home.social

#password — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #password, aggregated by home.social.

  1. Telegram Desktop Session Theft Via macOS Infostealer Malware

    Recommendations for users of the messaging service Telegram to change their passwords and make sure they are safe and easy to log into, as well as access to the service, have been published by the BBC.

    Pulse ID: 6a59dfd7382e71d3bfe00b33
    Pulse Link: otx.alienvault.com/pulse/6a59d
    Pulse Author: cryptocti
    Created: 2026-07-17 07:55:03

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BBC #CyberSecurity #InfoSec #InfoStealer #Mac #MacOS #Malware #OTX #OpenThreatExchange #Password #Passwords #Telegram #Word #bot #cryptocti

  2. ClickLock Stealer: Paste Once, Lose Everything

    A new modular macOS information stealer named ClickLock Stealer has been discovered targeting users primarily in Europe, North America, and the Middle East. The malware is likely distributed via ClickFix social engineering pages that trick victims into pasting malicious commands into Terminal. Once executed, it deploys four components: a credential stealer, a Keychain stealer targeting Chrome's encryption key, a comprehensive crypto wallet harvester, and a persistent GSocket-based backdoor. The malware employs an aggressive 'locker' technique, killing all visible applications except password dialogs to force user compliance. It targets data from eight browsers, 31 crypto wallet extensions, seven password managers, desktop wallets, macOS Keychain, and shell history. The campaign has compromised at least 100 victims across 33 countries since May 2026, using compromised WordPress domains and Telegram for command and control and exfiltration.

    Pulse ID: 6a58c1a90a160ce1e25e78e7
    Pulse Link: otx.alienvault.com/pulse/6a58c
    Pulse Author: AlienVault
    Created: 2026-07-16 11:34:01

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Browser #Chrome #CyberSecurity #Encryption #Europe #InfoSec #Mac #MacOS #Malware #MiddleEast #NorthAmerica #OTX #OpenThreatExchange #Password #RAT #RCE #RDP #SocialEngineering #Telegram #Word #Wordpress #bot #AlienVault

  3. ClickLock Stealer: Paste Once, Lose Everything

    A new modular macOS information stealer named ClickLock Stealer has been discovered targeting users primarily in Europe, North America, and the Middle East. The malware is likely distributed via ClickFix social engineering pages that trick victims into pasting malicious commands into Terminal. Once executed, it deploys four components: a credential stealer, a Keychain stealer targeting Chrome's encryption key, a comprehensive crypto wallet harvester, and a persistent GSocket-based backdoor. The malware employs an aggressive 'locker' technique, killing all visible applications except password dialogs to force user compliance. It targets data from eight browsers, 31 crypto wallet extensions, seven password managers, desktop wallets, macOS Keychain, and shell history. The campaign has compromised at least 100 victims across 33 countries since May 2026, using compromised WordPress domains and Telegram for command and control and exfiltration.

    Pulse ID: 6a58c1a90a160ce1e25e78e7
    Pulse Link: otx.alienvault.com/pulse/6a58c
    Pulse Author: AlienVault
    Created: 2026-07-16 11:34:01

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Browser #Chrome #CyberSecurity #Encryption #Europe #InfoSec #Mac #MacOS #Malware #MiddleEast #NorthAmerica #OTX #OpenThreatExchange #Password #RAT #RCE #RDP #SocialEngineering #Telegram #Word #Wordpress #bot #AlienVault

  4. Shared Claude Chats Meet ClickFix

    A ClickFix campaign has been identified that abuses Anthropic's Claude platform through shareable chat links to distribute MacSync Stealer targeting macOS users. Attackers utilized malvertising with paid Google ads to direct victims searching for Claude-related terms to malicious shared Claude chats falsely labeled as 'Apple Support.' These chats contained obfuscated installation commands that, when executed, deployed a multi-stage infection chain. The malware steals credentials from browsers and password managers, cryptocurrency wallet data, sensitive files, and system information. The campaign ran from June 12-19, 2026, targeting primarily Mac users with Russian-language comments in the code suggesting Russian-speaking threat actors. Domains used adopted themes related to U.S. local services to appear legitimate.

    Pulse ID: 6a57b1d61379f5309f46131d
    Pulse Link: otx.alienvault.com/pulse/6a57b
    Pulse Author: AlienVault
    Created: 2026-07-15 16:14:14

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CyberSecurity #Google #GoogleAds #InfoSec #Mac #MacOS #Malvertising #Malware #OTX #OpenThreatExchange #Password #Russia #Word #bot #cryptocurrency #AlienVault

  5. Shared Claude Chats Meet ClickFix

    A ClickFix campaign has been identified that abuses Anthropic's Claude platform through shareable chat links to distribute MacSync Stealer targeting macOS users. Attackers utilized malvertising with paid Google ads to direct victims searching for Claude-related terms to malicious shared Claude chats falsely labeled as 'Apple Support.' These chats contained obfuscated installation commands that, when executed, deployed a multi-stage infection chain. The malware steals credentials from browsers and password managers, cryptocurrency wallet data, sensitive files, and system information. The campaign ran from June 12-19, 2026, targeting primarily Mac users with Russian-language comments in the code suggesting Russian-speaking threat actors. Domains used adopted themes related to U.S. local services to appear legitimate.

    Pulse ID: 6a57b1d61379f5309f46131d
    Pulse Link: otx.alienvault.com/pulse/6a57b
    Pulse Author: AlienVault
    Created: 2026-07-15 16:14:14

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CyberSecurity #Google #GoogleAds #InfoSec #Mac #MacOS #Malvertising #Malware #OTX #OpenThreatExchange #Password #Russia #Word #bot #cryptocurrency #AlienVault

  6. Six Minutes to Compromise: How 'Patriot Bait' Actor Used AI to Build and Deploy a C&C Botnet

    A Russian-speaking threat actor known as 'bandcampro' leveraged Google Gemini CLI to migrate and operate a command-and-control botnet in six minutes, with the AI handling 89% of all work including architecture, coding, deployment, and debugging. Analysis of 200 Gemini CLI session logs from March-April 2026 revealed the actor controlled eight computers in a dental clinic, accessing OpenDental databases. The actor communicated intentions in plain Russian while AI executed technical operations. The entire C&C infrastructure fits in three plain-text files totaling 5KB, making it highly portable and disposable. Beyond botnet operations, the actor used AI for password cracking, WordPress compromise, and planning cryptocurrency fraud targeting elderly victims in the US and Canada. The AI proactively suggested improvements 59 times unprompted, demonstrating how AI lowers barriers for threat actors by replacing technical skill requirements with simple natural-language instructions.

    Pulse ID: 6a57358efddea38fc28153f6
    Pulse Link: otx.alienvault.com/pulse/6a573
    Pulse Author: AlienVault
    Created: 2026-07-15 07:23:58

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Canada #CandC #CyberSecurity #Google #InfoSec #IoT #OTX #OpenThreatExchange #Password #RAT #RDP #Russia #Troll #Word #Wordpress #bot #botnet #cryptocurrency #AlienVault

  7. Six Minutes to Compromise: How 'Patriot Bait' Actor Used AI to Build and Deploy a C&C Botnet

    A Russian-speaking threat actor known as 'bandcampro' leveraged Google Gemini CLI to migrate and operate a command-and-control botnet in six minutes, with the AI handling 89% of all work including architecture, coding, deployment, and debugging. Analysis of 200 Gemini CLI session logs from March-April 2026 revealed the actor controlled eight computers in a dental clinic, accessing OpenDental databases. The actor communicated intentions in plain Russian while AI executed technical operations. The entire C&C infrastructure fits in three plain-text files totaling 5KB, making it highly portable and disposable. Beyond botnet operations, the actor used AI for password cracking, WordPress compromise, and planning cryptocurrency fraud targeting elderly victims in the US and Canada. The AI proactively suggested improvements 59 times unprompted, demonstrating how AI lowers barriers for threat actors by replacing technical skill requirements with simple natural-language instructions.

    Pulse ID: 6a57358efddea38fc28153f6
    Pulse Link: otx.alienvault.com/pulse/6a573
    Pulse Author: AlienVault
    Created: 2026-07-15 07:23:58

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Canada #CandC #CyberSecurity #Google #InfoSec #IoT #OTX #OpenThreatExchange #Password #RAT #RDP #Russia #Troll #Word #Wordpress #bot #botnet #cryptocurrency #AlienVault

  8. Threat Spotlight: The Jalisco Toolkit and AI-Powered Phishing Surge

    Phishing attacks have surged in 2026 as AI-powered phishing-as-a-service kits enable threat actors to bypass multi-factor authentication and harvest OAuth tokens at scale. Two phishing tools were identified in active campaigns: Jalisco, a device code phishing toolkit that provisions fresh OAuth codes in real time to defeat time-based security controls, and OmegaLord, a credential harvester that captures phone numbers alongside passwords to intercept MFA. Both tools demonstrate that attackers are engineering sophisticated methods to defeat authentication controls. These toolkits are part of a broader ecosystem that includes AI-powered PhaaS kits like EvilTokens and Kali365, which leverage legitimate cloud platforms to evade detection. Following compromise, attackers establish persistence by enrolling multiple devices to victim Entra ID tenants, enabling access that survives password resets and extends the window for data exfiltration and extortion.

    Pulse ID: 6a56e4f5789e1bf3de8e82be
    Pulse Link: otx.alienvault.com/pulse/6a56e
    Pulse Author: AlienVault
    Created: 2026-07-15 01:40:05

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #CyberSecurity #ESET #Extortion #InfoSec #MFA #OTX #OpenThreatExchange #Password #Passwords #Phishing #RAT #RCE #Word #bot #AlienVault

  9. Threat Spotlight: The Jalisco Toolkit and AI-Powered Phishing Surge

    Phishing attacks have surged in 2026 as AI-powered phishing-as-a-service kits enable threat actors to bypass multi-factor authentication and harvest OAuth tokens at scale. Two phishing tools were identified in active campaigns: Jalisco, a device code phishing toolkit that provisions fresh OAuth codes in real time to defeat time-based security controls, and OmegaLord, a credential harvester that captures phone numbers alongside passwords to intercept MFA. Both tools demonstrate that attackers are engineering sophisticated methods to defeat authentication controls. These toolkits are part of a broader ecosystem that includes AI-powered PhaaS kits like EvilTokens and Kali365, which leverage legitimate cloud platforms to evade detection. Following compromise, attackers establish persistence by enrolling multiple devices to victim Entra ID tenants, enabling access that survives password resets and extends the window for data exfiltration and extortion.

    Pulse ID: 6a56e4f5789e1bf3de8e82be
    Pulse Link: otx.alienvault.com/pulse/6a56e
    Pulse Author: AlienVault
    Created: 2026-07-15 01:40:05

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #CyberSecurity #ESET #Extortion #InfoSec #MFA #OTX #OpenThreatExchange #Password #Passwords #Phishing #RAT #RCE #Word #bot #AlienVault

  10. Threat Spotlight: The Jalisco Toolkit and AI-Powered Phishing Surge

    Phishing attacks have surged in 2026 as AI-powered phishing-as-a-service kits enable threat actors to bypass multi-factor authentication and harvest OAuth tokens at scale. Two phishing tools were identified in active campaigns: Jalisco, a device code phishing toolkit that provisions fresh OAuth codes in real time to defeat time-based security controls, and OmegaLord, a credential harvester that captures phone numbers alongside passwords to intercept MFA. Both tools demonstrate that attackers are engineering sophisticated methods to defeat authentication controls. These toolkits are part of a broader ecosystem that includes AI-powered PhaaS kits like EvilTokens and Kali365, which leverage legitimate cloud platforms to evade detection. Following compromise, attackers establish persistence by enrolling multiple devices to victim Entra ID tenants, enabling access that survives password resets and extends the window for data exfiltration and extortion.

    Pulse ID: 6a56e4f5789e1bf3de8e82be
    Pulse Link: otx.alienvault.com/pulse/6a56e
    Pulse Author: AlienVault
    Created: 2026-07-15 01:40:05

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #CyberSecurity #ESET #Extortion #InfoSec #MFA #OTX #OpenThreatExchange #Password #Passwords #Phishing #RAT #RCE #Word #bot #AlienVault

  11. Threat Spotlight: The Jalisco Toolkit and AI-Powered Phishing Surge

    Phishing attacks have surged in 2026 as AI-powered phishing-as-a-service kits enable threat actors to bypass multi-factor authentication and harvest OAuth tokens at scale. Two phishing tools were identified in active campaigns: Jalisco, a device code phishing toolkit that provisions fresh OAuth codes in real time to defeat time-based security controls, and OmegaLord, a credential harvester that captures phone numbers alongside passwords to intercept MFA. Both tools demonstrate that attackers are engineering sophisticated methods to defeat authentication controls. These toolkits are part of a broader ecosystem that includes AI-powered PhaaS kits like EvilTokens and Kali365, which leverage legitimate cloud platforms to evade detection. Following compromise, attackers establish persistence by enrolling multiple devices to victim Entra ID tenants, enabling access that survives password resets and extends the window for data exfiltration and extortion.

    Pulse ID: 6a56e4f5789e1bf3de8e82be
    Pulse Link: otx.alienvault.com/pulse/6a56e
    Pulse Author: AlienVault
    Created: 2026-07-15 01:40:05

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #CyberSecurity #ESET #Extortion #InfoSec #MFA #OTX #OpenThreatExchange #Password #Passwords #Phishing #RAT #RCE #Word #bot #AlienVault

  12. Threat Spotlight: The Jalisco Toolkit and AI-Powered Phishing Surge

    Phishing attacks have surged in 2026 as AI-powered phishing-as-a-service kits enable threat actors to bypass multi-factor authentication and harvest OAuth tokens at scale. Two phishing tools were identified in active campaigns: Jalisco, a device code phishing toolkit that provisions fresh OAuth codes in real time to defeat time-based security controls, and OmegaLord, a credential harvester that captures phone numbers alongside passwords to intercept MFA. Both tools demonstrate that attackers are engineering sophisticated methods to defeat authentication controls. These toolkits are part of a broader ecosystem that includes AI-powered PhaaS kits like EvilTokens and Kali365, which leverage legitimate cloud platforms to evade detection. Following compromise, attackers establish persistence by enrolling multiple devices to victim Entra ID tenants, enabling access that survives password resets and extends the window for data exfiltration and extortion.

    Pulse ID: 6a56e4f5789e1bf3de8e82be
    Pulse Link: otx.alienvault.com/pulse/6a56e
    Pulse Author: AlienVault
    Created: 2026-07-15 01:40:05

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #CyberSecurity #ESET #Extortion #InfoSec #MFA #OTX #OpenThreatExchange #Password #Passwords #Phishing #RAT #RCE #Word #bot #AlienVault

  13. How WP-SHELLSTORM Exposed 1.4M WordPress Sites

    A financially motivated cybercrime group operating as WP-SHELLSTORM was exposed when their Python SimpleHTTPServer remained open for 22 days, revealing toolkits, logs, and target lists. The operation targeted over 1.4 million domains using 27 weaponized CVEs and deployed more than 5,700 active webshells across WordPress and Joomla platforms. A parallel campaign targeted Apache Nacos, XXL-Job, and Spring Boot infrastructure, exfiltrating 613 configuration files from 11 victims across nine organizations in May 2026, compromising cloud credentials, database passwords, and payment system keys. The Chinese-linked actor utilized sophisticated obfuscated webshells, botnet infrastructure, and implants designed to evade detection by mimicking legitimate system processes.

    Pulse ID: 6a54b716f22fd928cabf4eb8
    Pulse Link: otx.alienvault.com/pulse/6a54b
    Pulse Author: AlienVault
    Created: 2026-07-13 09:59:50

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #APAC #Apache #Chinese #Cloud #CyberCrime #CyberSecurity #HTTP #HTTPS #InfoSec #Mimic #OTX #OpenThreatExchange #Password #Passwords #Python #RAT #RDP #Word #Wordpress #bot #botnet #AlienVault

  14. How WP-SHELLSTORM Exposed 1.4M WordPress Sites

    A financially motivated cybercrime group operating as WP-SHELLSTORM was exposed when their Python SimpleHTTPServer remained open for 22 days, revealing toolkits, logs, and target lists. The operation targeted over 1.4 million domains using 27 weaponized CVEs and deployed more than 5,700 active webshells across WordPress and Joomla platforms. A parallel campaign targeted Apache Nacos, XXL-Job, and Spring Boot infrastructure, exfiltrating 613 configuration files from 11 victims across nine organizations in May 2026, compromising cloud credentials, database passwords, and payment system keys. The Chinese-linked actor utilized sophisticated obfuscated webshells, botnet infrastructure, and implants designed to evade detection by mimicking legitimate system processes.

    Pulse ID: 6a54b716f22fd928cabf4eb8
    Pulse Link: otx.alienvault.com/pulse/6a54b
    Pulse Author: AlienVault
    Created: 2026-07-13 09:59:50

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #APAC #Apache #Chinese #Cloud #CyberCrime #CyberSecurity #HTTP #HTTPS #InfoSec #Mimic #OTX #OpenThreatExchange #Password #Passwords #Python #RAT #RDP #Word #Wordpress #bot #botnet #AlienVault

  15. How WP-SHELLSTORM Exposed 1.4M WordPress Sites

    A financially motivated cybercrime group operating as WP-SHELLSTORM was exposed when their Python SimpleHTTPServer remained open for 22 days, revealing toolkits, logs, and target lists. The operation targeted over 1.4 million domains using 27 weaponized CVEs and deployed more than 5,700 active webshells across WordPress and Joomla platforms. A parallel campaign targeted Apache Nacos, XXL-Job, and Spring Boot infrastructure, exfiltrating 613 configuration files from 11 victims across nine organizations in May 2026, compromising cloud credentials, database passwords, and payment system keys. The Chinese-linked actor utilized sophisticated obfuscated webshells, botnet infrastructure, and implants designed to evade detection by mimicking legitimate system processes.

    Pulse ID: 6a54b716f22fd928cabf4eb8
    Pulse Link: otx.alienvault.com/pulse/6a54b
    Pulse Author: AlienVault
    Created: 2026-07-13 09:59:50

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #APAC #Apache #Chinese #Cloud #CyberCrime #CyberSecurity #HTTP #HTTPS #InfoSec #Mimic #OTX #OpenThreatExchange #Password #Passwords #Python #RAT #RDP #Word #Wordpress #bot #botnet #AlienVault

  16. How WP-SHELLSTORM Exposed 1.4M WordPress Sites

    A financially motivated cybercrime group operating as WP-SHELLSTORM was exposed when their Python SimpleHTTPServer remained open for 22 days, revealing toolkits, logs, and target lists. The operation targeted over 1.4 million domains using 27 weaponized CVEs and deployed more than 5,700 active webshells across WordPress and Joomla platforms. A parallel campaign targeted Apache Nacos, XXL-Job, and Spring Boot infrastructure, exfiltrating 613 configuration files from 11 victims across nine organizations in May 2026, compromising cloud credentials, database passwords, and payment system keys. The Chinese-linked actor utilized sophisticated obfuscated webshells, botnet infrastructure, and implants designed to evade detection by mimicking legitimate system processes.

    Pulse ID: 6a54b716f22fd928cabf4eb8
    Pulse Link: otx.alienvault.com/pulse/6a54b
    Pulse Author: AlienVault
    Created: 2026-07-13 09:59:50

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #APAC #Apache #Chinese #Cloud #CyberCrime #CyberSecurity #HTTP #HTTPS #InfoSec #Mimic #OTX #OpenThreatExchange #Password #Passwords #Python #RAT #RDP #Word #Wordpress #bot #botnet #AlienVault

  17. How WP-SHELLSTORM Exposed 1.4M WordPress Sites

    A financially motivated cybercrime group operating as WP-SHELLSTORM was exposed when their Python SimpleHTTPServer remained open for 22 days, revealing toolkits, logs, and target lists. The operation targeted over 1.4 million domains using 27 weaponized CVEs and deployed more than 5,700 active webshells across WordPress and Joomla platforms. A parallel campaign targeted Apache Nacos, XXL-Job, and Spring Boot infrastructure, exfiltrating 613 configuration files from 11 victims across nine organizations in May 2026, compromising cloud credentials, database passwords, and payment system keys. The Chinese-linked actor utilized sophisticated obfuscated webshells, botnet infrastructure, and implants designed to evade detection by mimicking legitimate system processes.

    Pulse ID: 6a54b716f22fd928cabf4eb8
    Pulse Link: otx.alienvault.com/pulse/6a54b
    Pulse Author: AlienVault
    Created: 2026-07-13 09:59:50

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #APAC #Apache #Chinese #Cloud #CyberCrime #CyberSecurity #HTTP #HTTPS #InfoSec #Mimic #OTX #OpenThreatExchange #Password #Passwords #Python #RAT #RDP #Word #Wordpress #bot #botnet #AlienVault

  18. July 12th, 2026 - CryptoGen Cyber Threat Intelligence Advisory #10139 - RedHook Malware Exploiting Wireless Debugging for Advanced Device Control

    RedHook is an Android banking malware that abuses Wireless Debugging
    and Accessibility permissions to control infected phones. It can steal
    passwords, monitor screens, install apps and change device settings.

    Pulse ID: 6a53f92afa8b6fe7bbe13a50
    Pulse Link: otx.alienvault.com/pulse/6a53f
    Pulse Author: cryptocti
    Created: 2026-07-12 20:29:30

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Android #Bank #CryptoGen #CyberSecurity #InfoSec #Malware #OTX #OpenThreatExchange #Password #Passwords #Word #bot #cryptocti

  19. July 12th, 2026 - CryptoGen Cyber Threat Intelligence Advisory #10139 - RedHook Malware Exploiting Wireless Debugging for Advanced Device Control

    RedHook is an Android banking malware that abuses Wireless Debugging
    and Accessibility permissions to control infected phones. It can steal
    passwords, monitor screens, install apps and change device settings.

    Pulse ID: 6a53f92afa8b6fe7bbe13a50
    Pulse Link: otx.alienvault.com/pulse/6a53f
    Pulse Author: cryptocti
    Created: 2026-07-12 20:29:30

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Android #Bank #CryptoGen #CyberSecurity #InfoSec #Malware #OTX #OpenThreatExchange #Password #Passwords #Word #bot #cryptocti

  20. From Invoice to AnyDesk: Uncovering a Phishing Campaign Targeting Russian Aerospace Organizations

    A sophisticated spear-phishing campaign targeting Russian aerospace and aviation organizations has been identified, likely attributed to the Rare Werewolf threat group. The attack begins with fraudulent emails impersonating a legitimate Russian aerospace research institute, delivering password-protected archives containing malicious installers. The campaign employs living-off-the-land techniques, abusing legitimate tools including AnyDesk, Blat, WinRAR, and Tray Minimizer to establish persistent remote access. The attack chain deploys portable AnyDesk with unattended access configured using a predefined password, exfiltrates configuration data via SMTP to attacker-controlled infrastructure, and establishes persistence through scheduled tasks. The operators conceal their activities by minimizing the AnyDesk interface and removing forensic artifacts. This methodology aligns with previously documented Rare Werewolf campaigns targeting strategically important sectors across Russia, Belarus, and Kazakhstan, par...

