Skip to content

Instantly share code, notes, and snippets.

View brkalbyrk's full-sized avatar

Berk ALBAYRAK brkalbyrk

View GitHub Profile
@brkalbyrk
brkalbyrk / INFO_V8_Javascript_Engine_Jul_11.yar
Created July 10, 2024 21:58
This rule detects files compiled by the V8 Javascript engine.
import "pe"
rule INFO_V8_Javascript_Engine_Jul_11 : INFO JS COMPILER {
meta:
description = "This rule detects files compiled by the V8 Javascript engine."
author = "@brkalbyrk7"
date = "2024-07-10"
sharing = "TLP:WHITE"
tags = "info,javascript,compiler"
reference = "https://github.com/v8/v8"
# Commands
**All Available Commands:**
`help` - Displays a list of commands.
`ping` - Check system status and IP
`screenshot` - Take a screenshot
`download <filepath>` - Download a file C:/path/to/file.txt.
`killself` - Terminates itself with aura.
`delete <path>` - Deletes the specified file or folder. Ex: delete C:/path/to/file.txt
`cmd <command>` - Runs a command in CMD and returns the result.
`dir <optional path>` - Shows the current directory. This can be changed by putting a directory next to it.
@brkalbyrk
brkalbyrk / AMOS.txt
Created December 15, 2025 21:37
AMOS Stealer Domains - 16.12.2025
# AMOS Stealer Domains - 16.12.2025
jmpbowl[.]xyz
jmpbowl[.]space
elfrodbloom[.]coupons
argoflyleens[.]space
kjvnsrux[.]frozendoome[.]com
slabiflc[.]ergodown[.]com
gmiyhkzh[.]ergodown[.]com
gulgivmu[.]apple-pkgs[.]com
filebreef[.]com
@brkalbyrk
brkalbyrk / Shubv2.0.md
Last active March 27, 2026 20:36
SHub Stealer v2.0

SHub Stealer v2.0

Malware: SHub Stealer v2.0 Type: macOS AppleScript Infostealer Delivery: ClickFix (fake Apple security update) C2: wewannaliveinpice[.]com
SHA256 (payload): 8ef539340b4f8271ed783223b3e49b7b8099381c6439024e7407474698fe9f10


@brkalbyrk
brkalbyrk / MacSync.md
Created March 30, 2026 21:46
MacSync Stealer — Build: c3 | v1.1.2 | IOCs

MacSync Stealer — Build: c3 | v1.1.2 | IOCs

Last updated: 2026-03-30

Clickfix URLs

hxxps://index.orbitstreamvault4[.]lat/c3/?c=AM6HwGmifAUAvYwCAElUOQASAAAAAAA-
hxxps://filealphaweave[.]com/c3/?c=ANIbyWn3bQUAvYwCAEZSOQAZAAAAAACr
hxxps://fileomegaform[.]com/c3/?c=ALL-x2lxgAUAvYwCAElOOQAZAAAAAACZ
hxxps://index.nebulasyncforge4[.]baby/c3/?c=ABYAxmmifAUAvYwCAENMOQAZAAAAAAAx
hxxps://upsreit[.]com/c3/?c=AL2bvGmifAUAvYwCAE1YOQAZAAAAAACs
@brkalbyrk
brkalbyrk / MacSync_02042026.md
Created April 2, 2026 18:00
MacSync Stealer — Build: c3 | v1.1.2 | IOCs

MacSync ClickFix domains

filesolarpatch[.]com
filecybertrail[.]com
ultranodecluster1[.]homes
ultranodecluster2[.]homes
ultranodecluster3[.]homes
ultranodecluster4[.]homes
ultranodecluster5[.]homes
index[.]orbitstreamvault4[.]lat
@brkalbyrk
brkalbyrk / MacOS_Github_Themed_Clickfix_16052026.md
Last active May 17, 2026 01:02
MacOS_Github_Themed_Clickfix_16052026

Clickfix Github Themed MacOS Infostealer Deliver Campaign IOCs

C2 Domains

share2e32git.sbs
plombirsirni.com

Clickfix Pages

anydomen.info
@brkalbyrk
brkalbyrk / DriveSurge_Campaign_Stealer.md
Created August 10, 2026 21:36
macOS Stealer (DriveSurge campaign / fake com.apple.syslogd)

IOCs

Stealers observed in the DriveSurge campaign (Silent Push: ClickFix + fake update driveby attacks on thousands of compromised sites). Two stage macOS malware with dedicated arm64 (Apple Silicon) and x86_64 (Intel) builds, obfuscated bash loader → ~30MB Garble Obfuscated Go stealer. Steals 100+ crypto wallets, macOS Keychain, browser creds/cookies, SSH/GPG keys. Patches Atomic Wallet & Exodus Electron apps to intercept passwords. Shows fake Ledger Live / Trezor Suite "security update" dialogs to phish 24-word seed phrases. Persistence via LaunchAgent + ~/.persistenced.

C2 / Telemetry Servers (POST /api/t)

http://89.208.97.111:8133/api/t
http://45.155.71.15:8133/api/t
http://213.165.42.172:8133/api/t