ASTRA RCE Profile picture
Astra - astrarce@proton.me

May 29, 5 tweets

I hacked back this phishing kit and found X accounts with millions of followers I could control.

I received this email yesterday. Obviously a phishing attempt for an X account take over.

Most likely a compromised email or SMTP server.

A quick fuzz of the malicious application endpoint revealed https://xoauth-mgr-2026[.]fly[.]dev/setup.php

As well as a username and password for the dashboard

The threat actor did not follow instructions.

Login panel located at xoauth-mgr-2026.fly.dev/login

Now.. this is the interesting part.

A vibe coded admin dashboard where the threat actor can take action on the accounts which authorized to that malicious X app through the phishing kit.

Clicking into any account gives me the ability to take actions as that user.

Share this Scrolly Tale with your friends.

A Scrolly Tale is a new way to read Twitter threads with a more visually immersive experience.
Discover more beautiful Scrolly Tales like this.

Keep scrolling