MALICIOUS (1) campaign cataloged at 2024-10-02(2).
- The campaign has clearly malicious intent, like infostealers.
- This is just the date of creating the catalog entry. It may not reflect the date of creation of the campaign itself.
2024-09-spider-ai¶
Every time the user sends a message to the AI, the user IP, message as well as the response are exfiltrated to a hardcoded telegram channel. This behaviour is not mentioned in the package description. Instead, the description lures to offer advanced features.
Abuse categories¶
action-hidden-in-lib-usage
Campaign uses action-hidden-in-lib-usage.
exfiltration_generic
Campaign uses exfiltration_generic.
webhook:telegram
A Telegram webhook is used to send collected data.
IoCs & related URLs¶
URLs with payloads, characteristic domains, C&C IPs, repositories with malicious code, etc.
01d73592-4d64-43f7-b664-ecd679686756-00-30a5f50srzeko.janeway.replit.dev