#malware — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #malware, aggregated by home.social.
-
Quel(s) syndicat(s) propose(nt) à ses adhérents de le(s) suivre sur des #réseaux_sociaux #malveillants #Malware comme #Facebook, #Instagram, #TikTok, de le(s) contacter sur #Gmail #Whatsapp, de faire une #Visio #Visioconférence sur #zoom ou #Teams ?
#CGT #FO #CFTC #UNSA #FSU #Solidaires
Que fera une #ExtrêmeDroite au pouvoir en #France ?
2min : https://video.blast-info.fr/w/gUwNAWd7rTh5XeX8mb7geS?start=15m26s&stop=16m49s
"Flinguer" les #militants de #gauche et les syndicats.
1/4
Les syndicats protègent ma #ViePrivée :
-
Quel(s) syndicat(s) propose(nt) à ses adhérents de le(s) suivre sur des #réseaux_sociaux #malveillants #Malware comme #Facebook, #Instagram, #TikTok, de le(s) contacter sur #Gmail #Whatsapp, de faire une #Visio #Visioconférence sur #zoom ou #Teams ?
#CGT #FO #CFTC #UNSA #FSU #Solidaires
Que fera une #ExtrêmeDroite au pouvoir en #France ?
2min : https://video.blast-info.fr/w/gUwNAWd7rTh5XeX8mb7geS?start=15m26s&stop=16m49s
"Flinguer" les #militants de #gauche et les syndicats.
1/4
Les syndicats protègent ma #ViePrivée :
-
Quel(s) syndicat(s) propose(nt) à ses adhérents de le(s) suivre sur des #réseaux_sociaux #malveillants #Malware comme #Facebook, #Instagram, #TikTok, de le(s) contacter sur #Gmail #Whatsapp, de faire une #Visio #Visioconférence sur #zoom ou #Teams ?
#CGT #FO #CFTC #UNSA #FSU #Solidaires
Que fera une #ExtrêmeDroite au pouvoir en #France ?
2min : https://video.blast-info.fr/w/gUwNAWd7rTh5XeX8mb7geS?start=15m26s&stop=16m49s
"Flinguer" les #militants de #gauche et les syndicats.
1/4
Les syndicats protègent ma #ViePrivée :
-
Quel(s) syndicat(s) propose(nt) à ses adhérents de le(s) suivre sur des #réseaux_sociaux #malveillants #Malware comme #Facebook, #Instagram, #TikTok, de le(s) contacter sur #Gmail #Whatsapp, de faire une #Visio #Visioconférence sur #zoom ou #Teams ?
#CGT #FO #CFTC #UNSA #FSU #Solidaires
Que fera une #ExtrêmeDroite au pouvoir en #France ?
2min : https://video.blast-info.fr/w/gUwNAWd7rTh5XeX8mb7geS?start=15m26s&stop=16m49s
"Flinguer" les #militants de #gauche et les syndicats.
1/4
Les syndicats protègent ma #ViePrivée :
-
Quel(s) syndicat(s) propose(nt) à ses adhérents de le(s) suivre sur des #réseaux_sociaux #malveillants #Malware comme #Facebook, #Instagram, #TikTok, de le(s) contacter sur #Gmail #Whatsapp, de faire une #Visio #Visioconférence sur #zoom ou #Teams ?
#CGT #FO #CFTC #UNSA #FSU #Solidaires
Que fera une #ExtrêmeDroite au pouvoir en #France ?
2min : https://video.blast-info.fr/w/gUwNAWd7rTh5XeX8mb7geS?start=15m26s&stop=16m49s
"Flinguer" les #militants de #gauche et les syndicats.
1/4
Les syndicats protègent ma #ViePrivée :
-
Cert Polska: Meta‑hirdetések vezettek a Playen lévő Messenger Prohoz, ami titkos betöltővel prémium SMS-ekre iratkozott fel. Érintett vagy? Töröld az appot és ellenőrizd a mobilászfizetéseidet.
#CERTPolska #Meta #Android #MessengerPro #GooglePlay #premiumSMS #malware #mobilszámlázás #biztonság #ITbiztonság
-
Cert Polska: Meta‑hirdetések vezettek a Playen lévő Messenger Prohoz, ami titkos betöltővel prémium SMS-ekre iratkozott fel. Érintett vagy? Töröld az appot és ellenőrizd a mobilászfizetéseidet.
#CERTPolska #Meta #Android #MessengerPro #GooglePlay #premiumSMS #malware #mobilszámlázás #biztonság #ITbiztonság
-
Cert Polska: Meta‑hirdetések vezettek a Playen lévő Messenger Prohoz, ami titkos betöltővel prémium SMS-ekre iratkozott fel. Érintett vagy? Töröld az appot és ellenőrizd a mobilászfizetéseidet.
#CERTPolska #Meta #Android #MessengerPro #GooglePlay #premiumSMS #malware #mobilszámlázás #biztonság #ITbiztonság
-
Cert Polska: Meta‑hirdetések vezettek a Playen lévő Messenger Prohoz, ami titkos betöltővel prémium SMS-ekre iratkozott fel. Érintett vagy? Töröld az appot és ellenőrizd a mobilászfizetéseidet.
#CERTPolska #Meta #Android #MessengerPro #GooglePlay #premiumSMS #malware #mobilszámlázás #biztonság #ITbiztonság
-
Cert Polska: Meta‑hirdetések vezettek a Playen lévő Messenger Prohoz, ami titkos betöltővel prémium SMS-ekre iratkozott fel. Érintett vagy? Töröld az appot és ellenőrizd a mobilászfizetéseidet.
#CERTPolska #Meta #Android #MessengerPro #GooglePlay #premiumSMS #malware #mobilszámlázás #biztonság #ITbiztonság
-
Hackers Turned Ethereum Into a Secret Messaging System for Malware
A North Korea-linked malware campaign has found a way to keep infected computers connected to its operators. Instead of storing malware on Ethereum, the attackers hide the location of a control server inside cryptocurrency transfers. The campaign reaches developers through fake job offers, tainted code repositories and malicious software packages. Running the code can install […] The post Hackers Turned Ethereum Into a Secret Messaging System for Malware appeared first on Cyber Security News .
Pulse ID: 6abbd180e44bac1271a42ec6
Pulse Link: https://otx.alienvault.com/pulse/6abbd180e44bac1271a42ec6
Pulse Author: CyberHunter_NL
Created: 2026-09-29 14:56:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Malware #cryptocurrency #developers #NorthKorea #OTX #CyberHunter_NL
-
Hackers Turned Ethereum Into a Secret Messaging System for Malware
A North Korea-linked malware campaign has found a way to keep infected computers connected to its operators. Instead of storing malware on Ethereum, the attackers hide the location of a control server inside cryptocurrency transfers. The campaign reaches developers through fake job offers, tainted code repositories and malicious software packages. Running the code can install […] The post Hackers Turned Ethereum Into a Secret Messaging System for Malware appeared first on Cyber Security News .
Pulse ID: 6abbd180e44bac1271a42ec6
Pulse Link: https://otx.alienvault.com/pulse/6abbd180e44bac1271a42ec6
Pulse Author: CyberHunter_NL
Created: 2026-09-29 14:56:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Malware #cryptocurrency #developers #NorthKorea #OTX #CyberHunter_NL
-
Hackers Turned Ethereum Into a Secret Messaging System for Malware
A North Korea-linked malware campaign has found a way to keep infected computers connected to its operators. Instead of storing malware on Ethereum, the attackers hide the location of a control server inside cryptocurrency transfers. The campaign reaches developers through fake job offers, tainted code repositories and malicious software packages. Running the code can install […] The post Hackers Turned Ethereum Into a Secret Messaging System for Malware appeared first on Cyber Security News .
Pulse ID: 6abbd180e44bac1271a42ec6
Pulse Link: https://otx.alienvault.com/pulse/6abbd180e44bac1271a42ec6
Pulse Author: CyberHunter_NL
Created: 2026-09-29 14:56:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Malware #cryptocurrency #developers #NorthKorea #OTX #CyberHunter_NL
-
Hackers Turned Ethereum Into a Secret Messaging System for Malware
A North Korea-linked malware campaign has found a way to keep infected computers connected to its operators. Instead of storing malware on Ethereum, the attackers hide the location of a control server inside cryptocurrency transfers. The campaign reaches developers through fake job offers, tainted code repositories and malicious software packages. Running the code can install […] The post Hackers Turned Ethereum Into a Secret Messaging System for Malware appeared first on Cyber Security News .
