Sabitlenmiş Tweet
cthulu.eth (inactive)
1.2K posts

cthulu.eth (inactive)
@Cthulu_dot_eth
Profile art by @MrBrownNFT • Former @ensdomains core team
Sea Katılım Aralık 2021
412 Takip Edilen704 Takipçiler

Interesting, the timelines fit what I've recovered. My iPhone had spyware installed in mid-to-late -23, and then again in -24 it seems. Initially it was re-activated by sending images (didn't survive reboots)
My mother's iPhone had spyware installed in late 2025.
Both survive updates/reboots now, and lockdown mode has no effect on the latest iOS.
Keyloggers on certain keyboards. Both times our security cameras were targeted, first some average wifi ones, later the DMZ'd LAN-only ones I replaced them with.
Other devices were compromised through physical access. The SD card containing the bootloader to a fairly locked down router I replaced the compromised APs with went missing from the device a couple of days after I installed it (which controlled the new DMZ'd LAN security cams)
What's curious about it is that there's no actual ingenuity, it seems to be entirely MITM/supply chain/physical access using tooling not made by the attacker.
I monitored the attacker briefly and I sincerely doubt they discovered any of the vulnerabilities they're exploiting.
English

@lcfr_eth Yep, I started collecting logs/data dumps/rpms from [most] devices before/after. For the APs I mentioned that they were compromised in conversation, 8 min later they predictably connected in from an AWS US-East tunnel and tried (really badly) to destroy evidence.
And much more.
English

@Cthulu_dot_eth Btw I wasn't suggesting they (ens) were responsible but possibly someone trying to target ens / associates to get the treasury funds etc
Do you have any forensic reports of any devices?
English

@lcfr_eth Right, but MITMing a TLS1.3 connection at ISP-level isn't typical. I'm on Starlink, clean install/no router. Haven't had crypto since -23.
Police suggested it being related to previous employment also. I refused to sign an NDA when I quit which stirred the pot a bit. I'm unsure.
English

everything except the iphone stuff sounds standard for some persistent pwnage.. pwn access points, MITM the repos or install backdoored repos in the yum files which pulls from an attackers infrastructure to push further in.
i dont understand the hidden memory cards etc if this is happening to/around you IRL ... i'd suggest you gtfo of where you are ..
For the iphone stuff you maybe read about the Coruna exploit chains that leaked and have been used to target crypto people? you might fall under that risk threat from your association with ENS or something? (attackers targetting anyone in proximity to the target is common as well)
English

@LinusEkenstam This proves that AI generates next-level acting performances
English
cthulu.eth (inactive) retweetledi

Ethereum Follow Protocol (@efp) is now live on mainnet!
EFP is a decentralized onchain social graph protocol for Ethereum accounts
a new primitive of the Ethereum identity stack, complementing other elements like ENS & SIWE, & can enhance any crypto app
Link to app & more 👇

English
cthulu.eth (inactive) retweetledi

The arrest of Telegram’s CEO, Pavel Durov, marks an enormous escalation by a state’s authorities. We are monitoring the situation closely and will continue to do so. eff.org/deeplinks/2024…
English
cthulu.eth (inactive) retweetledi

Hey folks, give OpenBSD a chance and start using OpenBSD in your critical infrastructures from now on. I'll definitely be turning one of my laptops into an OpenBSD computer. Fuck the xz backdoor.
openbsd.org

English

