Filter
Exclude
Time range
-
Near
M†rrie retweeted
1
1
2
36
Nipplelove63 retweeted
Italian Workerman
3
17
239
21,969
SkyFall-Pack v2.1 is out. •Automated Cobalt Strike updates •Cleaner Workerman config •License support in Ansible for CS install •Optimized OST-C2 VM provisioning •Automated malleable profiles (custom HTTP headers) •Fixed all deprecation warnings github.com/nickvourd/SkyFall… #c2 #automation #ansible #terraform Feedback welcome.
3
22
1,227
🚨 Live Hook Android banking trojan C2 panel found with unauthenticated endpoints, an open Socket.IO event bus, and MySQL 8.0.31 exposed directly to the internet. 🔬 Full report: intel.breakglass.tech/post/d… A ThreatFox-sourced IOC led us to a fully mapped Hook/ERMAC C2 panel at 31[.]57[.]216[.]126. We enumerated 24 live API endpoints across a Laravel/PHP backend, extracted the complete 35-command bot vocabulary from a 3.6MB React SPA bundle, and identified two endpoints with no authentication middleware. The Socket.IO server on port 3434 accepted unauthenticated subscriptions to bot events, logs, and operator activity streams. 🔎 In a nutshell: • Split architecture: nginx SPA (port 80), Laravel API (8089), Workerman WebSocket VNC relay (8000), Socket.IO event bus (3434), MySQL (3306) • /api/v1/smartInjections/getSessions has NO auth middleware -- would leak stolen overlay credentials if DB were functional • Socket.IO at port 3434 accepts arbitrary subscribe events ("bots", "logs", "all") and newBot injections without any credentials • MySQL 8.0.31 directly internet-facing on port 3306 with caching_sha2_password -- 25,500 connection IDs indicate heavy historical use • CORS set to Access-Control-Allow-Origin: * on all API responses -- full cross-origin attack surface • Turkish operator indicated by language strings ("ROOT kullanici olustur"), multi-language panel supports TR/RU/EN/ZH 🧬 IOCs: 31[.]57[.]216[.]126 (Hook C2 panel) hxxp[:]//31[.]57[.]216[.]126:8089/api/v1/sign-in hxxp[:]//31[.]57[.]216[.]126:3434/socket.io/ #bankingTrojan #Hook #ERMAC #android #malware #threatintel #C2
1
2
48
Replying to @stuzi_pants
Sending out the racist fuckwits while he sits at his desk in Spain writing emails to himself "Dear M̶e̶ S̶t̶e̶p̶h̶e̶n̶ Tommy You are the greatestest tallerest handsomest toughestest man. You my ero! Me simple workerman from Melton Cheesebury an me follow u. Me want cunty back"
6
138
6 Nov 2025
Replying to @iamodeal
My top 5 in no particular order: Gaslight 101 Landmine Coffee 24/48 Mr Workerman
2
41
1,297
3 Nov 2025
Grime Legend Griminal, in full Exodus form. Presence in motion, Lutte Bomber, Workerman Flower Tiger Jacket, Pas De Ce Monde crown pieces. The Amour Backpack seals it, and the air moves different, Exodus Zion for her, Jerusalem for him. Www.exoduspdcm.com
1
2
2
67
Shocked and dismayed by the events at the Louvre. Where has man gone wrong??? Brazen in daylight,,dressed like workerman. NO. Capers should only be at night,,striped shirt man with stocking over head and comically large sack with dollar sign on it. Piano keys when they walk
7
13
231
5,152
1 Oct 2025
Replying to @haradatora
Oh and in good condition! I bet a workerman had all his stuff out and then left in a hurry forgetting those
1
2
8
30 Sep 2025
Replying to @4r7hr @eigenrobot
Not as a ln accepted "profession" and not in the later waves of feminism. If it's wrong can you find an example more recent? Although thh imo the bigger tell us that the nurse and ballerina are female and the workerman male
2
27
1,122
Workerman Downlow always in the comments being an absolute weirdo
3
107
Replying to @CollinJHumphrey
Middlemen always trying to get a slice of the Workerman pie.
1
2
88
Workerman workerman workerman
5
757