Pulse ID: 6abbd180e44bac1271a42ec6
Pulse Link: https://otx.alienvault.com/pulse/6abbd180e44bac1271a42ec6
Pulse Author: CyberHunter_NL
Created: 2026-09-29 14:56:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Malware #cryptocurrency #developers #NorthKorea #OTX #CyberHunter_NL
-
Hackers Turned Ethereum Into a Secret Messaging System for Malware
A North Korea-linked malware campaign has found a way to keep infected computers connected to its operators. Instead of storing malware on Ethereum, the attackers hide the location of a control server inside cryptocurrency transfers. The campaign reaches developers through fake job offers, tainted code repositories and malicious software packages. Running the code can install […] The post Hackers Turned Ethereum Into a Secret Messaging System for Malware appeared first on Cyber Security News .
Pulse ID: 6abbd180e44bac1271a42ec6
Pulse Link: https://otx.alienvault.com/pulse/6abbd180e44bac1271a42ec6
Pulse Author: CyberHunter_NL
Created: 2026-09-29 14:56:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Malware #cryptocurrency #developers #NorthKorea #OTX #CyberHunter_NL
-
SilverFox Hackers Built Fake Software Sites That Hide Malware From Security Researchers
Fake software download pages are drawing Windows users into a Silver Fox-linked malware campaign. The pages imitate familiar vendors and supply installers that can leave an infected computer vulnerable to continued access. Microsoft has observed compromises across several industries, mainly affecting Chinese-speaking users. The attackers rely on a simple habit: people search for an application, […] The post SilverFox Hackers Built Fake Software Sites That Hide Malware From Security Researchers appeared first on Cyber Security News .
Pulse ID: 6abbd1840ec1548557e63430
Pulse Link: https://otx.alienvault.com/pulse/6abbd1840ec1548557e63430
Pulse Author: CyberHunter_NL
Created: 2026-09-29 14:56:04Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
SilverFox Hackers Built Fake Software Sites That Hide Malware From Security Researchers
Fake software download pages are drawing Windows users into a Silver Fox-linked malware campaign. The pages imitate familiar vendors and supply installers that can leave an infected computer vulnerable to continued access. Microsoft has observed compromises across several industries, mainly affecting Chinese-speaking users. The attackers rely on a simple habit: people search for an application, […] The post SilverFox Hackers Built Fake Software Sites That Hide Malware From Security Researchers appeared first on Cyber Security News .
Pulse ID: 6abbd1840ec1548557e63430
Pulse Link: https://otx.alienvault.com/pulse/6abbd1840ec1548557e63430
Pulse Author: CyberHunter_NL
Created: 2026-09-29 14:56:04Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
SilverFox Hackers Built Fake Software Sites That Hide Malware From Security Researchers
Fake software download pages are drawing Windows users into a Silver Fox-linked malware campaign. The pages imitate familiar vendors and supply installers that can leave an infected computer vulnerable to continued access. Microsoft has observed compromises across several industries, mainly affecting Chinese-speaking users. The attackers rely on a simple habit: people search for an application, […] The post SilverFox Hackers Built Fake Software Sites That Hide Malware From Security Researchers appeared first on Cyber Security News .
Pulse ID: 6abbd1840ec1548557e63430
Pulse Link: https://otx.alienvault.com/pulse/6abbd1840ec1548557e63430
Pulse Author: CyberHunter_NL
Created: 2026-09-29 14:56:04Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
SilverFox Hackers Built Fake Software Sites That Hide Malware From Security Researchers
Fake software download pages are drawing Windows users into a Silver Fox-linked malware campaign. The pages imitate familiar vendors and supply installers that can leave an infected computer vulnerable to continued access. Microsoft has observed compromises across several industries, mainly affecting Chinese-speaking users. The attackers rely on a simple habit: people search for an application, […] The post SilverFox Hackers Built Fake Software Sites That Hide Malware From Security Researchers appeared first on Cyber Security News .
Pulse ID: 6abbd1840ec1548557e63430
Pulse Link: https://otx.alienvault.com/pulse/6abbd1840ec1548557e63430
Pulse Author: CyberHunter_NL
Created: 2026-09-29 14:56:04Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
SilverFox Hackers Built Fake Software Sites That Hide Malware From Security Researchers
Fake software download pages are drawing Windows users into a Silver Fox-linked malware campaign. The pages imitate familiar vendors and supply installers that can leave an infected computer vulnerable to continued access. Microsoft has observed compromises across several industries, mainly affecting Chinese-speaking users. The attackers rely on a simple habit: people search for an application, […] The post SilverFox Hackers Built Fake Software Sites That Hide Malware From Security Researchers appeared first on Cyber Security News .
Pulse ID: 6abbd1840ec1548557e63430
Pulse Link: https://otx.alienvault.com/pulse/6abbd1840ec1548557e63430
Pulse Author: CyberHunter_NL
Created: 2026-09-29 14:56:04Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
The attack isn't rocket science but from an attacker perspective quite neat.
The MSI is quite small and contains, appart from the hostnames little "suspicious" code.
The random readme prevents signature based detection.
As the code is retrieved and directly executed in memory, file based detections can't detect it.
Furthermore, attackers can modify it anytime and the next execution uses the updated code.And, last but not least there is less forensic evidence left on the infected system.
As I mentioned, I couldn't retrive the code and therefore I can't analyse what the code did 🥴
-
The attack isn't rocket science but from an attacker perspective quite neat.
The MSI is quite small and contains, appart from the hostnames little "suspicious" code.
The random readme prevents signature based detection.
As the code is retrieved and directly executed in memory, file based detections can't detect it.
Furthermore, attackers can modify it anytime and the next execution uses the updated code.And, last but not least there is less forensic evidence left on the infected system.
As I mentioned, I couldn't retrive the code and therefore I can't analyse what the code did 🥴
-
The attack isn't rocket science but from an attacker perspective quite neat.
The MSI is quite small and contains, appart from the hostnames little "suspicious" code.
The random readme prevents signature based detection.
As the code is retrieved and directly executed in memory, file based detections can't detect it.
Furthermore, attackers can modify it anytime and the next execution uses the updated code.And, last but not least there is less forensic evidence left on the infected system.
As I mentioned, I couldn't retrive the code and therefore I can't analyse what the code did 🥴
-
The attack isn't rocket science but from an attacker perspective quite neat.
The MSI is quite small and contains, appart from the hostnames little "suspicious" code.
The random readme prevents signature based detection.
As the code is retrieved and directly executed in memory, file based detections can't detect it.
Furthermore, attackers can modify it anytime and the next execution uses the updated code.And, last but not least there is less forensic evidence left on the infected system.
As I mentioned, I couldn't retrive the code and therefore I can't analyse what the code did 🥴
-
The attack isn't rocket science but from an attacker perspective quite neat.
The MSI is quite small and contains, appart from the hostnames little "suspicious" code.
The random readme prevents signature based detection.
As the code is retrieved and directly executed in memory, file based detections can't detect it.
Furthermore, attackers can modify it anytime and the next execution uses the updated code.And, last but not least there is less forensic evidence left on the infected system.
