Found an active, full-featured C2 / Browser-in-the-Middle (BiTM) + Infostealer infrastructure exposed at 194.59.30.195:8000 (public IP 20.248.121.116, domain https://t.co/xHjfCoNIE7). This isn't just a phishing page - it's a remote browser takeover toolkit designed to steal credentials, session cookies, and financial data in real time.
The Attack Chain: Victims land on client.html, which streams live DOM snapshots from the attacker-controlled server inside an invisible iframe. The victim sees a perfect replica of their target site (Gmail, Chase, PayPal, Microsoft, etc.). Every interaction (clicks, scrolls, keystrokes) is relayed to the server, executed on a real Playwright browser instance, and the updated page is streamed back. The victim is never interacting with the legitimate site; they're inside a fully transparent proxy.
Stealth & Evasion: The server runs with headless=False and stealth_mode=True - launching visible Chrome instances (via Xvfb on Linux) to evade headless detection used by anti-bot systems like Cloudflare and Akamai. Desktop resolution is set to 4K (3840x2160) to perfectly mimic high-end user workstations.
Brand Impersonation: The client includes a massive built-in library of 150+ brand logos and color palettes (Google, Apple, Yahoo, Amazon, all major banks). When a victim navigates to a target URL, the loading screen dynamically mirrors the exact official branding, building instant trust before the fake page loads.
Credential & Financial Theft: The injected JavaScript actively hunts for sensitive fields targeting ssn, card, cvv, password, and email. The developers left a comment in the code: // FIX: Show FULL password value - no masking. Every password and credit card detail is captured in plain text and logged to data/key.json on the server.
Telegram & Proxy Exfiltration with Hardcoded Secrets: The server integrates a Telegram bot for instant exfiltration - bot token and chat ID are hardcoded directly in https://t.co/Bloj7CYIUA. Premium residential proxy credentials for Decodo and Oxylabs are also embedded in plain text, allowing the operator to bypass geo-restrictions while exposing their own paid infrastructure.
Infrastructure & OPSEC Failures: Admin credentials are hardcoded (batman123 pattern). XOR encryption uses a static key. Cloudflare Tunnel is built-in for public exposure. The server supports hidden_session=true - a flag that keeps certain victims invisible in the admin panel, allowing covert monitoring.
IOCs: 194.59.30.195:8000 | 20.248.121.116 | https://t.co/xHjfCoNIE7 | /admin | wss:///ws & /admin | data/key.json (keystrokes) | profiles/ (stolen cookies/history) | persistent_links.json (backdoor access links). Hardcoded admin credentials present. Telegram bot configured for exfiltration.
This is a low-skill codebase with high-impact criminal potential. The operator left multiple hardcoded secrets in plain text. Block the IPs immediately, monitor for profiles/ directory artifacts, and enforce phishing-resistant MFA.
#Infosec #Malware #C2 #Keylogger #BiTM #ThreatIntel #CyberSecurity #OpSecFail
50 sitios web que parecen 'ilegales' pero son perfectamente legales
1. https://t.co/CYYb69wAS1 — Descarga cualquier video de redes sociales
2. https://t.co/xfNyQaAfIH — Photoshop gratis
3. https://t.co/w9e9ZDKE0m — Correo electrónico temporal con un clic
4. https://t.co/zXVgMSMUKz — Más de 100 herramientas gratuitas en un solo sitio
5. https://t.co/4xWixCITyY — Accede a cualquier página web antigua
6. https://t.co/xmNwQwcbYD — Millones de libros de texto gratuitos
7. https://t.co/jsDkn2CLNG — Artículos de investigación gratuitos
8. https://t.co/dTEnsoq5wj — Encuentra alternativas gratuitas a aplicaciones
9. https://t.co/MKUIpIk3fd — Localiza dónde transmitir cualquier contenido
10. https://t.co/hBCRDs18p7 — 70.000 libros clásicos gratuitos
11. https://t.co/5VDGisfoED — Descargas gratuitas de PDF
12. https://t.co/dexoB5XzFz — Cursos gratuitos de universidades de élite
13. https://t.co/1lWE4zpHnz — Resuelve cualquier problema matemático al instante
14. https://t.co/FQuiLJAQrv — Elimina el fondo con un clic
15. https://t.co/Yf79zg46dZ — Borra objetos de fotos
16. https://t.co/P93Os8H5YT — Elimina el fondo de videos gratis
17. https://t.co/PyuYNPGTg0 — Comprime cualquier imagen gratis
18. https://t.co/8HsgHZFqEa — Gráficos dibujados a mano gratis
19. https://t.co/x6dKy6uePw — Convierte código en obras de arte
20. https://t.co/1LwFgBSVsn — Capturas de pantalla de código impresionantes
21. https://t.co/VY67Rwectv — Rastrea cualquier vuelo en tiempo real
22. https://t.co/hsUebR2Qlq — Rastrea el historial de precios de Amazon
23. https://t.co/LwPqZyGLyk — Verifica si has sido hackeado
24. https://t.co/udMswDyPke — Escanea malware en cualquier archivo
25. https://t.co/2TQmvJG176 — Envía mensajes autodestructivos
26. https://t.co/zdsDl0QODh — Comparte archivos que se eliminan automáticamente
27. https://t.co/VgXSsWh1wC — Archiva cualquier página web para siempre
28. https://t.co/BOWcUdOSyN — Elimina tu presencia de cualquier sitio web
29. https://t.co/0bteSbcPOY — Escucha cualquier emisora de radio del mundo
30. https://t.co/oql666oy5Q — Identifica las canciones de cualquier programa
31. https://t.co/5qnhYNh81M — Música para concentrarte
32. https://t.co/CFocTWwgKi — Paisajes sonoros personalizados para enfocarte
33. https://t.co/aIZ45zCe60 — Busca cada libro que se haya escrito
34. https://t.co/IAHMqpWARB — Asistente de IA para artículos de investigación
35. https://t.co/5ElktAwRwe — Busca consensos científicos
36. https://t.co/IwLwfgPx66 — Mapea investigaciones de forma visual
37. https://t.co/YgN1nSJFWJ — Búsqueda académica gratuita
38. https://t.co/yX50WOr9r5 — Comprende cualquier artículo de investigación
39. https://t.co/99qKiNBFKB — Resume cualquier video de YouTube
40. https://t.co/N2k4sNcQzA — Búsqueda de IA para desarrolladores
41. https://t.co/WmIpaukYAv — Prueba cualquier expresión regular al instante
42. https://t.co/W3yyseeqKE — Formatea cualquier código de forma clara
43. https://t.co/5Cy9PfvYBW — Entiende comandos de terminal
44. https://t.co/LWtsQbSSRH — Pizarra infinita en el navegador
45. https://t.co/4qhuHCjzmu — Verifica si un sitio web está caído
46. https://t.co/9DviDE62bT — Búsqueda inversa de imágenes
47. https://t.co/sikp898xZG — Prueba tu velocidad de internet
48. https://t.co/3dHGFcLd8Q — Edita PDF gratis
49. https://t.co/8Eeusq9Ovu — Combina y divide PDF
50. https://t.co/cUmwy95yYR — Correo temporal en segundos
Todo legal. Todo gratis.
Guárdalo antes de que se te olvide.🔖
🚨 A public PoC has been released for CVE-2026-25243 affecting Redis.
The flaw could allow authenticated remote code execution (RCE) via a crafted RESTORE payload. Fixed in Redis 8.6.3.
🔗 https://t.co/hLeR95nVDT
#Redis#RCE#CVE#CyberSecurity
SubCat by @duty_1g DNS brute forcing, continuous monitoring, screenshots with a built-in web report, and deep browser-based detection for sharper subdomain intelligence.
https://t.co/wW9ZVMvDKU
Abusing Printers to Compromise Active Directory
Modern office printers are often overlooked entry points into corporate networks. They can be abused to capture domain authentication data and ultimately facilitate a full domain compromise
We covered it in our article and gave recommendations on how to protect your environment
https://t.co/eHtWmFjeXz
@three_cube@_aircorridor
Use NextJS? Recon ✨
A quick way to find "all" paths for Next.js websites:
DevTools->Console
console.log(__BUILD_MANIFEST.sortedPages)
javascript:console.log(__BUILD_MANIFEST.sortedPages.join('\n'));
Credit: @ofjaaah#infosec#bugbountytips#bugbounty
We found a gadget-free RCE in Fastjson 1.2.83 - the final release of the 1.x line, and still one of the most widely-deployed Java JSON libraries in production today, even with 2.x around.
No classpath gadget. One payload-> RCE.
‼️🚨 CVE-2026-63030 // wp2shell-poc: Proof-of-concept for an unauthenticated SQL injection in WordPress core that chains to remote code execution, via REST batch route confusion.
PoC: https://t.co/ZZIufPdeKR
UN PROGRAMADOR ACABA DE LOGRAR LO QUE GOOGLE LLEVA AÑOS PASANDO POR ALTO
Desarrolló un navegador en rust creado específicamente para automatizar procesos, hacer scraping web y potenciar agentes de IA
> Solo consume 30MB de RAM
> Las páginas cargan en apenas 85ms
> Bloquea automáticamente más de 3.500 trackers
> Elimina anuncios, analíticas y scripts de rastreo
Se llama Obscura
Y tiene algo que Chrome nunca va a poder ofrecer
Cada sesión genera una huella completamente distinta. GPU, canvas, audio, batería… todo se randomiza
Ningún detector lo identifica porque se comporta exactamente igual que un Chrome real
Es el reemplazo directo de Puppeteer y Playwright
Sin Node.js. Sin dependencias. Un solo binario
Ya supera las 16k estrellas en GitHub. 100% open source. Totalmente gratis
Guárdalo antes de que se te olvide, es una joya 📄
🚨 CVE-2026-48313 - high 🚨
ColdFusion - Path Traversal
> ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitatio...
👾 https://t.co/e7ajcuA4ZP
@pdnuclei#NucleiTemplates#cve
A PoC/exploit has been discovered for vulnerability CVE-2026-26114
PT ID: PT-2026-24324
Vendor: Microsoft
Product: Microsoft SharePoint Enterprise Server 2016
Description: Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Link: https://t.co/uHBd5jt9MN
#dbugs_vuln
🔐 SwaggerSpy – Automated OSINT Tool for Discovering Exposed Information on SwaggerHub APIs
SwaggerSpy is an open-source OSINT tool that automates intelligence gathering from publicly available SwaggerHub API documentation. It searches SwaggerHub projects and analyzes API specifications using pattern matching to identify potentially exposed sensitive information, such as API keys, credentials, tokens, secrets, endpoints, and other security-relevant artifacts that may have been unintentionally included in documentation. The tool helps security researchers, application security engineers, penetration testers, bug bounty hunters, developers, and defensive security teams identify accidental information exposure, improve API security posture, and validate secure documentation practices. SwaggerSpy is intended for authorized security research, educational purposes, and defensive assessments of publicly accessible API documentation, enabling organizations to proactively identify and remediate potential information leaks before they become security risks.
🔗 https://t.co/eV70HnDKel
#OSINT #APISecurity #AppSec #CyberSecurity #ThreatIntelligence #SecurityResearch #OpenSource #DevSecOps