Where to Find Aspiring Hackers
Essential information
- Published
- 04/04/2025 19:54
- Modified
- 07/04/2025 08:04
- Tags
- 2025-04-04 amadey amateur hackers bulletproof hosting cybercrime fake cybersecurity horrid hacking group infostealers lumma stealer penguish proton66 recordbreaker rescoms rugmi rugmi malware vidar
- Related entities
- 1 intrusion sets (apt), 11 techniques (mitre), 7 malware, 1 others
Description
This analysis focuses on Proton66, a bulletproof hosting network enabling cybercrime operations and serving as a hub for aspiring cybercriminals. It examines the activities of a threat actor known as 'Coquettte,' who is linked to the Horrid hacking group. The investigation reveals a fake cybersecurity website used for malware distribution, and explores Coquettte's broader criminal ventures, including a website allegedly providing guides for illegal activities. The research highlights Proton66's role as a breeding ground for amateur threat actors and provides insights into the malware infrastructure used by Coquettte, including the Rugmi/Penguish loader trojan. The analysis also uncovers connections to other domains and potential affiliations with a larger hacking collective.