Fake Instagram Growth Tool "imad213" Steals Credentials: Malware Alert!

A new malware campaign is targeting Instagram users seeking to boost their follower counts. Disguised as a legitimate growth tool called "imad213," the malware steals login credentials and sends them to an attacker's server.
The malware, distributed via a malicious PyPI package, uses sophisticated social engineering tactics, including professional branding and detailed documentation, to trick users into installing it. Victims are instructed to use simple commands like "pip install imad213" and "imad213," making the process seem legitimate.
Once installed, the tool displays a convincing "INSTA-FOLLOWERS" interface, prompting users to enter their real Instagram credentials. Unbeknownst to them, this information is being harvested and sent to the attacker.
Socket.dev analysts have linked this campaign to a threat actor known as "IMAD-213," who uses the email address madmadimado59@gmail.com and operates multiple malicious tools. The malware also includes a remote kill switch, giving the attacker control over all infected instances.


The stolen credentials are then broadcast to ten different Turkish bot services, including takipcimx.net, takipcizen.com, and bigtakip.net. These services, registered around the same time and actively maintained, suggest a well-coordinated and long-term operation.
Compromised accounts face immediate policy violations, potentially leading to suspension or permanent termination. With Instagram's massive user base, this campaign poses a significant threat, exploiting users' desire for social media validation. Users should be extremely cautious when using third-party growth tools and verify their legitimacy before providing any credentials.
- Other (42)
- Ransomware (152)
- Events and News (27)
- Features (45)
- Security (481)
- Tips (79)
- Google (24)
- Achievements (11)
- Products (35)
- Activation (7)
- Dealers (1)
- Bank Phishing (46)
- Malware Alerts (223)
- Cyber Attack (274)
- Data Backup (12)
- Data Breach (111)
- Phishing (160)
- Securty Tips (2)
- Browser Hijack (19)
- Adware (15)
- Email And Password (69)
- Android Security (71)
- Knoweldgebase (38)
- Botnet (16)
- Updates (4)
- Alert (71)
- Hacking (59)
- Social Media (8)
- vulnerability (63)
- Hacker (33)
- Spyware (11)
- Windows (7)
- Microsoft (21)
- Uber (1)
- YouTube (1)
- Trojan (3)
- Website hacks (6)
- Paytm (1)
- Credit card scam (1)
- Telegram (3)
- RAT (5)
- Bug (3)
- Twitter (2)
- Facebook (7)
- Banking Trojan (8)
- Mozilla (2)
- COVID-19 (5)
- Instagram (3)
- NPAV Announcement (9)
- IoT Security (1)
- Deals and Offers (2)
- Cloud Security (12)
- Offers (5)
- Gaming (1)
- FireFox (2)
- LinkedIn (3)
- WhatsApp (5)
- Amazon (2)
- DMart (1)
- Payment Risk (4)
- Occasion (3)
- firewall (2)
- Cloud malware (2)
- Cloud storage (2)
- Financial fraud (13)
- Impersonation phishing (1)
- DDoS (7)
- Smishing (2)
- Whale (0)
- Whale phishing (4)
- WINRAR (2)
- ZIP (2)