#SIMfarm

2025-11-07

📬 Razzia in Berlin und Brandenburg: massenhafter Versand von SMS als Betrugsversuch
#Mobilfunk #Szene #§263StGB #BerlinTempelhof #dpaMeldung #Kurznachrichten #PhisingBetrüger #Simfarm #SMS sc.tarnkappe.info/90eb1c

gtbarrygtbarry
2025-10-28

Europol Dismantles SIM Farm Network Powering 49 Million Fake Accounts Worldwide

Europol announced the disruption of a sophisticated cybercrime-as-a-service (CaaS) platform that operated a SIM farm and enabled its customers to carry out a broad spectrum of crimes ranging from phishing to investment fraud.

thehackernews.com/2025/10/euro

Zeroday Podcast (sven)zeroday@chaos.social
2025-10-21

Faszinierend - #Heise gibt Einblicke in eine aufgeflogene Sim-Farm mit 40000 aktiven Sim-Karten youtube.com/watch?v=EgbOzut6O6M #itsecurity #simfarm #simbox

2025-10-19

Hey team! 👋 It's been a bit quiet on the news front over the last 24 hours, but we've still got some important updates on a major cybercrime takedown, ongoing infostealer campaigns, and a significant data privacy fine. Let's dive in:

Europol Disrupts Massive SIM Farm Network 🛡️

- Europol, in 'Operation SIMCARTEL', has dismantled a sophisticated cybercrime-as-a-service (CaaS) platform operating SIM farms globally.
- The operation led to seven arrests, seizure of 1,200 SIM box devices containing 40,000 active SIM cards, five servers, and significant financial assets.
- This network enabled the creation of over 49 million fake online accounts, facilitating phishing, smishing, investment fraud, and other crimes across more than 80 countries.

📰 The Hacker News | thehackernews.com/2025/10/euro

TikTok Videos Push Infostealers via ClickFix Attacks ⚠️

- Cybercriminals are actively using TikTok videos, disguised as free activation guides for popular software like Windows and Spotify, to spread information-stealing malware.
- The campaign leverages a "ClickFix" social engineering technique, tricking users into executing malicious PowerShell commands as an administrator.
- This script downloads Aura Stealer, which then exfiltrates sensitive data including browser credentials, authentication cookies, and cryptocurrency wallet information.

🤖 Bleeping Computer | bleepingcomputer.com/news/secu

Experian Fined for Mass Data Collection Violations 🔒

- Experian Netherlands has been hit with a EUR 2.7 million ($3.2 million) fine by the Dutch Data Protection Authority (AP) for multiple GDPR violations.
- The company unlawfully collected personal data from various public and private sources, including the Chamber of Commerce and telecom/energy companies, without informing individuals or obtaining consent.
- This data was used to generate credit scores, which adversely affected individuals' ability to secure services or pay installments, highlighting critical data privacy breaches.

🤖 Bleeping Computer | bleepingcomputer.com/news/lega

#CyberSecurity #ThreatIntelligence #Cybercrime #Europol #SIMFarm #Malware #Infostealer #TikTok #SocialEngineering #DataPrivacy #GDPR #Experian #InfoSec

2025-10-17

It's been a busy 24 hours in the cyber world with significant updates on recent breaches, innovative threat actor techniques, critical vulnerabilities, and ongoing legal battles over digital privacy. Let's dive in:

Recent Cyber Attacks & Breaches ⚠️

- Peer-to-peer lender Prosper confirmed a September cyberattack, with HaveIBeenPwned reporting 17.6 million affected victims. Compromised data includes email addresses, personal details, and Social Security numbers, though customer accounts and funds remain safe.
- Dairy Farmers of America (DFA) disclosed a June ransomware attack by the Play gang, which used sophisticated social engineering to steal sensitive personal information, including SSNs and bank account numbers, from 4,546 individuals. This highlights a concerning trend of increasing attacks on the food and agriculture sector.
- Envoy Air, an American Airlines subsidiary, confirmed data theft from its Oracle E-Business Suite by the Clop extortion group. Clop exploited zero-day vulnerabilities (CVE-2025-61882, CVE-2025-61884) in Oracle EBS, a campaign that has affected dozens of organisations, including Harvard University.
- Europol's "SIMCARTEL" operation dismantled a sophisticated cybercrime network responsible for over 3,200 fraud cases and $5.8 million in losses. The network used 1,200 SIM box devices and 40,000 active SIM cards to facilitate phishing, scams, and other crimes across 80+ countries by providing anonymous phone numbers for fake accounts.
- An indictment against former US National Security Adviser John Bolton revealed that suspected Iranian hackers accessed his email account in July 2021, threatening to leak sensitive materials and drawing comparisons to past high-profile email breaches.