As I mentioned, I couldn't retrive the code and therefore I can't analyse what the code did 🥴
-
🚨 PHISHING DETECTED 🚨
🔗 Suspicious URL: keycloak[.]evergreenfin[.]ltd
🔍 Analysis at: https://phishdestroy.io/domain/keycloak.evergreenfin.ltd/#NFT #CyberFraud #ScamPrevention #WalletHackers #BlockchainSafety #malware #ScamDetection
-
🚨 PHISHING DETECTED 🚨
🔗 Suspicious URL: keycloak[.]evergreenfin[.]ltd
🔍 Analysis at: https://phishdestroy.io/domain/keycloak.evergreenfin.ltd/#NFT #CyberFraud #ScamPrevention #WalletHackers #BlockchainSafety #malware #ScamDetection
-
🚨 PHISHING DETECTED 🚨
🔗 Suspicious URL: vip[.]beacox[.]com
🔍 Analysis at: https://phishdestroy.io/domain/vip.beacox.com/ -
🚨 PHISHING DETECTED 🚨
🔗 Suspicious URL: vip[.]beacox[.]com
🔍 Analysis at: https://phishdestroy.io/domain/vip.beacox.com/ -
🚨 PHISHING DETECTED 🚨
🔗 Suspicious URL: vip[.]foapux[.]com
🔍 Analysis at: https://phishdestroy.io/domain/vip.foapux.com/#CryptoAwareness #malware #WalletHackers #CryptoThreats #AntiPhishing #Web3Hacking #Web3Awareness
-
🚨 PHISHING DETECTED 🚨
🔗 Suspicious URL: vip[.]foapux[.]com
🔍 Analysis at: https://phishdestroy.io/domain/vip.foapux.com/#CryptoAwareness #malware #WalletHackers #CryptoThreats #AntiPhishing #Web3Hacking #Web3Awareness
-
🚨 PHISHING DETECTED 🚨
🔗 Suspicious URL: royal[.]fexowin[.]com
🔍 Analysis at: https://phishdestroy.io/domain/royal.fexowin.com/#malware #CryptoAwareness #WalletDrainers #AntiPhishing #Web3Hacking #PhishingScam #scamalert
-
🚨 PHISHING DETECTED 🚨
🔗 Suspicious URL: royal[.]fexowin[.]com
🔍 Analysis at: https://phishdestroy.io/domain/royal.fexowin.com/#malware #CryptoAwareness #WalletDrainers #AntiPhishing #Web3Hacking #PhishingScam #scamalert
-
As I managed to get my hands on the malicious MSI file I can provide some more details.
You can unpack the MSI file with 7zip.
This reveals a PowerShell script.This script downloads a standalone Python interpreter, installs pip and some packages (
pythonnet,pywin32,pywinpty, andwebsockets).It than creates a README.md with random ASCII content
And finally, loads and executed some Python code from one of three host (portojavspirit.net, herobustore.net, appsyspro.net) at
/cl/flash/c?v=17and executes the codeSadly, I failed to retrive the code from any of the above-mentioned hosts.
So again, if someone has more success, let me know.
-
As I managed to get my hands on the malicious MSI file I can provide some more details.
You can unpack the MSI file with 7zip.
This reveals a PowerShell script.This script downloads a standalone Python interpreter, installs pip and some packages (
pythonnet,pywin32,pywinpty, andwebsockets).It than creates a README.md with random ASCII content
And finally, loads and executed some Python code from one of three host (portojavspirit.net, herobustore.net, appsyspro.net) at
/cl/flash/c?v=17and executes the codeSadly, I failed to retrive the code from any of the above-mentioned hosts.
So again, if someone has more success, let me know.
-
As I managed to get my hands on the malicious MSI file I can provide some more details.
You can unpack the MSI file with 7zip.
This reveals a PowerShell script.This script downloads a standalone Python interpreter, installs pip and some packages (
pythonnet,pywin32,pywinpty, andwebsockets).It than creates a README.md with random ASCII content
And finally, loads and executed some Python code from one of three host (portojavspirit.net, herobustore.net, appsyspro.net) at
/cl/flash/c?v=17and executes the codeSadly, I failed to retrive the code from any of the above-mentioned hosts.
So again, if someone has more success, let me know.
-
As I managed to get my hands on the malicious MSI file I can provide some more details.
You can unpack the MSI file with 7zip.
This reveals a PowerShell script.This script downloads a standalone Python interpreter, installs pip and some packages (
pythonnet,pywin32,pywinpty, andwebsockets).It than creates a README.md with random ASCII content
And finally, loads and executed some Python code from one of three host (portojavspirit.net, herobustore.net, appsyspro.net) at
/cl/flash/c?v=17and executes the codeSadly, I failed to retrive the code from any of the above-mentioned hosts.
So again, if someone has more success, let me know.
-
As I managed to get my hands on the malicious MSI file I can provide some more details.
You can unpack the MSI file with 7zip.
This reveals a PowerShell script.This script downloads a standalone Python interpreter, installs pip and some packages (
pythonnet,pywin32,pywinpty, andwebsockets).It than creates a README.md with random ASCII content
And finally, loads and executed some Python code from one of three host (portojavspirit.net, herobustore.net, appsyspro.net) at
/cl/flash/c?v=17and executes the codeSadly, I failed to retrive the code from any of the above-mentioned hosts.
So again, if someone has more success, let me know.
-
🚨 PHISHING DETECTED 🚨
🔗 Suspicious URL: huiyuanzhongxin[.]evergreenfin[.]ltd
🔍 Analysis at: https://phishdestroy.io/domain/huiyuanzhongxin.evergreenfin.ltd/#BlockchainSafety #malware #WalletHackers #ScamDetection #NFT #ScamPrevention #CryptoAwareness
-
🚨 PHISHING DETECTED 🚨
🔗 Suspicious URL: huiyuanzhongxin[.]evergreenfin[.]ltd
🔍 Analysis at: https://phishdestroy.io/domain/huiyuanzhongxin.evergreenfin.ltd/#BlockchainSafety #malware #WalletHackers #ScamDetection #NFT #ScamPrevention #CryptoAwareness
-
🚨 PHISHING DETECTED 🚨
🔗 Suspicious URL: home[.]koesux[.]com
🔍 Analysis at: https://phishdestroy.io/domain/home.koesux.com/#malware #Web3Security #AntiPhishing #CryptoHacking #WalletSecurity #CryptoProtection #CyberFraud
-
🚨 PHISHING DETECTED 🚨
🔗 Suspicious URL: home[.]koesux[.]com
🔍 Analysis at: https://phishdestroy.io/domain/home.koesux.com/#malware #Web3Security #AntiPhishing #CryptoHacking #WalletSecurity #CryptoProtection #CyberFraud
-
🚨 PHISHING DETECTED 🚨
🔗 Suspicious URL: home[.]doahux[.]com
🔍 Analysis at: https://phishdestroy.io/domain/home.doahux.com/#AntiPhishing #ProtectCrypto #scam #NFT #BlockchainFraud #malware #ScamDetection
-
🚨 PHISHING DETECTED 🚨
🔗 Suspicious URL: home[.]doahux[.]com
🔍 Analysis at: https://phishdestroy.io/domain/home.doahux.com/#AntiPhishing #ProtectCrypto #scam #NFT #BlockchainFraud #malware #ScamDetection
-
🚨 PHISHING DETECTED 🚨
🔗 Suspicious URL: go[.]caagex[.]com
🔍 Analysis at: https://phishdestroy.io/domain/go.caagex.com/ -
🚨 PHISHING DETECTED 🚨
🔗 Suspicious URL: go[.]caagex[.]com
🔍 Analysis at: https://phishdestroy.io/domain/go.caagex.com/ -
🚨 PHISHING DETECTED 🚨
🔗 Suspicious URL: sophies[.]hostel[.]town
🔍 Analysis at: https://phishdestroy.io/domain/sophies.hostel.town/#DigitalFraud #CryptoHacking #ScamDetection #fake #BlockchainFraud #malware
-
🚨 PHISHING DETECTED 🚨
🔗 Suspicious URL: sophies[.]hostel[.]town
🔍 Analysis at: https://phishdestroy.io/domain/sophies.hostel.town/#DigitalFraud #CryptoHacking #ScamDetection #fake #BlockchainFraud #malware
-
🚨 PHISHING DETECTED 🚨
🔗 Suspicious URL: gmarket[.]evergreenfin[.]ltd
🔍 Analysis at: https://phishdestroy.io/domain/gmarket.evergreenfin.ltd/#NFT #scam #CryptoHacking #malware #PhishingWarning #ScamPrevention #CyberFraud
-
🚨 PHISHING DETECTED 🚨
🔗 Suspicious URL: gmarket[.]evergreenfin[.]ltd
🔍 Analysis at: https://phishdestroy.io/domain/gmarket.evergreenfin.ltd/#NFT #scam #CryptoHacking #malware #PhishingWarning #ScamPrevention #CyberFraud