u/imataxfrauder

Opium (Mac exploit) Is a rat.
▲ 5 r/ROBLOXExploiting+1 crossposts

Opium (Mac exploit) Is a rat.

https://preview.redd.it/sz6qren6ru5h1.png?width=1148&format=png&auto=webp&s=d0fba2c9c42bd8cbeecc522d8c5976b126802389

Hello, I, mzzreal/taxfrauder have found that opiumware is a rat, lets get to the point.

1: The launcher links to a website (https://2ihmdb56pm.ufs.sh/f/WTDaMpjqfHMYpWCxBgeBd0ELlvU1TejXtDaQb4wxsPmRIru2, already down.) which is known for providing malware, this also bypasses the windows "A unknown app tried to install something onto your device"

2: Opiumware quickly shut down the 3 websites on the oh so not obfuscated launcher that downloads, the three websites are:
DYLIB_URL="https://2ihmdb56pm.ufs.sh/f/WTDaMpjqfHMYj8Qcj4CmOQUAKVtnZY69l2rkxRo8zi5HShqj" MODULES_URL="https://2ihmdb56pm.ufs.sh/f/WTDaMpjqfHMYajjw6y98FHm9SWoBKltDhNf21rbckGsg5p6i" UI_URL="https://2ihmdb56pm.ufs.sh/f/WTDaMpjqfHMYpWCxBgeBd0ELlvU1TejXtDaQb4wxsPmRIru2" <= This is the one mentioned previously, these all were taken down.

3: I ran Opiumware in a VM and it had anti-vm and anti-av in it, I used a program to check what it sends and receive and I have confirmed it was a rat, thanks to a anonymous person for tipping me about it.

4: Opiumware's owners/dev team planted a mole in MEN (mac exploiting network) and they (refer to 2) took them down as soon as a anonymous member posted the information.

And that's my point. Opiumware is a rat, you shouldnt use it, just use kraaksploit or macsploit.

Also, Opiumware has been making botted posts and bot accounts to advertise themselves, this further proves my point.

Also, I'm looking for people to help in the process of figuring out the rat and the logs. I will be giving them a FULLY open source progam to help.
Added evidence, DM me for more pictures/proof.

The launcher's link is: https://raw.githubusercontent.com/norbyv1/OpiumwareInstall/refs/heads/main/inst , and you can inspect the source code there.

suspicious bash curl to install something from a malware provider, leads to a file called arminst that has a archive password, commonly used to breach AVs

https://preview.redd.it/avtryr5o6u5h1.png?width=1241&format=png&auto=webp&s=72af3f621eb71aff109cf21ab02000455c4b91f9

https://preview.redd.it/k8es97pf5u5h1.png?width=503&format=png&auto=webp&s=bdf32f39bedddb5dfb1f42e7c49c2386a8c511d5

anonymous tipper

https://preview.redd.it/isqcx1n7ru5h1.png?width=1148&format=png&auto=webp&s=703a9d8775e222ef5823e5ad19c2846476267d73

https://preview.redd.it/i0zwz5mcru5h1.png?width=1075&format=png&auto=webp&s=54abd8a92fcac8ff37aef7fe6b04c2d4adc6c9ef

reddit.com
u/imataxfrauder — 4 days ago