Threat Intel as a reverse-engineer in Crimeware domain. Dubbed "Malware Mangler" by TheRegister. sysopfb@infosec.exchange

Joined August 2016
65 Photos and videos
Pinned Tweet
11 Mar 2020
Maksim Yakubets was indicted but treasury department also went after Evil Corp, what is really interesting is all the alluding to them being linked to FSB and as it turns out Yakubets is married to the daughter of Eduard Bendersky. w/ Joshua Platt @ WSJPro in Charlotte, NC 1/3
3
11
28
Dumped a bunch of notes surrounding a macos based stealer from etherhiding clickfix github.com/sysopfb/open_mal_… someone also released a blog surrounding pieces of it last night: medium.com/@ashishbogati098/…

1
3
11
1,343
sysopfb retweeted
Cool find from @sysopfb here is a couple of Images from the Panel, This specific panel was delivering a MacOS stealer notnullOSX http.html:"notnullOSX " - Shodan Search http://111.90.]143.163:8080/install
Nice writeup rmceoin.github.io/malware-an… Of note is a panel: hxxp://65.38.120.]80:8080 they left some tidbits behind in the login page: <<label>Пул доменов (по одному на строку)</label>"oeannon.]com&#10;heethcote.]com&#10;windlrr.]com"
6
5
1,345
Nice writeup rmceoin.github.io/malware-an… Of note is a panel: hxxp://65.38.120.]80:8080 they left some tidbits behind in the login page: <<label>Пул доменов (по одному на строку)</label>"oeannon.]com&#10;heethcote.]com&#10;windlrr.]com"
1
2
6
1,870
1
253
11 Jun 2025
medium.com/walmartglobaltech… Kudos to GitHub they were taking stuff down very fast
3
14
952
13 Mar 2025
Auto decoding IOCs from Arechclient and the onboard browser extension they drop medium.com/walmartglobaltech…
2
6
2,224
11 Mar 2025
medium.com/walmartglobaltech… go through a little of the panel they are using for the fake invites also
5
9
1,204
11 Dec 2024
Samples look like stealers. Some of the recent ones being Lumma placekeawe(.my
10 Dec 2024
I got drained, fully drained. Hi everyone, I'm just coming to share with you all the worst day of my life, and how it happened so that you guys don't ever have to pass through it. Thread below.
2
4
1,103
11 Mar 2020
Maksim Yakubets was indicted but treasury department also went after Evil Corp, what is really interesting is all the alluding to them being linked to FSB and as it turns out Yakubets is married to the daughter of Eduard Bendersky. w/ Joshua Platt @ WSJPro in Charlotte, NC 1/3
3
11
28
1 Oct 2024
2
395
23 Aug 2024
Hadn't seen this mentioned for stealc before? b717c966167148b7178e67727be7ac55d76d82acab88782e798e477a00abdd8b
3
16
1,399