<?xml version="1.0" encoding="utf-8"?><feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en"><generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator><link href="https://blackspam.com/feed.xml" rel="self" type="application/atom+xml" /><link href="https://blackspam.com/" rel="alternate" type="text/html" hreflang="en" /><updated>2026-10-07T23:48:31+03:00</updated><id>https://blackspam.com/feed.xml</id><title type="html">blackspam</title><subtitle>Security notes, sysadmin field logs and side projects.</subtitle><author><name>Mothanna Abu Judeh</name><email>info@blackspam.com</email></author><entry><title type="html">Chasing Ghosts: Unmasking a Phishing Gang in Jordan</title><link href="https://blackspam.com/posts/chasing-ghosts/" rel="alternate" type="text/html" title="Chasing Ghosts: Unmasking a Phishing Gang in Jordan" /><published>2026-01-31T00:00:00+03:00</published><updated>2026-01-31T00:00:00+03:00</updated><id>https://blackspam.com/posts/chasing-ghosts</id><content type="html" xml:base="https://blackspam.com/posts/chasing-ghosts/"><![CDATA[<p>For the past couple of months, a scam has been quietly spreading across Jordan.</p>

<p>It shows up as a sponsored post on Facebook or Instagram — clean graphics, friendly wording, a promise of a reward, government support, or some extra balance on your wallet. All you have to do is “verify” your account through ZainCash, Orange Money, or UWallet. You tap the link, land on a login page that looks exactly like your wallet, and type in your number, your password, and the OTP that arrives a second later.</p>

<p>And just like that, your balance is gone — pulled out through CliQ before you even understand what happened.</p>

<p>I probably would’ve scrolled past it like everyone else. But then people close to me started getting hit. So I decided to find out who was behind it.</p>

<h2 id="collecting-the-pieces-">Collecting the pieces 🔍</h2>

<p>I started by saving every version of the campaign I could find on Facebook. Over that stretch I counted 15 of them — different names, different graphics, same trap.</p>

<p>I opened them one by one. All fake login pages, as expected. But when I started reading the page source, something stood out: the code was stuffed with instructions and comments, the kind of thing you see when a page is generated by AI. The graphics and the copywriting had that same synthetic feel. So now I knew what I was looking at — an <strong>AI-driven phishing campaign</strong>.</p>

<p>Then I did the obvious thing: opened one of the fake pages, typed in junk data, and fired up Burp Suite to watch where it went.</p>

<p>The login form wasn’t talking to a wallet. It was talking to a <strong>Telegram bot</strong> — and the request had the bot token and chat ID sitting right there in the open. I saved them, sent the request through, and let Telegram answer back. It handed me a surprising amount of juicy info: the bot’s name, its username, and the admin’s name and handle.</p>

<p>I repeated this for all 15 links, then used tools like Matkap and TeleTracker to pull the admin usernames behind each bot. Then I opened Telegram and went through the accounts one by one, hoping one would slip and lead me to a real person.</p>

<p>Almost all of them were garbage names — “Hero,” random strings like <code class="language-plaintext highlighter-rouge">sskhhhibapxx</code>. All except one, which carried a real Jordanian family name and a display photo of an actual face. I grabbed the name, searched Instagram, and found a public account that matched. I pulled his public info and started mapping it out — but something felt off. My gut said this wasn’t the guy. This was a stolen identity, planted as a decoy. Classic misdirection.</p>

<h2 id="hitting-a-wall-">Hitting a wall 💀</h2>

<p>I went back to the bots. Telegram’s API has an endpoint, <code class="language-plaintext highlighter-rouge">getUpdates</code>, that lets you read a bot’s recent messages — so I started scrolling through the history. Mostly it was a river of stolen credentials. But right at the beginning of the log, I found screenshots.</p>

<p>One was a CliQ alias from the Ahli Bank app. Another was a CliQ name inside a ZainCash wallet — with the phone number clearly visible.</p>

<p>I resolved the CliQ aliases into full four-part names through the bank app, ran the phone number through caller-ID apps like TrueCaller, and got a name back. Then I dropped everything into a single diagram in Obsidian so I could actually see the connections.</p>

<p>And here’s where I got stuck.</p>

<p>Staring at that map — the names, the numbers, the accounts — it was obvious these were all just victims, or people whose identities had been borrowed. And I started doubting my biggest assumption: that the scammer was even <em>inside</em> Jordan.</p>

<p>Think about it:</p>

<ul>
  <li>Who risks sending stolen money to a wallet registered in their own name?</li>
  <li>Who puts their personal phone number on a wallet collecting drained balances?</li>
  <li>Who uses a country’s own symbols and the names of its national institutions to scam its own people?</li>
</ul>

<h2 id="the-one-mistake-they-made">The one mistake they made</h2>

<p>While I was sitting there frustrated, half-scrolling Facebook, a brand-new campaign popped up — one I hadn’t seen before. Without really thinking, I opened the link, pulled the bot’s credentials, and checked its messages.</p>

<p>Nothing yet. Not a single victim had hit it.</p>

<p>That was the moment things got interesting. 😁</p>

<p>I’ll be honest that what came next was improvised — me reacting in the moment, not following some clean playbook. The bot was fresh and empty, so I sent it a fake error message, the kind that would make its owner think the link was broken on their end and that a technical glitch was why no victims were coming through. Tucked inside that message was a link that would quietly log whoever opened it — a legitimate Telegram link wrapped in an IP logger, then wrapped again in a trusted URL shortener so it looked clean.</p>

<blockquote>
  <p>API Connection/Response Failure: [short link]</p>
</blockquote>

<p>Then I waited. An hour. Two hours. Nothing. I went to sleep.</p>

<p>The next morning I opened my laptop, checked the logger — and there it was. A click. 👀</p>

<p>My eyes went straight to the Country field:</p>

<h3 id="-casablanca-morocco-">📍 Casablanca, Morocco 🇲🇦</h3>

<p>Along with the public IP, local IP, ISP, browser, OS, device info, screen resolution, and language. From the public IP I could see an open port, and from there even the router — a home Huawei unit (Shodan is wonderful).</p>

<p>The guy running a “Jordanian” scam had been sitting in Morocco the whole time.</p>

<h2 id="taking-it-down-">Taking it down 💣</h2>

<p>Once I had what I needed, the question shifted from <em>who</em> to <em>how do I kill this before more people get hurt.</em></p>

<p>I didn’t have the access to revoke the bots, so in the heat of the moment I did the crude thing: I pointed Burp Suite’s Intruder at the bot and buried it under thousands of fake submissions — random numbers, random passwords — so that any real victim data would drown in the noise and be useless to sort through. It bought time, but the real fix was never going to be me alone hammering a bot.</p>

<p>So I built a proper report, with screenshots proving this was phishing and credential harvesting, and sent it everywhere it needed to go:</p>

<ul>
  <li><strong>Facebook</strong>, where the ads were running</li>
  <li><strong>Google</strong>, since some pages were hosted on Blogger</li>
  <li><strong>Vercel</strong>, which hosted others</li>
  <li><strong>Telegram</strong>, where the stolen data was being collected</li>
</ul>

<p>I wrote it hard. Within 48 hours, a big chunk of the operation was down.</p>

<h2 id="what-i-want-you-to-take-from-this">What I want you to take from this</h2>

<ul>
  <li><strong>More campaigns will come.</strong> This kind of scam loves occasions — New Year, national holidays, anything that gives it a reason to offer you “a gift.” The only real defense is awareness.</li>
  <li>This is probably <strong>Phishing-as-a-Service (PhaaS)</strong> — not one clever person, but a kit someone rents and points at a new country.</li>
  <li>Everything I collected was already publicly exposed by the attackers themselves. I didn’t publish anyone’s identity. This is strictly for awareness.</li>
  <li>If you ever get caught by a scam like this, don’t stay quiet. Go to the <strong>Cybercrime Unit</strong> and file an official report.</li>
</ul>

