{
"$type": "site.standard.document",
"bskyPostRef": {
"cid": "bafyreic2kggl7jpmi2q6vwxsi333mjyvj5ix7e5lnwuo7hfy2x2pbs6w5q",
"uri": "at://did:plc:wnd7xrumusq5uayjfi2pgfno/app.bsky.feed.post/3mey5y5dh6pg2"
},
"coverImage": {
"$type": "blob",
"ref": {
"$link": "bafkreibil6zgyjonrnvylvt74s3egzs2koj2zxnengfjiajez3tkdekwxu"
},
"mimeType": "binary/octet-stream",
"size": 517071
},
"description": "TL;DR\n\n * DHS subpoenas tech firms to unmask anonymous anti-ICE social media accounts\n * Trojanized 7-Zip Installer Distributes Proxyware via Residential Proxy Network\n * Lumma Info-Stealer Delivered via Google Groups Social Engineering Campaign\n\n\nđ¨ DHS Doxxes 300 Anti-ICE Accounts With No Warrant â Google, Meta Comply Without Judicial Oversight\n\n300 ANONYMOUS ACCOUNTS DOXXED BY DHS WITHOUT A WARRANT. đ¨ Google, Meta, Reddit, Discord handed over emails, IPs, credit card last-4s⌠for posting âIC",
"path": "/2026-02-16-79378380632678398519566125946557523026/",
"publishedAt": "2026-02-16T13:32:19.000Z",
"site": "https://espresso.cafecito.tech",
"tags": [
"@-ing"
],
"textContent": "### TL;DR\n\n * DHS subpoenas tech firms to unmask anonymous anti-ICE social media accounts\n * Trojanized 7-Zip Installer Distributes Proxyware via Residential Proxy Network\n * Lumma Info-Stealer Delivered via Google Groups Social Engineering Campaign\n\n\n\n* * *\n\n## đ¨ DHS Doxxes 300 Anti-ICE Accounts With No Warrant â Google, Meta Comply Without Judicial Oversight\n\n> 300 ANONYMOUS ACCOUNTS DOXXED BY DHS WITHOUT A WARRANT. đ¨ Google, Meta, Reddit, Discord handed over emails, IPs, credit card last-4s⌠for posting âICE is evilâ. No judge. No crime. Just a subpoena and a corporate shrug. You think your âprivateâ DMs are safe? Try telling that to the British student whose data got shipped to ICE because they liked a meme. Whoâs next? Your Reddit rant about rent? Your Discord voice chat about unionizing? â Whatâs your threshold for silence?\n\nUncle Samâs newest party trick? Slamming **â300 admin subpoenas** on Google, Meta, Reddit & Discord in under two weeksâno judge, no warrant, just a bureaucratic _âplease hand over the peasantsâ_. Targets: anyone roasting ICE online. Goodbye anonymity, hello real-world PII buffet.\n\n#### How does this legal jackhammer work?\n\n * **8 U.S.C. §1225(d)** lets DHS lawyers self-issue demands for name, email, phone, IP, card digits, device IDs, the lot.\n * Platforms quietly CSV-wrap the data, TLS-ship it to DHS portals; logs auto-purged after 30 daysâbecause _âhygieneâ_.\n * No court signs off; only way out is a user-or-ACLU motion to quash. (Spoiler: 2 withdrawn, 4 motions filed, 0 injunctions.)\n\n\n\n#### Impact in a nutshell\n\n * **Privacy** : âĽ150 accounts doxxed â stalking, job-loss, deportation-risk.\n * **Speech** : chilled; even meme lords think twice before @-ing ICE.\n * **Security ops** : DHS claims _âofficer safetyâ_ âyet produces zero metrics proving raids got safer.\n * **Corporate compliance cost** : staff hours, lawyer fees, PR bleach.\n * **International side-eye** : UK student caught in dragnet; extraterritorial reach sans treaty.\n\n\n\n#### What the platforms did (and didnât)\n\n**Observed**\n\n * Meta pre-warned ~80% of targetsâ _âWeâre snitching⌠but politely.â_\n * Google complied first, asked questions later; 28,622 govt requests in Q1 2025 alone (â15%).\n\n\n\n**Recommended**\n\n * Standardize 14-day user-challenge window industry-wide.\n * Require magistrate review for any subpoena touching pure speechâmake DHS work for it.\n\n\n\n#### Outlook\n\n * **2026 H1** : more subpoenas drop; ACLU litigation backlog balloons.