Bitcoin Forum
July 24, 2026, 05:09:41 PM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 [2]  All
  Print  
Author Topic: Samfw.com Scam - Fraud & Trojan RAT Malware : SamFWTool Theft (XMR)  (Read 586 times)
craftyart1010 (OP)
Jr. Member
*
Offline

Activity: 34
Merit: 1


View Profile
June 30, 2026, 01:16:56 PM
 #21

OP: Why would you install a tool marked with many malware threats?

Popular threat label
trojan.abapplication/ewep
Threat categories
trojan
pua

Family labels
abapplication
ewep
frpbypass



If multiple independent AV engines label the same file/process as Trojan/Malware and not just “riskware,” it’s usually not safe to run even if some people call it a false positive. AV naming like “PossibleThreat,” “PUA,” or “Riskware” can include borderline/uncertain detections, but your list is also full of “Agent” and “Trojan” labels, which tend to be higher-signal than “PUA” alone.

Don’t run it!

I know it was my mistake I trusted this sofware,  I found on YouTube, Reddit, and other forum sites that claimed it was clean and had no viruses. But that wasn’t true. It turned out there was a very well-hidden malware inside it.

I believe this person was involved in malicious updates possibly inserting malware and then removing or altering it so it wouldn’t get detected. He’s a pure criminal, and I hope he’ll face the consequences soon.

I’m posting this to warn everyone: don’t blindly trust what you read online. It’s possible many of the comments are fake, created by him to make the tool look safe and harmless.

After installing this ‘samfwscam tool’, everything on my computer was wiped, including my wallet data. It was the biggest mistake of my life.


Keywords
SamFw FRP Tool scam, SamFw FRP Tool malware, SamFwToolSetup_v5.4.zip scam, SamFwToolSetup_v5.4.zip malware, SamFwToolSetup_v5.5.1.zip scam, SamFwToolSetup_v5.5.1.zip malware, Remove FRP one click scam, Remove FRP one click malware, Change CSC one click scam, Change CSC one click malware, FRP bypass scam, FRP bypass malware, scam, crypto wallet drained malware, private keys stolen scam, samfw.com scam, Vietnamese scam, Tungtata scam, Tungtata malware


albon
Legendary
*
Offline

Activity: 2506
Merit: 2413



View Profile
June 30, 2026, 01:35:02 PM
 #22

OP: Why would you install a tool marked with many malware threats?

If multiple independent AV engines label the same file/process as Trojan/Malware and not just “riskware,” it’s usually not safe to run even if some people call it a false positive. AV naming like “PossibleThreat,” “PUA,” or “Riskware” can include borderline/uncertain detections, but your list is also full of “Agent” and “Trojan” labels, which tend to be higher-signal than “PUA” alone.

Don’t run it!
I think the OP wasn't careful, he may not have bothered checking the software before installing it on his computer or he may have relied on the software reviews too much.

Even if he decided to run it, he should have done so in a VM or a sandbox.

Based on what's been posted, although the technical evidence here points to the developer, the @OP still doesn't want to cooperate or show proof that he actually lost money. In my opinion, that makes it difficult for many people to believe his story.

Anyone can write a convincing story, but sharing solid evidence makes it much easier for any member here to verify the claim.

█████████████████████████
███████▀▀███████▀▀███████
█████▀░░▄███████▄░░▀█████
███▀░░██████▀░▀████░░▀███
██▀░░▀▀▀████████████░░▀██
██░░█▄████▀▀███▀█████░░██
██░░███▄▄███████▀▀███░░██
██░░████████████████░░██
██▄░░████▄▄██████▄▄█░░▄██
███▄░░██████░░████░░▄███
█████▄░░▀███░░▐▀░░▄█████
███████▄▄███████▄▄███████
█████████████████████████
.
 ROOBET .██████. BET ON WORLD CUP  🗺 ⚽︎.██████.
|

█▄█
▀█▀
████▄▄██████▄▄████
█▄███▀█░░█████░░█▀███▄█
▀█▄▄░▐█████████▌▄▄█▀
██▄▄█████████▄▄████▌
██████▄▄████████
█▀▀████████████████
██████
█████████████
██
█▀▀██████████████
▀▀▀███████████▀▀▀▀
|.
   BET NOW   
craftyart1010 (OP)
Jr. Member
*
Offline

Activity: 34
Merit: 1


View Profile
June 30, 2026, 01:45:45 PM
 #23

OP: Why would you install a tool marked with many malware threats?

If multiple independent AV engines label the same file/process as Trojan/Malware and not just “riskware,” it’s usually not safe to run even if some people call it a false positive. AV naming like “PossibleThreat,” “PUA,” or “Riskware” can include borderline/uncertain detections, but your list is also full of “Agent” and “Trojan” labels, which tend to be higher-signal than “PUA” alone.

Don’t run it!
I think the OP wasn't careful, he may not have bothered checking the software before installing it on his computer or he may have relied on the software reviews too much.

Even if he decided to run it, he should have done so in a VM or a sandbox.

Based on what's been posted, although the technical evidence here points to the developer, the @OP still doesn't want to cooperate or show proof that he actually lost money. In my opinion, that makes it difficult for many people to believe his story.

Anyone can write a convincing story, but sharing solid evidence makes it much easier for any member here to verify the claim.

This tool doesn’t work on a VM or sandbox. It only works on the main computer, and many people said the same thing on other forums.

Also, I’m not here to lie or create fake reviews. I told you I lost $3M not $1M, not $3.98M. Why would I lie here? If I were a liar, what would I gain by trying to warn everyone? I’m genuinely dealing with an Vietnamese scammer who ruined my life and doesn’t even reply to my messages.

This case has already been reported to the Vietnamese police, they are investigating it whether you believe me or not, I’m sorry, but I’m sharing everything I have.

If it’s all fake, then why am I wasting my time publishing this everywhere to expose the Samfw scam?

I’ll keep going, and I won’t stop. I won’t let this scammer continue scamming people!

Published at:
https://github.com/9623813/tungtata_scammer
https://96238132834.wixsite.com/samfwscam
https://www.tumblr.com/samfwtoolscam
https://github.com/tungtata/SamFw-Tool-Update/issues/1
https://github.com/chenxiaolong/BasicSync/issues/178
https://www.trustpilot.com/reviews/6a3e2e1f7bded8c96b894260
http://tungtatascam.com/do-not-download-or-use-any-tools-from-samfw-com/
https://www.samfwscam.com/2026/06/27/d%E1%BA%B7ng-thanh-tung-tungtata-is-a-confirmed-scammer-and-malware-distributor/
https://github.com/tungtatascam
https://www.tumblr.com/tungtatascam
https://hackmd.io/@SamfwScam
https://archive.org/details/scammer_tungtata_pic2
https://archive.org/details/@samfwscam
https://github.com/samfwtoolscam
https://github.com/samfwfrpscam

My computer was mostly empty and didn’t have many things. I only put important files images and documents etc. But the scammer wiped everything, even shredding whole files. How can I post more details?
albon
Legendary
*
Offline

Activity: 2506
Merit: 2413



View Profile
June 30, 2026, 02:09:50 PM
 #24

Also, I’m not here to lie or create fake reviews. I told you I lost $3M not $1M, not $3.98M. Why would I lie here? If I were a liar, what would I gain by trying to warn everyone? I’m genuinely dealing with an Vietnamese scammer who ruined my life and doesn’t even reply to my messages.

This case has already been reported to the Vietnamese police, they are investigating it whether you believe me or not, I’m sorry, but I’m sharing everything I have.

If it’s all fake, then why am I wasting my time publishing this everywhere to expose the Samfw scam?
I didn’t say that you are lying. I only asked for your wallet address and the transactions that were made from your wallet so we can verify that these funds were stolen. That way we can verify everything on a block explorer. Everything can be verified on-chain. We are not relying on statements or intentions here, but on evidence that can actually be verified.

There’s nothing unusual about this request. Even if you reported this to the Vietnamese police, they would likely ask you for proof of ownership of these funds, as well as evidence of the theft and the transaction history in your wallet. If you are confident in what you are saying, then why not simply provide this basic information?

My computer was mostly empty and didn’t have many things. I only put important files images and documents etc. But the scammer wiped everything, even shredding whole files. How can I post more details?
Did you not store this information on a hardware device or a USB drive? And you didn’t keep your wallet address or seed phrase in any other secure place either?

█████████████████████████
███████▀▀███████▀▀███████
█████▀░░▄███████▄░░▀█████
███▀░░██████▀░▀████░░▀███
██▀░░▀▀▀████████████░░▀██
██░░█▄████▀▀███▀█████░░██
██░░███▄▄███████▀▀███░░██
██░░████████████████░░██
██▄░░████▄▄██████▄▄█░░▄██
███▄░░██████░░████░░▄███
█████▄░░▀███░░▐▀░░▄█████
███████▄▄███████▄▄███████
█████████████████████████
.
 ROOBET .██████. BET ON WORLD CUP  🗺 ⚽︎.██████.
|

█▄█
▀█▀
████▄▄██████▄▄████
█▄███▀█░░█████░░█▀███▄█
▀█▄▄░▐█████████▌▄▄█▀
██▄▄█████████▄▄████▌
██████▄▄████████
█▀▀████████████████
██████
█████████████
██
█▀▀██████████████
▀▀▀███████████▀▀▀▀
|.
   BET NOW   
craftyart1010 (OP)
Jr. Member
*
Offline

Activity: 34
Merit: 1


View Profile
June 30, 2026, 02:58:45 PM
 #25

Also, I’m not here to lie or create fake reviews. I told you I lost $3M not $1M, not $3.98M. Why would I lie here? If I were a liar, what would I gain by trying to warn everyone? I’m genuinely dealing with an Vietnamese scammer who ruined my life and doesn’t even reply to my messages.

This case has already been reported to the Vietnamese police, they are investigating it whether you believe me or not, I’m sorry, but I’m sharing everything I have.

If it’s all fake, then why am I wasting my time publishing this everywhere to expose the Samfw scam?
I didn’t say that you are lying. I only asked for your wallet address and the transactions that were made from your wallet so we can verify that these funds were stolen. That way we can verify everything on a block explorer. Everything can be verified on-chain. We are not relying on statements or intentions here, but on evidence that can actually be verified.

There’s nothing unusual about this request. Even if you reported this to the Vietnamese police, they would likely ask you for proof of ownership of these funds, as well as evidence of the theft and the transaction history in your wallet. If you are confident in what you are saying, then why not simply provide this basic information?

My computer was mostly empty and didn’t have many things. I only put important files images and documents etc. But the scammer wiped everything, even shredding whole files. How can I post more details?
Did you not store this information on a hardware device or a USB drive? And you didn’t keep your wallet address or seed phrase in any other secure place either?

I understand you. As I said, I didn’t store my information anywhere else. I thought my computer was the most secure place, and nothing happened for years. If I had, of course I would have shared it I wouldn’t keep it hidden. My only place to store my information was on my computer, and once everything was wiped, I lost it. For years, my wallet was stored on my computer with no issues. After I installed his tool, few hours later everything I had has been lost. That’s all. I’ve already provided everything I have.
albon
Legendary
*
Offline

Activity: 2506
Merit: 2413



View Profile
June 30, 2026, 04:22:50 PM
 #26

I understand you. As I said, I didn’t store my information anywhere else. I thought my computer was the most secure place, and nothing happened for years. If I had, of course I would have shared it I wouldn’t keep it hidden. My only place to store my information was on my computer, and once everything was wiped, I lost it. For years, my wallet was stored on my computer with no issues. After I installed his tool, few hours later everything I had has been lost. That’s all. I’ve already provided everything I have.
WOW, how is that even possible to store $3 million in a hot wallet on a computer connected to the internet, instead of using offline storage, without having a backup of the recovery phrase and writing down your wallet address somewhere? You also kept all your private info on your main computer with nothing saved elsewhere and didn’t consider the risk that your device could be got compromised within minutes.

In any case, the software behavior looks suspicious from the analysis and this is the main issue. However, the claim of losing $3 million cannot be confirmed without evidence such as wallet transactions, wallet address, proof on the blockchain. As long as you do not provide what I mentioned, your claim regarding this amount cannot be verified.

█████████████████████████
███████▀▀███████▀▀███████
█████▀░░▄███████▄░░▀█████
███▀░░██████▀░▀████░░▀███
██▀░░▀▀▀████████████░░▀██
██░░█▄████▀▀███▀█████░░██
██░░███▄▄███████▀▀███░░██
██░░████████████████░░██
██▄░░████▄▄██████▄▄█░░▄██
███▄░░██████░░████░░▄███
█████▄░░▀███░░▐▀░░▄█████
███████▄▄███████▄▄███████
█████████████████████████
.
 ROOBET .██████. BET ON WORLD CUP  🗺 ⚽︎.██████.
|

█▄█
▀█▀
████▄▄██████▄▄████
█▄███▀█░░█████░░█▀███▄█
▀█▄▄░▐█████████▌▄▄█▀
██▄▄█████████▄▄████▌
██████▄▄████████
█▀▀████████████████
██████
█████████████
██
█▀▀██████████████
▀▀▀███████████▀▀▀▀
|.
   BET NOW   
craftyart1010 (OP)
Jr. Member
*
Offline

Activity: 34
Merit: 1


View Profile
June 30, 2026, 05:30:12 PM
 #27

I understand you. As I said, I didn’t store my information anywhere else. I thought my computer was the most secure place, and nothing happened for years. If I had, of course I would have shared it I wouldn’t keep it hidden. My only place to store my information was on my computer, and once everything was wiped, I lost it. For years, my wallet was stored on my computer with no issues. After I installed his tool, few hours later everything I had has been lost. That’s all. I’ve already provided everything I have.
WOW, how is that even possible to store $3 million in a hot wallet on a computer connected to the internet, instead of using offline storage, without having a backup of the recovery phrase and writing down your wallet address somewhere? You also kept all your private info on your main computer with nothing saved elsewhere and didn’t consider the risk that your device could be got compromised within minutes.

In any case, the software behavior looks suspicious from the analysis and this is the main issue. However, the claim of losing $3 million cannot be confirmed without evidence such as wallet transactions, wallet address, proof on the blockchain. As long as you do not provide what I mentioned, your claim regarding this amount cannot be verified.

It was like that for years without an issue. I never had a single problem until I installed SAMFWtool and then I got scammed then in few hours SamFwToolSetup_v5.4.zip software deleted from his site and updated with new version that’s all.

We’ll see what police will handle

I don’t want to talk publicly anymore because this guy is watching and doesn’t even care to reply. We’ll see.

im here to expose him and make a public warning. this was me today, but tomorrow it could be you. what he did was a scam. his scam network is very sophisticated, and anyone can be a victim.
Mfadi74
Newbie
*
Offline

Activity: 3
Merit: 0


View Profile
July 01, 2026, 04:21:17 PM
 #28

OP: Why would you install a tool marked with many malware threats?

If multiple independent AV engines label the same file/process as Trojan/Malware and not just “riskware,” it’s usually not safe to run even if some people call it a false positive. AV naming like “PossibleThreat,” “PUA,” or “Riskware” can include borderline/uncertain detections, but your list is also full of “Agent” and “Trojan” labels, which tend to be higher-signal than “PUA” alone.

Don’t run it!
I think the OP wasn't careful, he may not have bothered checking the software before installing it on his computer or he may have relied on the software reviews too much.

Even if he decided to run it, he should have done so in a VM or a sandbox.

Based on what's been posted, although the technical evidence here points to the developer, the @OP still doesn't want to cooperate or show proof that he actually lost money. In my opinion, that makes it difficult for many people to believe his story.

Anyone can write a convincing story, but sharing solid evidence makes it much easier for any member here to verify the claim.

Even if you pay me, I would never install this tool on my computer.

You may check reports on any.run.

Verdict: Malicious activity

https://app.any.run/tasks/de281be5-5011-48b3-b397-e52708dd162f

https://any.run/report/ce373c65752e7bbc267c670dca97a5be8403e226363ebfdce26201a58423b5f4/de281be5-5011-48b3-b397-e52708dd162f
craftyart1010 (OP)
Jr. Member
*
Offline

Activity: 34
Merit: 1


View Profile
July 03, 2026, 07:38:28 PM
 #29




There are also other people who reported samfw.com as a scam to https://reportfraud.ftc.gov, and I believe there are more reports than this.



Online info and videos about “SamFw FRP Tool” are often inaccurate. Yes, the tool may work, but there can be hidden or unusual network traffics. Operators tungtata target victims selectively: if you have nothing sensitive on the computer or on your phone, they may not behave obviously. However, if your device contains private data especially crypto wallet seed phrases, passwords, or other credentials they able to connect to the computer and/or execute malware to steal information. Also, running the tool may require disabling antivirus protection, which can make this kind of attack easier for an operator.

Do not trust this SamFw FRP tool or run it.

I’m a victim, and I’m fighting alone against them. I’ve already reported this case to the authorities, and I’m doing my best to warn everyone.

This scammer TungTata, is doing his best to hide his ass, but he’ll get busted.

I lost $3 million because of a seemingly simple but extremely dangerous file called SamFwToolSetup_v5.4.zip. What happened is that my wallet drained the same day, and they later updated the software to SamFwToolSetup_v5.5.1.zip.

Vietnamese scammer, “TungTata”

Don’t install “SamFw FRP Tool.” It’s a scam, be careful!

If you have already used the software, taking steps to secure your PC and smartphone is highly recommended!
craftyart1010 (OP)
Jr. Member
*
Offline

Activity: 34
Merit: 1


View Profile
July 05, 2026, 06:01:53 PM
 #30

Also do not believe Trustpilot reviews. Scammer tungtata buys them to fake it. During my daily checks everyday 20-50 positive reviews keep adding. He also keeps buying blog reviews and posting reviews to show his tool working without issue and there is no malware inside. This is a SEO work done by them to lie to the community.

Do not download, install, or run any software from samfw.com!

https://www.filescan.io/uploads/6a4947bf047ec54f9809c4fd/reports/9d437319-5042-43f2-b44b-da7cf7ee4584/ioc?iocId=93693de1-8923-4bd8-a10d-9e03b59c5184
SamFwToolSetup - Confirmed Threat

https://hybrid-analysis.com/sample/e640a65efcae264ad6f758bb3b9da0d37ed8c690bda6f113416558d4bcbbcf3a
Quote
Spyware
Found a string that may be used as part of an injection method
Persistence
Creates new processes
Spawns a lot of processes
Writes data to a remote process
Evasive
Contains ability to adjust token privileges
Contains ability to terminate a process
Marks file for deletion

If you want to still use, only get a “burner” laptop with nothing important on it.



craftyart1010 (OP)
Jr. Member
*
Offline

Activity: 34
Merit: 1


View Profile
July 06, 2026, 03:12:29 PM
 #31

https://forums.malwarebytes.com/topic/337471-undected-malware/

Malwarebytes Senior Research Engineer ran a test on the file and found a malicious payload.

“Trojan.dropper” in SamFw Tool means it’s typically installs or delivers additional malicious software to your system after it runs.

This malware designed to install other malicious software, such as spyware, ransomware, or backdoors, onto your computer.

It is likely a stealer (Infostealer) onto your machine. This type of malware is designed to scrape your browser data, cookies, saved passwords, and private keys/seed phrases to empty your wallets.

Quote
Trojan.Dropper, C:\1\1\1\SAMFWTOOLSETUP.EXE, No Action By User, 90, 1416795, 1.0.111810, , ame, , A8BB817630386982FEB98106FED8EA89, E640A65EFCAE264AD6F758BB3B9DA0D37ED8C690BDA6F113416558D4BCBBCF3A

What exactly happened to us is that all my files and private crypto wallet seeds were stolen after I installed SamFwToolSetup_v5.4.zip. Then few hours later, my funds were drained.

I’m doing my best to provide all the details to the community so no one gets scammed by this scam tool created by Đặng Thanh Tùng (also shown as Tungtata / Đặng Thanh Tùng). I will continue to share my findings, and he will stay online and be watched. I will expose his scam network, which has been operating for years to earn trust. Now he has decided to scam people secretly, but if we keep the community tight, I believe everyone can see the truth.


Keywords:
samfw trojan.dropper malware, samfw trojan.dropper, samfwtool trojan.dropper, samfw tooldropper, samfw trojan dropper malware, samfwtoolsetupp.exe trojan.dropper, SAMFWTOOLSETUP.EXE trojan.dropper, samfwtoolsetup trojan.dropper, samfwsetup trojan.dropper, samfw tool trojan.dropper, samfw trojan.dropper infostealer
albon
Legendary
*
Offline

Activity: 2506
Merit: 2413



View Profile
July 06, 2026, 04:29:52 PM
 #32

I’m a victim, and I’m fighting alone against them. I’ve already reported this case to the authorities, and I’m doing my best to warn everyone.
I see you already reported this to the FTC, but did you also report it to the FBI? via IC3, Vietnam’s public security ministry, Interpol, or your country’s embassy there?

You should probably escalate this through these channels, but you need to write a full report with all the details of what happened, with as much evidence as you can.

Also do not believe Trustpilot reviews. Scammer tungtata buys them to fake it.
You can’t really rely on reviews as a main source, because they can be purchased.

Also, there are also services that sell fake reviews, which breaks Trustpilot rules. But, you should have proof if you’re saying that he is actually buying these illegal services.

█████████████████████████
███████▀▀███████▀▀███████
█████▀░░▄███████▄░░▀█████
███▀░░██████▀░▀████░░▀███
██▀░░▀▀▀████████████░░▀██
██░░█▄████▀▀███▀█████░░██
██░░███▄▄███████▀▀███░░██
██░░████████████████░░██
██▄░░████▄▄██████▄▄█░░▄██
███▄░░██████░░████░░▄███
█████▄░░▀███░░▐▀░░▄█████
███████▄▄███████▄▄███████
█████████████████████████
.
 ROOBET .██████. BET ON WORLD CUP  🗺 ⚽︎.██████.
|

█▄█
▀█▀
████▄▄██████▄▄████
█▄███▀█░░█████░░█▀███▄█
▀█▄▄░▐█████████▌▄▄█▀
██▄▄█████████▄▄████▌
██████▄▄████████
█▀▀████████████████
██████
█████████████
██
█▀▀██████████████
▀▀▀███████████▀▀▀▀
|.
   BET NOW   
craftyart1010 (OP)
Jr. Member
*
Offline

Activity: 34
Merit: 1


View Profile
July 08, 2026, 02:50:08 PM
 #33

I’m a victim, and I’m fighting alone against them. I’ve already reported this case to the authorities, and I’m doing my best to warn everyone.
I see you already reported this to the FTC, but did you also report it to the FBI? via IC3, Vietnam’s public security ministry, Interpol, or your country’s embassy there?

You should probably escalate this through these channels, but you need to write a full report with all the details of what happened, with as much evidence as you can.

Also do not believe Trustpilot reviews. Scammer tungtata buys them to fake it.
You can’t really rely on reviews as a main source, because they can be purchased.

Also, there are also services that sell fake reviews, which breaks Trustpilot rules. But, you should have proof if you’re saying that he is actually buying these illegal services.

Hi,

This SamFw scam has been reported to many authorities, including the FBI and IC3. The scammer, “tungtata,” uses a Trojan.dropper to install a RAT and other malicious software on computers. Note that they often target victims selectively. They don’t target people who have nothing on their computers such as no crypto data, no wallet seed phrases etc. If you have nothing important, you might say the tool is working and see no issue. But this guy is little smart! Get it?

Even after my personal request Malwarebytes team has reported that “SamFwToolSetup” (samfw) contains Trojan.dropper. That means it run and then install additional malware. It’s often associated with infostealers that can steal browser data, cookies, saved passwords, and even cryptocurrency wallet seed phrases etc.

Again, do not download, install, or run anything from samfw.com. Unfortunately, many people still aren’t aware of these warnings and install the tool on their main computers.

Most online comments are fake and claiming it is a false positive is misleading. I ignored this virustotal red flags, installed it, and my wallet was drained in few hours.

SamFw is a scam tool created by Đặng Thanh Tùng (also shown as Tungtata)

Keywords:
samfw trojan.dropper malware, samfw trojan.dropper, samfwtool trojan.dropper, samfw tooldropper, samfw trojan dropper malware, samfwtoolsetupp.exe trojan.dropper, SAMFWTOOLSETUP.EXE trojan.dropper, samfwtoolsetup trojan.dropper, samfwsetup trojan.dropper, samfw tool trojan.dropper, samfw trojan.dropper infostealer

albon
Legendary
*
Offline

Activity: 2506
Merit: 2413



View Profile
July 09, 2026, 03:01:37 PM
 #34

This SamFw scam has been reported to many authorities, including the FBI and IC3.
Well done. I hope these authorities look into your report, check it, and take action against this person if, based on the evidence provided, they determine that he was involved in this scam.

Strangely, after his last post about it, went silent and hasn't replied to anything else that people asked here, including the issues he needed to clarify.

They don’t target people who have nothing on their computers such as no crypto data, no wallet seed phrases etc. If you have nothing important, you might say the tool is working and see no issue. But this guy is little smart! Get it?
Of course, the primary targets are people who have important data, personal information, or crypto wallets with a lot of money in them. I mean, what's the point of hacking a computer that have anything valuable?

Even after my personal request Malwarebytes team has reported that “SamFwToolSetup” (samfw) contains Trojan.dropper. That means it run and then install additional malware. It’s often associated with infostealers that can steal browser data, cookies, saved passwords, and even cryptocurrency wallet seed phrases etc.
Could you share the report they sent you with us? A Trojan dropper is a serious threat, as it can gain access to private data without the user knowing.

