Skip to content

Instantly share code, notes, and snippets.

@arash16
Last active February 2, 2026 18:39
Show Gist options
  • Select an option

  • Save arash16/cf778b8a29be2a3b818bcdae5f7583f5 to your computer and use it in GitHub Desktop.

Select an option

Save arash16/cf778b8a29be2a3b818bcdae5f7583f5 to your computer and use it in GitHub Desktop.
# ⚠️ You are HACKED ⚠️
@arash16
Copy link
Author

arash16 commented Feb 2, 2026

The malware spawns 3 parallel processes:

  1. Collect all sensitive known data, like browser profiles, .ssh keys, windows passwords, chrome specific extensions data (wallets)
  2. Search the whole system for files containing interesting words for attacker (wallet, password, phone, .env, .cfg, .ini, etc)
  3. Start a live websocket connection to server that attacker can ask victim's computer to run custom commands

Consider everything sensitive to be stolen. This is not speculation, I have read the malware's de-obfuscated source code!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment