Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

    /// <summary>
    /// Checks if Blueswan service is running.
    /// </summary>
    /// <returns></returns>
What fresh hell is this?


From a quick search, looks like a software testing framework: https://www.cigniti.com/blueswan/

Edit: see https://news.ycombinator.com/item?id=30038085


The malware DLL has "https://locator.blueswan.io" in it, and various texts referring to "bs-worker" or Blueswan-worker. It's more like an internal codename.

Fun fact: the DLL also has various "C:\Users\akabos" strings, that being the "CTO" of this enterprise: https://ru.linkedin.com/in/akabos

Russian malware writers don't care much for CI.


I meant the formatting, turning one line of pretty useless comment into 4 lines of garbage boilerplate.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: