AfroSec
790 subscribers
456 photos
33 videos
7 files
239 links
hello friend
am AfroSec | AASTU dropout | cybersecurity enthusiast | CRTO | CRTOM | CRTA | passionate about Red Teaming :)

portifolio : https://afrosec.et
blog: https://blog.afrosec.et
file : @Afr0Files
Download Telegram
hmmm ๐Ÿ™ƒ

@AfroSec
๐Ÿฅฐ5โค1๐Ÿ”ฅ1
yoo so i just created a Red Team Discord

If you're into hacking, redteaming ofc , or learning real-world security come join us.

๐Ÿ‘‰ https://discord.gg/t4tcrF95

Letโ€™s grow and learn together :))

@AfroSec
โšก6โค1๐Ÿ™1
melllow my fellow hackers and defenders
how u holdin up tho ? ๐ŸคŸ

@AfroSec
โค4โšก2
Forwarded from vx-underground
> be iranian threat actors
> compromise FBI directors personal email
> fast forward like, 5 hours
> $10,000,000 bounty on head

Opinion: I think Kash Patel is extremely mad
๐Ÿคฏ5๐Ÿคฃ1
vx-underground
$10,000,000 bounty on head
this is a lot fr ๐Ÿคฏ๐Ÿคฏ
@AfroSec
let the night grind begin huh ๐Ÿ˜Ž๐Ÿ˜Ž

btw mn gud new znabu like damn ๐Ÿฅถ

@AfroSec
โšก8๐Ÿ”ฅ4๐Ÿคฉ3
some threat actors get into a system โ€” letโ€™s say your personal computer.

now youโ€™re also a hackerโ€ฆ you think:
โ€œYeah I can just monitor the traffic with Wireshark and catch them blah blah.โ€

but hereโ€™s the thingโ€ฆ

They can make their traffic look completely legit. how?

Malleable C2 profiles

This is basically a domain-specific language (DSL) introduced by Cobalt Strike that lets redteamers redefine how their beacon(implant) communicates with the TS.

means....
They can disguise malicious traffic to look like:

* browsing social media
* streaming music
* accessing cloud services

So your โ€œsuspicious trafficโ€ just looks normal.

Core components:

โ€ข HTTP GET / POST
โ€ข Global options (sleeptime, useragent, etc.)
โ€ข Data transformation & obfuscation (prepend, append, encoding)


set useragent "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36";
set jitter 0;
set sleeptime 0;
set timeout 10;
set retry 0;

http-get {
set uri "/afro_checkin.php";
client {
header "Accept" "text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8";
header "Accept-Language" "en-US,en;q=0.5";
header "Connection" "keep-alive";
metadata {
base64;
prepend "user=";
header "z-User";
}
}
server {
header "Server" "nginx/1.18.0";
contentencoding "gzip";
output {
print;
}
}
}


whatโ€™s happening here?

โ€ข Beacon checks in with metadata (ID, hostname, process, etc.)
โ€ข Data gets base64 encoded
โ€ข Then "user=" is prepended โ†’ user=base64payload
โ€ข Sent inside a custom header โ†’ z-User

Now it just looks like a normal HTTP request header.

Meanwhileโ€ฆ

โ€ข Team Server responds with payload
โ€ข Encoded + compressed (gzip)
โ€ข Still looks legit in traffic

There are a lot of templates on GitHub go check them out

but donโ€™t just copy-paste them
u will get flagged fast :)

Most public profiles are already burned.

Alsoโ€ฆ
~90% of them are HTTP/S listeners

If you want to go deeper (P2P, SMB, DNSโ€ฆ)

@AfroSec
๐Ÿ”ฅ3๐Ÿ‘1
hmmm ๐Ÿ™ƒ

@AfroSec
50๐ŸŽ‰28๐Ÿ’ฏ2โคโ€๐Ÿ”ฅ1
This media is not supported in your browser
VIEW IN TELEGRAM
sijemer eko we are ๐Ÿ˜ญ๐Ÿ˜ญ๐Ÿฅ€cooked

@AfroSec
๐Ÿคฃ7๐Ÿ˜ญ1
AfroSec
hmmm ๐Ÿ™ƒ @AfroSec
thank you guys for your birthday wishes, I really mean it
A lot of new members joined this year too , thank you all for being part of my journey.

much love and respect ๐Ÿ˜Š

@AfroSec
โคโ€๐Ÿ”ฅ8โค2
โš ๏ธ Axios โ€” the JavaScript HTTP client with 100M+ weekly downloads โ€” has been compromised with malicious versions dropping a Remote Access Trojan

๐Ÿ“Œ If you installed axios@1.14.1 or axios@0.30.4, assume your system is compromised!

๐Ÿ” Am I affected?

- MacOS
ls -la /Library/Caches/com.apple.act.mond 2>/dev/null && echo "COMPROMISED"
- Linux
ls -la /tmp/ld.py 2>/dev/null && echo "COMPROMISED"
- Windows
dir "%PROGRAMDATA%\wt.exe" 2>nul && echo COMPROMISED

Fix it:
npm install axios@1.14.0 โ† for 1.x users
npm install axios@0.30.3 โ† for 0.x users
rm -rf node_modules/plain-crypto-js
npm install --ignore-scripts

Read More [ Blog ]
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ˜‚๐Ÿ˜‚ this era

Me, Myself and I โŒ
Me, Myself and AI โœ…

even telegram cant leave as alone eko gud new ๐Ÿ˜
@AfroSec
๐Ÿ˜17
heyyy everyone
we are gonna be live on discord just kinda chill event we will solve one AD machine and learn along the way

if u r free check it out now https://discord.gg/XP948E8B :)

@AfroSec
๐Ÿ”ฅ8โšก2
did anyone see what i posted lool :)
๐Ÿคฃ6๐Ÿ‘2๐Ÿ˜2
#experience
from what I saw (experience), most Ethiopian websites are CMS-based, mainly WordPress. The funny part is that they completely trust the CMS to handle everything end-to-end, like security or other configurations. but, the fact is that the wp-json schema is enough to gather all their endpoints and do shady stuff ๐Ÿ˜‚ Sometimes they open sensitive directories like wp-includes or wp-content, then forget about their existence, which is a really bad security measure.

@AfroSec
๐Ÿ”ฅ3โšก2
jst found this on linkedin and i liked it :)

@AfroSec
โค16โคโ€๐Ÿ”ฅ4๐Ÿฅฐ2
Forwarded from The Hacker News
๐Ÿšจ WARNING - APT28 ran a global router hijack to steal credentials.

The group compromised MikroTik and TP-Link devices, rewrote DNS settings, and redirected traffic for credential theft at scale -- impacting 18,000+ IPs across 120 countries, including government and cloud targets.

๐Ÿ”— Read here โ†’ https://thehackernews.com/2026/04/russian-state-linked-apt28-exploits.html
๐Ÿคฏ2
W ๐Ÿ”ฅ attack chain fr ๐Ÿ‘Œ

@AfroSec
๐Ÿ”ฅ3๐Ÿค”1