    Pulse ID: 6a4f858d17f60f10d1e16c2c
    Pulse Link: otx.alienvault.com/pulse/6a4f8
    Pulse Author: AlienVault
    Created: 2026-07-09 11:27:09

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AnyDesk #Belarus #CyberSecurity #Email #InfoSec #Kazakhstan #Nim #OTX #OpenThreatExchange #Password #Phishing #RAT #Russia #SpearPhishing #Troll #WinRAR #Word #bot #AlienVault

  21. From Invoice to AnyDesk: Uncovering a Phishing Campaign Targeting Russian Aerospace Organizations

    A sophisticated spear-phishing campaign targeting Russian aerospace and aviation organizations has been identified, likely attributed to the Rare Werewolf threat group. The attack begins with fraudulent emails impersonating a legitimate Russian aerospace research institute, delivering password-protected archives containing malicious installers. The campaign employs living-off-the-land techniques, abusing legitimate tools including AnyDesk, Blat, WinRAR, and Tray Minimizer to establish persistent remote access. The attack chain deploys portable AnyDesk with unattended access configured using a predefined password, exfiltrates configuration data via SMTP to attacker-controlled infrastructure, and establishes persistence through scheduled tasks. The operators conceal their activities by minimizing the AnyDesk interface and removing forensic artifacts. This methodology aligns with previously documented Rare Werewolf campaigns targeting strategically important sectors across Russia, Belarus, and Kazakhstan, par...

    Pulse ID: 6a4f858d17f60f10d1e16c2c
    Pulse Link: otx.alienvault.com/pulse/6a4f8
    Pulse Author: AlienVault
    Created: 2026-07-09 11:27:09

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AnyDesk #Belarus #CyberSecurity #Email #InfoSec #Kazakhstan #Nim #OTX #OpenThreatExchange #Password #Phishing #RAT #Russia #SpearPhishing #Troll #WinRAR #Word #bot #AlienVault

  22. Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation

    A financially motivated campaign identified in April 2026 delivers Vidar stealer and XMRig cryptocurrency miner to victims worldwide through malvertising. Attackers distribute password-protected archives impersonating cracked software, using Go-compiled loaders built with the Factory-v3 framework. The malware employs sophisticated evasion techniques including rogue Authenticode certificates mimicking JustWatch and BleacherReport, file-size inflation to hundreds of MB with null bytes, and AMSI bypass. Once executed, Vidar stealer exfiltrates browser credentials, cookies and cryptocurrency wallets to C2 infrastructure, while XMRig mines Monero cryptocurrency. The operation establishes persistence through registry modifications, scheduled tasks and startup folder scripts. The threat actor, operating under the moniker X3D MINER, primarily targets victims in the U.S. and European Union through a dual-monetization scheme combining credential theft and cryptojacking.

    Pulse ID: 6a4d89812b006d2839a4dc49
    Pulse Link: otx.alienvault.com/pulse/6a4d8
    Pulse Author: AlienVault
    Created: 2026-07-07 23:19:29

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Cookies #CryptoJacking #CyberSecurity #Europe #EuropeanUnion #InfoSec #Malvertising #Malware #Mimic #OTX #OpenThreatExchange #Password #RAT #Vidar #Word #bot #cryptocurrency #AlienVault

  23. Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation

    A financially motivated campaign identified in April 2026 delivers Vidar stealer and XMRig cryptocurrency miner to victims worldwide through malvertising. Attackers distribute password-protected archives impersonating cracked software, using Go-compiled loaders built with the Factory-v3 framework. The malware employs sophisticated evasion techniques including rogue Authenticode certificates mimicking JustWatch and BleacherReport, file-size inflation to hundreds of MB with null bytes, and AMSI bypass. Once executed, Vidar stealer exfiltrates browser credentials, cookies and cryptocurrency wallets to C2 infrastructure, while XMRig mines Monero cryptocurrency. The operation establishes persistence through registry modifications, scheduled tasks and startup folder scripts. The threat actor, operating under the moniker X3D MINER, primarily targets victims in the U.S. and European Union through a dual-monetization scheme combining credential theft and cryptojacking.

    Pulse ID: 6a4d89812b006d2839a4dc49
    Pulse Link: otx.alienvault.com/pulse/6a4d8
    Pulse Author: AlienVault
    Created: 2026-07-07 23:19:29

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Cookies #CryptoJacking #CyberSecurity #Europe #EuropeanUnion #InfoSec #Malvertising #Malware #Mimic #OTX #OpenThreatExchange #Password #RAT #Vidar #Word #bot #cryptocurrency #AlienVault

  24. Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation

    A financially motivated campaign identified in April 2026 delivers Vidar stealer and XMRig cryptocurrency miner to victims worldwide through malvertising. Attackers distribute password-protected archives impersonating cracked software, using Go-compiled loaders built with the Factory-v3 framework. The malware employs sophisticated evasion techniques including rogue Authenticode certificates mimicking JustWatch and BleacherReport, file-size inflation to hundreds of MB with null bytes, and AMSI bypass. Once executed, Vidar stealer exfiltrates browser credentials, cookies and cryptocurrency wallets to C2 infrastructure, while XMRig mines Monero cryptocurrency. The operation establishes persistence through registry modifications, scheduled tasks and startup folder scripts. The threat actor, operating under the moniker X3D MINER, primarily targets victims in the U.S. and European Union through a dual-monetization scheme combining credential theft and cryptojacking.

    Pulse ID: 6a4d89812b006d2839a4dc49
    Pulse Link: otx.alienvault.com/pulse/6a4d8
    Pulse Author: AlienVault
    Created: 2026-07-07 23:19:29

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Cookies #CryptoJacking #CyberSecurity #Europe #EuropeanUnion #InfoSec #Malvertising #Malware #Mimic #OTX #OpenThreatExchange #Password #RAT #Vidar #Word #bot #cryptocurrency #AlienVault

  25. Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation

    A financially motivated campaign identified in April 2026 delivers Vidar stealer and XMRig cryptocurrency miner to victims worldwide through malvertising. Attackers distribute password-protected archives impersonating cracked software, using Go-compiled loaders built with the Factory-v3 framework. The malware employs sophisticated evasion techniques including rogue Authenticode certificates mimicking JustWatch and BleacherReport, file-size inflation to hundreds of MB with null bytes, and AMSI bypass. Once executed, Vidar stealer exfiltrates browser credentials, cookies and cryptocurrency wallets to C2 infrastructure, while XMRig mines Monero cryptocurrency. The operation establishes persistence through registry modifications, scheduled tasks and startup folder scripts. The threat actor, operating under the moniker X3D MINER, primarily targets victims in the U.S. and European Union through a dual-monetization scheme combining credential theft and cryptojacking.

    Pulse ID: 6a4d89812b006d2839a4dc49
    Pulse Link: otx.alienvault.com/pulse/6a4d8
    Pulse Author: AlienVault
    Created: 2026-07-07 23:19:29

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Cookies #CryptoJacking #CyberSecurity #Europe #EuropeanUnion #InfoSec #Malvertising #Malware #Mimic #OTX #OpenThreatExchange #Password #RAT #Vidar #Word #bot #cryptocurrency #AlienVault

  26. Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation

    A financially motivated campaign identified in April 2026 delivers Vidar stealer and XMRig cryptocurrency miner to victims worldwide through malvertising. Attackers distribute password-protected archives impersonating cracked software, using Go-compiled loaders built with the Factory-v3 framework. The malware employs sophisticated evasion techniques including rogue Authenticode certificates mimicking JustWatch and BleacherReport, file-size inflation to hundreds of MB with null bytes, and AMSI bypass. Once executed, Vidar stealer exfiltrates browser credentials, cookies and cryptocurrency wallets to C2 infrastructure, while XMRig mines Monero cryptocurrency. The operation establishes persistence through registry modifications, scheduled tasks and startup folder scripts. The threat actor, operating under the moniker X3D MINER, primarily targets victims in the U.S. and European Union through a dual-monetization scheme combining credential theft and cryptojacking.

    Pulse ID: 6a4d89812b006d2839a4dc49
    Pulse Link: otx.alienvault.com/pulse/6a4d8
    Pulse Author: AlienVault
    Created: 2026-07-07 23:19:29

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Cookies #CryptoJacking #CyberSecurity #Europe #EuropeanUnion #InfoSec #Malvertising #Malware #Mimic #OTX #OpenThreatExchange #Password #RAT #Vidar #Word #bot #cryptocurrency #AlienVault

  27. Headless Schlüsselringe
    Wo ist bei angemeldetem Benutzer ein #passwort für eineApplikationen am besten aufgehoben? Dieser Beitrag vergleicht drei mögliche Schlüsselringe, die ohne GUI und Interaktion auskommen.
    infosophia.eu/keyrings.html
    #it #informatik #itsecurity #password #passwords #keyring #keyrings #headless #headlesscli #cli #keepassxc #secrettool #pass #cryptography #privacy #privatsphare #kryptografie #kryptographie

  28. LumiPass - der Passwortmanager für Deine Amiga Workbench - mit Import/Export, Generator, Pwned-Online-Check und ARexx-Bridge.

    amigaworld.de/software/lumipas

    #commodore #amiga #amigaos #amigaworld #software #password #crypto #retro

  29. LumiPass - der Passwortmanager für Deine Amiga Workbench - mit Import/Export, Generator, Pwned-Online-Check und ARexx-Bridge.

    amigaworld.de/software/lumipas

    #commodore #amiga #amigaos #amigaworld #software #password #crypto #retro

  30. Vibe Coded Extortion: Path from Legal Lure to CrownX Ransom Capabilities

    A sophisticated multi-stage phishing campaign delivers a previously undocumented framework called Avalon through spoofed legal documents hosted on Proton Drive. The intrusion begins with password-protected archives containing ISO images that execute malicious MSBuild projects, loading payloads entirely in memory without conventional executable attachments. Avalon consolidates credential theft, lateral movement, recovery disruption, and ransomware capabilities within a single framework, with its encryption component branded as CrownX. The framework demonstrates hallmarks of AI-assisted development, rapidly combining multiple post-exploitation capabilities that previously required sustained development effort. Avalon targets browsers, cryptocurrency wallets, messaging platforms, VPN configurations, and infrastructure systems while implementing extensive defense evasion techniques against major security products. The framework disrupts recovery by eliminating Volume Shadow Copies, Windows Recovery Environment...

    Pulse ID: 6a46d120d41fcc87a8a52932
    Pulse Link: otx.alienvault.com/pulse/6a46d
    Pulse Author: AlienVault
    Created: 2026-07-02 20:59:12

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CyberSecurity #Encryption #Extortion #InfoSec #MSBuild #OTX #OpenThreatExchange #Password #Phishing #RAT #RansomWare #VPN #Windows #Word #bot #cryptocurrency #AlienVault

  31. Vibe Coded Extortion: Path from Legal Lure to CrownX Ransom Capabilities

    A sophisticated multi-stage phishing campaign delivers a previously undocumented framework called Avalon through spoofed legal documents hosted on Proton Drive. The intrusion begins with password-protected archives containing ISO images that execute malicious MSBuild projects, loading payloads entirely in memory without conventional executable attachments. Avalon consolidates credential theft, lateral movement, recovery disruption, and ransomware capabilities within a single framework, with its encryption component branded as CrownX. The framework demonstrates hallmarks of AI-assisted development, rapidly combining multiple post-exploitation capabilities that previously required sustained development effort. Avalon targets browsers, cryptocurrency wallets, messaging platforms, VPN configurations, and infrastructure systems while implementing extensive defense evasion techniques against major security products. The framework disrupts recovery by eliminating Volume Shadow Copies, Windows Recovery Environment...

    Pulse ID: 6a46d120d41fcc87a8a52932
    Pulse Link: otx.alienvault.com/pulse/6a46d
    Pulse Author: AlienVault
    Created: 2026-07-02 20:59:12

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CyberSecurity #Encryption #Extortion #InfoSec #MSBuild #OTX #OpenThreatExchange #Password #Phishing #RAT #RansomWare #VPN #Windows #Word #bot #cryptocurrency #AlienVault

  32. 🐀🛡️ Cybersicurezza in pillole — Password deboli, porta aperta

    Una password semplice è un invito per gli attaccanti.

    • Usa password lunghe e uniche
    • Non riutilizzarle su più servizi
    • Attiva l'autenticazione a due fattori (2FA)
    • Affidati a un gestore di password

    🔒 Una password robusta protegge i tuoi dati. Una debole può compromettere tutta la tua vita digitale.

    @sicurezza

    #Cybersecurity #Password #2FA #Privacy #NextRed

  33. 🐀🛡️ Cybersicurezza in pillole — Password deboli, porta aperta

    Una password semplice è un invito per gli attaccanti.

    • Usa password lunghe e uniche
    • Non riutilizzarle su più servizi
    • Attiva l'autenticazione a due fattori (2FA)
    • Affidati a un gestore di password

    🔒 Una password robusta protegge i tuoi dati. Una debole può compromettere tutta la tua vita digitale.

    @sicurezza

    #Cybersecurity #Password #2FA #Privacy #NextRed

  34. RustDuck: An In-Depth Analysis of a Two-Stage Botnet

    Since February 2026, a new malware family utilizing a Loader plus Core two-stage architecture has been detected, primarily conducting large-scale DDoS attacks with strong cross-platform capabilities. The family is transitioning from C to Rust programming language, demonstrating rapid evolution in anti-defense and traffic encryption techniques. Propagation methods include weak password brute-forcing via Telnet and SSH, exploitation of IoT device vulnerabilities affecting Android ADB, TVT API, Ruijie, TP-Link, and ZTE devices, plus web component vulnerabilities in ThinkPHP, Jenkins, and YARN. The botnet employs sophisticated anti-debugging mechanisms including environment checks, honeypot detection, and timing verification. Communication protocols leverage Curve25519 key exchange, ChaCha20-Poly1305 and AES-GCM encryption, implementing strict handshake verification processes. Over 20 IPs have been observed spreading the botnet, with multiple variants showing increasingly complex encryption and obfuscation techn

    Pulse ID: 6a4635e7998db450b0ccdee2
    Pulse Link: otx.alienvault.com/pulse/6a463
    Pulse Author: AlienVault
    Created: 2026-07-02 09:56:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Android #ChaCha20 #CyberSecurity #DDoS #DoS #Encryption #HoneyPot #InfoSec #IoT #Malware #OTX #OpenThreatExchange #PHP #Password #RAT #Rust #SMS #SSH #Telnet #Word #bot #botnet #AlienVault

  35. RustDuck: An In-Depth Analysis of a Two-Stage Botnet

    Since February 2026, a new malware family utilizing a Loader plus Core two-stage architecture has been detected, primarily conducting large-scale DDoS attacks with strong cross-platform capabilities. The family is transitioning from C to Rust programming language, demonstrating rapid evolution in anti-defense and traffic encryption techniques. Propagation methods include weak password brute-forcing via Telnet and SSH, exploitation of IoT device vulnerabilities affecting Android ADB, TVT API, Ruijie, TP-Link, and ZTE devices, plus web component vulnerabilities in ThinkPHP, Jenkins, and YARN. The botnet employs sophisticated anti-debugging mechanisms including environment checks, honeypot detection, and timing verification. Communication protocols leverage Curve25519 key exchange, ChaCha20-Poly1305 and AES-GCM encryption, implementing strict handshake verification processes. Over 20 IPs have been observed spreading the botnet, with multiple variants showing increasingly complex encryption and obfuscation techn

    Pulse ID: 6a4635e7998db450b0ccdee2
    Pulse Link: otx.alienvault.com/pulse/6a463
    Pulse Author: AlienVault
    Created: 2026-07-02 09:56:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Android #ChaCha20 #CyberSecurity #DDoS #DoS #Encryption #HoneyPot #InfoSec #IoT #Malware #OTX #OpenThreatExchange #PHP #Password #RAT #Rust #SMS #SSH #Telnet #Word #bot #botnet #AlienVault

