http://deepweb4wt3m4dhutpxpe7d7wxdftfdf4hhag4sizgon6th5lcefloid.onion/blog/newest/looney-tunables-are-being-used-by-kinsing-hackers-to-steal-credentials
In the most recent attacks, hackers used a Proof of Concept (PoC) exploit in Python that was made public on October 5th by a researcher going by the name bl4sty. After this, the Kinsing hackers set off another PHP exploit, which, after being decoded, turned out to be JavaScript meant to be used for more attacks. Attackers could manage files, run commands, and gather information about the device using this JavaScript code as a web shell.