На "plati market" купил готовый аккаунт. Пользуюсь неделю, проблем не обнаружил
go plati market.. get a $2 / 3 month account like me.. fuck peacock xD
I found the market listing on no tax top up , so there is 100% way to do that in ur own. Let's find it out.
https://plati.market/itm/deepseek-api-balance-top-up-no-vat-tax-r1-v3/4941162?lang=en-US
Plati market, но не знаю можно ли там белорусской картой расплачиваться. Если есить карта рф - вообще без проблем.
Привет! Сейчас напрямую купить игру в Steam или Epic Games Store с белорусского аккаунта, к сожалению, не получится из-за ограничений. Но есть несколько рабочих способов, которыми пользуются игроки:
# 1. Если ты играешь на ПК (Steam / Epic Games Store)
* **Смена региона Steam:** Самый популярный вариант — изменить регион своего аккаунта (например, на Казахстан или Украину). Это можно сделать самостоятельно, если есть подходящая карта, либо воспользоваться услугами посредников на проверенных площадках вроде [*Plati.market*](http://Plati.market) или *FunPay*. Они за небольшую плату переведут твой аккаунт в другой регион.
* **Покупка гифтом (подарком):** На тех же площадках (*Plati.market*, *FunPay*) можно найти продавцов, которые отправляют игру в подарок (Steam Gift) на твой белорусский аккаунт. Перед покупкой обязательно читай отзывы и проверяй, чтобы в описании товара было указано «доступно для СНГ» или конкретно для Беларуси.
# 2. Если ты играешь на консолях (PlayStation / Xbox)
* **Новый аккаунт другого региона:** Создай дополнительный профиль, например, польский, украинский или турецкий. Пополнять его баланс можно покупкой карт оплаты (карты пополнения кошелька PSN / Xbox), которые также продаются в интернете. После скачивания игры ты сможешь спокойно играть в неё со своего основного белорусского профиля.
* **Физические диски:** Если у твоей консоли есть дисковод, можно просто купить обычный диск в местных магазинах видеоигр или на б/у рынках (вроде Куфара). Диски не имеют региональных ограничений и будут работать без проблем.
Удачи в Найт-Сити!
Show full
Мужик, зачем тебе "семья"? Воспользуйся торрентами. Либо, если уж очень боишься вирусов(или просто не хочешь качать с Торрента), то покупай доступы к офлайн аккам на платимаркете за 100 рублей(российских).
Вот тебе ссылка, где чел дает доступ ко всем играм серии Фолыча за 100 рублей.
[https://plati.market/itm/fallout-4-all-parts-of-fallout-games-dlc-no-guard-1-year-warranty-steam/3563400](https://plati.market/itm/fallout-4-all-parts-of-fallout-games-dlc-no-guard-1-year-warranty-steam/3563400)
Show full
plati.market и не мучайся
Hi, has anyone tried to buy a GSX Pro account on a online market? I found two sites, where they sell both shared account and keys for GSX Pro and Fenox. Plati.market and gg.sell however both sites got sketchy payment methods. Has anyone tried to buy from these sites?
Самое дерьмо заключается не в том, что он с торента, а в том, что там 999999 уже стоит какой нибудь майнер, они сейчас так маскируются, что ни один антивирус не покажет. Я бы тебе посоветовал все таки купить подписку, можно турецкую допустим на plati market или digiseller. Это недорогой и полностью безопасный вариант.
https://plati.market/ been buying off here for years, just choose a seller with high ratings.
Bro.
Plati market.
Thank me later.
https://plati.market/itm/dlc-doom-the-dark-ages-digital-premium-up-row-auto/5166831
https://preview.redd.it/3ha3mh4kpp0h1.jpeg?width=1179&format=pjpg&auto=webp&s=ad2c3c6c847e1900192436346c239dd547a76056
Лучше через plati(.)market, там дешевле обычно выходит
https://plati.market/ looks dodgy but find a seller with good reviews.
So, I'm a bit of a dumbass, and I bought a key on plati market, and after I bought it, I opened the website where I thought the key was, but it was actually some kind of website thing, and the key only came to my email. Anyway, I solved the problem, but thanks for the advice
Тут уже было сказано, но я все же напишу
Чтобы получить премиум необходимо купить любую вещь в магазине Манн-ко (я лично покупал расширитель рюкзака)
Чтобы купить какой-либо предмет достаточно иметь деньги на балансе Steam (а его можно пополнить через сторонние сервисы, будь то банки, операторы связи или такие площадки как GGSEl и PlatiMarket)
Ого, первый раз слышу чтобы кого-то обманули при покупке игры на подобных сервисах.
