TGViewer
Channel Public Channel
Reverse Dungeon

Reverse Dungeon

@reverse_dungeon

Reverser's notes
The Mentor
1989
Subscribers
4.99K
Photos
743
Videos
59
Links
2.3K
Recent Posts 20 shown
Post #4134 673
Post #4132 1.54K

Forwarded from W1R3L355

https://hunt.io/blog/redis-cryptomining-botnet-3562-servers

TL;DR: Челы из Hunt.io вскрыли майнинг-ботнет на 3500+ серверов Redis просто потому, что мамкин оператор забыл закрыть open directory на 80 порту своего C2.

Внутри лежал полный фарш: логи атак, исходники тулчейна и реестр винды самого атакующего. Эксплойт красивый (Rogue Redis Replication с генерацией RDB на лету и дропом cron-тасок), маскировка майнера отличная (трафик XMRig по TLS на 443 порт), но OPSEC оператора - абсолютное дно. Взломать 3.5к тачек, чтобы потом спалить свою домашнюю пекарню через дамп реестра и общий Monero-кошелек - это премия Дарвина в инфобезе.
hunt.io Redis Cryptomining Botnet Compromised 3,562 Servers, Exposed by the Operator's Own Files A single exposed directory held the full toolkit behind a Redis cryptomining botnet. We parsed the operator's own campaign logs to confirm 3,562 compromised servers and map their tradecraft.
  • ❤ 7
  • 🐳 5
Post #4129 2.4K
Post #4124 2.14K

Forwarded from linkmeup

История про расследование масштабной кибершпионской кампании чисто под вечернюю рюмочку чая, так что советую не забыть.
Суть такая: ребятки из Китайской APT нашли уязвимость в широко используемой в Европе Ivanti Endpoint Manager Mobile и, совершенно не стесняясь, залезли через неё куда только не лень было. От госки и медицины до телекома и финансистов. А слово Mobile намекает нам, что через это они и в телефоны сотрудников перепрыгнули, закинув туда свои сертификаты и слушая весь пролетающий трафик.
Так что системы управления мобилками гребцов – это весело и удобно, но есть нюанс.
https://www.youtube.com/watch?v=2GzydBBGdbg
YouTube Black Hat Europe 2025 | China's Nexus APT Exploiting Ivanti Endpoint Manager Mobile This session explores a targeted cyber espionage campaign by a China-nexus nation state APT group that exploited Ivanti Endpoint Manager Mobile (EPMM) to infiltrate critical sectors across Europe, including government, healthcare, telecom, and finance. The…
  • ❤‍🔥 1
Post #4122 1.76K

Forwarded from Source Byte

Dissecting the dark web : reverse engineering the tools of the underground economy
Older posts →

About this channel

How can I read @reverse_dungeon without a Telegram account?
TGViewer shows the public web preview Telegram publishes for Reverse Dungeon: recent posts, photos, videos and the subscriber count, with no app, login or account.
How many subscribers does Reverse Dungeon have?
Reverse Dungeon (@reverse_dungeon) has 4.99K subscribers on Telegram, refreshed roughly every 30 minutes.
Does Reverse Dungeon know I viewed it here?
No. Public channel previews carry no viewer identity, and TGViewer has no accounts or tracking of what you look up.
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →