FBI's CYBERCRIME CLEANUP: Four Sites Down, One Mystery Remains
The FBI has been playing whack-a-mole with cybercrime websites, seizing four notable forums and marketplaces last week. Cracked.io and Nulled.to, which range from “wannabe ethical hackers” to “full-on cybercriminal central,” have been taken offline. StarkRDP.io—an RDP hosting service with a suspiciously sketchy clientele—was also snatched up. And finally, MySellix.io, the Amazon for stolen goods, was supposedly seized… except it’s still up and running like nothing happened.
Why? Honeypot theory. The best way to catch cybercriminals is to let them log in as if nothing’s wrong and quietly collect their credentials. Picture a hacker entering their stolen login details only to realise they’ve just handed the FBI their entire criminal resume. Oops.
FACEBOOK DECLARES LINUX IS MALWARE: The Dumbest Thing This Week
In a mind-blowing display of tech illiteracy, Facebook’s internal policy makers have decided that Linux is malware. That’s right, the operating system that powers 96.6% of the top web servers, 70% of all global infrastructure, and Facebook’s own data centres has been flagged as a security risk.
Linux discussion groups? Banned.
Posts about Linux? Removed.
Facebook engineers trying to fix this nonsense… probably banned too.
This isn’t just dumb, it’s so dumb that it loops back around to being impressive. The best part? As of writing, some Linux links and posts are still flagged, so either Facebook’s AI has gone rogue, or Zuckerberg’s been tricked into thinking Windows XP is the future.
We can only hope they fix this soon, or that Facebook admits it’s actually the real malware.
FIRE SCAM MALWARE: When Free Telegram Premium Costs You Everything
If you're the kind of person who sees "Free Telegram Premium" and thinks "Oh sweet, free stuff!", congratulations, you’re exactly the target for Fire Scam, a nasty new Android malware.
Here’s the scam:
1. You visit a phishing site or even the RU Store, a Russian Android app store.
2. You download what you think is Telegram Premium, but surprise, it’s malware!
3. Fire Scam installs an infostealer, scanning for passwords, private keys, and session tokens.
4. Your sensitive data is exfiltrated faster than a crypto rug pull.
What makes Fire Scam particularly evil is its use of DexGuard, a tool normally used by game developers to prevent cheating. But in this case, it's being used to bypass antivirus detection**, making it **harder to detect than a government spy at a hacker convention.
So, lesson of the day: if something premium is offered for free, assume the only thing you’ll be getting is a virus and a very bad day.
FINAL THOUGHTS
This week’s cybersecurity news has it all the FBI setting honeypots, Facebook embarrassing itself on a global scale, and Android users getting owned for being cheap. If this trend keeps up, next week we might find out that Microsoft Word has been classified as a terrorist organisation or that Windows 11 is secretly mining Bitcoin for the NSA.
Stay safe out there, and remember:
- Don’t log into seized cybercrime sites.
- Linux is NOT malware (but Facebook’s brain might be).
- If it’s “too good to be true,” it’s probably stealing your data.
Breach Exposure Monitoring | Dark Web Monitoring + Surface Web Monitoring
Scan Any Domain for Free https://breachaware.com/scan
THIS MONTHS SPOTLIGHT, VULNERABILITY CHAT & PRIVACY HEADLINES
Ransomware incidents increased by 10% in 2024.
https://breachaware.com/research/ransomware-incidents-increased-by-10-percent-in-2024
A total of 13 breaches were found and analysed resulting in 9,885,988 leaked accounts containing a total of 23 different data types. The breaches found publicly and freely available included Job and Talent [2], XP Game Plus, Prixet Technology, Stealer Log 0502 and Maxxecom.
Fire scam malware masquerading as a Telegram premium app.
https://breachaware.com/research/fire-scam-malware-masquerading-as-a-telegram-premium-app
A total of 21 breaches were found and analysed resulting in 3,896,922 leaked accounts containing a total of 29 different data types. The breaches found publicly and freely available included Amai, Gift Flora, Religare Broking, Stealer Log 0503 and PnP.
Insurance company being sued for violating privacy of 45 million Americans.
https://breachaware.com/research/insurance-company-being-sued-for-violating-privacy-of-45-million-americans
A total of 36 breaches were found and analysed resulting in 9,251,596 leaked accounts containing a total of 37 different data types. The breaches found publicly and freely available included Guardian Industries, Ptt HGS, PPL Electric Utilities, Emias and Excellanto.
Your Router Might Be a Hacker’s Playground
https://breachaware.com/research/your-router-might-be-a-hackers-playground
A total of 26 breaches were found and analysed resulting in 10,232,404 leaked accounts containing a total of 34 different data types. The breaches found publicly and freely available included Chinese Software Developer Network (CSDN), Club Penguin Rewritten, Doxbin Paste, Stealer Log 0505 and bombuj.
BreachAware Insight
THE LATEST CURATED INTEL FROM OUR RESEARCH CENTREListen to our podcast, where Andrew, the visionary CEO of BreachAware, sits down with unsung heroes of the cyber security industry. Get ready to uncover the stories and insights of industry trailblazers you might not have heard of before, as they share their experiences, opinions, and insider intel. But beware, it's not all serious talk—expect a healthy dose of humour (and the odd cussing) sprinkled throughout the conversation.