<p>Stay safe — and guard your wallets.</p>]]></content><author><name>Mothanna Abu Judeh</name><email>info@blackspam.com</email></author><category term="phishing" /><category term="telegram" /><category term="osint" /><category term="jordan" /><category term="incident-response" /><category term="awareness" /><summary type="html"><![CDATA[How I tracked down an AI-powered phishing gang draining Jordanian wallets.]]></summary></entry><entry><title type="html">DeepSeek-R1: vulnerabilities and what they mean for security work</title><link href="https://blackspam.com/posts/deepseek-r1-security-risks/" rel="alternate" type="text/html" title="DeepSeek-R1: vulnerabilities and what they mean for security work" /><published>2025-02-14T00:00:00+03:00</published><updated>2025-02-14T00:00:00+03:00</updated><id>https://blackspam.com/posts/deepseek-r1-security-risks</id><content type="html" xml:base="https://blackspam.com/posts/deepseek-r1-security-risks/"><![CDATA[<p>As an IT engineer with an interest in offensive security, I’ve been following DeepSeek-R1, a reasoning model from the Chinese company DeepSeek. It has drawn a lot of attention for its reasoning ability and low cost. What interests me here is a different angle: the security weaknesses that have been reported in it, and what they mean for anyone who builds on, or has to defend against, models like this.</p>

<blockquote class="warn">
  <p>This post is about understanding and defending against these weaknesses. It does not include working bypass prompts or instructions for producing harmful output.</p>
</blockquote>

<h2 id="reported-vulnerabilities">Reported vulnerabilities</h2>

<h3 id="prompt-injection-and-information-leakage">Prompt injection and information leakage</h3>

<p>DeepSeek-R1 has been reported to be vulnerable to prompt injection, where crafted input overrides the instructions the application intended the model to follow. In a tool that feeds untrusted text to the model — a chatbot summarizing a web page, say — this can lead to unintended behavior or leakage of context the model was supposed to keep private.</p>

<h3 id="generation-of-harmful-content">Generation of harmful content</h3>

<p>Independent testing has found the model comparatively easy to push into producing harmful content, including insecure or outright malicious code. One widely cited red-team evaluation reported a high success rate at eliciting unsafe code. For a defender, the takeaway isn’t the headline number; it’s that a cheap, capable model with weak guardrails lowers the cost of generating attack tooling.</p>

<h3 id="data-sourcing-and-legal-questions">Data-sourcing and legal questions</h3>

<p>There are also open questions about the model’s training data and originality, including claims that it may have incorporated output from other models. Those raise intellectual-property and data-privacy concerns that are worth keeping in mind before putting it anywhere near sensitive data.</p>

<h2 id="why-this-matters-for-security-work">Why this matters for security work</h2>

<p>The same properties that make these weaknesses a risk also make the model worth studying:</p>

<ul>
  <li><strong>Threat modeling.</strong> If you ship a product that calls an LLM, prompt injection is now part of your attack surface. Testing how a model behaves under adversarial input tells you what controls you need around it — input/output validation, least-privilege tool access, and not trusting model output as if a human wrote it.</li>
  <li><strong>Research and defense.</strong> The model being open means researchers can study its failure modes directly and build better detections and guardrails, rather than guessing at a black box.</li>
  <li><strong>Awareness.</strong> For teams adopting AI, these reports are a useful reminder that a model’s capability and its safety are separate things. A capable model with weak alignment is not a safe default.</li>
</ul>

<h2 id="conclusion">Conclusion</h2>

<p>DeepSeek-R1 is a capable model with a genuinely weak safety posture, at least as shipped. That combination is exactly what makes it interesting to study and risky to deploy carelessly. If you’re building with it, treat its output as untrusted, wrap it in real controls, and keep sensitive data away from it. The broader lesson holds for every model on this curve: capability is arriving faster than alignment, and that gap is where the security work is.</p>]]></content><author><name>Mothanna Abu Judeh</name><email>info@blackspam.com</email></author><category term="security" /><category term="ai" /><category term="llm" /><summary type="html"><![CDATA[A look at the security weaknesses reported in DeepSeek-R1 — prompt injection, harmful-content generation, and what they imply for defenders.]]></summary></entry></feed>