  36. RustDuck: An In-Depth Analysis of a Two-Stage Botnet

    Since February 2026, a new malware family utilizing a Loader plus Core two-stage architecture has been detected, primarily conducting large-scale DDoS attacks with strong cross-platform capabilities. The family is transitioning from C to Rust programming language, demonstrating rapid evolution in anti-defense and traffic encryption techniques. Propagation methods include weak password brute-forcing via Telnet and SSH, exploitation of IoT device vulnerabilities affecting Android ADB, TVT API, Ruijie, TP-Link, and ZTE devices, plus web component vulnerabilities in ThinkPHP, Jenkins, and YARN. The botnet employs sophisticated anti-debugging mechanisms including environment checks, honeypot detection, and timing verification. Communication protocols leverage Curve25519 key exchange, ChaCha20-Poly1305 and AES-GCM encryption, implementing strict handshake verification processes. Over 20 IPs have been observed spreading the botnet, with multiple variants showing increasingly complex encryption and obfuscation techn

    Pulse ID: 6a4635e7998db450b0ccdee2
    Pulse Link: otx.alienvault.com/pulse/6a463
    Pulse Author: AlienVault
    Created: 2026-07-02 09:56:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Android #ChaCha20 #CyberSecurity #DDoS #DoS #Encryption #HoneyPot #InfoSec #IoT #Malware #OTX #OpenThreatExchange #PHP #Password #RAT #Rust #SMS #SSH #Telnet #Word #bot #botnet #AlienVault

  37. RustDuck: An In-Depth Analysis of a Two-Stage Botnet

    Since February 2026, a new malware family utilizing a Loader plus Core two-stage architecture has been detected, primarily conducting large-scale DDoS attacks with strong cross-platform capabilities. The family is transitioning from C to Rust programming language, demonstrating rapid evolution in anti-defense and traffic encryption techniques. Propagation methods include weak password brute-forcing via Telnet and SSH, exploitation of IoT device vulnerabilities affecting Android ADB, TVT API, Ruijie, TP-Link, and ZTE devices, plus web component vulnerabilities in ThinkPHP, Jenkins, and YARN. The botnet employs sophisticated anti-debugging mechanisms including environment checks, honeypot detection, and timing verification. Communication protocols leverage Curve25519 key exchange, ChaCha20-Poly1305 and AES-GCM encryption, implementing strict handshake verification processes. Over 20 IPs have been observed spreading the botnet, with multiple variants showing increasingly complex encryption and obfuscation techn

    Pulse ID: 6a4635e7998db450b0ccdee2
    Pulse Link: otx.alienvault.com/pulse/6a463
    Pulse Author: AlienVault
    Created: 2026-07-02 09:56:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Android #ChaCha20 #CyberSecurity #DDoS #DoS #Encryption #HoneyPot #InfoSec #IoT #Malware #OTX #OpenThreatExchange #PHP #Password #RAT #Rust #SMS #SSH #Telnet #Word #bot #botnet #AlienVault

  38. RustDuck: An In-Depth Analysis of a Two-Stage Botnet

    Since February 2026, a new malware family utilizing a Loader plus Core two-stage architecture has been detected, primarily conducting large-scale DDoS attacks with strong cross-platform capabilities. The family is transitioning from C to Rust programming language, demonstrating rapid evolution in anti-defense and traffic encryption techniques. Propagation methods include weak password brute-forcing via Telnet and SSH, exploitation of IoT device vulnerabilities affecting Android ADB, TVT API, Ruijie, TP-Link, and ZTE devices, plus web component vulnerabilities in ThinkPHP, Jenkins, and YARN. The botnet employs sophisticated anti-debugging mechanisms including environment checks, honeypot detection, and timing verification. Communication protocols leverage Curve25519 key exchange, ChaCha20-Poly1305 and AES-GCM encryption, implementing strict handshake verification processes. Over 20 IPs have been observed spreading the botnet, with multiple variants showing increasingly complex encryption and obfuscation techn

    Pulse ID: 6a4635e7998db450b0ccdee2
    Pulse Link: otx.alienvault.com/pulse/6a463
    Pulse Author: AlienVault
    Created: 2026-07-02 09:56:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Android #ChaCha20 #CyberSecurity #DDoS #DoS #Encryption #HoneyPot #InfoSec #IoT #Malware #OTX #OpenThreatExchange #PHP #Password #RAT #Rust #SMS #SSH #Telnet #Word #bot #botnet #AlienVault

  39. OTP Clients servers closed source & vendor lock-in

    TIL about freeOTP an Open Source OTP client for the two major mobile OS.

    I already have a couple of nice OTP clients on my phones and love to have alternatives, in case one is not compiled anymore for newer Android OS

    History

    Many years ago I stubled upon authy a closed variable OTP client for Android. It ran on Linux win64 Android

    This pesky client did something you'd expect from an ex-girl / boy-friend!

    Authy has a model where it allows you to seamlessly sync your OTP parameters with their double blind server network Double blind just like private bin, a magnificient piece of encryption software you should also know / learn about.
    The authy sync network never sees your data since there are multiple encryption layers.

    Without checking the fine print (just like your ex- there is none) I used authy, migrating my multitude of OTP records because I loved the convenience of auto server sync. THe migration took a redacted time (many OTP records reside here) and I added a redacted ammount of records afterwards...

    Horrors krept up when I wanted to see my OTP records from within authy, not the output the codes themselves
    I could not find that option, which my other OTP client has.
    I send a tweet to authy verified account which I had frequent daily & fun conversations with, promoting the program on twitter (many many years ago).
    I asked which external switch I could use in the linux client to export my OTP codes

    Authy twitter: dead silence...

    On my tweets I normally got responses within 5 - 30 minutes

    I never got a response from them again

    Baffled at this sudden chance in character (just like your ex- who ignores you in your own house all of a sudden) I did extensive research in the subject matter

    Research had showed that authy has malicious code & policy which punishes people who use external methods to extract their OTP codes from the program!

    What do they do you ask?

    Simple:

    • you are locked in using the program
    • you get locked out trying to break the lock-in

    Details

    The OTP records are in encrypted vault(s) on your device, which could be your linux machine Android or mac / iphone
    In order to get a OTP record decrypted contact was needed with the authy sync server network

    You get cut off when they detect your attempt of jailbreaking your own OTP records

    Your client is not allowed to contact the servers for a set ammount of time, locking you out of accessing all your accounts which you got trapped in the authy jail, just like your failed relationship with your ex-

    When contact is allowed again, you will usually stop messing with your main account, leaving you only to create new OTP records for your accounts, defeating the convenience of server sided sync.

    Authy you bad bad ex-!

    I had forgotten the main rule

    There is no cloud, just someone else computer!

    After that debacle I fetched Open and ad free Android clients, of which none have Linux programs. These clients give full export posibilities and backup

    Update:

    I am looking now for Linux clients and executed

    • apt install otp
    • apt install otpclient

    Otpclient gave me a warning that my OS memlocklimit is too low, which means I need to tune that first to sane levels. otherwise insecure memory use may be the result for otpclient.
    I shall execute what is written in the last source link
    I have now linux native OTP programs in which I can import my OTP data on my Android devices

    This is where freeOTP shall also participate

    Sources:

    mnn otp(1)

    man otpclient(1)

    en.wikipedia.org/wiki/One-time

    en.wikipedia.org/wiki/Multi-fa

    en.wikipedia.org/wiki/OTPW

    en.wikipedia.org/wiki/FreeOTP

    freeotp.github.io/

    freeipa.org/

    github.com/paolostivanin/OTPCl

    #2FA #MFA #OTP #programming #Linux #Android #authy #bad #One #Time #Password #export

  40. OTP Clients servers closed source & vendor lock-in

    TIL about freeOTP an Open Source OTP client for the two major mobile OS.

