216.73.216.36

Amateur Hacker Leverages Bulletproof Hosting Server to Spread Malware

· Published 03/04/2025 17:18 · Modified 03/04/2025 18:31

Export JSON

Essential information

Published
03/04/2025 17:18
Modified
03/04/2025 18:31
Tags
2025-04-03 amadey amateur hacker bulletproof hosting cybercrime incubator fake antivirus horrid collective illegal guides lumma stealer proton66 raccoon stealer v2 rescoms rugmi vidar
Related entities
6 observables, 1 intrusion sets (apt), 13 techniques (mitre), 6 malware, 1 others

Description

A novice cybercriminal, known as 'Coquettte', has been discovered using a Russian provider, , to distribute malware. The hacker's activities include deploying the malware loader through a fake cybersecurity product website and selling guides for illegal substances and weapons. Coquettte is believed to be part of a loosely structured hacking collective called Horrid. The threat actor's infrastructure spans multiple domains and platforms, including GitHub, YouTube, and Last.fm. This network appears to serve as an incubator for aspiring cybercriminals, offering malware resources, hosting solutions, and a collaborative environment for underground hacking activities.

External references