This directory serves as the centralized digital forensics, threat intelligence, and defensive engineering repository for the Hybrid Infrastructure & Cybersecurity Laboratory. It documents real-world cybercrime campaigns investigated locally, reverse-engineered malware/phishing backends, full Capture The Flag (CTF) writeups, vulnerability research (CVEs), and active DNS threat blocklists enforced on our perimeter firewall.
cyber/
├── README.md # Security directory overview & threat dashboard
├── forbidden_domains.txt # Unified domain blocklist (Local IoCs + DNSC + ThreatFeeds)
├── lista_interzisa.txt # Romanian localized mirror of forbidden domains
├── dnsc_blacklist.json # DNSC automated API threat intelligence cache
├── csirt_cache.json # National & international CSIRT response telemetry
├── csirt_telemetry.json # Real-time incident resolution & sinkhole metrics
│
├── mediagalaxy-ecommerce-fraud-forensics/ # SEC-2026-ECOM-005: Fake Media Galaxy retail phishing & Yunnan SaaS backend
├── revolut-vishing-forensics/ # SEC-2026-VISH-002: Romanian VoIP caller ID spoofing & real-time OTP relay
├── task-scam-infrastructure-analysis/ # SEC-2026-TASK-003: Pig butchering task scam platform, Vue state & API audit
├── tiktok-mrr-scam-infrastructure/ # SEC-2025-MRR-001: Synthetic media funnels & $497 course resale syndicates
├── openid-mitm-phishing-forensics/ # SEC-2025-AITM-004: Steam OpenID Browser-in-the-Middle (BitM) credential harvesting
│
├── antigravity/ # Automated DFIR tooling (Apple Vision OCR, ad scrapers, DNS sinkhole sync)
├── cve/ # Critical ecosystem CVE assessments (Proxmox VE, Hyper-V, AD DNS/DHCP)
├── ctf/ # Capture The Flag challenge writeups, exploit scripts & schema dumpers
└── red-team/ # Local security auditing, container isolation & privilege escalation checks
| Case ID | Case Title & Vector | Threat Actor Profile / Origin | Ingress Vector | Technical Impact | Resolution & Defense Status |
|---|---|---|---|---|---|
SEC-2026-ECOM-005 |
Media Galaxy Retail Impersonation | Yunnan, China (yiyangsaas.com / eName Tech) |
Sponsored TikTok / FB Video Ads | Unauthorized card charge (~21 EUR, morvethemi london), credential harvesting |
Takedown Confirmed: DNSC ticket #178465, domain sinkholed, PNRISC blacklisted, card reissued & chargeback filed. |
SEC-2026-VISH-002 |
Revolut Vishing & Credential Relay | Romanian VoIP SIP Trunk (0749-XXX) |
Spoofed Caller ID + SMS lures | Real-time OTP / 3D Secure session relay attempt | Remediated: C2 domain reported to registrar, Revolut Fraud Operations triage, Unbound DNS sinkholed. |
SEC-2026-TASK-003 |
Pig Butchering Task Scam Platform | Russian white-label syndicate (Vue / Vite / Laravel) | WhatsApp / Telegram recruitment (888888) |
Escrow deposit trap, cryptocurrency loss (USDT TRC-20) | Exposed: Backend /api/v1/site/config audited, withdrawal kill-switch proven hardcoded, SQLi surface identified. |
SEC-2025-MRR-001 |
