I got the payload to this malware. It is absurdly silly. This malware is killing me bro. It is so unbelievably silly.
This was 100% written using Claude or ChatGPT. I've never seen a malware payload LEAVE NOTES describing what it's doing.
The malware has a Powershell script that connects to the C2 for stinky malware stuff. This module is responsible for persistence. Thankfully their persistence script documented the entire code base and file locations.
Very cool. Thank you spoopy Russian Counter Strike scammers.
Even more silly, the C2 is hardcoded as a string (seen in attached image). The C2 address shows it has been an active malware campaign since at least January 31st, 2026 based off of data present on VirusTotal. It was initially uploaded as "9lixh".
This persistence script was from a victim machine so I've censored some data. Regardless, the botched cyrillic notes also makes me giggle.
Russian to English translations present in this silly script which documents everything for us:
# Пути для удаления
# Paths for deletion
# Завершаем процессы python и pythonw
# Terminate/finish the python and pythonw processes
# Удаляем автозапуск из реестра
# Remove autorun from the registry
# Завершаем процесс монитора
# Stop the monitoring process
# Новая функция для проверки f.json и убийства процессов
# New function for checking f.json and killing processes
# Проверяем флаг library
# Check the library flag
# Список процессов для убийства
# List of processes to kill
# Проверка флага удаления (каждые 20 секунд)
# Check the deletion flag (every 20 seconds)
# 20 секунд при интервале 2 секунды
# 20 seconds with a 2-second interval
# Проверка f.json и убийство процессов (каждые 4 секунды)
# Check f.json and kill processes (every 4 seconds)
@The_GeRM1@DaDandyman "Holocaust denial is when you echo the historical consensus narrative surrounding the Holocaust, which is that camps served different functions during the war."
Everything is genocide but genocide.
Everything is Holocaust Denial but Holocaust Denial.
Why are you so retarded?
@FrostedYukio@HoodiKarmea Oh, another thing:
It is not illegal for you to spread or distribute any piece of functional software, even malware! What's illegal is UNAUTHORIZED ACCESS INTO A COMPUTER SYSTEM.
When you downloaded Vanguard, Agreed to the ToS, and accepted the UAC prompt:
YOU AUTHORIZED IT!
@FrostedYukio@HoodiKarmea this retarded "soft bricked" narrative is like saying HDCP "soft bricks" capture cards. no. no it doesn't do that. and if you think it does, you are a moron.
@0xDarrk@riotgames you cannot hotwire a car by taking a fucking sledgehammer to the ignition. if you get IOMMU blocked and you're retarded enough to keep running your DMA through it whatever instability happens is on you.
@Connor973245@KyouKunDesuwa@crash@riotgames no, you disable IOMMU in your BIOS and uninstall vanguard in the situation that whatever shitty DMA you had kept attacking from more and more vectors on your motherboard that caused your operating system to reject it.
@buckochum@Grimdoomer My friend, the actions are authorized. You downloaded and installed the software which openly and honestly tells you that it protects its memory with your IOMMU. Then you plugged in a device that tries to break that hardware-backed protection and it broke shit. 😂
@NolanPrinter@_indubswetrust_@ThatRetiredDude@ogisadaDMA I DID reply to you. Yes! I own that I replied to you. Meanwhile, your retarded ass blames ME for YOUR choice to go through my profile and painstakingly reply to dozens of tweets. 😂
The difference between me and you is that I don't say "look what you made me do!!!"