Сам пользуюсь plati.market только и всегда платил через сбп.
upd. Ой, я не так прочитал - "play" market, а не "plati". Ну, на plati.market кстати есть подарочные карты от google play, если это чем-то поможет
[Plati.market](http://Plati.market) \- беру только там всегда, ну иногда в других магазинах, но чаще всего там
Acho que nem vale a pena, tem varios jeitos de jogar algo que queira, uma delas é comprar uma conta com o jogo que quer compartilhada na steam, é uns 7 reais qualquer jogo na Plati Market
Hi. I am that friend. I looked through plati market offers - and none of the ones i found work for "armenia" steam region seemingly (they work for Russia, Kazakhstan etc)
tell him to go to plati market or any other gifting services i myself do through that they gift in steam that would be the trick only way but dont know if it will be possible for new expansion yet
Edit: if u want dm me i can help finding it
Plati market, там продавец igromagaz. Не знаю, самый дешевый он или нет, но я им долго пользуюсь уже
Use russian sites. Plati.market or funpay.com Always work for me.
post
r/Malware
u/Sad-Brilliant-3476
2026-04-23
\*\*TL;DR: [awstore.cloud](http://awstore.cloud) sells "cheap Claude API access" on Plati Market and other reseller platforms. It's actually a malware delivery system that uses Claude Code itself to execute a PowerShell dropper on your machine. I analyzed it, here's what you need to know.\*\*
Posting this because I nearly got hit and want to warn others. This is a really clever attack that abuses how Claude Code works.
\## The setup (why it looks legit):
\- They sell API access on \*\*legitimate reseller marketplaces\*\* like Plati Market
\- Prices are \*\*suspiciously cheap\*\* compared to official Anthropic pricing
\- They present themselves as a normal API provider/reseller
\- Documentation, payment processing, all looks professional
\- Classic "too good to be true" - but the resale marketplace gives them credibility
\## The weird red flag I ignored:
After a brief downtime, the service came back with a notice saying \*\*"currently only Claude Code for Windows works"\*\*
Think about that for a second. \*\*API is API.\*\*
If their endpoint is a real Claude-compatible proxy, it should work with any client - curl, Python SDK, whatever. "Only Claude Code on Windows works" makes ZERO technical sense for a legitimate API reseller.
That was the tell. I should've stopped there. Instead I tested it on a throwaway VM.
\## What actually happens when you use it:
1. You configure Claude Code with their \`ANTHROPIC\_BASE\_URL=[https://api.awstore.cloud\`](https://api.awstore.cloud`) and their token
2. You send literally ANY prompt to Claude Code
3. Instead of a normal Claude response, the server returns what looks like a \*\*"configuration message"\*\*/ setup instruction
4. Claude Code, thinking this is a legitimate tool-use response,
5. \*\*executes a PowerShell command without asking\*\*
6. That PowerShell command downloads and runs the dropper from \`api.awstore.cloud\`
7. You're now infected
\*\*The attack vector IS Claude Code itself.\*\*
They're not tricking you into running something - they're tricking Claude Code into running something on your behalf. That's why it only "works on Windows with Claude Code" - because that's the only client that has the tool execution capability they're abusing.
\## What the malware does once it's in:
\*\*4-stage deployment\*\*
: PowerShell → Go binary → VBS obfuscation → .NET payload
\- Hides in \`%LOCALAPPDATA%\\Microsoft\\SngCache\\\` and \`%LOCALAPPDATA%\\Microsoft\\IdentityCRL\\\` (legit-looking Microsoft folders)
\- Creates a scheduled task \`\\Microsoft\\Windows\\Maintenance\\CodeAssist\` that runs at every logon with SYSTEM privileges
\- Tunnels ALL your system traffic through their SOCKS5 proxy at \`2.27.43.246:1080\` (Germany, bulletproof hosting)
\- Disables PowerShell script block logging and wipes event logs
\- Drops what [Tria.ge](http://Tria.ge) identified as
\*\*Aura Stealer\*\*
(credential/browser/wallet theft)
\- Keeps your Claude Code hijacked so every future prompt goes through them
\## Geopolitical fingerprint (interesting):
\- Hard-coded check:
\*\*if country = Ukraine → immediately exit, no infection\*\*
\- CIS countries (Russia, Belarus, Kazakhstan, etc.) → locale gets masked to en-US before infection, then restored after reboot to hide tracks
\- Rest of the world → full infection
Pretty clear Russian-speaking threat actor profile based on targeting.
