home.social

#rtdna β€” Public Fediverse posts

Live and recent posts from across the Fediverse tagged #rtdna, aggregated by home.social.

  1. CW: #infosec SecuredDNSπŸ€πŸ‘‰β˜£οΈ #YIL

    #YIL

    opendns.com:853 πŸ‘‰β˜£οΈ &
    doh.sse.cisco.com:853 πŸ‘‰β˜£οΈ

    Is a part of the #GreyMarketCALEA
    attaccc server proxy server network for #GammaGroup's #FinFisher #FinSpy #Finsky via logged attacccs' on specific honeypot clients online πŸ”πŸ§

    #RTDNA #news #infosec

  2. CW: #infosec #GreyMarketCALEA #attaccc proxy servers on InfoSec.Exchange

    Hmm, two infrastructure IPs behind InfoSecExchange used for attaccc's today from fast.ly & bunny.net. β˜£οΈπŸ”

    🧐

    Fast.ly β˜£οΈβš οΈπŸ‘‰ 151.101.43.52

    Bunny.Net β˜£οΈβš οΈπŸ‘‰ 143-244-50-84.bunnyinfra.net

    #GreyMarketCALEA #infosec
    #investigations #StateSponsoredMalware #GammaGroup #FinFisher #FinSpy #RTDNA #news

    @jerry

  3. @samirx @TechCrunch

    It's for mass surveillance, use of felons coordinating of Meta to target someone for assaults/murder/theft type targeting, physical property theft ( like WaterGate), breaking & entering coordination, targeting by gps the targeting of vehicle car wrecks, etc, as a used by felons type of non-law enforcement kind of thing in the #CALEA #CALEAGreyMarket, when used against ' the press ' or anyone else they target.

    #GammaGroup #FinFisher #FinSpy #Finsky

    #Meta #GangStalkers & use this software.

    It's installed via #GooglePlayStore & #AppleAppStore with #MITM targeting as well as with a phone call or text message from an infected device.
    #StateSponsoredMalware

    Currently there are some REALLY misconfigured #GammaGroup clients which when called will infect EVERYTHING from you phone to your computer to tablet. It's basically digital rape & slavery. Basically.

    Luckily on #Android OS it's super easy to detect without software because it is so overt, not covert.

    #RTDNA #infosec #StateSponsoredMalwareβ„’

    #NSOGroup & #GammaGroup are the most commonly used varieties in USA.

  4. @davidaugust

    Sure. Depends on the OS.

    I focus on Android OS 10, 11 & 12 currently #VirusTota'ing the client #FinFisher, #FinSpy & #finsky & their attaccc proxy servers also.

    Android 13, 14, 15 for GammaGroup.Com client is on my roadmap this year & into next year though.

    I've been super busy on other projects since this one is very charity work oriented in #infosec of #CALEA & #GreyMarket #CALEA software.

    Occasionally I also post about #NSOGroup since they are a competitor to GammaGroup in the UK.

    #StateSponsoredMalware
    #WhitelistedMalware
    #LawfulIntercept
    #UnlawfulIntercept
    #investigations

    #RTDNA #malware #journalism

  5. This one node is quite the repeat offender in attacccing as a many year logged attaccc server of exploits.

    #VirusTotal

    Fastly DNS GammaGroup FinFisher FinSpy
    Attaccc Node Proxy IP : 151.101.3.52

    #Fastly #DNS
    #GamaGroup #FinFisher #FinSpy #AttacccProxyServers

    virustotal.com/graph/embed/gb9

    Rescanned today after 2 months of not being scanned.

    #infosec #CALEAMalware #GreyMarketInvestigations #RTDNA #news

  6. CW: #GammaGroup #FinFisher #FinSpy #SystemApp callback list of hosts / shims on #BunnyNet via #DataPacket

    Historical list of #SystemApp callback to #FinFisher clients logged while on #InfoseceXchange that's good for #tcpdump correlation #investigations in #Germany on the CDN #DataPacket hosting the #BunnyNet since November 2022ish for #GermanProsecutors to correlate.

    #FinFisherCom🀝#EnemyOfTheInternet

    #CALEA #greymarket #CALEAmalware πŸ”πŸ§#infosec

    ΒΉ
    143-244-49-183.bunnyinfra.net

    Β²
    143-244-50-83.bunnyinfra.net

    Β³
    169.150.221.147

    ⁴
    143-244-50-88.bunnyinfra.net

    ⁡
    143-244-50-211.bunnyinfra.net

    ⁢
    169-150-249-163.bunnyinfra.net

    ⁷
    169-150-221-147.bunnyinfra.net

    ⁸
    143-244-50-82.bunnyinfra.net

    ⁹
    143-244-50-213.bunnyinfra.net

    ¹⁰
    143-244-50-209.bunnyinfra.net

    ΒΉΒΉ
    143-244-49-180.bunnyinfra.net

    ΒΉΒ²
    143.244.50.214

    ΒΉΒ³
    185-93-1-251.bunnyinfra.net

    ¹⁴
    unn-169-150-249-163.datapacket.com

    ¹⁡
    unn-169-150-249-165.datapacket.com

    ¹⁢
    unn-169-150-249-164.datapacket.com

    ¹⁷
    unn-169-150-249-166.datapacket.com

    Cities:
    ΒΉ
    reddit.com/r/netzpolitik/comme

    Β²
    en.wikipedia.org/wiki/FinFishe

    Β³
    spiegel.de/netzwelt/netzpoliti

    ⁴
    netzpolitik.org/2022/nach-pfae

    ⁡
    securityweek.com/german-author

    ⁢
    bloomberg.com/news/articles/20

    #RTDNA #StateSponsoredMalwareβ„’ #SSMβ„’ #malware

  7. CW: #VerifiedNews #VerifiedReporters #W3C #WebBrowser #RFE #RTDNA #OpenSource

    I wonder when the #NewsBusiness is going to get their #reporters to cryptographicly sign their #NewsStories with a built in #SHA512 module in all major #webbrowsers #W3C #IEEE #RFE #disinformation campaign fights #opensourcesoftware & extend this to #RSS readers also? πŸ’―πŸ€”

    ΒΉ Perhaps this #SHA512 generates a hash of 'the web page and the images / videos used' so that the whole thing can be 'verified by the #NewsOrganization & #TheReporter' as a cross signed #VerifiedNewsStory so one could, as a reader, know iF this has been modified via #MITM or not, showing the story as a #TrustedNewsStory?

    Β² Perhaps simple, well established iconography, such as the lock πŸ”“πŸ”’πŸ—οΈ, color coded red or grey or green, could be used to show this like it does already for HTTPS?

    Β³ Perhaps there is a #GPGP module that could be adapted for this purposes since there is a GPGP.js, init? #UIUX thots

    ⁴ #EndToEndNewsBlockchain πŸ”—πŸ”’πŸ’―

    ⁡ #LoT (A per news organization #LedgerOfThings utilizing current #Blockchain technologies but on a per #NewsOrganizationLevelBlockchain that could interoperate with a master #NewsLoT for verification purposes that is country specific as well as regional specific as well as world level news #LoT specific for verification purposes πŸ“°πŸ—žοΈπŸ’―

    ⁢ Multi-Level checks could be utilized as this specification(s) rolls out so as to be an πŸ§… layer verification system that iF even one thing fails, #SHA512, #LoTNewsOrgSpecific, #LoTNewsReporter, #LotNewsRegional, #LoTNewsNational, #LoTNewsWorld, #GPGPNewsOrg, #GPGNewsReporterSpecific, etc, there is a way to debug this #TamperProof #VerifiedNewsReportingArchitecture

    ⁷ "What would Phil Zimmerman.do?" πŸ’―πŸ€”

    #RTDNA #VerifiedNewsRSS #VerifiedNewsroom #VerifiedReporters specifications #RFE #news

    @evacide @eff
    @moznews
    @developers
    @rsa