Testing Fileless Malware that works on Every Operating System

preview_player
Показать описание
In this video I investigate & reverse engineer an infostealer + clipper that works on Windows, Linux & macOS.
CORRECTION: Syndott is a real Software development house who were targetted by sophisticated threat actors (the same people responsible for what almost happened to our freelancer). They are not involved in this attack

Disclaimer: The content in this video is for education and entertainment purposes to showcase the dangers of malware & malicious software. I do not encourage any form of illegal hacking, nor do I encourage the usage of game cheats, cracks or hacks.

Cracks are sometimes shown to highlight the dangers of software piracy, my content is not intended to teach anybody how to pirate, or maliciously hack.

More Malware Investigation Videos:

(C) Eric Parker 2024
Рекомендации по теме
Комментарии
Автор

Syndott (The real one) responded, what appears to have happened here is a deep ID fraud targeting them. All of their online accounts were taken over, including the domain, which is why things looked as sketchy as they did.

I wanted to pin a comment to highlight that (along with a description edit). I am assuming that every company who's name & likeness was used here is legitimate (& unrelated to the attack).

EricParker
Автор

we got cross platform viruses before bloodborne on PC

JoCaTen
Автор

All those people saying "Yeah but it doesn't work on TempleOS" istg i'm gonna make a virus specifically for this

Golem
Автор

So funny that the payload was formatted in a single line of code. It's like a reverse form of Security through Obscurity.

DirectionD
Автор

0/10 virus. cant install on my psp. won't use anytime soon

cscscscss
Автор

Finally, a virus that works on every platform

Though I can’t seem to get it to run on my 3DS…must be a work in progress

MiiniStar
Автор

This looks really interesting! Also the attacker didn't seem to provide any release packages. I am wondering if this could be behind some social engineering attempts to compromise developers or companies by submitting fake inquiries or collabs requests. A cool find indeed!

Edit: You can use git scm on Windows. There is even a portable version and it runs on Windows 10 out of the box. :)

muB
Автор

I approach all interactions on the internet where someone comes to me with a question, shares a program, or offers something either privately or publicly with the base assumption that it's a social engineering or malware attempt. Other people don't, and while I appreciate that people trust me not to be malicious, the lack of concern and how easily they say yes is uncomfortable. "Thanks for your trust. Don't do it again."

cinderwolf
Автор

jRat was crossplatform developed in like 2010-2011 using java and was promoted/sold on hackforums. It had its own issues where you could pwn the C&C server. The scary part was that when jRat was released, most AV software didnt even care to scan java files and whitelisted the JVM, so it was undetected for weeks/months on release.

unknowntotherestoftheworld
Автор

But the real question will this work on MS-DOS

sfisher
Автор

we got Non-OS-Racist/All OS Inclusive Viruses before GTA 6 and Half-Life 3

sillyGooberHamza
Автор

Great video. Really like your explenations, you should consider creating a tutorial about reverse engeneering, so a full course or something.

oliver-nation
Автор

You always bring awesome stuff and almost 100k congrats!

ClassicGameHacking
Автор

All platforms, except the one with the yellow lines

hhhllkk
Автор

7:49 this number will haunt me forever....

ilia-live
Автор

Nah, NPM doesn’t care about MITM attacks. It just happily ignores the Windows certificate store.

Kwpolska
Автор

True compatibility some games just wish for

didu
Автор

Can you do a video on the pirated games scene like IGG-Games or other uploaders?

PvPsFinests
Автор

i got a question when i downloaded a crack software it got a virus but the virus is different, it can upload youtube videos with out logging in my google acc. there's no notifi that my google has been login.

MurasakiShizu
Автор

At this point base64 should be worth investigating in any script.

vidal