    I already have a couple of nice OTP clients on my phones and love to have alternatives, in case one is not compiled anymore for newer Android OS

    History

    Many years ago I stubled upon authy a closed variable OTP client for Android. It ran on Linux win64 Android

    This pesky client did something you'd expect from an ex-girl / boy-friend!

    Authy has a model where it allows you to seamlessly sync your OTP parameters with their double blind server network Double blind just like private bin, a magnificient piece of encryption software you should also know / learn about.
    The authy sync network never sees your data since there are multiple encryption layers.

    Without checking the fine print (just like your ex- there is none) I used authy, migrating my multitude of OTP records because I loved the convenience of auto server sync. THe migration took a redacted time (many OTP records reside here) and I added a redacted ammount of records afterwards...

    Horrors krept up when I wanted to see my OTP records from within authy, not the output the codes themselves
    I could not find that option, which my other OTP client has.
    I send a tweet to authy verified account which I had frequent daily & fun conversations with, promoting the program on twitter (many many years ago).
    I asked which external switch I could use in the linux client to export my OTP codes

    Authy twitter: dead silence...

    On my tweets I normally got responses within 5 - 30 minutes

    I never got a response from them again

    Baffled at this sudden chance in character (just like your ex- who ignores you in your own house all of a sudden) I did extensive research in the subject matter

    Research had showed that authy has malicious code & policy which punishes people who use external methods to extract their OTP codes from the program!

    What do they do you ask?

    Simple:

    • you are locked in using the program
    • you get locked out trying to break the lock-in

    Details

    The OTP records are in encrypted vault(s) on your device, which could be your linux machine Android or mac / iphone
    In order to get a OTP record decrypted contact was needed with the authy sync server network

    You get cut off when they detect your attempt of jailbreaking your own OTP records

    Your client is not allowed to contact the servers for a set ammount of time, locking you out of accessing all your accounts which you got trapped in the authy jail, just like your failed relationship with your ex-

    When contact is allowed again, you will usually stop messing with your main account, leaving you only to create new OTP records for your accounts, defeating the convenience of server sided sync.

    Authy you bad bad ex-!

    I had forgotten the main rule

    There is no cloud, just someone else computer!

    After that debacle I fetched Open and ad free Android clients, of which none have Linux programs. These clients give full export posibilities and backup

    Update:

    I am looking now for Linux clients and executed

    • apt install otp
    • apt install otpclient

    Otpclient gave me a warning that my OS memlocklimit is too low, which means I need to tune that first to sane levels. otherwise insecure memory use may be the result for otpclient.
    I shall execute what is written in the last source link
    I have now linux native OTP programs in which I can import my OTP data on my Android devices

    This is where freeOTP shall also participate

    Sources:

    mnn otp(1)

    man otpclient(1)

    en.wikipedia.org/wiki/One-time

    en.wikipedia.org/wiki/Multi-fa

    en.wikipedia.org/wiki/OTPW

    en.wikipedia.org/wiki/FreeOTP

    freeotp.github.io/

    freeipa.org/

    github.com/paolostivanin/OTPCl

    #2FA #MFA #OTP #programming #Linux #Android #authy #bad #One #Time #Password #export

  41. OTP Clients servers closed source & vendor lock-in

    TIL about freeOTP an Open Source OTP client for the two major mobile OS.

    I already have a couple of nice OTP clients on my phones and love to have alternatives, in case one is not compiled anymore for newer Android OS

    History

    Many years ago I stubled upon authy a closed variable OTP client for Android. It ran on Linux win64 Android

    This pesky client did something you'd expect from an ex-girl / boy-friend!

    Authy has a model where it allows you to seamlessly sync your OTP parameters with their double blind server network Double blind just like private bin, a magnificient piece of encryption software you should also know / learn about.
    The authy sync network never sees your data since there are multiple encryption layers.

    Without checking the fine print (just like your ex- there is none) I used authy, migrating my multitude of OTP records because I loved the convenience of auto server sync. THe migration took a redacted time (many OTP records reside here) and I added a redacted ammount of records afterwards...

    Horrors krept up when I wanted to see my OTP records from within authy, not the output the codes themselves
    I could not find that option, which my other OTP client has.
    I send a tweet to authy verified account which I had frequent daily & fun conversations with, promoting the program on twitter (many many years ago).
    I asked which external switch I could use in the linux client to export my OTP codes

    Authy twitter: dead silence...

    On my tweets I normally got responses within 5 - 30 minutes

    I never got a response from them again

    Baffled at this sudden chance in character (just like your ex- who ignores you in your own house all of a sudden) I did extensive research in the subject matter

    Research had showed that authy has malicious code & policy which punishes people who use external methods to extract their OTP codes from the program!

    What do they do you ask?

    Simple:

    • you are locked in using the program
    • you get locked out trying to break the lock-in

    Details

    The OTP records are in encrypted vault(s) on your device, which could be your linux machine Android or mac / iphone
    In order to get a OTP record decrypted contact was needed with the authy sync server network

    You get cut off when they detect your attempt of jailbreaking your own OTP records

    Your client is not allowed to contact the servers for a set ammount of time, locking you out of accessing all your accounts which you got trapped in the authy jail, just like your failed relationship with your ex-

    When contact is allowed again, you will usually stop messing with your main account, leaving you only to create new OTP records for your accounts, defeating the convenience of server sided sync.

    Authy you bad bad ex-!

    I had forgotten the main rule

    There is no cloud, just someone else computer!

    After that debacle I fetched Open and ad free Android clients, of which none have Linux programs. These clients give full export posibilities and backup

    Update:

    I am looking now for Linux clients and executed

    • apt install otp
    • apt install otpclient

    Otpclient gave me a warning that my OS memlocklimit is too low, which means I need to tune that first to sane levels. otherwise insecure memory use may be the result for otpclient.
    I shall execute what is written in the last source link
    I have now linux native OTP programs in which I can import my OTP data on my Android devices

    This is where freeOTP shall also participate

    Sources:

    mnn otp(1)

    man otpclient(1)

    en.wikipedia.org/wiki/One-time

    en.wikipedia.org/wiki/Multi-fa

    en.wikipedia.org/wiki/OTPW

    en.wikipedia.org/wiki/FreeOTP

    freeotp.github.io/

    freeipa.org/

    github.com/paolostivanin/OTPCl

    #2FA #MFA #OTP #programming #Linux #Android #authy #bad #One #Time #Password #export

  42. OTP Clients servers closed source & vendor lock-in

    TIL about freeOTP an Open Source OTP client for the two major mobile OS.

    I already have a couple of nice OTP clients on my phones and love to have alternatives, in case one is not compiled anymore for newer Android OS

    History

    Many years ago I stubled upon authy a closed variable OTP client for Android. It ran on Linux win64 Android

    This pesky client did something you'd expect from an ex-girl / boy-friend!

    Authy has a model where it allows you to seamlessly sync your OTP parameters with their double blind server network Double blind just like private bin, a magnificient piece of encryption software you should also know / learn about.
    The authy sync network never sees your data since there are multiple encryption layers.

    Without checking the fine print (just like your ex- there is none) I used authy, migrating my multitude of OTP records because I loved the convenience of auto server sync. THe migration took a redacted time (many OTP records reside here) and I added a redacted ammount of records afterwards...

    Horrors krept up when I wanted to see my OTP records from within authy, not the output the codes themselves
    I could not find that option, which my other OTP client has.
    I send a tweet to authy verified account which I had frequent daily & fun conversations with, promoting the program on twitter (many many years ago).
    I asked which external switch I could use in the linux client to export my OTP codes

    Authy twitter: dead silence...

    On my tweets I normally got responses within 5 - 30 minutes

    I never got a response from them again

    Baffled at this sudden chance in character (just like your ex- who ignores you in your own house all of a sudden) I did extensive research in the subject matter

    Research had showed that authy has malicious code & policy which punishes people who use external methods to extract their OTP codes from the program!

