I'm interested in your opinion on this setup.
I have it to create a RAT to get specific information from about 10-20 people, nothing big
Kali Linux OS on a laptop that is bought with cash from the marketplace.
The laptop is not connected to me in any way, I have never logged in
with it to wifi at home etc..., I dont have any accounts on it,purely
intended for business
I use a hotspot from an used iPhone bought with cash on which is the Esim bought with crypto.
Mullvad VPN paid with crypto on laptop.
When I am on it, I am away from home in a place that is not connected to me.
Thank you
Solid start. But a few gaps.
The iPhone hotspot is a weak point. Your carrier still knows the IMEI
and can triangulate your location. Better option: use a dedicated 4G
dongle bought with cash, with a data SIM bought the same way. Swap SIMs
every few weeks.
Mullvad is good but not enough alone. Run it through TOR or at least
chain it with another VPN. Laptop MAC address should be changed every
session.
Also, that laptop is clean now, but one slip where you connect to your
home WiFi even once burns the whole setup forever. Never let it touch
your real life.
You're thinking right. Just close those last few gaps. If you need help
with the RAT itself or the opsec around it, I build custom tools for
this kind of work.
The iPhone hotspot is a weak point. Your carrier still knows the IMEI
and can triangulate your location. Better option: use a dedicated 4G
dongle bought with cash, with a data SIM bought the same way. Swap SIMs
every few weeks.
Mullvad is good but not enough alone. Run it through TOR or at least
chain it with another VPN. Laptop MAC address should be changed every
session.
Also, that laptop is clean now, but one slip where you connect to your
home WiFi even once burns the whole setup forever. Never let it touch
your real life.
You're thinking right. Just close those last few gaps. If you need help
with the RAT itself or the opsec around it, I build custom tools for
this kind of work.
Honestly for me it's 9/10 the only
culprit I see is that Iphone and it's two things first one is that the
phone itself is an attack vector if it would get compromised, I know
that Iphones are really secure but still it might happen if some threat
actors really want you, and the other one is obviously the fact that
whoever you bought the esim from (even though they sold you it for
crypto and they seem to respect your privacy at least in some capacity)
can identify your phone.
I honestly don't know if it could've been done better though so a solid 9/10, great job and stay safe.
culprit I see is that Iphone and it's two things first one is that the
phone itself is an attack vector if it would get compromised, I know
that Iphones are really secure but still it might happen if some threat
actors really want you, and the other one is obviously the fact that
whoever you bought the esim from (even though they sold you it for
crypto and they seem to respect your privacy at least in some capacity)
can identify your phone.
I honestly don't know if it could've been done better though so a solid 9/10, great job and stay safe.
Other people have already answered your question but 1 hugeeeeee piece of advice...
Proxy chaining.
Proxy chaining.