Welcome to BlueTeamCoolTeam
So this is a thing now. BlueTeamCoolTeam is a personal blog where I’ll be publishing hands-on write-ups of real malware samples and incidents — the kind that show up on a Monday morning when someb...
So this is a thing now. BlueTeamCoolTeam is a personal blog where I’ll be publishing hands-on write-ups of real malware samples and incidents — the kind that show up on a Monday morning when someb...
A theory: 52.4% of 3,015 compromised WordPress sites run the exact version that patched wp2shell, a pre-auth RCE chain - and why that's not a coincidence.
ClickFix isn't a malware family - it's a grammar with two variables: which binary runs, and how its name is obfuscated. Eight confirmed vectors, reproducible.
A ClickFix stealer padded to 842MB that resolves its C2 from a Telegram bio and spawns a real Edge browser to beat App-Bound Encryption.
A Go-compiled Windows stealer hides its C2 address entirely, then reads it live from a Telegram channel bio and a Steam profile.
ClickFix keeps leaning on EtherHiding for C2 - combined with a prior investigation, this now accounts for over 3,500 compromised sites.
A second EtherHiding contract, a funding link, and a fully revalidated victim count: 1,829 confirmed hacked websites across two distinct kit families.
A JScript backdoor persists as a WMI ActiveScriptEventConsumer with no file on disk, resolving its C2 address by reading Ethereum smart-contract storage.

A ClickFix DLL side-load traced through a Polygon smart contract (EtherHiding) to 18 C2 domains and 153 confirmed hacked sites across three operators.
FakeNet-NG's WinDivert driver wouldn't load on my ARM Windows box, so I built feintnet: a single Go binary that fakes DNS, TLS, and C2 for malware analysis.