TikTok MRR Synthetic Media Funnels | Commercial digital storefronts (Stan.store / Stripe) | TikTok FYP algorithm hooks & faceless video swarms | $497 recurring course resale scheme | Documented: Algorithmic churn audited, CapCut/ElevenLabs synthetic media pipelines exposed, consumer advisory issued. |
SEC-2025-AITM-004 |
Steam OpenID BitM Credential Harvesting | Reverse Proxy C2 / CSReserve clone kit | Discord / Steam esports tournament votes | OpenID session theft (steamLoginSecure), Family View PIN lock |
Mitigated: Threat reported to Valve Security, reverse proxy IP identified, accounts recovered, sandbox scrubbed. |
flowchart TD
subgraph INGRESS["1. Threat Ingress Vectors"]
I1["Sponsored Ads (TikTok / Meta)<br/>Media Galaxy Phishing"]
I2["Telephony VoIP / SMS<br/>Revolut Spoofed Vishing (0749)"]
I3["Direct Messaging (Telegram / WhatsApp)<br/>Task Scam Recruitment (888888)"]
I4["Social Engineering Bio Links<br/>Stan.store $497 Resell Courses"]
I5["Esports Lures (Discord DMs)<br/>Steam OpenID Tournament Voting"]
end
subgraph TRIAGE["2. Forensic Triage & Teardown"]
T1["Sandbox Environment<br/>Isolated Proxmox KVM & Kali Linux"]
T2["Network Traffic Interception<br/>Burp Suite Pro TLS MITM Inspection"]
T3["Client-Side DOM & Token Audit<br/>Canvas GPU Fingerprinting & Storage State"]
T4["Backend C2 & API Reverse Engineering<br/>/api/v1/ Endpoints & SSL SAN Pivoting"]
I1 & I2 & I3 & I4 & I5 --> T1 --> T2 --> T3 --> T4
end
subgraph MITIGATION["3. Automated Homelab Defense & Public Disclosure"]
M1["OPNsense Unbound DNS Sinkhole<br/>Null-route to 0.0.0.0 / :: (forbidden_domains.txt)"]
M2["Suricata NIDS/IPS Rules<br/>Perimeter Deep Packet Inspection on vmbr0/vmbr1"]
M3["Wazuh SIEM / XDR Alerts<br/>Syslog Ingestion & Behavioral Rule Triggers (LXC 106)"]
M4["National CSIRT Escalation<br/>DNSC Incident Reports & Cloudflare / Registrar Abuse"]
M5["Banking Dispute Recovery<br/>BCR / Visa Dispute Disclosures & Chargeback Tracking"]
T4 --> M1
T4 --> M2
T4 --> M3
T4 --> M4
T4 --> M5
end
Indicators of Compromise (IoCs) extracted from live investigations are directly operationalized in our datacenter:
Malicious FQDNs and hosting domains are compiled into cyber/forbidden_domains.txt and automatically synchronized with Unbound DNS on our OPNsense perimeter firewall.
# Excerpt from OPNsense Unbound DNS Blocklist configuration
local-zone: "mediagalaxy.voetbalshop-nlco.com" redirect
local-data: "mediagalaxy.voetbalshop-nlco.com A 0.0.0.0"
local-data: "mediagalaxy.voetbalshop-nlco.com AAAA ::"
local-zone: "yiyangsaas.com" redirect
local-data: "yiyangsaas.com A 0.0.0.0"
local-data: "yiyangsaas.com AAAA ::"
local-zone: "worvixglobal.com" redirect
local-data: "worvixglobal.com A 0.0.0.0"
local-data: "worvixglobal.com AAAA ::"
The automation script cyber/antigravity/opnsense_dns_sinkhole.py interfaces with the Proxmox hypervisor (192.168.1.132) and updates the active Unbound DNS cache without interrupting production traffic.
Custom Suricata inspection rules deployed on OPNsense detect malicious API probes and phishing kit signatures:
# Rule 1: Detect Media Galaxy Phishing Backend Traffic
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"THREAT-INTEL Media Galaxy Phishing Domain Egress (yiyangsaas.com)"; flow:established,to_server; http.host; content:"yiyangsaas.com"; classtype:trojan-activity; sid:2026001; rev:1;)
# Rule 2: Detect Task Scam Client Configuration Probe
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"THREAT-INTEL Pig Butchering Task Scam API Config Ingress"; flow:established,from_server; http.stat_code; content:"200"; file_data; content:"withdrawMethodBank"; content:"defaultCountryCode"; content:"+40"; classtype:bad-unknown; sid:2026002; rev:1;)
# Rule 3: Detect BitM Steam OpenID Reverse Proxy Exfiltration
alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"THREAT-INTEL Steam OpenID BitM Cookie Exfiltration Attempt"; flow:established,to_server; content:"steamLoginSecure"; content:"sessionid"; nocase; classtype:credential-theft; sid:2026003; rev:1;)
The central Wazuh SIEM cluster collects syslog streams from OPNsense (filterlog), Nginx reverse proxies, and hypervisor audit logs. Custom decoders and rules trigger alerts for forensic matches:
<group name="homelab,cyber_forensics,">
<!-- Rule: Triggered on DNS resolution attempt for known fraudulent domain -->
<rule id="100501" level="12">
<if_sid>100500</if_sid>
<match>mediagalaxy.voetbalshop-nlco.com|yiyangsaas.com|worvixglobal.com</match>
<description>Homelab Host attempted resolution of confirmed Phishing/Fraud IoC</description>
<mitre>
<id>T1566.002</id>
<id>T1071.004</id>
</mitre>
</rule>
</group>5.1. cyber/antigravity/ · DFIR & Intelligence Automation
5.2. cyber/cve/ · Critical Vulnerability Research
5.3. cyber/ctf/ · Capture The Flag Compendium
The primary intelligence feed cyber/forbidden_domains.txt (and localized mirror cyber/lista_interzisa.txt) consolidates threat indicators from:
- Local Investigations: Newly identified phishing lures, fake checkouts, and C2 servers.
- DNSC National Blacklist: Synchronized against
blacklist.dnsc.roviacyber/dnsc_blacklist.json. - Community Threat Feeds: URLhaus, ThreatFox, and PhishTank verified threat nodes.
An automated cron workflow (scripts/sync_forbidden_domains.py) normalizes, deduplicates, and validates domain syntax before triggering OPNsense Unbound reloads.
| Tactic | Technique ID | Technique Name | Investigated Case Files |
|---|---|---|---|
| Reconnaissance | T1598 |
Phishing for Information | Revolut Vishing (SEC-2026-VISH-002) |
| Reconnaissance | T1592 |
Gather Victim Host Information | Task Scam Fingerprinting (SEC-2026-TASK-003) |
| Resource Development | T1583.001 |
Acquire Infrastructure: Domains | Media Galaxy (SEC-2026-ECOM-005), Steam OpenID |
| Initial Access | T1566.001 |
Spearphishing Link | Steam OpenID BitM (SEC-2025-AITM-004) |
| Initial Access | T1566.002 |
Spearphishing via Social Media Ads | Media Galaxy Phishing, TikTok MRR (SEC-2025-MRR-001) |
| Initial Access | T1566.004 |
Voice Phishing (Vishing) | Revolut VoIP Caller ID Spoofing (SEC-2026-VISH-002) |
| Credential Access | T1557.001 |
Adversary-in-the-Middle (AiTM) | Steam OpenID BitM (SEC-2025-AITM-004) |
| Credential Access | T1056.001 |
Web Form Input Capture | Media Galaxy Fake Checkout (SEC-2026-ECOM-005) |
| Credential Access | T1556 |
Modify Authentication Process | Revolut Real-Time OTP Relay (SEC-2026-VISH-002) |
| Persistence | T1098 |
Account Manipulation (Family View) | Steam OpenID BitM (SEC-2025-AITM-004) |
| Impact | T1499 |
Endpoint Denial of Service / Lockout | Task Scam Withdrawal Kill-Switch (SEC-2026-TASK-003) |
| Impact | T1657 |
Financial Theft & Fraudulent Charges | Media Galaxy (morvethemi london), Task Scam (USDT) |