#keylogger — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #keylogger, aggregated by home.social.
-
Blend between Banking Malware & Spyware
A newly identified Android malware family named Manic combines banking malware and mobile spyware capabilities, targeting Ukrainian banks, government services, messaging applications, Russian and European financial institutions, and global fintech and cryptocurrency services. Active since February 2026, Manic enables extensive Device Takeover operations through sophisticated surveillance and remote-control features. It employs advanced PIN stealing techniques without requiring traditional overlay attacks, utilizing Accessibility services as a UI keylogger to capture lock-screen inputs, recovery phrases, and authentication codes. A distinctive feature is its Wi-Fi mesh egress technique, allowing compromised devices to relay stolen data through other infected phones via Wi-Fi Direct, Bluetooth, or BLE when direct C2 access is unavailable. The malware monitors 169 applications including banks, cryptocurrency wallets, government eID services, and military-focused messengers across multiple countries.
Pulse ID: 6a86e8ec13b0f932cade0ec4
Pulse Link: https://otx.alienvault.com/pulse/6a86e8ec13b0f932cade0ec4
Pulse Author: AlienVault
Created: 2026-08-20 11:45:48Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Android #Bank #CyberSecurity #Europe #Government #InfoSec #KeyLogger #Malware #Military #OTX #OpenThreatExchange #RAT #Russia #SpyWare #UK #Ukr #Ukrainian #bot #cryptocurrency #AlienVault
-
Blend between Banking Malware & Spyware
A newly identified Android malware family named Manic combines banking malware and mobile spyware capabilities, targeting Ukrainian banks, government services, messaging applications, Russian and European financial institutions, and global fintech and cryptocurrency services. Active since February 2026, Manic enables extensive Device Takeover operations through sophisticated surveillance and remote-control features. It employs advanced PIN stealing techniques without requiring traditional overlay attacks, utilizing Accessibility services as a UI keylogger to capture lock-screen inputs, recovery phrases, and authentication codes. A distinctive feature is its Wi-Fi mesh egress technique, allowing compromised devices to relay stolen data through other infected phones via Wi-Fi Direct, Bluetooth, or BLE when direct C2 access is unavailable. The malware monitors 169 applications including banks, cryptocurrency wallets, government eID services, and military-focused messengers across multiple countries.
Pulse ID: 6a86e8ec13b0f932cade0ec4
Pulse Link: https://otx.alienvault.com/pulse/6a86e8ec13b0f932cade0ec4
Pulse Author: AlienVault
Created: 2026-08-20 11:45:48Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Android #Bank #CyberSecurity #Europe #Government #InfoSec #KeyLogger #Malware #Military #OTX #OpenThreatExchange #RAT #Russia #SpyWare #UK #Ukr #Ukrainian #bot #cryptocurrency #AlienVault
-
Blend between Banking Malware & Spyware
A newly identified Android malware family named Manic combines banking malware and mobile spyware capabilities, targeting Ukrainian banks, government services, messaging applications, Russian and European financial institutions, and global fintech and cryptocurrency services. Active since February 2026, Manic enables extensive Device Takeover operations through sophisticated surveillance and remote-control features. It employs advanced PIN stealing techniques without requiring traditional overlay attacks, utilizing Accessibility services as a UI keylogger to capture lock-screen inputs, recovery phrases, and authentication codes. A distinctive feature is its Wi-Fi mesh egress technique, allowing compromised devices to relay stolen data through other infected phones via Wi-Fi Direct, Bluetooth, or BLE when direct C2 access is unavailable. The malware monitors 169 applications including banks, cryptocurrency wallets, government eID services, and military-focused messengers across multiple countries.
Pulse ID: 6a86e8ec13b0f932cade0ec4
Pulse Link: https://otx.alienvault.com/pulse/6a86e8ec13b0f932cade0ec4
Pulse Author: AlienVault
Created: 2026-08-20 11:45:48Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Android #Bank #CyberSecurity #Europe #Government #InfoSec #KeyLogger #Malware #Military #OTX #OpenThreatExchange #RAT #Russia #SpyWare #UK #Ukr #Ukrainian #bot #cryptocurrency #AlienVault
-
Blend between Banking Malware & Spyware
A newly identified Android malware family named Manic combines banking malware and mobile spyware capabilities, targeting Ukrainian banks, government services, messaging applications, Russian and European financial institutions, and global fintech and cryptocurrency services. Active since February 2026, Manic enables extensive Device Takeover operations through sophisticated surveillance and remote-control features. It employs advanced PIN stealing techniques without requiring traditional overlay attacks, utilizing Accessibility services as a UI keylogger to capture lock-screen inputs, recovery phrases, and authentication codes. A distinctive feature is its Wi-Fi mesh egress technique, allowing compromised devices to relay stolen data through other infected phones via Wi-Fi Direct, Bluetooth, or BLE when direct C2 access is unavailable. The malware monitors 169 applications including banks, cryptocurrency wallets, government eID services, and military-focused messengers across multiple countries.
Pulse ID: 6a86e8ec13b0f932cade0ec4
Pulse Link: https://otx.alienvault.com/pulse/6a86e8ec13b0f932cade0ec4
Pulse Author: AlienVault
Created: 2026-08-20 11:45:48Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Android #Bank #CyberSecurity #Europe #Government #InfoSec #KeyLogger #Malware #Military #OTX #OpenThreatExchange #RAT #Russia #SpyWare #UK #Ukr #Ukrainian #bot #cryptocurrency #AlienVault
-
Blend between Banking Malware & Spyware
A newly identified Android malware family named Manic combines banking malware and mobile spyware capabilities, targeting Ukrainian banks, government services, messaging applications, Russian and European financial institutions, and global fintech and cryptocurrency services. Active since February 2026, Manic enables extensive Device Takeover operations through sophisticated surveillance and remote-control features. It employs advanced PIN stealing techniques without requiring traditional overlay attacks, utilizing Accessibility services as a UI keylogger to capture lock-screen inputs, recovery phrases, and authentication codes. A distinctive feature is its Wi-Fi mesh egress technique, allowing compromised devices to relay stolen data through other infected phones via Wi-Fi Direct, Bluetooth, or BLE when direct C2 access is unavailable. The malware monitors 169 applications including banks, cryptocurrency wallets, government eID services, and military-focused messengers across multiple countries.
