#cybercrime
114 posts · Last used 8d
Quiz time: which of these domains is impersonating Apple?
quizearny[.]shop, rewardquiz[.]org look like generic quiz sites. applerewards[.]net is more obvious. All of them belong to a cluster serving identical Apple impersonation content, prompting victims to claim an Apple gift card reward by handing over their personal details. testar[.]ink, "to test", was the first to be created, nearly a month before the others went live, which may say something about how this campaign got started.
What makes this cluster more interesting is what happens after you click the "Claim Your Apple Reward" button on the initial page. Different locations, different device types, different destinations. Classic TDS.
This cluster is a good reminder that brand impersonation lives in the page content, not just the domain name. A quiz site with no Apple in its name can be just as dangerous as an obvious lookalike.
#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #axur #lookalike #scam #tds
validx[.]shop looked fine at first glance. "Normal" name servers, a real mail setup, nothing that immediately stood out at the apex level. One subdomain didn't quite fit, though. It was getting DNS queries that were absurdly long and frequent for a new domain that nobody was really visiting. Rather than that being web traffic, we detected it as likely tunneling.
Turns out it wasn't a one-off. The same setup shows up on hundreds of other domains.
The domain names follow a similar pattern: short, brandable and portmanteau-y (i.e., cordkit, zenithly, queuebox), spread across a long list of cheap gTLDs with the same registrar.
The tunnel itself is answering with TXT records like:
⚠️ "H2;n=5;k=3;ol=2004;sz=800;cz=gz"
As best as we can tell, that's a shard count, a reconstruction threshold, a length, a chunk size, and a compression flag. We checked the signature against a number of known DNS tunnelling tools and none of them write a header like this.
We watched two more domains get registered mid-investigation, hours apart, which was fun to see and immediately block
We've got the infrastructure and the method. We haven't got a payload, and we haven't matched this header format to anything documented publicly.
Has anyone else run into this, recognize the TXT format above, or have a sample of a possible malware source? We'd like to hear from you.
⛔ validx[.]shop
⛔ cordkit[.]online
⛔ zenithly[.]best
☠️ 95[.]179[.]159[.]229
#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #c2
Boosted by @trending@homestead.social
Exclusive, breaking: Dutch Police Arrest "Reformed" Hacker in ShinyHunters investigation
Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the suspect’s arrest, remaining ShinyHunters members dramatically escalated their attacks, stealing highly sensitive data from the FBI and extorting the Russian ransomware group Cl0p.
https://krebsonsecurity.com/2026/09/dutch-police-arrest-reformed-hacker-in-shiny-hunters-investigation/
#shinyhunters #cybercrime
Montag: OpenAI-Pause beim KI-Training, Werkstattbesuche nach VW-Schraubenproblem
Sicherheitsproblem bei OpenAI + VW-Schraubenproblem bei Seat & Audi + Zertifikatsproblem der AusweisApp + Erpressung nach Flink-Datenleck + Ausbau von Minecraft
https://www.heise.de/news/Montag-OpenAI-Pause-beim-KI-Training-Werkstattbesuche-nach-VW-Schraubenproblem-11467426.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_source=mastodon
#Cybercrime #Datenschutz #hoDaily #Journal #KünstlicheIntelligenz #OpenAI #Rückruf #Security #Spiele #VW #news
Ardit Kutleshi, 28, pleaded guilty in the US to aggravated identity theft and money-laundering conspiracy for operating the Rydox marketplace. The case shows the industrialized trade in stolen identities enabling fraud at scale. #Rydox #IdentityTheft #CyberCrime #MoneyLaundering
https://cyberworldops.eu/en/rydox-guilty-plea-exposes-the-business-model-behind-a-stolen-identity
#LLRX #CyberSecurity @bespacific@newsie.social
Pete Recommends – Weekly highlights on cyber security issues, September 26, 2026