🕵🏼 The Register | go.theregister.com/feed/www.th
🗞️ The Record | therecord.media/dairy-farm-lea
🗞️ The Record | therecord.media/regional-airli
🤖 Bleeping Computer | bleepingcomputer.com/news/secu
🤫 CyberScoop | cyberscoop.com/europol-dismant
🗞️ The Record | therecord.media/europe-sim-far
🤫 CyberScoop | cyberscoop.com/john-bolton-ind

New Threat Research & Tradecraft 🛡️

- North Korean threat groups, including Famous Chollima and UNC5342, are employing advanced evasive techniques. Famous Chollima uses BeaverTail and OtterCookie for keylogging and screenshotting, while UNC5342 leverages EtherHiding, a JavaScript payload that uses a public blockchain as a decentralised, resilient C2 server.
- These groups primarily target job seekers with fake offers and technical assessments to deploy multi-stage malware (JadeSnow, BeaverTail, InvisibleFerret) for espionage, persistent network access, and cryptocurrency theft.
- Microsoft has revoked over 200 fraudulent certificates used by the Vanilla Tempest (aka Vice Society/Vice Spider) ransomware group. These certificates signed fake Microsoft Teams installers that delivered the Oyster backdoor, ultimately leading to Rhysida ransomware deployment, often initiated via SEO poisoning.

🤫 CyberScoop | cyberscoop.com/north-korea-att
💥 The Hacker News | thehackernews.com/2025/10/micr

Critical Vulnerabilities & Exposure 🚨

- A critical out-of-bounds write vulnerability (CVE-2025-9242, CVSS 9.3) in WatchGuard Fireware OS's IKEv2 process allows unauthenticated remote code execution (RCE). This pre-authentication flaw, affecting internet-exposed VPN services, is highly attractive to ransomware groups and requires immediate patching.
- Over 266,000 F5 BIG-IP instances are exposed online following a nation-state breach (linked to China's UNC5291) that stole source code and undisclosed vulnerabilities. F5 has released patches for 44 flaws, and CISA has mandated federal agencies to update or decommission end-of-life devices by late October.
- Microsoft patched CVE-2025-55315 (CVSS 9.8), the highest-severity ASP.NET Core flaw ever, which is an HTTP request smuggling bug in the Kestrel web server. This vulnerability could allow authenticated attackers to hijack credentials, bypass security controls, or perform injection attacks, necessitating prompt updates for all affected .NET applications.
- ConnectWise addressed two critical vulnerabilities in its Automate RMM platform: CVE-2025-11492 (CVSS 9.6) for cleartext sensitive data transmission and CVE-2025-11493 (CVSS 8.8) for lack of update integrity verification. These flaws, especially when combined, enable adversary-in-the-middle (AiTM) attacks to intercept traffic and push malicious updates, posing a significant supply chain risk.

💥 The Hacker News | thehackernews.com/2025/10/rese
🤖 Bleeping Computer | bleepingcomputer.com/news/secu
🤖 Bleeping Computer | bleepingcomputer.com/news/micr
🤖 Bleeping Computer | bleepingcomputer.com/news/secu

Digital Rights & Regulatory Battles ⚖️

- The Electronic Frontier Foundation (EFF) and three US labor unions are suing the Trump administration over its "Catch and Revoke" social media surveillance program. This program uses AI to monitor non-citizen visa holders' online activity for "anti-American" views, raising serious First Amendment and privacy concerns, and has led to union members self-censoring.
- The Computer & Communications Industry Association (CCIA) is challenging Texas's new "App Store Accountability Act," which mandates age verification and parental consent for app downloads for users under 18. The CCIA argues this law is an unconstitutional "censorship regime" that infringes on free speech and user privacy, while being largely ineffective.

🕵🏼 The Register | go.theregister.com/feed/www.th
🗞️ The Record | therecord.media/tech-industry-

#CyberSecurity #ThreatIntelligence #Ransomware #DataBreach #NationState #APT #ZeroDay #Vulnerability #RCE #SupplyChain #SIMFarm #SocialEngineering #AI #DataPrivacy #Regulatory #InfoSec #CyberAttack #Malware #IncidentResponse

2025-10-02

Ich glaube, nachdem nun selbst einige Medien aus dem InfoSec-Bereich die stark nach Humbug riechende SIM-Farm-Geschichte des USSS völlig unkritisch übernommen haben, bin ich wohl gezwungen, den Medienkonsum einiger Medien zu überdenken.

Positiv erwähnt sei Seytonic.

