Sabitlenmiş Tweet
Merl
5.1K posts

Merl
@Merlax_
🛡️ Cybersecurity | 🔍 Threat Intel | 🏹 Offensive Hunter | ⚔️ Red Team Padre de Familia 👨👩👧 Dobby es un elfo libre 🆓
Katılım Mayıs 2010
690 Takip Edilen3.3K Takipçiler
Merl retweetledi
Merl retweetledi

Merl retweetledi
Merl retweetledi
Merl retweetledi
Merl retweetledi

We tracked a new activity cluster targeting Mexican banking customers.
Elastic Security Labs discovered REF6045, an operator-assisted banking fraud campaign targeting customers of Mexican banks, fintechs, and cryptocurrency platforms through ClickFix fake-CAPTCHA lures.
The operation exhibits a reliance on AI-generated code and suffers from significant operational security (OPSEC) failures that exposed their infrastructure and their toolkit.
The toolkit gives operators a full fraud workflow from:
•Vishing overlay: lock the screen behind a fake bank warning
•Browser redirect: paste a phishing URL via automated keystrokes
•Clipboard swap: replace CLABE or card numbers mid-transfer
•Remote access: install Remote Utilities for hands-on takeover
Research by @k33b0i and @soolidsnakee.
Full analysis from Elastic Security Labs: go.es.io/4eP6VZF

English
Merl retweetledi

Yeah exactly, I truly believe as well that it is far to unlikely that it has been automated from X side, while I do believe that they accept any incoming "Illegal Activity" report as being truthful (considering the line of work we are doing), I don't believe that they went out their way to fully automate and scan every single tweet for the past few years that i have made and started to report my account and lock it. As a lot of those tweets are from 2022 until 2024. I believe it is rather a bad actor abusing the report system from X to take down competitor accounts or individuals they dont want to have a reach on this platform. These reports originated from last week and whereas I have received a full on suspension today in the morning. And in the email it specifically highlights the fact it was reported by a user and not automated system as it says "due to a user report".


vx-underground@vxunderground
Chat, X is lowkey kind of innocent, but something odd is happening. Spider was banned, yes. However, prior to his ban he was reported 22 times in one day. Someone is mass reporting security researchers trying to get them banned.
English
Merl retweetledi

#phishing 🇧🇷 [Terremoto na Venezuela: as crianças precisam da sua ajuda | UNICEF Brazil]
hxxp://37.148.135.113/
http://37.148.135.113/expand-donation-form.js
http://37.148.135.113/qrcode-local.js


Português
Merl retweetledi
Merl retweetledi

Recent research reveals that #ScatteredSpider is not a singular organized group but a decentralized #cybercrime collective comprised of multiple, independent subclusters. This loose affiliation of operators, connected primarily through shared TTPs and social engineering techniques, poses a unique challenge for attribution. Our latest analysis explains how this structure, akin to a hacking movement, provides inherent resilience against #lawenforcement actions. It's not a single group to track, but a persistent culture of cybercrime that evolves continuously.



English
Merl retweetledi

ok gang this is getting nearer to being able to publish I think....
What have I made with an LLM?
I've made an edge appliance which can be used to teach people how to:
> understand secure edge architecture
> how to see common misconfigurations
> how to understand about firewall fules
> how to abuse legitimate features (e.g. packet capture)
> and I've put in a bunch of simulated vulnerabilities based on real world CVEs

English

Acá me comí una suspensión por mostrar que un C2 tenía una sección para diseñar overlays, es como si fuera ilegal sacarle una captura al mspaint.exe

vx-underground@vxunderground
> be malware researcher > discuss botnet > share malware IoCs (Indicator of Compromise) > mysteriously mass reported > BANNED FOR VIOLATING THE RULES > ???
Español
Merl retweetledi
Merl retweetledi

On June 9, the FBI kicked off Operation Riptide, our ongoing, coordinated campaign targeting the criminal actors, infrastructure, and financial networks behind cybercrime, cyber-enabled crime, and fraud against the American people. During the last two weeks, the FBI, working alongside domestic and international partners, executed multiple disruptive actions in support of Operation Riptide.
➡️@FBICleveland, in coordination with private sector partners, conducted a technical takedown operation against Outsider, a Chinese phishing-as-a-service platform.
➡️As the result of an investigation by @FBI_Nashville, @FBISanDiego, and @FBIElPaso, a Conti ransomware actor pleaded guilty to wire fraud conspiracy in connection with a scheme that infected more than 1,000 computers and networks worldwide.
➡️@FBIBoston announced their support of the international takedown of the First VPN service, used to compromise businesses in the U.S. and around the world.
➡️We joined international law enforcement partners in announcing the disruption of SocGholish malware.
This is only the beginning—we will continue identifying, disrupting, and dismantling the networks that support cybercrime and victimize Americans.

English
Merl retweetledi

New #OperationEndgame actions revealed.
This time targeting: #StealC
The blip video is hardcore.
1. #StealC Admin stole data from his affiliates/users
2. #StealC was so vulnerable, even Law Enforcement is laughing about them, directly mentioning the exploits being leveraged to steal their stuff.
3. Also a lot of affiliates seem to be named on the number plates of the vehicles, showing #OpEndgame knows exactly who they are up against.
4. Seems Law Enforcement themselves realized that they are only a "Bonus Stage" to ending an already completely broken product XD
I guess we can call this blip
#EndgameLevelTrolling ^^
More links on this in the first comment below.
English
Merl retweetledi
Merl retweetledi

New season of #OperationEndgame just dropped.
This time, they targeted #SocGholish.
106 servers and domains taken down, 14.971 websites remediated.
Of course, they released a movie like video for it again.
Link to press release in the comments :)
#OpEndgame #SocGholish
English




