Pulse ID: 6a86e8ec13b0f932cade0ec4
Pulse Link: https://otx.alienvault.com/pulse/6a86e8ec13b0f932cade0ec4
Pulse Author: AlienVault
Created: 2026-08-20 11:45:48Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Android #Bank #CyberSecurity #Europe #Government #InfoSec #KeyLogger #Malware #Military #OTX #OpenThreatExchange #RAT #Russia #SpyWare #UK #Ukr #Ukrainian #bot #cryptocurrency #AlienVault
-
📢 CSS dans les webmails : exfiltration de tokens, keyloggers et prise de contrôle de comptes
Cet article de recherche technique présente une série de techniques d'attaque exploitant le rendu CSS dans les clients webmail. Les cibles étudiées incluent Yahoo Mail, AOL Mail, Fastmail, ProtonMail, Gmail et Outlook. Détournement de balises <label> : les…
📖 cyberveille : https://cyberveille.ch/posts/2026-08-10-css-dans-les-webmails-exfiltration-de-tokens-keyloggers-et-prise-de-controle-de-comptes/
🌐 source : https://portswigger.net/research/css-the-bomb-inside-your-inbox
🟡 vérification factuelle moyenne
#keylogger #webmail #Cyberveille -
Analysis of a Phishing Email Attack Case
The Larva-24009 threat actor, also known as HeptaX, has been conducting phishing email campaigns since 2023, targeting Korean and global users to install malware. Active through 2026, the actor uses LNK files disguised as documents with topics like hospital surveys, blockchain, project proposals, and resumes to target enterprises. Upon execution, obfuscated PowerShell commands deploy backdoors and download additional scripts from command-and-control servers. The attack chain includes persistence mechanisms via Task Scheduler, remote access through QuasarRAT and UltraVNC, and information theft using NirSoft tools, custom keyloggers, and screenshot capabilities. The actor also creates backdoor RDP accounts and exfiltrates credentials, browser data, and user files. Version 2.1 of their Notifier malware utilizes Telegram API for status reporting. The campaigns demonstrate consistent tactics and infrastructure across multiple years of operation.
Pulse ID: 6a70c6f0d15cdde2874f628e
Pulse Link: https://otx.alienvault.com/pulse/6a70c6f0d15cdde2874f628e
Pulse Author: AlienVault
Created: 2026-08-03 16:50:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #BlockChain #Browser #CyberSecurity #Email #Hospital #ICS #InfoSec #InformationTheft #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #RDP #SMS #Telegram #VNC #bot #AlienVault
-
Analysis of a Phishing Email Attack Case
The Larva-24009 threat actor, also known as HeptaX, has been conducting phishing email campaigns since 2023, targeting Korean and global users to install malware. Active through 2026, the actor uses LNK files disguised as documents with topics like hospital surveys, blockchain, project proposals, and resumes to target enterprises. Upon execution, obfuscated PowerShell commands deploy backdoors and download additional scripts from command-and-control servers. The attack chain includes persistence mechanisms via Task Scheduler, remote access through QuasarRAT and UltraVNC, and information theft using NirSoft tools, custom keyloggers, and screenshot capabilities. The actor also creates backdoor RDP accounts and exfiltrates credentials, browser data, and user files. Version 2.1 of their Notifier malware utilizes Telegram API for status reporting. The campaigns demonstrate consistent tactics and infrastructure across multiple years of operation.
Pulse ID: 6a70c6f0d15cdde2874f628e
Pulse Link: https://otx.alienvault.com/pulse/6a70c6f0d15cdde2874f628e
Pulse Author: AlienVault
Created: 2026-08-03 16:50:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #BlockChain #Browser #CyberSecurity #Email #Hospital #ICS #InfoSec #InformationTheft #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #RDP #SMS #Telegram #VNC #bot #AlienVault
-
Analysis of a Phishing Email Attack Case
The Larva-24009 threat actor, also known as HeptaX, has been conducting phishing email campaigns since 2023, targeting Korean and global users to install malware. Active through 2026, the actor uses LNK files disguised as documents with topics like hospital surveys, blockchain, project proposals, and resumes to target enterprises. Upon execution, obfuscated PowerShell commands deploy backdoors and download additional scripts from command-and-control servers. The attack chain includes persistence mechanisms via Task Scheduler, remote access through QuasarRAT and UltraVNC, and information theft using NirSoft tools, custom keyloggers, and screenshot capabilities. The actor also creates backdoor RDP accounts and exfiltrates credentials, browser data, and user files. Version 2.1 of their Notifier malware utilizes Telegram API for status reporting. The campaigns demonstrate consistent tactics and infrastructure across multiple years of operation.
Pulse ID: 6a70c6f0d15cdde2874f628e
Pulse Link: https://otx.alienvault.com/pulse/6a70c6f0d15cdde2874f628e
Pulse Author: AlienVault
Created: 2026-08-03 16:50:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #BlockChain #Browser #CyberSecurity #Email #Hospital #ICS #InfoSec #InformationTheft #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #RDP #SMS #Telegram #VNC #bot #AlienVault
-
Analysis of a Phishing Email Attack Case
The Larva-24009 threat actor, also known as HeptaX, has been conducting phishing email campaigns since 2023, targeting Korean and global users to install malware. Active through 2026, the actor uses LNK files disguised as documents with topics like hospital surveys, blockchain, project proposals, and resumes to target enterprises. Upon execution, obfuscated PowerShell commands deploy backdoors and download additional scripts from command-and-control servers. The attack chain includes persistence mechanisms via Task Scheduler, remote access through QuasarRAT and UltraVNC, and information theft using NirSoft tools, custom keyloggers, and screenshot capabilities. The actor also creates backdoor RDP accounts and exfiltrates credentials, browser data, and user files. Version 2.1 of their Notifier malware utilizes Telegram API for status reporting. The campaigns demonstrate consistent tactics and infrastructure across multiple years of operation.
Pulse ID: 6a70c6f0d15cdde2874f628e
Pulse Link: https://otx.alienvault.com/pulse/6a70c6f0d15cdde2874f628e
Pulse Author: AlienVault
Created: 2026-08-03 16:50:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #BlockChain #Browser #CyberSecurity #Email #Hospital #ICS #InfoSec #InformationTheft #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #RDP #SMS #Telegram #VNC #bot #AlienVault
-
Analysis of a Phishing Email Attack Case
The Larva-24009 threat actor, also known as HeptaX, has been conducting phishing email campaigns since 2023, targeting Korean and global users to install malware. Active through 2026, the actor uses LNK files disguised as documents with topics like hospital surveys, blockchain, project proposals, and resumes to target enterprises. Upon execution, obfuscated PowerShell commands deploy backdoors and download additional scripts from command-and-control servers. The attack chain includes persistence mechanisms via Task Scheduler, remote access through QuasarRAT and UltraVNC, and information theft using NirSoft tools, custom keyloggers, and screenshot capabilities. The actor also creates backdoor RDP accounts and exfiltrates credentials, browser data, and user files. Version 2.1 of their Notifier malware utilizes Telegram API for status reporting. The campaigns demonstrate consistent tactics and infrastructure across multiple years of operation.
