=================================
== Investigations by 0xFantasy ==
=================================

Google: You Get an Open Redirect! You Get an Open Redirect!

default web appsec phishing
Google has a multitude of open redirects that are frequently abused by threat actors. They are used to both deter initial URL scanning and obfuscate the final phishing URL. A recent example of this in the wild found by KnowBe4 showcased combining multiple redirects in a row. Google seemingly has no interest in fixing these issues according to their VRP. These redirects span different Google domains and products including Search, Meet and Ads (formerly DoubleClick).

Trump Mobile: God Mode API Endpoint, Plaintext Passwords, and Mobile Device Identifiers

default web appsec
For an indeterminate amount of time, the Trump Mobile API had at least two unprotected endpoints that could be exploited for either a) mass general info disclosure or b) targeted and enumerable info disclosure including plain text passwords; full PII including name, address, and email; and unique mobile device identifiers inlcuding IMEI and ICCID.

No, your phishing kit does not have a Cloudflare bypass

default web phishing
Through my daily work and from reading quite a few blog posts, researchers consistently mistake that a phishing kit is leveraging /cdn-cgi/phish-bypass to hinder web and security scanners. This stems from a misunderstanding of what the Cloudflare /cdn-cgi/ endpoint is and how it operates.

Next-Gen Python Malware: Leveraging Astral's UV as a One-Shot Loader

default malware python
Python- and JavaScript-based malware has become increasingly popular within the last few years. Specifically, the DPRK’s Contagious Interview campaign has leveraged both languages using a variety delivery methods.

Telegra.ph: Malware, Scams, and Leaked Government Docs (Kinda)

default osint socialmedia malware
I’ve recently been doing some research regarding Telegram for work. This eventually led me to their sister platform, Telegra.ph. Simply put, Telegraph is a closed-source, minimalist, Pastebin-like site that allows anyone publish text-based content.

Weaponizing Unity Packages for Malware Delivery

default malware
I was recently talking to a handful of online friends about UGC (user generated content) creation within the Unity ecosystem. One of them jokingly mentioned how someone they knew was “ratted” by downloading an asset, that is usually behind a paywall, for free. Ratted from a Unity package?

How to Actually Secure Your X Account

default socialmedia
There has been a large increase in X account compromises over the past few months. As such, I wanted to compile a list of security policies and tips as well as common phishing tactics.

Investigating Hackers', Exploiters' Favorite Instant Crypto Exchange

default osint crypto vasp
If you’ve done any reading or sleuthing regarding the movements of funds after hacks, you’ve probably encountered eXchCX before. Incidents including but not limited to…

River Poker Casino Investigation

default osint crypto gambling vasp
This is one of two articles based on "prompted" investigations. Starting out with an initial question and/or piece of media, the investigation is still open ended.

Mujahideen Brigade Investigation

default osint crypto terrorism
This is one of two articles based on “prompted” investigations. Starting out with an initial question and/or piece of media, the investigation is still open ended.
1 of 1