fa
Feedback
vmo (Director's Cut)

vmo (Director's Cut)

کانال بسته

نمایش بیشتر
کشور مشخص نشده استفناوری و برنامه‌ها34 408
1 536
مشترکین
اطلاعاتی وجود ندارد24 ساعت
-77 روز
-10030 روز
آرشیو پست ها
C'EST EN ROUTE

C'EST EN ROUTE

My new telegram @ZwLoadDriver

Rotemelli1 ports and database will be deleted at Midnight as we are permanently discontinuing Rotemelli1 Backup your infected systems We are not back on telegram. This is just a friendly reminder for members not in the Simpex Channel who do not get the notifications you can use the new private updates channel https://t.me/+RJy7lXtqEp9jZDA5 the simplex channel has been deleted. contacts are intact

FALSE COMPROMISE NOTICE users brought to our attention today there was a misleading message posted to our channel days ago 'F
FALSE COMPROMISE NOTICE users brought to our attention today there was a misleading message posted to our channel days ago 'Falkonc2 has been compromised. contact for negotiation' first of all we never saw any such message because the attacker probably deleted the message so we had no idea such a thing had happened until a user brought to our attention today because we were working on a new morpher and did not notice that activity this is not the first time we have experienced this with telegram so its not as surprising because telegram used to manually disable our channels of communication when we used to publish public poc and works and we moved to private groups and attacker somehow got access to the group and posted a misleading message and an ad most people or attackers have known us to reject posting ads in any channel associated with us and we recently received a message from couple of apts and loaders asking for ads placement but we refused and someone probably had to use a telegram 0day or access to our backup account to post such misleading message as of this writing we are fed up and leaving telegram completely for these numerous errors and unapproved access our updates and private channel has been moved to simplex link below. goodbye https://smp12.simplex.im/c#qWGsadvrIodXHMDrDPra2_S0QX-UtrIsQFWWEEeQG24 ANY OTHER MESSAGE SENT AFTER THIS MESSAGE IS FAKE AND NOT FROM US

Extra Security Additions [!] Windows agent will use a unified tor proxy routing feature for communications to remove traces of operation to affiliate system completely [!] Javascript and CSS will be removed completely from the clearnet and tor cdn to improve load time and speed [!] Affiliate logon to the windows agent will now require a compulsory 4 digit decryption pin for all systems and communication to the central c2 server to add an extra layer of security which prevents account takeover through KeyID file [!] PGP key encryption will be compulsory for all windows agent downloads to prevent account takeovers and binary exposure falkonC2 Comms.

Additions in falkonC2 v3 Cherenkov Signed stubs with legitimate certificates Quickbooks company data and backup file extracto
Additions in falkonC2 v3 Cherenkov Signed stubs with legitimate certificates Quickbooks company data and backup file extractor Privilege escalation to SYSTEM/NTAUTHORITY DNSFORGE banking and crypto addon Morpher for Microsoft Endpoint and Security 1 SURPRISE FEATURE Coming this July falkonC2 Comms.

falkonC2 DNSFORGE feature to replace legitimate banking and crypto websites with a scampage or sniffer whilst domain and ssl certificate remains unchanged Currently works on all Google Chrome versions Coming this July falkonC2 Comms.

EARLY JULY V3 CHERENKOV
EARLY JULY V3 CHERENKOV

Support will be online soon We took some time off from depression and debugging Sorry for inconvinience caused We turned on automated maintenance system which will keep the servers online till we return without interruptions falkonC2 Comms.

exploit has been upgraded to LPE with no external dependencies stubs will now run with SYSTEM privileges by default enabling direct controls and system level access to the following; killing most av agents silently extracting quickbooks customer and payment data extracting chrome cookies autofills passwords running infected systems as ddos pool replacing accounting software with duplicate versions to reroute transactions dumping kerberos tickets and ntlm hashes of the system etc falkonC2 Comms.

falkonC2 new morpher polymorphism startup persistence no disk falkonC2 Comms.
falkonC2 new morpher polymorphism startup persistence no disk falkonC2 Comms.

We received reports about lost requests and messages with the qTox support service For this reason qTox communication has bee
We received reports about lost requests and messages with the qTox support service For this reason qTox communication has been discontinued permanently Use the alternative below which is has been vetted as stable and secure falkonC2 SimpleX Support (simplex.chat/downloads/) https://smp10.simplex.im/a#jEhRodC0hqitonn7HEdgEVSLvevnR7FDk9OGkl2J4A8 falkonC2 Comms.

Telegram support contact has been deactivated infect immediately Please write to qTox support from here on for quick support and entry requests The following changes will be applied next week ahead of upcoming update • falkonC2 Tor CDN will be updated to newer version as well as new Clearnet CDN to increase download speed to 80% faster as compared to Tor • Various profiles on forums will be deactivated except T1erOne Forum • Rate limiting will be introduced in the Central Stub Assembler • Device limit will be applied in the agent to prevent affiliate account hijacking (uploading your license file to upload services such as temp[.]sh limewire[.]com mega[.]nz automatically grants administrators of these services permission to extract your logs from the agent using the license file you uploaded to their service just to transfer it to another pc; We delt with similar situation yesterday and we do not advise you to use public service for transfer of license or agent simple alternative is to use scp or sftp) • New pool of domains will be deployed to replace old domains and will use an independent cdn not cloudflare routed even though stubs are not detected with the old domains we just like to be a step ahead of backups for smooth operation • Resident loader will be diabled for other public malware families and focus solely on private projects and rmms We have seen the Telemetry and FlareIO report published recently; We are not worried about the reports as long as affiliates are targetting the right systems Get qTox Support - @falkonc2 Enjoy the rest of the week

Direct privilege escalation 0day has been cut down to required size to fit into the stub with compatibility options for windows 7-vista being worked on currently windows 8-11 is done with Microsft Defender detection bypass embedded Sophos EDR bypass for screenconnect and datto is also done as of this morning TrendMicro bypass and Bitdefender new morpher in coming weeks Enjoy the rest of the week