SamFW, a popular Android FRP bypass tool, just stole 10,000 XMR (approx. $3 million). It wasn’t a simple hack. It was a targeted theft using a Trojan RAT hidden inside their official installer.
What Happened:
A user downloaded samfwtoolsetup_v5.4.zip. Within moments of running it, their Feather Wallet (Monero) was drained. Simultaneously, the remote attackers wiped the victim’s entire hard drive.
When the victim tried to prove what happened, they found that SamFW had already updated their download link to version v5.5.1 and removed the blog post announcing the incident. They stripped the evidence to hide their tracks.
The Suspect: Đặng Thanh Tùng (Tungtata)
This isn’t just “bad customer service.” This is sophisticated cybercrime.
We are pushing for a formal report with the Vietnamese Cyber Police. We are looking for:
Contact: [email protected]
What Happened:
A user downloaded samfwtoolsetup_v5.4.zip. Within moments of running it, their Feather Wallet (Monero) was drained. Simultaneously, the remote attackers wiped the victim’s entire hard drive.
When the victim tried to prove what happened, they found that SamFW had already updated their download link to version v5.5.1 and removed the blog post announcing the incident. They stripped the evidence to hide their tracks.
The Suspect: Đặng Thanh Tùng (Tungtata)
- Who: Founder/Developer of SamFW and MiFirm.net.
- Where: Hanoi, Vietnam. He uses a US LLC (SamFW Global LLC, Boulder, CO) as a front, but the real money and operations are tied to Quynh Chi Investment and Technology Co. Ltd. in Hanoi.
- The Attitude: When confronted, he didn’t offer a refund. He told the victim to “report it to the police” and sent a laughing emoji before blocking them on Telegram.
This isn’t just “bad customer service.” This is sophisticated cybercrime.
- Malware: The tool contains a Remote Access Trojan (RAT). It doesn’t just unlock phones; it monitors wallets and can wipe your PC.
- Active Cover-up: They change the binary between versions (v5.4 to v5.5.1) to evade antivirus detection and remove logs after the theft.
- Scale: With over 22,000 subscribers on their Telegram channel, the potential victim pool is huge. This $3M might just be the tip of the iceberg.
- Name: Đặng Thanh Tùng (DOB: 1992)
- Company: Quynh Chi Investment and Technology Co. Ltd.
- Address: No. 26, Alley 89, Quan Nhan Street, Thanh Xuan Ward, Hanoi, Vietnam
- Tax ID: 0110492308
- Contact:
- Emails: [email protected], [email protected]
- PayPal/Skrill: [email protected]
- Telegram: @tungtata
- Phone: +84.1296.935.935 / +84.967.888.448
- Scam Archive: https://96238132834.wixsite.com/samfwscam
- GitHub Repo: https://github.com/9623813/tungtata_scammer
- Telegram Channel: https://t.me/samfwcom
We are pushing for a formal report with the Vietnamese Cyber Police. We are looking for:
- Other victims: If you used SamFWTool and lost crypto or data, reach out.
- Vietnamese witnesses: If you know the address in Hanoi or can verify Tungtata’s identity, please help.
- Tech experts: Who can compare the v5.4 and v5.5.1 binaries to map the RAT?
Contact: [email protected]