<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[DarkSignal: Cyber-Crime Arena]]></title><description><![CDATA[Tracking the evolving underground of digital threats, from malware markets to ransomware actors, and covert networks driving the cyber underworld.]]></description><link>https://www.darksignal.co/s/cyber-crime-arena</link><image><url>https://substackcdn.com/image/fetch/$s_!ztRX!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf96a1f2-8ab6-4995-a09e-591568a9a496_1024x1024.png</url><title>DarkSignal: Cyber-Crime Arena</title><link>https://www.darksignal.co/s/cyber-crime-arena</link></image><generator>Substack</generator><lastBuildDate>Sat, 11 Apr 2026 07:56:32 GMT</lastBuildDate><atom:link href="https://www.darksignal.co/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[DarkSignal]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[admin@darksignal.co]]></webMaster><itunes:owner><itunes:email><![CDATA[admin@darksignal.co]]></itunes:email><itunes:name><![CDATA[DarkSignal]]></itunes:name></itunes:owner><itunes:author><![CDATA[DarkSignal]]></itunes:author><googleplay:owner><![CDATA[admin@darksignal.co]]></googleplay:owner><googleplay:email><![CDATA[admin@darksignal.co]]></googleplay:email><googleplay:author><![CDATA[DarkSignal]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[When Nemesis Met His Own Nemesis: The Fall of One of the Dark Web’s Largest Marketplaces]]></title><description><![CDATA[Nemesis: A Dark Web Giant Built on Drugs, Fraud, and Ransomware]]></description><link>https://www.darksignal.co/p/when-nemesis-met-his-own-nemesis</link><guid isPermaLink="false">https://www.darksignal.co/p/when-nemesis-met-his-own-nemesis</guid><dc:creator><![CDATA[DarkSignal]]></dc:creator><pubDate>Thu, 13 Nov 2025 08:46:31 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!FaUh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0fc54e32-7129-4797-8e6c-4fcce247e684_720x717.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!FaUh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0fc54e32-7129-4797-8e6c-4fcce247e684_720x717.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!FaUh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0fc54e32-7129-4797-8e6c-4fcce247e684_720x717.jpeg 424w, https://substackcdn.com/image/fetch/$s_!FaUh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0fc54e32-7129-4797-8e6c-4fcce247e684_720x717.jpeg 848w, https://substackcdn.com/image/fetch/$s_!FaUh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0fc54e32-7129-4797-8e6c-4fcce247e684_720x717.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!FaUh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0fc54e32-7129-4797-8e6c-4fcce247e684_720x717.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!FaUh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0fc54e32-7129-4797-8e6c-4fcce247e684_720x717.jpeg" width="720" height="717" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0fc54e32-7129-4797-8e6c-4fcce247e684_720x717.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:717,&quot;width&quot;:720,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:42092,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/178773057?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0fc54e32-7129-4797-8e6c-4fcce247e684_720x717.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!FaUh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0fc54e32-7129-4797-8e6c-4fcce247e684_720x717.jpeg 424w, https://substackcdn.com/image/fetch/$s_!FaUh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0fc54e32-7129-4797-8e6c-4fcce247e684_720x717.jpeg 848w, https://substackcdn.com/image/fetch/$s_!FaUh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0fc54e32-7129-4797-8e6c-4fcce247e684_720x717.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!FaUh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0fc54e32-7129-4797-8e6c-4fcce247e684_720x717.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>Nemesis: A Dark Web Giant Built on Drugs, Fraud, and Ransomware</strong></h3><p>Nemesis was one of the most recognizable darknet marketplaces, launched in 2021 and serving as a major hub for trading drugs (including fentanyl and synthetic opioids), stolen data, forged documents, ransomware, and DDoS services.<br>At its peak, Nemesis reached over 150,000 active users and more than 1,100 vendors, many of them based in Germany.<br>In narcotics alone, the platform surpassed 30 million dollars in revenue.</p><p>Nemesis incorporated several mechanisms designed to obscure the origin and destination of funds, making financial tracking extremely difficult.<br>These included built-in mixing services to blend transactions, multi-signature payments for added security and complexity, and internal crypto conversion options, all of which contributed to a thick veil of anonymity around every deal.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.darksignal.co/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h3><strong>The Iranian Operator Behind the Marketplace</strong></h3><p>The owner of Nemesis, Behrouz Prasad, an Iranian national, collected a commission from every transaction and maintained full control over the platform and its wallets.<br>He went even further by offering dedicated crypto laundering services to drug traffickers and cybercriminals who relied on Nemesis as part of their wider operations.</p><p>A joint intelligence operation involving Germany, Lithuania, and the United States gathered extensive intelligence that eventually led to the discovery sealing Prasad&#8217;s fate.</p><h3><strong>The OPSEC Mistake That Exposed Everything</strong></h3><p>An OSINT investigation uncovered a critical link.<br>Prasad used identical passwords on two unrelated services: the Bitfinex cryptocurrency exchange, where wallet addresses tied to Nemesis operated, and the administrator account on Nemesis itself.</p><p>Matching passwords across accounts is common, but when the password is as unusual as &#8220;behrouP.3456abCdeFj&#8221;, it becomes a flashing red warning sign for any experienced investigator.</p><p>Further analysis using blockchain tracing platforms exposed IP addresses and usernames belonging to Prasad, who had committed one of the most classic OPSEC failures in cybercrime: password reuse.</p><p>The pile of evidence grew until, on March 20, 2024, special forces from multiple intelligence agencies raided his home and arrested him.<br>All Nemesis servers were seized in the operation.</p><p>Following the arrest and the evidence discovered, the US Department of the Treasury imposed sanctions on Prasad, including full asset seizure in the United States and a complete prohibition on any business or financial dealings with him.</p><h3><strong>DarkSignal&#8217;s Closing Thoughts</strong></h3><p>Time and time again, we see major operators who run multimillion-dollar criminal infrastructures, violate federal laws, and risk decades in prison, ultimately falling because of a simple OPSEC slip.<br>Intelligence agencies count on these mistakes, just as they did with Ross Ulbricht, with Prasad, and with many others.</p><p>Who will make the next mistake?</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.darksignal.co/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Black Basta Shuts Down: Internal Leaks, Betrayal, and the Fall of a Major Ransomware Empire]]></title><description><![CDATA[A Leading RaaS Operation Collapses in Chaos]]></description><link>https://www.darksignal.co/p/black-basta-shuts-down-internal-leaks</link><guid isPermaLink="false">https://www.darksignal.co/p/black-basta-shuts-down-internal-leaks</guid><dc:creator><![CDATA[DarkSignal]]></dc:creator><pubDate>Thu, 13 Nov 2025 08:43:51 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!-_VR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Facfec10a-1fe6-4fba-afa8-60279dc4265b_800x800.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-_VR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Facfec10a-1fe6-4fba-afa8-60279dc4265b_800x800.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-_VR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Facfec10a-1fe6-4fba-afa8-60279dc4265b_800x800.jpeg 424w, https://substackcdn.com/image/fetch/$s_!-_VR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Facfec10a-1fe6-4fba-afa8-60279dc4265b_800x800.jpeg 848w, https://substackcdn.com/image/fetch/$s_!-_VR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Facfec10a-1fe6-4fba-afa8-60279dc4265b_800x800.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!-_VR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Facfec10a-1fe6-4fba-afa8-60279dc4265b_800x800.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-_VR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Facfec10a-1fe6-4fba-afa8-60279dc4265b_800x800.jpeg" width="800" height="800" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/acfec10a-1fe6-4fba-afa8-60279dc4265b_800x800.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:800,&quot;width&quot;:800,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:153047,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/178772951?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Facfec10a-1fe6-4fba-afa8-60279dc4265b_800x800.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-_VR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Facfec10a-1fe6-4fba-afa8-60279dc4265b_800x800.jpeg 424w, https://substackcdn.com/image/fetch/$s_!-_VR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Facfec10a-1fe6-4fba-afa8-60279dc4265b_800x800.jpeg 848w, https://substackcdn.com/image/fetch/$s_!-_VR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Facfec10a-1fe6-4fba-afa8-60279dc4265b_800x800.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!