Sunday, September 13, 2026

Beware of Instagram Growth Tools Stealing Login Credentials and Sending Them to Attackers

A discovery by Socket’s Threat Research Team has unveiled a malicious Python package named imad213, masquerading as an Instagram growth tool.

Created by a threat actor identified as im_ad__213 with the associated email madmadimado59@gmail[.]com, this malware cunningly tricks users into surrendering their Instagram credentials.

Deceptive Python Package Targets Instagram Users

Promoted with a polished GitHub README and branded as a legitimate follower-boosting service under the guise of “IMAD-213,” the package lures victims through forums and Discord servers with promises of rapid social media growth.

 Instagram Growth Tools
malicious imad213 package.

Its detailed installation instructions (pip install imad213) and deceptive safety tips, such as using temporary accounts, create a false sense of security, convincing users to input sensitive data without suspicion.

Upon execution, imad213 initiates a covert check with a remote server hosted on Netlify (https://imad-213-imad21[.]netlify[.]app/pass[.]txt) to verify if it can proceed, showcasing a remote kill switch that provides the attacker full control over the malware’s operation.

If approved, the tool prompts users for their Instagram login details under the pretense of facilitating growth services, even saving them locally in plaintext to a file named credentials.txt as a social engineering tactic to appear convenient and trustworthy.

 Instagram Growth Tools
Malicious website

Credential Harvesting

However, the true danger lies in its next move: the malware broadcasts these credentials to a network of ten interconnected Turkish bot services, including takipcimx[.]net and takipcizen[.]com, which pose as legitimate Instagram growth platforms with professional interfaces.

According to Socket Report, these sites, operational for nearly four years and linked through shared WHOIS records and a common registrar, are flagged by security tools like VirusTotal for phishing, revealing a coordinated, long-term credential harvesting operation.

This Credential Laundering Network distributes stolen data across multiple endpoints, obscuring its origin and amplifying the risk of account compromise across platforms, especially given Instagram’s 2 billion active users and the frequent reuse of passwords.

Beyond immediate theft, the attack hints at evolving threats, as the same actor behind imad213 has crafted other malicious tools like taya and poppo213 with consistent branding and coding patterns.

Utilizing legitimate hosting services like Netlify for command and control suggests a trend where future malware may hide within trusted infrastructures, evading traditional detection.

Moreover, the social engineering tactics, such as fake safety advisories, could advance into more deceptive features like bogus two-factor authentication prompts to extract additional security data.

Instagram’s strict policies against artificial growth tools mean users risk account suspension alongside data loss, while the broader implications point to cross-platform targeting, potentially encompassing TikTok or gaming credentials within unified attack frameworks.

Socket’s security solutions, including real-time behavioral analysis and GitHub app integrations, offer a defense by flagging such supply chain threats before they infiltrate systems, underscoring the need for vigilance in an era of sophisticated social media malware.

Indicators of Compromise (IOCs)

TypeIndicatorDescription
Package Nameimad213Malicious Python package
Threat Actorim_ad__213Creator of the malware
Emailmadmadimado59@gmail[.]comAssociated with threat actor
C2 URLhttps://imad-213-imad21[.]netlify[.]app/pass.txtRemote kill switch control file
Local Storage Filecredentials.txtPlaintext storage of stolen data
Malicious Domainstakipcimx[.]net, takipcizen[.]com, etc.Bot services harvesting credentials

Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates.

Aman Mishra
Aman Mishra
Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Threat Actors Use Claude AI Agents to Automate Cyberattacks and Steal Sensitive Data

Threat actors are increasingly using Claude-based AI workflows to...

China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks

China-linked threat actors UTA0560 and JungleBamboo chained a Google...

New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets

A newly identified phishing campaign is abusing the legitimate...

CISA Warns of Critical GitLab Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

Related Articles

Recent News