26829th poster gets a cookie (cookie thread (Part 7)) (Part 11)

if it was a LinkedIn connection maybe

cute matching pfp business associates looking for economic growth though strategic partnerships :pleading_face:

2 Likes

I ran a RenPy game with a legitimate loader

6 Likes

And also scanned the game beforehand with Windows Defender AND MalwareBytes and they both came up clear >.>

5 Likes

Nobody is immune to getting hacked, and I know this of myself, which is why my ssh logins are all IP gated and my password manager is not accessible via pin code or biometrics, and my clipboard history is off
What is deeply unfortunate is that I did just use sensitive documents for bank account applications and a psychiatry appointment which almost certainly got stolen given what I deduced via forensics, but, I’m already a victim of identity theft so nothing really changes

10 Likes

And why I don’t store my master password to my vault in my browser.
Don’t do that. It’s the key to your encrypted vault.

5 Likes

The good news is that these types of sophisticated evasion techniques are on the upper end of malware attacks so general AVs should catch them

At the end of the day its all about your threat model. I wasn’t willing to store my sensitive documents on another airgapped PC out of convenience and took the risk and got got :man_shrugging:

Like for example if your adversary is someone with a C2 center controlling Pegasus…

3 Likes

Okay maybe I should finally start bring more secure on my computer
Passwords.txt isnt gonna cut it in this day n age…

12 Likes

It even had VM detection, despite fronting as GPU-intended software >.>
I suppose that’s one of the reasons you’d deliver the payload via a game

2 Likes

Do u have ur disc back btw? I assume so but wanna double check

2 Likes

AHWH72UWBSNAL1L

IDK HALF THE WORDS DAERON IS SAYING

2 Likes

IM FUCKED TOO

6 Likes

Yes, that’s been secured, and I rotated the password for only this account on this site
But realistically every FoL password I have used is compromised

3 Likes

Attacker used legitimate game .exe to run adjacent malicious code
Malicious code used multiple clever techniques to hide from antiviruses
Malicious code then used other clever techniques to elevate its permissions to user level, which let it grab any files my user could
This included literally any file on my PC that wasn’t administrator privileged, but they only targeted sensitive documents & passwords & cookies
Malicious code also uses clever techniques to hide where the malicious code came from and where it delivers the stolen data to

10 Likes

7 Likes

the red circle and the arrow like we cannot see him

1 Like

It gotta work if somebody falls for it

1 Like

LEGIT

1 Like

I’m dissapointed nobody announced it on breadbox, I want a full wall of constant ā€œhey x got hackedā€

1 Like

Public Hacking Log.

I have acquired Switch 2 from my brother.

2 Likes