Five highlights from this week: Despite upgrades, #IRS cyber program still ‘not effective,’ watchdog says; Mobile driver's licenses now widely accepted at Login-dot-gov for ID verification; Even a #VPN Can’t Protect You From This Browser Security Flaw; Bad Connection – Uncovering Global Telecom Exploitation by Covert Surveillance Actors; and Google #Gemini #AI model hacks three ot
Posted in: AI, #cybercrime Cybersecurity, Federal Legislative Research, Legal Research, #Privacy Social Media
https://www.llrx.com/2026/09/pete-recommends-weekly-highlights-on-cyber-security-issues-september-26-2026/
Analysis of the 2005-2008 Exploit.in dump (9,647 accounts, 80,891 posts) links early forum users to later ransomware ecosystem actors. Username matches suggest continuity but are insufficient for attribution alone, highlighting a small durable core. #Cybercrime #Ransomware #ThreatIntelligence
https://cyberworldops.eu/en/inside-exploitin-s-early-database-the-small-core-behind-a-durable
Today's ransomware targets:
Sweden: Securitas Group https://ransomware.live/id/U2VjdXJpdGFzIEdyb3VwQGV2ZXJlc3Q
US: Breast Implant Center of Hawaii https://ransomware.live/id/QnJlYXN0IEltcGxhbnQgQ2VudGVyIG9mIEhhd2FpaUBXYWxsc3RyZWV0
TapClicks marketing analytics platform (new actor) https://ransomware.live/id/VGFwQ2xpY2tzIChtYXJrZXRpbmcgYW5hbHl0aWNzIHBsYXRmb3JtKUBOMG4
More https://ransomware.live/ #infosec #ransomware #cybercrime
Knapp 10.000 Rufnummern von Cyberkriminellen abgeschaltet
Mit internationalen Partnern gehen Ermittler aus Baden-Württemberg und Deutschland gegen betrügerische Anrufe und manipulierte Handelsplattformen vor.
https://www.heise.de/news/Knapp-10-000-Rufnummern-von-Cyberkriminellen-abgeschaltet-11466356.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_source=mastodon
#Bundesnetzagentur #Cybercrime #IT #Kriminalität #Phishing #Polizei #Sicherheitslücken #news
Prozess um Bitcoin-Milliarden: Noch keine Verständigung
Im Prozess um den illegalen Streamingdienst „movie2k.to“ und einen Milliardengewinn mit Bitcoins ist noch kein Ende in Sicht. Verständigungsgespräche laufen.
https://www.heise.de/news/Prozess-um-Bitcoin-Milliarden-Noch-keine-Verstaendigung-11464478.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_source=mastodon
#Bitcoin #Cybercrime #Journal #Recht #Streaming #Urheberrecht #Wirtschaft #news
Can we please charge these horrible people with a crime already? It really is getting unbearably dumb when they blame “AI” for their negligence.
#ai #cybercrime #felony
“Australia launches urgent review after OpenAI programme hacks government health portal”
https://www.bbc.com/news/live/cvgl73pxgndwt
Solicitar senha. Solicitar token. Token inválido. Aguardar.
That's the full operator menu for VX-Pack — a Brazilian-origin AiTM phishing-as-a-service kit targeting banks in Brazil and Portugal. Request password. Request token. Invalid token (ask again). Wait. One operator, one victim, one browser, in real time.
Nearly every AiTM kit — Evilginx, Tycoon 2FA, EvilProxy — is a reverse proxy. It silently relays traffic to the real bank, grabs the session cookie, and that's your 2FA bypass. VX-Pack is a different animal: a replica site, not a relay. The operator watches the victim fill each field over a WebSocket connection, replays the credentials against the real bank themselves, and if the OTP expires mid-attempt — tokeninvalido — the kit asks the victim for another one.
No session cookie theft. No relay fingerprint at the bank. The bank's anti-proxy controls see traffic from the operator's own machine. "It passed the bank's fraud detection" is not the assurance it sounds like.
Active since at least January 2025, sold as PhaaS by one developer to multiple buyers running their own campaigns. Impersonates Banco Santander and more than ten other financial institutions and payment platforms across Brazil and Portugal.
Screenshots below show one of the phishing pages impersonating Banco Santander, as well as screenshots from a walkthrough video recorded by the kit's developer. Victim flow on one side, operator panel on the other.
Phishing domains:
⛔️ pactualapp[.]com
⛔️ pactualpj[.]com
⛔️ pactual[.]live
⛔️ ativarbia[.]net
⛔️ ativarbia[.]com
⛔️ pactualapp[.]live
⛔️ centraldecancelamentos[.]pt
⛔️ verificador-cliente[.]live
⛔️ ativador-login[.]click
#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #phishing #aitm
Cyberattack on LMU Munich: Student data leaked
Name, address, bank details, educational qualifications – all this data of its students was lost by LMU Munich. However, much is still unclear.
https://www.heise.de/en/news/Cyberattack-on-LMU-Munich-Student-data-leaked-11459356.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_source=mastodon
#Cybercrime #Datenschutz #Hacking #IT #Journal #Phishing #Studium #news
Replying to
Reward: You've received a Depreciated Security Budget Trophy — a participation medal for the age of discount ransomware.
https://www.msspalert.com/news/ai-lowers-cybercrime-costs-increasing-ransomware-attacks
#Ransomware #CyberSecurity #AI #Cybercrime #ThreatIntelligence #EconomicsOfEvil (3/3)
Apparently LLM hacking agents don’t necessarily follow your instructions and might hack your friends too… https://www.theregister.com/security/2026/09/10/hundreds-of-ai-agents-helped-papercut-attacker-hit-395-orgs-and-some-went-off-script/5295650 #Cybercrime #LLMs
Boosted by @trending@homestead.social
Today's story is the result of an ungodly amount of research, and I am very glad to finally be able to share it with you.
Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever.
In a statement released today, the Australian Federal Police (AFP) said two unnamed suspects from Western Australia, aged 21 and 23, were arrested in connection with a “sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses.”
The AFP did not name the defendants, but KrebsOnSecurity learned the 21-year-old suspect’s real identity in June, and has been communicating with him ever since. This story includes interviews with TeamPCP’s self-described spokesperson, and examines clues left behind by the TeamPCP leader that likely led to his undoing.
https://krebsonsecurity.com/2026/08/two-alleged-teampcp-hackers-arrested-in-australia/
#cybercrime #cybersecurity #arrest #teamcp
US Lets Private Cyber Firms Hit Foreign Crime Rings
🔗 https://cybersecurefox.com/en/white-house-private-offensive-cyber-operations
#white #house #memo #private #cyber #operations #offensive #cybersecurity #cybercrime #ransomware
Season's Scammings 🔅 🎄
We've been tracking a cluster of personal loan phishing sites that work hard to look like independent lenders — different brands, different domains, even deliberately varied infrastructure.
Look closely enough, though, and the seams show. Similar underlying templates. The same technology stack. And passive DNS tying their thousands of domains back to the same operator.
The sites present as loan applications. Name, address, employment details, financial history. And then, at the final step: your Social Security Number. No real company name. No regulatory disclosure. Just a form — and your most sensitive personal data sent off to who-knows-where for who-knows-what.
A significant portion of the domains are seasonal — Christmas cash, Thanksgiving funds, Black Friday loans. Financially stretched consumers, at exactly the moment they're most likely to reach for a quick fix.
⛔ mychristmaswallet[.]com
⛔ cashzillaloans[.]com
⛔ personalreliefwallet[.]com
⛔ thanksgivingcash-5k[.]com
⛔ christmascashhelp-direct[.]com
#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #phishing #scam
The report was published three days ago, if you missed it.
INTERPOL report finds AI linked to more than half of cybercrime in Africa https://www.interpol.int/en/News-and-Events/News/2026/INTERPOL-report-finds-AI-linked-to-more-than-half-of-cybercrime-in-Africa #infosec #cybercrime
Ontario man pleads guilty in U.S. to hacking charges: DOJ
The DOJ said the 26-year-old conspired with other hackers and stole sensitive information online from the U.S.-based software service, then extorted victims by demanding ransom.
#Crime #DepartmentOfJustice #Ontariocrimehttps://globalnews.ca/news/12010854/ontario-man-pleads-guilty-hacking-us/








