We Watched the Victims in Real Time
The most unsettling part of this research wasn’t the malware. It was watching real people get robbed, live.
While analyzing the campaign, LMG connected to the attackers’ command-and-control server the same way an infected machine would. We didn’t run the malware and we didn’t touch anyone’s data — but the server, with no authentication at all, immediately began broadcasting its list of active victims.
Live victim monitoring on the attackers’ C2. Identifying details are redacted.
Each entry included a victim’s IP address, location, username, and operating system. Over three days we watched 22 unique endpoints across 11 countries connect and disconnect as the malware did its work — Windows, macOS, and Linux machines in Germany, India, the U.S., Ukraine, Japan, Ireland, and more. The list grew as we watched. This wasn’t a sample. It was a live, active campaign.
In one case, the username was a real first and last name. A quick search turned up the person — and a phone number listed on their resume. Tom called. It turned out the infected machine belonged to the person’s spouse, who had run a recruiter’s “coding challenge” on the shared family computer that day.
That detail matters for employers: when you hire someone, you also inherit whoever else uses their personal device. A careful, tech-savvy candidate can still be compromised through a family member’s interview on the same laptop.
The exposed victim list was a serious operational-security failure by the attacker — and a rare, safe window into how fast and how far these campaigns spread. These attacks aren’t theoretical. They’re running right now, and the people losing data often have no idea.
Go deeper
Part 6 of the series. Read the full analysis in the LMG Security whitepaper, and hear Tom and Sherri on the Cyberside Chats episode, “Damaged Goods: When Your New Hire Is Already Compromised.”