Who said what(@g0njxa) 's Twitter Profile Photo

⚠️Watch out fake AV websites sharing malware

(for android)
/avast-securedownload.com Avast

Stealer
/bitdefender-app.com Bitdefender

(via Buer Loader?)
/malwarebytes.pro Malwarebytes

samples and detonations below 👀

⚠️Watch out fake AV websites sharing malware

#Spynote (for android)
/avast-securedownload.com @Avast 

#Lumma Stealer
/bitdefender-app.com @Bitdefender 

#StealC (via Buer Loader?)
/malwarebytes.pro @Malwarebytes 

samples and detonations below 👀
account_circle
Germán Fernández(@1ZRR4H) 's Twitter Profile Photo

⚠️ Android RAT dirigido a Chile 🇨🇱 y suplantando a Banco Estado y Banco Santander.

Para infectar a sus víctimas, el atacante realiza campañas de a través de la técnica conocida como BITB (Browser In The Browser). Ref: mrd0x.com/browser-in-the…

69.197.134.103…

⚠️ #SpyNote Android RAT dirigido a Chile 🇨🇱 y suplantando a Banco Estado y Banco Santander.

Para infectar a sus víctimas, el atacante realiza campañas de #phishing a través de la técnica conocida como BITB (Browser In The Browser). Ref: mrd0x.com/browser-in-the…

69.197.134.103…
account_circle
The Lallantop(@TheLallantop) 's Twitter Profile Photo

Android में नाम के मालवेयर ने एंट्री मारी है. जो सिस्टम अपडेट या ऐप अपडेट के नाम पर यूजर्स को लुभाता है. लिंक पर क्लिक करते ही कॉल लॉग से लेकर SMS, कैमरा और स्टोरेज का एक्सेस हासिल कर लेता है.

पूरी खबर: thelallantop.com/technology/pos…

Android में #SpyNote नाम के मालवेयर ने एंट्री मारी है. जो सिस्टम अपडेट या ऐप अपडेट के नाम पर यूजर्स को लुभाता है. लिंक पर क्लिक करते ही कॉल लॉग से लेकर SMS, कैमरा और स्टोरेज का एक्सेस हासिल कर लेता है.

पूरी खबर: thelallantop.com/technology/pos…
account_circle
emre(@0x6rss) 's Twitter Profile Photo

This is a type of craxs rat( ) malware. Since A101 is a Turkish🇹🇷 market chain, the target is Turkish citizens.

This is a type of craxs rat(#spynote) malware. Since A101 is a Turkish🇹🇷 market chain, the target is Turkish citizens.
account_circle
Karol Paciorek(@karol_paciorek) 's Twitter Profile Photo

🆕 Fresh : 161.35.124[.71

💻Client.exe - / botnet :
🔗 tria.ge/231201-mj55jah…

💻winapi.exe / ai.exe / netexe.jpg - (Base64 + Raw Inflate)
📡 C2: 65.0.50[.125:22355

📱ready.apk -
📡C2: 193.161.193[.99:20590

🆕 Fresh #opendir: 161.35.124[.71

💻Client.exe - #quasar / botnet #office04: 
🔗 tria.ge/231201-mj55jah…

💻winapi.exe / ai.exe / netexe.jpg - #PowerShell (Base64 + Raw Inflate)
📡 C2: 65.0.50[.125:22355 

📱ready.apk - #spynote
📡C2: 193.161.193[.99:20590
account_circle
FalconFeeds.io(@FalconFeedsio) 's Twitter Profile Photo

Some active C2 panels of Spynote botnet:

http://104[.]233[.]210[.]35/
https://warwickyouth[.]com/
https://csx22[.]top/
https://malai01.dorila[.]top/
https://lapassover[.]site/
https://video01.dorila[.]top/
https://heishitanfan[.]online/
http://104.225.158.203.16clouds[.]com/…

Some active C2 panels of Spynote botnet:

http://104[.]233[.]210[.]35/
https://warwickyouth[.]com/
https://csx22[.]top/
https://malai01.dorila[.]top/
https://lapassover[.]site/
https://video01.dorila[.]top/
https://heishitanfan[.]online/
http://104.225.158.203.16clouds[.]com/…
account_circle
Cleafy LABS(@cleafylabs) 's Twitter Profile Photo

🚨 Our technical analysis on SpyNote, a formerly Android Spyware recently adopted to perform bank frauds via Account Takeover attacks (ATO) and on-device fraud (ODF) against customers of several European banks.

