The trolling level is off the charts
The trolling level is off the charts
Not sure what type of #malware this is, but it's not Koi Stealer.
Details at github.com/malware-traf...
Not sure what type of #malware this is, but it's not Koi Stealer.
Details at github.com/malware-traf...
It's journalistic malpractice for the mainstream press to not continuously ask what he's hiding.
It's journalistic malpractice for the mainstream press to not continuously ask what he's hiding.
You're free to do whatever you want with it. However, if you make a profit, give us some money. If you don't... you're mean.
vx-underground.org/Art
You're free to do whatever you want with it. However, if you make a profit, give us some money. If you don't... you're mean.
vx-underground.org/Art
Whitewashing her reputation is madness.
Whitewashing her reputation is madness.
Release the files!
Build concentration camps? Oh yeah, definitely part of our mission.
Build concentration camps? Oh yeah, definitely part of our mission.
The number isn't zero.
The number isn't zero.
From a cursory look it seems like they didn't even try to hide the edit in the metadata, this looks suspiciously like two separate files edited together (not just cutting something out), seems "MJCOLE~1" used PremierPro to do at least part of it
This one works by tricking users into copying a file path in Windows Explorer.
Attackers modify the clipboard, so you're actually pasting and running PowerShell ahead of the file path
mrd0x.com/filefix-clic...
This one works by tricking users into copying a file path in Windows Explorer.
Attackers modify the clipboard, so you're actually pasting and running PowerShell ahead of the file path
mrd0x.com/filefix-clic...
A #pcap of the traffic, the malware/artifacts, and some IOCs are available at www.malware-traffic-analysis.net/2025/06/18/i....
Today's the 12th anniversary of my blog, so I made this post a bit more old school.
A #pcap of the traffic, the malware/artifacts, and some IOCs are available at www.malware-traffic-analysis.net/2025/06/18/i....
Today's the 12th anniversary of my blog, so I made this post a bit more old school.
He was conducting routine immigration court work, escorting individuals from hearings.
He asked ICE for their warrant - well within his legal rights.
This is political intimidation.
He was conducting routine immigration court work, escorting individuals from hearings.
He asked ICE for their warrant - well within his legal rights.
This is political intimidation.
You can downplay that concern all you want. But it IS happening to people and happening without due process. There's no reason it couldn't happen to him.
You can downplay that concern all you want. But it IS happening to people and happening without due process. There's no reason it couldn't happen to him.
⛔ 195.82.146.193:443
⛔ 195.82.146.221:443
⛔ 195.82.146.223:443
Not only Lumma botnet C2s are hosted there ⤵️
threatfox.abuse.ch/asn/47105/
⛔ 195.82.146.193:443
⛔ 195.82.146.221:443
⛔ 195.82.146.223:443
Not only Lumma botnet C2s are hosted there ⤵️
threatfox.abuse.ch/asn/47105/
2. Whose interest is this message serving?
3. Nobody really believes Russia is going nuclear, especially without their strategic bombers.
2. Whose interest is this message serving?
3. Nobody really believes Russia is going nuclear, especially without their strategic bombers.