-_VR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Facfec10a-1fe6-4fba-afa8-60279dc4265b_800x800.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>A Leading RaaS Operation Collapses in Chaos</strong></h3><p>One of the most well-known RaaS (Ransomware as a Service) groups in the cybercrime ecosystem, operating under the name Black Basta and first appearing in April 2022, is dramatically closing its doors.<br>The group hit high-profile companies in the United States and Germany in sectors such as real estate, retail, and healthcare, earning hundreds of millions of dollars through its signature attack method that became widely adopted among other ransomware crews: double extortion.</p><p>Black Basta, founded in 2022 and suspiciously soon after the shutdown of the Conti group, would encrypt a victim&#8217;s data and simultaneously threaten to leak stolen sensitive information.<br>This created a situation where victims faced not only operational disruption and data loss, but also severe reputational and financial damage, since leaked information could embarrass companies and expose them to competitive or regulatory risk.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.darksignal.co/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h3><strong>Massive Internal Leak Shakes the Group</strong></h3><p>In February 2025, tens of thousands of internal chats leaked from within the group.<br>Hundreds of thousands of messages revealed internal conflicts, disputes between members, debates about techniques, and discussions on new tactics.</p><p>The source of the leak remains unclear, but it likely stemmed from internal tensions after some members pushed to begin attacking financial institutions in Russia, a controversial decision that created significant internal friction.</p><p>As of now, no arrests or confirmed law enforcement actions have been announced, but the sheer amount of raw intelligence now in investigators&#8217; hands is enormous.<br>The leaks include social engineering templates, crypto wallet addresses, tactical discussions about victims, nearly 400 ZoomInfo links (likely representing potential future targets), and even the identities of some of the group&#8217;s top figures, including Lapa, one of the leaders, and Trump, who allegedly managed the operation.</p><h3><strong>A Glimpse Into the Organization&#8217;s Structure</strong></h3><p>Members include a 17-year-old minor, expert social engineers tasked with identifying key personnel in victim organizations and initiating phone-based contact, and research and exploitation specialists who focused heavily on VPN vulnerabilities, a technique the group used extensively.</p><p>All victims were managed in a shared spreadsheet, with precise records documenting who was targeted, how, who was contacted, why, and with which method.<br>It mirrored a corporate sales and CRM workflow, only adapted for criminal operations.</p><p>Some of the group&#8217;s affiliates are now taking advantage of the chaos and betrayals.<br>They attack victims with ransomware, receive payment, and then refuse to provide decryption keys, exploiting the collapse for personal gain.</p><p>This type of behavior is uncharacteristic of the original group, which typically adhered to its own internal code of &#8220;honor&#8221; and provided decryption keys once ransom payments were received.</p><h3><strong>The End of Black Basta, but Not the End of Its Members</strong></h3><p>The group&#8217;s operation may be over, but it is entirely possible that its core members, united by shared motivation and experience, will regroup under a new name.<br>This particular market stall has closed, but the marketplace is still full.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.darksignal.co/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The Operation That Began by Accident and Changed the Criminal World Forever]]></title><description><![CDATA[Criminal Groups Flee Telegram and Search for a New Home]]></description><link>https://www.darksignal.co/p/the-operation-that-began-by-accident</link><guid isPermaLink="false">https://www.darksignal.co/p/the-operation-that-began-by-accident</guid><dc:creator><![CDATA[DarkSignal]]></dc:creator><pubDate>Thu, 13 Nov 2025 08:41:48 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!pPiC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77cdd923-54f0-4901-9a33-9d969f808608_529x699.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!pPiC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77cdd923-54f0-4901-9a33-9d969f808608_529x699.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!pPiC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77cdd923-54f0-4901-9a33-9d969f808608_529x699.jpeg 424w, https://substackcdn.com/image/fetch/$s_!pPiC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77cdd923-54f0-4901-9a33-9d969f808608_529x699.jpeg 848w, https://substackcdn.com/image/fetch/$s_!pPiC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77cdd923-54f0-4901-9a33-9d969f808608_529x699.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!pPiC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77cdd923-54f0-4901-9a33-9d969f808608_529x699.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!pPiC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77cdd923-54f0-4901-9a33-9d969f808608_529x699.jpeg" width="529" height="699" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/77cdd923-54f0-4901-9a33-9d969f808608_529x699.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:699,&quot;width&quot;:529,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:16534,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/178772829?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77cdd923-54f0-4901-9a33-9d969f808608_529x699.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!pPiC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77cdd923-54f0-4901-9a33-9d969f808608_529x699.jpeg 424w, https://substackcdn.com/image/fetch/$s_!pPiC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77cdd923-54f0-4901-9a33-9d969f808608_529x699.jpeg 848w, https://substackcdn.com/image/fetch/$s_!pPiC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77cdd923-54f0-4901-9a33-9d969f808608_529x699.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!pPiC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77cdd923-54f0-4901-9a33-9d969f808608_529x699.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>Criminal Groups Flee Telegram and Search for a New Home</strong></h3><p>After the arrest of Pavel Durov, founder of Telegram, criminal and espionage groups worldwide announced they were abandoning the platform, claiming it was no longer secure and that Durov was now cooperating with law enforcement.<br>An alternative had not yet been chosen, but several messaging apps offered similar capabilities relying on pseudo-anonymity or full anonymity.<br>The real question was simple: who is actually behind these alternative platforms?</p><h3><strong>Phantom Secure: The Prequel to a Global Trap</strong></h3><p>In 2016, a Canadian company called Phantom Secure made headlines. It produced customized mobile phones with advanced encryption, marketed as a solution for secure communication.<br>Heavy criminal organizations around the world relied on Phantom Secure to run massive money laundering operations, coordinate criminal activity, and manage their enterprises below the radar.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.darksignal.co/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Authorities did not appreciate this.<br>In 2018, Vincent Ramos, the company&#8217;s founder, was arrested and pressured to install a backdoor in the devices. He refused and was sentenced to nine years in prison.<br>But for law enforcement, that wasn&#8217;t enough.</p><h3><strong>AN0M: The FBI Plants a Trojan Horse in the Criminal Underworld</strong></h3><p>The FBI seized the opportunity created by Phantom Secure&#8217;s shutdown and the vacuum left among criminals.<br>Working with the Australian Federal Police, they built a new encrypted communication app called AN0M.</p><p>The app was marketed as an ultra-secure messaging platform that ran exclusively on modified smartphones stripped of all standard apps, including calling and email functions.<br>Anyone wishing to communicate with another user had to supply that person with a dedicated AN0M device, which significantly boosted trust between criminals.</p><p>The encryption was completely real, intentionally so, because faking it could have exposed the entire operation.<br>But every message sent through AN0M was secretly forwarded to law enforcement.<br>Each message was also tagged with precise geolocation data, allowing full intelligence coverage and real-time tracking of users.</p><h3><strong>A Window Into Global Organized Crime</strong></h3><p>Through AN0M, authorities infiltrated the criminal underworld at an unprecedented level.<br>They monitored more than 12,000 devices across 300 crime groups in over 100 countries.<br>They documented massive international drug trafficking operations, intercontinental weapons deals, plots to commit murder, human trafficking networks, and distribution of CSAM.</p><p>Users had no idea they were operating inside one of the most sophisticated honeypots ever deployed.</p><p>In 2021, the FBI announced Operation Trojan Shield, resulting in the arrest of more than 800 criminals worldwide, including senior members of organized crime groups in Australia, Europe, and South Africa.</p><p>After the operation was exposed, many AN0M users tried to destroy their devices, but the years of accumulated intelligence allowed authorities to continue making arrests and seize enormous quantities of evidence.