By Tom Pohl   /   Jun 22nd, 2026

We Watched the Victims in Real Time

The most unsettling part of this research wasn’t the malware. It was watching real people get robbed, live. 

While analyzing the campaign, LMG connected to the attackers’ command-and-control server the same way an infected machine would. We didn’t run the malware and we didn’t touch anyone’s data — but the server, with no authentication at all, immediately began broadcasting its list of active victims. 

blog 6 pic

Live victim monitoring on the attackers’ C2. Identifying details are redacted. 

Each entry included a victim’s IP address, location, username, and operating system. Over three days we watched 22 unique endpoints across 11 countries connect and disconnect as the malware did its work — Windows, macOS, and Linux machines in Germany, India, the U.S., Ukraine, Japan, Ireland, and more. The list grew as we watched. This wasn’t a sample. It was a live, active campaign. 

In one case, the username was a real first and last name. A quick search turned up the person — and a phone number listed on their resume. Tom called. It turned out the infected machine belonged to the person’s spouse, who had run a recruiter’s “coding challenge” on the shared family computer that day. 

That detail matters for employers: when you hire someone, you also inherit whoever else uses their personal device. A careful, tech-savvy candidate can still be compromised through a family member’s interview on the same laptop. 

The exposed victim list was a serious operational-security failure by the attacker — and a rare, safe window into how fast and how far these campaigns spread. These attacks aren’t theoretical. They’re running right now, and the people losing data often have no idea. 

 

Go deeper 

Part 6 of the series. Read the full analysis in the LMG Security whitepaper, and hear Tom and Sherri on the Cyberside Chats episode, “Damaged Goods: When Your New Hire Is Already Compromised.” 

About the Author

Picture of LMG Security's Penetration Testing Manager & Principal Consultant Tom Pohl

Tom Pohl

Tom is the Director of Penetration Testing for LMG Security, a seasoned hacker, and the winner of many hacking competitions, including Wild West Hackin’ Fest, Circle City Con, THOTCON, BSidesLV, and DEFCON. Tom is a seasoned presenter at major security conferences such as DEFCON, BSidesLV, CornCon, and SecDSM, and he has led technical training classes for many organizations. In addition, Tom also discovered several vulnerabilities that have been covered in a number of major industry publications. Prior to working for LMG, Tom was the head of software architecture at Businessolver for nearly 20 years.

CONTACT US