    What do they do you ask?

    Simple:

    • you are locked in using the program
    • you get locked out trying to break the lock-in

    Details

    The OTP records are in encrypted vault(s) on your device, which could be your linux machine Android or mac / iphone
    In order to get a OTP record decrypted contact was needed with the authy sync server network

    You get cut off when they detect your attempt of jailbreaking your own OTP records

    Your client is not allowed to contact the servers for a set ammount of time, locking you out of accessing all your accounts which you got trapped in the authy jail, just like your failed relationship with your ex-

    When contact is allowed again, you will usually stop messing with your main account, leaving you only to create new OTP records for your accounts, defeating the convenience of server sided sync.

    Authy you bad bad ex-!

    I had forgotten the main rule

    There is no cloud, just someone else computer!

    After that debacle I fetched Open and ad free Android clients, of which none have Linux programs. These clients give full export posibilities and backup

    Update:

    I am looking now for Linux clients and executed

    • apt install otp
    • apt install otpclient

    Otpclient gave me a warning that my OS memlocklimit is too low, which means I need to tune that first to sane levels. otherwise insecure memory use may be the result for otpclient.
    I shall execute what is written in the last source link
    I have now linux native OTP programs in which I can import my OTP data on my Android devices

    This is where freeOTP shall also participate

    Sources:

    mnn otp(1)

    man otpclient(1)

    en.wikipedia.org/wiki/One-time

    en.wikipedia.org/wiki/Multi-fa

    en.wikipedia.org/wiki/OTPW

    en.wikipedia.org/wiki/FreeOTP

    freeotp.github.io/

    freeipa.org/

    github.com/paolostivanin/OTPCl

    #2FA #MFA #OTP #programming #Linux #Android #authy #bad #One #Time #Password #export

  43. OTP Clients servers closed source & vendor lock-in

    TIL about freeOTP an Open Source OTP client for the two major mobile OS.

    I already have a couple of nice OTP clients on my phones and love to have alternatives, in case one is not compiled anymore for newer Android OS

    History

    Many years ago I stubled upon authy a closed variable OTP client for Android. It ran on Linux win64 Android

    This pesky client did something you'd expect from an ex-girl / boy-friend!

    Authy has a model where it allows you to seamlessly sync your OTP parameters with their double blind server network Double blind just like private bin, a magnificient piece of encryption software you should also know / learn about.
    The authy sync network never sees your data since there are multiple encryption layers.

    Without checking the fine print (just like your ex- there is none) I used authy, migrating my multitude of OTP records because I loved the convenience of auto server sync. THe migration took a redacted time (many OTP records reside here) and I added a redacted ammount of records afterwards...

    Horrors krept up when I wanted to see my OTP records from within authy, not the output the codes themselves
    I could not find that option, which my other OTP client has.
    I send a tweet to authy verified account which I had frequent daily & fun conversations with, promoting the program on twitter (many many years ago).
    I asked which external switch I could use in the linux client to export my OTP codes

    Authy twitter: dead silence...

    On my tweets I normally got responses within 5 - 30 minutes

    I never got a response from them again

    Baffled at this sudden chance in character (just like your ex- who ignores you in your own house all of a sudden) I did extensive research in the subject matter

    Research had showed that authy has malicious code & policy which punishes people who use external methods to extract their OTP codes from the program!

    What do they do you ask?

    Simple:

    • you are locked in using the program
    • you get locked out trying to break the lock-in

    Details

    The OTP records are in encrypted vault(s) on your device, which could be your linux machine Android or mac / iphone
    In order to get a OTP record decrypted contact was needed with the authy sync server network

    You get cut off when they detect your attempt of jailbreaking your own OTP records

    Your client is not allowed to contact the servers for a set ammount of time, locking you out of accessing all your accounts which you got trapped in the authy jail, just like your failed relationship with your ex-

    When contact is allowed again, you will usually stop messing with your main account, leaving you only to create new OTP records for your accounts, defeating the convenience of server sided sync.

    Authy you bad bad ex-!

    I had forgotten the main rule

    There is no cloud, just someone else computer!

    After that debacle I fetched Open and ad free Android clients, of which none have Linux programs. These clients give full export posibilities and backup

    Update:

    I am looking now for Linux clients and executed

    • apt install otp
    • apt install otpclient

    Otpclient gave me a warning that my OS memlocklimit is too low, which means I need to tune that first to sane levels. otherwise insecure memory use may be the result for otpclient.
    I shall execute what is written in the last source link
    I have now linux native OTP programs in which I can import my OTP data on my Android devices

    This is where freeOTP shall also participate

    Sources:

    mnn otp(1)

    man otpclient(1)

    en.wikipedia.org/wiki/One-time

    en.wikipedia.org/wiki/Multi-fa

    en.wikipedia.org/wiki/OTPW

    en.wikipedia.org/wiki/FreeOTP

    freeotp.github.io/

    freeipa.org/

    github.com/paolostivanin/OTPCl

    #2FA #MFA #OTP #programming #Linux #Android #authy #bad #One #Time #Password #export

  44. Chrome and Firefox Extensions Posing as Free VPNs Add Clipboard Stealers via Malicious Updates

    Malicious browser extensions distributed through Chrome Web Store and Firefox Add-ons marketplaces posed as free VPN services while secretly stealing clipboard data. The Chrome extension, with 146 users, and Firefox extension, with 3,499 users, initially functioned as proxy tools but later incorporated clipboard theft through staged updates. Chrome versions 1.1 onwards and Firefox version 1.3.3 onwards continuously monitored clipboard contents every 500-1500 milliseconds, capturing passwords, API keys, cryptocurrency addresses, and authentication tokens. Stolen data was chunked, tagged with session identifiers, and exfiltrated via HTTP to attacker-controlled infrastructure at multiple IP addresses. Both extensions shared code patterns, infrastructure, and exfiltration endpoints despite appearing as separate products, indicating coordinated malicious operations behind legitimate-appearing privacy tools.

    Pulse ID: 6a43b188e88186c48de04785
    Pulse Link: otx.alienvault.com/pulse/6a43b
    Pulse Author: AlienVault
    Created: 2026-06-30 12:07:36

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Chrome #ChromeExtension #Clipboard #CyberSecurity #Endpoint #FireFox #HTTP #InfoSec #OTX #OpenThreatExchange #Password #Passwords #Privacy #Proxy #RAT #Troll #VPN #Word #bot #cryptocurrency #AlienVault

  45. Chrome and Firefox Extensions Posing as Free VPNs Add Clipboard Stealers via Malicious Updates

    Malicious browser extensions distributed through Chrome Web Store and Firefox Add-ons marketplaces posed as free VPN services while secretly stealing clipboard data. The Chrome extension, with 146 users, and Firefox extension, with 3,499 users, initially functioned as proxy tools but later incorporated clipboard theft through staged updates. Chrome versions 1.1 onwards and Firefox version 1.3.3 onwards continuously monitored clipboard contents every 500-1500 milliseconds, capturing passwords, API keys, cryptocurrency addresses, and authentication tokens. Stolen data was chunked, tagged with session identifiers, and exfiltrated via HTTP to attacker-controlled infrastructure at multiple IP addresses. Both extensions shared code patterns, infrastructure, and exfiltration endpoints despite appearing as separate products, indicating coordinated malicious operations behind legitimate-appearing privacy tools.

    Pulse ID: 6a43b188e88186c48de04785
    Pulse Link: otx.alienvault.com/pulse/6a43b
    Pulse Author: AlienVault
    Created: 2026-06-30 12:07:36

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Chrome #ChromeExtension #Clipboard #CyberSecurity #Endpoint #FireFox #HTTP #InfoSec #OTX #OpenThreatExchange #Password #Passwords #Privacy #Proxy #RAT #Troll #VPN #Word #bot #cryptocurrency #AlienVault