Register for your free account! | Forgot your password?
Call Of Duty Cheats

Go Back   elitepvpers > Popular Games > Call of Duty
You last visited: Today at 17:05

  • Please register to post and access all features, it's quick, easy and FREE!

Advertisement



Cobalt innocent & competitor malware spread

Discussion on Cobalt innocent & competitor malware spread within the Call of Duty forum part of the Popular Games category.

Closed Thread
 
Old   #1

 
lort1234's Avatar
 
elite*gold: 124
Join Date: Mar 2015
Posts: 1,272
Received Thanks: 542
Post Cobalt innocent & competitor malware spread

This is copy&pasted from Cobalt's discord server where they announced it.

Announcement:
Quote:
After looking at reports of people saying cobalt is a "RAT", We have concluded that there is an infected client exe being spread that is 8MB in size.

This client exe seems to be being spread by a competitor trying to sabotage us.

After looking further into this infected client exe we saw that this will implant a file called "DRM.exe", This file is NOT related to cobalt and delete it if you see it.

This client exe tries to make it as OBVIOUS as possible to make us look bad. ( clipboard replacer, forcing discord to use 100% CPU, etc... )

It also drops a JavaScript file into your discord files, This script will send information about your PC to the competitors server.

We have found that the webhook attached in the script file matches the exact server id of our competitions server.

We have attached the DEOBFUSCATED script file here for people to look at and have attached evidence that this client exe is being spread by our competition trying to sabotage us, and that our client is clean.

I hope this clears up all the confusion that has happened in the past few days ❤️, It is disappointing to see competitors sabotaging our product instead of improving their own...

NOTE:
I have made this announcement yesterday but since then a elite pvpers post has been posted talking about this, If the so called reverse engineers of elite pvpers want to take a moment to see which server the webhook leads in the javascript file they will find it leads directly to our competitions server 😃

DEOBFUSCATED:

Videos & Picture:
lort1234 is offline  
Old 05/04/2022, 12:27   #2
 
elite*gold: 0
Join Date: Jan 2021
Posts: 2
Received Thanks: 3
he is lying his *** off, bro got caught in 4k
MadsM is offline  
Thanks
1 User
Old 05/04/2022, 16:50   #3

 
lort1234's Avatar
 
elite*gold: 124
Join Date: Mar 2015
Posts: 1,272
Received Thanks: 542
Edit
Official response from ACD:

Quote:
Dear User's, A competitor of ours just went from being a RAT to being a RAT because of us ��

Apparently WE sabotage their Website/Loader and added a File called "DMR.exe" Into their customers loader ( Which WE DID NOT DO )

The "Proof" proven by competitor doesn't mean anything if anything it just proves that their security is ****.

Webhook leading to our Discord ID? That's your proof? ����


I mean
If a random skid was able to do this to our tool than I would be freaking out as well.

that's your **** up now take responsibility for it.

I honestly don't think anyone would be able to even do such thing.

And if they did than shame on YOU and your user SHOULD be concerned.

How about you focus on your security instead of trying to come up with some bs as excuse on how the DMR.exe file ended up in your tool.

To begin with User's should never be concerned about their Security. Specially a random skid Sabotaging/Cracking a provider.


Also this same provider trying to blame us, Loves saying how WE Copy and Paste to Dev our own tool

Like if we aren't the first to ever bypass everything before any other provider.

what a joke that guy ehhhhhh?

Don't worry ACD User's that's something you guys don't ever have to worry about.

Security is our top focus asides of some BADASS update times/Features. ��


Edit2: Banned after posting this.
lort1234 is offline  
Old 05/04/2022, 18:49   #4


 
zebleer's Avatar
 
elite*gold: 49968
Join Date: Jul 2021
Posts: 2,044
Received Thanks: 1,370
@lort1234 are you part of the Cobalt staff team or something? Why are you defending them? They are clearly lying.

The loader is protected. It can't be edited by one byte without vmprotect or themida throwing errors & preventing functionality.

& how did Cobalt's server get infiltrated sot hat the loader could be tampered with & tampered copy retained?

Cobalt did this ****. Cobalt is spreading malware & counting on user stupidity to get away with it. They are malware distributors. They even admitted it, just not the part where they admit it was them who added it.

It's very obvious they put ACD's Discord server ID in their own malware to frame them. That doesn't mean ACD did it. Why would ACD send information to their public Discord server anyways, and not a secure private location?

Even if this was all somehow true (it's not), good luck with a provider that has such **** security that anyone can just spread malware to their users via their own website loader.

Do not support malware distributors please.

zebleer is offline  
Thanks
1 User
Old 05/04/2022, 19:30   #5

 
lort1234's Avatar
 
elite*gold: 124
Join Date: Mar 2015
Posts: 1,272
Received Thanks: 542
Quote:
Originally Posted by zebleer View Post
@ are you part of the Cobalt staff team or something? Why are you defending them? They are clearly lying.

The loader is protected. It can't be edited by one byte without vmprotect or themids throwing errors & preventing functionality.

& how did Cobalt's server get infiltrated sot hat the loader could be tampered with & tampered copy retained?

Cobalt did this shit. Cobalt is spreading malware & counting on user stupidity to get away with it. They are malware distributors. They even admitted it, just not the part where they admit it was them who added it.

It's very obvious they put ACD's Discord server ID in their own malware to frame them. That doesn't mean ACD did it. Why would ACD send information to their public Discord server anyways, and not a secure private location?

Even if this was all somehow true (it's not), good luck with a provider that has such shit security that anyone can just spread malware to their users via their own website loader.

Do not support malware distributors please.

No im not a part of their staff or even a customer.

1. It isn't unheard of in the cheating community for providers to crack other providers software to use it a harmful way.

2. The fact that it wasn't all client.exe that had the miner in them (Actually a small % of clients did) seems to me that it didn't come from their website, it was most likely a cracked version of the loader that had the miner. And that loader was most likely shared through out the discord.

3. Why ACD allegedly have sent the information to their main server i do not know, but people in the cheating community aren't always the smartest. Note that ACD doesn't dev anything them self, they are reselling their software.

4. The security of Cobalt i cannot speak about since i don't know about it. But again it isn't unheard of providers cracking other providers in the cheating community.

5. Again i don't think the client.exe was spread through their website, but most likely was a cracked version of their loader, that was spread through discord.

6. I don't see any reason for Cobalt to spread a miner to their users, they are growing rapidly, also faster than any other providers atm. Why ruin a growing good business? That in my eyes doesn't make any sense at all.

But for other providers this isn't good, the fast that both Cobalt and ACD have been seen as cheats you use for raging give them the same user base.

Cobalt is also 1/5 of the price of ACD cheat + spoofer.

I believe that ACD have more benefits for ruining Cobalt reputation/sales than Cobalt would have to rat their own customers.

I do not support malware distributors. But i also wont join on the hype train to accuse a provider, that in the most logically way probably haven't done anything wrong other than having a weak protection against debugging and are being stupid enough to allow share a client.exe in their general channel on discord.

I hope that people can make their own choice on who they believe in the right and who isn't. But it was not my intention to accuse ACD, i indented for this information to be public to people can make their own choice.

Good day
lort1234 is offline  
Old 05/04/2022, 19:45   #6


 
zebleer's Avatar
 
elite*gold: 49968
Join Date: Jul 2021
Posts: 2,044
Received Thanks: 1,370
Quote:
Originally Posted by lort1234 View Post
No im not a part of their staff or even a customer.

1. It isn't unheard of in the cheating community for providers to crack other providers software to use it a harmful way.

2. The fact that it wasn't all client.exe that had the miner in them (Actually a small % of clients did) seems to me that it didn't come from their website, it was most likely a cracked version of the loader that had the miner. And that loader was most likely shared through out the discord.

3. Why ACD allegedly have sent the information to their main server i do not know, but people in the cheating community aren't always the smartest. Note that ACD doesn't dev anything them self, they are reselling their software.

4. The security of Cobalt i cannot speak about since i don't know about it. But again it isn't unheard of providers cracking other providers in the cheating community.

5. Again i don't think the client.exe was spread through their website, but most likely was a cracked version of their loader, that was spread through discord.

6. I don't see any reason for Cobalt to spread a miner to their users, they are growing rapidly, also faster than any other providers atm. Why ruin a growing good business? That in my eyes doesn't make any sense at all.

But for other providers this isn't good, the fast that both Cobalt and ACD have been seen as cheats you use for raging give them the same user base.

Cobalt is also 1/5 of the price of ACD cheat + spoofer.

I believe that ACD have more benefits for ruining Cobalt reputation/sales than Cobalt would have to rat their own customers.

