logo

Hacker trap: Fake OnlyFans tool backstabs cybercriminals, steals passwords

ID: 8b1fb642-7934-5c0e-b1bb-5f60fe27f224

STIX ID: report--8b1fb642-7934-5c0e-b1bb-5f60fe27f224

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-09-05

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Veriti Research uncovered a deception campaign where a fake OnlyFans "checker" distributed the Lumma stealer via a GitHub-hosted payload; once executed the malware exfiltrates credentials, two-factor tokens, browser cookies, and cryptocurrency wallets and connects to .shop C2 domains. The GitHub account 'UserBesty' hosts additional fake tools (DisneyChecker.exe, InstaCheck.exe, ccMirai.exe) used to lure other cybercriminals, demonstrating active malware distribution and C2 infrastructure tied to the campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.