Amateur Hacker Leverages Bulletproof Hosting Server to Spread Malware
Essential information
- Published
- 03/04/2025 17:18
- Modified
- 03/04/2025 18:31
- Tags
- 2025-04-03 amadey amateur hacker bulletproof hosting cybercrime incubator fake antivirus horrid collective illegal guides lumma stealer proton66 raccoon stealer v2 rescoms rugmi vidar
- Related entities
- 6 observables, 1 intrusion sets (apt), 13 techniques (mitre), 6 malware, 1 others
Description
A novice cybercriminal, known as 'Coquettte', has been discovered using a Russian bulletproof hosting provider, Proton66, to distribute malware. The hacker's activities include deploying the Rugmi malware loader through a fake cybersecurity product website and selling guides for illegal substances and weapons. Coquettte is believed to be part of a loosely structured hacking collective called Horrid. The threat actor's infrastructure spans multiple domains and platforms, including GitHub, YouTube, and Last.fm. This network appears to serve as an incubator for aspiring cybercriminals, offering malware resources, hosting solutions, and a collaborative environment for underground hacking activities.