βοΈ { ππ ππ―π©π’π±π±π'π° ππ¬π²π«π€π’ } βοΈ
Closed channel
π§ͺ ππππβππΈππ πΈπΉπππ πΌππΌβππβπβπΎπ§ͺ You search how to setup windows on VM, what credit reports are or how checks work? We show you practical ones to understand β οΈ Unauthorized advertisments in comments will lead to a ban from channel :)
Show moreNo data
Subscribers
+724 hours
+657 days
+16630 days
Posts Archive
I am looking for: snakekeylogger vip stub (uncrypted, raw)
Get in touch. No money, no bullshit - just teamwork.
π RESOURCES
β«οΈHere are some proxy and voip services you might not know and maybe test. If you have tested one of these websites, send a message to @scarlettaowner as feedback and help our community. π―
π PROXY SERVICES
https://juicyproxies.com/ (High-Speed 5G Mobile Proxies)
https://proximy.io/ (Unlimited Mobile Proxies)
https://datalabs.net/ (Residential & Datacenter Proxies)
https://proxies.fo/ (AT&T ISP, Datacenter, IPv6, Residential and Mobile Proxies)
https://www.thunderproxies.com/ (Datacenter, Residential and Static ISP Proxies)
https://www.pyproxy.com/ (Residential, ISP and Datacenter Proxies)
https://www.doveip.com (Residential & 3G/4G/5G Mobile Proxies)
https://www.lunaproxy.com/ (Residential Proxies)
https://proxidize.com/ (4G/LTE/5G Mobile Proxies)
https://netnut.io/ (Residential, Mobile and Datacenter Proxies)
https://www.illusory.io/ (5G Mobiles Proxies)
https://astroproxy.com/ (Mobile, Residential and Datacenter Proxies)
https://iproxy.online/ (4G/5G Mobile Proxies)
https://proxyempire.io/ (Residential, Dedicated and Datacenter Proxies)
https://cryptoproxy.store/ (Mobile socks5 proxies)
π± VOIP SERVICES
https://voip.ms/ (Rent Number & VoIP Phone Services)
https://blacktel.io (Rent Virtual Phone or eSIM)
https://onlinesim.io/ (Temp Numbers & Rent Numbers)
https://sms-man.com/ (SMS Receiving Service & Rent Numbers)
https://tiger-sms.com/ (Temp Numbers & Rent Number)
https://silent.link/ (4G/5G Gobal eSIM)
π» Share And Support Channelπ»
https://t.me/+Tk_9OcuIuHE3YmZi
β οΈ Potato App is a Honeypot for the authorities
I have seen yesterday at German channels some new posts about Potato, an alternative App for Telegram.
Potato appears to be fairly new on the market and gained popularity with Durov's arrest. In some circles, it is being touted as a secure alternative to Telegram, promising security and anonymity. The fact that the Potato app is presumably a clone of the Telegram messenger and that the people behind it are unknown tends to be ignored. The company MarkMonitor was commissioned to ensure that the people behind the Potato app remain hidden. The profit-oriented company specializes in the registration of domains and the fight against piracy. The world-famous and well-known corporate giants therefore commission MarkMonitor to be active in protecting their brands. There is an obvious conflict of interest here, which speaks against the security of the Potato AppπΊ References : https://www.youtube.com/watch?v=fqbyrYKQEZU https://youtube.com/watch?v=tXP6mRzgRcw After we know, who "MarkMonitor" is, and what they do, how does Potato is associated with it ? If you run a whois command with potato.im, the official domain, then you will get some domain names:
whois potato.im Expiry Date: 23/07/2025 00:59:55 Name Server:ns-1166.awsdns-17.org. Name Server:ns-1660.awsdns-15.co.uk. Name Server:ns-328.awsdns-41.com. Name Server:ns-721.awsdns-26.net.Now you go to https://www.whois.com/whois/ and paste one of the entries. The first entry gives back :
Registrar Information Registrar: MarkMonitor Inc. IANA ID: 292 Abuse Email: abusecomplaints@markmonitor.com Abuse Phone: +1.2083895740There you go. You can even use their website to search it π https://whois-webform.markmonitor.com/whois/ π¨ What can i do now ? βΆοΈLook through your chats to see what you've done. βΆοΈSecure your devices with encryption and passwords. βΆοΈUninstall Potato βΆοΈFollow this channel's OPSEC guide βοΈAnd last but not least βΆοΈPray they don't fuck your ass. Sources from the channels : https://t.me/AnleitungenTelegramBeispiele/5684 https://t.me/AnleitungenTelegram/3294
Seems like SnakeKeylogger is back. But where ?
If you have access to courses which could be interesting to this community let me know letβs export & share them.
Just paste me login and i check it out
@scarlettaowner
Anyone got evilginx with evilpuppet dm me with it. @scarlettaowner.
unecessary comments / useless dms will be ignored.
URL Resolution: Scan shortened URLs by following redirects.
Behavioral Analysis: Flag numbers with no prior legitimate activity.
User Reporting: Carriers encourage forwarding spam to 7726, improving detection.
Spammers must stay one step ahead, constantly adapting to these evolving defenses.
Example: Send an RCS message with a phishing link thatβs only decrypted on the recipientβs device, evading carrier filters.
5. Evading Volume-Based Detection
Why? Anti-spam systems often flag high-volume SMS from single numbers. Spammers avoid this by distributing messages across multiple sources.
How?
Multiple Numbers: Use a pool of disposable or virtual numbers, often bought in bulk from the dark web. Each number sends low-volume messages to stay under thresholds.
Grey Routes: Route SMS through unregulated or low-cost international providers to obscure the sender.
Botnets: Use compromised devices to send messages, distributing the load and mimicking legitimate P2P traffic.
Example: Send 10 messages from 100 different numbers instead of 1,000 from one, reducing the chance of triggering volume-based blocks.
6. Bypassing Machine Learning Filters
Why? Modern anti-spam systems use machine learning to detect spam patterns. Spammers can confuse these models by varying message content or structure.
How?
Randomized Content: Use templates with randomized words, sentence structures, or timestamps to avoid consistent patterns (e.g., βChase Alert: Act now!β vs. βUrgent: Chase issue detected!β).
Natural Language Mimicry: Craft messages that resemble legitimate P2P or A2P SMS, avoiding overt spam cues like βfreeβ or βwinβ.
Adversarial Inputs: Add noise (e.g., irrelevant phrases like βHope youβre well!β) to disrupt ML classification without affecting the phishing goal.
Example: βHi, Chase noticed an issue with your recent login. Please check [link] to resolve. Have a great day!β The friendly tone and lack of overt urgency may slip past filters.
7. Exploiting 2FA or OTP Systems
Why? Chase often sends 2FA codes via SMS, and anti-spam systems may whitelist these to avoid blocking legitimate messages. Spammers can piggyback on this trust.
How?
Fake OTP Format: Mimic 2FA SMS (e.g., βChase Code: 483920. Do not share.β) but include a malicious link or reply instruction.
Spear-Phishing: Target specific users with personalized messages based on leaked data (e.g., from past breaches), making the SMS seem contextually relevant.
SIM Swap or Interception: In rare cases, spammers could attempt SIM swaps or use malware to intercept SMS on compromised devices, though this is complex and less scalable.
Example: βChase 2FA: Use code 729104 to verify your login. If not you, secure your account at [link].β This blends in with real 2FA messages.
Technical Considerations
Encryption Limitations: True encryption (e.g., AES) isnβt practical for SMS due to the 160-character limit and lack of native encryption in SMS protocols. RCS offers end-to-end encryption, but adoption is limited. Obfuscation is more common than encryption.
Anti-Spam Countermeasures: Systems like reCAPTCHA SMS defense assess phone number risk before sending SMS, so spammers must use clean or stolen numbers. SMS firewalls scan for URLs and content, requiring careful link and text crafting.
Legal Risks: Sending spam SMS, especially impersonating banks like Chase, violates laws like the U.S. Telephone Consumer Protection Act, with hefty fines. Detection by carriers or law enforcement is a significant risk.
Example of a Hypothetical Spam SMS
Original: βChase: Your account is locked. Click https://chase-login.com to verify.β Obfuscated: βCh@s3: Y0ur acc0unt is l0ck3d. V1s1t https://bit.ly/3xYz t0 s3cur3. Thx!β
This uses character substitution, a shortened URL, and a friendly tone to evade basic filters while mimicking a legitimate alert.
Why This Works
Keyword Evasion: Obfuscated text avoids matching βChaseβ or βverifyβ in spam databases.
URL Hiding: Shortened or trusted domains bypass blocklists.
Trust Exploitation: Mimicking Chaseβs format and 2FA style tricks users and may slip past whitelists.
Low Volume: Using multiple numbers avoids volume-based detection.
Countermeasures by Anti-Spam Systems
To understand why these methods work, consider how anti-spam systems counter them:
Advanced ML Models: Detect obfuscated text by normalizing characters (e.g., converting βCh@s3β to βChaseβ).
How Spammers Might Encrypt or Obfuscate SMS to Evade Anti-Spam Bots
Anti-spam systems, like those used by mobile carriers (e.g., Telstraβs SMS scam filter) or Google Messages, rely on content analysis, URL scanning, sender reputation, and behavioral patterns to flag spam. To bypass these, spammers could use the following methods:
1. Text Obfuscation (Not True Encryption)
Why? Anti-spam bots scan for keywords (e.g., βChase,β βaccount suspended,β βverify nowβ) or suspicious patterns. Obfuscating text makes it harder for algorithms to match against known spam signatures.
How?
Character Substitution: Replace letters with similar-looking characters or symbols (e.g., βCh@s3β instead of βChase,β or βV3r!fyβ instead of βVerifyβ). This can fool simple keyword filters.
Unicode/Non-Standard Characters: Use Unicode characters that resemble ASCII (e.g., Cyrillic βΠ°β instead of Latin βaβ). For example, βΠ‘haseβ (with a Cyrillic βΠ‘β) might bypass filters expecting βChase.β
Spacing or Punctuation: Insert spaces, dots, or special characters (e.g., βC h a s eβ or βChase.Alertβ) to break keyword detection.
Misspellings or Synonyms: Use slight misspellings (e.g., βChaceβ or βChaaseβ) or synonyms (e.g., βsecureβ instead of βverifyβ) to avoid exact matches.
Example: Instead of βChase: Your account is locked. Click here to verify,β use βCh@s3: Y0ur acc0unt is l0ck3d. V1s1t [link] t0 s3cur3.β
2. URL Obfuscation
Why? Many Chase alert scams include malicious links, which anti-spam systems like Cellusys SMS Anti-Phishing scan for known malicious domains or suspicious patterns. Obfuscating URLs can bypass these checks.
How?
Shortened URLs: Use legitimate URL shorteners (e.g., bit.ly, tinyurl) to mask the destination. Shorteners hide the full domain, making it harder for filters to assess without resolving the link.
Trusted Domains: Host phishing pages on compromised or trusted domains (e.g., Google Drive, Amazon S3) to leverage their reputation, as noted in phishing email techniques. For SMS, a link like βhttps://docs.google.com/β¦β might appear safe.
Encoded URLs: Encode parts of the URL (e.g., βhttps://xnβchse-9ua.comβ for a domain that visually mimics βchase.comβ using Punycode).
Dynamic Links: Use redirect services or single-use URLs that change frequently to evade blocklists.
Example: Instead of βhttps://fake-chase.com,β use βhttps://bit.ly/3xYzβ or βhttps://docs.google.com/secure-chase-login.β
3. Mimicking Legitimate Formatting
Why? Chase alert scams exploit trust in official-looking messages. By closely mimicking legitimate Chase SMS formats, spammers reduce suspicion from both users and bots.
