Welcome to BlueTeamCoolTeam
So this is a thing now. BlueTeamCoolTeam is a personal blog where I’ll be publishing hands-on write-ups of real malware samples and incidents — the kind that show up on a Monday morning when someb...
So this is a thing now. BlueTeamCoolTeam is a personal blog where I’ll be publishing hands-on write-ups of real malware samples and incidents — the kind that show up on a Monday morning when someb...
Agta returns: a Google share link, a fake Adobe update that installs ScreenConnect, then Agta pushed a day later. Same RAT build, new infra, 66 panels.
A phishing email disguised as a Webex invite led to four different remote-access tools chained together: Rocky RMM, ScreenConnect, and Level.io.
A successful first-try admin login and an unrestricted image upload turned into six disguised ASP.NET web shells sharing one hardcoded auth token, rcc68.
Seven ClickFix incidents, one primitive: rundll32 executes a remote DLL by ordinal over a WebDAV share mounted via @SSL - fileless, no SMB to block.
A theory: 52.4% of 3,015 compromised WordPress sites run the exact version that patched wp2shell, a pre-auth RCE chain - and why that's not a coincidence.
ClickFix isn't a malware family - it's a grammar with two variables: which binary runs, and how its name is obfuscated. Eight confirmed vectors, reproducible.
A ClickFix stealer padded to 842MB that resolves its C2 from a Telegram bio and spawns a real Edge browser to beat App-Bound Encryption.
A Go-compiled Windows stealer hides its C2 address entirely, then reads it live from a Telegram channel bio and a Steam profile.
ClickFix keeps leaning on EtherHiding for C2 - combined with a prior investigation, this now accounts for over 3,500 compromised sites.