\n * **2027** : Congress may bolt judicial-approval amendment onto §1225(d); transparency reports finally split _âspeechâ_ vs _âcrimeâ_ buckets.\n * **2028+** : If statute tightens, expect ICE to pivot to purchase of commercial data brokersâsame poop, different plumbing.\n\n\n\nDHS is betting the Constitution canât hit what the Constitution canât see. Until courts or Congress call foul, your burner handle is one CSV away from a federal folder. Encrypt, organize, and maybe leave the geotag at homeâbecause _âland of the freeâ_ just got a paid DLC.\n\n* * *\n\n## đ¤ 2TB/Day Proxy Empire: Fake 7-Zip Installer Turns US Homes into Criminal Exit Nodes\n\n> 12 THOUSAND MACHINES. TURNED INTO FREE PROXIES. đ¤đ¸ Your â7-Zipâ installer? Now a 2TB/day bandwidth pump for criminals. Itâs not malwareâitâs a _service_. Hero.exe runs as SYSTEM. Firewall? Opened. DNS? Hiding in Googleâs. Your laptop? Now a proxy for credential stuffers. Who pays? YOU. In bandwidth. In liability. In ISP throttling. Downloaded from YouTube? Congratsâyou just rented out your CPU. Should companies be fined for letting fake installers live on Reddit? đ¤\n\nEver felt that hot-staple-gun pain when you realize the âhelpfulâ YouTube guru who taught you to âzip like a proâ actually hot-wired your rig to relay strangersâ sketchy traffic? Congratsâwelcome to the Jozeal Networkâs latest side-hustle: weaponizing 7-Zipâs good name to shove Hero.exe down 23,000+ U.S. throats since October.\n\n### How the Hell Did a File Archiver Become a Proxy Pimp?\n\n 1. Fake site (7zip[.]com) clones the real one.\n 2. Installer drops three lilâ nasties into SysWOW64\\hero, registers them as SYSTEM services.\n 3. netsh punches firewall holes on ports 1000 & 1002âbecause why knock when you can kick the door in?\n 4. XOR key 0x70 encrypts C2 chatter; DNS-over-HTTPS hides the phone book.\n 5. Your CPU + bandwidth are auctioned off for credential-stuffing, phishing, and âpremiumâ web-scrapingâat two cents a gig, cheaper than a gum-ball.\n\n\n\n### Damage Scorecard (Spoiler: Youâre the Product)\n\n * **Bandwidth** : 2 TB/day siphoned from 23.0.0.0/8 aloneâenough to stream 800 hours of 4K cat videos.\n * **Legal** : Your IP is now the return address for someone elseâs fraudâenjoy the subpoena.\n * **Performance** : 3.4 proxy sessions/hour per host; feel that lag? Thatâs Hero squatting on your socket like a drunk roommate.\n * **Reputation** : IP-based blocklists tag you as âresidential proxyâburn with fire.â Good luck accessing your bank tomorrow.\n\n\n\n### Corporate/Institutional Response & Gaps\n\n * **Observed** : AV vendors pushed 12 new IoCs in four monthsâyet 2 TB still leaks daily.\n * **Recommended** :\n * SHA-256 check every 7-Zip binary against 7-zip.org (takes 3 sâfaster than re-imaging).\n * Block hero-sms[.]co & buddies at DNS; no one legit queries âsmshero.vipâ from a cubicle.\n * Alert on services created in SysWOW64\\hero or netsh opening 1000/1002âif your SOC canât do that, demote the SIEM to a lava lamp.\n\n\n\n### Timeline of (In)Convenience\n\n * **Q1 2026** : Takedown notices kill a few C2s; infections plateau at ~30 k hosts.\n * **Q3 2026** : Expect copy-cats bundling Hero into VLC, Notepad++, whatever you trustâbecause nothing screams âsecurityâ like a code-signed Trojan.\n * **2027** : CA/B Forum tightens signing rules; supply-chain verification moves from âniceâ to âaudit item.â Until then, keep hashing, keep blocking, keep swearing.\n\n\n\n### Bottom Line\n\nYour free archiving tool isnât just zipping filesâitâs zipping your network dignity into a cheap proxy sandwich. Bookmark 7-zip.org, verify hashes, and treat random YouTube installers like radioactive dung. Because if you donât, the next âhelpfulâ tutorial will monetize your misery at two cents a popâcheaper than your pain, pricier than your pride.\n\n* * *\n\n## 𤯠395K Systems Infected via Google Groups: Lumma Stealer Exploits Trust, Not BugsâUS, UK, Russia Hit Hard\n\n> 395K Windows boxes nuked in 2 months⌠by a Google Groups post. 𤯠Attackers didnât hack your networkâthey just posted âDownload {YourCompany} for Win10â in your teamâs group. You clicked. Now your passwords, crypto wallets, and 2FA tokens are on a darkweb eBay. Googleâs TLS cert? Perfect. Your IT teamâs trust? Exploited. Whoâs next? Your HR department? Your CFOâs Gmail? â Why does âtrusted platformâ still mean âopen doorâ?\n\nGoogle Groups, the beige sweater of collaboration tools, is now the hottest ticket in cyber-crime. Crooks slap âDownload {Org}_for_Windows10â into public threads, tuck a goo.gl-shortened link behind it, andâbamâ395,000 Windows boxes cough up credentials faster than you can say âfree candy.â The bait lands on Drive, the redirect chain ends in an AutoIt blob called CastleLoader, and your browser cookies march out the door in base64 go-bags.\n\n**How the sausage is made**\n\n * CastleLoader runs only in RAM, re-assembles Lumma stealer from junk-code chunks, schedules a task named âX-Finder,â then phones home every 60 s.\n * C2 condos: ninja-browser[.]com, nb-download[.]com, nbdownload[.]spaceârotate every 48 h like cheap Airbnb keys.\n * Price tag on the dark-web shelf: $2,500 for the premium âweâll-steal-your-2FA-tooâ bundle.\n\n\n\n**What it hurts**\n\n * **Credentials** : 395 k infections â every SSO token, crypto wallet, and saved password becomes a free buffet.\n * **Incident load** : SOC analysts drown in multipart/form-data POST alerts; mean time to boredom â 3 h.\n * **Reputation** : Google links mean users click first, think neverâuntil legal starts asking why customer data is on Telegram.\n\n\n\n**Corporate response & the holes they left**\n\n * Googleâs abuse team nukes individual linksâthen attackers publish five more; whack-a-mole score: mole 5, Google 0.\n * Most tenants still allow anonymous Drive preview; zero default policy blocks AutoIt.\n * SIEM rules exist⌠if you remembered to import the IOCs; 70 % of sampled orgs hadnât (per Feb telemetry).\n\n\n\n**Outlookâgrab your crystal ball**\n\n * **Next 3 months** : expect OneDrive copy-cats; infection pace holds at ~6 k/week.\n * **2026 Q4** : AI-generated âvideo update from your CEOâ joins ClickFix; success rate projected +22 %.\n * **2027** : If Google locks down redirects, operators pivot to Dropboxâbecause trust is cheaper than zero-days.\n\n\n\n**Bottom line**\nLumma turned Googleâs goodwill into a free malware CDN; every unblocked Drive link is a potential $2.5 k profit for some hoodie in Minsk. Block AutoIt, rewrite short URLs, and train users to distrust even âofficialâ Google postsâbecause the only thing worse than spam in your inbox is ransomware on your disk.\n\n* * *\n\n### In Other News\n\n * Odido Data Breach Exposes 6.2 Million Customers' Personal Data in Netherlands\n * Singapore Identifies UNC3886 as Culprit in Multi-Month Telecom Cyber Espionage\n * State-Sponsored Actors Use Gemini AI for Reconnaissance, Phishing, and Code Generation\n * Russia bans WhatsApp, Telegram, and mandates MAX messaging platform on all devices\n\n",
"title": "300 Doxxed Accounts, 12K Proxy Machines, 395K Windows Nuked â Corporate Trust Is the New Vulnerability",
"updatedAt": "2026-02-16T13:32:19.000Z"
}