> be me
> get dm
> its my friend
@Intel80x86
> author of
@HyperDbg
> wtf i love him
> open message
> "smelly i got goop"
> wtf i love goop
> "i found malware campaign"
> wtf i love malware campaigns
> "The Threat Actor(s) have created a website which is specifically tailored to malware analysts, or reverse engineers, who utilize hypervisor-based frameworks. Their malware campaign appears to have begun about 8 days ago. I became aware of the issue when their "product" compared themselves to HyperDbg. Their website is clearly vibe coded, however parts appear to be in Mandarin"
> wtf theyre targeting people who like goop
> sends url to website
> vt01[.]com
> look inside
> lol ai slop
> go to download page
> vt01[.]com/en/download
> immediately flagged as malware by firefox
> allow download plz
> split nanosecond touches the disk
> windows: OMFG MALWARE!!!
> ??? this malware STINKS
> sha256: 5934d1a64afd62e7d1badb81e8613e01efe9cf9c7d6748271c6d0761e3b11eb7
> look inside
> delphi, weird PE sections
> throw into triage
> YARA rules IMMEDIATELY identify the malware family
> XRed
> wtf is XRed?
> cant remember any family named XRed
> December, 2025: XRed impersonates Indian Ministry of Finance and Income Tax Department
> December, 2025: XRed targets US and UK companies that do business in India
> March, 2025: XRed targets manufacturing companies in the United Kingdom
> May, 2025: Threat Actors compromise ProColored, their driver update was compromised to push XRed
> July, 2025: Threat Actors compromise video game mouse company, push malware to video game players who use EndGame Gear for gaming
this is strange goop