Pulse ID: 6a70c6f0d15cdde2874f628e
Pulse Link: https://otx.alienvault.com/pulse/6a70c6f0d15cdde2874f628e
Pulse Author: AlienVault
Created: 2026-08-03 16:50:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #BlockChain #Browser #CyberSecurity #Email #Hospital #ICS #InfoSec #InformationTheft #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #RDP #SMS #Telegram #VNC #bot #AlienVault
-
Złośliwe rozszerzenie do Chrome wykrada prompty z ChatGPT, Claude, Copilota i wielu innych serwisów AI
Rozszerzenie do przeglądarki Chrome – Prompt Optimizer – Second Brain (nadal dostępne w oficjalnym sklepie Chrome Web Store) którego zadaniem jest wsparcie użytkownika podczas pracy z modelami AI, po cichu wykrada wpisywane prompty i generowane odpowiedzi. Oczywiście twórcy rozszerzenia deklarują, że dane użytkownika w żaden sposób nie są gromadzone. Jak...
-
Złośliwe rozszerzenie do Chrome wykrada prompty z ChatGPT, Claude, Copilota i wielu innych serwisów AI
Rozszerzenie do przeglądarki Chrome – Prompt Optimizer – Second Brain (nadal dostępne w oficjalnym sklepie Chrome Web Store) którego zadaniem jest wsparcie użytkownika podczas pracy z modelami AI, po cichu wykrada wpisywane prompty i generowane odpowiedzi. Oczywiście twórcy rozszerzenia deklarują, że dane użytkownika w żaden sposób nie są gromadzone. Jak...
-
Złośliwe rozszerzenie do Chrome wykrada prompty z ChatGPT, Claude, Copilota i wielu innych serwisów AI
Rozszerzenie do przeglądarki Chrome – Prompt Optimizer – Second Brain (nadal dostępne w oficjalnym sklepie Chrome Web Store) którego zadaniem jest wsparcie użytkownika podczas pracy z modelami AI, po cichu wykrada wpisywane prompty i generowane odpowiedzi. Oczywiście twórcy rozszerzenia deklarują, że dane użytkownika w żaden sposób nie są gromadzone. Jak...
-
Złośliwe rozszerzenie do Chrome wykrada prompty z ChatGPT, Claude, Copilota i wielu innych serwisów AI
Rozszerzenie do przeglądarki Chrome – Prompt Optimizer – Second Brain (nadal dostępne w oficjalnym sklepie Chrome Web Store) którego zadaniem jest wsparcie użytkownika podczas pracy z modelami AI, po cichu wykrada wpisywane prompty i generowane odpowiedzi. Oczywiście twórcy rozszerzenia deklarują, że dane użytkownika w żaden sposób nie są gromadzone. Jak...
-
Złośliwe rozszerzenie do Chrome wykrada prompty z ChatGPT, Claude, Copilota i wielu innych serwisów AI
Rozszerzenie do przeglądarki Chrome – Prompt Optimizer – Second Brain (nadal dostępne w oficjalnym sklepie Chrome Web Store) którego zadaniem jest wsparcie użytkownika podczas pracy z modelami AI, po cichu wykrada wpisywane prompty i generowane odpowiedzi. Oczywiście twórcy rozszerzenia deklarują, że dane użytkownika w żaden sposób nie są gromadzone. Jak...
-
June 2026 Threat Trend Report on APT Attacks (South Korea)
AhnLab monitored Advanced Persistent Threat attacks targeting South Korea during June 2026, identifying multiple attack types distributed primarily through spear phishing campaigns. Threat actors disguised malicious files as work-related documents, with LNK files being the most common delivery method. Six distinct attack types were observed, employing various techniques including malicious PowerShell commands, AutoIt malware, curl.exe abuse, GitHub repository exploitation, Task Scheduler persistence, DLL side-loading, and Python backdoors. These attacks deployed Infostealers, keyloggers, backdoors, and remote access tools like XenoRAT. Once executed, the malware established persistence, exfiltrated system information, and enabled remote control of compromised systems. Organizations are advised to verify email senders, avoid opening files from unknown sources, apply security patches, and maintain updated antivirus software to mitigate these persistent threats.
Pulse ID: 6a635bdf995351cf539c3b56
Pulse Link: https://otx.alienvault.com/pulse/6a635bdf995351cf539c3b56
Pulse Author: AlienVault
Created: 2026-07-24 12:34:39Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AhnLab #Autoit #BackDoor #CyberSecurity #Email #GitHub #InfoSec #InfoStealer #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #Python #RAT #RCE #SouthKorea #SpearPhishing #bot #AlienVault
-
June 2026 Threat Trend Report on APT Attacks (South Korea)
AhnLab monitored Advanced Persistent Threat attacks targeting South Korea during June 2026, identifying multiple attack types distributed primarily through spear phishing campaigns. Threat actors disguised malicious files as work-related documents, with LNK files being the most common delivery method. Six distinct attack types were observed, employing various techniques including malicious PowerShell commands, AutoIt malware, curl.exe abuse, GitHub repository exploitation, Task Scheduler persistence, DLL side-loading, and Python backdoors. These attacks deployed Infostealers, keyloggers, backdoors, and remote access tools like XenoRAT. Once executed, the malware established persistence, exfiltrated system information, and enabled remote control of compromised systems. Organizations are advised to verify email senders, avoid opening files from unknown sources, apply security patches, and maintain updated antivirus software to mitigate these persistent threats.
Pulse ID: 6a635bdf995351cf539c3b56
Pulse Link: https://otx.alienvault.com/pulse/6a635bdf995351cf539c3b56
Pulse Author: AlienVault
Created: 2026-07-24 12:34:39Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AhnLab #Autoit #BackDoor #CyberSecurity #Email #GitHub #InfoSec #InfoStealer #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #Python #RAT #RCE #SouthKorea #SpearPhishing #bot #AlienVault
-
June 2026 Threat Trend Report on APT Attacks (South Korea)
AhnLab monitored Advanced Persistent Threat attacks targeting South Korea during June 2026, identifying multiple attack types distributed primarily through spear phishing campaigns. Threat actors disguised malicious files as work-related documents, with LNK files being the most common delivery method. Six distinct attack types were observed, employing various techniques including malicious PowerShell commands, AutoIt malware, curl.exe abuse, GitHub repository exploitation, Task Scheduler persistence, DLL side-loading, and Python backdoors. These attacks deployed Infostealers, keyloggers, backdoors, and remote access tools like XenoRAT. Once executed, the malware established persistence, exfiltrated system information, and enabled remote control of compromised systems. Organizations are advised to verify email senders, avoid opening files from unknown sources, apply security patches, and maintain updated antivirus software to mitigate these persistent threats.
