Post B6UoO2M6lnUxuZkLwW by mildsunrise@tech.lgbt
 (DIR) More posts by mildsunrise@tech.lgbt
 (DIR) Post #B6UoO2M6lnUxuZkLwW by mildsunrise@tech.lgbt
       1 likes, 0 repeats
       
       looks like privacy.thenexus.today is compromised? when i try to visit a post (example) something replaces the whole tree with an iframe to a malware site
       
 (DIR) Post #B6UsXHwOaq8qfgO2HQ by mildsunrise@tech.lgbt
       0 likes, 0 repeats
       
       the malicious payload is being injected in the html directly... @thenexusofprivacy
       
 (DIR) Post #B6UsXIBzeqcPS3gUam by mildsunrise@tech.lgbt
       0 likes, 0 repeats
       
       reported the malware domain to cloudflare and the registrar, i'm curious how quickly they'll (not) act
       
 (DIR) Post #B6UsXIOOuiXk4XUOvo by stag@mk.absturztau.be
       0 likes, 0 repeats
       
       @mildsunrise@tech.lgbt thats useless cloudflare has a neutrality policy they basically dont take things down ever
       
 (DIR) Post #B6UsXIa6DDtueoxkAK by mildsunrise@tech.lgbt
       0 likes, 0 repeats
       
       @stag seems like they've acted already, see https://platecrumbs.com/
       
 (DIR) Post #B6UsXIk1cJqB9bbfdY by star@amazonawaws.com
       0 likes, 0 repeats
       
       @mildsunrise @stag lmfao
       
 (DIR) Post #B6UsgdQu3VZnvy74iW by ShadowJonathan@tech.lgbt
       0 likes, 0 repeats
       
       @mildsunrise also report it to the registrar, so it's report goes on an independent path
       
 (DIR) Post #B6UsgdmWl6sF12ELQG by mildsunrise@tech.lgbt
       0 likes, 0 repeats
       
       @ShadowJonathan yes, i've reported it to both(?)
       
 (DIR) Post #B6Usge0LvhvthuhNyK by Rairii@labyrinth.zone
       0 likes, 0 repeats
       
       @mildsunrise @ShadowJonathan seems they added some inline javascript at the bottom of the page that sets up the iframe, which is to a clickfix lure, interestingly enough it sets up an iframe to drop a file into the downloads directory and then the clickfix batch code unzips it and runs the resulting js file with cscript. i haven't heard of that before for clickfix, but it obviously relies on the user not having changed the downloads dir (that's a thing you can do, i point it to another drive)
       
 (DIR) Post #B6UthqF21FgJu1hQo4 by Rairii@labyrinth.zone
       0 likes, 0 repeats
       
       @mildsunrise @ShadowJonathan the main payload is an inno setup installer signed by a valid code signing cert from sectigo:CN = Lway FirmwareO = Lway FirmwareS = UusimaaC = FI2.5.4.15 = Private Organization1.3.6.1.4.1.311.60.2.1.3 = FISERIALNUMBER = 3462375-9RFC822 Name=kasperlahtela@gmail.comthis extracts to an otherwise-legitimate electron app that has been somehow backdoored (replaced app.asar)