I do not support malware distributors. But i also wont join on the hype train to accuse a provider, that in the most logically way probably haven't done anything wrong other than having a weak protection against debugging and are being stupid enough to allow share a client.exe in their general channel on discord.

I hope that people can make their own choice on who they believe in the right and who isn't. But it was not my intention to accuse ACD, i indented for this information to be public to people can make their own choice.

Good day
1. It isn't unheard of in the cheating community for providers to crack other providers software to use it a harmful way.
The malware analysts who evaluated Cobalt and found what Cobalt admitted was found got it from cobalt.solutions, the primary website. Cobalt also said nothing about a crack but that is secondary evidence.

2. The fact that it wasn't all client.exe that had the miner in them (Actually a small % of clients did) seems to me that it didn't come from their website, it was most likely a cracked version of the loader that had the miner. And that loader was most likely shared through out the discord.
So you've never heard of evasive malware? That is a factor of malware analysis. Malware might remain inactive for long periods of time before starting activity, it might be present in only a few instances of production, etc. These are all examples of evasive measures for malware.

3. Why ACD allegedly have sent the information to their main server i do not know, but people in the cheating community aren't always the smartest. Note that ACD doesn't dev anything them self, they are reselling their software.
Yes I know ACD is a reseller so how are they somehow able to hack Cobalt's website and alter a VMP protected loader for download? If they are somehow smart enough to do that, they aren't going to be stupid enough to leave a trail to their main Discord server which is not secure, not anonymous, and might get deleted at any time.

4. The security of Cobalt i cannot speak about since i don't know about it. But again it isn't unheard of providers cracking other providers in the cheating community.
Already answered #1.

5. Again i don't think the client.exe was spread through their website, but most likely was a cracked version of their loader, that was spread through discord.
It came from their website. People aren't distributing cheat provider loaders on Discord unless it's advertised cracked, which Cobalt didn't get cracked. They get the shit from the website like everyone else.

6. I don't see any reason for Cobalt to spread a miner to their users, they are growing rapidly, also faster than any other providers atm. Why ruin a growing good business? That in my eyes doesn't make any sense at all.
Yeah their free and 10 eur products are really flying off the shelf because they're good and not because they are cheap. When something is free or cheap in the cheat scene, your device might be what they get, not your money.

But for other providers this isn't good, the fast that both Cobalt and ACD have been seen as cheats you use for raging give them the same user base.
Cobalt is also 1/5 of the price of ACD cheat + spoofer.
I believe that ACD have more benefits for ruining Cobalt reputation/sales than Cobalt would have to rat their own customers.

Yeah ACD seems to be profit driven while Cobalt seems to be malware infection driven. Not sure why you're surprised by the price difference. Cobalt has given away a lot for "free" too. Nothing in life is free.

I do not support malware distributors. But i also wont join on the hype train to accuse a provider, that in the most logically way probably haven't done anything wrong other than having a weak protection against debugging and are being stupid enough to allow share a client.exe in their general channel on discord.
I hope that people can make their own choice on who they believe in the right and who isn't. But it was not my intention to accuse ACD, i indented for this information to be public to people can make their own choice.

The proof is legitimately overwhelming that Cobalt is a malware distributor. This is not a hype train.
zebleer is offline  
Old 05/04/2022, 20:08   #7

 
lort1234's Avatar
 
elite*gold: 124
Join Date: Mar 2015
Posts: 1,272
Received Thanks: 542
Quote:
Originally Posted by zebleer View Post
1. It isn't unheard of in the cheating community for providers to crack other providers software to use it a harmful way.
The malware analysts who evaluated Cobalt and found what Cobalt admitted was found got it from cobalt.solutions, the primary website. Cobalt also said nothing about a crack but that is secondary evidence.

"Allegedly" came from their website.

2. The fact that it wasn't all client.exe that had the miner in them (Actually a small % of clients did) seems to me that it didn't come from their website, it was most likely a cracked version of the loader that had the miner. And that loader was most likely shared through out the discord.
So you've never heard of evasive malware? That is a factor of malware analysis. Malware might remain inactive for long periods of time before starting activity, it might be present in only a few instances of production, etc. These are all examples of evasive measures for malware.

I am aware of evasive malware. But even if it where evasive malware the dmr.exe file should still be there, which it wasn't for the majority of users. As i wrote on a small % of users have had this dmr.exe file on their system.