Pulse ID: 6a635bdf995351cf539c3b56
Pulse Link: https://otx.alienvault.com/pulse/6a635bdf995351cf539c3b56
Pulse Author: AlienVault
Created: 2026-07-24 12:34:39Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AhnLab #Autoit #BackDoor #CyberSecurity #Email #GitHub #InfoSec #InfoStealer #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #Python #RAT #RCE #SouthKorea #SpearPhishing #bot #AlienVault
-
June 2026 Threat Trend Report on APT Attacks (South Korea)
AhnLab monitored Advanced Persistent Threat attacks targeting South Korea during June 2026, identifying multiple attack types distributed primarily through spear phishing campaigns. Threat actors disguised malicious files as work-related documents, with LNK files being the most common delivery method. Six distinct attack types were observed, employing various techniques including malicious PowerShell commands, AutoIt malware, curl.exe abuse, GitHub repository exploitation, Task Scheduler persistence, DLL side-loading, and Python backdoors. These attacks deployed Infostealers, keyloggers, backdoors, and remote access tools like XenoRAT. Once executed, the malware established persistence, exfiltrated system information, and enabled remote control of compromised systems. Organizations are advised to verify email senders, avoid opening files from unknown sources, apply security patches, and maintain updated antivirus software to mitigate these persistent threats.
Pulse ID: 6a635bdf995351cf539c3b56
Pulse Link: https://otx.alienvault.com/pulse/6a635bdf995351cf539c3b56
Pulse Author: AlienVault
Created: 2026-07-24 12:34:39Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AhnLab #Autoit #BackDoor #CyberSecurity #Email #GitHub #InfoSec #InfoStealer #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #Python #RAT #RCE #SouthKorea #SpearPhishing #bot #AlienVault
-
June 2026 Threat Trend Report on APT Attacks (South Korea)
AhnLab monitored Advanced Persistent Threat attacks targeting South Korea during June 2026, identifying multiple attack types distributed primarily through spear phishing campaigns. Threat actors disguised malicious files as work-related documents, with LNK files being the most common delivery method. Six distinct attack types were observed, employing various techniques including malicious PowerShell commands, AutoIt malware, curl.exe abuse, GitHub repository exploitation, Task Scheduler persistence, DLL side-loading, and Python backdoors. These attacks deployed Infostealers, keyloggers, backdoors, and remote access tools like XenoRAT. Once executed, the malware established persistence, exfiltrated system information, and enabled remote control of compromised systems. Organizations are advised to verify email senders, avoid opening files from unknown sources, apply security patches, and maintain updated antivirus software to mitigate these persistent threats.
Pulse ID: 6a635bdf995351cf539c3b56
Pulse Link: https://otx.alienvault.com/pulse/6a635bdf995351cf539c3b56
Pulse Author: AlienVault
Created: 2026-07-24 12:34:39Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AhnLab #Autoit #BackDoor #CyberSecurity #Email #GitHub #InfoSec #InfoStealer #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #Python #RAT #RCE #SouthKorea #SpearPhishing #bot #AlienVault
-
Hey people - I am planning to write a systemwide #keylogger for #linux in #C. That would be monitoring your /dev/input directory. I already wrote it a week ago and it works. Provided your user is in the input group, or any group that has read access to /dev/input directory.
Anyone needs the code to see how I wrote it? It is just a read #syscalls, alongside with input-event-codes.h.
Nothing malicious guys - just a program that shows you the power of 'What' - when some user is in input group;
I just don't know if I can send them here :).
Reply if you wanna know anything. -
Hey people - I am planning to write a systemwide #keylogger for #linux in #C. That would be monitoring your /dev/input directory. I already wrote it a week ago and it works. Provided your user is in the input group, or any group that has read access to /dev/input directory.
Anyone needs the code to see how I wrote it? It is just a read #syscalls, alongside with input-event-codes.h.
Nothing malicious guys - just a program that shows you the power of 'What' - when some user is in input group;
I just don't know if I can send them here :).
Reply if you wanna know anything. -
Hey people - I am planning to write a systemwide #keylogger for #linux in #C. That would be monitoring your /dev/input directory. I already wrote it a week ago and it works. Provided your user is in the input group, or any group that has read access to /dev/input directory.
Anyone needs the code to see how I wrote it? It is just a read #syscalls, alongside with input-event-codes.h.
Nothing malicious guys - just a program that shows you the power of 'What' - when some user is in input group;
I just don't know if I can send them here :).
Reply if you wanna know anything. -
Hey people - I am planning to write a systemwide #keylogger for #linux in #C. That would be monitoring your /dev/input directory. I already wrote it a week ago and it works. Provided your user is in the input group, or any group that has read access to /dev/input directory.
Anyone needs the code to see how I wrote it? It is just a read #syscalls, alongside with input-event-codes.h.
Nothing malicious guys - just a program that shows you the power of 'What' - when some user is in input group;
I just don't know if I can send them here :).
Reply if you wanna know anything. -
Meta exposed worker keystroke data that was being used to train AI, making it accessible to anyone at the company.
The data included personnel and performance info, private convos, full transcriptions…
https://www.wired.com/story/meta-accidentally-let-employees-access-each-others-keystroke-data/
-
Meta exposed worker keystroke data that was being used to train AI, making it accessible to anyone at the company.
The data included personnel and performance info, private convos, full transcriptions…
https://www.wired.com/story/meta-accidentally-let-employees-access-each-others-keystroke-data/
-
Meta exposed worker keystroke data that was being used to train AI, making it accessible to anyone at the company.
The data included personnel and performance info, private convos, full transcriptions…
https://www.wired.com/story/meta-accidentally-let-employees-access-each-others-keystroke-data/
-
Meta exposed worker keystroke data that was being used to train AI, making it accessible to anyone at the company.
The data included personnel and performance info, private convos, full transcriptions…
https://www.wired.com/story/meta-accidentally-let-employees-access-each-others-keystroke-data/
-
Meta exposed worker keystroke data that was being used to train AI, making it accessible to anyone at the company.
The data included personnel and performance info, private convos, full transcriptions…
https://www.wired.com/story/meta-accidentally-let-employees-access-each-others-keystroke-data/
-
Der Praxisteil meines „Hacking- und Pentest-Hardware-Workshops” umfasst fünf Stationen. In Kleingruppen von maximal drei Personen arbeiten die Teilnehmenden etwa eine Stunde lang die Aufgaben durch. In dieser Zeit gehe ich von Station zu Station und gebe Tipps sowie zusätzliche Informationen. Bei der ersten Station „Gadgets & Logger” dreht sich alles um Spionagegadgets, Keylogger und Screenlogger.
