allie

997 posts

allie banner
allie

allie

@kittenlyy

the lion & the lamb ✺ cybercriminal, b.s. compsci, offsec engineer ✺ xotwod ✺ Free Palestine 🇵🇸

🇺🇸🇩🇰🇸🇪 24 Katılım Temmuz 2018
318 Takip Edilen282 Takipçiler
allie retweetledi
S.🎧
S.🎧@1ssve·
It's bare minimum friday, don’t you let that job stress you out today
English
168
10.3K
65.5K
1.6M
allie retweetledi
ирис
ирис@saltwatermp3·
My problem is that I lowkey do not belong in this realm
English
85
7.7K
25.9K
426.7K
allie retweetledi
NewsWire
NewsWire@NewsWire_US·
NSA USING ANTHROPIC'S MYTHOS DESPITE BLACKLIST - AXIOS
English
42
104
2.1K
112.8K
allie retweetledi
✧
@northstardoll·
✧ tweet media
ZXX
1
639
2.7K
46.4K
allie
allie@kittenlyy·
the laugh I let out when “only checked for virtualbox” VMware truthers win once again
vx-underground@vxunderground

Yeah, so pretty much this cpuid.com malware is a pain in the ass. I'd have to spend a good bit of time trying to bonk it with a stick and reconstruct some of it. Whoever developed this malware actually cares about evasion and made some intelligent decisions when developing this malware payload. This appears to only impact HWMonitor 64bit. It appears (based on user reports) cpuid became malicious around 7PM EST, April 10th, 2026. However, it is possible it was much earlier than this, this is just when people began noticing and discussing it online. From an extremely high-level overview, it appears the ultimate goal of this malware is data theft, specifically browser credentials. However, I could be wrong in that assessment, but I'm fairly confident in it. I'm guessing this is the end goal because when I emulated it I can see it messing with Google Chrome's IElevation COM interface (trying to dump and decrypt saved passwords). However, between this it does a bunch of other stuff too. 1. They (an unknown Threat Actor) compromised cpuid.com to deliver malware from HWMonitor. It impacts the actual installer as well as the portable installer. It downloads stuff from supp0v3-dot-com, the same domain used from a previous malware campaign targeting FileZilla in the beginning of March, 2026 initially reported by MalwareBytes. 2. HWMonitor comes packaged with a malicious CRYPTBASE.dll. CRYPTBASE.dll is a legitimate Windows library, but they made a fake one to blend in (malware masquerading). This DLL is responsible for connecting to their C2 and downloading the other malware stages. 3. It tries to detect emulation and prevent reverse engineering by checking for the presence of specific registry keys on the machine. However, they failed doing this and didn't account for everything. Notably, they only check for VirtualBox (whomp, whomp). 4. It downloads a .cs file from a remote C2 and then compiles it manually on the machine by invoking .NET stuff. This is an interesting strategy. It does all of this via Powershell (LOLBIN nonsense). 5. The .cs file it compiles is a .NET binary with NTDLL exports. The main HWMonitor binary performs process injection using this compiled .NET binary. This is an interesting strategy. 6. Almost everything it does is performed in-memory. I would have to do through this and manually bonk all of this stuff with a stick and determine precisely how it operates. However, I don't think that is necessary because at this point we know this is malware and we know it's trying to steal browser credentials. +2 points for IElevation COM Interface credential dumping +1 point for inline Powershell CLI DLL compilation +1 point for .NET assembly NTDLL export proxying -1 point for botched anti-emulation +2 points for website compromise and supply chain attack +1 point for memory persistence -3 points for recycling the same C2 from March, 2026 campaign Overall I give this malware a B-. This is pretty good malware.

English
0
0
0
90
allie
allie@kittenlyy·
supply chain attack friday
English
0
0
1
31
allie retweetledi
Secular Talk (KyleKulinskiShow@bsky.social)
Has it occurred to anybody beyond leftists yet that this is flat out nazi shit, that the US & Israel are the new nazis and that’s more or less how history will record this moment? It has to have at this point right?
English
438
2.2K
20.3K
400.8K
allie retweetledi
Justin🦩Boldaji
Justin🦩Boldaji@justinboldaji·
Telling everyone how impressive my first gay bareback orgy was
English
1.7K
28.8K
277.6K
47.2M
allie
allie@kittenlyy·
on stream too 💀
English
0
0
1
80
allie
allie@kittenlyy·
#remembering the time my friends and I queued into shirolul in valorant and spent the entire game taunting in match chat abt being a pedo while hard targeting her and spraying n bagging her body 🥸
English
1
0
3
147
allie retweetledi
Mike Drucker
Mike Drucker@MikeDrucker·
You can really tell America is winning this war when the president panic posts “open the fuckin’ strait, you crazy bastards” at 5 am on Easter Sunday along with an extension on their deadline
English
82
7K
84.8K
939.5K
allie
allie@kittenlyy·
i love being vindicated
English
0
0
1
58
allie retweetledi
cuckold jones
cuckold jones@cuckcat·
it would be a good friday if i got a lobotomy
English
12
1.2K
3.9K
87K
allie
allie@kittenlyy·
INZOROCKS TONIGHT
English
0
0
1
75
allie retweetledi
dustin Couch
dustin Couch@Dustinkcouch·
nasa employee: oh hey u guys are back early astronaut: moon's haunted nasa employee: what? astronaut: *loading a pistol and getting back on the rocket-ship* moon's haunted
English
772
97.6K
350.4K
0