OogWay (@way_oog) 's Twitter Profile
OogWay

@way_oog

Threat Intelligence + OSINT + Anti Cybercrime from 🇻🇳

ID: 1229593474179031040

calendar_today18-02-2020 02:28:58

166 Tweet

12 Followers

685 Following

WatchingRac (@racwatchin8872) 's Twitter Profile Photo

#Github #Malware #Lumma 💣Campaign Using SolaraExecutor-V3 to infect victims with Lumma Stealer: Github -> Exe with Powershell Code -> Pastebin -> Github -> Lumma Stealer pastebin.com/1KvNgjk3

#Github #Malware #Lumma
💣Campaign Using SolaraExecutor-V3 to infect victims with Lumma Stealer:

Github -> Exe with Powershell Code -> Pastebin -> Github -> Lumma Stealer

pastebin.com/1KvNgjk3
Cyber_OSINT (@cyber_o51nt) 's Twitter Profile Photo

Sygnia reports on Weaver Ant, a China-nexus threat actor infiltrating a telecom provider using web shells for cyber espionage, detailing their tactics and offering defense strategies against state-sponsored threats. #CyberSecurity #ThreatIntelligence ift.tt/wAbt7IE

The Hacker News (@thehackersnews) 's Twitter Profile Photo

🚨 A Russian group, Water Gamayun, is abusing a Windows zero-day (CVE-2025-26633) to drop two chilling backdoors: SilentPrism & DarkWisp. They’re hiding in plain sight—using signed .msi files posing as legit apps like DingTalk & VooV to hijack systems. 👀 Targets? Your data,

🚨 A Russian group, Water Gamayun, is abusing a Windows zero-day (CVE-2025-26633) to drop two chilling backdoors: SilentPrism & DarkWisp.

They’re hiding in plain sight—using signed .msi files posing as legit apps like DingTalk & VooV to hijack systems.

👀 Targets? Your data,
FalconFeeds.io (@falconfeedsio) 's Twitter Profile Photo

🚨 DDoS Alert 🚨 Army Special Forces Electric claims to have taken down the website of National Bank of Cambodia (NBC) (nbc.gov.kh) 🇰🇭 NB: The site is up and active.

🚨 DDoS Alert 🚨

Army Special Forces Electric claims to have taken down the website of National Bank of Cambodia (NBC) (nbc.gov.kh) 🇰🇭

NB: The site is up and active.
Yogesh Londhe (@suyog41) 's Twitter Profile Photo

Braodo Stealer Table_chairs_apartment_size_images_2b0819.rar 0d0c1b11f85e0655d320422ee0cf84bf Table_chairs_apartment_size_images_2b0819.bat 33bd8b7c295cd66e8d7e1f377821f3c1 download payload & python library from github[.]com/bvit17 #Braodo #Stealer #IOC

Braodo Stealer

Table_chairs_apartment_size_images_2b0819.rar
0d0c1b11f85e0655d320422ee0cf84bf

Table_chairs_apartment_size_images_2b0819.bat
33bd8b7c295cd66e8d7e1f377821f3c1

download payload & python library from
github[.]com/bvit17

#Braodo #Stealer #IOC
780th Military Intelligence Brigade (Cyber) (@780thc) 's Twitter Profile Photo

OpenAI has revealed that it banned a set of ChatGPT accounts that were likely operated by Russian-speaking threat actors and two Chinese nation-state hacking groups | thehackernews.com/2025/06/openai… The Hacker News

Mikhail Kasimov (@500mk500) 's Twitter Profile Photo

#Clickfix aborsimanjur\.com accarda\.com ahbwh1325asdw\.shop aslidomino\.info aslidomino\.online aslidomino\.org aslidomino\.pro aslidomino\.site banlieuefashion\.com bekingslot\.org berkahpoker\.co berkahpoker\.org betingslot-2024\.com betingslot-amp\.cfd [1/2]

lc4m (@luc4m) 's Twitter Profile Photo

#malspam delivers #remcos rat to 🇮🇹 vt:c50b5e77227fea5243ae85d37e8a308d mb:4864a55cff27f686023456a22371e790 vt:91e8261fc4590d9705e64caf444dccbf There also is an obf file inside the python runtime with a weird "TUOI_LON_DECODE" (a troll from TA?) JAMESWT

#malspam delivers #remcos rat to 🇮🇹 

vt:c50b5e77227fea5243ae85d37e8a308d
mb:4864a55cff27f686023456a22371e790
vt:91e8261fc4590d9705e64caf444dccbf

There also is an obf file inside the python runtime with a weird "TUOI_LON_DECODE" (a troll from  TA?)

<a href="/JAMESWT_WT/">JAMESWT</a>
ANY.RUN (@anyrun_app) 's Twitter Profile Photo

👾 Top threats in June 2025. #BRAODO Stealer abusing GitHub, obfuscated scripts dropping #Remcos, and BAT files delivering #NetSupportRAT. See detailed breakdown of these attacks and gather threat intel for proactive defense ⬇️ any.run/cybersecurity-…

Cyber_OSINT (@cyber_o51nt) 's Twitter Profile Photo

Unit 42 reports that ClickFix campaigns are increasing, highlighting three that have spread NetSupport RAT, Latrodectus, and Lumma Stealer malware. #CyberSecurity #Malware ift.tt/WNPYCSt