Fake OnlyFans cybercrime tool infects hackers with malware
ID: 7fd6df22-eb18-52cb-9e35-843a828bef5b
STIX ID: report--7fd6df22-eb18-52cb-9e35-843a828bef5b
Feed Name: Bleeping Computer
Threat Score
**Executive Summary:** Veriti Research uncovered a deception campaign where a malicious OnlyFans 'checker' executable (brtjgjsefd.exe) hosted on GitHub installs the Lumma stealer; the operator (GitHub user "UserBesty") hosts additional fake checkers (DisneyChecker.exe, InstaCheck.exe, ccMirai.exe) and uses .shop domains as command-and-control, enabling credential, cookie, 2FA, and cryptocurrency wallet theft as well as additional payload loading.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
