جولة لمدة دقيقة ونصف داخل لوحة التحكم (Panel) الخاصة بمجموعة الفدية LockBit 3.0 تكشف تفاصيل مهمة عن عمليات وأدوات المجموعة الداخلية.
🔹 أبرز محتويات الفيديو:
•لوحة إدارة الحسابات والدعم الفني.
•لوحة إعداد برمجيات الفدية (Ransomware Builder)، والتي توفر خصائص متقدمة مثل حذف سجلات الأحداث (Event Logs) وإيقاف برامج الحماية (Kill Defender).
•قائمة ضحايا المجموعة مع تواريخ وحجم البيانات المسروقة.
•تفاصيل إدارة حسابات المستخدمين (Affiliates) وبياناتهم.
•وصول إلى ملفات السيرفر الداخلية، بما في ذلك ملفات حساسة ومشفّرة (shadow file).
•إحصائيات لزيارات لوحة التحكم وتفاعل الضحايا مع طلبات فك التشفير.
•محادثات بين LockBit والضحايا توضح أساليب التفاوض والضغط لدفع الفدية.
Con ustedes 🥁.... el panel de la botnet #BazarLoader aka #BazarBackdoor utilizado por los operadores de Conti Ransomware 🔥🔥🔥
608 dominios únicos extraídos desde la sección de bots (posiblemente compañías comprometidas) 🌶️
[+] https://t.co/bS4RA8c8bJ
#ContiLeaks 🕵️♂️
🚨LockBit 5.0 Has Arrived: Targeting Windows, Linux, and ESXi
A new version of the LockBit ransomware, LockBit 5.0, has been discovered targeting Windows, Linux, and VMware ESXi systems.
Trend Micro analyzed samples of this variant, which continues the Ransomware-as-a-Service (RaaS) model. LockBit 5.0 is capable of disabling security tools, encrypting data quickly, and spreading laterally through networks. The variant uses command-line parameters to customize attacks and supports multiple CPU architectures (e.g., ARM, MIPS, x86, x64). The Linux and ESXi versions include shell scripts that stop virtual machines to enable encryption.
The malware uses legitimate tools, like AnyDesk, Advanced IP Scanner, and netscan, to conduct reconnaissance and maintain persistence. While the exact number of victims or ransom demands was not disclosed, LockBit 5.0’s technical sophistication suggests it is being actively deployed in ongoing campaigns.
Source:https://t.co/hsoelVn9LG
‼️ HYFLOCK RaaS/Panel seen on a popular Russian cybercrime forum
The admin states:
Hyflock is a new ransomware-as-a-service (RaaS) operation positioning itself as a competitor to LockBit.
Key highlights from their pitch to potential affiliates:
Their Windows encryptor is claimed to be the fastest available, featuring GPO deployment, shadow copy deletion, self-deletion, and cloud-synced folder encryption.
Beyond a standard operator panel, their platform includes a built-in marketplace where affiliates can purchase initial access and exploit tools, with direct seller communication.
The platform also supports team creation and management. They offer an 80/20 revenue split (affiliate/operator) with fast settlements, noting the split may adjust after the first transaction.
As a newer group, they're actively soliciting feedback and iterating quickly. They adhere to not attacking the CIS, China, and North Korea.
🚨 Anubis RaaS updates affiliate program
The threat actor #superSonic is recruiting and announcing program changes on their Ransomware-as-a-Service #Anubis.
🛠️ Claimed updates include:
• Free VOIP calls + target contact checks
• Spam mail ops to victims
• No DDoS in program rules
• Joint-wallet “transparent” negotiations
• Servers provided for data exfiltration
• 24/7 support for affiliates
• Legal team for negotiation support
• Direct outreach to victims, regulators, media
• “Quality” breach posts to maximize impact
• Fast-mode encryption; improved wiper speed
⚠️ These are seller claims and not independently verified.
#ThreatIntel #Ransomware #Anubis #RaaS #Cybercrime #DoubleExtortion #Linux #ESXi #Infosec #CTI #DarkWeb #Malware
صح لأنه صار فعلًا بزنس زي ما تقول ( أوبر) ولكن للاختراق.
الفكرة ببساطة إن منصات الفدية كخدمة (RaaS) صارت تتطور عشان تجذب الهاكرز اللي يبغون ينفذون هجماتهم بدون ما يتعبون في البرمجة أو التطوير.
و بدل ما المطوّر نفسه يهاجم:
• يبني منصة
• يطوّر برمجية فدية جاهزة
• يوفّر لوحة تحكم
• ويتفق على تقاسم الأرباح
والهاكر اللي يبي يشتغل:
• يستخدم الأدوات
• ينفذ الاختراق
• والمطوّر يأخذ نسبته من الفدية إذا دفعوها الضحايا
يعني تحوّل الموضوع من “هاكر يهاجم”
إلى بيزنس موديل كامل مبني على جذب الهاكرز وتنفيذ عمليات باسمهم.
شوف هذا الفيديو شرحت في النموذج كامل.
🚨 Remus information-stealing malware offered as a service
A forum seller is advertising Remus, a malware-as-a-service stealer promoted with 24/7 support, an easy-to-use control panel, configurable builds, automated log processing, Telegram integration, and a claimed callback rate of up to 90%.
The seller claims Remus can collect:
• Data from 21 browsers, 16 cold wallets, and 38 applications
• Credentials, cookies, autofill data, browser history, saved notes, and payment card numbers with CVVs
• Cryptocurrency seed phrases, private keys, wallet files, and MetaMask data
• Data from 181 Chromium wallet extensions, 43 password managers, 11 note extensions, and 13 two-factor authentication extensions
• Data from 42 Mozilla wallet extensions, 22 password managers, and four authentication extensions
• Files from selected folders using configurable paths, masks, depth limits, exclusions, and maximum file sizes
The management panel reportedly includes:
• Full and incomplete log scoring with detailed statistics
• Search filters for cookies, passwords, browser history, and other collected data
• AND/OR search conditions and preconfigured filters for different targeting categories
• Instant browser-based log viewing without downloading the archive
• Unlimited log exports and simultaneous download tasks
• Per-build statistics pages and configurable collection rules
• Telegram alerts, bots, loaders, and callback notifications
• Support for operator-controlled collection servers deployed through Docker
The malware is reportedly written in C++ and uses:
• System calls and a custom communication protocol
• Encrypted configurations and encrypted data transmission
• Compressed logs, caching, backup servers, and microservice infrastructure
• Build obfuscation and a small executable footprint
• Claimed EDR bypass capabilities
• Claimed detection of virtual machines, honeypots, and dedicated analysis servers
• A claimed automated MetaMask wallet brute-force feature
Pricing is advertised at:
• Base: $250 per month
• Pro: $500 per month
• Enterprise: $1,000 per month
Higher-priced plans reportedly add more builds, filters, Telegram bots, loaders, concurrent exports, team accounts, worker dashboards, API access, granular permissions, and DLL, PowerShell, or in-memory execution options.
This claim is currently unverified.
Midnight Blizzard/Storm-2945
Since February 2026, Storm-2945 has conducted AI-augmented operations including targeted device code and OAuth code phishing campaigns leading to Entra device registration and subsequent data collection from Microsoft 365.
Since early May 2026, Storm-2945 manipulating DNS and HTTP traffic from networks served by captive portals to redirect user traffic through actor-controlled infrastructure.
https://t.co/gJGcS6tMYU
[Wipeload Project ⛰️ — Step 6] Chrome Full-Chain Exploitation
In this article, we take the UAF we landed in the previous step, shape it into a full Read/Write primitive, and ride it all the way to Medium integrity code execution — completing the Sandbox Escape!
Let's dive in!
https://t.co/rSTHjoWtNN
#Hackyboiz #Wipeload #ChromeFullChain #BrowserExploitation #SandboxEscape #WindowsLPE #CyberSecurity
THREAT INTELLIGENCE ALERT
Forensic analysis of a commercial Malware-as-a-Service (MaaS) full package AURA C2 + AURA CRYPTER FUD v4.0 + BINDER PDF.
Key findings: • Active C2 panel showing 101 clients (24 online), 39.5 GB of exfiltrated data, 102,915 passwords, and stealer_data uploads from multiple countries (Algeria, Vietnam, Singapore, France, Morocco, and others). • Crypter featuring code obfuscation, anti-debug/VM, delay execution, and UPX compression options. • Malicious PDF generator using “professional invoice” and “document requires Adobe Reader update” lures that redirect victims to the payload download. • Advertised pricing: full package for 500 | Binder + FUD for 200.
Indicators of Compromise (IOCs): • C2: 193.181.214.66:5000 (tracked by ViriBack C2 Tracker as the “Aura” family since 06/04/2026) • Payload domain: https://t.co/JMHimUNWZs
Infrastructure is already indexed in public threat trackers. This is an active commercial operation distributing stealer/RAT malware via PDF-based social engineering.
Immediate blocking of the IOCs and monitoring for credential/token exfiltration behavior is recommended.
#CyberSecurity #ThreatIntel #Malware #InfoSec #CyberCrime #MaaS #Phishing #C2 #Stealer #RAT #CyberThreatIntelligence #MalwareAnalysis
Whether you're writing implants, building EDR killers, abusing BYOVD, unhooking kernel callbacks, patching ETW, AMSI bypasses, LOLBins, or doing detection engineering, you need to know how the sensor actually works under the hood.
@0XDbgMan just dropped a full RE teardown of CrowdStrike Falcon's csagent.sys. Save this before it disappears.
If CrowdStrike Falcon is in your environment and you don't know how it works at the kernel level, you're operating blind on both sides of the engagement.
https://t.co/rqhDgni7tP
#Infosec #ReverseEngineering #MalwareAnalysis