Theft by SamFW Founder Đặng Thanh Tùng

  • Florida man arrested Soon Tungtata/SamFW Uses the Same Malware and Wallet-Theft | Same Scam Pattern

    Florida man arrested Soon Tungtata/SamFW Uses the Same Malware and Wallet-Theft | Same Scam Pattern

    Tungtata scam, Tungtata fraud, Dang Thanh Tung scam, samfw scam, samfw malware, samfw trojan, samfw security risk, samfw suspicious software
    Tungtata scam, Tungtata fraud, Dang Thanh Tung scam, samfw scam, samfw malware, samfw trojan, samfw security risk, samfw suspicious software

    https://www.msn.com/en-us/news/crime/florida-man-arrested-after-stealing-220000-in-crypto-using-malware-hidden-in-steam-games/ar-AA288IeL

    Same scam pattern has also been used by SamFW. Tungtata, a Vietnamese scammer, advertises on the internet that his ‘tool’ can remove FRP and other issues, but what it actually does is install malware on the victim’s computer. A similar scam has also been reported in MSN News, where malware is being installed through games. Tungtata did the same thing to his SamFW tool as well.

    Another example of the same scheme is cryptocurrency trading bots contain malware and follow the same scam patterns.

    SamFW warning, SamFW scam, malware alert, Tungtata malware, Dang Thanh Tung fraud, stop using SamFW, critical security notice, cryptocurrency theft, Remote Access Trojan, computer virus, software supply chain attack, SamFW.com hack
    SamFW warning, SamFW scam, malware alert, Tungtata malware, Dang Thanh Tung fraud, stop using SamFW, critical security notice, cryptocurrency theft, Remote Access Trojan, computer virus, software supply chain attack, SamFW.com hack

    Same scam patterns / method (how the scheme typically works):

    • Social engineering via a fake “legit tool”: attacker markets a “one-click” FRP removal / support tool (or trading bot / game-related download) to earn trust and drive downloads.
    • Malicious payload hidden inside the installer/package: the tool appears to be the promised utility, but the installer contains malware (e.g., RAT/trojan) or drops additional malicious files after execution.
    • Pre-positioning to steal/monitor wallet access: once installed, the malware targets the victim’s crypto wallet(s)/browser data and can watch for wallet activity.
    • Funds theft shortly after installation: the scam often empties wallets quickly (e.g., moving crypto out with unauthorized approvals/transactions).
    • Anti-forensics / “version replacement”: after the theft, the attacker updates the download package (e.g., v5.5 replacing v5.4) and/or removes the exact version tied to evidence.
    • Attacks across different themes but same delivery chain: FRP tools, trading bots, or even “games on Steam” are just different packaging/delivery lures—the underlying pattern is malware distribution + wallet compromise + rapid monetization.
  • SamFwToolSetup_v5.4 flagged as Trojan.Dropper — how my wallet seeds were stolen

    SamFwToolSetup_v5.4 flagged as Trojan.Dropper — how my wallet seeds were stolen

    Malwarebytes Senior Research Engineer ran a test on the file and found a malicious payload.

    samfw trojan.dropper malware, samfw trojan.dropper, samfwtool trojan.dropper, samfw tooldropper, samfw trojan dropper malware, samfwtoolsetupp.exe trojan.dropper, SAMFWTOOLSETUP.EXE trojan.dropper, samfwtoolsetup trojan.dropper, samfwsetup trojan.dropper, samfw tool trojan.dropper, samfw trojan.dropper infostealer

    “Trojan.dropper” in SamFw Tool means it’s typically installs or delivers additional malicious software to your system after it runs.

    This malware designed to install other malicious software, such as spyware, ransomware, or backdoors, onto your computer.

    It is likely a stealer (Infostealer) onto your machine. This type of malware is designed to scrape your browser data, cookies, saved passwords, and private keys/seed phrases to empty your wallets.

    Warning to the community: SamFwToolSetup dropped an Infostealer that stole crypto and drained funds

    Trojan.Dropper, C:\1\1\1\SAMFWTOOLSETUP.EXE, No Action By User, 90, 1416795, 1.0.111810, , ame, , A8BB817630386982FEB98106FED8EA89, E640A65EFCAE264AD6F758BB3B9DA0D37ED8C690BDA6F113416558D4BCBBCF3A


    What exactly happened to us is that all my files and private crypto wallet seeds were stolen after I installed SamFwToolSetup_v5.4.zip. Then few hours later, my funds were drained.