</p><h3><strong>One Accidental Operation, Hundreds of Arrests, and Millions in Seizures</strong></h3><p>The operation ultimately led to the arrest of around 800 criminals across 18 countries.<br>Authorities seized more than 40 tons of cocaine, cannabis, and meth, 250 weapons, gold bars, hundreds of luxury vehicles, and nearly 48 million dollars in cash.</p><p>Even when criminal groups feel pressured to abandon a platform they trusted for years, the choice of replacement can reshape the entire landscape.<br>You never truly know who is behind the next &#8220;secure&#8221; app or where it will eventually lead.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.darksignal.co/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Helix: The Bitcoin Mixer That Became One of the Largest Money-Laundering Machines Ever Built]]></title><description><![CDATA[A Bedroom Project That Exploited Bitcoin&#8217;s Biggest Weakness]]></description><link>https://www.darksignal.co/p/helix-the-bitcoin-mixer-that-became</link><guid isPermaLink="false">https://www.darksignal.co/p/helix-the-bitcoin-mixer-that-became</guid><dc:creator><![CDATA[DarkSignal]]></dc:creator><pubDate>Thu, 13 Nov 2025 08:38:53 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!miIa!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa5dcb82-0327-478e-bdcc-e5b79248bdf4_1200x630.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!miIa!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa5dcb82-0327-478e-bdcc-e5b79248bdf4_1200x630.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!miIa!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa5dcb82-0327-478e-bdcc-e5b79248bdf4_1200x630.jpeg 424w, https://substackcdn.com/image/fetch/$s_!miIa!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa5dcb82-0327-478e-bdcc-e5b79248bdf4_1200x630.jpeg 848w, https://substackcdn.com/image/fetch/$s_!miIa!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa5dcb82-0327-478e-bdcc-e5b79248bdf4_1200x630.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!miIa!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa5dcb82-0327-478e-bdcc-e5b79248bdf4_1200x630.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!miIa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa5dcb82-0327-478e-bdcc-e5b79248bdf4_1200x630.jpeg" width="1200" height="630" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/aa5dcb82-0327-478e-bdcc-e5b79248bdf4_1200x630.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:630,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:133085,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/178772570?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa5dcb82-0327-478e-bdcc-e5b79248bdf4_1200x630.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!miIa!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa5dcb82-0327-478e-bdcc-e5b79248bdf4_1200x630.jpeg 424w, https://substackcdn.com/image/fetch/$s_!miIa!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa5dcb82-0327-478e-bdcc-e5b79248bdf4_1200x630.jpeg 848w, https://substackcdn.com/image/fetch/$s_!miIa!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa5dcb82-0327-478e-bdcc-e5b79248bdf4_1200x630.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!miIa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa5dcb82-0327-478e-bdcc-e5b79248bdf4_1200x630.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>A Bedroom Project That Exploited Bitcoin&#8217;s Biggest Weakness</strong></h3><p>It wasn&#8217;t an earring. It was one of the largest money laundering operations ever created.</p><p>In 2014, a few years after Bitcoin began gaining mainstream traction, a young man named Larry Harmon noticed a major problem in the ecosystem and a growing need among users.<br>People wanted privacy and sought ways to stay out of sight from governments and law enforcement, who increasingly wanted visibility into everything.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.darksignal.co/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Driven by the belief that people deserve privacy, even regarding their digital wallets, Larry built Helix in his bedroom.<br>Helix became the largest Bitcoin mixer of its time, a service designed to turn &#8220;dirty&#8221; cryptocurrency into &#8220;clean&#8221; coins by passing them through a vast network of anonymous wallets.<br>In exchange, the mixer took a small fee based on transaction size or risk level.</p><p>Since Bitcoin operates on the blockchain, which records every transaction ever made and allows anyone to download and analyze the ledger, each coin effectively has a unique digital fingerprint.<br>This means that, in theory, Bitcoin can be traced back to real individuals if needed.</p><p>Helix was built to break that trace.<br>No matter how questionable the money&#8217;s origin was, the mixer&#8217;s goal was to erase the financial trail and destroy any hope of linking funds back to their real source.</p><h3><strong>How Helix Worked Behind the Scenes</strong></h3><ul><li><p>User A sends their Bitcoin to the mixer&#8217;s wallet.</p></li><li><p>Helix breaks the coins into tiny fragments and blends them with countless clean transactions from other users on the network.</p></li><li><p>After the mixing cycle, Helix returns fresh coins to User A&#8217;s wallet, minus the agreed-upon service fee.</p></li></ul><p>This service became essential among criminals, darknet vendors, and intelligence operatives worldwide.<br>Larry marketed Helix across major darknet marketplaces such as Agora Market, AlphaBay, and Dream Market, all of which dealt with global-scale criminal activity.</p><p>Helix began to explode in popularity. At its peak, it laundered more than 300 million dollars. That&#8217;s when things started to fall apart.</p><h3><strong>A Global Investigation and a Sudden Fall</strong></h3><p>In February 2020, authorities launched a secret operation to identify and arrest Larry.<br>Inside his home, agents found hardware wallets storing large amounts of cryptocurrency and even a Google Drive spreadsheet showing ownership of over 56 million dollars in Bitcoin and other assets.</p><p>Larry argued that he was merely a service provider and could not be responsible for the actions of users he had never met.<br>But the defense didn&#8217;t hold.<br>Authorities charged him with facilitating global-scale criminal activity and laundering massive amounts of money.</p><h3><strong>Twenty Years, Millions in Fines, and a Deal on the Table</strong></h3><p>Larry pled guilty in 2021.<br>He received a 20-year prison sentence, a 60 million dollar fine, and forfeiture of roughly 4,400 Bitcoin he had earned as fees.</p><p>After delivering the stick, authorities also offered the carrot.<br>If Larry chose to cooperate, expose operators of other mixing services, and provide intelligence on criminals, he could earn back his freedom.</p><p>At the end of the day, it&#8217;s all business. Nothing personal.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.darksignal.co/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Operation Shipwrecked: The Takedown of PopeyeTools and a Decade of Digital Credit-Card Crime]]></title><description><![CDATA[A Joint Blow by the US Department of Justice and the UK&#8217;s NCA]]></description><link>https://www.darksignal.co/p/operation-shipwrecked-the-takedown</link><guid isPermaLink="false">https://www.darksignal.co/p/operation-shipwrecked-the-takedown</guid><dc:creator><![CDATA[DarkSignal]]></dc:creator><pubDate>Thu, 13 Nov 2025 08:33:17 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!WZEA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58de1002-2eca-4c8f-9b28-eba57ac571f0_712x400.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!WZEA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58de1002-2eca-4c8f-9b28-eba57ac571f0_712x400.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!WZEA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58de1002-2eca-4c8f-9b28-eba57ac571f0_712x400.jpeg 424w, https://substackcdn.com/image/fetch/$s_!WZEA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58de1002-2eca-4c8f-9b28-eba57ac571f0_712x400.jpeg 848w, https://substackcdn.com/image/fetch/$s_!WZEA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58de1002-2eca-4c8f-9b28-eba57ac571f0_712x400.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!WZEA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58de1002-2eca-4c8f-9b28-eba57ac571f0_712x400.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!WZEA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58de1002-2eca-4c8f-9b28-eba57ac571f0_712x400.jpeg" width="712" height="400" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/58de1002-2eca-4c8f-9b28-eba57ac571f0_712x400.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:400,&quot;width&quot;:712,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:50353,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/178772430?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58de1002-2eca-4c8f-9b28-eba57ac571f0_712x400.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!WZEA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58de1002-2eca-4c8f-9b28-eba57ac571f0_712x400.jpeg 424w, https://substackcdn.com/image/fetch/$s_!WZEA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58de1002-2eca-4c8f-9b28-eba57ac571f0_712x400.jpeg 848w, https://substackcdn.com/image/fetch/$s_!WZEA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58de1002-2eca-4c8f-9b28-eba57ac571f0_712x400.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!WZEA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58de1002-2eca-4c8f-9b28-eba57ac571f0_712x400.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>A Joint Blow by the US Department of Justice and the UK&#8217;s NCA</strong></h3><p>The US Department of Justice and the UK&#8217;s National Crime Agency announced a coordinated raid and shutdown of a major underground marketplace known as PopeyeTools, as part of an international effort called Operation Shipwrecked.</p><p>PopeyeTools operated within a specific cybercrime niche known as carding, which centers on financial fraud.<br>The forum specialized in forged credit cards, detailed guides for cloning and fabricating card data, hardware for stealing card information (commonly known as skimmers), discussions and tutorials, and even the sale of ransomware tools and related malicious code.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.darksignal.co/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h3><strong>Three Operators, One Decade of Fraud</strong></h3><p>Three men, ages 25 to 37, all originating from Pakistan, were identified as the operators of the site. They now face charges involving computer fraud, financial crime, and cyber offenses, and could receive up to 10 years in federal prison if convicted.</p><p>Authorities seized three domains that had long served as gateways to the forum:<br><code>popeyetools[.]com<br>popeyetools[.]co.uk<br>popeyetools[.]to</code></p><p>These domains supported the platform for many years, allowing access to a marketplace that became a central hub for trading stolen financial data and credit cards.</p><p>For nearly a decade, the forum served hundreds of thousands of cybercriminals around the world. Many were involved in ransomware operations, extortion, and large-scale credit card theft or forgery.<br>Among the data sold were bank account numbers, credit and debit card numbers, identity documents, full PII records, and other sensitive information belonging to victims worldwide, many of whom had no idea their details were circulating in criminal markets.</p><h3><strong>A Marketplace Thriving on &#8220;Quality&#8221; Crime</strong></h3><p>The site became widely popular and generated millions of dollars due to the perceived reliability of its vendors.<br>Ironically, despite operating a criminal marketplace, PopeyeTools enforced a refund policy for invalid card data or unusable information.<br>The operators promoted their motto proudly: &#8220;We Believe in Quality, Not Quantity.&#8221;</p><p>Beyond the domain seizures and the shutdown of the entire marketplace, authorities also confiscated over 300,000 dollars worth of cryptocurrency from an account controlled by one of the operators.</p><h3><strong>Another Round in the Cat and Mouse Game</strong></h3><p>This is not the first, and certainly not the last, time that law enforcement agencies announce raids against darknet forums and cybercrime communities.<br>It is a continuous game of cat and mouse, with both sides improving their capabilities and vast sums of money at stake.</p><p>So the real question remains: who is faster and smarter this time, the cat or the mouse?</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.darksignal.co/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Is the Neighbor’s Wi-Fi Really Greener? The APT Attack That Jumped Networks]]></title><description><![CDATA[A Russian APT Group Takes Creativity to a New Level]]></description><link>https://www.darksignal.co/p/is-the-neighbors-wi-fi-really-greener</link><guid isPermaLink="false">https://www.darksignal.co/p/is-the-neighbors-wi-fi-really-greener</guid><dc:creator><![CDATA[DarkSignal]]></dc:creator><pubDate>Thu, 13 Nov 2025 08:30:31 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!wWF_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e6c1c65-53de-4f6b-b4c4-51e44f9246b7_816x755.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wWF_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e6c1c65-53de-4f6b-b4c4-51e44f9246b7_816x755.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wWF_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e6c1c65-53de-4f6b-b4c4-51e44f9246b7_816x755.jpeg 424w, https://substackcdn.com/image/fetch/$s_!wWF_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e6c1c65-53de-4f6b-b4c4-51e44f9246b7_816x755.jpeg 848w, https://substackcdn.com/image/fetch/$s_!wWF_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e6c1c65-53de-4f6b-b4c4-51e44f9246b7_816x755.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!wWF_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e6c1c65-53de-4f6b-b4c4-51e44f9246b7_816x755.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wWF_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e6c1c65-53de-4f6b-b4c4-51e44f9246b7_816x755.jpeg" width="816" height="755" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4e6c1c65-53de-4f6b-b4c4-51e44f9246b7_816x755.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:755,&quot;width&quot;:816,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:244479,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/178772294?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb028ec3b-d061-43d5-931e-b3223043ba2f_816x815.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wWF_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e6c1c65-53de-4f6b-b4c4-51e44f9246b7_816x755.jpeg 424w, https://substackcdn.com/image/fetch/$s_!wWF_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e6c1c65-53de-4f6b-b4c4-51e44f9246b7_816x755.jpeg 848w, https://substackcdn.com/image/fetch/$s_!wWF_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e6c1c65-53de-4f6b-b4c4-51e44f9246b7_816x755.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!wWF_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e6c1c65-53de-4f6b-b4c4-51e44f9246b7_816x755.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>A Russian APT Group Takes Creativity to a New Level</strong></h3><p>A Russian threat group named GruesomeLarch, better known as Fancy Bear or APT28, which is widely associated with state-sponsored espionage operations, reached a new level of sophistication in an effort to infiltrate a victim&#8217;s corporate network.<br>In February 2022, shortly before Russia invaded Ukraine, the group launched an operation that gave them full access to the victim&#8217;s environment by exploiting physically nearby corporate Wi-Fi networks.<br>This technique is known as a Nearest Neighbor Attack, where attackers compromise a nearby organization first and use it as a bridge to reach their actual target.</p><h3><strong>Breaking In Through Wi-Fi and Weak Authentication</strong></h3><p>How did they do it?<br>The group used a technique known as password spraying, where attackers attempt large numbers of username and password combinations against public-facing services until a valid set of credentials is found.<br>The victim&#8217;s corporate Wi-Fi network did not require MFA, allowing connections using username and password alone.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.darksignal.co/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>After successfully obtaining valid Wi-Fi credentials, the attackers hit their first obstacle. Due to physical distance, they could not connect directly to the network.</p><p>Fancy Bear did not give up. Using pre-attack intelligence collection, they mapped all nearby companies with offices located close to the victim. They then breached those adjacent organizations.</p><p>Inside these neighboring networks, the infrastructure allowed for wired access to the internal network as well as Wi-Fi adapters that could scan for nearby wireless signals.<br>This meant the attackers could use these adapters to detect and connect to surrounding Wi-Fi networks, including the victim&#8217;s.</p><p>The group repeated the password spraying technique on the neighboring companies, obtained additional credentials, and leveraged the deployed Wi-Fi adapters to scan the area until they reached the victim&#8217;s Wi-Fi signal.<br>Using the credentials from the initial breach and access through the &#8220;middle company,&#8221; they managed to compromise the primary target, acting as if they were an ISP relaying communication between the user and the destination server.</p><h3><strong>What the Attackers Actually Did Inside the Network</strong></h3><p>The incident response team later discovered a malicious file named servtask.bat, designed to extract sensitive data from the Windows Registry and compress it into a ZIP file in an attempt to evade EDR detection.<br>The attackers also used a built-in Windows tool called cipher.exe, which enables secure deletion of files to prevent forensic recovery.</p><p>After deeper analysis, investigators identified connections to the victim and the neighboring companies coming from Wi-Fi adapters with similar MAC addresses.<br>This immediately indicated that the same operator had compromised multiple organizations in coordinated time frames, revealing both the attack method and the attribution to Russia.</p><p>Tools like GooseEgg and servtask.bat, both previously associated with APT28 operations, further strengthened the connection to the group.</p><h3><strong>A Sobering Look at Cross-Organization Espionage</strong></h3><p>This is not the first time we have heard about state-backed threat groups conducting cross-border espionage.<br>However, this case is notable because it involved innocent, unrelated &#8220;white&#8221; organizations that had no involvement with the operation or the conflict.<br>They were simply chess pieces on a board controlled by players who did not know them and did not care about the collateral damage.</p><p>It is a strong reminder of how far state-sponsored APT groups are willing to go and how creative they can become when a target is important enough.