I want to raise awareness about the Samfwscam: after installing SamFwTool (SamFwToolSetup_v5.4.zip), my XMR Feather wallet that I had open was drained shortly afterward, and when I tried to contact the admin/operator Tung Tạtạ (tungtata) on Telegram, he blocked me and send me laughing emoji, so I’m warning people to be extremely careful don’t run this tool on your main computer (especially if you keep wallets, seed phrases, private keys, or other sensitive data there), because they use sophisticated methods to access devices and steal credentials and wallet funds; please take this seriously, and don’t rely on Trustpilot reviews since scammer tungtata buy fake positive reviews, and even though it hurts, I’m not giving up because I want to help protect more people from this samfwscam.
Goal is prevent more people from falling for this samfw scam and drive attention to it publicly. Even Malwarebytes Senior Research Engineer confirmed that the tool contain malware by running a test on SamFwToolSetup and detecting a malicious payload.
Compensation: I will pay you based on the what you did (e.g., posts, engagement, and visibility).
If you’re willing to help, please reach me on simpleX
This is meant to warn people about samfw tool scams: don’t download or install unknown tools on your computer. I was scammed by samfw, and I’m doing my best to alert others and raise public awareness.
Florida man arrested after stealing $220,000 in crypto using malware hidden in Steam games!
A similar scam technique has been described in major cybersecurity reporting: attackers distributing malware embedded inside seemingly legitimate downloads/games to steal credentials and crypto assets. For example, U.S. reporting describes a case where malware embedded in video games was used to drain crypto wallets after installation.
Not same actors are involved, but it supports that the tactic malicious payloads hidden in “legit” downloads
For example, on the whole internet, you’ll see videos and posts advertising the SamFw FRP Tool, claiming it can remove FRP with one click and change CSC with one click. However, there’s a hidden and secret threat inside: the tool works, but it also contains malware. They secretly install malware on your computer and scan your private files. If they find private keys or crypto wallets, they steal them and wipe all your data.
Do not download, install, or run any software from samfw.com! - https://bitcointalk.org/index.php?topic=5586649.0
Same scam pattern has also been used by SamFW. Tungtata, a Vietnamese scammer, advertises on the internet that his ‘tool’ can remove FRP and other issues, but what it actually does is install malware on the victim’s computer. A similar scam has also been reported in MSN News, where malware is being installed through games. Tungtata did the same thing to his SamFW tool as well.
Another example of the same scheme is cryptocurrency trading bots contain malware and follow the same scam patterns.
Social engineering via a fake “legit tool”: attacker markets a “one-click” FRP removal / support tool (or trading bot / game-related download) to earn trust and drive downloads.
once installed, the malware targets the victim’s crypto wallet(s)/browser data and can watch for wallet activity.
FRP tools, trading bots, or even “games on Steam” are just different packaging/delivery lures the underlying pattern is malware distribution
Malwarebytes Senior Research Engineer ran a test on the file and found a malicious payload.
“Trojan.dropper” in SamFw Tool means it’s typically installs or delivers additional malicious software to your system after it runs.
This malware designed to install other malicious software, such as spyware, ransomware, or backdoors, onto your computer.
It is likely a stealer (Infostealer) onto your machine. This type of malware is designed to scrape your browser data, cookies, saved passwords, and private keys/seed phrases to empty your wallets.
Trojan.Dropper, C:111SAMFWTOOLSETUP.EXE, No Action By User, 90, 1416795, 1.0.111810, , ame, , A8BB817630386982FEB98106FED8EA89, E640A65EFCAE264AD6F758BB3B9DA0D37ED8C690BDA6F113416558D4BCBBCF3A
What exactly happened to us is that all my files and private crypto wallet seeds were stolen after I installed SamFwToolSetup_v5.4.zip. Then few hours later, my funds were drained.
I’m doing my best to provide all the details to the community so no one gets scammed by this scam tool created by Đặng Thanh Tùng (also shown as Tungtata / Đặng Thanh Tùng). I will continue to share my findings, and he will stay online and be watched. I will expose his scam network, which has been operating for years to earn trust. Now he has decided to scam people secretly, but if we keep the community tight, I believe everyone can see the truth.
Đặng Thanh Tùng (also known as “Tungtata”) is a founder of MiFirm / Phone Info Pro / SamFw / Trạmsạc.app. I am calling him a scammer because of his “SamFW Tool” package (v5.4) contains malicious code.
For years, my crypto wallet was untouched and the wallet remained safely on my computer. After I installed “SamFW Tool” (v5.4), my entire wallet balance was drained. In addition, my data appears to have been wiped: text files were shredded, and multiple files were irrecoverable.
This happened immediately after installing the tool. I believe the tool includes malware or code that injects and runs unwanted actions on the computer. I am currently alone trying to warn others not to install this tool.
I’m not making this up I am a victim and I lost a significant amount. When I tried to seek clarification, the scammer blocked me and told me to go to the police.
I’m asking for help: guidance on how to report this properly, preserve evidence, and protect others from falling victim.