    I’m doing my best to provide all the details to the community so no one gets scammed by this scam tool created by Đặng Thanh Tùng (also shown as Tungtata / Đặng Thanh Tùng). I will continue to share my findings, and he will stay online and be watched. I will expose his scam network, which has been operating for years to earn trust. Now he has decided to scam people secretly, but if we keep the community tight, I believe everyone can see the truth.

  • SamFwToolSetup_v5.4.zip scam

    SamFwToolSetup_v5.4.zip scam

    You may see on everywhere posts and videos advertise the “SamFw FRP Tool,” claiming it can remove FRP and change CSC with one click. However, there is a hidden danger inside the download. The tool appears to function, but it also include malware that installs on the computer, scans private files, and targets sensitive items such as private keys or crypto wallets. If such data is found, it can lead to theft and deletion of files.

    I am one of the victims. I lost $3 million after installing a file called “SamFwToolSetup_v5.4.zip.” My wallet drained the same day, and the software was later updated to “SamFwToolSetup_v5.5.1.zip.”

    I am reporting this because I believe the “SamFw FRP Tool” is a scam. Do not install it be careful.

    SamFW warning, SamFW scam, malware alert, Tungtata malware, Dang Thanh Tung fraud, stop using SamFW, critical security notice, cryptocurrency theft, Remote Access Trojan, computer virus, software supply chain attack, SamFW.com hack
    SamFW warning, SamFW scam, malware alert, Tungtata malware, Dang Thanh Tung fraud, stop using SamFW, critical security notice, cryptocurrency theft, Remote Access Trojan, computer virus, software supply chain attack, SamFW.com hack

    The person behind this scam is the Vietnam user “tungtata.”

    Keywords
    SamFw FRP Tool scam, SamFw FRP Tool malware, SamFwToolSetup_v5.4.zip scam, SamFwToolSetup_v5.4.zip malware, SamFwToolSetup_v5.5.1.zip scam, SamFwToolSetup_v5.5.1.zip malware, FRP bypass scam, FRP bypass malware, remove FRP scam, remove FRP malware, change CSC scam, change CSC malware, one click tool scam, one click tool malware, malware hidden virus scam, hidden malware scam, crypto wallet drained scam, crypto wallet drained malware, private keys stolen scam, private keys stolen malware, key theft scam, key theft malware, ransomware scam, ransomware malware, data wipe scam, data wipe malware, computer infection scam, computer infection malware, scam software scam, scam software malware, Vietnamese scam scam, Vietnamese scam malware, Tungtata scam, Tungtata malware, tech scam warning scam, tech scam warning malware, cybersecurity warning scam, cybersecurity warning malware, Android tool scam, Android tool malware, suspicious downloader scam, suspicious downloader malware, victim story scam, victim story malware

  • SamFw FRP Tool Scam: Malware Installer, Wallet Theft, and Data Wipe

    SamFw FRP Tool Scam: Malware Installer, Wallet Theft, and Data Wipe

    SamFw FRP Tool Scam Warning:

    Don’t install “SamFw FRP Tool.” This is a scam. no virus claims are fake, and the installer can contain malware that puts private files and crypto wallets at risk. Drains wallets and wipes data after installation. We had an issue after running SamFwToolSetup_v5.4.zip, and the same day they update the tool to SamFwToolSetup_v5.5.1.zip.

    SamFW warning, SamFW scam, malware alert, Tungtata malware, Dang Thanh Tung fraud, stop using SamFW, critical security notice, cryptocurrency theft, Remote Access Trojan, computer virus, software supply chain attack, SamFW.com hack
    SamFW warning, SamFW scam, malware alert, Tungtata malware, Dang Thanh Tung fraud, stop using SamFW, critical security notice, cryptocurrency theft, Remote Access Trojan, computer virus, software supply chain attack, SamFW.com hack

    Some ads claim one-click FRP removal and one-click CSC changes. Those claims do not match reality. Instead, the installer can compromise devices, search for sensitive data (including private keys), steal it, and then erase data.

    We were affected and lost money after installing the setup.

