sfba.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
A Mastodon instance for the San Francisco Bay Area. Come on in and join us!

Server stats:

2.4K
active users

on a day with no ADHD meds, my roommate knocks on the door and is like "a friend got their discord hacked but before I knew it they sent me an EXE and I ran it. am I hacked?"

I am some kind of reverse engineer/security engineer but I'm not very good at it WHEN MY BRAIN DOESN'T WORK

seems it is an electron based javascript malware that tries to steal all your passwords from all your browsers

huh, one of the things it does is check your RAM speed.

I think because that's a thing real computers have, and it's trying to do a roundabout VM check?

but yeah it does a bunch of checks to see if anything remotely debuggy or VMy is running or even installed, then refuses to do stuff

Andrew Drake

@foone Electron-based malware... gonna need to sit down for a minute.

I guess when everything you install is yet another bespoke copy of Electron hogging all of your resources, one more copy of Electron could be a reasonable way to blend in.

I do kind of love the prospect that even malware developers are too cheap to bother with native platform development these days.