TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Dismantling a Crappy Malware Operation

102 pointsby MrBruhabout 2 years ago

9 comments

nightpoolabout 2 years ago
You mentioned they were using Dropbox to distribute the malware—did you follow up with them? What about the university?
jallaspritabout 2 years ago
I am surprised and also not surprised that they had approximately 0 OPSEC related to their hustle.
评论 #35309569 未加载
nubinetworkabout 2 years ago
Nice, but I have to wonder why Github acted on this so fast... I reported one account spreading Python based malware 2 months ago and the account was still there up until last week.
quacksilverabout 2 years ago
Great work! - though the redaction of names / university is very leaky if that is a concern (particularly if you have some knowledge of common Vietnamese naming patterns)
评论 #35313356 未加载
评论 #35316494 未加载
atsushinabout 2 years ago
Really fun analysis, wasn't aware that Python scripts could be packaged into an executable until now, learned something new. Thanks for sharing!
评论 #35309655 未加载
voiper1about 2 years ago
Incredible detective work!<p>Why would discord let anyone delete a webhook?<p>I&#x27;d think anyone can post to the webhook, but you need to be authorized to modify it.
评论 #35312450 未加载
juunppabout 2 years ago
Did they have &quot;malware development and distribution&quot; on their resume?
charcircuitabout 2 years ago
As mentioned in the article anyone can delete a malicious webhook.<p><a href="https:&#x2F;&#x2F;webhooks.scam.gay&#x2F;" rel="nofollow">https:&#x2F;&#x2F;webhooks.scam.gay&#x2F;</a> is a site that makes it easy to do for people who want a tool do it for them.
b1c1jonesabout 2 years ago
Great work!