3. Why ACD allegedly have sent the information to their main server i do not know, but people in the cheating community aren't always the smartest. Note that ACD doesn't dev anything them self, they are reselling their software.
Yes I know ACD is a reseller so how are they somehow able to hack Cobalt's website and alter a VMP protected loader for download? If they are somehow smart enough to do that, they aren't going to be stupid enough to leave a trail to their main Discord server which is not secure, not anonymous, and might get deleted at any time.

That might be true, unless they didn't think about it.

4. The security of Cobalt i cannot speak about since i don't know about it. But again it isn't unheard of providers cracking other providers in the cheating community.
Already answered #1.

5. Again i don't think the client.exe was spread through their website, but most likely was a cracked version of their loader, that was spread through discord.
It came from their website. People aren't distributing cheat provider loaders on Discord unless it's advertised cracked, which Cobalt didn't get cracked. They get the shit from the website like everyone else.

I think you should investigate some more, since you have no information about this. Client have been shared a lot in the Cobalt discord server, anyone that have the slightest insight of this would know this is true.

6. I don't see any reason for Cobalt to spread a miner to their users, they are growing rapidly, also faster than any other providers atm. Why ruin a growing good business? That in my eyes doesn't make any sense at all.
Yeah their free and 10 eur products are really flying off the shelf because they're good and not because they are cheap. When something is free or cheap in the cheat scene, your device might be what they get, not your money.

Yes they are. That's is not true at all, just because they are cheap doesn't mean they are "after your device" it can be a good step to start up a business and get customers. And then after a while you either raise the price or keep it as it is and get more customers.

But for other providers this isn't good, the fast that both Cobalt and ACD have been seen as cheats you use for raging give them the same user base.
Cobalt is also 1/5 of the price of ACD cheat + spoofer.
I believe that ACD have more benefits for ruining Cobalt reputation/sales than Cobalt would have to rat their own customers.

Yeah ACD seems to be profit driven while Cobalt seems to be malware infection driven. Not sure why you're surprised by the price difference. Cobalt has given away a lot for "free" too. Nothing in life is free.

This statement is just not proven.

I do not support malware distributors. But i also wont join on the hype train to accuse a provider, that in the most logically way probably haven't done anything wrong other than having a weak protection against debugging and are being stupid enough to allow share a client.exe in their general channel on discord.
I hope that people can make their own choice on who they believe in the right and who isn't. But it was not my intention to accuse ACD, i indented for this information to be public to people can make their own choice.

The proof is legitimately overwhelming that Cobalt is a malware distributor. This is not a hype train.
The there is proof for both sides of the story.

Again as i said this thread was to spread information. People can think for them self and decide what they want to believe. Because as mentioned there is proof on both sides of the story.
lort1234 is offline  
Old 05/04/2022, 20:28   #8
Chasing







 
Satan's Avatar
 
elite*gold: 0
The Black Market: 199/0/0
Join Date: Mar 2013
Posts: 7,738
Received Thanks: 2,142
This one here should be enough to discuss:


#closed
Satan is offline  
Closed Thread


Similar Threads Similar Threads
(New) GaMe WoRLD Online.Is it a competitor?
06/27/2010 - CO2 PServer Archive - 2 Replies
:::::::::::::::::::::::::::::::::::::::::::::::::: ~¤¦¦§¦¦¤~ Welcome to GaMe WoRLD ~¤¦¦§¦¦¤~ ::::::::::::::::::::::::::::::::::::::::::::::::: : this is the full server which you search for let's start with features 1-server 24/7 on VPS On patch 5087 2-mobs drop 100 CPS per monster
Are you going to pay for the bot? botsmall competitor will be cheaper
09/26/2007 - Dekaron - 12 Replies
so i contacted botsmall's distro competitor on msn today and asked about the pricing they are going to offer. I was told they are not releasing it retail yet until they verify that the majority of the bugs are fixed. as far as pricing I was told "we will price this as we on our botcard" so from the price of thier botscards on various games, it will be 6-8$ for 2 weeks. when i asked them if this is correct they said yes. on the downside, botsmall is retail (unfixed product) in 2 days....



All times are GMT +1. The time now is 17:05.


Powered by vBulletin®
Copyright ©2000 - 2026, Jelsoft Enterprises Ltd.
SEO by vBSEO ©2011, Crawlability, Inc.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Support | Contact Us | FAQ | Advertising | Privacy Policy | Terms of Service | Abuse
Copyright ©2026 elitepvpers All Rights Reserved.