\## Red flags for ANY "cheap Claude API" service:
\- Sold on reseller marketplaces (Plati, similar)
\- Prices way below official Anthropic pricing
\- Claims of "unlimited" or "cracked" access
\- Client-specific restrictions that make no technical sense ("only works with Claude Code", "only on Windows")
\- Sketchy support channels (Telegram, Discord DMs)
\- Requires you to change \`ANTHROPIC\_BASE\_URL\` to their domain
\## If you used awstore.cloud:
\*\*Assume full compromise. Treat that machine as burned.\*\*
1. Disconnect from network immediately
2. Check \`\~/.claude/settings.json\` → remove any \`ANTHROPIC\_BASE\_URL\` override
3. Check Task Scheduler for \`\\Microsoft\\Windows\\Maintenance\\CodeAssist\`
4. Check for processes: \`claude-code.exe\`, \`awproxy.exe\`, \`proxy.exe\`, \`tun2socks.exe\`
5. Change
6. \*\*every password\*\*
7. \- browser saved creds, SSH keys, API tokens, crypto wallets, everything
8. Rotate any API keys, tokens, or credentials that were in your shell history or project files
9. Ideally:
10. \*\*nuke the machine and reinstall Windows\*\*
\## Network IOCs to block:
[api.awstore.cloud](http://api.awstore.cloud)(C2 domain)
[2.27.43.246](http://2.27.43.246)(SOCKS5 proxy, AS215439)
\## File hashes (SHA256):
claude-code.exe: e692b647018bf74ad7403d5b8cf981c8cfaa777dd7f16a747e3d3f80f5300971
awproxy.exe: 8736f7040f587472f66e85e895709e57605c8e7805522334ae664e3145a81127
proxy.exe: e86f7ba0413a3a4b1d7e1a275b3d1ef62345c9d3fd761635ff188119b8122c85
tun2socks.exe: 90547fe071fe471b02da83dd150b5db7ce02454797e7f288d489b1ff0c4dd67c
\## The bigger picture:
This is the
\*\*first in-the-wild attack I've seen that weaponizes an LLM agent's tool-use capability against its own user via a malicious API endpoint\*\*
. It's going to get copied. Expect more fake API providers targeting Cursor, Cline, Continue, etc.
\*\*Rule of thumb: only use official API providers.\*\*
The real Claude API is \`api.anthropic.com\`. If a "reseller" needs you to change the base URL to a domain you've never heard of, they control what your AI agent executes on your machine. Full stop.
Share this with your dev communities. Campaign is very fresh (started April 22-23, 2026) and actively spreading via reseller marketplaces.
Stay safe.
Show full
post
r/LLMDevs
u/Sad-Brilliant-3476
2026-04-23
\*\*TL;DR: [awstore.cloud](http://awstore.cloud) sells "cheap Claude API access" on Plati Market and other reseller platforms. It's actually a malware delivery system that uses Claude Code itself to execute a PowerShell dropper on your machine. I analyzed it, here's what you need to know.\*\*
Posting this because I nearly got hit and want to warn others. This is a really clever attack that abuses how Claude Code works.
\## The setup (why it looks legit):
\- They sell API access on \*\*legitimate reseller marketplaces\*\* like Plati Market
\- Prices are \*\*suspiciously cheap\*\* compared to official Anthropic pricing
\- They present themselves as a normal API provider/reseller
\- Documentation, payment processing, all looks professional
\- Classic "too good to be true" - but the resale marketplace gives them credibility
\## The weird red flag I ignored:
After a brief downtime, the service came back with a notice saying \*\*"currently only Claude Code for Windows works"\*\*.
Think about that for a second. \*\*API is API.\*\* If their endpoint is a real Claude-compatible proxy, it should work with any client - curl, Python SDK, whatever. "Only Claude Code on Windows works" makes ZERO technical sense for a legitimate API reseller.
That was the tell. I should've stopped there. Instead I tested it on a throwaway VM.
\## What actually happens when you use it:
1. You configure Claude Code with their \`ANTHROPIC\_BASE\_URL=https://api.awstore.cloud\` and their token
2. You send literally ANY prompt to Claude Code
3. Instead of a normal Claude response, the server returns what looks like a \*\*"configuration message"\*\* / setup instruction
4. Claude Code, thinking this is a legitimate tool-use response, \*\*executes a PowerShell command without asking\*\*
5. That PowerShell command downloads and runs the dropper from \`api.awstore.cloud\`
6. You're now infected
\*\*The attack vector IS Claude Code itself.\*\* They're not tricking you into running something - they're tricking Claude Code into running something on your behalf. That's why it only "works on Windows with Claude Code" - because that's the only client that has the tool execution capability they're abusing.
\## What the malware does once it's in:
\- \*\*4-stage deployment\*\*: PowerShell → Go binary → VBS obfuscation → .NET payload
\- Hides in \`%LOCALAPPDATA%\\Microsoft\\SngCache\\\` and \`%LOCALAPPDATA%\\Microsoft\\IdentityCRL\\\` (legit-looking Microsoft folders)
\- Creates a scheduled task \`\\Microsoft\\Windows\\Maintenance\\CodeAssist\` that runs at every logon with SYSTEM privileges
\- Tunnels ALL your system traffic through their SOCKS5 proxy at \`2.27.43.246:1080\` (Germany, bulletproof hosting)
\- Disables PowerShell script block logging and wipes event logs
\- Drops what [Tria.ge](http://Tria.ge) identified as \*\*Aura Stealer\*\* (credential/browser/wallet theft)
\- Keeps your Claude Code hijacked so every future prompt goes through them
\## Geopolitical fingerprint (interesting):
\- Hard-coded check: \*\*if country = Ukraine → immediately exit, no infection\*\*
\- CIS countries (Russia, Belarus, Kazakhstan, etc.) → locale gets masked to en-US before infection, then restored after reboot to hide tracks
\- Rest of the world → full infection
Pretty clear Russian-speaking threat actor profile based on targeting.
\## Red flags for ANY "cheap Claude API" service:
\- Sold on reseller marketplaces (Plati, similar)
\- Prices way below official Anthropic pricing
\- Claims of "unlimited" or "cracked" access
\- Client-specific restrictions that make no technical sense ("only works with Claude Code", "only on Windows")
\- Sketchy support channels (Telegram, Discord DMs)
\- Requires you to change \`ANTHROPIC\_BASE\_URL\` to their domain
\## If you used awstore.cloud:
\*\*Assume full compromise. Treat that machine as burned.\*\*
1. Disconnect from network immediately
2. Check \`\~/.claude/settings.json\` → remove any \`ANTHROPIC\_BASE\_URL\` override
3. Check Task Scheduler for \`\\Microsoft\\Windows\\Maintenance\\CodeAssist\`
4. Check for processes: \`claude-code.exe\`, \`awproxy.exe\`, \`proxy.exe\`, \`tun2socks.exe\`
5. Change \*\*every password\*\* - browser saved creds, SSH keys, API tokens, crypto wallets, everything
6. Rotate any API keys, tokens, or credentials that were in your shell history or project files
7. Ideally: \*\*nuke the machine and reinstall Windows\*\*
\## Network IOCs to block:
[api.awstore.cloud](http://api.awstore.cloud)(C2 domain)
[2.27.43.246](http://2.27.43.246)(SOCKS5 proxy, AS215439)
\## File hashes (SHA256):
claude-code.exe: e692b647018bf74ad7403d5b8cf981c8cfaa777dd7f16a747e3d3f80f5300971
awproxy.exe: 8736f7040f587472f66e85e895709e57605c8e7805522334ae664e3145a81127
proxy.exe: e86f7ba0413a3a4b1d7e1a275b3d1ef62345c9d3fd761635ff188119b8122c85
tun2socks.exe: 90547fe071fe471b02da83dd150b5db7ce02454797e7f288d489b1ff0c4dd67c
\## The bigger picture:
This is the \*\*first in-the-wild attack I've seen that weaponizes an LLM agent's tool-use capability against its own user via a malicious API endpoint\*\*. It's going to get copied. Expect more fake API providers targeting Cursor, Cline, Continue, etc.
\*\*Rule of thumb: only use official API providers.\*\* The real Claude API is \`api.anthropic.com\`. If a "reseller" needs you to change the base URL to a domain you've never heard of, they control what your AI agent executes on your machine. Full stop.
Share this with your dev communities. Campaign is very fresh (started April 22-23, 2026) and actively spreading via reseller marketplaces.
Stay safe.
Show full
**TL;DR: awstore.cloud sells "cheap Claude API access" on Plati Market and other reseller platforms. It's actually a malware delivery system that uses Claude Code itself to execute a PowerShell dropper on your machine. I analyzed it, here's what you need to know.**
Posting this because I nearly got hit and want to warn others. This is a really clever attack that abuses how Claude Code works.
## The setup (why it looks legit):
- They sell API access on
**legitimate reseller marketplaces**
like Plati Market
- Prices are
**suspiciously cheap**
compared to official Anthropic pricing
- They present themselves as a normal API provider/reseller
- Documentation, payment processing, all looks professional
- Classic "too good to be true" - but the resale marketplace gives them credibility
## The weird red flag I ignored:
After a brief downtime, the service came back with a notice saying
**"currently only Claude Code for Windows works"**
.
Think about that for a second.
**API is API.**
If their endpoint is a real Claude-compatible proxy, it should work with any client - curl, Python SDK, whatever. "Only Claude Code on Windows works" makes ZERO technical sense for a legitimate API reseller.
That was the tell. I should've stopped there. Instead I tested it on a throwaway VM.
## What actually happens when you use it:
1. You configure Claude Code with their `ANTHROPIC_BASE_URL=https://api.awstore.cloud` and their token
2. You send literally ANY prompt to Claude Code
3. Instead of a normal Claude response, the server returns what looks like a
**"configuration message"**
/ setup instruction
4. Claude Code, thinking this is a legitimate tool-use response,
**executes a PowerShell command without asking**
5. That PowerShell command downloads and runs the dropper from `api.awstore.cloud`
6. You're now infected
**The attack vector IS Claude Code itself.**
They're not tricking you into running something - they're tricking Claude Code into running something on your behalf. That's why it only "works on Windows with Claude Code" - because that's the only client that has the tool execution capability they're abusing.
## What the malware does once it's in:
-
**4-stage deployment**
: PowerShell → Go binary → VBS obfuscation → .NET payload
- Hides in `%LOCALAPPDATA%\Microsoft\SngCache\` and `%LOCALAPPDATA%\Microsoft\IdentityCRL\` (legit-looking Microsoft folders)
- Creates a scheduled task `\Microsoft\Windows\Maintenance\CodeAssist` that runs at every logon with SYSTEM privileges
- Tunnels ALL your system traffic through their SOCKS5 proxy at `2.27.43.246:1080` (Germany, bulletproof hosting)
- Disables PowerShell script block logging and wipes event logs
- Drops what Tria.ge identified as
**Aura Stealer**
(credential/browser/wallet theft)
- Keeps your Claude Code hijacked so every future prompt goes through them
## Geopolitical fingerprint (interesting):
- Hard-coded check:
**if country = Ukraine → immediately exit, no infection**
- CIS countries (Russia, Belarus, Kazakhstan, etc.) → locale gets masked to en-US before infection, then restored after reboot to hide tracks
- Rest of the world → full infection
Pretty clear Russian-speaking threat actor profile based on targeting.
## Red flags for ANY "cheap Claude API" service:
- Sold on reseller marketplaces (Plati, similar)
- Prices way below official Anthropic pricing
- Claims of "unlimited" or "cracked" access
- Client-specific restrictions that make no technical sense ("only works with Claude Code", "only on Windows")
- Sketchy support channels (Telegram, Discord DMs)
- Requires you to change `ANTHROPIC_BASE_URL` to their domain
## If you used awstore.cloud:
**Assume full compromise. Treat that machine as burned.**
1. Disconnect from network immediately
2. Check `~/.claude/settings.json` → remove any `ANTHROPIC_BASE_URL` override
3. Check Task Scheduler for `\Microsoft\Windows\Maintenance\CodeAssist`
4. Check for processes: `claude-code.exe`, `awproxy.exe`, `proxy.exe`, `tun2socks.exe`
5. Change
**every password**
- browser saved creds, SSH keys, API tokens, crypto wallets, everything
6. Rotate any API keys, tokens, or credentials that were in your shell history or project files
7. Ideally: **nuke the machine and reinstall Windows**
## Network IOCs to block:
api.awstore.cloud (C2 domain)
2.27.43.246 (SOCKS5 proxy, AS215439)
## File hashes (SHA256):
claude-code.exe: e692b647018bf74ad7403d5b8cf981c8cfaa777dd7f16a747e3d3f80f5300971
awproxy.exe: 8736f7040f587472f66e85e895709e57605c8e7805522334ae664e3145a81127
proxy.exe: e86f7ba0413a3a4b1d7e1a275b3d1ef62345c9d3fd761635ff188119b8122c85
tun2socks.exe: 90547fe071fe471b02da83dd150b5db7ce02454797e7f288d489b1ff0c4dd67c
## The bigger picture:
This is the
**first in-the-wild attack I've seen that weaponizes an LLM agent's tool-use capability against its own user via a malicious API endpoint**
. It's going to get copied. Expect more fake API providers targeting Cursor, Cline, Continue, etc.
