Bitcoin Forum
July 30, 2026, 06:17:55 AM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 [3]  All
  Print  
Author Topic: Samfw.com Scam - Fraud & Trojan RAT Malware : SamFWTool Theft (XMR)  (Read 703 times)
craftyart1010 (OP)
Jr. Member
*
Offline

Activity: 38
Merit: 2

Samfwtool Confirmed Scam | Do Not Install


View Profile
July 25, 2026, 07:56:47 AM
 #41



Samfw scam is still active and the scammer is continuing to search for more victims. Once again case has been reported to the FBI Internet Crime Complaint Center (IC3).  

The individual involved (Tung tata) is using a “tool” to scam people, and the tool has already been flagged as malware by Malwarebytes. He appeared online on a forum but stopped responding !
We need to raise awareness to help stop this scam. Do not trust paid promotions, “safe” claims, or paid reviews about this tool those fake.  

If you encounter or already interacted with Samfw or Tung tata’s tool, consider reporting it through the proper channels and share your experience to warn others. This scammer is based in Vietnam.

They are using sophisticated methods to connect to your device and steal credentials, accounts, and wallet funds. Please take this seriously and protect yourselves. Also do not believe Trustpilot reviews. Scammer tungtata buys them to fake it. He also keeps buying blog reviews and posting reviews to show his tool working without issue and that there is no malware inside. This is SEO work done by them to lie to the community.

Do not download, install, or run any software from samfw.com!
marto25
Member
**
Online Online

Activity: 160
Merit: 11

No-KYC. No Account. No Compromise.


View Profile WWW
July 26, 2026, 06:37:21 AM
 #42

We've been following this thread since it opened.

The SamFW case is well-documented at this point — Trojan.Dropper confirmed by Malwarebytes, fake timestamp set to 2097, sandbox evasion by design, version 5.4 pulled immediately after the theft.

We wrote a full breakdown — not about who is guilty, but about the opsec failure that made this possible in the first place. Because the real issue is not this specific tool. It is running any software on a machine that holds an active wallet.

Full article: https://matomba.substack.com/p/one-zip-file-one-empty-wallet-why

One environment for tools. One environment for assets. Never the same machine.

NULL_ROUTE · Privacy Directory · No-KYC · XMR-first  — cetoc.org/routen.html
craftyart1010 (OP)
Jr. Member
*
Offline

Activity: 38
Merit: 2

Samfwtool Confirmed Scam | Do Not Install


View Profile
July 26, 2026, 09:00:32 AM
 #43

We've been following this thread since it opened.

The SamFW case is well-documented at this point — Trojan.Dropper confirmed by Malwarebytes, fake timestamp set to 2097, sandbox evasion by design, version 5.4 pulled immediately after the theft.

We wrote a full breakdown — not about who is guilty, but about the opsec failure that made this possible in the first place. Because the real issue is not this specific tool. It is running any software on a machine that holds an active wallet.

Full article: https://matomba.substack.com/p/one-zip-file-one-empty-wallet-why

One environment for tools. One environment for assets. Never the same machine.

Thank you so much for all your efforts.

Quote
7955375aa728bcd66fd0778674cd279d8bb911bf0ff553bc09c7a5e05aebcdee

A small donation sent to support a helping community and help raise awareness about this samfwscam.

Everyone please don’t underestimate it this is a highly sophisticated, smart scam, and right now everyone is at risk.

I’m offering a donation to people who help spread the warning about samfw and make this samfwfrpscam more public so that no one else has to get scammed like I did.

So far, I’ve warned many people about the scam and helped them understand the risks. I’ve also guided them through uninstalling the samfw malicious software, and recommended formatting their computers and switching to Ubuntu or Linux Mint.

xmrbro
Newbie
*
Offline

Activity: 25
Merit: 5


View Profile WWW
July 26, 2026, 06:07:12 PM
 #44

Hello, I came across your topic by chance and I sincerely sympathize with your loss. I hope you find peace and are able to overcome it. The case is very complex and important, which is why I wrote a detailed post on a Tor forum with the goal of warning other people and protecting them. Since I am also a German speaker, I translated it and posted it in the German-speaking community on BT.

https://bitcointalk.org/index.php?topic=5589494.msg66981449
craftyart1010 (OP)
Jr. Member
*
Offline

Activity: 38
Merit: 2

Samfwtool Confirmed Scam | Do Not Install


View Profile
July 27, 2026, 08:25:42 AM
 #45

Hello, I came across your topic by chance and I sincerely sympathize with your loss. I hope you find peace and are able to overcome it. The case is very complex and important, which is why I wrote a detailed post on a Tor forum with the goal of warning other people and protecting them. Since I am also a German speaker, I translated it and posted it in the German-speaking community on BT.

https://bitcointalk.org/index.php?topic=5589494.msg66981449

Thank you for helping spread awareness about samfw as a scam and warning other users.

Quote
7a0a8dbc89fdd03f48166064fa2387575c45ab051e53a4fa92128527f0cbe93d

A small donation sent to support a helping community and help raise awareness about this samfwscam.

Do not download, install, or use anything from samfw.com. New accounts online are posting that “Samfw is safe” and claiming any security detections are false positives. These posts are part of scam operations done by scammer tungtata. I’m doing my best to share clear details with the community so nobody gets scammed by this tool. It created by Đặng Thanh Tùng (also shown under names like Tungtata / Đặng Thanh Tùng). I’ll keep posting what I find, and I’ll monitor his activity. My goal is to expose the wider samfw scam network he’s been operating for years and that has earned people’s trust with fake posts.

albon
Legendary
*
Offline

Activity: 2506
Merit: 2414



View Profile
July 29, 2026, 01:50:06 PM
 #46

Thank you for helping spread awareness about samfw as a scam and warning other users.
I have a LinkedIn account with more than 2,000 followers, and a Medium account with more than 280 followers.

If you'd like me to publish your content there, feel free to send me a PM on the forum with the complete content in a TXT file, and I'll post it.

The goal is to spread awareness and help this content rank in search engines, so it may prevent others from becoming victims of this malicious tool.

New accounts online are posting that “Samfw is safe” and claiming any security detections are false positives. These posts are part of scam operations done by scammer tungtata. I’m doing my best to share clear details with the community so nobody gets scammed by this tool.
This is misleading marketing, and unfortunately it can harm many people who may end up getting scammed, just as it happened to you because of the misleading information being widely promoted about this tool.

I truly hope your efforts help you recover your losses and protect potential users of this tool from becoming victims of having their devices compromised.

█████████████████████████
███████▀▀███████▀▀███████
█████▀░░▄███████▄░░▀█████
███▀░░██████▀░▀████░░▀███
██▀░░▀▀▀████████████░░▀██
██░░█▄████▀▀███▀█████░░██
██░░███▄▄███████▀▀███░░██
██░░████████████████░░██
██▄░░████▄▄██████▄▄█░░▄██
███▄░░██████░░████░░▄███
█████▄░░▀███░░▐▀░░▄█████
███████▄▄███████▄▄███████
█████████████████████████
.
 ROOBET .██████. BET ON WORLD CUP  🗺 ⚽︎.██████.
|

█▄█
▀█▀
████▄▄██████▄▄████
█▄███▀█░░█████░░█▀███▄█
▀█▄▄░▐█████████▌▄▄█▀
██▄▄█████████▄▄████▌
██████▄▄████████
█▀▀████████████████
██████
█████████████
██
█▀▀██████████████
▀▀▀███████████▀▀▀▀
|.
   BET NOW   
craftyart1010 (OP)
Jr. Member
*
Offline

Activity: 38
Merit: 2

Samfwtool Confirmed Scam | Do Not Install


View Profile
July 29, 2026, 07:28:44 PM
 #47

Thank you for helping spread awareness about samfw as a scam and warning other users.
I have a LinkedIn account with more than 2,000 followers, and a Medium account with more than 280 followers.

If you'd like me to publish your content there, feel free to send me a PM on the forum with the complete content in a TXT file, and I'll post it.

The goal is to spread awareness and help this content rank in search engines, so it may prevent others from becoming victims of this malicious tool.

New accounts online are posting that “Samfw is safe” and claiming any security detections are false positives. These posts are part of scam operations done by scammer tungtata. I’m doing my best to share clear details with the community so nobody gets scammed by this tool.
This is misleading marketing, and unfortunately it can harm many people who may end up getting scammed, just as it happened to you because of the misleading information being widely promoted about this tool.

I truly hope your efforts help you recover your losses and protect potential users of this tool from becoming victims of having their devices compromised.

Two articles have been sent thank you, albon. Also, good news: their website is marked as Ethereum phishing.

samfwscam “Trojan.dropper” in SamFw Tool #272509

https://github.com/MetaMask/eth-phishing-detect/issues/272509

Samfw is distributing malware stealthily. I’m telling you: if you don’t have important things on your computer, the tool may seem to work without issue. But if you have crypto wallets and seed phrases stored on your computer, they can drain your funds. They use trojan droppers to install a RAT and other malware on your device.

This “samfwscam” is very smart and sophisticated. Do not download or install their scam tool. This is a public warning.

Keywords: samfwscam, SAMFW scam, malware warning, trojan dropper, RAT, remote access trojan, stealth malware, crypto wallet, seed phrase, seed theft, crypto drain, cybersecurity, scam tool, phishing, malware distribution, malware protection, stay safe online

Scammer tungtata offer "one-click" solutions (FRP bypass, CSC changes) to entice users, particularly those seeking technical workarounds for mobile devices. But there is something hidden behind the samfwtool.

Key technical findings, documented publicly:

    Malwarebytes analyzed the installer and identified a Trojan.Dropper payload: C:\1\1\1\SAMFWTOOLSETUP.EXE

    VirusTotal flagged version 5.4 across multiple engines — classifications include Trojan, PUA, and heuristic detections

    The file contained a fake timestamp set to year 2097 — a known anti-forensics technique

    The tool refused to run in VirtualBox and sandboxed environments — by design

    Version 5.4 was deleted from the official site shortly after the theft, replaced with 5.5


https://substack.com/home/post/p-208528787 - read more about samfwscam
Pages: « 1 2 [3]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!