Full report: cleafy.com/cleafy-labs/sp…

🚨 Our technical analysis on SpyNote, a formerly Android Spyware recently adopted to perform bank frauds via Account Takeover attacks (ATO) and on-device fraud (ODF) against customers of several European banks. 

Full report: cleafy.com/cleafy-labs/sp…

#android #botnet #cleafy
account_circle
Juan Carlos Ortiz 🛡️ Negocios Ciberseguros(@CycuraMX) 's Twitter Profile Photo

¿Te preocupa tu privacidad?

Siempre debes tener cuidado con lo que descargas en tu smartphone.

SpyNote es una muestra.

Se trata de un troyano para Android que puede grabar tus conversaciones y más.

🧵🖱️

¿Te preocupa tu privacidad?

Siempre debes tener cuidado con lo que descargas en tu smartphone.

SpyNote es una muestra. 

Se trata de un troyano para Android que puede grabar tus conversaciones y más.

🧵🖱️
account_circle
Michael R(@nahamike01) 's Twitter Profile Photo


chromeupdatetools[.]online
IP: 68.67.203[.]208

downloaded file: chrome-update.apk >
virustotal.com/gui/file/c278b…

#Spynote
chromeupdatetools[.]online
IP: 68.67.203[.]208

downloaded file: chrome-update.apk  >
virustotal.com/gui/file/c278b…
account_circle
vx-underground(@vxunderground) 's Twitter Profile Photo

We've updated the vx-underground malware sample collection

- Arechclient2
- CobaltStrike
- Emotet
- IcedId
- LockBitRansomware
- NetSupportRAT
- NSIS
- Paradies
- PoweRAT
- QakBot
- RedCap
- RedLine
- RoyalRansomware
- SpyNote
- Xdr33

Check it out here: vx-underground.org

We've updated the vx-underground malware sample collection

- Arechclient2
- CobaltStrike
- Emotet
- IcedId
- LockBitRansomware
- NetSupportRAT
- NSIS
- Paradies
- PoweRAT
- QakBot
- RedCap
- RedLine
- RoyalRansomware
- SpyNote
- Xdr33

Check it out here: vx-underground.org
account_circle
Osumi, Yusuke(@ozuma5119) 's Twitter Profile Photo

⚠️fake Android App [Rapport ラポート]

IP: 194.124.216[.]154 (AS3214 xTom)
Abused Brand: Bank of Japan 日本銀行
IoC: otx.alienvault.com/pulse/6440223b…

🦠/skin/client/signed10317c.apk
bazaar.abuse.ch/sample/7c4fdf5…
bazaar.abuse.ch/sample/841271e…
Naomi Suzuki moto_sato bunny

⚠️fake Android App [Rapport ラポート] #SpyNote #trojan

IP: 194.124.216[.]154 (AS3214 xTom)
Abused Brand: Bank of Japan 日本銀行
IoC: otx.alienvault.com/pulse/6440223b…

🦠/skin/client/signed10317c.apk
bazaar.abuse.ch/sample/7c4fdf5…
bazaar.abuse.ch/sample/841271e…
@NaomiSuzuki_ @58_158_177_102 @bunnymaid
account_circle
Cert AgID(@AgidCert) 's Twitter Profile Photo

🇮🇹 Campagna mascherata da App Mobile

🦠 è noto per le sue capacità invasive

ℹ️ Approfondimenti e 💣 👇

🔗 cert-agid.gov.it/news/rilevata-…

🇮🇹 Campagna #SpyNote mascherata da App #INPS Mobile

🦠 #SpyNote è noto per le sue capacità invasive

ℹ️ Approfondimenti e 💣 #IoC👇

🔗 cert-agid.gov.it/news/rilevata-…
account_circle
Virus Bulletin(@virusbtn) 's Twitter Profile Photo

Zscaler researchers show how a threat actor created malicious Skype, Google Meet and Zoom websites to spread SpyNote RAT to Android users and NjRAT & DCRat to Windows users. zscaler.com/blogs/security…

Zscaler researchers show how a threat actor created malicious Skype, Google Meet and Zoom websites to spread SpyNote RAT to Android users and NjRAT & DCRat to Windows users. zscaler.com/blogs/security…
account_circle