AI agents.
Data stolen (according to the Threat Actor):
- Trained model checkpoint (16GB)
- Proprietary training dataset (407MB)
- Full source code (modeling_novopert.py, training pipeline)
- 113 training runs with complete logs
- Internal infrastructure maps (HPC, Slurm, SSH)
- Container images (53GB+)
- Developer identities and internal hostnames
- Private GitHub repository URL
Novo Nordisk is the company that became famous after producing weight loss drugs like Ozempic and Wegovy
The Threat Actor(s) responsible for the attack has been playfully extorting Novo Nordisk (they're not being playful) and have unveiled some details regarding what was stolen.
Interestingly, it appears Novo Nordisk has it's own internal AI thing because some of the data stolen was stuff from their internal AI agents.
Data stolen (according to the Threat Actor):
- Trained model checkpoint (16GB)
- Proprietary training dataset (407MB)
- Full source code (modeling_novopert.py, training pipeline)
- 113 training runs with complete logs
- Internal infrastructure maps (HPC, Slurm, SSH)
- Container images (53GB+)
- Developer identities and internal hostnames
- Private GitHub repository URL
π€£56π14β€12π«‘8π1
vx-underground
Novo Nordisk has been compromised. Novo Nordisk has confirmed the compromise. Novo Nordisk is the company that became famous after producing weight loss drugs like Ozempic and Wegovy The Threat Actor(s) responsible for the attack has been playfully extortingβ¦
It is worth noting this compromise contains many elements which appear assisted by AI. I am making an educated guess and am going to state I believe these Threat Actors may have used AI to assist in this compromise (to an unknown extent).
π₯38π€10β€6π₯°1π’1
omggg i made a joke about only 25 people using arch and all the fucking arch nerds appeared like UHMM ERRM SCHMELLY, ID LIKE TO INTERJECT FOR A MOMENT ,,, ASHCTULALY ARCH IS P POPULAR AND ITS USED FOR STEAM AND
holy cannoli bro, shut uppppp. its a joke. fucking hell
holy cannoli bro, shut uppppp. its a joke. fucking hell
π€£202π12π₯11π«‘7β€5π€4π₯°3π1π1
vx-underground
omggg i made a joke about only 25 people using arch and all the fucking arch nerds appeared like UHMM ERRM SCHMELLY, ID LIKE TO INTERJECT FOR A MOMENT ,,, ASHCTULALY ARCH IS P POPULAR AND ITS USED FOR STEAM AND holy cannoli bro, shut uppppp. its a joke. fuckingβ¦
ERHMMM SCHMEEELY ITS USED BY ABOOT 10 PERCENT OF THE LIN...
i dont care bro, its a joke, save your factoids for someone else.
i dont care bro, its a joke, save your factoids for someone else.
π€£118π―17π€13π₯5π2π2β€1π₯°1π1π’1
This is absolutely disgusting content.
My Mother, an angel whom'st've never used a GNU or a Linux, was a devout Windows user. She was not a Linux.
Also, I am not a larp. I own several Gay Fox masks and have visited 4channel. I used Kali Linux twice (when my Mom wasn't looking), and have only given my ID verification to Instagram and Facebook.
Oh, and by the way, I encrypt my banking information using Coinbase Bitcoin.
I'm off the grid.
My Mother, an angel whom'st've never used a GNU or a Linux, was a devout Windows user. She was not a Linux.
Also, I am not a larp. I own several Gay Fox masks and have visited 4channel. I used Kali Linux twice (when my Mom wasn't looking), and have only given my ID verification to Instagram and Facebook.
Oh, and by the way, I encrypt my banking information using Coinbase Bitcoin.
I'm off the grid.
π€£308β€26π18π7β€βπ₯4π«‘4π₯1π₯°1π€―1π1
Tired of noobs complaining the WINAPI for malware development is weird. It's not.
How do you create a file?
The CreateFile function.
How do you open a file for reading?
The CreateFile function.
How do you open a file for writing?
The CreateFile function.
How do you get a handle to a directory?
The CreateFile function.
How do delete a file?
The CreateFile function.
How do you get access to a physical disk?
The CreateFile function.
How do you get access to a file stream?
The CreateFile function.
How do you get access to the console buffer?
The CreateFile function.
How do you get access to pipes?
The CreateFile function.
How do you perform interprocess communication?
The CreateFile function.
Just make sure you use the appropriate version of CreateFile (CreateFileA for ANSI, or CreateFileW for wide characters).
Alternatively, you can use CreateFile2 which is the same as CreateFile except the parameters are passed as a data structure named CREATEFILE2_EXTENDED_PARAMETERS. However, be aware CreateFile2 only works on Windows 8 and above and designed more or less for programs running from the Windows app store.
Alternatively, alternatively, you could use CreateFile3 which is nearly identical to CreateFile2 except it uses the CREATEFILE3_EXTENDED_PARAMETERS structure and is more or less designed for sandboxed packaged applications. However, be aware CreateFile3 only works on Windows11 24H2 and above.
It's shrimple, honestly.
How do you create a file?
The CreateFile function.
How do you open a file for reading?
The CreateFile function.
How do you open a file for writing?
The CreateFile function.
How do you get a handle to a directory?
The CreateFile function.
How do delete a file?
The CreateFile function.
How do you get access to a physical disk?
The CreateFile function.
How do you get access to a file stream?
The CreateFile function.
How do you get access to the console buffer?
The CreateFile function.
How do you get access to pipes?
The CreateFile function.
How do you perform interprocess communication?
The CreateFile function.
Just make sure you use the appropriate version of CreateFile (CreateFileA for ANSI, or CreateFileW for wide characters).
Alternatively, you can use CreateFile2 which is the same as CreateFile except the parameters are passed as a data structure named CREATEFILE2_EXTENDED_PARAMETERS. However, be aware CreateFile2 only works on Windows 8 and above and designed more or less for programs running from the Windows app store.
Alternatively, alternatively, you could use CreateFile3 which is nearly identical to CreateFile2 except it uses the CREATEFILE3_EXTENDED_PARAMETERS structure and is more or less designed for sandboxed packaged applications. However, be aware CreateFile3 only works on Windows11 24H2 and above.
It's shrimple, honestly.
π₯107π€£53β€16π₯°10π±7π4π4π’1
vx-underground
Tired of noobs complaining the WINAPI for malware development is weird. It's not. How do you create a file? The CreateFile function. How do you open a file for reading? The CreateFile function. How do you open a file for writing? The CreateFile function.β¦
Oh, I forgot, to create a directory you cannot use CreateFile. CreateFile is only used for getting access to a directory object. If you want to create a directory you need to use CreateDirectory or CreateDirectoryEx.
There is also OpenFile, which kind of acts similar to CreateFile, and you can also call DeleteFile instead of CreateFile with the FILE_FLAG_DELETE_ON_CLOSE flag.
There is also OpenFile, which kind of acts similar to CreateFile, and you can also call DeleteFile instead of CreateFile with the FILE_FLAG_DELETE_ON_CLOSE flag.
β€69π12π«‘7π€―3π€2π’1
BobDaHacker compromised FIFA and was able to hijack their livestream cameras.
They considered replacing the FIFA cameras with the 1987 hit classic "Never Gonna Give You Up" by Rick Astley. Instead, they reported it and FIFA immediately fixed the issue
https://bobdahacker.com/blog/fifa-hack
They considered replacing the FIFA cameras with the 1987 hit classic "Never Gonna Give You Up" by Rick Astley. Instead, they reported it and FIFA immediately fixed the issue
https://bobdahacker.com/blog/fifa-hack
Bobdahacker
I Could've Rickrolled the Entire FIFA World Cup. All I Needed Was My ID.
How I found that anyone could register on FIFA's public Agent Platform, gain access to the Football Data Platform's Streaming Management panel, and get RTMP ingest URLs and stream keys for every live FIFA World Cup 2026 camera feed. I then spent hours callingβ¦
π€£64π₯°57π’22β€4π₯4π3π±3π€―2π€©2π―1π€1
Chrome version 150 and 151, scheduled for deployment in the next 4 weeks or so, will remove the last references to ManifestV2.
