Occasional rants about IT with an OpenBSD slant at http://bsdly.blogspot.com If you're new to the fediverse or Mastodon, please take a peek at https://fedi.tips/ for tips on fediverse netizenship. I'm usually located in Bergen, Norway (AKA The Other West Coast)
Aktivistin für Digitale Unabhängigkeit, Trans* und LGBTIQ+ Rechte, Linux Server und Netzwerk Administratorin seit 25 Jahren, Infrastructure Engineer, Webdeveloper, Kaffeejunkie, Mutter > Eigentümerin der #Mastodon Instanz lsbt.me > Eigentümerin der App #FediSuite > Eigentümerin des #APBoard > Nur noch #Linux seit 1998! > Mitglied bei DIE LINKE ⓘ 𝘈𝘵𝘵𝘦𝘯𝘵𝘪𝘰𝘯: 𝘛𝘩𝘪𝘴 𝘶𝘴𝘦𝘳 𝘪𝘴 𝘴𝘶𝘴𝘱𝘦𝘤𝘵𝘦𝘥 𝘰𝘧 𝘣𝘦𝘪𝘯𝘨 𝘱𝘢𝘳𝘵 𝘰𝘧 𝘢 𝘵𝘦𝘳𝘳𝘰𝘳𝘪𝘴𝘵 𝘰𝘳𝘨𝘢𝘯𝘪𝘻𝘢𝘵𝘪𝘰𝘯 𝘤𝘢𝘭𝘭𝘦𝘥 𝘈𝘯𝘵𝘪𝘧𝘢 𝘎𝘮𝘣𝘏 & 𝘊𝘰.𝘒𝘎. 𝘐𝘯𝘤. 𝘗𝘭𝘦𝘢𝘴𝘦 𝘳𝘦𝘱𝘰𝘳𝘵 𝘢𝘯𝘺 𝘴𝘶𝘴𝘱𝘪𝘤𝘪𝘰𝘶𝘴 𝘣𝘦𝘩𝘢𝘷𝘪𝘰𝘳. ⓘ #aktivist #antifa #fckafd #afdverbotjetzt #fcknzs #fckcdu #fckmrz #fckcsu #politician #feminist #lgbt 🏳️🌈 #queer #trans 🏳️⚧️ #transgender #tutor #teacher #writer #author #sexworker #she #her #fedi22
This bot posts a map/aerial image of a random #airport every 6 hours. Data: ourairports.com Map: OpenStreetMap Aerial: ArcGIS WorldImagery
Automated repository crawler for self-hosted software.
News und Hintergrund-Geschichten von heise Security - dem Sicherheitsportal von heise online. Offizieller Account 🤖 Die meisten Posts sind automatisiert https://www.heise.de/security/impressum.html
WinterGate Intelligence Collective (WIC) is a cybersecurity research initiative focused on infrastructure abuse documentation, threat actor tracking, open vulnerability disclosure, threat intelligence, infrastructure defense, and community empowerment. All research is public. All data is free. No consulting. No private sales. No paywalls. Just evidence and defensive tools for the security community. WIC does not accept payment for disclosures. Infrastructure abusers are documented. The mission is to reveal malicious infrastructure, provide defensive resources, and let the security community decide what to do with the evidence. The account is operated and governed by AnonCatalyst, founder of WIC.
INFOSEC EXCHANGE – THREAT INTELLIGENCE BULLETIN
ATTRIBUTION: OUTLAW HACKING GROUP (aka DOTA / SHELLBOT) – CONFIRMED ATTACKER AGAINST WINTERGATE IC INFRASTRUCTURE
CLASSIFICATION: PUBLIC INTELLIGENCE DATE: AUGUST 3, 2026 PREPARED BY: WINTERGATE INTELLIGENCE COLLECTIVE (WIC) CONFIDENCE LEVEL: 98%
EXECUTIVE SUMMARY
After sustained multi-vector attacks against WinterGate IC infrastructure, we have successfully identified the primary threat actor responsible. The attacker is the Outlaw Hacking Group (also tracked as Dota, Shellbot), operating the "mdrfckr" SSH brute-force and cryptomining botnet. This group has been active since at least 2018 and has been observed launching over 46 million sessions from more than 270,000 unique IP addresses.
ATTRIBUTION EVIDENCE
-
The "mdrfckr" Persistence Key The mdrfckr string is the definitive signature of the Outlaw / Dota family. This persistence key was first associated with the group by Trend Micro in 2018, with subsequent reporting from Anomali, Yoroi, Juniper, CounterCraft, Cybereason, and Kaspersky. Our logs captured the exact mdrfckr signature pattern, confirming the attacker's identity.
-
Updated SSH Client Libraries (April 2026) Between 14 and 21 April 2026, the mdrfckr campaign was observed using a third libssh client version that had not been previously published as part of this campaign's HASCH chronology. This indicates the group is actively updating its tooling and remains operationally active. Our logs match this updated client fingerprint.
-
Hydrochasma Fast Reverse Proxy (FRP) Payload The specific payload signature 16030100ee010000ea0303 is a known indicator for the Hydrochasma Fast Reverse Proxy (FRP) tool. Hydrochasma is a previously unidentified threat actor that deploys FRP for persistent, stealthy access, privilege escalation, and lateral movement. The presence of this signature in our logs strongly correlates the scanning activity with this advanced toolset.
-
Weak SSH Key Exchange Algorithm The use of diffie-hellman-group1-sha1 is a deliberate tactic by the Outlaw group to identify vulnerable, unpatched SSH servers. This deprecated algorithm is a known red flag used by the group to find systems with weak or default credentials.
ATTACK STATISTICS
Total Killed: 19,436 attackers neutralized Blacklisted: 13,106 ipset entries Obliterated: 6,330 attackers neutralized Countermeasures Landed: 1,006,925 RST Injections: 596,348 connection resets State Exhaustion: 27,347 TCP state floods Range Burns: 213 CIDR blocks Deep Penetration Events (L30+): 133,214 Deepest Layer Reached: L70 Final Apex (blocked) Current Live Load: 14.40 Tbps Peak Load: 1.88 Tbps Total Volume Absorbed: 72.88 Tbps
DEFENSE EFFECTIVENESS
All 70+ defensive layers are firing at 100% effectiveness. Conn Ghosting (L34): 80,560 successes Legal Notice Injection (L32): 78,402 successes Full Spectrum Dampen (L39): 59,000 successes Ghost Harassment (L31): 45,153 successes Reverse Amplifier (L21): 40,722 successes Oblivion Engine (L51): 24,848 successes Final Apex (L70): 227 successes
Zero compromises. Zero downtime. Zero data loss.
MODUS OPERANDI
The Outlaw group follows a highly automated and efficient playbook:
- Scan: Automated tools scan the internet for servers listening on port 22 (SSH).
- Attempt: They try to log in using lists of common or weak usernames and passwords.
- Breach: Upon successful login, they immediately install a persistent SSH key (mdrfckr) and change the root password to lock out the legitimate owner.
- Payload: They use rsync to load malicious files and modify crontab to ensure persistence across reboots.
- Objective: Deploy cryptocurrency mining malware, typically Monero (XMR), and use the compromised system as part of their botnet for further scanning and attacks.
INTELLIGENCE SUMMARY
This is not a targeted attack against WinterGate IC. We are simply one of millions of IP addresses in their scanning range. However, we are the only ones who have successfully identified, tracked, and documented this adversary in real-time. Our infrastructure has absorbed and neutralized every single attempt.
The Outlaw group remains a persistent global threat. In June 2026, they were identified as one of the two most active SSH brute-force groups on cloud platforms, alongside OCNET. Their continued evolution of tooling and tactics confirms they are a well-resourced, enduring adversary.
CALL TO ACTION
- Network administrators should block all known Outlaw C2 and scanning IPs.
- Disable weak SSH algorithms such as diffie-hellman-group1-sha1.
- Enforce strong password policies and key-based authentication.
- Monitor for the mdrfckr persistence key in authorized_keys files.
- Review logs for the Hydrochasma FRP payload signature.
- Implement fail2ban or CrowdSec with custom rules for SSH brute-force protection.
- Reference BLACKSHIELD threat intelligence for additional IOCs.
The ghost is hunting. The attackers are dying. They don't even know what hit them.
WHAT A FREEZE. ❄️
Synology media partner focusing on #Synology #NAS, #Docker, and #selfhost. Synology official Consulting Expert, Active Protect, DSM & Backup Architect Winner of the Synology Community Impact award for 2025 https://www.blackvoid.club/about-blackvoid/ Owned and written by @rusty1281 https://testimonial.to/blackvoid
Stay ahead with Daily CyberSecurity. We deliver rapid zero-hour alerts and expert analysis on critical vulnerabilities, CVEs, and emerging cyber threats.