█████████████████████████
███████▀▀███████▀▀███████
█████▀░░▄███████▄░░▀█████
███▀░░██████▀░▀████░░▀███
██▀░░▀▀▀████████████░░▀██
██░░█▄████▀▀███▀█████░░██
██░░███▄▄███████▀▀███░░██
██░░████████████████░░██
██▄░░████▄▄██████▄▄█░░▄██
███▄░░██████░░████░░▄███
█████▄░░▀███░░▐▀░░▄█████
███████▄▄███████▄▄███████
█████████████████████████
.
 ROOBET .██████. BET ON WORLD CUP  🗺 ⚽︎.██████.
|

█▄█
▀█▀
████▄▄██████▄▄████
█▄███▀█░░█████░░█▀███▄█
▀█▄▄░▐█████████▌▄▄█▀
██▄▄█████████▄▄████▌
██████▄▄████████
█▀▀████████████████
██████
█████████████
██
█▀▀██████████████
▀▀▀███████████▀▀▀▀
|.
   BET NOW   
craftyart1010 (OP)
Jr. Member
*
Offline

Activity: 34
Merit: 1


View Profile
July 10, 2026, 05:42:16 AM
Merited by albon (1)
 #35

This SamFw scam has been reported to many authorities, including the FBI and IC3.
Well done. I hope these authorities look into your report, check it, and take action against this person if, based on the evidence provided, they determine that he was involved in this scam.

Strangely, after his last post about it, went silent and hasn't replied to anything else that people asked here, including the issues he needed to clarify.

They don’t target people who have nothing on their computers such as no crypto data, no wallet seed phrases etc. If you have nothing important, you might say the tool is working and see no issue. But this guy is little smart! Get it?
Of course, the primary targets are people who have important data, personal information, or crypto wallets with a lot of money in them. I mean, what's the point of hacking a computer that have anything valuable?

Even after my personal request Malwarebytes team has reported that “SamFwToolSetup” (samfw) contains Trojan.dropper. That means it run and then install additional malware. It’s often associated with infostealers that can steal browser data, cookies, saved passwords, and even cryptocurrency wallet seed phrases etc.
Could you share the report they sent you with us? A Trojan dropper is a serious threat, as it can gain access to private data without the user knowing.

He won’t reply because he knows he did something. He’s online, comes here, and reads the posts.

This person deliberately distributes Trojan.Dropper malware in “Samfwfrptool” and tries to find victims. Their scam slogan is that you must disable your antivirus in order to use the tool. During my research on Reddit, even some people became suspicious and warned the community but all the scam SEO done by Vietnamese scammer, “TungTata” do not make those post become on top of search. I also noticed it very late while checking everywhere on online.

In fact, they were right. What kind of tool wouldn’t work in a sandbox or in VirtualBox, but only on a main computer? That was their sophisticated scam method and all fake false positive malware claims.

While talking with some other skilled people, all they said was that Vietnam is a place where online scams are common like it’s something easy, almost toy-like.

Quote
Of course, the primary targets are people who have important data, personal information, or crypto wallets with a lot of money in them. I mean, what's the point of hacking a computer that have anything valuable?

That’s correct, and it’s exactly what happened to me. The tool is safe if you don’t have anything important on your computer.

Quote
Could you share the report they sent you with us? A Trojan dropper is a serious threat, as it can gain access to private data without the user knowing.

https://forums.malwarebytes.com/topic/337471-undected-malware/

This scam tool, SamFwToolSetup_v5.4.zip, has been analyzed by them. To see the replies, you need to register.

I’ll add a screenshot here.





Quote
Trojan.Dropper, C:\1\1\1\SAMFWTOOLSETUP.EXE

What does a trojan dropper do?

  • Download and install other malware.
  • Use your computer for click fraud.
  • Record your keystrokes and the sites you visit.
  • Send information about your PC, including usernames and browsing history, to a remote malicious hacker.
  • Give remote access to your PC.
  • Advertising banners are injected with the web pages that you are visiting.
  • Random web page text is turned into hyperlinks.
  • Browser popups appear which recommend fake updates or other software.

And more and more people are still installing this SamFW malware on their computers. I’m alone fighting the scammer tungtata, and this fight won’t be over.
Mfadi74
Newbie
*
Offline

Activity: 3
Merit: 0


View Profile
July 13, 2026, 05:15:25 AM
 #36

This SamFw scam has been reported to many authorities, including the FBI and IC3.
Well done. I hope these authorities look into your report, check it, and take action against this person if, based on the evidence provided, they determine that he was involved in this scam.

Strangely, after his last post about it, went silent and hasn't replied to anything else that people asked here, including the issues he needed to clarify.

They don’t target people who have nothing on their computers such as no crypto data, no wallet seed phrases etc. If you have nothing important, you might say the tool is working and see no issue. But this guy is little smart! Get it?
Of course, the primary targets are people who have important data, personal information, or crypto wallets with a lot of money in them. I mean, what's the point of hacking a computer that have anything valuable?

Even after my personal request Malwarebytes team has reported that “SamFwToolSetup” (samfw) contains Trojan.dropper. That means it run and then install additional malware. It’s often associated with infostealers that can steal browser data, cookies, saved passwords, and even cryptocurrency wallet seed phrases etc.
Could you share the report they sent you with us? A Trojan dropper is a serious threat, as it can gain access to private data without the user knowing.

