bolha.us is one of the many independent Mastodon servers you can use to participate in the fediverse.
We're a Brazilian IT Community. We love IT/DevOps/Cloud, but we also love to talk about life, the universe, and more. | Nós somos uma comunidade de TI Brasileira, gostamos de Dev/DevOps/Cloud e mais!

Server stats:

253
active users

#infostealer

1 post1 participant0 posts today
abs(in)the<p>Given that sophisticated <a href="https://mastodon.sdf.org/tags/infostealer" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infostealer</span></a> <a href="https://mastodon.sdf.org/tags/malware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>malware</span></a> increasingly includes checks to avoid detection by shutting down if it detects it is on a virtualised host...</p><p>What is the security vs convenience+performance tradeoff for running a primary work environment inside a virtualised guest?</p><p>Or... is there actually a (small) security benefit by running a kernel shim to make your real environment appear to be virtualised?</p><p>random <a href="https://mastodon.sdf.org/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a> thought for the day</p>
N_{Dario Fadda}<p><a href="https://poliversity.it/tags/RANSOMFEED" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>RANSOMFEED</span></a> </p><p>☠️ <a href="https://poliversity.it/tags/HellCat" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>HellCat</span></a> ransomware group has exploited stolen Jira credentials from <a href="https://poliversity.it/tags/infostealer" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infostealer</span></a> malware to target new four organizations</p><p><a href="https://ransomfeed.it/stats.php?page=group-profile&amp;group=hellcat" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">ransomfeed.it/stats.php?page=g</span><span class="invisible">roup-profile&amp;group=hellcat</span></a></p>
CryptoLek<p>StealC infostealer has a major update.</p><p>According to the person behind the malware, the development of the second version took half a year, and in its essence, it is an entirely new software.</p><p>Me being me, I decided not to bother too much and, instead, just dump a machine translation of the user’s post, with some minor edits from my side.</p><p><a href="https://cryptolek.info/2025/03/30/stealc-v2-a-major-update-to-a-popular-infostealer/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">cryptolek.info/2025/03/30/stea</span><span class="invisible">lc-v2-a-major-update-to-a-popular-infostealer/</span></a></p><p><a href="https://infosec.exchange/tags/StealC" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>StealC</span></a> <a href="https://infosec.exchange/tags/infostealer" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infostealer</span></a></p>
The New Oil<p><a href="https://mastodon.thenewoil.org/tags/Infostealer" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Infostealer</span></a> campaign compromises 10 <a href="https://mastodon.thenewoil.org/tags/npm" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>npm</span></a> packages, targets devs</p><p><a href="https://www.bleepingcomputer.com/news/security/infostealer-campaign-compromises-10-npm-packages-targets-devs/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">bleepingcomputer.com/news/secu</span><span class="invisible">rity/infostealer-campaign-compromises-10-npm-packages-targets-devs/</span></a></p><p><a href="https://mastodon.thenewoil.org/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a></p>
Cybernews<p>Arkana Security claimed responsibility for a breach at WideOpenWest (WoW), with Huston Rock researchers citing an infostealer infection.</p><p><a href="https://infosec.exchange/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a> <a href="https://infosec.exchange/tags/databreach" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>databreach</span></a> <a href="https://infosec.exchange/tags/infostealer" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infostealer</span></a> <a href="https://infosec.exchange/tags/hacking" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>hacking</span></a> <a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a> </p><p><a href="https://cnews.link/wideopenwest-allegedly-breached-hackers-threaten-data-release-1/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">cnews.link/wideopenwest-allege</span><span class="invisible">dly-breached-hackers-threaten-data-release-1/</span></a></p>
Intego Mac Security :verified:<p>🚨 Valve’s Steam game platform was exploited to push malware—twice in 2 months. 👀</p><p>Valve has removed “Sniper: Phantom’s Resolution” from Steam. Last month it banned “PirateFi”—both reportedly contained infostealer malware.</p><p>Read <span class="h-card" translate="no"><a href="https://infosec.exchange/@theJoshMeister" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>theJoshMeister</span></a></span>’s report: <a href="https://www.intego.com/mac-security-blog/steam-game-store-exploited-to-push-malware-twice-in-2-months/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">intego.com/mac-security-blog/s</span><span class="invisible">team-game-store-exploited-to-push-malware-twice-in-2-months/</span></a></p><p><a href="https://infosec.exchange/tags/malware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>malware</span></a> <a href="https://infosec.exchange/tags/steamgame" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>steamgame</span></a> <a href="https://infosec.exchange/tags/steamstorepage" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>steamstorepage</span></a> <a href="https://infosec.exchange/tags/infostealer" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infostealer</span></a> <a href="https://infosec.exchange/tags/stealer" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>stealer</span></a> <a href="https://infosec.exchange/tags/gaming" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>gaming</span></a> <a