Bitcoin Forum
June 24, 2026, 11:45:22 PM *
News: Latest Bitcoin Core release: 31.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Samfw.com Scam - Fraud & Trojan RAT Malware : SamFWTool Theft (XMR)  (Read 42 times)
craftyart1010 (OP)
Newbie
*
Offline

Activity: 4
Merit: 0


View Profile
Today at 02:03:35 PM
Last edit: Today at 03:58:43 PM by craftyart1010
 #1

Scammer name: Đặng Thanh Tùng (also shown as Tungtata / Đặng Thanh Tùng) Based in Hanoi Capital of Vietnam

https://talkimg.com/images/2026/06/24/U1KWz5.jpg

https://talkimg.com/images/2026/06/24/U1KBmC.png

Role stated: founder / main developer of “SamFW” and MiFirm.net (from About page at Samfw.com)
Education stated: Quang Ninh Industrial College (from About page at Samfw.com)
Named partner/founder: Thang; partner and founder of LeHuy Technology Company (from About page at Samfw.com)

Company / registered entity: SamFW Global LLC

Location listed publicly: Boulder, Colorado, United States

Developer country listed publicly for Đặng Thanh Tùng: Vietnam
Additional public connections: listings linking the service to Quynh Chi Investment and Technology Co. Ltd. (Hanoi, Vietnam); and repeating Boulder, Colorado for SamFW Global LLC.


A family member installed “SamFW Tool” from samfw.com on Jun 23, 2026. Shortly after installation, 10,000 XMR (about $3 million) were withdrawn from the Feather Wallet, and everything in victim’s computer data was deleted.

https://talkimg.com/images/2026/06/24/U1KIsD.png

After installing samfwtoolsetup_v5.4.zip, the suspected operators stole the funds from the Feather Wallet. After the theft, they removed and modified the original tool package to reduce evidence. The download is now replaced with a revised version labeled SamFwToolSetup_v5.5.1.zip.

After the scam, the photo of the incident was taken on a phone. Later, the scammer updated their website and removed that specific version of the tool.

Source: https://samfw.com/blog/samfw-frp-tool-1-0-remove-samsung-frp-one-click

We want to report a serious suspected theft and cybercrime to Vietnamese police (cyber unit). We believe the tool contains sophisticated malicious functionality, potentially including hidden remote access or wallet monitoring. We’re seeking help from the community to gather and document evidence, including additional information about the responsible parties. If you are in Vietnam and can assist, you will be rewarded for your help. Please share any relevant findings here. For urgent information, you can contact us via email: 96238132834@proton.me

We already reported this case to several Vietnamese crypto exchanges, but we still need further assistance. Any additional help would be greatly appreciated and will be rewarded.

After the scam, we contacted the Đặng Thanh Tùng, who responded that if we believed it was a scam, we should report it to the police and send laughing face emoji. Shortly afterward, he blocked us on Telegram.


Evidence links have collected:
https://t.me/samfwcom
https://www.buymeacoffee.com/tungtata
https://about.me/tungtata
https://t.me/tungtata
https://facebook.com/tungtata
https://github.com/tungtata
https://www.paypal.com/paypalme/DangThanhTung
Paypal: tungvn48@gmail.com
Skrill: tungvn48@gmail.com
https://www.tungtata.net/
Dang Thanh Tung
@DangThanhTung
Dong Da, HÀ NỘI
QUYNH CHI INVESTMENT AND TECHNOLOGY CO.,LTD - No. 26, Alley 89, Quan Nhan Street, Thanh Xuan Ward, Hanoi City, Vietnam
Tax Identification Number: 0110492308
https://xdaforums.com/m/tungtata.8243977/about
fb.com/ThanhTungOfficial
Whatsapp: +84.1296.935.935 and +84.967.888.448
Birth Year: 1992

We need assistance making contact with Vietnam police officers and the cybercrime unit. Any help or introductions will be appreciated and will be rewarded.

Published at:
https://github.com/9623813/tungtata_scammer


Keywords:
Tungtata scam, Tungtata fraud, Dang Thanh Tung scam, samfw scam, samfw malware, samfw trojan, samfw security risk, samfw suspicious software, Tungtata trojan virus, samfw warning, Đặng Thanh Tùng scammer, owner Đặng Thanh Tùng fraud, tungtata scam, DangThanhTung scammer, DangThanhTung fraud, DangThanhTung rat trojan
craftyart1010 (OP)
Newbie
*
Offline

Activity: 4
Merit: 0


View Profile
Today at 07:54:54 PM
 #2

We’re looking for a Vietnamese translator to translate this scam thread.

In addition reward, the translator should help us to contact the appropriate Vietnamese authorities to report this scam.

The suspect is Đặng Thanh Tùng (also shown as Tungtata / Đặng Thanh Tùng), based in Hanoi. He uses RAT (malicious remote access tool) by injecting his own tool to defraud victims. What he does is that he doesn’t always deploy ratted trojan tools. Instead, he shares them only in certain updates, and then removes them afterward scam. In our case, after he stole our money, he returned to the site to post an updated version of the tool and removed the virus one.

We plan to report this scam case to the relevant authorities, and we’d like additional suggestions from other users on Bitcointalk. We also need help from users in Vietnam to assist with outreach and coordination related to this scam.

Cong An (Vietnam Police) - Trình báo lừa đảo trực tuyến tới Công an.
Interpol
VNCERT/CC - Trung tâm ứng cứu khẩn cấp máy tính Việt Nam.
econsumer.gov
albon
Legendary
*
Offline

Activity: 2464
Merit: 2369



View Profile
Today at 11:28:16 PM
 #3

What he does is that he doesn’t always deploy ratted trojan tools. Instead, he shares them only in certain updates, and then removes them afterward scam. In our case, after he stole our money, he returned to the site to post an updated version of the tool and removed the virus one.
I agree with that. In fact, if you try to open the following link now -> SamFwToolSetup_v5.4.zip, you will find that he has already removed version v5.4 from his website.

It is no longer available, and it is not even present on his Telegram channel, which has over 19K subscribers.



However, even with the SamFwToolSetup_v5.5.1.zip version, if you check VirusTotal, you will find that it is flagged as malicious by 2/57 security vendors. Among the threat categories, it is classified as a Trojan, and its popular threat label is trojan.packunwan. It is also associated with the tags detect-debug-environment, long-sleeps, and contains-pe.



I hope you can provide the TXID for the transaction in which 10,000 XMR was allegedly stolen, so that we can also verify the validity of your claim and see where those funds were sent. This is an extremely large amount of money. Before installing any software, it is important to verify that it is free of malware. Also, software like this should never be installed on a primary computer that contains wallets holding such significant amounts of funds.

█████████████████████████
███████▀▀███████▀▀███████
█████▀░░▄███████▄░░▀█████
███▀░░██████▀░▀████░░▀███
██▀░░▀▀▀████████████░░▀██
██░░█▄████▀▀███▀█████░░██
██░░███▄▄███████▀▀███░░██
██░░████████████████░░██
██▄░░████▄▄██████▄▄█░░▄██
███▄░░██████░░████░░▄███
█████▄░░▀███░░▐▀░░▄█████
███████▄▄███████▄▄███████
█████████████████████████
.
 ROOBET .██████. BET ON WORLD CUP  🗺 ⚽︎.██████.
|

█▄█
▀█▀
████▄▄██████▄▄████
█▄███▀█░░█████░░█▀███▄█
▀█▄▄░▐█████████▌▄▄█▀
██▄▄█████████▄▄████▌
██████▄▄████████
█▀▀████████████████
██████
█████████████
██
█▀▀██████████████
▀▀▀███████████▀▀▀▀
|.
   BET NOW   
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!