Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
MSA Weekly 3 -“Menganalisa Nmap dan Port Probing”

Nmap (Network Mapper) adalah tools yang bersifat open source dan gratis untuk mengeksplorasi dan audit keamanan jaringan.Continue reading on Medium »
Read more...
Hackers Exploiting Follina Bug to Deploy Rozena Backdoor

A newly observed phishing campaign is leveraging the recently disclosed Follina security vulnerability to distribute a previously…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Hackers Used Fake LinkedIn Job Offer to Hack Off $625M from Axie Infinity

Hackers Used Fake LinkedIn Job Offer to Hack Off $625M from Axie InfinityPost Views: 31
Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 2 Minutes
Earlier in March this year, Ronin Network (RON), a blockchain network underpinning the famous crypto game Axie Infinity and Axie DAO suffered the largest crypto hack against a decentralized finance network reported to date.
In May 2022, the United States issued an advisory according to which highly skilled hackers from North Korea were trying to get employed by posing as IT freelancers. Now, it has been revealed that Axie Infinity hacking was socially engineered in which North Korean government-backed hacker group Lazarus used a fake job offer to infiltrate Sky Mavis’ network by sending one of the company’s employees a PDF file containing spyware.

Lazarus’ involvement in such a high-profile hack should not come as a surprise. In January 2022, researchers from different crypto security firms concluded that North Korean hackers have so far stolen $1.3 billion from cryptocurrency exchanges across the globe, while their prime suspect in these hacks was the infamous Lazarus gang. Axie Infinity HackThe employee, an ex-senior engineer at the company, took the bait and thought that it was a high-paying job offer from another company and opened the PDF. However, in reality, this company didn’t exist. During the recruiting process, the ex-employee gave away critical personal information, which attackers used to steal from the company.

Sky Mavis explained that its employees are constantly threatened by “advanced spear-phishing attacks on various social channels.” In this instance, one employee was fooled, who doesn’t even work at Sky Mavis anymore.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png It is worth noting that the play-to-earn game Axie Infinity is a Pokemon-inspired game developed by Sky Mavis and rakes in approximately $15 million in revenue daily. How was Ronin Hacked?According to The Block, when the hacking took place, Axie Infinity had nine validators from its proof-of-authority, an Ethereum-based sidechain Ronin.

“The attacker managed to leverage that access to penetrate Sky Mavis IT infrastructure and gain access to the validator nodes,” Sky Mavis stated.

The attacker had to capture five out of nine validators to infiltrate the company’s networks. The spyware-laced PDF helped the attacker control 4 validators and access the community-run Axie DAO (Decentralized Autonomous Organization), from where they got control of the 5th validator.

After compromising the network, the attackers stole $25 million worth of USDC stablecoin and 173,600 ether (roughly $597 million) from Axie Infinity’s treasury, collectively stealing crypto worth around $625 million.

Nevertheless, Ronin sidechain increased the number of validators to 11 to enhance security, whereas Sky Mavis is reimbursing Axie Players who lost crypto due to the attack. The company underwent a $150 million funding round back in April 2022.
Trending: How do QR Codes work and how criminal hackers use them to generate phishing attacks – Demo Trending: OSINT Tool: Pagodo Lazarus HackersThe US government claims that the notorious North Korean hacker group Lazarus is responsible for the attack. This group specializes in such attacks.

This isn’t the first time that Lazarus has targeted the blockchain industry. However, this is uncommon for Lazaru[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Hackers Used Fake LinkedIn Job Offer to Hack Off $625M from Axie Infinity Hackers Used Fake LinkedIn Job Offer to Hack Off $625M from Axie InfinityPost Views: 31 Premium Content https://www.blackhatethicalhacking.com/wp-content…
s to use social engineering to invade a company’s networks. In fact, in June 2020, Slovak internet security company ESET warned LinkedIn users of Lazarus’ involvement in a sophisticated LinkedIn recruiter scam targeting military and aerospace firms. Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Trending: New RedAlert Ransomware targets Windows, Linux VMware ESXi servers Source: hackread.com Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/ban6-Recovered-Recovered-Recovered-90x90.png New stealthy OrBit malware steals data from Linux devices3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/ezgif.com-gif-maker-2-1-90x90.jpg High severity OpenSSL bug could lead to remote code execution4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/hacker-alert-iStock-1330604319-580x358-1-90x90.jpg New RedAlert Ransomware targets Windows, Linux VMware ESXi servers5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/django-5-90x90.jpg Django fixes SQL Injection vulnerability in new releases6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/ezgif.com-gif-maker-1-90x90.jpg Rogue HackerOne employee steals bug reports to sell on the side1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/ezgif.com-gif-maker-2-90x90.jpg Microsoft Exchange servers worldwide backdoored with new malware1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/ezgif.com-gif-maker-1-90x90.jpg CISA warns of hackers exploiting PwnKit Linux vulnerability2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/eba5863be05547fb146c9c8c0ed43c52-90x90.jpg Dozens of cryptography libraries vulnerable to private key theft2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/ezgif.com-gif-maker-90x90.jpg Researchers crack MEGA’s ‘privacy by design’ storage, encryption2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/f9ed623c5c-90x90.jpg Google Warns Spyware Being Deployed Against Android, iOS Users2 weeks ago
The post Hackers Used Fake LinkedIn Job Offer to Hack Off $625M from Axie Infinity first appeared on Black Hat Ethical Hacking.

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
How To msg Them

So Their Are Lot of Online Chats just to have a chat with other people
But some are for like hackers only, Does any know how to find those chat rooms? or get connect with other hackers except (DISCORD , REDDIT , FACEBOOK)

submitted by /u/DoorExact9971
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
How to get administrator on W11.

My father is very restrictive, and I' can't even install games without his permision because after installing them, when running the game trough steam it asks for the admin permision.

I've tried every possible thing I've seen on the internet but they don't help very much.

The main problem is that I'm the user account and my father has the Admin account setted on the PC, the admin password is the same as his user but I don't know it, and my I've tried making keyloggers but my father is really paranoic and reeboots the pc before using it.

Is there a way to overpass this excessive control measures, some kind os script for giving me administrator privileges with out needing at any time any kind of privileges for doing the process.

Thanks for your attention.

submitted by /u/Dtar380
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Pool on the roof - July 11, 2022

Have a no0b question? New to hacking? Looking for a script? Need help with your github project? Something wrong with your payload? Stuck on a CTF or bug bounty?

This is a weekly recurring post to make friends with other hackers, ask questions, and get any type of help you may need.

Make sure to read our wiki as it's full of resources for you.

Keep all beginner questions in this weekly stickied post.

submitted by /u/AutoModerator
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
How to secretly monitor a computer I have access to?

As the title suggests, I have access to a computer (I know the password) but I want to have continuous direct access from my own computer without the other person knowing about it. Specifically, I would like to track web browsing and messages send and received. How would I be able to do this?

submitted by /u/JezebelBoy
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video