Skip to main content
Sign in
AVOID.NET

Entity Graph

Browse extracted entities, relationships, and potential duplicates.

Total entities
22,536
Relationships
17,946
Potential duplicates
0

Entities

Australia imposed additional sanctions on Aeza-related infrastructure in a round targeting ransomware infrastructure providers; UK had already joined the July 2025 U.S. designation of Aeza International Ltd.(2025-11-01:clickfix-macos-go-based-infostealer-crypto-wallet-drainer-august-2026)event
e3c6e3ba
U.S. Treasury OFAC sanctioned Aeza Group LLC and three affiliated entities (Aeza International Ltd., Aeza Logistic LLC, Cloud Solutions LLC) along with four individual executives, for providing bulletproof hosting infrastructure to ransomware and infostealer operators including Meduza, Lumma, and BianLian.(2025-07-01:clickfix-macos-go-based-infostealer-crypto-wallet-drainer-august-2026)event
a84d5602
ClickFix macOS Go-Based Infostealer Crypto Wallet Drainer (August 2026)protocol
ce1fc8b3
HackRead published coverage confirming gamers, cryptocurrency users, and web application users as the primary target demographics, and detailing the malware's harvesting of Steam, Valorant, Roblox, and Minecraft accounts alongside wallet seed phrases.(2026-08-15:vanta-stealer-python-infostealer-targeting-crypto-wallets)event
a047e023
CyberSecurityNews reported that Vanta Stealer empties browser vaults, crypto wallets, and gaming accounts, describing its speed of data extraction on compromised Windows systems.(2026-08-10:vanta-stealer-python-infostealer-targeting-crypto-wallets)event
386ecd6c
GBHackers reported on Vanta Stealer's use of PyArmor obfuscation, its cross-platform Python base, and its targeting of browser passwords, crypto wallets, and Discord tokens.(2026-08-07:vanta-stealer-python-infostealer-targeting-crypto-wallets)event
952862f3
Rankiteo catalogued the threat with a severity rating of 85/100, noting the malware's targeting of Discord, Telegram, Roblox, and Minecraft alongside browser passwords and cryptocurrency wallets.(2026-08-06:vanta-stealer-python-infostealer-targeting-crypto-wallets)event
9ab4d646
Point Wild's Lat61 Threat Intelligence Team (researchers Prathamesh Shingare and Kedar Shashikant Pandit) published the primary technical dissection of Vanta Stealer, documenting its PyInstaller/PyArmor architecture, dynamic module retrieval, targeted data categories, exfiltration mechanism, and 20 SHA256 IOCs.(2026-07-28:vanta-stealer-python-infostealer-targeting-crypto-wallets)event
a590fe71
Vanta Stealer — Python Infostealer Targeting Crypto Walletsorganization
02388bc6
CPcTERriWFUy7vTqdNrdCmhEpG6z6qEqcTp3UrjbxBEawallet52% conf
064cc173
vulert.comdomain
282690f7
osv.devdomain
286beaff
TrapDoor supply chain campaign detected targeting 34 packages across npm, PyPI, and Crates.io, stealing crypto wallet keystores, SSH keys, and cloud credentials from developers.(2026-05-19:requests-secure-v2)event
0d1313d0
RubyGems and PyPI reported hit by further waves of malicious packages stealing credentials and cryptocurrency, prompting security changes to both registries. Specific date approximate based on reporting.(2025-08-01:requests-secure-v2)event
0191aaa7
Checkmarx reported packages including AtomicDecoderss, TrustDecoderss, WalletDecoderss, and ExodusDecodes on PyPI, masquerading as wallet recovery tools to steal private keys and mnemonic phrases from Atomic, Trust Wallet, MetaMask, Exodus, and other wallets. Specific date approximate based on reporting.(2024-10-01:requests-secure-v2)event
99e838ab
requests-darwin-lite, a fake requests variant concealing a Golang Sliver C2 framework inside a manipulated PNG logo file, was identified on PyPI after 417 downloads and taken down. Specific date approximate based on reporting.(2024-05-01:requests-secure-v2)event
13639402
PyPI suspended new project creation and user registration at 02:16 UTC in response to the mass typosquatting campaign. All identified malicious packages were removed the same day.(2024-03-28:requests-secure-v2)event
56c682d7
Over 500 typosquatting variants of popular Python packages including more than 50 targeting the requests library (e.g., reqzests, requzsts) were uploaded to PyPI by an automated campaign carrying zgRAT-linked crypto-stealing payloads.(2024-03-26:requests-secure-v2)event
91d8e82f
requests-secure-v2organization
aa2fcca1
707b9ad7
Zscaler ThreatLabz updates its original blog post on the indirect prompt injection campaigns. No confirmed takedown of debank[.]auction is noted in available sources as of this date.(2026-08-05:debank-auction)event
e05c25f4