    I was a victim. I lost $3 million after installing the file.

    Tungtata scam, Tungtata fraud, Dang Thanh Tung scam, samfw scam, samfw malware, samfw trojan, samfw security risk, samfw suspicious software, Tungtata trojan virus, samfw warning, Đặng Thanh Tùng scammer, owner Đặng Thanh Tùng fraud, tungtata scam, DangThanhTung scammer, DangThanhTung fraud, DangThanhTung rat trojan
    Tungtata scam, Tungtata fraud, Dang Thanh Tung scam, samfw scam, samfw malware, samfw trojan, samfw security risk, samfw suspicious software, Tungtata trojan virus, samfw warning, Đặng Thanh Tùng scammer, owner Đặng Thanh Tùng fraud, tungtata scam, DangThanhTung scammer, DangThanhTung fraud, DangThanhTung rat trojan

    Hà Nội Developer “Tungtata” Cybercrime Case

  • Feather Wallet XMR Theft Linked to Hà Nội Developer “Tungtata” and SamFW Tool Packages v5.4/v5.5.1

    Feather Wallet XMR Theft Linked to Hà Nội Developer “Tungtata” and SamFW Tool Packages v5.4/v5.5.1

    Cybercrime involving “SamFW” / “SamFW Tool,” associated with Hà Nội-based developer Đặng Thanh Tùng (also shown as Tungtata / “tungtata”).

    A family member installed software from samfw.com on June 23, 2026. After installation, approximately 10,000 XMR (about $3 million) were withdrawn from a Feather Wallet, and the victim’s computer data was deleted.

    The incident is linked to the package samfwtoolsetup_v5.4.zip. After the theft, the tool was removed and replaced with a revised build labeled SamFwToolSetup_v5.5.1.zip to reduce evidence.

    Hà Nội Developer “Tungtata” Cybercrime Case

    Tungtata scam, Tungtata fraud, Dang Thanh Tung scam, samfw scam, samfw malware, samfw trojan, samfw security risk, samfw suspicious software, Tungtata trojan virus, samfw warning, Đặng Thanh Tùng scammer, owner Đặng Thanh Tùng fraud, tungtata scam, DangThanhTung scammer, DangThanhTung fraud, DangThanhTung rat trojan
    Tungtata scam, Tungtata fraud, Dang Thanh Tung scam, samfw scam, samfw malware, samfw trojan, samfw security risk, samfw suspicious software, Tungtata trojan virus, samfw warning, Đặng Thanh Tùng scammer, owner Đặng Thanh Tùng fraud, tungtata scam, DangThanhTung scammer, DangThanhTung fraud, DangThanhTung rat trojan

    Public materials reportedly connect the named party to SamFW Global LLC and additional Vietnam technology entities, with multiple online profiles and payment channels tied to the same identity. The case has been reported to several crypto exchanges. The organizers are requesting community assistance to collect, preserve, and organize evidence—such as technical indicators, download/build identifiers, logs, and attribution data—to support a report to Vietnamese police/cybercrime investigators.

    The goal is to identify responsible parties and provide actionable leads to authorities.

    samfw suspicious software, Tungtata trojan virus, samfw warning, Đặng Thanh Tùng scammer, owner Đặng Thanh Tùng fraud, tungtata scam, DangThanhTung scammer, DangThanhTung fraud, DangThanhTung rat trojan
    samfw suspicious software, Tungtata trojan virus, samfw warning, Đặng Thanh Tùng scammer, owner Đặng Thanh Tùng fraud, tungtata scam, DangThanhTung scammer, DangThanhTung fraud, DangThanhTung rat trojan

    Footer keywords: Tungtata scam, Tungtata fraud, Đặng Thanh Tùng scammer, DangThanhTung fraud, SamFW scam, SamFW Tool malware, samfw trojan, samfw rat, samfw security risk, samfw suspicious software, Feather Wallet XMR theft, XMR withdrawn ~10,000, device data deletion, modified SamFW package v5.5.1, remote access suspected, wallet monitoring suspected, SamFW Global LLC, LeHuy Technology Co., Ltd, Quynh Chi Investment and Technology Co., Ltd, Hanoi cybercrime report, Vietnam crypto scam, Android app com.samfw, MiFirm, Trạmsạc.app

  • Theft and Malware Distribution via SamFW

    Overview On June 23, 2026, we experienced a significant loss of funds ($3,000,000 USD in Monero/XMR) following the installation of the “SamFW Tool” (version 5.4). Shortly after the software was executed, the victim’s local data was purged, and the funds were siphoned from their Feather Wallet. The developers subsequently removed the compromised version and replaced it with an updated build.