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.darksignal.co/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[When Cybercriminals Take the Bait]]></title><description><![CDATA[A Honeypot Disguised as a Hacker&#8217;s Dream Tool]]></description><link>https://www.darksignal.co/p/when-cybercriminals-take-the-bait</link><guid isPermaLink="false">https://www.darksignal.co/p/when-cybercriminals-take-the-bait</guid><dc:creator><![CDATA[DarkSignal]]></dc:creator><pubDate>Thu, 13 Nov 2025 08:27:05 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!6tfg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0edd773c-24a8-41d6-a3fd-ba267edf5a0d_1360x814.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6tfg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0edd773c-24a8-41d6-a3fd-ba267edf5a0d_1360x814.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6tfg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0edd773c-24a8-41d6-a3fd-ba267edf5a0d_1360x814.jpeg 424w, https://substackcdn.com/image/fetch/$s_!6tfg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0edd773c-24a8-41d6-a3fd-ba267edf5a0d_1360x814.jpeg 848w, https://substackcdn.com/image/fetch/$s_!6tfg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0edd773c-24a8-41d6-a3fd-ba267edf5a0d_1360x814.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!6tfg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0edd773c-24a8-41d6-a3fd-ba267edf5a0d_1360x814.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6tfg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0edd773c-24a8-41d6-a3fd-ba267edf5a0d_1360x814.jpeg" width="1360" height="814" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0edd773c-24a8-41d6-a3fd-ba267edf5a0d_1360x814.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:814,&quot;width&quot;:1360,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:88294,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/178772115?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0edd773c-24a8-41d6-a3fd-ba267edf5a0d_1360x814.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6tfg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0edd773c-24a8-41d6-a3fd-ba267edf5a0d_1360x814.jpeg 424w, https://substackcdn.com/image/fetch/$s_!6tfg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0edd773c-24a8-41d6-a3fd-ba267edf5a0d_1360x814.jpeg 848w, https://substackcdn.com/image/fetch/$s_!6tfg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0edd773c-24a8-41d6-a3fd-ba267edf5a0d_1360x814.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!6tfg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0edd773c-24a8-41d6-a3fd-ba267edf5a0d_1360x814.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><h3><strong>A Honeypot Disguised as a Hacker&#8217;s Dream Tool</strong></h3><p>Cristian Cornea, founder of the annual BSides Transylvania cyber conference in Romania, decided to flip the script and start hunting cybercriminals using deception and a honeypot.<br>On a well-known Deep Web forum, Cristian, under a different alias, of course, posted an offer for a tool called Jinn Ransomware v1.0 Builder.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.darksignal.co/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>The package claimed to include source code that attackers could freely modify, allowing them to change the ransomware&#8217;s behavior, choose which file types are encrypted, alter distribution methods, and even customize the ransom note.<br>It was marketed as fully undetectable and designed to help attackers engineer new ransomware variants tailored to their needs.<br>The tool spread quickly, and more than 100 users downloaded it with malicious intent.</p><h3><strong>The Real Payload Hidden in the Code</strong></h3><p>While the attackers believed they had gained a powerful weapon, Cristian was the one gaining the real advantage.<br>Inside the Jinn source code, he had planted reporting functions that secretly sent back information about users and their activity.</p><p>All of Jinn&#8217;s advertised capabilities, including supposed support for multiple languages like Python, C, and PowerShell, and even its AES encryption features, were incomplete or entirely fake.<br>They existed only to create the illusion of a sophisticated ransomware builder, while in reality, they had almost no functional value.</p><p>While attackers were busy testing the tool, Cristian remotely connected to their devices using a C and C server he controlled.<br>He collected extensive intelligence on their techniques, infrastructure, and most importantly, their identities.<br>He then reported everything to law enforcement, together with solid forensic evidence.</p><h3><strong>DarkSignal&#8217;s Closing Thoughts </strong></h3><p>The attackers&#8217; downfall was trust, which is exactly what honeypots exploit.<br>Just like bait in nature, a tempting digital asset such as a sensitive database, a seemingly perfect hacking tool, or direct access to corporate servers should always raise suspicion.<br>Someone might be waiting for exactly that moment, and the attacker&#8217;s actions could play directly into the defender&#8217;s hands.</p><p>If even one of the users who downloaded Jinn had taken a basic look at the source code, they would likely have spotted the backdoor and the missing functionality that should have immediately raised doubts.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.darksignal.co/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Racism, Revenge, and Artificial Intelligence: A Modern Digital Tragedy]]></title><description><![CDATA[A Viral Recording and a Community in Turmoil]]></description><link>https://www.darksignal.co/p/racism-revenge-and-artificial-intelligence</link><guid isPermaLink="false">https://www.darksignal.co/p/racism-revenge-and-artificial-intelligence</guid><dc:creator><![CDATA[DarkSignal]]></dc:creator><pubDate>Thu, 13 Nov 2025 08:22:18 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Y0KX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f0686f8-c378-4109-b65c-07c6c6b4d2ec_800x458.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Y0KX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f0686f8-c378-4109-b65c-07c6c6b4d2ec_800x458.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Y0KX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f0686f8-c378-4109-b65c-07c6c6b4d2ec_800x458.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Y0KX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f0686f8-c378-4109-b65c-07c6c6b4d2ec_800x458.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Y0KX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f0686f8-c378-4109-b65c-07c6c6b4d2ec_800x458.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Y0KX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f0686f8-c378-4109-b65c-07c6c6b4d2ec_800x458.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Y0KX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f0686f8-c378-4109-b65c-07c6c6b4d2ec_800x458.jpeg" width="800" height="458" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0f0686f8-c378-4109-b65c-07c6c6b4d2ec_800x458.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:458,&quot;width&quot;:800,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:89077,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/178771839?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f0686f8-c378-4109-b65c-07c6c6b4d2ec_800x458.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Y0KX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f0686f8-c378-4109-b65c-07c6c6b4d2ec_800x458.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Y0KX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f0686f8-c378-4109-b65c-07c6c6b4d2ec_800x458.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Y0KX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f0686f8-c378-4109-b65c-07c6c6b4d2ec_800x458.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Y0KX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f0686f8-c378-4109-b65c-07c6c6b4d2ec_800x458.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>A Viral Recording and a Community in Turmoil</strong></h3><p>The internet exploded after a shocking racism scandal involving the principal of Pikesville High School in Maryland, who was secretly recorded making harsh, deeply racist remarks about both Jewish and African-American communities.<br><br>Three teachers received a strange email from a sender named TJFOUT9, titled &#8220;School Principal &#8211; Disturbing Recording.&#8221;<br>Inside was the audio, filled with extreme, hateful statements supposedly spoken by the principal himself.</p><p>As fate would have it, one of the teachers who received the recording already disliked the principal.<br>From there, the dominoes fell quickly: the clip spread to major national outlets like CNN and Fox News, students themselves received the recording, and suddenly no one doubted the principal&#8217;s guilt.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.darksignal.co/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h3><strong>From Viral Outrage to Real-World Danger</strong></h3><p>The recording went so viral across social media that the principal became a national villain overnight.<br>Security at the school was dramatically tightened due to credible threats, staff faced intense public backlash, and the principal and his family received direct death threats via phone calls.<br>Police began guarding his home 24/7 to prevent potential attacks.</p><p>He was immediately suspended from his job, drowned in public shame, and it seemed like his life and his family&#8217;s life had been ruined beyond repair.<br>For someone who speaks this way, many would argue the consequences were deserved.<br>But the principal insisted, even months later, that he never said those things.