
Calwarez
144 posts

Calwarez
@calwarez
Director for Malicious Infrastructure Discovery @ Recorded Future | Views my own



NEW: Block one ASN, disrupt sixteen malware families. OMEGATECH (AS202412) — a three-month-old bulletproof hosting network with 18 /24 prefixes (4,608 IPs). One subnet alone hosts 67 C2 servers: Remcos (6,562 sightings), AsyncRAT (4,379), Amadey, Latrodectus, XWorm, Stealc, DCRat, LOBSHOT, Eye Pyramid, Mirai, Bashlite, Quasar, ClearFake, SectopRAT, SuperShell, SheetRAT. Seychelles .sc abuse contact. Pfcloud UG transit. Zero legitimate traffic. We recovered an Amadey credential stealer plugin (cred64.dll) targeting Chrome, Firefox, Outlook, Thunderbird, FileZilla, WinSCP, and Monero wallets. 3 YARA + 10 Suricata on GitHub. Full writeup: intel.breakglass.tech/post/omegatech… h/t @Fact_Finder03





Void Stealer Tor C2 panel http[://ddccvyclo5p7qdwkvgithmfd2wensrnuvz6hfpjqupgsyzalvq6h4xid.onion/fakjak3ak/aghgfaasfaa/login I have a mid confidence that below IOCs belongs to Void Stealer. intercttp[.xyz jjjgaasda[.live 151[.243.113.71:8080 83[.217.209.227:8080 185[.107.74.138:8080 193[.233.112.254:8080 @500mk500 !!















1/ New report from myself and @_whoisnt : “Malicious Infrastructure Finds Stability with aurologic GmbH.” We uncover how German ISP aurologic GmbH has become a central nexus for high-risk hosting networks, sustaining large concentrations of malicious infrastructure.
