Make a deal with Ruchna :verified:
🔒 Paid proposals held safely in escrow — released only when the work's approved.
📊 Post engagement
🔥 Top post: Italian 🇮🇹 bank Widiba is the latest victim of Copybara imperson · 4 likes + reposts
📊 Activity & format
Recent posts
View on Mastodon ↗
🔥 Top post
Italian 🇮🇹 bank Widiba is the latest victim of Copybara impersonation. Newer variants also now implement anti-debug checks to prevent running on an emulator. Some more variants impersonating an ISP and the Poste can be seen at an open directory.
C2 : 45.86.231[.]15
Technical an…
ClaudeFix: In a case of peak 2026, we've come across a campaign involving shared Claude chats hosting #ClickFix instructions to distribute a macOS infostealer.
In this research for Zscaler Threat Hunting, I analyzed a malvertising campaig…
Italian 🇮🇹 bank Hype is the latest victim of Copybara impersonation. Accessibility Service abuse continues. Technical analysis here : https://www.zscaler.com/blogs/security-research/technical-analysis-copybara
C2 : 92.255.85[.]200
#Android…
Noticed an <activity-alias> definition in an AndroidManifest.xml for the first time and this particular case specifies android:enabled as false for the alias. Truly curious why an application (malicious in this case) would define an activi…
Yet another tale of Accessibility Service abuse. Sharing findings around a new #Copybara Android malware variant that impersonates financial institutions in Italy🇮🇹 and Spain🇪🇸 to exfiltrate credentials from unsuspecting victims. https://t…
Nice presentation by Victor Chebyshev at @botconf on #LightSpy2, the next stage payload dropped by #DragonEgg and #Wrmspy attributed to APT41 https://youtu.be/dk-9X5FczPY?feature=shared #Botconf2024
Conference abstract/"paper" submissions littered with emojis - not "digging it"
Dynamic DNS TXT Records as TDS - that's a first https://blog.sucuri.net/2023/08/from-google-dns-to-tech-support-scam-sites-unmasking-the-malware-trail.html
Couple new and interesting static analysis bypass techniques for Android APKs in here : https://www.zimperium.com/blog/over-3000-android-malware-samples-using-multiple-techniques-to-bypass-detection/
"By running a retrohunt on public appli…
(Re?) Discovering today VT livehunt doesn't support the #androguard module.
#Yara pros: seeking suggestions if you know of alternate methods to track APK certificate match uploads
🐘 Community & instance
💡 Facts
🕵️ Fake follower check
Estimated- Est. 97% real, active audience · Low fake-follower risk.
- Strong engagement (~0.3× of followers engage each post) — an active, real audience.
- Established account (3+ years old).
Heuristic estimate from engagement, follower ratios, account age & growth — a screening signal, not a guarantee.
About
📸 Gallery
🔀 Audience overlap
EstimatedEstimated shared audience with similar creators — useful for avoiding overlap (or doubling down) when planning a campaign.
More like this
Find more →✉ Message Ruchna :verified:
Reaching out to influencers is a Pro feature. Upgrade to message any influencer directly — perfect for brands and agencies booking sponsorships.
- ✓ Message any influencer from their listing
- ✓ The influencer gets notified by email
- ✓ Manage every conversation in one inbox
Already Pro? Log in.
🎤 Event / appearance with Ruchna :verified:
Booking an event / appearance is a Pro feature. Upgrade to book Ruchna :verified: for an in-person or virtual appearance — payment held safely in escrow until the event is done.
- ✓ Book them for events, livestreams, panels & more
- ✓ Ruchna :verified: gets notified by email
- ✓ Fee held in escrow, released after the appearance
Already Pro? Log in.
You're out of free requests this month
Free accounts get 5 per month. Go Pro for unlimited sponsor pitches, collab requests & sponsorship deals — plus featured placement, the Verified badge, free withdrawals and more.
Upgrade to Pro — $9.95/mo →Your free limit resets on the 1st of next month.