23pds Profile picture
Sep 11 10 tweets 10 min read
🔥最近RedLine黑客更新了产品视频,我们来看下他们的攻击手法、常用工具等:1/🧵
🔥The RedLine hackers have recently updated their product videos, so let's take a look at their attack techniques, common tools and more: 1/🧵
@SlowMist_Team @evilcos @wallet_guard
@SlowMist_Team @evilcos @wallet_guard 2/🧵首先他们是Saas服务,Bot恶意机器人的模式,通过下图这样的方式来传播、钓鱼虚拟货币用户:
Firstly they are Saas services, Bot malicious bots in the mode of spreading, phishing virtual currency users by means such as the following.
@SlowMist_Team @evilcos @wallet_guard 3/🧵 教使用者如何通过社交网络、邮件钓鱼,使用什么在线工具绕过杀毒软件查杀、做SEO、投放诱饵
3/🧵 Teach users how to phish through social networks, emails, and what online tools to use to bypass anti-virus software、Doing SEO, placing bait
@SlowMist_Team @evilcos @wallet_guard 4/🧵攻击者是典型俄语使用者,视频用使用俄语、英语双语,电脑操作系统都是俄语。( 图:发送钓鱼邮件)
The attacker is a typical Russian speaker, the video is bilingual in Russian and English and the computer operating system is all in Russian
@SlowMist_Team @evilcos @wallet_guard 5/🧵各种专业的钓鱼、盗窃工具展示、使用,窃取虚拟货币。
Various professional fishing and theft tools on display and in use,Stealing virtual currency.
@SlowMist_Team @evilcos @wallet_guard 6/🧵专业盗窃木马,用户中招木马,木马就扫描本地电脑钱包、密码、私钥等上传到恶意服务器。
Professional theft Trojan, the user is hit by the Trojan and the Trojan scans the local computer for wallets, passwords, private keys, etc. and uploads them to a malicious server.
@SlowMist_Team @evilcos @wallet_guard 7/🧵演示密码、浏览器、加密货币钱包盗窃方式,可以看到使用的hashcat等专业黑客工具
Demonstration of password, browser, and cryptocurrency wallet theft, with the use of professional hacking tools such as hashcat visible
@SlowMist_Team @evilcos @wallet_guard 8/🧵 恶意软件记录的受害者详细信息。
Details of the victim recorded by the malware
@tayvano_ @NFTherder @keenz_eth @BoxMrChen @Mudit__Gupta Spread the word to prevent more people from being scammed. Thanks~
9/🧵而且远不止,包括最火的NFT,他们都有全套诈骗教程:伪造艺术家信息-伪造推特账号-发布作品-诈骗完成。And far more, including the hottest NFT, who have a full tutorial on scams: fake artist info - fake Twitter account - post work - scam complete.

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with 23pds

23pds Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @IM_23pds

Sep 10
前两天我们团队 @SlowMist_Team 刚刚曝光Redline Stealer 木马会扫描你的电脑私钥等文件,盗取数字货币的分析,今天发现它的升级版 META Stealer /BlackGuard 木马也来了,攻击手法类似,小伙伴们小心了 ⚠️
就像 @evilcos 调侃的:目前为止,Web2 到 Web3 最成功的转型是黑客。🤣
Read 4 tweets
Sep 8
众多的丢币事件让很多人误以为硬件钱包用上了就不会丢币?这是一个误区,别迷信,丢不丢币跟你用啥关系不大。核心是人的安全意识,我们遇到很多丢币事件,用硬件钱包的事件往往丢币金额更大 🐶 尴尬不?
在区块链黑暗世界,时刻保持警惕,切勿贪婪捡便宜,个人安全意识永远是安全的第一道防线。
欢迎留言探讨,有疑问我会第一时间答复。
硬件钱包理论上可以提高攻击的门槛,但是不等于用了就不会丢币,这是两码事,搞清楚。
Read 7 tweets
Sep 4
昨天团队帮助@BoxMrChen 追踪分析了下,目前看找回可能比较难。 刚好顺着@keenz_eth 的话我写几点常见的建议:
1.如果你在币圈玩,首先建议基础硬件上,推荐iphone,不推荐安卓手机,苹果手机的权限控制更严格;如果你是电脑用的多,推荐Mac,不推荐windows电脑,因为针对windows的各种木马病毒已经太成熟了。
2.使用PC,注意安装杀毒软件,不论是Mac还是Windows,都要安装。推荐卡巴斯基或AVG,最菜你也得装个火绒或360吧…
Read 12 tweets
Sep 2
Through analysis, I think the kyberswap may not be the attack caused by GMT. Google GMT is a service provided by Google, which is relatively safe, so it is more likely that someone has changed the front-end code of kyberswap or kyberswap has been hijacked.@Foresight_News @evilcos
@Foresight_News @evilcos @sniko_
The way to use GMT code is very simple. It just assigns an ID to the user, and the user embeds it in his own front-end code for statistics. Image
@Foresight_News @evilcos @sniko_ Now the kyberswap GMT code seems to be still there, so could the problem with this attack be GMT? Image
Read 5 tweets
Aug 11
👀Everyone is talking about web3.0, but all ignore the fragility of web3.0:
‼️Let me briefly list the common attack risk points, please read the following list carefully, it is very important: @SlowMist_Team @0xfoobar @officer_cia @sniko_ @Mudit__Gupta
@SlowMist_Team @0xfoobar @officer_cia @sniko_ @Mudit__Gupta 1/web3 still needs a domain name, which is the entrance to the Internet. And the domain name needs to be registered with the domain name service provider, there is a risk here: the domain name service provider may be attacked by social engineering
@SlowMist_Team @0xfoobar @officer_cia @sniko_ @Mudit__Gupta 1.1/such as the @GoDaddy hacking of employees before, resulting in a large number of web3 attacks, and the hacking @CurveFinance in the past two days, all of which are services business was invaded.
Read 14 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us on Twitter!

:(