@steipete I didn’t know such a feature existed. I learned about the issue through the news and started monitoring the new ecosystem, and I happened to discover it. In my urgency, I sent a message right away. I’m sorry if I bothered you.
@steipete Hi Peter,
We have just identified an account and a skill that appear to be operated by the same threat actor responsible for the recent attack campaign that attempted to trick agents into installing the legacy openclawcli.
https://t.co/WMiuYL4ohl
Every single data breach ever reported or sold was carefully collected by an unknown actor and left in a misconfigured instance. I'd say it is even bigger than @troyhunt's HIBP.
#TA505 yet there is geofenced/ip blacklist
Xls from proxy working
https://t.co/3I9h6rnrqn
-> mgrs-service.]com/rddrd
Xls sample from italian IP disarmed
https://t.co/EqXlJKCmDJ
Trick, discovery with the collaboration of @reecdeep@stoerchl@malwrhunterteam@VK_Intel@guelfoweb