#USpol #USSS #UNGA #NYC #NewYork #SIMFarm #Infosec #Security

Alexander Janßenitnomad@ruhr.social
2025-09-27

This article about the #SIMFarm in #NYC is actually not that bad. It's still cybering a little, but not too cringe. lite.cnn.com/2025/09/27/us/nyc

2025-09-25
<!--kg-card-begin: html-->
<div class="outpost-pub-container"></div>
<!--kg-card-end: html-->

<!--kg-card-begin: html-->
  <div class="subscribe">
    <h5 class="subscribe__title">Subscribe</h5>
    <div class="subscribe__content">
      <div class="subscribe__descr" id="post-subscribe">Join the newsletter to get the latest updates.</div>
      <form>
        <input required="required" type="email" />
        <button class="btn--brand" title="Subscribe" type="submit">
          <i class="icon icon-arrow-right">
  	        <svg class="icon__svg" xmlns="http://www.w3.org/2000/svg">
    		  <use xlink:href="https://www.404media.co/assets/icons/feather-sprite.svg?v=a043330434#arrow-right" xmlns:xlink="http://www.w3.org/1999/xlink">
  			</svg>
	      </i>
        </button>
        <div class="message message-success">
          <div class="message__header">
            <div class="message__type">Success</div> 
            <div class="message__close js-msg-close">
              <i class="icon icon-x icon--xs">
  			    <svg class="icon__svg" xmlns="http://www.w3.org/2000/svg">
    			  <use xlink:href="https://www.404media.co/assets/icons/feather-sprite.svg?v=a043330434#x" xmlns:xlink="http://www.w3.org/1999/xlink">
  				</svg>
			  </i>
            </div>
          </div>
          <div class="message__content">
            Great! Check your inbox and click the link.
          </div>
        </div>
        <div class="message message-error">
          <div class="message__heade
2025-09-24

‘SIM Farms’ Are a #Spam Plague. A Giant One in New York Threatened US #infrastructure , Feds Say

The agency says it found a network of some 300 #servers and 100,000 #SIM cards—enough to knock out cell service in the #NYC area. Experts say it mirrors facilities typically used for #cybercrime.
#simfarm

wired.com/story/sim-farm-new-y

Secret Service dismantles massive SIM farm. Mobile domain becoming security battleground.
jpmellojr.blogspot.com/2025/09
#MobileSecurity #SIMFarm #NationalSecurity #SecretService

30 million texts per minute, enough to knock out NYC cell service!! Spam’s getting serious, stay sharp out there. #SIMFarm #Scams #CyberSecurity #InfoSec

‘SIM Farms’ Are a Spam Plague....

N-gated Hacker Newsngate
2025-09-24

🚨 BREAKING NEWS: Secret Service "uncovers" shocking SIM farm, aka... a regular Tuesday for organized crime. 🎉 Major newspapers regurgitate official statements, failing once again to distinguish between a spy thriller and a tech support nightmare. 📞💥
cybersect.substack.com/p/that-

Nick EspinosaNickAEsp
2025-09-23
CONFIG.SYS: LOADHIGHloadhigh@bitbang.social
2024-09-04

Some #SimFarm gameplay tips:

* (Lake) water pumps can also used to push water in ditches further (e.g. coming from "weak" windmills)
* Irrigation ditches make the best fences for animals as they can't cross them
* Animals trapped in barns (using ditches) increase in price every week *and* don't eat from those expensive hay bales
* Roads and ditches can be built outside your land, saving precious space
* Small and large sheds can also store bought chemicals (in case you like that sort of thing)

A screenshot of the DOS game SimFarm showing two irrigation ditches, with the one having a water pump pushing the water further.A screenshot of the DOS game SimFarm showing two cows that are healthy and having a very nice $690 value, despite having been trapped inside a barn without any water or food for months.
CONFIG.SYS: LOADHIGHloadhigh@bitbang.social
2024-09-04

In #SimFarm one of your biggest expenses is the spraying of your fields with fertilizer and chemicals.

Spraying is supposed to cost $200 (that's what the tooltip tells you) but actually costs $275. That's 37.5% more!

There is a way to buy them in advance for $200 but it involves a lot of (in my opinion) unfun micromanagement and clicking.

That's why I wrote a patcher for the game (v1.0 and v1.3, #DOS) that brings the price down to $200.

You can get it here: gofile.io/d/FdBmu6

A screenshot of the DOS game SimFarm that shows the game saying that spraying a field with pesticide costs $200 but it's actually $275.A screenshot of my patcher for SimFarm that reduces the price of chemicals to $200
CONFIG.SYS: LOADHIGHloadhigh@bitbang.social
2024-08-30

#SimFarm apparently a crop editor that you could order separately from Leaping Lizard Software (probably for #DOS?)

I found out about it from a usenet post (groups.google.com/g/comp.sys.m, 1995) asking if the editor was also for Mac. The writer learned about it from an ad in the SimFarm Almanac book (a "strategy guide" although one review called it shallow and more of an extended tutorial)

Unfortunately both book and program are nowhere to be found but I'd love to get my hands on either of them.

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst