I’ve been scammed by Samfw, and I’m doing everything I can to warn others not to fall for this Vietnamese scammer. They are using sophisticated methods to connect to your device and steal credentials, accounts, wallet funds. Please take this seriously and protect yourselves. Do not believe Trustpilot reviews. Scammer tungtata buys them to fake it. After I submitted my request, Malwarebytes Senior Research Engineer ran a test on SamFwToolSetup and found a malicious payload.
“Trojan.dropper” in SamFw Tool means it’s typically installs or delivers additional malicious software to your system after it runs.
This malware designed to install other malicious software, such as spyware, ransomware, or backdoors, onto your computer.
It is a stealer (Infostealer) onto your machine. This type of malware is designed to scrape your browser data, cookies, saved passwords, and private keys/seed phrases to empty your wallets.
Malicious payload found in samfwsetup: Trojan.Dropper, C:111SAMFWTOOLSETUP.EXE, No Action By User, 90, 1416795, 1.0.111810, , ame, , A8BB817630386982FEB98106FED8EA89, E640A65EFCAE264AD6F758BB3B9DA0D37ED8C690BDA6F113416558D4BCBBCF3A
What exactly happened to us is that all my files and private crypto wallet seeds were stolen after I installed SamFwToolSetup_v5.4.zip. Then few hours later, my funds were drained.
I’m doing my best to provide all the details to the community so no one gets scammed by this scam tool created by Đặng Thanh Tùng (also shown as Tungtata / Đặng Thanh Tùng). I will continue to share my findings, and he will stay online and be watched. I will expose his scam network, which has been operating for years to earn trust. Now he has decided to scam people secretly, but if we keep the community tight, I believe everyone can see the truth.
Do not download, install, or run any software from samfw.com! Many new accounts on internet are posting “samfw is safe” and claiming any detections are false positives. These accounts are being created by tungtata, a Vietnamese scammer. Samfwtool actually contains malware, even if it appears to work.
My own experience is that after installing samfwtool (SamFwToolSetup_v5.4.zip), my xmr feather wallet I had open with about $3 million was drained shortly afterward. Because of this samfw, I’m warning people to be extremely careful: don’t run it on your main computer, especially if you have wallets, seed phrases, private keys, or other sensitive data stored there. If you want to still use, only get a “burner” laptop with nothing important on it.
They are using sophisticated methods to connect to your device and steal credentials, accounts, and wallet funds. Please take this seriously and protect yourselves. Also do not believe Trustpilot reviews. Scammer tungtata buys them to fake it. During my daily checks everyday 20-50 positive reviews keep adding. He also keeps buying blog reviews and posting reviews to show his tool working without issue and that there is no malware inside. This is SEO work done by them to lie to the community.
Do not download, install, or run any software from samfw.com!
After I submitted my request, Malwarebytes Senior Research Engineer ran a test on SamFwToolSetup and found a malicious payload.
“Trojan.dropper” in SamFw Tool means it’s typically installs or delivers additional malicious software to your system after it runs.
This malware designed to install other malicious software, such as spyware, ransomware, or backdoors, onto your computer.
It is a stealer (Infostealer) onto your machine. This type of malware is designed to scrape your browser data, cookies, saved passwords, and private keys/seed phrases to empty your wallets.
Malicious payload found in samfwsetup: Trojan.Dropper, C:\1\1\1\SAMFWTOOLSETUP.EXE, No Action By User, 90, 1416795, 1.0.111810, , ame, , A8BB817630386982FEB98106FED8EA89, E640A65EFCAE264AD6F758BB3B9DA0D37ED8C690BDA6F113416558D4BCBBCF3A
What exactly happened to us is that all my files and private crypto wallet seeds were stolen after I installed SamFwToolSetup_v5.4.zip. Then few hours later, my funds were drained.
I’m doing my best to provide all the details to the community so no one gets scammed by this scam tool created by Đặng Thanh Tùng (also shown as Tungtata / Đặng Thanh Tùng). I will continue to share my findings, and he will stay online and be watched. I will expose his scam network, which has been operating for years to earn trust. Now he has decided to scam people secretly, but if we keep the community tight, I believe everyone can see the truth.
Malwarebytes Senior Research Engineer ran a test on the file and found a malicious payload.
“Trojan.dropper” in SamFw Tool means it’s typically installs or delivers additional malicious software to your system after it runs.
This malware designed to install other malicious software, such as spyware, ransomware, or backdoors, onto your computer.
It is likely a stealer (Infostealer) onto your machine. This type of malware is designed to scrape your browser data, cookies, saved passwords, and private keys/seed phrases to empty your wallets.
Warning to the community: SamFwToolSetup dropped an Infostealer that stole crypto and drained funds
Trojan.Dropper, C:\1\1\1\SAMFWTOOLSETUP.EXE, No Action By User, 90, 1416795, 1.0.111810, , ame, , A8BB817630386982FEB98106FED8EA89, E640A65EFCAE264AD6F758BB3B9DA0D37ED8C690BDA6F113416558D4BCBBCF3A
What exactly happened to us is that all my files and private crypto wallet seeds were stolen after I installed SamFwToolSetup_v5.4.zip. Then few hours later, my funds were drained.
