home.social

#infobloxthreatintel — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #infobloxthreatintel, aggregated by home.social.

  1. Solicitar senha. Solicitar token. Token inválido. Aguardar.

    That's the full operator menu for VX-Pack — a Brazilian-origin AiTM phishing-as-a-service kit targeting banks in Brazil and Portugal. Request password. Request token. Invalid token (ask again). Wait. One operator, one victim, one browser, in real time.

    Nearly every AiTM kit — Evilginx, Tycoon 2FA, EvilProxy — is a reverse proxy. It silently relays traffic to the real bank, grabs the session cookie, and that's your 2FA bypass. VX-Pack is a different animal: a replica site, not a relay. The operator watches the victim fill each field over a WebSocket connection, replays the credentials against the real bank themselves, and if the OTP expires mid-attempt — tokeninvalido — the kit asks the victim for another one.

    No session cookie theft. No relay fingerprint at the bank. The bank's anti-proxy controls see traffic from the operator's own machine. "It passed the bank's fraud detection" is not the assurance it sounds like.

    Active since at least January 2025, sold as PhaaS by one developer to multiple buyers running their own campaigns. Impersonates Banco Santander and more than ten other financial institutions and payment platforms across Brazil and Portugal.

    Screenshots below show one of the phishing pages impersonating Banco Santander, as well as screenshots from a walkthrough video recorded by the kit's developer. Victim flow on one side, operator panel on the other.

    Phishing domains:
    ⛔️ pactualapp[.]com
    ⛔️ pactualpj[.]com
    ⛔️ pactual[.]live
    ⛔️ ativarbia[.]net
    ⛔️ ativarbia[.]com
    ⛔️ pactualapp[.]live
    ⛔️ centraldecancelamentos[.]pt
    ⛔️ verificador-cliente[.]live
    ⛔️ ativador-login[.]click

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #phishing #aitm

  2. Solicitar senha. Solicitar token. Token inválido. Aguardar.

    That's the full operator menu for VX-Pack — a Brazilian-origin AiTM phishing-as-a-service kit targeting banks in Brazil and Portugal. Request password. Request token. Invalid token (ask again). Wait. One operator, one victim, one browser, in real time.

    Nearly every AiTM kit — Evilginx, Tycoon 2FA, EvilProxy — is a reverse proxy. It silently relays traffic to the real bank, grabs the session cookie, and that's your 2FA bypass. VX-Pack is a different animal: a replica site, not a relay. The operator watches the victim fill each field over a WebSocket connection, replays the credentials against the real bank themselves, and if the OTP expires mid-attempt — tokeninvalido — the kit asks the victim for another one.

    No session cookie theft. No relay fingerprint at the bank. The bank's anti-proxy controls see traffic from the operator's own machine. "It passed the bank's fraud detection" is not the assurance it sounds like.

    Active since at least January 2025, sold as PhaaS by one developer to multiple buyers running their own campaigns. Impersonates Banco Santander and more than ten other financial institutions and payment platforms across Brazil and Portugal.

    Screenshots below show one of the phishing pages impersonating Banco Santander, as well as screenshots from a walkthrough video recorded by the kit's developer. Victim flow on one side, operator panel on the other.

    Phishing domains:
    ⛔️ pactualapp[.]com
    ⛔️ pactualpj[.]com
    ⛔️ pactual[.]live
    ⛔️ ativarbia[.]net
    ⛔️ ativarbia[.]com
    ⛔️ pactualapp[.]live
    ⛔️ centraldecancelamentos[.]pt
    ⛔️ verificador-cliente[.]live
    ⛔️ ativador-login[.]click

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #phishing #aitm

  3. Solicitar senha. Solicitar token. Token inválido. Aguardar.

    That's the full operator menu for VX-Pack — a Brazilian-origin AiTM phishing-as-a-service kit targeting banks in Brazil and Portugal. Request password. Request token. Invalid token (ask again). Wait. One operator, one victim, one browser, in real time.

    Nearly every AiTM kit — Evilginx, Tycoon 2FA, EvilProxy — is a reverse proxy. It silently relays traffic to the real bank, grabs the session cookie, and that's your 2FA bypass. VX-Pack is a different animal: a replica site, not a relay. The operator watches the victim fill each field over a WebSocket connection, replays the credentials against the real bank themselves, and if the OTP expires mid-attempt — tokeninvalido — the kit asks the victim for another one.

    No session cookie theft. No relay fingerprint at the bank. The bank's anti-proxy controls see traffic from the operator's own machine. "It passed the bank's fraud detection" is not the assurance it sounds like.

    Active since at least January 2025, sold as PhaaS by one developer to multiple buyers running their own campaigns. Impersonates Banco Santander and more than ten other financial institutions and payment platforms across Brazil and Portugal.

    Screenshots below show one of the phishing pages impersonating Banco Santander, as well as screenshots from a walkthrough video recorded by the kit's developer. Victim flow on one side, operator panel on the other.

    Phishing domains:
    ⛔️ pactualapp[.]com
    ⛔️ pactualpj[.]com
    ⛔️ pactual[.]live
    ⛔️ ativarbia[.]net
    ⛔️ ativarbia[.]com
    ⛔️ pactualapp[.]live
    ⛔️ centraldecancelamentos[.]pt
    ⛔️ verificador-cliente[.]live
    ⛔️ ativador-login[.]click

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #phishing #aitm

  4. Solicitar senha. Solicitar token. Token inválido. Aguardar.

    That's the full operator menu for VX-Pack — a Brazilian-origin AiTM phishing-as-a-service kit targeting banks in Brazil and Portugal. Request password. Request token. Invalid token (ask again). Wait. One operator, one victim, one browser, in real time.

    Nearly every AiTM kit — Evilginx, Tycoon 2FA, EvilProxy — is a reverse proxy. It silently relays traffic to the real bank, grabs the session cookie, and that's your 2FA bypass. VX-Pack is a different animal: a replica site, not a relay. The operator watches the victim fill each field over a WebSocket connection, replays the credentials against the real bank themselves, and if the OTP expires mid-attempt — tokeninvalido — the kit asks the victim for another one.

    No session cookie theft. No relay fingerprint at the bank. The bank's anti-proxy controls see traffic from the operator's own machine. "It passed the bank's fraud detection" is not the assurance it sounds like.

    Active since at least January 2025, sold as PhaaS by one developer to multiple buyers running their own campaigns. Impersonates Banco Santander and more than ten other financial institutions and payment platforms across Brazil and Portugal.

    Screenshots below show one of the phishing pages impersonating Banco Santander, as well as screenshots from a walkthrough video recorded by the kit's developer. Victim flow on one side, operator panel on the other.

    Phishing domains:
    ⛔️ pactualapp[.]com
    ⛔️ pactualpj[.]com
    ⛔️ pactual[.]live
    ⛔️ ativarbia[.]net
    ⛔️ ativarbia[.]com
    ⛔️ pactualapp[.]live
    ⛔️ centraldecancelamentos[.]pt
    ⛔️ verificador-cliente[.]live
    ⛔️ ativador-login[.]click

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #phishing #aitm

  5. Solicitar senha. Solicitar token. Token inválido. Aguardar.

    That's the full operator menu for VX-Pack — a Brazilian-origin AiTM phishing-as-a-service kit targeting banks in Brazil and Portugal. Request password. Request token. Invalid token (ask again). Wait. One operator, one victim, one browser, in real time.

    Nearly every AiTM kit — Evilginx, Tycoon 2FA, EvilProxy — is a reverse proxy. It silently relays traffic to the real bank, grabs the session cookie, and that's your 2FA bypass. VX-Pack is a different animal: a replica site, not a relay. The operator watches the victim fill each field over a WebSocket connection, replays the credentials against the real bank themselves, and if the OTP expires mid-attempt — tokeninvalido — the kit asks the victim for another one.

    No session cookie theft. No relay fingerprint at the bank. The bank's anti-proxy controls see traffic from the operator's own machine. "It passed the bank's fraud detection" is not the assurance it sounds like.

    Active since at least January 2025, sold as PhaaS by one developer to multiple buyers running their own campaigns. Impersonates Banco Santander and more than ten other financial institutions and payment platforms across Brazil and Portugal.