=> Klicken Sie hier, um mehr über die Workshop-Inhalte zu erfahren: https://scheible.it/workshop (6.7. in Stuttgart)
#ITSicherheit #CyberAwareness #Seminar #SecurityKnowHow #Keylogger
-
Der Praxisteil meines „Hacking- und Pentest-Hardware-Workshops” umfasst fünf Stationen. In Kleingruppen von maximal drei Personen arbeiten die Teilnehmenden etwa eine Stunde lang die Aufgaben durch. In dieser Zeit gehe ich von Station zu Station und gebe Tipps sowie zusätzliche Informationen. Bei der ersten Station „Gadgets & Logger” dreht sich alles um Spionagegadgets, Keylogger und Screenlogger.
=> Klicken Sie hier, um mehr über die Workshop-Inhalte zu erfahren: https://scheible.it/workshop (6.7. in Stuttgart)
#ITSicherheit #CyberAwareness #Seminar #SecurityKnowHow #Keylogger
-
Der Praxisteil meines „Hacking- und Pentest-Hardware-Workshops” umfasst fünf Stationen. In Kleingruppen von maximal drei Personen arbeiten die Teilnehmenden etwa eine Stunde lang die Aufgaben durch. In dieser Zeit gehe ich von Station zu Station und gebe Tipps sowie zusätzliche Informationen. Bei der ersten Station „Gadgets & Logger” dreht sich alles um Spionagegadgets, Keylogger und Screenlogger.
=> Klicken Sie hier, um mehr über die Workshop-Inhalte zu erfahren: https://scheible.it/workshop (6.7. in Stuttgart)
#ITSicherheit #CyberAwareness #Seminar #SecurityKnowHow #Keylogger
-
Der Praxisteil meines „Hacking- und Pentest-Hardware-Workshops” umfasst fünf Stationen. In Kleingruppen von maximal drei Personen arbeiten die Teilnehmenden etwa eine Stunde lang die Aufgaben durch. In dieser Zeit gehe ich von Station zu Station und gebe Tipps sowie zusätzliche Informationen. Bei der ersten Station „Gadgets & Logger” dreht sich alles um Spionagegadgets, Keylogger und Screenlogger.
=> Klicken Sie hier, um mehr über die Workshop-Inhalte zu erfahren: https://scheible.it/workshop (6.7. in Stuttgart)
#ITSicherheit #CyberAwareness #Seminar #SecurityKnowHow #Keylogger
-
@kubikpixel war das unwissentlich? Schon im April gab es Berichte darüber. So wie ich das verstanden hatte gab es da schon Unmut bei den Angestellten. Auch #ct4004 hatte das Thema Anfang Mai im Podcast.
-
@kubikpixel war das unwissentlich? Schon im April gab es Berichte darüber. So wie ich das verstanden hatte gab es da schon Unmut bei den Angestellten. Auch #ct4004 hatte das Thema Anfang Mai im Podcast.
-
@kubikpixel war das unwissentlich? Schon im April gab es Berichte darüber. So wie ich das verstanden hatte gab es da schon Unmut bei den Angestellten. Auch #ct4004 hatte das Thema Anfang Mai im Podcast.
-
@kubikpixel war das unwissentlich? Schon im April gab es Berichte darüber. So wie ich das verstanden hatte gab es da schon Unmut bei den Angestellten. Auch #ct4004 hatte das Thema Anfang Mai im Podcast.
-
@kubikpixel war das unwissentlich? Schon im April gab es Berichte darüber. So wie ich das verstanden hatte gab es da schon Unmut bei den Angestellten. Auch #ct4004 hatte das Thema Anfang Mai im Podcast.
-
https://www.europesays.com/ch-fr/147669/ Banal et pourtant dangereux : ce câble USB renferme un terrible piège #Cybersécurité #gadget #Hack #Hacker #hacking #Keylogger #Malware #Piratage #Science #ScienceAndTechnology #Sciences #SciencesEtTechnologies #Suisse #technologie #Technologies #Technology #usb
-
https://www.europesays.com/be-fr/119572/ Banal et pourtant dangereux : ce câble USB renferme un terrible piège #BE #BEFr #Belgique #Belgium #cybersécurité #gadget #Hack #Hacker #hacking #Keylogger #Malware #Piratage #Science #ScienceAndTechnology #Sciences #SciencesEtTechnologies #Technologie #Technologies #Technology #usb
-
𝗘𝘃𝗶𝗹𝗖𝗿𝗼𝘄 𝗞𝗲𝘆𝗹𝗼𝗴𝗴𝗲𝗿 - 𝗗𝗲𝗿 𝗞𝗲𝘆𝗹𝗼𝗴𝗴𝗲𝗿 𝗳𝘂̈𝗿 𝗡𝗲𝗿𝗱𝘀 ⌨️
Der typische Hardware-Keylogger ist darauf ausgelegt, möglichst einfach zu funktionieren. Meist genügt es, ihn einzustecken und loszulegen. Zum Auslesen der Daten muss lediglich eine bestimmte Tastenkombination betätigt werden, um sie in einer TXT-Datei zu speichern.
Der EvilCrow Keylogger ist anders. Er basiert auf einem Atmega32U4 mit Arduino-Lilypad-USB-Bootloader, einem ESP32-PICO für die WLAN-Kommunikation und einem MicroSD-Kartenleser. Die Software dazu ist auf GitHub zu finden.
Eigenen Projekten steht nichts im Wege 😉
-
𝗘𝘃𝗶𝗹𝗖𝗿𝗼𝘄 𝗞𝗲𝘆𝗹𝗼𝗴𝗴𝗲𝗿 - 𝗗𝗲𝗿 𝗞𝗲𝘆𝗹𝗼𝗴𝗴𝗲𝗿 𝗳𝘂̈𝗿 𝗡𝗲𝗿𝗱𝘀 ⌨️
Der typische Hardware-Keylogger ist darauf ausgelegt, möglichst einfach zu funktionieren. Meist genügt es, ihn einzustecken und loszulegen. Zum Auslesen der Daten muss lediglich eine bestimmte Tastenkombination betätigt werden, um sie in einer TXT-Datei zu speichern.
Der EvilCrow Keylogger ist anders. Er basiert auf einem Atmega32U4 mit Arduino-Lilypad-USB-Bootloader, einem ESP32-PICO für die WLAN-Kommunikation und einem MicroSD-Kartenleser. Die Software dazu ist auf GitHub zu finden.
