Tuesday, January 21, 2025
HomeCyber Security NewsCybercriminals Selling Python-based Hacking Tool via Telegram

Cybercriminals Selling Python-based Hacking Tool via Telegram

Published on

SIEM as a Service

Follow Us on Google News

Recently, Cado Security Labs discovered and unveiled details of a new Python-based credential harvester called “Legion.”

Cybersecurity researchers have asserted that this hacking tool, “Legion” has already made its way to Telegram and is being actively marketed on Telegram by its operators. 

While this hacking tool has been specifically designed to target and exploit a wide range of email services, Legion is likely linked to the infamous AndroxGh0st malware family, which made headlines for the first time in December 2022.

Legion Offerings

There are several modules included in Legion that are used to enumerate:-

  • Vulnerable SMTP servers
  • Remote Code Execution (RCE)
  • Exploit vulnerable versions of Apache
  • Brute-force cPanel
  • Brute-force WebHost Manager (WHM) accounts
  • Interact with Shodan’s API
  • Hijack SMS messages
  • Compromise Amazon Web Services credentials

Besides this, AlienFox is a comprehensive toolset, and it has been identified that AndroxGh0st is part of this toolset. 

Since this toolset is vast in nature, so, it also provides threat actors with the ability to steal API keys and essential secrets from cloud services.

Legion Tool

The presence of Legion on multiple Telegram channels, coupled with its promotion through YouTube tutorial videos, strongly suggests that this is not a casual or isolated attempt at spreading malware but rather a widespread and coordinated effort.

What’s the Origin?

Although the exact source of the malware remains unverified, there are indications that the developer behind it may be Indonesian or located in Indonesia, based on comments and other linguistic evidence found in Bahasa Indonesia.

Cado Security researchers have issued a precautionary recommendation to all users of web server technologies and frameworks, such as Laravel, to review their security processes and procedures.

To ensure maximum protection of sensitive information such as credentials, experts recommend storing such information in a .env file outside web server directories.

This will help prevent unauthorized access to critical data by limiting the potential attack surface which threat actors could exploit.

Targeted Services

Here below, we have mentioned the complete list of the services that are targeted:-

  • Twilio
  • Nexmo
  • Stripe/Paypal (payment API function)
  • AWS console credentials
  • AWS SNS, S3 and SES-specific credentials
  • Mailgun
  • Plivo
  • Clicksend
  • Mandrill
  • Mailjet
  • MessageBird
  • Vonage
  • Nexmo
  • Exotel
  • Onesignal
  • Clickatel
  • Tokbox
  • SMTP credentials
  • Database Administration and CMS credentials (CPanel, WHM, PHPmyadmin)

Here below, we have mentioned the list of the carriers that are targeted:-

  • Alltel
  • Amp’d Mobile
  • AT&T
  • Boost Mobile
  • Cingular
  • Cricket
  • Einstein PCS
  • Sprint
  • SunCom
  • T-Mobile
  • VoiceStream
  • US Cellular
  • Verizon
  • Virgin

Moreover, a GitHub Gist link appears on the profile of a user named “Galeh Rizky” who resides in Indonesia, according to his profile.

Code

Although the exact relationship between Galeh Rizky and Legion remains unclear at this time, the most shocking thing is the presence of their code in the detected sample.

Galeh Rizky may be the developer behind Legion, or a coincidence that their code has been used without their knowledge or consent.

This malware mainly depends on misconfigurations in web server technologies and frameworks. That’s why it’s strongly advised to recheck all security mechanisms to prevent further exploitation.

Struggling to Apply The Security Patch in Your System? – 

Related Read:

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Brave Browser Vulnerability Allows Malicious Website Appears as Trusted One

A security vulnerability has been identified in Brave Browser, potentially allowing malicious websites to...

Beware! Fake SBI Reward APK Attacking Users to Deliver Android Malware

A recent phishing campaign has targeted customers of SBI Bank through a deceptive message...

Gootloader Malware Employs Blackhat SEO Techniques To Attack Victims

The Gootloader malware family employs sophisticated social engineering tactics to infiltrate computers.By leveraging...

Critical SUSE Linux Distro Injection Vulnerability Allow Attackers Exploits “go-git” Library

A significant security vulnerability, designated CVE-2025-21613, has been discovered in the go-git library, used...

API Security Webinar

Free Webinar - DevSecOps Hacks

By embedding security into your CI/CD workflows, you can shift left, streamline your DevSecOps processes, and release secure applications faster—all while saving time and resources.

In this webinar, join Phani Deepak Akella ( VP of Marketing ) and Karthik Krishnamoorthy (CTO), Indusface as they explores best practices for integrating application security into your CI/CD workflows using tools like Jenkins and Jira.

Discussion points

Automate security scans as part of the CI/CD pipeline.
Get real-time, actionable insights into vulnerabilities.
Prioritize and track fixes directly in Jira, enhancing collaboration.
Reduce risks and costs by addressing vulnerabilities pre-production.

More like this

Brave Browser Vulnerability Allows Malicious Website Appears as Trusted One

A security vulnerability has been identified in Brave Browser, potentially allowing malicious websites to...

Beware! Fake SBI Reward APK Attacking Users to Deliver Android Malware

A recent phishing campaign has targeted customers of SBI Bank through a deceptive message...

Gootloader Malware Employs Blackhat SEO Techniques To Attack Victims

The Gootloader malware family employs sophisticated social engineering tactics to infiltrate computers.By leveraging...