logo

Fake OnlyFans cybercrime tool infects hackers with malware

ID: 7fd6df22-eb18-52cb-9e35-843a828bef5b

STIX ID: report--7fd6df22-eb18-52cb-9e35-843a828bef5b

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-09-05

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

**Executive Summary:** Veriti Research uncovered a deception campaign where a malicious OnlyFans 'checker' executable (brtjgjsefd.exe) hosted on GitHub installs the Lumma stealer; the operator (GitHub user "UserBesty") hosts additional fake checkers (DisneyChecker.exe, InstaCheck.exe, ccMirai.exe) and uses .shop domains as command-and-control, enabling credential, cookie, 2FA, and cryptocurrency wallet theft as well as additional payload loading.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.