He won’t reply because he knows he did something. He’s online, comes here, and reads the posts.

This person deliberately distributes Trojan.Dropper malware in “Samfwfrptool” and tries to find victims. Their scam slogan is that you must disable your antivirus in order to use the tool. During my research on Reddit, even some people became suspicious and warned the community but all the scam SEO done by Vietnamese scammer, “TungTata” do not make those post become on top of search. I also noticed it very late while checking everywhere on online.

In fact, they were right. What kind of tool wouldn’t work in a sandbox or in VirtualBox, but only on a main computer? That was their sophisticated scam method and all fake false positive malware claims.

While talking with some other skilled people, all they said was that Vietnam is a place where online scams are common like it’s something easy, almost toy-like.

Quote
Of course, the primary targets are people who have important data, personal information, or crypto wallets with a lot of money in them. I mean, what's the point of hacking a computer that have anything valuable?

That’s correct, and it’s exactly what happened to me. The tool is safe if you don’t have anything important on your computer.

Quote
Could you share the report they sent you with us? A Trojan dropper is a serious threat, as it can gain access to private data without the user knowing.

https://forums.malwarebytes.com/topic/337471-undected-malware/

This scam tool, SamFwToolSetup_v5.4.zip, has been analyzed by them. To see the replies, you need to register.

I’ll add a screenshot here.

https://talkimg.com/images/2026/07/10/Uc6Wv3.png

https://talkimg.com/images/2026/07/10/Uc6eiw.png

Quote
Trojan.Dropper, C:\1\1\1\SAMFWTOOLSETUP.EXE

What does a trojan dropper do?

  • Download and install other malware.
  • Use your computer for click fraud.
  • Record your keystrokes and the sites you visit.
  • Send information about your PC, including usernames and browsing history, to a remote malicious hacker.
  • Give remote access to your PC.
  • Advertising banners are injected with the web pages that you are visiting.
  • Random web page text is turned into hyperlinks.
  • Browser popups appear which recommend fake updates or other software.

And more and more people are still installing this SamFW malware on their computers. I’m alone fighting the scammer tungtata, and this fight won’t be over.


You can report the SamFW scam here as well. I don’t know where you live, so I’ll share a list of options.

Site to report scams in the United Kingdom: http://www.actionfraud.police.uk/

Site to report scams in the United States: https://www.ic3.gov/default.aspx

Site to report scams in Canada: https://antifraudcentre-centreantifraude.ca/report-signalez-eng.htm

Site to report scams in Europe: https://www.europol.europa.eu/report-a-crime/report-cybercrime-online

Site to report scams in Australia: https://www.scamwatch.gov.au/report-a-scam

Site to report scams in New Zealand: https://www.dia.govt.nz/Spam-How-to-Report-Scams

FTC scam alerts: https://www.consumer.ftc.gov/scam-alerts

Whenever a tool asks you to disable your security software to function, it is almost certainly malicious. Legitimate software developers sign their code with Certificates of Authenticity , which allows Windows and antivirus engines to verify the software's origin.

If a tool only "works" by disabling your protection, it is because it is intentionally designed to trigger heuristics and signature-based detection. If you ever see a prompt that requires you to bypass security, assume it is a compromise attempt.
albon
Legendary
*
Offline

Activity: 2506
Merit: 2413



View Profile
July 13, 2026, 01:30:48 PM
 #37

Their scam slogan is that you must disable your antivirus in order to use the tool. During my research on Reddit, even some people became suspicious and warned the community but all the scam SEO done by Vietnamese scammer, “TungTata” do not make those post become on top of search. I also noticed it very late while checking everywhere on online.

In fact, they were right. What kind of tool wouldn’t work in a sandbox or in VirtualBox, but only on a main computer? That was their sophisticated scam method and all fake false positive malware claims.
Any program that requires you to disable your antivirus to work or refuses to run in a virtual machine, should raise serious concerns. You should only use such software if you are 100% sure you can trust it, especially if your computer contains important data that you cannot afford to lose.

Isolated environments are the safest place to test programs like this. If I knew a program would not run in a virtual machine, I wouldn't take even a 1% risk by testing it on my main computer.

Unfortunately, you learned this lesson too late. If you had taken the necessary security precautions from the beginning, this probably wouldn't have happened.

While talking with some other skilled people, all they said was that Vietnam is a place where online scams are common like it’s something easy, almost toy-like.
Yes, that's true. Although hackers can be found all over the world, they may be more common in countries like Vietnam or other developing nations due to poor living conditions. As a result, some of them may turn to illegal methods to make money.

It's actually not that difficult to create software like this and embed malware or a Trojan inside it to steal users' data.

I've reported something similar before here: https://bitcointalk.org/index.php?topic=5585311.0

█████████████████████████
███████▀▀███████▀▀███████
█████▀░░▄███████▄░░▀█████
███▀░░██████▀░▀████░░▀███
██▀░░▀▀▀████████████░░▀██
██░░█▄████▀▀███▀█████░░██
██░░███▄▄███████▀▀███░░██
██░░████████████████░░██
██▄░░████▄▄██████▄▄█░░▄██
███▄░░██████░░████░░▄███
█████▄░░▀███░░▐▀░░▄█████
███████▄▄███████▄▄███████
█████████████████████████
.
 ROOBET .██████. BET ON WORLD CUP  🗺 ⚽︎.██████.
|

█▄█
▀█▀
████▄▄██████▄▄████
█▄███▀█░░█████░░█▀███▄█
▀█▄▄░▐█████████▌▄▄█▀
██▄▄█████████▄▄████▌
██████▄▄████████
█▀▀████████████████
██████
█████████████
██
█▀▀██████████████
▀▀▀███████████▀▀▀▀
|.
   BET NOW   
craftyart1010 (OP)
Jr. Member
*
Offline

Activity: 34
Merit: 1


View Profile
July 14, 2026, 07:18:13 PM
 #38

Their scam slogan is that you must disable your antivirus in order to use the tool. During my research on Reddit, even some people became suspicious and warned the community but all the scam SEO done by Vietnamese scammer, “TungTata” do not make those post become on top of search. I also noticed it very late while checking everywhere on online.

In fact, they were right. What kind of tool wouldn’t work in a sandbox or in VirtualBox, but only on a main computer? That was their sophisticated scam method and all fake false positive malware claims.
Any program that requires you to disable your antivirus to work or refuses to run in a virtual machine, should raise serious concerns. You should only use such software if you are 100% sure you can trust it, especially if your computer contains important data that you cannot afford to lose.

Isolated environments are the safest place to test programs like this. If I knew a program would not run in a virtual machine, I wouldn't take even a 1% risk by testing it on my main computer.

Unfortunately, you learned this lesson too late. If you had taken the necessary security precautions from the beginning, this probably wouldn't have happened.

While talking with some other skilled people, all they said was that Vietnam is a place where online scams are common like it’s something easy, almost toy-like.
Yes, that's true. Although hackers can be found all over the world, they may be more common in countries like Vietnam or other developing nations due to poor living conditions. As a result, some of them may turn to illegal methods to make money.

It's actually not that difficult to create software like this and embed malware or a Trojan inside it to steal users' data.

I've reported something similar before here: https://bitcointalk.org/index.php?topic=5585311.0

Thank you albon

This is the same pattern used in SamFW scams. If you accidentally install one of these tools, you’re likely to be compromised. SamFW “tools” contain hidden trojan droppers that can steal sensitive information like seed phrases and wallet passwords.

The safest approach is to avoid installing unknown software, and treat “free” downloads from the internet as potentially malicious. 

In your case, they distributing Trojan via a package named “CEX Trading Bot” and attempting to target victims.

In my case, they distributing Trojan.Dropper through ‘Samfwfrptool’ and attempts to find victims.

Do not download, install, or run anything from samfw.com
craftyart1010 (OP)
Jr. Member
*
Offline

Activity: 34
Merit: 1


View Profile
July 16, 2026, 07:51:35 PM
 #39

as I OP everyone read here there’s a clear “same pattern” theme between SamFW scam and npm campaign

https://www.rescana.com/post/active-exploitation-alert-148-malicious-npm-packages-masquerading-as-student-proxies-turn-browsers-into-ddos-botnet

SamFW-scam: FRP/trading/“tool” branding that sounds legitimate.
npm campaign: “student proxy / school filter bypass / tutoring” branding that looks harmless.


malicious part runs

SamFW-scam: tool may appear to unlock/do something, while the real payload (droppers/stealers/RAT) kicks in later.
npm campaign: the proxy “works” for bypassing filters, while the page loads hidden logic to join a swarm and generate attack traffic.

SamFW-scam: opportunistic selection toward people with valuable data (especially crypto credentials).
npm campaign: students/people seeking to bypass school filters (large volume of “willing” visitors to the proxy pages)

Both campaigns follow the same high-level blueprint: disguise + convince + evade scrutiny + run hidden payloads + monetize via opportunistic targets.

In short, if a tool cannot be safely analyzed in an isolated environment and asks you to lower security controls, treat it as highly suspicious and avoid using it on devices containing sensitive data.
craftyart1010 (OP)
Jr. Member
*
Offline

Activity: 34
Merit: 1


View Profile
July 21, 2026, 09:30:51 AM
 #40

Scammer Tungtata is still actively updating his tool and searching for new victims.

Do not download, install, or run any software from samfw.com. They use sophisticated techniques to access devices and steal credentials, compromise accounts, and take wallet funds. Treat this as a serious threat.

Also, don’t rely on Trustpilot reviews. The reviews manipulated Tungtata is buying positive ratings to mislead people.

During my daily checks, I’ve noticed that 20–50 new positive reviews are appearing every day. The same pattern is seen with blog reviews and promotional posts that claim the tool works normally and contains no malware.

This looks like coordinated SEO and review manipulation designed to deceive the community, hide risks, and make the scam appear legitimate.

Malwarebytes Senior Research Engineer analyzed the SamFwToolSetup file and identified a malicious payload. The detection “Trojan.dropper” indicates the SamFw Tool can act as a dropper after it runs, it typically installs or delivers additional malware to the system. 

This type of malware is commonly designed to download and install other harmful components, which include spyware, ransomware, or backdoors.

Bump!
Pages: « 1 [2]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!