    Screenshots below show one of the phishing pages impersonating Banco Santander, as well as screenshots from a walkthrough video recorded by the kit's developer. Victim flow on one side, operator panel on the other.

    Phishing domains:
    ⛔️ pactualapp[.]com
    ⛔️ pactualpj[.]com
    ⛔️ pactual[.]live
    ⛔️ ativarbia[.]net
    ⛔️ ativarbia[.]com
    ⛔️ pactualapp[.]live
    ⛔️ centraldecancelamentos[.]pt
    ⛔️ verificador-cliente[.]live
    ⛔️ ativador-login[.]click

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #phishing #aitm

  6. One tap to continue watching. Also: one tap to charge your phone bill €4.50. Click2SMS, what good are you, anyway?

    A redirect chain took us from a compromised legitimate site, through help_tds, then through a familiar Germany-based commercial TDS, to hmtraff[.]com where we finally arrived at d[.]gosmartdecision[.]com — part of an IRSF ecosystem we've been tracking since our fake CAPTCHA report.

    The landing page shows a fake video player. A large "Continue" button sits in front of it. That button is <a href="sms:81183?body=360 *CWZQ...">. One tap opens the SMS app, pre-loaded with a message to a premium-rate French shortcode. 4.50 EUR per code.

    Where the fake CAPTCHA required four separate actions to maintain a verification illusion, the video player needs one. Simpler, faster, probably more effective. The legal disclosure with the price is below the fold in 10pt text, while the large "Continue" button is in the middle of the screen.

    There's a second bonus layer: the page runs device fingerprinting and injects a credit card collection form for non-mobile visitors — cardholder name, number, CVV, expiry. Mobile French users see the Click2SMS flow. Others may get card phishing. Two modes. One domain. DNS-visible delivery chain throughout.

    hmtraff[.]com
    d[.]gosmartdecision[.]com

    Final landing page: urlscan.io/result/019f14b2-c99

    Prior report: infoblox.com/blog/threat-intel

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #smishing #tds #irsf

  7. Stolen phones - and specifically iPhones - have robust anti-theft protections. They are worthless once they're flagged - locked to their owner. So why are millions still being stolen every year?
    In this paper, we uncover a thriving underground marketplace focused on unlocking stolen phones. It is powered by:

    Lookalike domains impersonating Apple, Xiaomi, Samsung and other brands
    Smishing campaigns targeting device owners
    Pay‑as‑you‑go “unlocking” tools sold on Telegram
    By pivoting on DNS data, we identified 10,000+ malicious domains and a growing ecosystem turning locked devices into profit at scale.

    👉 Read how this supply chain works—from theft to resale—and why it’s growing fast. infoblox.com/blog/threat-intel

    #ThreatIntel #CyberSecurity #Phishing #MobileSecurity #iOS #Smishing #dns #threatintelligence #cybercrime #infosec #infoblox #infobloxthreatintel #threatintelligence #cybercrime  #infosec #infoblox #infobloxthreatintel

  8. Trust this “Amazon” phishing email in Japan—and you’re Prime sashimi 🎣 🍣

    Looking into our malspam data, we identified an active campaign impersonating Amazon and targeting Japanese citizens. The emails use subjects such as 「至急 Amazonプライム会員情報の確認」 (“Urgent: Confirm Amazon Prime member information”).

    The URLs within the emails ultimately lead to an Amazon phishing page, but only after routing victims through a TDS. Interestingly, instead of keeping the TDS step invisible, the actors chose to show it off—repackaging it as a reassuring security check.

    Upon clicking the link within the email, victims are first redirected to an RDGA TDS domain, where fingerprinting occurs. If the user does not match the targeting criteria (e.g., connecting from outside Japan), access is blocked. If they do match, potential victims are redirected to a second RDGA domain.
    This second and last domain is not a TDS domain, but funny enough, these actors decided they would emulate it anyway!

    At that step victims are already at the landing page but instead of immediately displaying a standard Amazon phishing page, the website displays a CAPTCHA and fake console interface simulating environment fingerprinting checks to “make sure your environment and connection is safe” before "proceeding to the landing page". Ironically, part of their message is true: fingerprinting did happen one domain earlier. It just wasn’t for the user’s benefit—it was to make sure the environment was safe… for the scammers. A few seconds later, without added user interaction needed, a fake Amazon login page is displayed.

    Domains samples:
    qqc10c[.]cyou
    51wang11c[.]cyou

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #scam #phishing #amazon #malspam #email #fingerprinting #japan

  9. 📱Smishing Slows, Quishing Quickens 🎣

    Sick of smishing and those pesky parking/toll texts? Don’t get caught by crafty, counterfeit court QR codes — it’s a scan-and-scam! 💳 🚨

    North American cell phone users are being hit with yet another wave of smishing campaigns that now include quishing elements. Likely orchestrated by Chinese-speaking threat actors, this latest campaign builds on previous vehicular violations, evolving tactics while impersonating US courts. 🧑‍⚖️

    We’ve recently seen a flurry of SMS messages pushing parking violations — but with a twist: face justice in court… or scan and pay instead!

    Delivered as an official-looking image, the actor has begun integrating QR codes into these lures to help mask suspicious phishing URLs, baiting victims into entering personal information, credentials, and ultimately making payments.

    For some, this lure may sound better than facing justice for their perceived poor parking. Victims who don't comply are warned that failure to appear or pay could have serious repercussions - a scare tactic designed to push you toward a hasty decision and scanning the QR code! 🫣

    We uncovered thousands of these nefarious domains, through their use of Registered Domain Generation Algorithms (RDGAs) and local government impersonation, hosted across a diverse range of hosting providers to evade takedown.

    Recent examples:
    ⛔ ahfgx[.]icu
    ⛔ euoyq[.]icu
    ⛔ htpze[.]icu
    ⛔ mwlaj[.]icu

    Friendly reminder - courts don't usually communicate with you via text. That said, we suspect this actor will continue to evolve, expanding their global reach and diversifying lures while improving tradecraft used in smishing and quishing delivery. As for us, we'll take our chances on evading that bench warrant and running from the law. 🏃‍♂️‍➡️

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #phishing #smishing #quishing

  10. Smishy New Year: Fake Rewards, Real Scams!

    Redeemed those "expiring" cell network reward points and awaiting your shiny new iPad or cash rebate?

    ⚠️📵 Think again. There's a catch - and your payment card details are on the hook! 🎣 💳

    Cell phone users in North America are getting hit with yet another wave of smishing campaigns, likely orchestrated by Chinese-speaking threat actors. This campaign builds on previous toll scams, evolving tactics and expanding targets. Over the holidays and well into the New Year, a barrage of SMS messages have posed as banks and cell phone networks, dangling phishing links to bait customers with fake points and high value rewards about to expire.

    Talk about FOMO! 💰🤑

    But you already know how this one plays out. Victims are prompted to enter payment details for “verification” or “shipping” and the only ones being rewarded are those taking the payments.

    We uncovered thousands of these nefarious domains through their use of Registered Domain Generation Algorithms (RDGAs) and brand impersonation, hosted across a diverse range of hosting providers to evade takedown.

    Recent examples:
    ⛔ anzrewardsprogram2026d[.]cc
    ⛔ <brand>.dvqlp[.]icu
    ⛔ <brand>.outdz[.]icu
    ⛔ <brand>.xqufa[.]cc
    ⛔ <brand>rewards.734726[.]com

    We suspect this actor will continue to evolve, expanding their global reach and diversifying lures while improving the tradecraft used in smishing delivery. As for us, we'll keep tracking til we get that iPad... 🙈

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #smishing #telecom #china

  11. 🎯 Spear targeted malware looking for French crypto devs [2/2]

    What makes this attack so effective ?
    🤔 Use of a lookalike domain that was aged for a year
    🚨 Use of legitimate binaries and Github ressources to confuse EDRs
    🔍 Very specific targeting of the victims with a convincing initial email written in proper French

    email distribution domain and malware c2:
    ⚠️ acpr-portail[.]fr

    first stage download domains:
    onde-amf[.]pages[.]dev
    amf-psan-docs[.]pages[.]dev

    malware distribution repo:
    https://raw[.]githubusercontent[.]com/jeromegerchin/

    #dns #threatintel #malware #RAT #cybersécurité #cybercrime #cybersecurity #ONDE #AMF #crypto #threatintelligence #infoblox #infobloxthreatintel

  12. 🎯 Spear targeted malware looking for French crypto devs [2/2]

    What makes this attack so effective ?
    🤔 Use of a lookalike domain that was aged for a year
    🚨 Use of legitimate binaries and Github ressources to confuse EDRs
    🔍 Very specific targeting of the victims with a convincing initial email written in proper French

    email distribution domain and malware c2:
    ⚠️ acpr-portail[.]fr

    first stage download domains:
    onde-amf[.]pages[.]dev
    amf-psan-docs[.]pages[.]dev

    malware distribution repo:
    https://raw[.]githubusercontent[.]com/jeromegerchin/

    #dns #threatintel #malware #RAT #cybersécurité #cybercrime #cybersecurity #ONDE #AMF #crypto #threatintelligence #infoblox #infobloxthreatintel

  13. 🎯 Spear targeted malware looking for French crypto devs [2/2]

    What makes this attack so effective ?
    🤔 Use of a lookalike domain that was aged for a year
    🚨 Use of legitimate binaries and Github ressources to confuse EDRs
    🔍 Very specific targeting of the victims with a convincing initial email written in proper French

    email distribution domain and malware c2:
    ⚠️ acpr-portail[.]fr

    first stage download domains:
    onde-amf[.]pages[.]dev
    amf-psan-docs[.]pages[.]dev

    malware distribution repo:
    https://raw[.]githubusercontent[.]com/jeromegerchin/

    #dns #threatintel #malware #RAT #cybersécurité #cybercrime #cybersecurity #ONDE #AMF #crypto #threatintelligence #infoblox #infobloxthreatintel

  14. 🎯 Spear targeted malware looking for French crypto devs [2/2]

    What makes this attack so effective ?
    🤔 Use of a lookalike domain that was aged for a year
    🚨 Use of legitimate binaries and Github ressources to confuse EDRs
    🔍 Very specific targeting of the victims with a convincing initial email written in proper French

    email distribution domain and malware c2:
    ⚠️ acpr-portail[.]fr

    first stage download domains:
    onde-amf[.]pages[.]dev
    amf-psan-docs[.]pages[.]dev

    malware distribution repo:
    https://raw[.]githubusercontent[.]com/jeromegerchin/

    #dns #threatintel #malware #RAT #cybersécurité #cybercrime #cybersecurity #ONDE #AMF #crypto #threatintelligence #infoblox #infobloxthreatintel

  15. 🎯 Spear targeted malware looking for French crypto devs [2/2]

    What makes this attack so effective ?
    🤔 Use of a lookalike domain that was aged for a year
    🚨 Use of legitimate binaries and Github ressources to confuse EDRs
    🔍 Very specific targeting of the victims with a convincing initial email written in proper French

    email distribution domain and malware c2:
    ⚠️ acpr-portail[.]fr

    first stage download domains:
    onde-amf[.]pages[.]dev
    amf-psan-docs[.]pages[.]dev

    malware distribution repo:
    https://raw[.]githubusercontent[.]com/jeromegerchin/

    #dns #threatintel #malware #RAT #cybersécurité #cybercrime #cybersecurity #ONDE #AMF #crypto #threatintelligence #infoblox #infobloxthreatintel

  16. 🎯 Spear targeted malware looking for French crypto devs [1/2]

    Even if you're French, you're probably unfamiliar with ONDE, the reporting system operated by AMF (equivalent to the US SEC). But a small number of individuals involved in crypto received emails just like this one, asking them to register a new key with the system before the end of year .

    The "key" is actually a Javascript file that will :
    👉 verify the C: disk is larger than 60 gb
    👉 look for various VM artifacts like drivers
    👉 compare current username to a list of known sandboxes
    👉 verify there are more than two files in the "recent" folder

    If those checks are successfull, a new script is downloaded and will build a Windows binary from different chunks hosted on Github.
    The final payload is a simple, but effective RAT written in Go, installed by a modified pyinstaller[.]exe binary.

