BLUEFOX V3 Private Stealer from the Developer [ RENT ]

distamx

Member
Messages
2
Reaction score
0
Points
1
A comprehensive solution for large amounts of traffic and log management.
Ready-made functionality for organizing work for you and your workers.
Installed on your server and managed by you.
Direct communication with the developer to discuss questions and suggestions, without support and sellers.

Runs on Windows 7 - Windows 11 (Windows Server 2008 R2 - Windows Server 2025) x86 x64.
The x86/x64 build is issued in the admin panel in the form of seven .NET (different versions and bitness) modules and two native C++ (CLR hosting in memory).
Both .NET modules and the native CLR module are perfectly encrypted.
The weight may vary when cleaning, at the time of creating the topic 150 KB.
Each downloaded build differs from each other thanks to its own morpher.
Convenient interface for accessing logs and settings.
Unlimited number of builds, labels, users in the admin panel, bridge servers.
The ability to work with the panel only through https or only through TOR, according to your Request.

Socket communication via proprietary TCP/IP protocol in encrypted form.
Support for bridge (proxy - spacers) servers to hide the main server and geo-targeting.
Data is collected and sent to the server in stages, grabber and loader settings do not affect the collection of browsers.
All work with data occurs in memory, without swapping DLLs, full decryption with archive collection on the server.
If it crashes at runtime, part of the data is already on the server.
Does not function in the CIS countries, checking by IP on the server and the installed ru-RU layout.

Collection of passwords, restore tokens, cookies, cards, history, autofills from Chromium-based from all profiles.
Collection of passwords, cookies, history, autofills from Firefox-based from all profiles.
Collection of extensions and wallets from the browser according to 136(+) rules.
Collection of cold wallets via recursive search.
Collection of cold wallets, messengers and 2FA desktop applications from standard paths by 32(+) rules.
Collection of FTP applications, MAIL and VPN clients from standard paths.
Customizable file grabber with depth and limits, preserving the original folder hierarchy.
Customizable loader (with the ability to specify specific builds and specific labels for the task) for running ps1/scripts and executable/regular files.

From you a Debian-based server with virtualization as the main one for C2, additional Debian-based servers with virtualization for bridge servers.
Quick installation with one command in ssh.

Rent for 30 days - $900 in BTC/ETH/XMR for each license key.
There is no and will not be a lifetime.
Work via a Escrow at your expense.

TOX: 32C82AC06886BE58C366BB55A695F804D83B413D6E71F4618E0E67F03493B70AE07AAD11CC6E
 
Update v3.1.4-3.1.5
  1. Added display of found links in the log when hovering over a mark in the table (similar to marks.txt)
  2. Updated the statistics page for a specific build; you can now see the IP, country, and date of the log, and filter fresh and empty logs.
  3. Added a feature to Telegram that displays found links in the log from marks (similar to marks.txt)
  4. Replaced the Powershell injector with an Nt* injector, leaving the Powershell as a backup for x86
  5. Rewrote shellcode for browsers, patch for in-memory work
  6. Changing the handshake key between the client and server
  7. Added anti-analysis to check the server for known honeypots
  8. Added reloc_x86 and reloc_x64 builds to the existing 9 builds to choose from
  9. Updated Steam file collection and added token collection
  10. Optimization and cleaning of the morpher and detectors

Current detections (without crypto):
SCANTIME https://av-sense.net/id/634276a1-973e-4b92-9202-225bea921163
RUNTIME (internet ON) https://euro-scan.ru/s/0fa138aea04415d4de302282fb1dee0d
 
Top