Eigenen Projekten steht nichts im Wege 😉
-
𝗞𝗲𝘆𝗹𝗼𝗴𝗴𝗲𝗿-𝗞𝗮𝗯𝗲𝗹 - 𝗴𝗲𝘁𝗮𝗿𝗻𝘁𝗲 𝗛𝗮𝗰𝗸𝗶𝗻𝗴 𝗛𝗮𝗿𝗱𝘄𝗮𝗿𝗲 🖥️
Wie sieht euer Kabelmanagement am Rechner aus? Ist alles schön aufgeräumt, sodass neue, fremde Hardware direkt auffällt? 🔌
WLAN-Keylogger kombinieren das Beste aus zwei Welten: Die Unauffälligkeit eines Hardware-Adapters und die Reichweite des Internets. Und das ist auch noch in einem unauffälligen USB-Verlängerungskabel getarnt.
Die gesamte Technik befindet sich in der USB-A-Buchse. Sie ist nur etwas größer als gewöhnlich. Auch hier ist wieder ein WLAN-Modul integriert. Um die abgefangen Daten der letzten Tage oder Wochen auszulesen, muss der Angreifer nur in Reichweite kommen.
-
𝗞𝗲𝘆𝗹𝗼𝗴𝗴𝗲𝗿-𝗞𝗮𝗯𝗲𝗹 - 𝗴𝗲𝘁𝗮𝗿𝗻𝘁𝗲 𝗛𝗮𝗰𝗸𝗶𝗻𝗴 𝗛𝗮𝗿𝗱𝘄𝗮𝗿𝗲 🖥️
Wie sieht euer Kabelmanagement am Rechner aus? Ist alles schön aufgeräumt, sodass neue, fremde Hardware direkt auffällt? 🔌
WLAN-Keylogger kombinieren das Beste aus zwei Welten: Die Unauffälligkeit eines Hardware-Adapters und die Reichweite des Internets. Und das ist auch noch in einem unauffälligen USB-Verlängerungskabel getarnt.
Die gesamte Technik befindet sich in der USB-A-Buchse. Sie ist nur etwas größer als gewöhnlich. Auch hier ist wieder ein WLAN-Modul integriert. Um die abgefangen Daten der letzten Tage oder Wochen auszulesen, muss der Angreifer nur in Reichweite kommen.
-
𝗪𝗟𝗔𝗡-𝗞𝗲𝘆𝗹𝗼𝗴𝗴𝗲𝗿 - 𝗦𝗲𝘁 𝗮𝗻𝗱 𝗙𝗼𝗿𝗴𝗲𝘁 📶
Einmal nicht aufgepasst und schon sind sämtliche Tastatureingaben im Speicher des Keyloggers.
WLAN-Keylogger sind der Albtraum jedes Admins. Der Angreifer muss nur einmal kurz physischen Zugriff haben, um das Gerät zu platzieren. Danach muss er nie wieder an den Opfer-Rechner zurückkehren.
⌨️ Der Angreifer kann abends oder am Wochenende bequem vom Auto aus, das sich in Reichweite des WLANs befindet, die abgegriffenen Daten auslesen.
𝘕𝘦𝘹𝘵 𝘓𝘦𝘷𝘦𝘭: Die vorhandene WLAN-Verbindung kann für den Internetzugriff verwendet werden und die Eingaben können live an einen Server gestreamt werden. 🌐
#HackingHardware #Keylogger #WLANKeylogger #KeyloggerWiFi #Workshop
-
𝗪𝗟𝗔𝗡-𝗞𝗲𝘆𝗹𝗼𝗴𝗴𝗲𝗿 - 𝗦𝗲𝘁 𝗮𝗻𝗱 𝗙𝗼𝗿𝗴𝗲𝘁 📶
Einmal nicht aufgepasst und schon sind sämtliche Tastatureingaben im Speicher des Keyloggers.
WLAN-Keylogger sind der Albtraum jedes Admins. Der Angreifer muss nur einmal kurz physischen Zugriff haben, um das Gerät zu platzieren. Danach muss er nie wieder an den Opfer-Rechner zurückkehren.
⌨️ Der Angreifer kann abends oder am Wochenende bequem vom Auto aus, das sich in Reichweite des WLANs befindet, die abgegriffenen Daten auslesen.
𝘕𝘦𝘹𝘵 𝘓𝘦𝘷𝘦𝘭: Die vorhandene WLAN-Verbindung kann für den Internetzugriff verwendet werden und die Eingaben können live an einen Server gestreamt werden. 🌐
#HackingHardware #Keylogger #WLANKeylogger #KeyloggerWiFi #Workshop
-
𝗗𝗮𝘀 𝗞𝗲𝘆𝗹𝗼𝗴𝗴𝗲𝗿-𝗠𝗼𝗱𝘂𝗹 - 𝗜𝗻𝗰𝗲𝗽𝘁𝗶𝗼𝗻 𝗶𝗻 𝗱𝗲𝗿 𝗧𝗮𝘀𝘁𝗮𝘁𝘂𝗿 ⌨️
In meinem Buch „Hardware & Security“ beschreibe ich ein fundamentales Problem: Das Vertrauen des Betriebssystems in die Hardware. Ein USB-Keylogger arbeitet auf der physikalischen Ebene. Er fängt die Scancodes ab, bevor sie das OS erreichen.
❓ Was passiert, wenn der Keylogger nicht hinter der Tastatur steckt, sondern darin?
Dieses winzige Modul wird direkt auf in der Tastatur an den USB-Anschluss gelötet. Von außen ist absolut nichts sichtbar. Kein verdächtiger USB-Stick, kein zusätzlicher Adapter.
Das ist die Königsdisziplin der Spionage: 𝘔𝘰𝘥𝘪𝘧𝘪𝘻𝘪𝘦𝘳𝘵𝘦 𝘏𝘢𝘳𝘥𝘸𝘢𝘳𝘦
#HackingHardware #Keylogger #USBKeylogger #KeyloggerModul #Workshop
-
𝗗𝗮𝘀 𝗞𝗲𝘆𝗹𝗼𝗴𝗴𝗲𝗿-𝗠𝗼𝗱𝘂𝗹 - 𝗜𝗻𝗰𝗲𝗽𝘁𝗶𝗼𝗻 𝗶𝗻 𝗱𝗲𝗿 𝗧𝗮𝘀𝘁𝗮𝘁𝘂𝗿 ⌨️
In meinem Buch „Hardware & Security“ beschreibe ich ein fundamentales Problem: Das Vertrauen des Betriebssystems in die Hardware. Ein USB-Keylogger arbeitet auf der physikalischen Ebene. Er fängt die Scancodes ab, bevor sie das OS erreichen.
❓ Was passiert, wenn der Keylogger nicht hinter der Tastatur steckt, sondern darin?
