Post B6UsXIOOuiXk4XUOvo by stag@mk.absturztau.be
(DIR) More posts by stag@mk.absturztau.be
(DIR) Post #B6UoO2M6lnUxuZkLwW by mildsunrise@tech.lgbt
1 likes, 0 repeats
looks like privacy.thenexus.today is compromised? when i try to visit a post (example) something replaces the whole tree with an iframe to a malware site
(DIR) Post #B6UsXHwOaq8qfgO2HQ by mildsunrise@tech.lgbt
0 likes, 0 repeats
the malicious payload is being injected in the html directly... @thenexusofprivacy
(DIR) Post #B6UsXIBzeqcPS3gUam by mildsunrise@tech.lgbt
0 likes, 0 repeats
reported the malware domain to cloudflare and the registrar, i'm curious how quickly they'll (not) act
(DIR) Post #B6UsXIOOuiXk4XUOvo by stag@mk.absturztau.be
0 likes, 0 repeats
@mildsunrise@tech.lgbt thats useless cloudflare has a neutrality policy they basically dont take things down ever
(DIR) Post #B6UsXIa6DDtueoxkAK by mildsunrise@tech.lgbt
0 likes, 0 repeats
@stag seems like they've acted already, see https://platecrumbs.com/
(DIR) Post #B6UsXIk1cJqB9bbfdY by star@amazonawaws.com
0 likes, 0 repeats
@mildsunrise @stag lmfao
(DIR) Post #B6UsgdQu3VZnvy74iW by ShadowJonathan@tech.lgbt
0 likes, 0 repeats
@mildsunrise also report it to the registrar, so it's report goes on an independent path
(DIR) Post #B6UsgdmWl6sF12ELQG by mildsunrise@tech.lgbt
0 likes, 0 repeats
@ShadowJonathan yes, i've reported it to both(?)
(DIR) Post #B6Usge0LvhvthuhNyK by Rairii@labyrinth.zone
0 likes, 0 repeats
@mildsunrise @ShadowJonathan seems they added some inline javascript at the bottom of the page that sets up the iframe, which is to a clickfix lure, interestingly enough it sets up an iframe to drop a file into the downloads directory and then the clickfix batch code unzips it and runs the resulting js file with cscript. i haven't heard of that before for clickfix, but it obviously relies on the user not having changed the downloads dir (that's a thing you can do, i point it to another drive)
(DIR) Post #B6UthqF21FgJu1hQo4 by Rairii@labyrinth.zone
0 likes, 0 repeats
@mildsunrise @ShadowJonathan the main payload is an inno setup installer signed by a valid code signing cert from sectigo:CN = Lway FirmwareO = Lway FirmwareS = UusimaaC = FI2.5.4.15 = Private Organization1.3.6.1.4.1.311.60.2.1.3 = FISERIALNUMBER = 3462375-9RFC822 Name=kasperlahtela@gmail.comthis extracts to an otherwise-legitimate electron app that has been somehow backdoored (replaced app.asar)