href="https://infosec.exchange/tags/gamingnews" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>gamingnews</span></a> <a href="https://infosec.exchange/tags/malwareprotection" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>malwareprotection</span></a> <a href="https://infosec.exchange/tags/antivirus" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>antivirus</span></a> <a href="https://infosec.exchange/tags/videogamenews" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>videogamenews</span></a> <a href="https://infosec.exchange/tags/gamenews" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>gamenews</span></a> <a href="https://infosec.exchange/tags/steam" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>steam</span></a> <a href="https://infosec.exchange/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a> <a href="https://infosec.exchange/tags/cybersecuritynews" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecuritynews</span></a> <a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a> <a href="https://infosec.exchange/tags/securitynews" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>securitynews</span></a> <a href="https://infosec.exchange/tags/informationsecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>informationsecurity</span></a> <a href="https://infosec.exchange/tags/malwarealert" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>malwarealert</span></a></p>
Bob Carver<p><a href="https://www.businessinsider.com/roleplay-pretend-chatgpt-writes-password-stealing-malware-google-chrome-2025-3" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">businessinsider.com/roleplay-p</span><span class="invisible">retend-chatgpt-writes-password-stealing-malware-google-chrome-2025-3</span></a><br><a href="https://infosec.exchange/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a> <a href="https://infosec.exchange/tags/ChatGPT" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ChatGPT</span></a> <a href="https://infosec.exchange/tags/LLMs" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LLMs</span></a> <a href="https://infosec.exchange/tags/malware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>malware</span></a> <a href="https://infosec.exchange/tags/infostealer" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infostealer</span></a></p>
JayeLTee<p>I asked for help here some months ago about one of the servers on this post that was hosted by Microsoft. </p><p>You can read about how that and other servers with infostealer logs ended up closed.</p><p>Hint: MSRC Portal is basically useless.</p><p><a href="https://jltee.substack.com/p/billions-of-infostealer-logs-exposed" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">jltee.substack.com/p/billions-</span><span class="invisible">of-infostealer-logs-exposed</span></a></p><p><a href="https://infosec.exchange/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a> <a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a> <a href="https://infosec.exchange/tags/infostealer" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infostealer</span></a> <a href="https://infosec.exchange/tags/data" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>data</span></a> <a href="https://infosec.exchange/tags/databases" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>databases</span></a> <a href="https://infosec.exchange/tags/microsoft" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>microsoft</span></a></p>
The New Oil<p><a href="https://mastodon.thenewoil.org/tags/EncryptHub" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>EncryptHub</span></a> breaches 618 orgs to deploy infostealers, <a href="https://mastodon.thenewoil.org/tags/ransomware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ransomware</span></a></p><p><a href="https://www.bleepingcomputer.com/news/security/encrypthub-breaches-618-orgs-to-deploy-infostealers-ransomware/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">bleepingcomputer.com/news/secu</span><span class="invisible">rity/encrypthub-breaches-618-orgs-to-deploy-infostealers-ransomware/</span></a></p><p><a href="https://mastodon.thenewoil.org/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a> <a href="https://mastodon.thenewoil.org/tags/cybercrime" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybercrime</span></a> <a href="https://mastodon.thenewoil.org/tags/infostealer" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infostealer</span></a> <a href="https://mastodon.thenewoil.org/tags/malware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>malware</span></a></p>
The New Oil<p><a href="https://mastodon.thenewoil.org/tags/HaveIBeenPwned" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>HaveIBeenPwned</span></a> adds 284M accounts stolen by <a href="https://mastodon.thenewoil.org/tags/infostealer" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infostealer</span></a> <a href="https://mastodon.thenewoil.org/tags/malware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>malware</span></a></p><p><a href="https://www.bleepingcomputer.com/news/security/have-i-been-pwned-adds-284m-accounts-stolen-by-infostealer-malware/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">bleepingcomputer.com/news/secu</span><span class="invisible">rity/have-i-been-pwned-adds-284m-accounts-stolen-by-infostealer-malware/</span></a></p><p><a href="https://mastodon.thenewoil.org/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a> <a href="https://mastodon.thenewoil.org/tags/HIBP" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>HIBP</span></a> <a href="https://mastodon.thenewoil.org/tags/DataBreach" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DataBreach</span></a></p>