Dieses winzige Modul wird direkt auf in der Tastatur an den USB-Anschluss gelötet. Von außen ist absolut nichts sichtbar. Kein verdächtiger USB-Stick, kein zusätzlicher Adapter.
Das ist die Königsdisziplin der Spionage: 𝘔𝘰𝘥𝘪𝘧𝘪𝘻𝘪𝘦𝘳𝘵𝘦 𝘏𝘢𝘳𝘥𝘸𝘢𝘳𝘦
#HackingHardware #Keylogger #USBKeylogger #KeyloggerModul #Workshop
-
𝗗𝗮𝘀 𝗞𝗲𝘆𝗹𝗼𝗴𝗴𝗲𝗿-𝗠𝗼𝗱𝘂𝗹 - 𝗜𝗻𝗰𝗲𝗽𝘁𝗶𝗼𝗻 𝗶𝗻 𝗱𝗲𝗿 𝗧𝗮𝘀𝘁𝗮𝘁𝘂𝗿 ⌨️
In meinem Buch „Hardware & Security“ beschreibe ich ein fundamentales Problem: Das Vertrauen des Betriebssystems in die Hardware. Ein USB-Keylogger arbeitet auf der physikalischen Ebene. Er fängt die Scancodes ab, bevor sie das OS erreichen.
❓ Was passiert, wenn der Keylogger nicht hinter der Tastatur steckt, sondern darin?
Dieses winzige Modul wird direkt auf in der Tastatur an den USB-Anschluss gelötet. Von außen ist absolut nichts sichtbar. Kein verdächtiger USB-Stick, kein zusätzlicher Adapter.
Das ist die Königsdisziplin der Spionage: 𝘔𝘰𝘥𝘪𝘧𝘪𝘻𝘪𝘦𝘳𝘵𝘦 𝘏𝘢𝘳𝘥𝘸𝘢𝘳𝘦
#HackingHardware #Keylogger #USBKeylogger #KeyloggerModul #Workshop
-
𝗗𝗮𝘀 𝗞𝗲𝘆𝗹𝗼𝗴𝗴𝗲𝗿-𝗠𝗼𝗱𝘂𝗹 - 𝗜𝗻𝗰𝗲𝗽𝘁𝗶𝗼𝗻 𝗶𝗻 𝗱𝗲𝗿 𝗧𝗮𝘀𝘁𝗮𝘁𝘂𝗿 ⌨️
In meinem Buch „Hardware & Security“ beschreibe ich ein fundamentales Problem: Das Vertrauen des Betriebssystems in die Hardware. Ein USB-Keylogger arbeitet auf der physikalischen Ebene. Er fängt die Scancodes ab, bevor sie das OS erreichen.
❓ Was passiert, wenn der Keylogger nicht hinter der Tastatur steckt, sondern darin?
Dieses winzige Modul wird direkt auf in der Tastatur an den USB-Anschluss gelötet. Von außen ist absolut nichts sichtbar. Kein verdächtiger USB-Stick, kein zusätzlicher Adapter.
Das ist die Königsdisziplin der Spionage: 𝘔𝘰𝘥𝘪𝘧𝘪𝘻𝘪𝘦𝘳𝘵𝘦 𝘏𝘢𝘳𝘥𝘸𝘢𝘳𝘦
#HackingHardware #Keylogger #USBKeylogger #KeyloggerModul #Workshop
-
𝗗𝗮𝘀 𝗞𝗲𝘆𝗹𝗼𝗴𝗴𝗲𝗿-𝗠𝗼𝗱𝘂𝗹 - 𝗜𝗻𝗰𝗲𝗽𝘁𝗶𝗼𝗻 𝗶𝗻 𝗱𝗲𝗿 𝗧𝗮𝘀𝘁𝗮𝘁𝘂𝗿 ⌨️
In meinem Buch „Hardware & Security“ beschreibe ich ein fundamentales Problem: Das Vertrauen des Betriebssystems in die Hardware. Ein USB-Keylogger arbeitet auf der physikalischen Ebene. Er fängt die Scancodes ab, bevor sie das OS erreichen.
❓ Was passiert, wenn der Keylogger nicht hinter der Tastatur steckt, sondern darin?
Dieses winzige Modul wird direkt auf in der Tastatur an den USB-Anschluss gelötet. Von außen ist absolut nichts sichtbar. Kein verdächtiger USB-Stick, kein zusätzlicher Adapter.
Das ist die Königsdisziplin der Spionage: 𝘔𝘰𝘥𝘪𝘧𝘪𝘻𝘪𝘦𝘳𝘵𝘦 𝘏𝘢𝘳𝘥𝘸𝘢𝘳𝘦
#HackingHardware #Keylogger #USBKeylogger #KeyloggerModul #Workshop
-
𝗨𝗦𝗕-𝗞𝗲𝘆𝗹𝗼𝗴𝗴𝗲𝗿 (𝗨𝗻𝗮𝘂𝗳𝗳𝗮̈𝗹𝗹𝗶𝗴𝗲 𝗦𝗽𝗶𝗼𝗻𝗮𝗴𝗲) - 𝗗𝗲𝗿 "𝗨𝗻𝘀𝗶𝗰𝗵𝘁𝗯𝗮𝗿𝗲" 𝗙𝗲𝗶𝗻𝗱
Die Antivirus Software schläft tief und fest, während jedes Wort mitgeschrieben wird. 😴
Einer der meistunterschätzten Angriffsvektoren in Unternehmen ist nicht der Phishing-Link, sondern das, was physisch zwischen Tastatur und PC steckt.
In meinen Workshop zeige ich diesen kleinen USB-Adapter. Er wird von Windows, macOS oder Linux nicht als Schadsoftware erkannt. Warum? Weil er die Signale unverändert durchleitet und mitprotokolliert, ohne dabei selbst mit dem Rechner zu interagieren.
Wer schaut schon auf die Rückseite seines Rechners, um fremde Hardware zu erkennen?
-
𝗨𝗦𝗕-𝗞𝗲𝘆𝗹𝗼𝗴𝗴𝗲𝗿 (𝗨𝗻𝗮𝘂𝗳𝗳𝗮̈𝗹𝗹𝗶𝗴𝗲 𝗦𝗽𝗶𝗼𝗻𝗮𝗴𝗲) - 𝗗𝗲𝗿 "𝗨𝗻𝘀𝗶𝗰𝗵𝘁𝗯𝗮𝗿𝗲" 𝗙𝗲𝗶𝗻𝗱
Die Antivirus Software schläft tief und fest, während jedes Wort mitgeschrieben wird. 😴
Einer der meistunterschätzten Angriffsvektoren in Unternehmen ist nicht der Phishing-Link, sondern das, was physisch zwischen Tastatur und PC steckt.
