r/blackhat 2h ago

how do y'all pull IP 's/info from a spoofed caller id?

0 Upvotes

I know about a few reverse lookup websites but the scammers always spoof their caller id and it never works. I'm wondering how people get around that? anything helps yall I'm just tryna bring justice to these mfs 💪

also mods I'm getting a warning before I post but I'm not telling anybody to hack anybody so am I good lol?


r/blackhat 1d ago

ATM Flaws Reveal Key Weaknesses in the Software Supply Chain

Thumbnail
wired.com
7 Upvotes

r/blackhat 1d ago

🙋‍♂️ What if you could write an encrypted (military-grade) love letter or diary notes that nobody can ever leak?

Post image
0 Upvotes

Dybuk lets you write normally, then seal the document into an encrypted .dybuk vault using AES-256-GCM + Argon2id.

I built Dybuk because i wanted a writing app that sits somewhere between Notepad and a full-blown word processor without the bloat, accounts, cloud sync, or Markdown syntax getting in the way.
Headers, bold, lists, code blocks, math, colours, glow effects, etc. are handled through shortcuts and a contextual toolbar. Markdown is serialized under the hood.
You just write here your deepest/darkest thoughts without the tension of someone reading it. 😅

What is the .dybuk format? Save a document in a completly self-contained encripted vault.
The password is processed through Argon2id, and the resulting encription uses AES-256-GCM with authenticated encription. So the file itself contains no plaintext.

That means .dybuk isn't really limited to diary entries. Private notes, diary entries, personal writing, love letters, confessions, secret messages,etc.
Anything you don't want sitting around as readable plaintext.

You can literally write a love letter normally, seal it into a .dybuk file, send the file to someone, and give them the password separately.

I just made the first public pre-release, so it's definitely not production-ready yet. There are still bugs and rough edges. I'm releasing it now because i'd rather have people actually use the idea than spend another few months polishing it in isolation.

GitHub: https://github.com/lukagray-dev/Dybuk

If you write private things, I'd like to know what you actually write in an encrypted writing format like .dybuk?


r/blackhat 2d ago

Cern Basher - shares some really great use cases for electric cybercabs

Thumbnail x.com
0 Upvotes

r/blackhat 5d ago

I made an open-source DDoS stress tool.

0 Upvotes

r/blackhat 5d ago

Hypothetically, how likely is the DOJ to prosecute a U.S. citizen for ransomware against a foreign adversary?

14 Upvotes

EDIT: Reading comprehension in this sub is at rock bottom levels. Please read the following post prior to commenting.

Hello everyone. I have a completely hypothetical question that I have been debating with friends. Due to strong arguments both for and against without a clear consensus, I feel it may be beyond our expertise as armchair lawyers and as such, I am pleased to present this to the greater community.

While this is a broad hypothetical, there are a few specific details that must be outlined for the sake of the argument:

\- The victim would be a clear, undeniable foreign adversary/hostile nation to the US

\- There is no direct conflict with or collateral damage to US interests or allies(as a result of the ransomware being deployed)

\- The individual would meticulously report all income from the ransomware payouts on Schedule 1, Line 8z of the IRS Form 1040, pleading the Fifth Amendment on the source of the income, and then pay their 37% top marginal tax rate(They make sure to pay Uncle Sam his cut and avoid committing tax fraud/evasion).

That being said, I want to note: I am **NOT** asking if the frameworks and legal statues to charge a person for this exist. They absolutely do.

The question is if the US citizen would be prosecuted and/or convicted if the victim is unable/unwilling to cooperate with a US court, there is no conflict with US interests, and they even pay taxes on the income.

Thanks and looking forward to any and all answers!

Disclaimer: Do not attempt this at home. Side effects may range from blacked out SUV’s parked outside your house to being arrested/murdered by a foreign intelligence service.


r/blackhat 6d ago

FBI Disrupts Chinese Proxy Tools Used in Mass Hacking of US Agencies and Infrastructure

Thumbnail
wired.com
60 Upvotes

r/blackhat 7d ago

Insight into agentic hacking tools: Hermes, OpenClaw and the Bayesian brain

Thumbnail
dreamgroup.com
2 Upvotes

r/blackhat 11d ago

I finally released Operon 1.0, a Rust-native agent harness built from scratch

Enable HLS to view with audio, or disable this notification

2 Upvotes

Following up on my post from last month. Got some good feedback and some fair criticism, so this time I actually want to be straight about what this is instead of hyping it up.

After several months of work I finally pushed the first stable release of Operon.

Its an agent harness with multiple frontends, same category as Claude Code or OpenClaw. Can manage files, run shell commands, browse the web, chain together multi step tasks, and you can control it from WhatsApp or Telegram too. Where its different is you dont need a terminal to use it. Theres a proper GUI (Tauri, not electron) and a TUI if youre the type who actually wants the terminal.

Why I started this? theres a detailed writeup in the README if you want the full reasoning, not gonna repeat it all here.

