All Topics
All Topics
Technology
Technology
Design
Design
Programming
Programming
Science
Science
News
News
Gaming
Gaming
Entertainment
Entertainment
Business
Business
Finance
Finance
Sports
Sports
Health
Health
Food
Food
Travel
Travel
Art
Art
Music
Music
Books
Books
Education
Education
Politics
Politics
Personal
Personal
No algorithm. No AI slop. No ads. Just RSS. Pro-human. Indie writers. Real journalism. Open web. Chronological. Hand toasted.

How a botnet abused my open source project's cloud version to phish 14,000 people

By

Andrej Acevski

2d ago· 5 min readenInsight

Summary

The author, who runs an open source project management tool called Kaneo, discovered that a botnet had abused the hosted cloud version of their software to send phishing emails to 14,000 people. After receiving a quota exhaustion notice from Resend (their email provider), they investigated and found fake workspaces created by scammers using the tool's email functionality for phishing campaigns. The article details the investigation, cleanup process, and lessons learned about the responsibilities of running cloud services for unknown users.

Key quotes

· 4 pulled
My sending quota for cloud.kaneo.app was exhausted. I had not sent anything in days.
Last weekend someone else found it.
What I found, what I cleaned up, and what it taught me about running cloud on behalf of people I've never met.
The new workspaces looked like this: 🔒Paul Brown from BANKING OPERATION
Snippet from the RSS feed
A botnet abused the hosted version of my open source project to phish 14,000 strangers. What I found, what I cleaned up, and what it taught me about running cloud on behalf of people I’ve never met.

You might also wanna read