Everyone on X was yapping about this Meccha Chameleon malware thingie. Internet nerds have been doing some internet detective research trying to find out who did it (I have no idea why, it was a relatively small malware campaign, there is much more dangerous malware than this).
Anyway, I bonked it with a stick.
> everyone yappin about this
> look inside
> goofy ahh batch file
> http downloads from ip address
> http? not https? what year is it?
> steamb.bat
> more ghetto batch files
> not obfuscated
> ok thanks i guess idk
> more http downloads
> makes fake microsoft security center folder
> ???
> downloads auto hot key script
> notes present
> AI GENERATED TRASH
> aes256 encrypted data blob
> fragmented
> all parts are labeled (part 1 - part 66)
> aes256 iv and key labeled
> ??? WHO IS THIS FOOLING BRO
> image 1
> make goopy python script
> add p1 - p66 together
> decrypt with documented aes256 keys
> lmfao wtf
> makes .exe
> look at .exe
> .NET c# goop
> first line of code
> EXTRACT PAYLOAD FROM RESOURCE SECTION
> ???
> encrypted, but encryption goopies still there
> image 2
> extract goopies
> another .exe
> slight attempt and obfuscation
> lol crypto stealer (image 3)
> other goop that looks like for RAT
SHA256: dc9a2f090f8d7ba31e1195573bbb5b1f0891f3b3722d8ad4c159f2519b1cb5b0
Anyway, I bonked it with a stick.
> everyone yappin about this
> look inside
> goofy ahh batch file
> http downloads from ip address
> http? not https? what year is it?
> steamb.bat
> more ghetto batch files
> not obfuscated
> ok thanks i guess idk
> more http downloads
> makes fake microsoft security center folder
> ???
> downloads auto hot key script
> notes present
> AI GENERATED TRASH
> aes256 encrypted data blob
> fragmented
> all parts are labeled (part 1 - part 66)
> aes256 iv and key labeled
> ??? WHO IS THIS FOOLING BRO
> image 1
> make goopy python script
> add p1 - p66 together
> decrypt with documented aes256 keys
> lmfao wtf
> makes .exe
> look at .exe
> .NET c# goop
> first line of code
> EXTRACT PAYLOAD FROM RESOURCE SECTION
> ???
> encrypted, but encryption goopies still there
> image 2
> extract goopies
> another .exe
> slight attempt and obfuscation
> lol crypto stealer (image 3)
> other goop that looks like for RAT
SHA256: dc9a2f090f8d7ba31e1195573bbb5b1f0891f3b3722d8ad4c159f2519b1cb5b0
π34β€18π€£8π±6π₯2
vx-underground
Everyone on X was yapping about this Meccha Chameleon malware thingie. Internet nerds have been doing some internet detective research trying to find out who did it (I have no idea why, it was a relatively small malware campaign, there is much more dangerousβ¦
This thingie
β€60π₯5β€βπ₯1
Also, apparently Meccha Chameleon people follow me on Telegram.
Hello MecchaChameleon malware people living inside my computer,
I think overall your strategy of using a malicious custom map thingie was cool and probably yielded moderate success. I don't think your intention was being like, 100,000 infected machines, but I suspect you got enough infected machines to be happy. People wrote you were using PureRAT, whether or not that is true, I don't know, YARA rules for flagging can be iffy.
But, when I was reverse engineering your C# payload (which I think you attempted to obfuscate?) I saw the weird dependency you used for remote access to machines. I can't remember what it was now, I deleted your goopies off my machine, but I saw it as an embedded resource next to PAYLOAD_ULTRA_MEGA_FUCK_OFF.zip which you decrypted and loaded as a raw assembly. Maybe that raw assembly you loaded was PureRAT? Or was it the stager? I don't know.
Obviously we've been this a million times before with other video games (malicious mods), but seeing it in something obscure was a nice surprise. Your advertisement, or demo, or whatever, you showed was not an RCE. An RCE would require ... remote code execution. This is really fancy payload smuggling.
