tobersotski (@tobersotski) 's Twitter Profile
tobersotski

@tobersotski

Malware Analyst and Reverse Engineer

ID: 1933443834551119872

calendar_today13-06-2025 08:39:03

7 Tweet

13 Followers

23 Following

tobersotski (@tobersotski) 's Twitter Profile Photo

LeetStealer #MalwareAnalysis In-depth analysis of Leet Stealer and its RAT module, featuring reverse engineering of the malicious code and live execution of the RAT. The images highlight the core functionalities of both components #LeetStealer #Infosec #ThreatIntelligence

LeetStealer #MalwareAnalysis
In-depth analysis of Leet Stealer and its RAT module, featuring reverse engineering of the malicious code and live execution of the RAT. The images highlight the core functionalities of both components 
#LeetStealer #Infosec #ThreatIntelligence
ShadowOpCode (@shadowopcode) 's Twitter Profile Photo

⚠️ALERT⚠️ there is an OPEN webshell on hxxps://boldcleaningsolutionsatl[.]com/ NEW domains: boldcompanions[.]com boldinnovationspetcare[.]com Cert AgID Gianni Amato JAMESWT vx-underground a lot of malwere inside 😋 cc: tobersotski x.com/AgidCert/statu…

⚠️ALERT⚠️
there is an OPEN webshell on hxxps://boldcleaningsolutionsatl[.]com/
NEW domains:
boldcompanions[.]com
boldinnovationspetcare[.]com
<a href="/AgidCert/">Cert AgID</a> <a href="/guelfoweb/">Gianni Amato</a> <a href="/JAMESWT_WT/">JAMESWT</a> 
<a href="/vxunderground/">vx-underground</a> a lot of malwere inside 😋
cc: <a href="/tobersotski/">tobersotski</a> 
x.com/AgidCert/statu…
ShadowOpCode (@shadowopcode) 's Twitter Profile Photo

🚨NEW python stealer🚨 🛸Drops .pyd in %APPDATA%\Local\Temp\_MEIxxxxx ⚠️Relaunch itself via CreateProcessW Exfil👇 browser cookies and password Discord Steam 📡send data via telegram bot C2: api[.telegram[.org/bot8484778379:AAG_EhhM1Ao139HBPfgfV0zVlMSi-2HfkCM/sendMessage bazaar👇

🚨NEW python stealer🚨
🛸Drops .pyd in %APPDATA%\Local\Temp\_MEIxxxxx
⚠️Relaunch itself via CreateProcessW
Exfil👇
browser cookies and password
Discord
Steam
📡send data via telegram bot
C2: api[.telegram[.org/bot8484778379:AAG_EhhM1Ao139HBPfgfV0zVlMSi-2HfkCM/sendMessage
bazaar👇
tobersotski (@tobersotski) 's Twitter Profile Photo

⚠️Facebook phishing campaign Fake warning about community standards violations, exploiting false account suspension alerts to steal user credentials Domains: checkkaccounttmetta[.short[.gy www[.accccounnts-ke-ta-min-24h-2025[.icu (created on 2025-11-21) Cert AgID JAMESWT

⚠️Facebook phishing campaign
Fake warning about community standards violations, exploiting false account suspension alerts to steal user credentials

Domains:
checkkaccounttmetta[.short[.gy
www[.accccounnts-ke-ta-min-24h-2025[.icu (created on 2025-11-21)

<a href="/AgidCert/">Cert AgID</a> <a href="/JAMESWT_WT/">JAMESWT</a>
ShadowOpCode (@shadowopcode) 's Twitter Profile Photo

🚨ALERT🚨 Malspam campaign against Sistema Sanitario Regionale Liguria Regione Liguria 📤Sender likely spoofed (🇺🇿 based server) 📥Receiver: Institutional PEC mail > rar > jse > powershell with AES encrypted ps1 > aspnet_compiler.exe (BLACKHAWK > Agent Tesla) IoC and sample below👇

🚨ALERT🚨
Malspam campaign against Sistema Sanitario Regionale Liguria <a href="/RegLiguria/">Regione Liguria</a> 
📤Sender likely spoofed (🇺🇿 based server)
📥Receiver: Institutional PEC
mail &gt; rar &gt; jse &gt; powershell with AES encrypted ps1 &gt; aspnet_compiler.exe (BLACKHAWK &gt; Agent Tesla)
IoC and sample below👇