Broader security press coverage of the campaign continues, with Infosecurity Magazine and other outlets amplifying the Zscaler findings.(2026-07-09:debank-auction)event
0ec21b22
SecurityWeek reports on the Zscaler findings, noting that four of 26 LLMs executed fraudulent crypto payments in testing and that GPT-5.4 and Claude Sonnet 4.5 misclassified the DeBank typosquatting domain as legitimate when lacking a reference source.(2026-07-06:debank-auction)event
49550bca
Zscaler ThreatLabz publishes research documenting debank[.]auction as an active indirect prompt injection campaign targeting AI agents, alongside a companion Python-library impersonation campaign.(2026-07-02:debank-auction)event
86af4f98
The Hacker News publishes analysis arguing that typosquatting has evolved from a user-facing risk to an AI supply chain threat, establishing the broader context for campaigns like debank.auction.(2026-05-01:debank-auction)event
9fea7a43
DeBank (debank.com), the legitimate DeFi portfolio tracker being impersonated, launches. Exact founding date is approximate; commonly cited as 2018.(2018-01-01:debank-auction)event
13579ff7
debank.auctionorganization
92e402ce
dharlawllp.comdomain
21ca0d33
Aleksei Andriunin sentenced to eight months in prison and one year supervised release. Gotbit Consulting LLC sentenced to five years probation and ordered to forfeit approximately $23 million and cease operations.(2025-06-01:vy-pham)event
d58f39fe
Gotbit founder Aleksei Andriunin pleads guilty to wire fraud and conspiracy to commit market manipulation.(2025-03-20:vy-pham)event
f1e19c08
Gotbit founder Aleksei Andriunin extradited to the United States.(2025-02-25:vy-pham)event
400bac76
DOJ unseals criminal information charging Vy Pham with conspiracy to commit market manipulation, conspiracy to commit wire fraud, and conspiracy to operate an unlicensed money transmitting business. Pham agrees to plead guilty. SEC simultaneously files civil complaint against Pham (Litigation Release No. 26153). SEC also files separate civil complaint against four other Saitama LLC promoters.(2024-10-09:vy-pham)event
a8f0a0c5
Gotbit founder Aleksei Andriunin arrested in Portugal as part of Operation Token Mirrors.(2024-10-08:vy-pham)event
70d2a4be
Alleged Robo Inu wash trading campaign with Gotbit ends, according to DOJ timeline.(2023-06-01:vy-pham)event
e2743203
Prosecutors allege Pham instructs Gotbit to boost Robo Inu volume 'above 1.1mil daily' on BitMart.(2023-01-01:vy-pham)event
a155a594
Saitama LLC dissolved. Saitama co-founders Armand, Kohli, and Tran form a new company in Dubai and relocate operations.(2022-06-01:vy-pham)event
fe5baf0c
Robo Inu Finance (RBIF) reaches its all-time high price.(2022-04-16:vy-pham)event
08c21f84
Robo Inu Finance begins alleged paid wash trading campaign with Gotbit Consulting LLC. Prosecutors allege a private Telegram chatroom is created among Pham, Gotbit executives Fedor Kedrov and Qawi Jalili, and others to coordinate fabricated volume.(2022-02-01:vy-pham)event
623f6254
Robo Inu Finance (RBIF) token launches on Ethereum, founded by Vy Pham after departing Saitama.(2021-11-01:vy-pham)event
46a2ed1f
Saitama LLC incorporated in Massachusetts. Vy Pham is among the promoters of Saitama Inu.(2021-08-01:vy-pham)event
fb6702b5
Saitama Inu token launches on Ethereum.(2021-05-30:vy-pham)event
0930b401
Vy Phamorganization
3112d97b
torrentfreak.comdomain
5ae31e11
SEC files proposed final judgment (LR-26496): Rainberry agrees to pay $10 million civil penalty and accept permanent injunction against Section 17(a)(3) violations. All remaining claims against Justin Sun, Tron Foundation, BitTorrent Foundation, and Rainberry dismissed with prejudice. No admissions of wrongdoing. Subject to federal court approval.(2026-03-05:rainberry-inc)event
fbe3397d
Six celebrity defendants (Lindsay Lohan, Jake Paul, Ne-Yo, Lil Yachty, Kendra Lust, Akon) settle SEC charges, paying approximately $400,000 each without admitting or denying findings.(2023-01-01:rainberry-inc)event
139475af
SEC files complaint (LR-25676) against Justin Sun, Tron Foundation, BitTorrent Foundation, and Rainberry Inc., alleging unregistered securities sales, wash trading, and undisclosed celebrity promotions of TRX and BTT. Eight celebrities including Lindsay Lohan and Jake Paul charged separately.(2023-03-22:rainberry-inc)event
d23788da
Former Rainberry employees Hall and Juraszek file California federal lawsuit alleging Sun directed illegal downloading of copyrighted films.(2020-01-01:rainberry-inc)event
b9ae5653
BitTorrent Token (BTT) launched via Binance Launchpad initial exchange offering.(2019-01-28:rainberry-inc)event
eb42e253
Data refreshes every 5 minutes · All metrics derived from Supabase