Anyway, it's obvious your staging was vibe coded. It was pretty easy to reverse engineer. I think you had the right idea on how to go about things, but between the segments being in order (1 - 66), the obvious embedded payload in the 2nd stager, and the really loud BATCH files, it wasn't going to go very far.
Thanks for the goopies though, it was chill.
Cheers,
(pic unrelated)
Hello MecchaChameleon malware people living inside my computer,
I think overall your strategy of using a malicious custom map thingie was cool and probably yielded moderate success. I don't think your intention was being like, 100,000 infected machines, but I suspect you got enough infected machines to be happy. People wrote you were using PureRAT, whether or not that is true, I don't know, YARA rules for flagging can be iffy.
But, when I was reverse engineering your C# payload (which I think you attempted to obfuscate?) I saw the weird dependency you used for remote access to machines. I can't remember what it was now, I deleted your goopies off my machine, but I saw it as an embedded resource next to PAYLOAD_ULTRA_MEGA_FUCK_OFF.zip which you decrypted and loaded as a raw assembly. Maybe that raw assembly you loaded was PureRAT? Or was it the stager? I don't know.
Obviously we've been this a million times before with other video games (malicious mods), but seeing it in something obscure was a nice surprise. Your advertisement, or demo, or whatever, you showed was not an RCE. An RCE would require ... remote code execution. This is really fancy payload smuggling.
Anyway, it's obvious your staging was vibe coded. It was pretty easy to reverse engineer. I think you had the right idea on how to go about things, but between the segments being in order (1 - 66), the obvious embedded payload in the 2nd stager, and the really loud BATCH files, it wasn't going to go very far.
Thanks for the goopies though, it was chill.
Cheers,
(pic unrelated)
π€£80β€15π₯°7π₯1
Dawg, I don't want to sound like a hater, but you need to CHILL OUT.
Your goopies just got attention because it was video game goop. This isn't like, CL0P ransomware group extorting the United States government for $50,000,000 because of a 0day exploit they had.
You're NOT FBI most wanted, bro. They're worried about big malware campaigns. The internet has crypto-drainers bringing in $100,000/month, CSAM all over TOR, large-scale botnets wreaking havoc on home users, businesses, and critical infrastructure, and they're also dealing with state-sponsored Threat Groups which are enemies of the United States.
You popping 50 people from Schlunko McSchmeeSchmee on Steam isn't going to make Kash Patel call the President of the United States and say you're El Chapo 2.0. This only got attention because it was on Steam
Gosh dang, bro. Relax. Half these fucking people on social media talking about it unironically spend a majority of their day scrolling TikTok and arguing in the comment section on YouTube videos. It's not that deep, bro.
Your goopies just got attention because it was video game goop. This isn't like, CL0P ransomware group extorting the United States government for $50,000,000 because of a 0day exploit they had.
You're NOT FBI most wanted, bro. They're worried about big malware campaigns. The internet has crypto-drainers bringing in $100,000/month, CSAM all over TOR, large-scale botnets wreaking havoc on home users, businesses, and critical infrastructure, and they're also dealing with state-sponsored Threat Groups which are enemies of the United States.
You popping 50 people from Schlunko McSchmeeSchmee on Steam isn't going to make Kash Patel call the President of the United States and say you're El Chapo 2.0. This only got attention because it was on Steam
Gosh dang, bro. Relax. Half these fucking people on social media talking about it unironically spend a majority of their day scrolling TikTok and arguing in the comment section on YouTube videos. It's not that deep, bro.