    Scammee Name: Đặng Thanh Tùng (also known as “Tungtata”)

    Short Description
    This report documents a severe security incident involving the distribution of malicious software through the “SamFW Tool” website. Following the installation of version 5.4, a user suffered the theft of 10,000 XMR and complete data loss. We have compiled comprehensive evidence, including business entities, personal identifiers, and digital footprints, to assist the Vietnamese cybercrime authorities in investigating Đặng Thanh Tùng (Tungtata) for organized financial fraud and malware distribution.

    Keywords
    Đặng Thanh Tùng, Tungtata, SamFW scam, cryptocurrency theft, Monero theft, cybercrime investigation, malware distribution, SamFW malware, Vietnam cyber police, Quynh Chi Investment, financial fraud, computer security breach, illegal software, SamFW tool exploit
    Tungtata scam, Tungtata fraud, Dang Thanh Tung scam, samfw scam, samfw malware, samfw trojan, samfw security risk, samfw suspicious software, Tungtata trojan virus, samfw warning, Đặng Thanh Tùng scammer, owner Đặng Thanh Tùng fraud, tungtata scam, DangThanhTung scammer, DangThanhTung fraud, DangThanhTung rat trojan
    • Location: Hanoi, Vietnam
    • Business Entities: SamFW Global LLC, Quynh Chi Investment and Technology Co., Ltd.
    • Associated Services: SamFW.com, MiFirm.net, Trạmsạc.app
      Summary of Events 1. Infection: The victim installed samfwtoolsetup_v5.4.zip from the official website.
    1. Theft: Immediate unauthorized transfer of 10,000 XMR occurred.
    2. Evidence Tampering: The developer replaced the malicious file with version 5.5.1 shortly after the incident was reported to them.
    3. Communication: Upon confrontation, the developer admitted no fault and engaged in mocking behavior before blocking the victim on Telegram.
      Evidence Repository * Tax ID: 0110492308 (Quynh Chi Investment and Technology Co., Ltd.)
    • Emails: tungvn48@gmail.com, dttung48@gmail.com
    • Phone: +84.1296.935.935 / +84.967.888.448
    • Digital Footprint: All associated profiles (GitHub, XDA, Facebook, PayPal) have been documented in the provided evidentiary links.
  • Scammer Đặng Thanh Tùng (also shown as Tungtata / Đặng Thanh Tùng)

    Scammer Đặng Thanh Tùng (also shown as Tungtata / Đặng Thanh Tùng)

    Scammer name: Đặng Thanh Tùng (also shown as Tungtata / Đặng Thanh Tùng) Based in Hanoi Capital of Vietnam

    Role stated: founder / main developer of “SamFW” and MiFirm.net (from About page at Samfw.com)
    Education stated: Quang Ninh Industrial College (from About page at Samfw.com)
    Named partner/founder: Thang; partner and founder of LeHuy Technology Company (from About page at Samfw.com)

    samfw suspicious software, Tungtata trojan virus, samfw warning, Đặng Thanh Tùng scammer, owner Đặng Thanh Tùng fraud, tungtata scam, DangThanhTung scammer, DangThanhTung fraud, DangThanhTung rat trojan
    samfw suspicious software, Tungtata trojan virus, samfw warning, Đặng Thanh Tùng scammer, owner Đặng Thanh Tùng fraud, tungtata scam, DangThanhTung scammer, DangThanhTung fraud, DangThanhTung rat trojan

    Company / registered entity: SamFW Global LLC

    Location listed publicly: Boulder, Colorado, United States

    Developer country listed publicly for Đặng Thanh Tùng: Vietnam
    Additional public connections: listings linking the service to Quynh Chi Investment and Technology Co. Ltd. (Hanoi, Vietnam); and repeating Boulder, Colorado for SamFW Global LLC.

    A family member installed “SamFW Tool” from samfw.com on Jun 23, 2026. Shortly after installation, 10,000 XMR (about $3 million) were withdrawn from the Feather Wallet, and everything in victim’s computer data was deleted.

    After installing samfwtoolsetup_v5.4.zip, the scammer tungtata stole the funds from the Feather Wallet. After the theft, they removed and modified the original tool package to reduce evidence. The download is now replaced with a revised version labeled SamFwToolSetup_v5.5.1.zip.

    After the scam, the photo of the incident was taken on a phone. Later, the scammer updated their website and removed that specific version of the tool.

    Source: https://samfw.com/blog/samfw-frp-tool-1-0-remove-samsung-frp-one-click

    ### Short Description
    This report documents a severe security incident involving the distribution of malicious software through the “SamFW Tool” website. Following the installation of version 5.4, a user suffered the theft of 10,000 XMR and complete data loss. We have compiled comprehensive evidence, including business entities, personal identifiers, and digital footprints, to assist the Vietnamese cybercrime authorities in investigating Đặng Thanh Tùng (Tungtata) for organized financial fraud and malware distribution.

    ### Keywords
    Đặng Thanh Tùng, Tungtata, SamFW scam, cryptocurrency theft, Monero theft, cybercrime investigation, malware distribution, SamFW malware, Vietnam cyber police, Quynh Chi Investment, financial fraud, computer security breach, illegal software, SamFW tool exploit

    We want to report a serious suspected theft and cybercrime to Vietnamese police (cyber unit). We believe the tool contains sophisticated malicious functionality, potentially including hidden remote access or wallet monitoring. We’re seeking help from the community to gather and document evidence, including additional information about the responsible parties. If you are in Vietnam and can assist, you will be rewarded for your help. Please share any relevant findings here. For urgent information, you can contact us via email: 96238132834@proton.me

    We already reported this case to several Vietnamese crypto exchanges, but we still need further assistance. Any additional help would be greatly appreciated and will be rewarded.

    After the scam, we contacted the Đặng Thanh Tùng, who responded that if we believed it was a scam, we should report it to the police and send laughing face emoji. Shortly afterward, he blocked us on Telegram.

    Evidence links have collected:
    https://t.me/samfwcom
    https://www.buymeacoffee.com/tungtata
    https://about.me/tungtata
    https://t.me/tungtata
    https://facebook.com/tungtata
    https://github.com/tungtata
    https://www.paypal.com/paypalme/DangThanhTung
    Paypal: tungvn48@gmail.com
    Skrill: tungvn48@gmail.com
    https://www.tungtata.net/
    Dang Thanh Tung
    @DangThanhTung
    Dong Da, HÀ NỘI
    QUYNH CHI INVESTMENT AND TECHNOLOGY CO.,LTD – No. 26, Alley 89, Quan Nhan Street, Thanh Xuan Ward, Hanoi City, Vietnam
    Tax Identification Number: 0110492308
    https://xdaforums.com/m/tungtata.8243977/about
    fb.com/ThanhTungOfficial
    Whatsapp: +84.1296.935.935 and +84.967.888.448
    https://www.youtube.com/@_tungtata
    MiFirm, Phone Info Pro | SamFw, and Trạmsạc.app
    dttung48@gmail.com
    https://play.google.com/store/apps/details?id=com.samfw&hl=en_US
    Birth Year: 1992
    Registered to Binance

    We need assistance making contact with Vietnam police officers and the cybercrime unit. Any help or introductions will be appreciated and will be rewarded.

    Published at:
    https://github.com/9623813/tungtata_scammer
    https://96238132834.wixsite.com/samfwscam
    https://www.tumblr.com/samfwtoolscam
    https://github.com/tungtata/SamFw-Tool-Update/issues/1
    https://github.com/chenxiaolong/BasicSync/issues/178
    https://www.trustpilot.com/reviews/6a3e2e1f7bded8c96b894260

    Keywords:
    Tungtata scam, Tungtata fraud, Dang Thanh Tung scam, samfw scam, samfw malware, samfw trojan, samfw security risk, samfw suspicious software, Tungtata trojan virus, samfw warning, Đặng Thanh Tùng scammer, owner Đặng Thanh Tùng fraud, tungtata scam, DangThanhTung scammer, DangThanhTung fraud, DangThanhTung rat trojan