</p><h3><strong>A Breakthrough: The FBI Uncovers a Hidden Enemy</strong></h3><p>After months of suffering, the principal received a call from the FBI.<br>Thanks to a subpoena issued to Google, investigators had identified another email linked to the same operation, tied to an IP address belonging to a former colleague: the school&#8217;s ex&#8211;gym teacher.</p><p>The two had a long-standing rivalry, their relationship had deteriorated, and the gym teacher&#8217;s contract was not renewed.<br>Plenty of motive for revenge.</p><p>Following this breakthrough, the recording was handed over to forensic audio analysts and deepfake experts, who issued a clear conclusion:<br><strong>The recording was fake -  generated by AI. The principal never said any of it.</strong></p><p>An arrest warrant was immediately issued for the gym teacher, who was caught just minutes before boarding a pre-booked flight to leave the country.</p><h3><strong>DarkSignal&#8217;s Closing Thoughts</strong></h3><p>Artificial intelligence continues to demonstrate how easily it can destroy lives, alter destinies, and manipulate public opinion, whether through framing the innocent, manufacturing cybercrimes, or even influencing elections.<br>In the digital world of 2024, being skeptical is no longer optional, it&#8217;s a survival requirement.</p><p>For this principal, luck intervened, and the accusations were disproven.<br>But imagine if just one of the individuals who threatened his life had decided to act?<br>It won&#8217;t be surprising when we eventually hear of an AI-generated deception leading directly to real-world loss of life.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.darksignal.co/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The Double Life of a “Cyber Expert”]]></title><description><![CDATA[A Rising Cybercrime Star Hiding in Plain Sight]]></description><link>https://www.darksignal.co/p/the-double-life-of-a-cyber-expert</link><guid isPermaLink="false">https://www.darksignal.co/p/the-double-life-of-a-cyber-expert</guid><dc:creator><![CDATA[DarkSignal]]></dc:creator><pubDate>Thu, 13 Nov 2025 08:17:12 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!gb8B!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2bc918a9-ec06-46b1-ba35-113dc69a7e48_800x462.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!gb8B!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2bc918a9-ec06-46b1-ba35-113dc69a7e48_800x462.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gb8B!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2bc918a9-ec06-46b1-ba35-113dc69a7e48_800x462.jpeg 424w, https://substackcdn.com/image/fetch/$s_!gb8B!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2bc918a9-ec06-46b1-ba35-113dc69a7e48_800x462.jpeg 848w, https://substackcdn.com/image/fetch/$s_!gb8B!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2bc918a9-ec06-46b1-ba35-113dc69a7e48_800x462.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!gb8B!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2bc918a9-ec06-46b1-ba35-113dc69a7e48_800x462.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gb8B!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2bc918a9-ec06-46b1-ba35-113dc69a7e48_800x462.jpeg" width="800" height="462" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2bc918a9-ec06-46b1-ba35-113dc69a7e48_800x462.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:462,&quot;width&quot;:800,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:95700,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/178771668?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2bc918a9-ec06-46b1-ba35-113dc69a7e48_800x462.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!gb8B!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2bc918a9-ec06-46b1-ba35-113dc69a7e48_800x462.jpeg 424w, https://substackcdn.com/image/fetch/$s_!gb8B!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2bc918a9-ec06-46b1-ba35-113dc69a7e48_800x462.jpeg 848w, https://substackcdn.com/image/fetch/$s_!gb8B!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2bc918a9-ec06-46b1-ba35-113dc69a7e48_800x462.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!gb8B!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2bc918a9-ec06-46b1-ba35-113dc69a7e48_800x462.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><h3><strong>A Rising Cybercrime Star Hiding in Plain Sight</strong></h3><p>The cybercrime world keeps surprising us, and this time with an exceptionally strange and unexpected case involving Lin Rui-Siang, a 23-year-old Taiwanese national accused of operating a darknet drug marketplace known as Incognito Market.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.darksignal.co/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>The forum is widely known and has generated more than 100 million dollars in illegal drug sales.<br>As if that weren&#8217;t enough, Lin also stole users&#8217; funds, extorted them, and threatened to expose their identities unless they paid him.</p><h3><strong>From Criminal Mastermind to Law-Enforcement Lecturer</strong></h3><p>Just two months ago, Lin stood behind a podium marked with the emblem of the Saint Lucia Police Force, delivering a lecture on cybercrime and cryptocurrencies to local officers.<br>The event was organized by the Taiwanese Embassy, where Lin was employed as a cyber expert.</p><p>The Saint Lucian government even issued an official announcement praising the course and Lin&#8217;s insights on the dark web and crypto-tracing.<br>Only this week did it become clear what Lin&#8217;s &#8220;professional qualifications&#8221; really were, and where he acquired the practical knowledge he so confidently taught.</p><h3><strong>A Four-Year Reign Over One of the Darknet&#8217;s Biggest Drug Markets</strong></h3><p>Unbeknownst to his Taiwanese employers or the Saint Lucia police, Lin had secretly been running one of the most prominent darknet drug markets, Incognito Market, for nearly four years.</p><p>Maintaining a double identity, Lin recently rebranded himself as a &#8220;crypto-crime specialist,&#8221; giving training sessions on tracking digital currencies to police forces.<br>At the same time, he created a service called Antinalysis, designed to help criminals evaluate whether their crypto assets were traceable by the very authorities he was advising.</p><h3><strong>The Digital Footprints That Gave Him Away</strong></h3><p>Despite his efforts to blend into the world of law enforcement, his financial trail ultimately revealed his true identity.<br>He was arrested at JFK Airport in New York and charged with running a narcotics operation, laundering money, and managing a criminal enterprise.</p><p>Lin Rui-Siang managed to deceive many, but in the end, his own digital footprints led directly to his arrest.<br>His story is a stark reminder of how thin the line between criminal and investigator can be, and how every online action leaves a trace capable of exposing an entire hidden world beneath the surface.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.darksignal.co/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The end of a cyber gang or a sophisticated deception?]]></title><description><![CDATA[The group known as AlphV, or more commonly BlackCat, operates under a very business-oriented model of RaaS (Ransomware as a Service).]]></description><link>https://www.darksignal.co/p/the-end-of-a-cyber-gang-or-a-sophisticated</link><guid isPermaLink="false">https://www.darksignal.co/p/the-end-of-a-cyber-gang-or-a-sophisticated</guid><dc:creator><![CDATA[DarkSignal]]></dc:creator><pubDate>Thu, 13 Nov 2025 08:11:48 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!LXNc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf041828-cf59-43e5-a13a-4870e172ab20_800x451.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!LXNc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf041828-cf59-43e5-a13a-4870e172ab20_800x451.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!LXNc!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf041828-cf59-43e5-a13a-4870e172ab20_800x451.jpeg 424w, https://substackcdn.com/image/fetch/$s_!LXNc!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf041828-cf59-43e5-a13a-4870e172ab20_800x451.jpeg 848w, https://substackcdn.com/image/fetch/$s_!LXNc!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf041828-cf59-43e5-a13a-4870e172ab20_800x451.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!LXNc!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf041828-cf59-43e5-a13a-4870e172ab20_800x451.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!LXNc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf041828-cf59-43e5-a13a-4870e172ab20_800x451.jpeg" width="800" height="451" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/df041828-cf59-43e5-a13a-4870e172ab20_800x451.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:451,&quot;width&quot;:800,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:50932,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/178771327?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf041828-cf59-43e5-a13a-4870e172ab20_800x451.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!LXNc!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf041828-cf59-43e5-a13a-4870e172ab20_800x451.jpeg 424w, https://substackcdn.com/image/fetch/$s_!LXNc!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf041828-cf59-43e5-a13a-4870e172ab20_800x451.jpeg 848w, https://substackcdn.com/image/fetch/$s_!LXNc!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf041828-cf59-43e5-a13a-4870e172ab20_800x451.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!LXNc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf041828-cf59-43e5-a13a-4870e172ab20_800x451.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The group known as AlphV, or more commonly BlackCat, operates under a very business-oriented model of RaaS (Ransomware as a Service). In practice, they deploy attack tools capable of encrypting an entire victim&#8217;s network and then demand a ransom in return.<br>The group first rose to prominence in 2021 and quickly built an impressive track record, hitting major organizations in the defense, retail, and healthcare sectors.</p><p>As expected with a group this notorious, intelligence agencies launched a worldwide hunt for the operators and affiliates behind their activities. And when an operation of this scale is active, there&#8217;s always noise in the air. Their business partners (affiliates) send them cuts from every successful attack, and naturally, the more they expand, the more their risk grows.<br>That&#8217;s why, in March 2024, reports surfaced that one of BlackCat&#8217;s crypto wallets had been drained without their knowledge, suggesting the group itself had fallen victim to an attack.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.darksignal.co/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>The world of cyber gangs is a jungle. Rivals are everywhere, competing groups and law-enforcement agencies alike.<br>The pressure intensified, especially after the severe sentences handed down earlier this month to the affiliates of LockBit, another major ransomware competitor, who now face decades in prison.</p><h3>The Pivot Point</h3><p>Then something unusual happened.<br>The leader of AlphV posted a statement on the group&#8217;s forum announcing that they were shutting down operations and &#8220;retiring.&#8221; They claimed they had enough money for a long vacation &#8212; or, as we&#8217;d call it in Israeli slang, a &#8220;post-army trip.&#8221;<br>According to the post, the group&#8217;s source code would be sold for five million dollars, allowing the next buyer to modify it and continue the group&#8217;s grand legacy.</p><p>A few days later, a familiar message appeared on their site - the infamous banner the cyber world knows well: <em>&#8220;The Domain Has Been Seized.&#8221;</em><br>The implication: law enforcement had taken them down, arrested them, and shut down their infrastructure.</p><h3>Truth or Deception?</h3><p>The FBI was stunned.<br>Despite being credited in the banner as the heroes who took down AlphV, they had no idea what the announcement was about. They checked with partner agencies that usually cooperate in operations of this scale &#8212; none of them knew anything either.</p><p>It turned out AlphV had socially engineered all of us, including law enforcement.<br>In the language of magicians, this tactic is called misdirection.<br>The group posted a fake seizure notice to throw investigators off their trail. The idea was simple: if everyone believes you&#8217;ve already been caught, they stop looking. Why chase something that doesn&#8217;t exist?</p><h3>DarkSignal&#8217;s Closing Thoughts</h3><p>For now, the group has gone quiet, retreating underground until the heat dies down.<br>Or,  and this is only speculation, they may be preparing a full rebrand and planning stronger attacks than ever under a new name.</p><p>Who knows?</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.darksignal.co/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The Fraud Supermarket Thriving on the Open Web]]></title><description><![CDATA[The world of cybercrime and the forums that fuel it is nothing new.]]></description><link>https://www.darksignal.co/p/the-fraud-supermarket-thriving-on</link><guid isPermaLink="false">https://www.darksignal.co/p/the-fraud-supermarket-thriving-on</guid><dc:creator><![CDATA[DarkSignal]]></dc:creator><pubDate>Thu, 13 Nov 2025 08:04:03 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!IJU2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c747f10-3827-430c-8a07-1c6e914c43a7_875x396.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!IJU2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c747f10-3827-430c-8a07-1c6e914c43a7_875x396.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!IJU2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c747f10-3827-430c-8a07-1c6e914c43a7_875x396.jpeg 424w, https://substackcdn.com/image/fetch/$s_!IJU2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c747f10-3827-430c-8a07-1c6e914c43a7_875x396.jpeg 848w, https://substackcdn.com/image/fetch/$s_!IJU2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c747f10-3827-430c-8a07-1c6e914c43a7_875x396.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!IJU2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c747f10-3827-430c-8a07-1c6e914c43a7_875x396.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!IJU2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c747f10-3827-430c-8a07-1c6e914c43a7_875x396.jpeg" width="875" height="396" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4c747f10-3827-430c-8a07-1c6e914c43a7_875x396.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:396,&quot;width&quot;:875,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:32808,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/178770962?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c747f10-3827-430c-8a07-1c6e914c43a7_875x396.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!IJU2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c747f10-3827-430c-8a07-1c6e914c43a7_875x396.jpeg 424w, https://substackcdn.com/image/fetch/$s_!IJU2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c747f10-3827-430c-8a07-1c6e914c43a7_875x396.jpeg 848w, https://substackcdn.com/image/fetch/$s_!IJU2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c747f10-3827-430c-8a07-1c6e914c43a7_875x396.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!IJU2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c747f10-3827-430c-8a07-1c6e914c43a7_875x396.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>The world of cybercrime and the forums that fuel it is nothing new. Most of these markets operate on the dark web, but recently, a new platform called OLVX has made headlines, not because it hides, but because it claims to &#8220;fear no authorities&#8221; and operates openly on the clearnet, accessible to anyone, anywhere, at any time.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.darksignal.co/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>The site advertises itself as a marketplace where you can buy all the tools and methods needed to carry out online fraud. It offers a wide range of listings, including phishing kits, RDP access, large volumes of stolen data, and spam-distribution systems.<br><br>The entire concept is to enable anyone, regardless of technical skill, to execute whatever online scam they want, with the quality of the operation determined solely by the tools they buy from sellers on the platform.</p><p>Not only is the entire marketplace hosted on the regular internet, but its operators have gone even further: they actively use SEO and analytics techniques to boost visibility, attract new users, and maximize their revenue potential.</p><p>OLVX also maintains an official Telegram channel where they frequently post product promotions, and they keep a noticeable standard of customer support for any issue that might arise, a clear sign that they understand trust is the foundation of criminal business just as much as legitimate commerce.</p><h4>Why OLVX Is So Different</h4><p>It seems the site&#8217;s operators understand their audience well. While most underground markets require escrow services, which charge significant fees, OLVX allows direct crypto payments. This obviously introduces the risk of the seller disappearing with the money, but as mentioned, everything here is built on trust, and that appears to be a core value the operators emphasize.</p><h3>DarkSignal&#8217;s Closing Thoughts</h3><p>There&#8217;s no doubt that the end of the year and holiday season drive increased activity on this and similar sites. Companies become more distracted planning for the new year, creating well-known windows of opportunity that attackers are eager to exploit.<br><br>The only question is: does it work?</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.darksignal.co/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[From Millions to a Manhunt: The Final Days of AlphaBay]]></title><description><![CDATA[In June 2014, a Canadian citizen named Alexandre Cazes sat at his computer and built a website that would later become one of the largest illegal marketplaces on the dark web.]]></description><link>https://www.darksignal.co/p/from-millions-to-a-manhunt-the-final</link><guid isPermaLink="false">https://www.darksignal.co/p/from-millions-to-a-manhunt-the-final</guid><dc:creator><![CDATA[DarkSignal]]></dc:creator><pubDate>Thu, 13 Nov 2025 07:37:22 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!ztRX!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf96a1f2-8ab6-4995-a09e-591568a9a496_1024x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vDzR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ff1227e-37c5-4df8-a9de-19c255aa8b25_280x163.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vDzR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ff1227e-37c5-4df8-a9de-19c255aa8b25_280x163.jpeg 424w, https://substackcdn.com/image/fetch/$s_!vDzR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ff1227e-37c5-4df8-a9de-19c255aa8b25_280x163.jpeg 848w, https://substackcdn.com/image/fetch/$s_!vDzR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ff1227e-37c5-4df8-a9de-19c255aa8b25_280x163.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!vDzR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ff1227e-37c5-4df8-a9de-19c255aa8b25_280x163.