G
gsehrjolqwefe
Member
- Joined
- July 21, 2026
- Messages
- 5
- Reaction score
- 0
- Points
- 1
- Thread Author
- #1
What's up, DNA.
We recently ran into a Telegram-based crew that’s been recruiting affiliates to distribute malware (stealers + winlockers) and skimming profits. They market themselves as a "legit partner program" but operate a classic scam: affiliates do the dirty work, admins keep the logs and the lion's share.
We don't like that. So we decompiled their entire toolkit.
What we found:
- Source code of their winlocker with an embedded backdoor (SvinLocker) is now public.
- Developer workstation path left in the binary:
C:\Users\nocki\Desktop\worm\SvinoLock\obj\Release\SvinoLock.pdb
_CorExeMain
(nocki = developer's local username)
- Telegram bot token used for their stealer logs: 8882203363:AAHLgqCw7qrelzavN7pwgTrGZs_RRmMKVm8
- Associated chat_id: 1793587
- Developer / admin Telegram accounts:
@anonnedhacker
@Leyla_khasan
@notvist
All three accounts are active and have confirmed their involvement.
What we're releasing:
Winlocker + backdoor source:
The bot token and chat_id are still active at the time of posting. We are not using them further, but we are making them known for transparency.
If you want to help de-anonymize the rest of their operation or track their next moves, we're coordinating here:
nocivics
This is not a drama post. This is a public service to anyone who values operational security and hates scammers hiding behind "partnership" programs.
Stay safe.
— nocivics
We recently ran into a Telegram-based crew that’s been recruiting affiliates to distribute malware (stealers + winlockers) and skimming profits. They market themselves as a "legit partner program" but operate a classic scam: affiliates do the dirty work, admins keep the logs and the lion's share.
We don't like that. So we decompiled their entire toolkit.
What we found:
- Source code of their winlocker with an embedded backdoor (SvinLocker) is now public.
- Developer workstation path left in the binary:
C:\Users\nocki\Desktop\worm\SvinoLock\obj\Release\SvinoLock.pdb
_CorExeMain
(nocki = developer's local username)
- Telegram bot token used for their stealer logs: 8882203363:AAHLgqCw7qrelzavN7pwgTrGZs_RRmMKVm8
- Associated chat_id: 1793587
- Developer / admin Telegram accounts:
@anonnedhacker
@Leyla_khasan
@notvist
All three accounts are active and have confirmed their involvement.
What we're releasing:
Winlocker + backdoor source:
To see this hidden content, you need to "Reply & React" with one of the following reactions:
Like,
Love,
Haha,
Wow,
Sad,
Angry
If you want to help de-anonymize the rest of their operation or track their next moves, we're coordinating here:
nocivics
This is not a drama post. This is a public service to anyone who values operational security and hates scammers hiding behind "partnership" programs.
Stay safe.
— nocivics