23pds (山哥) Profile picture
Sep 11, 2022 10 tweets 10 min read Read on X
🔥最近RedLine黑客更新了产品视频,我们来看下他们的攻击手法、常用工具等:1/🧵
🔥The RedLine hackers have recently updated their product videos, so let's take a look at their attack techniques, common tools and more: 1/🧵
@SlowMist_Team @evilcos @wallet_guard
@SlowMist_Team @evilcos @wallet_guard 2/🧵首先他们是Saas服务,Bot恶意机器人的模式,通过下图这样的方式来传播、钓鱼虚拟货币用户:
Firstly they are Saas services, Bot malicious bots in the mode of spreading, phishing virtual currency users by means such as the following.
@SlowMist_Team @evilcos @wallet_guard 3/🧵 教使用者如何通过社交网络、邮件钓鱼,使用什么在线工具绕过杀毒软件查杀、做SEO、投放诱饵
3/🧵 Teach users how to phish through social networks, emails, and what online tools to use to bypass anti-virus software、Doing SEO, placing bait
@SlowMist_Team @evilcos @wallet_guard 4/🧵攻击者是典型俄语使用者,视频用使用俄语、英语双语,电脑操作系统都是俄语。( 图:发送钓鱼邮件)
The attacker is a typical Russian speaker, the video is bilingual in Russian and English and the computer operating system is all in Russian
@SlowMist_Team @evilcos @wallet_guard 5/🧵各种专业的钓鱼、盗窃工具展示、使用,窃取虚拟货币。
Various professional fishing and theft tools on display and in use,Stealing virtual currency.
@SlowMist_Team @evilcos @wallet_guard 6/🧵专业盗窃木马,用户中招木马,木马就扫描本地电脑钱包、密码、私钥等上传到恶意服务器。
Professional theft Trojan, the user is hit by the Trojan and the Trojan scans the local computer for wallets, passwords, private keys, etc. and uploads them to a malicious server.
@SlowMist_Team @evilcos @wallet_guard 7/🧵演示密码、浏览器、加密货币钱包盗窃方式,可以看到使用的hashcat等专业黑客工具
Demonstration of password, browser, and cryptocurrency wallet theft, with the use of professional hacking tools such as hashcat visible
@SlowMist_Team @evilcos @wallet_guard 8/🧵 恶意软件记录的受害者详细信息。
Details of the victim recorded by the malware
@tayvano_ @NFTherder @keenz_eth @BoxMrChen @Mudit__Gupta Spread the word to prevent more people from being scammed. Thanks~
9/🧵而且远不止,包括最火的NFT,他们都有全套诈骗教程:伪造艺术家信息-伪造推特账号-发布作品-诈骗完成。And far more, including the hottest NFT, who have a full tutorial on scams: fake artist info - fake Twitter account - post work - scam complete.

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with 23pds (山哥)

23pds (山哥) Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @im23pds

Feb 21
🧐Lazarus Hacker, i know you can see my X posting, I've caught you on the trail and we'll be posting a related tracking article disclosing the details of this attack. @SlowMist_Team @evilcos Image
the Lazarus hackers first found the targeted employees through social engineering, added private GitHub repository access to the victims or victimized employees through live chat tools, and tricked the users into running the code that contained the backdoor.
in order to achieve their goal of tricking their victims into running, Lazarus hackers make hundreds or even thousands of dollars in direct payments to their victims in advance...
Just to gain the victim's trust.
Read 5 tweets
May 22, 2023
注意:开源密码管理器KeePass最近修复一个允许检索主密码的漏洞,该漏洞可被利用来从软件内存中检索出明文主密码,目前PoC 已公开,目前暂无补丁。
加密货币圈有不少用户使用此软件,注意资金风险。
@wublockchain12 @Foresight_News
blog.quarkslab.com/post-exploitat…
Read 4 tweets
May 18, 2023
刚才 @michaelwong123 刚好说了一种,那么顺着他的话,在发一个预警:硬件钱包一定要从 官方渠道!官方渠道!官方渠道 (重要的事情说三遍) 购买,切不可贪图便宜从第三方商店购买⚠️
此处提醒的重点不在硬件,不是前两天改装Ledger那种改装、供应链的问题! 而是另有套路! 大家注意!
@SlowMist_Team
总之一句话,硬件钱包一定要从 官方渠道!官方渠道!官方渠道 (重要的事情说三遍) 购买!👈
Update:今天imkey 官方发文,所以可以公布骗局了,我总结下:诈骗分子购买真的硬件钱包,然后自己做使用说明书!而说明书里面涉及的信息,如:App下载地址、Pin码设置等都是假的!从而盗取用户资金。
@wublockchain12 @evilcos @Foresight_News checking 👆
Read 4 tweets
Jan 24, 2023
1/ Today the FBI identified the North Korean hacker group Lazarus Group and APT38 as the Horizon Bridge attackers, with the hacker group using malware called 'TraderTraitor' to carry out the attack.
1/and laundered over $60 million in stolen Ether through a privacy protocol called Railgun. What are "TraderTraitor" and Railgun? @evilcos
2/ 'TraderTraitor' is Lazarus' malware that targets the cryptocurrency industry and blockchain technology primarily by luring employees of cryptocurrency-related platforms to download it.
Read 17 tweets
Jan 24, 2023
1/今天FBI确认朝鲜黑客组织 Lazarus Group 和 APT38 是 Horizo​​n Bridge 攻击者,黑客组织使用名为「TraderTraitor」的恶意软件进行攻击,并通过名为 Railgun 的隐私协议对被盗的超 6000 万美元的以太坊进行洗钱。「TraderTraitor」、Railgun 都是什么?@evilcos
2/「TraderTraitor」是Lazarus主要针对加密货币行业和区块链技术进行攻击的恶意软件,主要是诱导加密货币相关的平台员工下载,向加密货币组织中从事 IT 运营、软件创建和系统管理工作的人员发送消息,以提供高薪工作在各种媒体社交平台使用社会工程学投放,支持 macOS 和 Windows 操作系统。
3/员工上钩后,「TraderTraitor」会伪装成各种加密货币平台的软件,让员工下载,如这个平台:
Read 10 tweets
Jan 19, 2023
1/Redline从你电脑盗走你的MetaMask相关文件后,干什么? What does Redline do after stealing your MetaMask-related files from your computer? @MetaMask @MetaMaskSupport @Jon_HQ @tayvano_ @NFT_GOD
2/攻击者会安装一个全新的metamask扩展,然后用你的文件覆盖它本地的文件。The attacker will install a brand new metamask extension and then overwrite its local files with your files ImageImage
3/然后攻击者使用获取到的受害者各种密码去尝试受害者的metamask密码。The attacker then uses the various passwords obtained locally to try the victim's metamask password ImageImage
Read 9 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us!

:(