The New Oil<p>New <a href="https://mastodon.thenewoil.org/tags/FrigidStealer" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>FrigidStealer</span></a> <a href="https://mastodon.thenewoil.org/tags/infostealer" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infostealer</span></a> infects Macs via fake browser updates</p><p><a href="https://www.bleepingcomputer.com/news/security/new-frigidstealer-infostealer-infects-macs-via-fake-browser-updates/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">bleepingcomputer.com/news/secu</span><span class="invisible">rity/new-frigidstealer-infostealer-infects-macs-via-fake-browser-updates/</span></a></p><p><a href="https://mastodon.thenewoil.org/tags/malware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>malware</span></a> <a href="https://mastodon.thenewoil.org/tags/Mac" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Mac</span></a> <a href="https://mastodon.thenewoil.org/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a></p>
LavX News<p>Malicious Infostealer Packages Target Developers on PyPI Amid DeepSeek AI Surge</p><p>In a concerning trend, threat actors are leveraging the popularity of DeepSeek AI by distributing malicious infostealer packages on PyPI. Developers who downloaded these packages may have unknowingly ...</p><p><a href="https://news.lavx.hu/article/malicious-infostealer-packages-target-developers-on-pypi-amid-deepseek-ai-surge" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://</span><span class="ellipsis">news.lavx.hu/article/malicious</span><span class="invisible">-infostealer-packages-target-developers-on-pypi-amid-deepseek-ai-surge</span></a></p><p><a href="https://mastodon.cloud/tags/news" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>news</span></a> <a href="https://mastodon.cloud/tags/tech" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>tech</span></a> <a href="https://mastodon.cloud/tags/PyPI" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PyPI</span></a> <a href="https://mastodon.cloud/tags/DeepSeek" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DeepSeek</span></a> <a href="https://mastodon.cloud/tags/Infostealer" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Infostealer</span></a></p>
Sean Whalen 👨🏼‍🦼🏳️‍🌈🇺🇦🕊️<p>In this post I take a deep dive into a fake CAPTCHA on a compromised website, and the multistage fileless loader that delivered the Lumma Stealer malware if visitors followed its instructions.</p><p><a href="https://infosec.exchange/tags/Google" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Google</span></a> <a href="https://infosec.exchange/tags/reCAPTCHA" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>reCAPTCHA</span></a> <a href="https://infosec.exchange/tags/WordPress" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>WordPress</span></a> <a href="https://infosec.exchange/tags/PowerShell" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PowerShell</span></a> <a href="https://infosec.exchange/tags/Malware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Malware</span></a> <a href="https://infosec.exchange/tags/Emmenhtal" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Emmenhtal</span></a> <a href="https://infosec.exchange/tags/Infostealer" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Infostealer</span></a> <a href="https://infosec.exchange/tags/LummaStealer" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LummaStealer</span></a></p><p><a href="https://seanthegeek.net/posts/compromized-store-spread-lumma-stealer-using-fake-captcha/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">seanthegeek.net/posts/compromi</span><span class="invisible">zed-store-spread-lumma-stealer-using-fake-captcha/</span></a></p>
securityaffairs<p><a href="https://infosec.exchange/tags/Raccoon" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Raccoon</span></a> <a href="https://infosec.exchange/tags/Infostealer" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Infostealer</span></a> operator sentenced to 60 months in prison<br><a href="https://securityaffairs.com/172163/cyber-crime/raccoon-infostealer-operator-sentenced-to-60-months-prison.html" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">securityaffairs.com/172163/cyb</span><span class="invisible">er-crime/raccoon-infostealer-operator-sentenced-to-60-months-prison.html</span></a><br><a href="https://infosec.exchange/tags/securityaffairs" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>securityaffairs</span></a> <a href="https://infosec.exchange/tags/hacking" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>hacking</span></a></p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://mastodon.social/@MartinaNeumayer" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>MartinaNeumayer</span></a></span> <span class="h-card" translate="no"><a href="https://infosec.exchange/@nazgul" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>nazgul</span></a></span> it's not enough to <em>"Class Action"</em> because that allows Facebook to just pay and not face actual Accountability and Consequences!</p><ul><li>The entire chain from the developer who did this up to CISO &amp; CTO need to face jailtime for this InfoStealer!</li></ul><p><a href="https://infosec.space/@kkarhan/113414084603455255" translate="no" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://</span><span class="ellipsis">infosec.space/@kkarhan/1134140</span><span class="invisible">84603455255</span></a></p><p><a href="https://infosec.space/tags/LackOfAccountability" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LackOfAccountability</span></a> <a href="https://infosec.space/tags/LackOfConsequences" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LackOfConsequences</span></a> <a href="https://infosec.space/tags/ClassAction" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ClassAction</span></a> <a href="https://infosec.space/tags/NSAbook" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>NSAbook</span></a> <a href="https://infosec.space/tags/StasiBook" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>StasiBook</span></a> <a href="https://infosec.space/tags/InfoStealer" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>InfoStealer</span></a> <a href="https://infosec.space/tags/Malware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Malware</span></a> <a href="https://infosec.space/tags/WhatYouAllowIsWhatWillContinue" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>WhatYouAllowIsWhatWillContinue</span></a> <a href="https://infosec.space/tags/Accountability" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Accountability</span></a> <a href="https://infosec.space/tags/Consequences" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Consequences</span></a> <a href="https://infosec.space/tags/LackOfAccountability" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LackOfAccountability</span></a> <a href="https://infosec.space/tags/LackOfConsequences" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LackOfConsequences</span></a></p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://mastodon.social/@gurkanctn" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>gurkanctn</span></a></span> <span class="h-card" translate="no"><a href="https://infosec.exchange/@nazgul" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>nazgul</span></a></span> not just invading, but <a href="https://infosec.space/@kkarhan/113413999824933801" rel="nofollow noopener noreferrer" target="_blank">illegal</a>...</p><ul><li>Imagine if a Web Mailer (i.e. Protonmail) or eMail client (i.e. Outlook) were to scan your <code>/home/</code> directory and <em>preemptively upload</em> all the PDFs and OOXML files to OneDrive just in case you want to sent them from your laptop...</li></ul><p>This is called an <em>"info stealer"</em> and it's classified as a malware for <em>very good reasons</em>!</p><p><a href="https://infosec.space/tags/Privacy" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Privacy</span></a> <a href="https://infosec.space/tags/DataProtection" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DataProtection</span></a> <a href="https://infosec.space/tags/ConsumerRights" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ConsumerRights</span></a> <a href="https://infosec.space/tags/InfoStealer" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>InfoStealer</span></a> <a href="https://infosec.space/tags/Instagram" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Instagram</span></a> <a href="https://infosec.space/tags/Facebook" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Facebook</span></a> <a href="https://infosec.space/tags/NSAbook" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>NSAbook</span></a> <a href="https://infosec.space/tags/StasiBook" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>StasiBook</span></a> <a href="https://infosec.space/tags/DataExfiltration" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DataExfiltration</span></a> <a href="https://infosec.space/tags/GDPR" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GDPR</span></a> <a href="https://infosec.space/tags/BDSG" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>BDSG</span></a> <a href="https://infosec.space/tags/GAFAMs" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GAFAMs</span></a> <a href="https://infosec.space/tags/PRISM" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PRISM</span></a> <a href="https://infosec.space/tags/CloudAct" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CloudAct</span></a></p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://infosec.exchange/@nazgul" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>nazgul</span></a></span> <em>waits till he finds out that WhatsApp nonconsensually uploads everyones' contacts and phone numbers to NSAbook's servers...</em></p><p><a href="https://infosec.space/@kkarhan/113413999824933801" translate="no" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://</span><span class="ellipsis">infosec.space/@kkarhan/1134139</span><span class="invisible">99824933801</span></a><br><a href="https://infosec.space/@kkarhan/113413999824933801" translate="no" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://</span><span class="ellipsis">infosec.space/@kkarhan/1134139</span><span class="invisible">99824933801</span></a></p><p><a href="https://infosec.space/tags/Privacy" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Privacy</span></a> <a href="https://infosec.space/tags/InfoStealer" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>InfoStealer</span></a> <a href="https://infosec.space/tags/NSAbook" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>NSAbook</span></a> <a href="https://infosec.space/tags/StasiBook" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>StasiBook</span></a> <a href="https://infosec.space/tags/Facebook" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Facebook</span></a> <a href="https://infosec.space/tags/WhatsApp" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>WhatsApp</span></a> <a href="https://infosec.space/tags/DataHarvesting" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DataHarvesting</span></a> <a href="https://infosec.space/tags/DataProtection" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DataProtection</span></a> <a href="https://infosec.space/tags/ConsumerRights" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ConsumerRights</span></a> <a href="https://infosec.space/tags/PRISM" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PRISM</span></a> <a href="https://infosec.space/tags/GAFAMs" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GAFAMs</span></a></p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://mastodon.online/@nickali" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>nickali</span></a></span> <span class="h-card" translate="no"><a href="https://infosec.exchange/@nazgul" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>nazgul</span></a></span> that's because they never faced actual accountability nor consequences.