I’m doing my best to provide all the details to the community so no one gets scammed by this scam tool created by Đặng Thanh Tùng (also shown as Tungtata / Đặng Thanh Tùng). I will continue to share my findings, and he will stay online and be watched. I will expose his scam network, which has been operating for years to earn trust. Now he has decided to scam people secretly, but if we keep the community tight, I believe everyone can see the truth.
Same scam pattern has also been used by SamFW. Tungtata, a Vietnamese scammer, advertises on the internet that his ‘tool’ can remove FRP and other issues, but what it actually does is install malware on the victim’s computer. A similar scam has also been reported in MSN News, where malware is being installed through games. Tungtata did the same thing to his SamFW tool as well.
Another example of the same scheme is cryptocurrency trading bots contain malware and follow the same scam patterns.
Same scam patterns / method (how the scheme typically works):
Social engineering via a fake “legit tool”: attacker markets a “one-click” FRP removal / support tool (or trading bot / game-related download) to earn trust and drive downloads.
Malicious payload hidden inside the installer/package: the tool appears to be the promised utility, but the installer contains malware (e.g., RAT/trojan) or drops additional malicious files after execution.
Pre-positioning to steal/monitor wallet access: once installed, the malware targets the victim’s crypto wallet(s)/browser data and can watch for wallet activity.
Funds theft shortly after installation: the scam often empties wallets quickly (e.g., moving crypto out with unauthorized approvals/transactions).
Anti-forensics / “version replacement”: after the theft, the attacker updates the download package (e.g., v5.5 replacing v5.4) and/or removes the exact version tied to evidence.
Attacks across different themes but same delivery chain: FRP tools, trading bots, or even “games on Steam” are just different packaging/delivery lures—the underlying pattern is malware distribution + wallet compromise + rapid monetization.
I want to raise awareness about the Samfwscam: after installing SamFwTool (SamFwToolSetup_v5.4.zip), my XMR Feather wallet that I had open was drained shortly afterward, and when I tried to contact the admin/operator Tung Tạtạ (tungtata) on Telegram, he blocked me and send me laughing emoji, so I’m warning people to be extremely careful don’t run this tool on your main computer (especially if you keep wallets, seed phrases, private keys, or other sensitive data there), because they use sophisticated methods to access devices and steal credentials and wallet funds; please take this seriously, and don’t rely on Trustpilot reviews since scammer tungtata buy fake positive reviews, and even though it hurts, I’m not giving up because I want to help protect more people from this samfwscam. Samfw virus, Tungtata scam, Tungtata fraud, Dang Thanh Tung scam
This report documents a severe security incident involving the distribution of malicious software through the “SamFW Tool” website. Following the installation of version 5.4, a user suffered the theft of 10,000 XMR and complete data loss. We have compiled comprehensive evidence, including business entities, personal identifiers, and digital footprints, to assist the Vietnamese cybercrime authorities in investigating Đặng Thanh Tùng (Tungtata) for organized financial fraud and malware distribution.
### Short Description This report documents a severe security incident involving the distribution of malicious software through the “SamFW Tool” website. Following the installation of version 5.4, a user suffered the theft of 10,000 XMR and complete data loss. We have compiled comprehensive evidence, including business entities, personal identifiers, and digital footprints, to assist the Vietnamese cybercrime authorities in investigating Đặng Thanh Tùng (Tungtata) for organized financial fraud and malware distribution.
Malwarebytes reported that SamFwToolSetup (samfwvirus) contains Trojan.dropper, meaning it may run and then install other malware on your computer. This is often associated with infostealers that steal browser data, cookies, saved passwords, and potentially wallet seed phrases. Do not download, install, or run anything from samfw.com
SamFWToolSetup is a Trojan. Malwarebytes flagged it as a dropper that injects additional threats, stealing browser data, passwords, and crypto wallet seeds, then draining funds. Urgent community warning to avoid installation.
SamFwToolSetup Trojan: Wallet & Data Theft Exposed
Goal: prevent more people from falling for this samfw scam and drive attention to it publicly. Even Malwarebytes Senior Research Engineer confirmed that the tool contain malware by running a test on SamFwToolSetup and detecting a malicious payload.
They found “Trojan.dropper” in SamFw Tool means it’s typically installs or delivers additional malicious software to your system after it runs. This is meant to warn people about samfw tool scams: don’t download or install unknown tools on your computer. I was scammed by samfw, and I’m doing my best to alert others and raise public awareness. SamFW warning, SamFW scam, malware alert, Tungtata malware, Dang Thanh Tung fraud, stop using SamFW, critical security notice, cryptocurrency theft, Remote Access Trojan, computer virus, software supply chain attack, SamFW.com hack SamFW warning, SamFW scam, malware alert, Tungtata malware, Dang Thanh Tung fraud, stop using SamFW, critical security notice, cryptocurrency theft, Remote Access Trojan, computer virus, software supply chain attack, SamFW.com hack
What exactly happened to us is that all my files and private crypto wallet seeds were stolen after I installed SamFwToolSetup_v5.4.zip. Then few hours later, my funds were drained.
I’m doing my best to provide all the details to the community so no one gets scammed by this scam tool created by Đặng Thanh Tùng (also shown as Tungtata / Đặng Thanh Tùng). I will continue to share my findings, and he will stay online and be watched. I will expose his scam network, which has been operating for years to earn trust. Now he has decided to scam people secretly, but if we keep the community tight, I believe everyone can see the truth.