MaksRAT

20 posts

MaksRAT

MaksRAT

@MaksRAT_Off

https://t.co/FvqDXb7Pge

Katılım Temmuz 2025
2 Takip Edilen33 Takipçiler
MaksRAT
MaksRAT@MaksRAT_Off·
Soon there will finally be something big. And now GPT has shown that there are already many articles about me, which makes me happy.
MaksRAT tweet media
English
2
0
0
85
vx-underground
vx-underground@vxunderground·
Saw some report on a information stealer named MaksStealer, or MaksRat, or something. Written in Java, multi-staged, delivered from some Minecraft place. The dude makes it pretty clear he's just a kid, probably around 17 years old. He seems pretty happy Threat Intelligence and Malware Analysts have looked at his work. Proud of you, kid. You shouldn't facilitate crime and steal peoples identities and/or credentials, or operate a Malware-as-a-Service campaign, but the code looks pretty solid. You get a cat for being a clever kid.
vx-underground tweet media
English
15
17
425
25.9K
JaromirHorejsi
JaromirHorejsi@JaromirHorejsi·
@Oliver7203 @malwrhunterteam the hash mentioned in this thread is a downloader, which downloads several components, and some of them belong to a stealer. It also steals minecraft credentials. The autor is probably max/maks/maxim. Also domain hosting the stealer begins with maks....
English
1
0
2
487
MalwareHunterTeam
MalwareHunterTeam@malwrhunterteam·
"RAT_Builder.jar": ec4e915484b22a46b5581ef39695832191c557bf4d9bd8238da468ad9e8a75ae 😂
MalwareHunterTeam tweet media
English
1
4
28
5.2K
MaksRAT
MaksRAT@MaksRAT_Off·
Hello to all newcomers! xD
English
0
0
5
372
MaksRAT
MaksRAT@MaksRAT_Off·
@ShadowOpCode @finsub26373 As for the analysis of this "ecosystem", just go to the server that gave it to you and ask them.
English
0
0
0
62
ShadowOpCode
ShadowOpCode@ShadowOpCode·
@finsub26373 Appreciate you sharing this! Great to identify the obfuscator – every piece helps when dissecting these Java stealers and mapping their ecosystem.
English
2
0
0
105
MaksRAT
MaksRAT@MaksRAT_Off·
@ShadowOpCode http://146.103.40.110:6969 Thank you for reminding me of my childhood. I loved analyzing code like this. I also use skidfuscator, but here it's used Bozar.
MaksRAT tweet mediaMaksRAT tweet mediaMaksRAT tweet media
English
0
0
1
92
MaksRAT
MaksRAT@MaksRAT_Off·
@ShadowOpCode @vmray or wait you say about change code in rat? I was getting an error in newer versions of minecraft, so I had to change.
English
0
0
0
79
ShadowOpCode
ShadowOpCode@ShadowOpCode·
@MaksRAT_Off @vmray The fact that you're changing things after my report says it all. Next time, try harder. I’ll still find you.
English
2
0
2
125
VMRay
VMRay@vmray·
🚨 Alert: Emergent Java stealer flying under the radar of most AVs 🔍MaksStealer masquerades as a Minecraft mod to steal browser credentials, Discord tokens and crypto wallets. The obfuscated code shows that the stealer downloads additional Java payloads from the C2. In a nutshell: 📉 Only 3/65 AV detections on VT after a month since the initial upload 🗝️  Steals Discord tokens, crypto wallets, and credentials of Chrome, Opera GX, Edge, Brave, Vivaldi, Yandex 🔐 Config strings are encrypted with DES, Blowfish or XOR 📦 Downloads additional Java payload from C2 🕵️ MaksStealer is also known as MavenRAT or MaksRAT Check out VMRay's Dynamic Analysis report to get insights on behavior and detections others have missed: lnkd.in/db3iduFT Sample SHA256: 35f4a76fa14442f679e6f6d3908e5572d24025e9809abecc532350f542b52bfa
VMRay tweet mediaVMRay tweet mediaVMRay tweet mediaVMRay tweet media
English
4
16
21
3.7K
MaksRAT
MaksRAT@MaksRAT_Off·
@ShadowOpCode @vmray Calm down, I'm not hiding or fiddling with anything. I'm just glad to be noticed I'm happy to talk to you and point out the whole mountain of RATs that exist on Hypixel.
English
1
0
0
138