</p><ul><li>And I don't mean a fine, but actual jailtime! </li></ul><p><a href="https://infosec.space/@kkarhan/113413999824933801" translate="no" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://</span><span class="ellipsis">infosec.space/@kkarhan/1134139</span><span class="invisible">99824933801</span></a><br><a href="https://infosec.space/@kkarhan/113414012396154242" translate="no" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://</span><span class="ellipsis">infosec.space/@kkarhan/1134140</span><span class="invisible">12396154242</span></a></p><p><a href="https://infosec.space/tags/Accountability" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Accountability</span></a> <a href="https://infosec.space/tags/Consequences" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Consequences</span></a> <a href="https://infosec.space/tags/LackOfAccountability" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LackOfAccountability</span></a> <a href="https://infosec.space/tags/LackOfConsequences" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LackOfConsequences</span></a> <a href="https://infosec.space/tags/NSAbook" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>NSAbook</span></a> <a href="https://infosec.space/tags/StadiBook" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>StadiBook</span></a> <a href="https://infosec.space/tags/Facebook" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Facebook</span></a> <a href="https://infosec.space/tags/InfoStealer" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>InfoStealer</span></a> <a href="https://infosec.space/tags/DataExfiltration" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DataExfiltration</span></a></p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://apobangpo.space/@jodmentum" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>jodmentum</span></a></span> <span class="h-card" translate="no"><a href="https://infosec.exchange/@nazgul" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>nazgul</span></a></span> why is there no <em>"no thanks"</em> option with a tickbox <em>"don't ask me again"</em> next to it?</p><p>Pretty shure this violates <a href="https://infosec.space/tags/GDPR" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GDPR</span></a> &amp; <a href="https://infosec.space/tags/BDSG" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>BDSG</span></a>!</p><p>Cc: <span class="h-card" translate="no"><a href="https://ec.social-network.europa.eu/@EUCommission" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>EUCommission</span></a></span> <span class="h-card" translate="no"><a href="https://mastodon.social/@noybeu" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>noybeu</span></a></span> <span class="h-card" translate="no"><a href="https://social.bund.de/@bsi" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>bsi</span></a></span> <span class="h-card" translate="no"><a href="https://verbraucherzentrale.social/@Bundesverband" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>Bundesverband</span></a></span> </p><p><a href="https://infosec.space/tags/Facebook" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Facebook</span></a> <a href="https://infosec.space/tags/Instagram" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Instagram</span></a> <a href="https://infosec.space/tags/InfoStealer" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>InfoStealer</span></a> <a href="https://infosec.space/tags/DataProtection" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DataProtection</span></a> <a href="https://infosec.space/tags/ConsumerRights" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ConsumerRights</span></a> <a href="https://infosec.space/tags/NSAbook" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>NSAbook</span></a> <a href="https://infosec.space/tags/GAFAMs" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GAFAMs</span></a> <a href="https://infosec.space/tags/PRISM" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PRISM</span></a> <a href="https://infosec.space/tags/DataExfiltration" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DataExfiltration</span></a> <a href="https://infosec.space/tags/NonconsensualUpload" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>NonconsensualUpload</span></a> <a href="https://infosec.space/tags/NoThanks" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>NoThanks</span></a> <a href="https://infosec.space/tags/OptOut" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OptOut</span></a> <a href="https://infosec.space/tags/OptIn" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OptIn</span></a></p>
Taggart :donor:<p>A fantastic Lumma writeup, and another instance of targeting BitLockerToGo.exe as the injection point, making it an even stronger detection signal.</p><p><a href="https://blog.qualys.com/vulnerabilities-threat-research/2024/10/20/unmasking-lumma-stealer-analyzing-deceptive-tactics-with-fake-captcha" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">blog.qualys.com/vulnerabilitie</span><span class="invisible">s-threat-research/2024/10/20/unmasking-lumma-stealer-analyzing-deceptive-tactics-with-fake-captcha</span></a></p><p><a href="https://infosec.exchange/tags/ThreatIntel" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ThreatIntel</span></a> <a href="https://infosec.exchange/tags/ThreatIntelligence" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ThreatIntelligence</span></a> <a href="https://infosec.exchange/tags/InfoSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>InfoSec</span></a> <a href="https://infosec.exchange/tags/LummaStealer" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LummaStealer</span></a> <a href="https://infosec.exchange/tags/InfoStealer" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>InfoStealer</span></a></p>