Clandestine's banner
Clandestine's profile picture

Clandestine

@akaclandestine62,429 subscribers

| Security | Osint | Threat Research | Opsec | Threat Intelligence | Infosec | Threat Hunting | Humint |

Videos

akaclandestine's profile picture

Security Alert: OSINT Investigation – Fraud on Caixa Tem OSINT analysis has identified the commercialization of SIP infrastructure (“SIP CAIXA TEM”) for large-scale attacks against the Caixa Tem mobile banking app from Caixa Econômica Federal. 1. Acquisition of Calling Infrastructure • “SIP CAIXA TEM” = Brazilian VoIP SIP trunks optimized for mass calling. • Scalable packages: 5 channels for R$ 1,500 up to 100 channels for R$ 11,000, with prepaid minutes at R$ 0.10 per minute. • “Auto-dialer up to 50 threads + real-time transcription” for R$ 2,000 = automatic dialing software capable of running up to 50 simultaneous calls per operator (or per machine). Real-time speech-to-text allows the “agent” to read the victim’s responses without listening live, speeding up the scam and easing training/quality control. • Example number 558007260207 (= +55 800 726 0207) is the official Caixa 0800 hotline. The service enables spoofing (origin forgery) so the call appears to come directly from Caixa. 2. Execution of Vishing (the “scam call”) • The auto-dialer calls thousands of numbers (typically from leaked beneficiary databases). • Typical script: “Your Caixa Tem account has a problem/block/suspicion of fraud. To unblock it, confirm your details or make a test PIX to a secure account.” • The fraudster instructs the victim to open the Caixa Tem app live, share the screen, provide OTP codes, change registered email/phone/password, or install a fake app. • Once access is obtained, the scammer changes contact details, transfers the balance from the Digital Social Savings Account via PIX to “mule” accounts (money mules), and erases traces. Recommendation: Never provide passwords, codes, or authorize financial transactions over the phone. Contact Caixa exclusively through official channels. Report immediately: Caixa app or 0800 726 0207. #CyberSecurity #DigitalSecurity #DigitalFraud #CaixaTem #VishingBrazil #FraudAlert #OSINTBrazil #DigitalProtection @Caixa

Clandestine

146,293 Aufrufe • vor 5 Monaten

akaclandestine's profile picture

CVE-2026-42530 NGINX RCE

Clandestine

57,981 Aufrufe • vor 2 Monaten

akaclandestine's profile picture

🚨 THREAT INTELLIGENCE ALERT – APT IRAN | DESTRUCTIVE WIPER ATTACK Actor: APT IRAN (also tracked as APT IRAN مرکز تحقیقاتی) Operation type: Full-disk wiper (irreversible destruction) Confirmed target: pfSense Community Edition firewall hosted on Yesilbeyaz Hosting (Turkey) Hostname: date: August 2026 Executive Summary A successful wiper attack against a pfSense firewall (FreeBSD 14 + ZFS) running on Turkish hosting infrastructure has been documented with complete video evidence. The actor obtained root access and deliberately zeroed the first ~1 GB of the disk, destroying the GPT partition table, bootloader, and ZFS structures. The system is now permanently unbootable. All data and firewall configuration have been lost. Technical Analysis of the Attack (based on visual evidence) 1Initial access and reconnaissance ◦pfSense 2.7.0-RELEASE (amd64) web interface accessed with account [email protected]. ◦Virtualized system (QEMU Guest), uptime of approximately 69 days. ◦Multiple virtual interfaces with Turkish/Islamic naming conventions (ABIDIN, BASRI, GANOS, SHM, GROZ, KUMOVA, RAMMOS, ORTAKLAR, INKUTSAN, GLENN, ORKA, etc.), indicating a multi-tenant VPN or tunneling service environment. 2Destruction phase ◦Root shell access via console. ◦Commands executed: ▪sysctl kern.geom.debugflags=16 (enables GEOM destruction) ▪Attempts at gpart destroy ▪dd if=/dev/zero of=/dev/da0 bs=1M count=1000 oflag=direct conv=fsync (and variations) ◦Successful zeroing of the first 1 GB of the disk (da0), overwriting the GPT partition table, bootloader, and ZFS metadata. ◦Confirmation of transfer: ~1,048,576,000 bytes in approximately 1.45 seconds. 3Finalization ◦reboot -q ◦Host stops responding (“Host is not communicating for more than 15 seconds”). ◦System completely dead. Context and Threat Assessment •APT IRAN has already been monitored for data leak claims (Argentina, Thailand, France, Indonesia, Brazil – PII, medical records, and government data). The current operation demonstrates real destructive capability, not just exfiltration. •The target is Turkish hosting infrastructure (NATO member country) with strong indications of VPN service usage. This elevates the risk of collateral impact on end users and potential targets of Iranian interest in the region. •Classic Iranian / pro-Iranian hacktivist wiper tactic: privileged access → irreversible destruction of boot and filesystem structures → rapid exit. Unlike ransomware, the objective is permanent denial of service and evidence destruction. Second- and Third-Order Implications •Hosting and VPS providers in Turkey and the surrounding region become priority targets for Iran-aligned groups during periods of geopolitical tension. #ThreatIntel #APTIran #Wiper #pfSense #CyberAttack #Yesilbeyaz #Turkey #IranianAPT

Clandestine

20,071 Aufrufe • vor 1 Monat

akaclandestine's profile picture

🚨 THREAT INTELLIGENCE ALERT 🚨 The tool 🇨🇳 KernelGhost820 is being actively sold on the underground market for US$ 2,500, complete with full source code. This is a professional-grade suite with an intuitive graphical interface and six advanced modules, specifically designed for EDR evasion and sophisticated ransomware operations with efficient lateral movement: • EDR Removal Engine: Automatically detects and terminates more than 40 security products (including CrowdStrike, SentinelOne, Microsoft Defender, Kaspersky, and others). Supports Kernel, UserMode, and NTDLL termination modes, kernel driver loading for protected processes, disabling Windows Defender, and blocking telemetry connections. • Ransomware Module: Dual encryption using AES256CBC + RSA2048, supporting over 70 file types (documents, images, databases, backups, etc.). Automatically deletes Volume Shadow Copies to prevent recovery, generates custom ransom notes with Bitcoin addresses and contact emails, and changes the desktop wallpaper. • Remote Operations & Mass Deployment: Connects to remote devices on the local network via WMI (requires username and password). Scans installed software on target hosts, performs process termination, and enables one-click full tool deployment. Includes full-network scanning for open SMB port 445 with real-time progress tracking. • Detailed Process Manager and full Operation Logger (exportable to TXT). This tool significantly lowers the technical barrier for advanced ransomware actors targeting corporate environments. Immediate monitoring recommendations: • Evaluate the resilience of your EDR/XDR controls against kernel-mode bypass techniques • Intensify monitoring of anomalous SMB (port 445) traffic and WMI connections • Strengthen network segmentation and the principle of least privilege Our team is actively tracking this tool and any emerging variants. #ThreatIntelligence #Ransomware #EDRBypass #CyberSecurity #InfoSec #CyberThreat

Clandestine

40,816 Aufrufe • vor 4 Monaten

akaclandestine's profile picture

Hacking in progress...👀

Clandestine

43,887 Aufrufe • vor 2 Jahren

Keine weiteren Inhalte verfügbar