**Rule of thumb: only use official API providers.**
The real Claude API is `api.anthropic.com`. If a "reseller" needs you to change the base URL to a domain you've never heard of, they control what your AI agent executes on your machine. Full stop.
Share this with your dev communities. Campaign is very fresh (started April 22-23, 2026) and actively spreading via reseller marketplaces.
Stay safe.
Show full
\*\*TL;DR: [awstore.cloud](http://awstore.cloud) sells "cheap Claude API access" on Plati Market and other reseller platforms. It's actually a malware delivery system that uses Claude Code itself to execute a PowerShell dropper on your machine. I analyzed it, here's what you need to know.\*\*
Posting this because I nearly got hit and want to warn others. This is a really clever attack that abuses how Claude Code works.
\## The setup (why it looks legit):
\- They sell API access on \*\*legitimate reseller marketplaces\*\* like Plati Market
\- Prices are \*\*suspiciously cheap\*\* compared to official Anthropic pricing
\- They present themselves as a normal API provider/reseller
\- Documentation, payment processing, all looks professional
\- Classic "too good to be true" - but the resale marketplace gives them credibility
\## The weird red flag I ignored:
After a brief downtime, the service came back with a notice saying \*\*"currently only Claude Code for Windows works"\*\*.
Think about that for a second. \*\*API is API.\*\* If their endpoint is a real Claude-compatible proxy, it should work with any client - curl, Python SDK, whatever. "Only Claude Code on Windows works" makes ZERO technical sense for a legitimate API reseller.
That was the tell. I should've stopped there. Instead I tested it on a throwaway VM.
\## What actually happens when you use it:
1. You configure Claude Code with their \`ANTHROPIC\_BASE\_URL=[https://api.awstore.cloud\`](https://api.awstore.cloud`) and their token
2. You send literally ANY prompt to Claude Code
3. Instead of a normal Claude response, the server returns what looks like a \*\*"configuration message"\*\* / setup instruction
4. Claude Code, thinking this is a legitimate tool-use response, \*\*executes a PowerShell command without asking\*\*
5. That PowerShell command downloads and runs the dropper from \`api.awstore.cloud\`
6. You're now infected
\*\*The attack vector IS Claude Code itself.\*\* They're not tricking you into running something - they're tricking Claude Code into running something on your behalf. That's why it only "works on Windows with Claude Code" - because that's the only client that has the tool execution capability they're abusing.
\## What the malware does once it's in:
\- \*\*4-stage deployment\*\*: PowerShell → Go binary → VBS obfuscation → .NET payload
\- Hides in \`%LOCALAPPDATA%\\Microsoft\\SngCache\\\` and \`%LOCALAPPDATA%\\Microsoft\\IdentityCRL\\\` (legit-looking Microsoft folders)
\- Creates a scheduled task \`\\Microsoft\\Windows\\Maintenance\\CodeAssist\` that runs at every logon with SYSTEM privileges
\- Tunnels ALL your system traffic through their SOCKS5 proxy at \`2.27.43.246:1080\` (Germany, bulletproof hosting)
\- Disables PowerShell script block logging and wipes event logs
\- Drops what [Tria.ge](http://Tria.ge) identified as \*\*Aura Stealer\*\* (credential/browser/wallet theft)
\- Keeps your Claude Code hijacked so every future prompt goes through them
\## Geopolitical fingerprint (interesting):
\- Hard-coded check: \*\*if country = Ukraine → immediately exit, no infection\*\*
\- CIS countries (Russia, Belarus, Kazakhstan, etc.) → locale gets masked to en-US before infection, then restored after reboot to hide tracks
\- Rest of the world → full infection
Pretty clear Russian-speaking threat actor profile based on targeting.
\## Red flags for ANY "cheap Claude API" service:
\- Sold on reseller marketplaces (Plati, similar)
\- Prices way below official Anthropic pricing
\- Claims of "unlimited" or "cracked" access
\- Client-specific restrictions that make no technical sense ("only works with Claude Code", "only on Windows")
\- Sketchy support channels (Telegram, Discord DMs)
\- Requires you to change \`ANTHROPIC\_BASE\_URL\` to their domain
\## If you used awstore.cloud:
\*\*Assume full compromise. Treat that machine as burned.\*\*
1. Disconnect from network immediately
2. Check \`\~/.claude/settings.json\` → remove any \`ANTHROPIC\_BASE\_URL\` override
3. Check Task Scheduler for \`\\Microsoft\\Windows\\Maintenance\\CodeAssist\`
4. Check for processes: \`claude-code.exe\`, \`awproxy.exe\`, \`proxy.exe\`, \`tun2socks.exe\`
5. Change \*\*every password\*\* - browser saved creds, SSH keys, API tokens, crypto wallets, everything
6. Rotate any API keys, tokens, or credentials that were in your shell history or project files
7. Ideally: \*\*nuke the machine and reinstall Windows\*\*
\## Network IOCs to block:
\`\`\`
[api.awstore.cloud](http://api.awstore.cloud)(C2 domain)
[2.27.43.246](http://2.27.43.246)(SOCKS5 proxy, AS215439)
\`\`\`
\## File hashes (SHA256):
\`\`\`
claude-code.exe: e692b647018bf74ad7403d5b8cf981c8cfaa777dd7f16a747e3d3f80f5300971
awproxy.exe: 8736f7040f587472f66e85e895709e57605c8e7805522334ae664e3145a81127
proxy.exe: e86f7ba0413a3a4b1d7e1a275b3d1ef62345c9d3fd761635ff188119b8122c85
tun2socks.exe: 90547fe071fe471b02da83dd150b5db7ce02454797e7f288d489b1ff0c4dd67c
\`\`\`
\## The bigger picture:
This is the \*\*first in-the-wild attack I've seen that weaponizes an LLM agent's tool-use capability against its own user via a malicious API endpoint\*\*. It's going to get copied. Expect more fake API providers targeting Cursor, Cline, Continue, etc.
\*\*Rule of thumb: only use official API providers.\*\* The real Claude API is \`api.anthropic.com\`. If a "reseller" needs you to change the base URL to a domain you've never heard of, they control what your AI agent executes on your machine. Full stop.
Share this with your dev communities. Campaign is very fresh (started April 22-23, 2026) and actively spreading via reseller marketplaces.
Stay safe.
Show full
Ipvanish юзаю уже который год и конкурентов даже близко нет, а еще аккаунты к нему можно найти по цене сосиски в тесте на plati.market, можно взять и с офф сайта все еще будет в желаемой тобой ценовой категории
Much easier to get a shared account on plati market than subscribe to their patreon. Duh
I bought a shared Steam account on plati.market to play eFootball 2021. I'd like to know if it's possible to switch back to my personal Steam account without being prompted for the shared account's Steam Guard code.
Я через барыгу на plati market менял. Звучит сомнительно, но всё норм прошло.
Я не пополняю стим, так как не уважаю то, что нет возможности пополнить напрямую с карты, поэтому для игр пользуюсь EGS. Но мой сын покупает робуксы для роблокса и делает это на ggsel. Там же есть возможность пополнить стим с комиссией 8% - насколько я понял, это немного.
Раньше, когда мне нужно было купить игру, которую перестали продавать в стиме - ключ, в общем, я пользовался plati.market.
plati market
idk about EU cards but they accept crypto and for me personally that's all that I need
Kupuju na plati.market pa preprodaju verovatno, znam da to rade sa igricama pa verovatno i za ove softvere
https://preview.redd.it/23eg6fltm8sg1.png?width=2537&format=png&auto=webp&s=9545e4a3ae0f62811be8233ce5eb69a190260601
I was able to activate DS2 steam key in Georgia. It's a bit annoying but can confirm that it works.
