Today we published WeWorm, the first zero-click worm to spread through WeChat calls across iOS and Android.
We call you on WeChat and, without you answering or doing anything, take over your account within seconds. Then we use your phone to call your friends.
Story and demos: https://t.co/5qJOcwSPLN
Run your own: Self-host.
Fund your own: Stack XMR/Real assets
Answer to no one.
Stop watching the propaganda.
"The people are ultimately subordinate to government,
not the other way around,
and that inversion of power is the problem."
- Edward Snowden
Tracking a novel Rust-based backdoor as #ChaosC2 that uses Discord for C2. Threat actors drop #UltraViewer for remote access and #NodeJS for reverse proxy. It screenshots the victim device, supports commands like: download (download files), shell (hands-on keyboard shell commands). So far we're seeing two threat actors using it, "chaos_00019" and "Zalo". Threat actors are likely using a Chinese version of Discord given their general channel's name "常规".
https://t.co/bFU01MX5Ra