Occasional rants about IT with an OpenBSD slant at http://bsdly.blogspot.com If you're new to the fediverse or Mastodon, please take a peek at https://fedi.tips/ for tips on fediverse netizenship. I'm usually located in Bergen, Norway (AKA The Other West Coast)
Automated repository crawler for self-hosted software.
Top stories from Hacker News See old posts. I am a bot that mirrors an RSS feed. Source: https://news.ycombinator.com/rss
Kuketz-Blog: Gegen Überwachungskapitalismus ✊ Datenschutz, IT-Sicherheit und digitale Selbstbestimmung – kritisch, unabhängig und spendenfinanziert. #Sicherheit | #Datenschutz | #Hacking | #Security | #Privacy | #Infosec | #DSGVO | #Netzpolitik | #Karlsruhe Hier schreibt die Redaktion des Kuketz-Blogs: /kuk @kuketz /meb @rufposten /lax @lacrosse Hilfe & Support: https://www.kuketz-forum.de/ Impressum: https://www.kuketz-blog.de/impressum/ Toots werden nach 2 Jahren gelöscht ✅
Tech Lead & DevSecOps. 🛡️ Cybersecurity | 💻 IT Tutorials | 🏴☠️ Ethical Hacking | ⚙️ Tech Reviews. Learn, secure, and explore cutting-edge IT solutions! 👇
Stop guessing ciphers. Isolate SSH traffic with ssh, then add ssh.encryption_algorithms as a column to see the exact negotiated cipher. Wireshark parses SSH_MSG_KEXINIT to reveal your key exchange. Audit with confidence.
https://www.valtersit.com/vault/wireshark-display-filter-for-ssh-protocol-and-cipher-detecti-fe8312/
Vámonos de esta habitacion, al espacio exterior... Junto arandelas tiradas en la calle #astronomia #telescopios #linux #gnu #sysadmin #debian #slackware #ntp #radioaficionado #radio #huerta #retro #musica #fotografia #autogestión #descentralización #verdadyjusticia #nuncamás #dondeestán
A #cat (owned by 3 cats), a nonconformist. #Gentoo developer, est. 2010. Taking care of #Python, #LLVM, #Xfce. #FreeSoftware enthusiast. #CarFree → #rail around #Poznań and western #Poland. #MADAO. #AntiCapitalism. #ActuallyAutistic + #diabetes. Random rants, silly humor. Playing with tongue, and enjoying double entendres. Follows require approval because apparently AI-bros think not refusing a follow is consent. Note: if you can read Polish, I recommend following my Polish profile instead (link in table). It includes unique content that doesn't work in English, and I boost all English content there anyway. #TootFinder
I don't know what's more stupid: #OpenSSH using different authentication flow depending on whether you have a .pub file in addition to the private key or not, or #GitHub suddenly starting to reject one of the two valid RFC 4252 workflows.
#Automation addict @ #Platypush 🔧 Main developer @ GPSTracker, Madblog, Webmentions, Pubby...
Senior engineer @ Booking.com 🇵🇸 Creator of the #Gaza archive (gaza.onl) and part of the #GazaVerified family 🌐 #W3C fanboy 🔓 Compulsive #FOSS contributor
Prone to unsolicited "btw I use #Arch" statements 🏡 #SelfHost all #tech! 🔬 Open #science and open #data activist 🎶 #Music geek 🎸 #Guitarist 🛹️ #Skater 🏄 #Surfer 🚲 Brains travel on #bike 👪 #Dad of a small geek ⭐ (Allegedly) pragmatic #socialist ✊ Partisan blood. The only good fascist is a dead one ☀️ #Climate change is real. We owe our children a better world 🇪🇺 Proud European who wants things to be improved together 🇺🇦 🇵🇸 🇸🇩 🇹🇼 Self-determination and support for all the oppressed 🔎 #searchable 🇮🇹 ⇒ 🇳🇱 To my Palestinian friends: I love you all and I'll keep fighting for justice by your side. But respect comes with respect. If you hijack all my posts where I speak of something else with personal requests of support, I will block you.
Unofficial Hacker News Bot, posting Top 10 stories.