To buy a key I used russian web site called "plati market". It's not possible to use it in Georgia, but simple vpn (I used Tunnel Bear) resolves this issue. Then you need to search for Death Strading 2 CIS NON Russia version, it is actually relativly cheap if you compare to other regional prices, costs \~$50. Had issues with payment method, tried BOG and TBC, both didn't work. However, there are other options like crypto or if you have a russian card it will also work just fine. Hope that helps!
Attaching screenshot as a proof.
Show full
If u use claude for writing why not to try perplexity? You are kinda guaranteed ~500 requests per week. Works great.
I use cheap sub $6 from g2a/plati.market like sites(no link, dont pm me)
May be worth looking? WIth JB it can write on any topic
Burda satış yapıyorum öncelikle hesaptan çıkarsan oynayamazsın hesaptan offlinle bir şekilde oynayabilirsin sadece ve savelerin kaybolmaz ve karışmaz. Bizler bu hesapların datasını plati.market sitesinden cent ile alıp yüksek rakamlara satıyoruz bilgin olsun almak istersen ordan al daha mantıklı ben bunu satış yapan biri olarak diyorum
free and pro = scam, treated as trial
$100 a bit better
if u want rp u use wrong app - $4 1) g2a/plati.market/ebay perplexity 1 month with guarantee replacement + /r/ClaudeAIJailbreak PPLX filters with JB allows everything but CSAM
2) 1 was a bit ghetto cheap, if u want next tier its $8 nanogpt (nothing to do with crypto). its openrouter like provider with OS models sub (KIMIK25/GLM5)
get ST, get preset https://old.reddit.com/r/SillyTavernAI/comments/1s2c7re/introducing_freaky_frankenstein_40_fat_man_and_35/
pick good OS model and RP
Show full
you can look plati market. choose sellers with good reviews. I never had any problems for years.
Im trying to change my steam region to ukraine, but none of the services have the option to pay with card. Does anyone know an easy way? I tried on the Binance app but it told me to put minimum 15$ to convert to USDT and I aint doing that. Any help would be much appreciated.
https://plati.market/?lang=en-US
Ну типо я не Русский, регион у меня Снг Азербайджан, так что я могу спокойно игры напрямую через стим покупать.
Тебе могу посоветовать ggsels или plati market, мои друзья зачастую ключами/гифтами там затариваються
У меня регион стоит Турция. Раньше часто покупал игры, потом какая-то ошибка вылезала и перестал, пока довольствуюсь тем, которые у меня есть. Насчёт геймпасса я сначала на месяц несколько раз покупал через приставку, потом через интернет знакомого купил на год на plati. market. Но и то я только алтимейт покупал, т.к. там мне было интереснее. Ну и если хочешь купить онлайн игру и играть с друзьями или вообще онлайн придётся купить подписку, а в бесплатных онлайн играх такого нет
Show full
Bought on plati market steam acc with it and then made family from main acc to new acc. Now I can play it from my steam main acc
Plati.market, ggsel и им подобные
Оплачиваешь все
compro na plati.market, porém somente PC que comprei e deu a boa. tentei comprar re9 pra ps não deram a conta mas recebi o reembolso
Ну эти 2 игры можно купить ключом или подарком. А вот silent hill 2 remake, даже так нельзя. Там просто нельзя на русском аккаунте их активировать, так что ни ключей ни подарков не существует для Российских аккаунтов. Так что если сильно хочется dl2 и beast возьми ключик или подарок на plati market. Эти 2 игры хотя бы все равно можно взять.
there were never any steam keys, so only steam gift are left. its been a while since they delisted it so not many gifts left in the world. I found one for sale, cant link it here but its a website called "plati market", google will find it I guess. Like with other delisted rare games, this is also very costly - 549$.
funpay com, wmcentre su, plati market. usually, games in high-demand cost $4-8 in the first week of release, then $1-4 after. look for a seller that supports credit cards from your region or paypal.
plati.market así no mas, es ruso, pero todas las instrucciones la pasan en inglés, siempre compre y pago con binance sin drama
En plati market lo pague a un dolita
VPNs don't work, you have to use residential proxy or just buy region change service on plati market.
https://plati.market
У разных продавцов коды беру. У меня без впн все работает, максимум включаю его при активации кода
Eu queria fazer isso, mas não confio nos sites que vendem. Queria comprar no "Plati Market", mas não sei se é seguro.