    #dns #threatintel #malware #RAT #cybersécurité #cybercrime #cybersecurity #ONDE #AMF #crypto #threatintelligence #infoblox #infobloxthreatintel

  17. 🎯 Spear targeted malware looking for French crypto devs [1/2]

    Even if you're French, you're probably unfamiliar with ONDE, the reporting system operated by AMF (equivalent to the US SEC). But a small number of individuals involved in crypto received emails just like this one, asking them to register a new key with the system before the end of year .

    The "key" is actually a Javascript file that will :
    👉 verify the C: disk is larger than 60 gb
    👉 look for various VM artifacts like drivers
    👉 compare current username to a list of known sandboxes
    👉 verify there are more than two files in the "recent" folder

    If those checks are successfull, a new script is downloaded and will build a Windows binary from different chunks hosted on Github.
    The final payload is a simple, but effective RAT written in Go, installed by a modified pyinstaller[.]exe binary.

    #dns #threatintel #malware #RAT #cybersécurité #cybercrime #cybersecurity #ONDE #AMF #crypto #threatintelligence #infoblox #infobloxthreatintel

  18. 🎯 Spear targeted malware looking for French crypto devs [1/2]

    Even if you're French, you're probably unfamiliar with ONDE, the reporting system operated by AMF (equivalent to the US SEC). But a small number of individuals involved in crypto received emails just like this one, asking them to register a new key with the system before the end of year .

    The "key" is actually a Javascript file that will :
    👉 verify the C: disk is larger than 60 gb
    👉 look for various VM artifacts like drivers
    👉 compare current username to a list of known sandboxes
    👉 verify there are more than two files in the "recent" folder

    If those checks are successfull, a new script is downloaded and will build a Windows binary from different chunks hosted on Github.
    The final payload is a simple, but effective RAT written in Go, installed by a modified pyinstaller[.]exe binary.

    #dns #threatintel #malware #RAT #cybersécurité #cybercrime #cybersecurity #ONDE #AMF #crypto #threatintelligence #infoblox #infobloxthreatintel

  19. 🎯 Spear targeted malware looking for French crypto devs [1/2]

    Even if you're French, you're probably unfamiliar with ONDE, the reporting system operated by AMF (equivalent to the US SEC). But a small number of individuals involved in crypto received emails just like this one, asking them to register a new key with the system before the end of year .

    The "key" is actually a Javascript file that will :
    👉 verify the C: disk is larger than 60 gb
    👉 look for various VM artifacts like drivers
    👉 compare current username to a list of known sandboxes
    👉 verify there are more than two files in the "recent" folder

    If those checks are successfull, a new script is downloaded and will build a Windows binary from different chunks hosted on Github.
    The final payload is a simple, but effective RAT written in Go, installed by a modified pyinstaller[.]exe binary.

    #dns #threatintel #malware #RAT #cybersécurité #cybercrime #cybersecurity #ONDE #AMF #crypto #threatintelligence #infoblox #infobloxthreatintel

  20. 🎯 Spear targeted malware looking for French crypto devs [1/2]

    Even if you're French, you're probably unfamiliar with ONDE, the reporting system operated by AMF (equivalent to the US SEC). But a small number of individuals involved in crypto received emails just like this one, asking them to register a new key with the system before the end of year .

    The "key" is actually a Javascript file that will :
    👉 verify the C: disk is larger than 60 gb
    👉 look for various VM artifacts like drivers
    👉 compare current username to a list of known sandboxes
    👉 verify there are more than two files in the "recent" folder

    If those checks are successfull, a new script is downloaded and will build a Windows binary from different chunks hosted on Github.
    The final payload is a simple, but effective RAT written in Go, installed by a modified pyinstaller[.]exe binary.

    #dns #threatintel #malware #RAT #cybersécurité #cybercrime #cybersecurity #ONDE #AMF #crypto #threatintelligence #infoblox #infobloxthreatintel