Google Chrome developers wrote it is being removed because it is old tech-debt and is littered with vulnerabilities. The real answer is much more nuanced and would result in a discussion on "privacy", speed, software optimization, and code management.
Removing ManifestV2, for the newer ManifestV3, is architecturally more difficult for ad-blockers to be effective.
This has resulted in ad-blockers stopping support for Chromium.
Of course, with the final removal of ManifestV2, a majority of Chromium browsers (meaning, a vast majority of web browsers) will drop support for ad-blockers likely including Edge and Opera.
Google Chrome developers wrote it is being removed because it is old tech-debt and is littered with vulnerabilities. The real answer is much more nuanced and would result in a discussion on "privacy", speed, software optimization, and code management.
Removing ManifestV2, for the newer ManifestV3, is architecturally more difficult for ad-blockers to be effective.
This has resulted in ad-blockers stopping support for Chromium.
Of course, with the final removal of ManifestV2, a majority of Chromium browsers (meaning, a vast majority of web browsers) will drop support for ad-blockers likely including Edge and Opera.
π±63π’21π€£9π6π―6β€2π₯°2π1π€1
vx-underground
Chrome version 150 and 151, scheduled for deployment in the next 4 weeks or so, will remove the last references to ManifestV2. Google Chrome developers wrote it is being removed because it is old tech-debt and is littered with vulnerabilities. The real answerβ¦
If you want an actual explanation of ManifestV2 vs. ManifestV3
https://9to5google.com/2026/06/15/google-chromes-next-update-will-mark-the-end-of-popular-ad-blockers/
https://9to5google.com/2026/06/15/google-chromes-next-update-will-mark-the-end-of-popular-ad-blockers/
9to5Google
Google Chrome's next update will mark the end of popular ad blockers
Google Chromeβs move to Manifest V3 for extensions is closing its final loophole and, with it, bringing the end of...
π₯26π’11β€4π±1
> be pakistan government
> develop custom malware
> used to target high profile targets
> used against indian military and political ppl
> named SHEETCREEP
> send indian ppl file
> UAE-India Strategic Partnership Week
> malicious .lnk file
> .lnk executes malicious c sharp code
> does a bunch of stuff for persistence
> exfiltrates data to Google Sheets
> Google Sheets can be used to control victim pcs
> pakistan gov hardcodes google c2 sheet
> PAKISTAN GOV HARDCODES GOOGLE C2 SHEET
> embed access key in payload
> EMBED ACCESS KEY IN PAYLOAD
> malware nerds find it
> look inside
> find all targets from pakistan gov
> monitoring 91 ppl they think important
THEY STARTED SO STRONG. WHY DID YOU HARDCODE EVERYTHING. YOU BURNED YOUR OPERATION
https://www.securonix.com/blog/sheetcreep-evolved-google-sheets-rat/
> develop custom malware
> used to target high profile targets
> used against indian military and political ppl
> named SHEETCREEP
> send indian ppl file
> UAE-India Strategic Partnership Week
> malicious .lnk file
> .lnk executes malicious c sharp code
> does a bunch of stuff for persistence
> exfiltrates data to Google Sheets
> Google Sheets can be used to control victim pcs
> pakistan gov hardcodes google c2 sheet
> PAKISTAN GOV HARDCODES GOOGLE C2 SHEET
> embed access key in payload
> EMBED ACCESS KEY IN PAYLOAD
> malware nerds find it
> look inside
> find all targets from pakistan gov
> monitoring 91 ppl they think important
THEY STARTED SO STRONG. WHY DID YOU HARDCODE EVERYTHING. YOU BURNED YOUR OPERATION
https://www.securonix.com/blog/sheetcreep-evolved-google-sheets-rat/
Securonix
SHEET#CREEP Espionage Return
Securonix Threat Research: Securonix analyzes SHEET#CREEP, a stealthy RAT that uses Google Sheets as a command-and-control channel, enabling persistent access, espionage, and cloud-based evasion.
π62π€£55β€13π₯6π€―3π’2