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vDzR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ff1227e-37c5-4df8-a9de-19c255aa8b25_280x163.jpeg" width="310" height="180.46428571428572" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9ff1227e-37c5-4df8-a9de-19c255aa8b25_280x163.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;normal&quot;,&quot;height&quot;:163,&quot;width&quot;:280,&quot;resizeWidth&quot;:310,&quot;bytes&quot;:12566,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/178769653?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb76d99dc-b839-4d9c-ad80-06c7d563a305_310x163.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:&quot;center&quot;,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vDzR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ff1227e-37c5-4df8-a9de-19c255aa8b25_280x163.jpeg 424w, https://substackcdn.com/image/fetch/$s_!vDzR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ff1227e-37c5-4df8-a9de-19c255aa8b25_280x163.jpeg 848w, https://substackcdn.com/image/fetch/$s_!vDzR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ff1227e-37c5-4df8-a9de-19c255aa8b25_280x163.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!vDzR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ff1227e-37c5-4df8-a9de-19c255aa8b25_280x163.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p>In June 2014, a Canadian citizen named Alexandre Cazes sat at his computer and built a website that would later become one of the largest illegal marketplaces on the dark web.<br>Alexandre, born in &#8217;91, was highly ambitious. He envisioned his forum, which most of you know as AlphaBay, growing into one of the biggest marketplaces the Darknet had ever seen, eventually hosting more than 300,000 listings for hard drugs, weapons, malware, illicit hacking tools, and stolen data.</p><p>The forum, which generated tens of millions of dollars in cryptocurrency, became a prime target for multiple intelligence agencies. Yet for years, investigators had no idea who was running it. </p><p>The mystery remained unsolved until one day an Interpol agent received an anonymous tip: a copy of AlphaBay&#8217;s automated welcome email sent to every new user.<br>At the bottom of the message was Alexandre&#8217;s personal email address, a classic OPSEC mistake that ultimately led to his downfall. </p><p>This was the turning point. From there, identifying Alexandre and tracking his movements became straightforward.</p><h3>When Troubles Start Coming, They Come In Pairs</h3><p>Authorities planned an elaborate arrest operation in Thailand. On the appointed day, they staged a minor car crash against the fence of his home, hoping the commotion would push Alexandre to step outside while his laptop remained unlocked. And that&#8217;s exactly what happened.<br>As soon as he rushed out to see what was happening, officers moved in. He was arrested on the spot, and his unlocked computer was seized as a result of a coordinated operation involving Interpol and seven additional agencies.</p><p>With full access to the device, investigators could review transactions, identify new suspects, and map out AlphaBay&#8217;s user base.<br>By July 2017, Alexandre&#8217;s wife was charged with large-scale money laundering, Alexandre was arrested, and the entire marketplace was taken down.<br>About a month later, the man who had made millions, driven luxury cars, owned vacation homes, and ruled the largest marketplace on the dark web was found dead, of what seems like an apparent suicide.<br>And just like that, the urban legend of the Canadian who set a new standard for the criminal underworld came to an end.</p><h3>Legends Do Not Just Disappear</h3><p>Immediately after the forum&#8217;s takedown, its users, insatiable as ever, did what in the startup world is known as a &#8220;pivot.&#8221; They migrated quickly from the exposed marketplace to others.<br>Because where there is demand, supply will always find a way.</p>]]></content:encoded></item><item><title><![CDATA[Have You Heard of the "Perfect Crime"?]]></title><description><![CDATA[The story behind Exit Scams]]></description><link>https://www.darksignal.co/p/have-you-heard-of-the-perfect-crime</link><guid isPermaLink="false">https://www.darksignal.co/p/have-you-heard-of-the-perfect-crime</guid><dc:creator><![CDATA[DarkSignal]]></dc:creator><pubDate>Thu, 13 Nov 2025 07:24:50 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!iFY9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18305341-eaaa-4256-9439-ac555271f879_1692x917.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!iFY9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18305341-eaaa-4256-9439-ac555271f879_1692x917.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!iFY9!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18305341-eaaa-4256-9439-ac555271f879_1692x917.jpeg 424w, https://substackcdn.com/image/fetch/$s_!iFY9!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18305341-eaaa-4256-9439-ac555271f879_1692x917.jpeg 848w, https://substackcdn.com/image/fetch/$s_!iFY9!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18305341-eaaa-4256-9439-ac555271f879_1692x917.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!iFY9!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18305341-eaaa-4256-9439-ac555271f879_1692x917.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!iFY9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18305341-eaaa-4256-9439-ac555271f879_1692x917.jpeg" width="728" height="394.54846335697397" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/18305341-eaaa-4256-9439-ac555271f879_1692x917.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;normal&quot;,&quot;height&quot;:917,&quot;width&quot;:1692,&quot;resizeWidth&quot;:728,&quot;bytes&quot;:91272,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/178768953?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47cad2ee-7414-4a54-a5e8-7ce001ae9e9b_2048x1152.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:&quot;center&quot;,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!iFY9!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18305341-eaaa-4256-9439-ac555271f879_1692x917.jpeg 424w, https://substackcdn.com/image/fetch/$s_!iFY9!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18305341-eaaa-4256-9439-ac555271f879_1692x917.jpeg 848w, https://substackcdn.com/image/fetch/$s_!iFY9!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18305341-eaaa-4256-9439-ac555271f879_1692x917.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!iFY9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18305341-eaaa-4256-9439-ac555271f879_1692x917.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><br>Across the Darknet, you can find an endless supply of anything the digital underworld has to offer. Countless online shops sell every type of drug, weapons (including 3D-printed ones), ammunition, malware, forged or stolen documents, and, of course, a wide range of criminal services.<br>But what happens when the seller isn&#8217;t who they claim to be? What happens when you pay for a product or service that never arrives?</p><p>Congratulations! You&#8217;ve become a victim of an exit scam, also known as the perfect crime. After all, who exactly are you going to complain to when your illegal goods never show up?</p><p>That&#8217;s why buyers rely on several essential checks before making any purchase in high-risk environments.<br></p><h3>How do you do that?</h3><ul><li><p><strong>Estimate the seller&#8217;s track record:</strong><br>Many forums display live counters showing how many sales a vendor has made for each product. Follow these numbers for a few days to see if there are inconsistencies or sudden changes.</p></li><li><p><strong>If it seems too good to be true, it is:</strong><br>Prices can&#8217;t be drastically lower than the market average. Competition is high, and the risks are even higher.</p></li><li><p><strong>Reviews, reviews, and more reviews:</strong><br>There are sites and forums dedicated to reviewing darknet markets - Reddit, or its darknet counterpart &#8220;Dread&#8221;, for example.<br>There are Telegram groups for verification, chats discussing new and old forums, and even clearnet sites that categorize underground markets based on user reviews.</p><p>If there aren&#8217;t enough reviews, if the site is too new, not well-known, or if something feels off, just walk away. It&#8217;s not worth the risk of being scammed at best, arrested in a worse scenario, or physically harmed in the worst-case scenario.</p></li><li><p><strong>Use escrow services:</strong><br>In the darknet ecosystem, third-party escrow services act as trusted intermediaries to ensure that payments and deliveries are handled properly.<br>The buyer sends funds to the escrow, which notifies the seller but only releases the payment after the buyer confirms they&#8217;ve received the order and are satisfied. Once everything checks out, the escrow releases the money to the vendor and completes the transaction.</p><p>In any case, it&#8217;s always wise to rely on reputable directories and dedicated resources to verify marketplaces and reach the legitimate ones - for example, Dark.Fail, which provides a reliable, automatically updated list of the most current darknet links.</p></li></ul><h3>DarkSignal&#8217;s Closing Thoughts</h3><p>In the end, in a world where anyone can pretend to be someone else, trust is the real currency, and even the smallest mistake can come at a heavy cost.</p><p>To me, understanding how these scams operate isn&#8217;t just professional curiosity but a necessary layer of protection in an era where the line between criminal and victim is thinner than ever.</p>]]></content:encoded></item></channel></rss>