vx-underground

vx-underground

@vxunderground · Twitter ·

Post attempt number four. I'm sorry to people who have notifications enabled and keep receiving notifications. tl;dr this is active goop, i am sharing the link because someone asked for Lua goop, but if you visit the GitHub it's not my fault if you download the .zip and accidentally run it (itll steal all your sensitive documents and passwords hehe) Someone asked where the Lua goop was, this is the Lua goop I discussed earlier today. This GitHub profile is an active (updated 9 hours ago) SmartLoader malware campaign. The repository "MicVST" masquerades as a legitimate open-source solution. However, the "How to Install" section in the ReadMe links to a .zip file which is the SmartLoader payload. The .zip contains Launcher.bat which executes the *.exe and tells the *.exe to read the *.txt. The *.txt file is obfuscated Lua which is piped into the *.exe. The *.exe is a Lua VM. This profile has been active on GitHub for about 3 months completely undetected. The SmartLoader campaign resolves an additional secondary GitHub page which acts as a configuration file for the SmartLoader payload, instructing it what to do. https://github.com/tenrececaudatusarmour182