Gootloader

2.4K posts

Gootloader

Gootloader

@Gootloader

Security researcher dedicated to pissing off the Gootloader Threat Actor.

Everywhere and nowhere Beigetreten Nisan 2023
370 Folgt1.3K Follower
Gootloader retweetet
GhostExodus
GhostExodus@ExodusGhost·
Before I was arrested in 2009, I was at the height of my little cybercriminal "empire". I was standing at a crossroads. Part of me wanted an exit and a chance to redirect my skills toward something constructive. Another part of me feared that if I walked away, all the risks I had taken as a hacker would have meant nothing. 11 years in prison for hacking taught me that the reputation I thought I had built in that world, the ideals I believed in, and the status I thought mattered turned out to be far more futile than I could have imagined at the time. When everything collapsed, I realized that none of that mattered. I learned that most of what passes for loyalty and respect in cybercrime is conditional. Today, there's no reason to turn to cybercrime in order to feel accepted or to enjoy camaraderie and acceptance among peers, or to pursue a sense of justice and vindication. Cybercrime isn't the solution, or the stepping stone. All the hackers in my crew from back in the day have respectable cybersecurity careers today, because sooner or later everyone learns the same lesson. Cybercrime has limits, and it does not put food on the table without tremendous risk. #realtalk #hacking #hacktivism #truecrime
GhostExodus tweet media
English
8
17
136
25.4K
RussianPanda 🐼 🇺🇦
RussianPanda 🐼 🇺🇦@RussianPanda9xx·
I hate my life, I just accidentally reverted my VM without taking a snapshot and lost something important :C
English
20
1
113
5.4K
Gootloader
Gootloader@Gootloader·
@hellodotnyc are yall active on here? Got a bunch of domains to report to yall
English
0
0
0
122
RussianPanda 🐼 🇺🇦
RussianPanda 🐼 🇺🇦@RussianPanda9xx·
4 fillings in one visit at 9 am is not a dental appointment, it’s an ambush… 💀
English
20
0
77
3.2K
Gootloader
Gootloader@Gootloader·
@evernote why do you make it impossible to report malicious posts to yall? It’s giving accomplice vibes
English
0
0
1
115
fab0
fab0@FABO97662188·
#odyssey #macos #amos #malware Some fresh C2 servers used by Odyssey: 38.244.158[.]56 199.217.98[.]33 malext[.]com raytherrien[.]com Depending on the type, the data is sent to one of these servers. The last domain provides the initial payload. The initial vector is ClickFix.
fab0 tweet media
English
4
11
63
7.2K
Gootloader
Gootloader@Gootloader·
Anyone have a good way to monitor new @GoogleAds for a specific domain?
English
2
1
2
511
Moonlock Lab
Moonlock Lab@moonlock_lab·
🧙IOCs: 🔗 claude[.]ai/public/artifacts/434d0114-c787-4af4-bc08-4fb1f9c30d83 🔗 apple-mac-disk-space.medium[.]com 🔗 a2abotnet[.]com 🔗 raxelpak[.]com 🌐 IPs: 172[.]67.187.216, 104[.]21.56.197, 13[.]248.169.48, 76[.]223.54.146 #️⃣ Hashes: 64068d0b7fbef87a7af91834ead9bc0efa21f814b9e6a945b440db75bbcfed76 6292f64c81dbc57d5135c5773547cc6d79afa15efe4c90cfaf27e087c7aba701 c0676ba7726e6b4b836c2a07aacb92e41efd9eea7cbc31bbf1a7f9f9556dd4cb 📎 Staging: /tmp/osalogging.zip (MacSync stealer indicator) 📎 Compromised advertisers: T S Q SA (Colombia), Earth Rangers Foundation (Canada) Stay safe, don't paste random commands into your Terminal 🫡
English
2
2
19
2.3K
Moonlock Lab
Moonlock Lab@moonlock_lab·
🧵 1/ 🚨 What if a Google Sponsored result for a common macOS query led to malware? That's happening right now and 15K+ people have already seen it. We at @MoonlockLab observed 2 variants today abusing legitimate platforms for ClickFix delivery: a @AnthropicAI public artifact on claude.ai and a @Medium article impersonating Apple's "Support Team." Same TA behind both, check for details👇
Moonlock Lab tweet media
English
3
17
53
6.2K
Tanner
Tanner@wbmmfq·
Okay, not Gootloader. Not quite sure what it is tbh.
Tanner@wbmmfq

#Gootloader is trying to sell cars now. I think it's Gootloader, at least. And its website reeks of AI slop.

English
2
0
5
885
Tanner
Tanner@wbmmfq·
#Gootloader is trying to sell cars now. I think it's Gootloader, at least. And its website reeks of AI slop.
English
4
0
14
1.7K
Gootloader
Gootloader@Gootloader·
This was a fun one to dig into Confirmed exploitation requires: • User registration enabled • LA-Studio Element Kit = 1.5.6.3 • At least one published Elementor page PoC confirmed (details withheld). Nice find by Jitlada. Boeing777 & Waris Damkham!
Gootloader tweet media
Wordfence@wordfence

x.com/i/article/2014…

English
1
0
3
500