ASTRA RCE Profile picture
Astra - astrarce@proton.me
May 29 5 tweets 2 min read
I hacked back this phishing kit and found X accounts with millions of followers I could control.

I received this email yesterday. Obviously a phishing attempt for an X account take over.

Most likely a compromised email or SMTP server. Image
Image
A quick fuzz of the malicious application endpoint revealed https://xoauth-mgr-2026[.]fly[.]dev/setup.php

As well as a username and password for the dashboard

The threat actor did not follow instructions. Image