π€£152π₯14β€8π«‘5π3
vx-underground
Dawg, I don't want to sound like a hater, but you need to CHILL OUT. Your goopies just got attention because it was video game goop. This isn't like, CL0P ransomware group extorting the United States government for $50,000,000 because of a 0day exploit theyβ¦
I know I probably shouldn't tell someone who committed a felony to relax, but let's be real here, bro. FBI agents are paid like shit and they're dealing with serious problems, Schlunko McSchmeeSchmee isn't even on their radar. They probably don't even feel like doing the paperwork, some agent probably saw it, said "heh", and went back to some case where someone is laundering $10,000,000 of Bitcoin
How much money was stolen? What? Like $700? The FBI doesn't even look at you until you've done somewhere between $100,000 - $1,000,000. It costs them $200/hr for the attorneys alone, not to mention the man hours to talk to Steam, do the court paperwork, subpoena people, determine which field office is going to handle.
I don't know bro, whatever
How much money was stolen? What? Like $700? The FBI doesn't even look at you until you've done somewhere between $100,000 - $1,000,000. It costs them $200/hr for the attorneys alone, not to mention the man hours to talk to Steam, do the court paperwork, subpoena people, determine which field office is going to handle.
I don't know bro, whatever
β€88π―16π₯10π€£4
vx-underground
> check social media > internation cyber news digest posts > doxes some kid > nice broccoli haircut tho > nerd allegedly part of meccha chamelon thingie > worker or smthn, idfk > shows discord cam thingie > records his face > idk why > flexes $50,000 > idkβ¦
fr tho bro, if youre going to commit crime, launder money, whatever, dont show ur face on discord calls or flex bro, cmon man
π€£120β€8π4π€―2π’1π―1
GrapheneOS is cool and badass
β€187π―37π28π€£8π6π€5π₯4π4β€βπ₯1π₯°1π1
My wife and I frequently yell "HELP!" when we need help with the baby.
He is 17 months and he is crazy.
The good news is that he has suddenly began screaming "HELP" in public with zero context.
It's fun holding a baby and he screams "HELP!" around a bunch of strangers.
He is 17 months and he is crazy.
The good news is that he has suddenly began screaming "HELP" in public with zero context.
It's fun holding a baby and he screams "HELP!" around a bunch of strangers.
π€£231π29π«‘12β€6π₯°5π€2
vx-underground
> check twitter > account locked > ??? > DMCA takedown request > ??? > click see post > rockstar games compromise post > shows GTA 6 testing footage > 8:51 AM Β· Sep 19, 2022 you fucking assholes hit me with a DMCA takedown request on a video from 2022? seriously?
Marek, you goofy son of a bitch, with your goofy ass man-bun and bullshit risk compliance job, it isn't AI generated footage you lying little bitch.
If you're going to file a DMCA takedown request, you should write it's because RockStar games was compromised by an autistic teenager in the UK who social engineered HelpDesk support from an Amazon FireStick in a hotel room
I obviously can't file a counter claim, I'm a stinky nerd and you're representing a multi-billion dollar company, but I want you to know that you're a pussy and nobody at your job respects you
Have a nice day
If you're going to file a DMCA takedown request, you should write it's because RockStar games was compromised by an autistic teenager in the UK who social engineered HelpDesk support from an Amazon FireStick in a hotel room
I obviously can't file a counter claim, I'm a stinky nerd and you're representing a multi-billion dollar company, but I want you to know that you're a pussy and nobody at your job respects you
Have a nice day
π₯162π€£56π19β€11β€βπ₯2π€2π1
vx-underground
Marek, you goofy son of a bitch, with your goofy ass man-bun and bullshit risk compliance job, it isn't AI generated footage you lying little bitch. If you're going to file a DMCA takedown request, you should write it's because RockStar games was compromisedβ¦
Okay, maybe I'm a little annoyed, I'm sorry. Please excuse my language. I'm hungry and tired.
π’75π«‘30π17β€6π€4β€βπ₯3π₯1
This media is not supported in your browser
VIEW IN TELEGRAM
> download weird .exe
> accidentally run it
> disappears in the void
> accidentally run it
> disappears in the void
π74π€£37β€10π±5π«‘4π₯2β€βπ₯1