How?
Spoofed Sender ID: Use alphanumeric sender IDs (e.g., βChaseBankβ) or spoofed phone numbers that resemble official ones. Grey routes or lax A2P SMS providers can facilitate this.
Legitimate Wording: Copy phrasing from real Chase alerts (e.g., βYour card is temporarily locked. Call us now to unlock.β) but insert malicious links or numbers.
Timing and Context: Send messages during business hours or after legitimate bank activity to blend in with expected notifications.
Example: βCHASE: Suspicious activity detected on your account. Reply Y to confirm or visit [shortened link] to secure.β This mirrors real 2FA or fraud alerts.
4. End-to-End Encryption (RCS or Third-Party Apps)
Why? Google Messages supports RCS with end-to-end encryption, making message content unreadable to carriers or Google. Spammers could exploit this to hide malicious content from network-level filters.
How?
RCS Messaging: If both sender and recipient use RCS-enabled apps (e.g., Google Messages), the message is encrypted, preventing content scanning. Spammers could send encrypted spam that appears as gibberish if intercepted.
Third-Party Apps: Use encrypted messaging platforms (e.g., WhatsApp, Signal) to deliver phishing links, bypassing SMS firewalls entirely.
Challenge: RCS requires both parties to use compatible apps, limiting reach. Spammers might fall back to SMS for broader distribution.
Scarletta's Lounge on Potato :
https://ptslk.org/scarlettaslounge
Re-created Deepwaterleaks for the germans and posting the old content there:
https://ptslk.org/deepwaterleaks
Scam stores (don't buy from them!) π»
hydralogs.online
darkweb01.store
ze4w.cc
bazaarshop.cc
stakeshop.fo
daknight.net
xenonlogs.site
dridextool.com
protools.pw
worldusalogs.com
evilginx.info
darksu.io
elitehacks.live
d3ckl0gs.com
xbasetools.pro
daknight.net
vulnx.biz
βοΈIf you don't trust us and buy from it but don't cry if get scammed.
π€π€π€π€ π€π€π€ TO AVOID
SCAM ADVERTISEMENTS YOU SHOULDN'T SEND ANYONE MONEY ON 2025 ββ
πShopping Scams
They'll tell you to send very cheap money for them to shop expensive phone price for you
$50 to get iPhone 15+π± and so on.
πShopWithScrip Scam
You'll send them $30 for $2K balance account which I can't point everyone is scamming but 95% is a scam only very few is legit
πBetway/Sportybet Account Balance Adder..
When you see anyone ads on that don't message it's A SCAM. Itβs old scam but still people using it
πWorldRemit/Remittances Investment scam..
They'll tell you to send 100ghc and get 1000ghc less than 30mins it's a scam
NB: Worldremit is real when you follow up guidelines and workout yourself but don't send money to anyone to work worldremit for u
Same as Nala and Remitly, TapTapSend etc..
πLogs Conversation To BTC
It's purely SCAM
They'll tell u to send $80 and get $3K balance btc
It's a scam
πJumia logs
85% is a scam after you send them money for the logs they block u or give you fake logins and blame you for changing password
πTrust wallet bitcoin withdrawal
βWatch Only Walletββ canβt be withdrawn by any third party app or subscription all is SCAM
πCashapp Load Pay $50 get $500 or $600
And so on is SCAM
Iβll be updatingβ¦β¦.
If you know of any viral scam let me know to addup do the list to keep brothers safe here
β NB There're many Scams out there before you send anyone money of any business deal your not sure of Contact @scarlettaowner to find out if it's safe before you proceed. A word to the wise here βπΌβπΌ
Original post belongs to skymoney
The potato QR code. You can also use username @scarletta
We finally found an alternative to Telegram.
So. It's time to shift from Telegram
https://www.potato.im/
Reading some private messages.