In meinen Workshop zeige ich diesen kleinen USB-Adapter. Er wird von Windows, macOS oder Linux nicht als Schadsoftware erkannt. Warum? Weil er die Signale unverändert durchleitet und mitprotokolliert, ohne dabei selbst mit dem Rechner zu interagieren.
Wer schaut schon auf die Rückseite seines Rechners, um fremde Hardware zu erkennen?
-
𝗨𝗦𝗕-𝗞𝗲𝘆𝗹𝗼𝗴𝗴𝗲𝗿 (𝗨𝗻𝗮𝘂𝗳𝗳𝗮̈𝗹𝗹𝗶𝗴𝗲 𝗦𝗽𝗶𝗼𝗻𝗮𝗴𝗲) - 𝗗𝗲𝗿 "𝗨𝗻𝘀𝗶𝗰𝗵𝘁𝗯𝗮𝗿𝗲" 𝗙𝗲𝗶𝗻𝗱
Die Antivirus Software schläft tief und fest, während jedes Wort mitgeschrieben wird. 😴
Einer der meistunterschätzten Angriffsvektoren in Unternehmen ist nicht der Phishing-Link, sondern das, was physisch zwischen Tastatur und PC steckt.
In meinen Workshop zeige ich diesen kleinen USB-Adapter. Er wird von Windows, macOS oder Linux nicht als Schadsoftware erkannt. Warum? Weil er die Signale unverändert durchleitet und mitprotokolliert, ohne dabei selbst mit dem Rechner zu interagieren.
Wer schaut schon auf die Rückseite seines Rechners, um fremde Hardware zu erkennen?
-
𝗨𝗦𝗕-𝗞𝗲𝘆𝗹𝗼𝗴𝗴𝗲𝗿 (𝗨𝗻𝗮𝘂𝗳𝗳𝗮̈𝗹𝗹𝗶𝗴𝗲 𝗦𝗽𝗶𝗼𝗻𝗮𝗴𝗲) - 𝗗𝗲𝗿 "𝗨𝗻𝘀𝗶𝗰𝗵𝘁𝗯𝗮𝗿𝗲" 𝗙𝗲𝗶𝗻𝗱
Die Antivirus Software schläft tief und fest, während jedes Wort mitgeschrieben wird. 😴
Einer der meistunterschätzten Angriffsvektoren in Unternehmen ist nicht der Phishing-Link, sondern das, was physisch zwischen Tastatur und PC steckt.
In meinen Workshop zeige ich diesen kleinen USB-Adapter. Er wird von Windows, macOS oder Linux nicht als Schadsoftware erkannt. Warum? Weil er die Signale unverändert durchleitet und mitprotokolliert, ohne dabei selbst mit dem Rechner zu interagieren.
Wer schaut schon auf die Rückseite seines Rechners, um fremde Hardware zu erkennen?
-
𝗨𝗦𝗕-𝗞𝗲𝘆𝗹𝗼𝗴𝗴𝗲𝗿 (𝗨𝗻𝗮𝘂𝗳𝗳𝗮̈𝗹𝗹𝗶𝗴𝗲 𝗦𝗽𝗶𝗼𝗻𝗮𝗴𝗲) - 𝗗𝗲𝗿 "𝗨𝗻𝘀𝗶𝗰𝗵𝘁𝗯𝗮𝗿𝗲" 𝗙𝗲𝗶𝗻𝗱
Die Antivirus Software schläft tief und fest, während jedes Wort mitgeschrieben wird. 😴
Einer der meistunterschätzten Angriffsvektoren in Unternehmen ist nicht der Phishing-Link, sondern das, was physisch zwischen Tastatur und PC steckt.
In meinen Workshop zeige ich diesen kleinen USB-Adapter. Er wird von Windows, macOS oder Linux nicht als Schadsoftware erkannt. Warum? Weil er die Signale unverändert durchleitet und mitprotokolliert, ohne dabei selbst mit dem Rechner zu interagieren.
Wer schaut schon auf die Rückseite seines Rechners, um fremde Hardware zu erkennen?
-
#Firefox shippt #Brave-#AdBlock-Engine, Looksmaxxing und das Harz der Apokalypse
c't 4004 – der c't-3003-Podcast: #Meta zwingt zum #Keylogger | 22
- 17:32:
Take der Woche: Warum man sich von Meta fernhalten sollte
-1:22:32 News aus der #Krise: #PCB-Harz wird knapp
- 1:32:32:
Firefox shippt heimlich Brave Adblock Engine
Webseite der Episode:
https://ct-3003.podigee.io/23-new-episodeMediendatei:
https://audio.podigee-cdn.net/2482245-m-c27baab9b05f1a15697574de167edcd2.mp3?source=feed -
#Firefox shippt #Brave-#AdBlock-Engine, Looksmaxxing und das Harz der Apokalypse
c't 4004 – der c't-3003-Podcast: #Meta zwingt zum #Keylogger | 22
- 17:32:
Take der Woche: Warum man sich von Meta fernhalten sollte
-1:22:32 News aus der #Krise: #PCB-Harz wird knapp
- 1:32:32:
Firefox shippt heimlich Brave Adblock Engine
Webseite der Episode:
https://ct-3003.podigee.io/23-new-episodeMediendatei:
https://audio.podigee-cdn.net/2482245-m-c27baab9b05f1a15697574de167edcd2.mp3?source=feed -
𝘕𝘦𝘶𝘦𝘳 𝘉𝘭𝘰𝘨-𝘈𝘳𝘵𝘪𝘬𝘦𝘭: 𝗞𝗲𝘆𝗹𝗼𝗴𝗴𝗲𝗿 & 𝗕𝗮𝗱𝗨𝗦𝗕: 𝗔𝗶𝗿𝗗𝗿𝗶𝘃𝗲 𝗞𝗲𝘆𝗯𝗼𝗮𝗿𝗱 𝗪𝗶𝘇𝗮𝗿𝗱 𝗪𝗶𝗙𝗶 📖
➡️ Ich habe mir wieder eine neue Hardware besorgt: den AirDrive Keyboard Wizard WiFi. Diese kleine Hardware sieht aus wie ein USB-Tastaturadapter. Im Inneren befindet sich neben einem Hardware-Keylogger auch eine BadUSB-Funktion. Damit kann der Adapter eigenständig Tastatureingaben tätigen. Ich habe mir die Hacking-Hardware genauer angeschaut.
Zum Artikel: https://scheible.it/keylogger-badusb-airdrive-keyboard-wizard-wifi/
#HackingHardware #Innentäter #Keylogger #BadUSB
https://scheible.it/keylogger-badusb-airdrive-keyboard-wizard-wifi/