On the rust thing, no im not claiming it makes the AI itself faster, it doesnt really, most of the agent loop is just waiting on API calls regardless of language. Where rust actually helps is Operon idles around 65mb ram and opens in under 50ms, which matters more when the thing is supposed to just live on your machine in the background without you noticing its even running.

Since its reachable over whatsapp/telegram i had to actually think about who's allowed to do what. you (the owner) get full access, everyone else gets nothing by default until you explictly allow it. permission stuff is scoped down to specific tools/folders/channels, details in the readme.

Current state, being honest: - GUI basically done, use it almost daily - TUI still being wired up, not fully working - Vscode extension is planned, not built yet - I'm solo dev so expect rough edges and bugs, this isn't some polished startup product

Not rly looking for upvotes, mostly want people to break it and tell me whats broken. binaries on the releases page

repo: https://github.com/lukagray-dev/Operon


r/blackhat 12d ago

Anyone can recommend tools on Kali Linux to find the IP address of a network without connecting to the network?

0 Upvotes

r/blackhat 15d ago

[Help] Recovering/Flashing locked Redmi Y2 (Snapdragon 625 / ysl) without Mi Account authorization or hardware teardown

Thumbnail
0 Upvotes

r/blackhat 16d ago

massive azure exfiltration campaign impacts global brands - mcdonald’s, vodafone, and others

Thumbnail
infostealers.com
7 Upvotes

r/blackhat 16d ago

hacking windows pc

0 Upvotes

hey so im a really beginner hacker and i want to know how to hack a windows pc 10/11 with kali-linux what do i need to do to hack into a windows pc to get thru firewall and all of that and then the codes i need to do in the terminal to hack it can someone help me pls?


r/blackhat 18d ago

Software

0 Upvotes

Hello everyone. There use to be a software you had to put proxies to able to generate working accounts. It was a software were it gave you fast food/restaurant account rewards . It saved me in college. Does anybody know what it was called?


r/blackhat 19d ago

Ongoing phishing, targeting financial institutions and using Telegram as their C2

Thumbnail
anuw.me
2 Upvotes

r/blackhat 20d ago

Editing an invoice

0 Upvotes

I have an invoice I need to edit and Claude has declined editing it .What tool to use?


r/blackhat 20d ago

This Coin-Sized Device Can Hack a Boeing 737

Thumbnail
wired.com
20 Upvotes

r/blackhat 20d ago

Largest AI Supply Chain Breach of 2026: LiteLLM Hack Impacts Thousands of Global Enterprises - Data from the breach is now available

Thumbnail
infostealers.com
4 Upvotes

Hudson Rock's researchers have obtained and analyzed a staggering 153GB RAR archive. This massive corpus contains exactly 433,909 files. Through our analysis, we have successfully attributed 118,829 CI runner dumps to 2,488 affected corporate domains. Whenever a developer machine, production server, or CI/CD pipeline executed the compromised LiteLLM package, the threat actors successfully harvested the live environment memory and configurations mid-execution.


r/blackhat 27d ago

A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide

Thumbnail
wired.com
159 Upvotes

r/blackhat 27d ago

Coldwallet

0 Upvotes

Cold wallet exploit


r/blackhat 28d ago

Exploit & Hacktool Search Engine

Thumbnail
sploitus.com
14 Upvotes

Sploitius 2.0 is a new version of the coolest exploit search engine, updated design, new features. Better, faster, stronger


r/blackhat 29d ago

b3rito/oopso: An easy-to-use client-side OSINT query builder for discovering exposed file managers across search engines

4 Upvotes

I spent some time analyzing major open-source file managers to see which ones remain fully functional when authentication is disabled or bypassed. By extracting specific keywords, UI markers, and unique strings from those unauthenticated landing pages, I built targeted search queries to spot exposed instances.

To make these easy to use without manually tweaking syntax every time, I put together oopso, a lightweight browser tool that automates creating these search patterns across different engines.

It’s pretty straightforward, but hopefully saves some time if you do this kind of recon.

Check out the code on GitHub:https://github.com/b3rito/oopso


r/blackhat Jul 31 '26

Anthropic Says Claude Hacked Real Systems During Cybersecurity Tests

Thumbnail
wired.com
41 Upvotes

r/blackhat Jul 27 '26

This shouldn't be allowed...

Thumbnail
github.com
0 Upvotes

I built , an anonymous , hacker-style communication platform like a root chat — communications happen over the Tor network and all data is decentralized — every user on the network keeps a piece of the data...

learn more from the repo link.


r/blackhat Jul 27 '26

Looking for sms rental.

0 Upvotes

Hello im looking for a sms rental service and all i need it for is literally like 10 minutes to receive a code for a promo. I use textverified right now but its $6 for 3 days and i rather pay $2 for 1 or something like that since i only need the number for a very short amount of time. It needs to be a REAL number Non-Voip. Another thing is this service is very unknown so there is NO site that will have it i need it to just receive the message for me and forward it.