You’ve probably seen the headline that 16 billion Apple, Facebook, and Google passwords have been leaked, but let’s take a look at the full scope of the situation. 1/9
Looks like the Inferno drainer panel as shown in the screenshot from Commleak group
ace-panel[.top
156[.254.6.7
inferno-panel[.net
leading-xzbc-101[.com
45[.135.232.142
195[.160.222.145
icon_hash="212496978"
Good report: group-ib.com/blog/inferno-d…
As promised today as my brithday gift we are going to (check notes...) access the infrastructure of Quad7 (or 7777) a monitored and really well known botnet which is used for brute forcing microsoft 365 accounts and its members are mostly compromised routers.🧵
hE wAs iN rAnSomWaRe lOl hEs GnnA wOrK aT tHe CiA
Bro, the ransomware dorks fucking buy stolen credentials from Redline logs. Then they log in, make a half assed attempt to get to the domain controller, and push a payload. Even more "sophisticated" groups rely heavily on social