<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[DarkSignal: Deep Investigations]]></title><description><![CDATA[Uncovering hidden layers behind complex operations, from espionage footprints to clandestine activities shaping global security landscapes.
]]></description><link>https://www.darksignal.co/s/deep-investigations</link><image><url>https://substackcdn.com/image/fetch/$s_!ztRX!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf96a1f2-8ab6-4995-a09e-591568a9a496_1024x1024.png</url><title>DarkSignal: Deep Investigations</title><link>https://www.darksignal.co/s/deep-investigations</link></image><generator>Substack</generator><lastBuildDate>Thu, 09 Apr 2026 10:02:55 GMT</lastBuildDate><atom:link href="https://www.darksignal.co/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[DarkSignal]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[admin@darksignal.co]]></webMaster><itunes:owner><itunes:email><![CDATA[admin@darksignal.co]]></itunes:email><itunes:name><![CDATA[DarkSignal]]></itunes:name></itunes:owner><itunes:author><![CDATA[DarkSignal]]></itunes:author><googleplay:owner><![CDATA[admin@darksignal.co]]></googleplay:owner><googleplay:email><![CDATA[admin@darksignal.co]]></googleplay:email><googleplay:author><![CDATA[DarkSignal]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Anatomy of a Clone - Fake Red Alert Spyware]]></title><description><![CDATA[Shadow Alerts &#8211; The Sophistication of Modern Targeted Spyware]]></description><link>https://www.darksignal.co/p/anatomy-of-a-clone-fake-red-alert</link><guid isPermaLink="false">https://www.darksignal.co/p/anatomy-of-a-clone-fake-red-alert</guid><dc:creator><![CDATA[DarkSignal]]></dc:creator><pubDate>Wed, 04 Mar 2026 08:30:39 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!rP13!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6492ad52-f93d-44e0-83bf-ae0837b9d496_746x1417.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rP13!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6492ad52-f93d-44e0-83bf-ae0837b9d496_746x1417.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rP13!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6492ad52-f93d-44e0-83bf-ae0837b9d496_746x1417.png 424w, https://substackcdn.com/image/fetch/$s_!rP13!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6492ad52-f93d-44e0-83bf-ae0837b9d496_746x1417.png 848w, https://substackcdn.com/image/fetch/$s_!rP13!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6492ad52-f93d-44e0-83bf-ae0837b9d496_746x1417.png 1272w, https://substackcdn.com/image/fetch/$s_!rP13!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6492ad52-f93d-44e0-83bf-ae0837b9d496_746x1417.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rP13!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6492ad52-f93d-44e0-83bf-ae0837b9d496_746x1417.png" width="746" height="1417" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6492ad52-f93d-44e0-83bf-ae0837b9d496_746x1417.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1417,&quot;width&quot;:746,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2510585,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/189742643?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Facc72e38-5e75-4bed-b24b-a09379b20327_1024x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!rP13!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6492ad52-f93d-44e0-83bf-ae0837b9d496_746x1417.png 424w, https://substackcdn.com/image/fetch/$s_!rP13!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6492ad52-f93d-44e0-83bf-ae0837b9d496_746x1417.png 848w, https://substackcdn.com/image/fetch/$s_!rP13!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6492ad52-f93d-44e0-83bf-ae0837b9d496_746x1417.png 1272w, https://substackcdn.com/image/fetch/$s_!rP13!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6492ad52-f93d-44e0-83bf-ae0837b9d496_746x1417.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h4><strong>Shadow Alerts &#8211; The Sophistication of Modern Targeted Spyware</strong></h4><p>Throughout the prolonged period of regional hostilities, and specifically following the escalations with Iran, a targeted cyber-espionage campaign has been identified leveraging cynical social engineering to deploy spyware on Israeli Android devices.</p><p>The campaign utilizes mass SMS phishing that exploits public distress, compelling users to install a malicious application masquerading as the official &#8220;Red Alert&#8221; (Tzeva Adom) early-warning system.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.darksignal.co/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>The malware, identified by the package name com[.]red[.]alertx, is a prime example of strategic typosquatting. To establish total user trust, the application provides a fully functional interface, including authentic siren alerts, localized maps, and a comprehensive database of Israeli municipalities.</p><p>This front-end facade is designed to manipulate users into granting invasive permissions without scrutiny. Beneath this operational exterior, the system functions as an active intelligence-gathering tool, utilizing custom obfuscation techniques specifically engineered to bypass standard signature-based detection and heuristic analysis.</p><p>While initial findings attribute the core infrastructure to the Hamas-affiliated group APT-C-23 (Arid Viper), recent iterations of the spyware reveal the direct involvement of leading Iranian threat actors. This partnership has resulted in a significant leap in the malware&#8217;s technical sophistication, characterized by hardened evasion mechanisms and more resilient (C2) architectures.</p><p>This operational methodology, first observed after the October 7th attacks and refined during the &#8220;12-Day War&#8221; with Iran, has now reached its most advanced stage. This report provides a detailed technical analysis of the latest builds, the encryption methods employed, and the evolving synergy between regional threat groups operating against the Israeli theatre.</p><div class="image-gallery-embed" data-attrs="{&quot;gallery&quot;:{&quot;images&quot;:[{&quot;type&quot;:&quot;image/png&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/54e58fc8-e8f3-46db-a2a1-0ca28ae666a2_371x324.png&quot;},{&quot;type&quot;:&quot;image/png&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c59d0f05-61e3-43eb-bc5f-ad64ca2708a5_1120x870.png&quot;}],&quot;caption&quot;:&quot;&quot;,&quot;alt&quot;:&quot;&quot;,&quot;staticGalleryImage&quot;:{&quot;type&quot;:&quot;image/png&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b9b66ca7-96f2-4a51-8710-2ca5b8379f61_1456x720.png&quot;}},&quot;isEditorNode&quot;:true}"></div><h4><strong>Anatomy of a Clone</strong></h4><p>The application implements an exceptionally thorough and meticulous impersonation of the legitimate &#8220;Red Alert&#8221; (Tzeva Adom) system. Every visible layer, from iconography and auditory assets to user interface and localized data, is engineered to be indistinguishable from the genuine application. This high-fidelity mimicry is a calculated effort to neutralize user suspicion during the high-stress window of installation.</p><p>At the visual level, the malware utilizes direct asset theft from the original platform, including the iconic red circle and white broadcast tower launcher icon. <br>This continuity extends deep into the application&#8217;s architecture, where specific layout files mimic complex features such as &#8220;Location Alerts,&#8221; &#8220;Secondary Notifications,&#8221; and &#8220;Shelter Exit Timers&#8221; To ensure broad demographic appeal and credibility across the Israeli theatre, the developers integrated full Right-to-Left (RTL) support with dedicated Hebrew (layout-iw/) and Arabic (layout-ar/) directories.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Z0Ff!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37faea74-6d1c-4f5f-83b8-de85cf760d01_418x257.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Z0Ff!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37faea74-6d1c-4f5f-83b8-de85cf760d01_418x257.png 424w, https://substackcdn.com/image/fetch/$s_!Z0Ff!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37faea74-6d1c-4f5f-83b8-de85cf760d01_418x257.png 848w, https://substackcdn.com/image/fetch/$s_!Z0Ff!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37faea74-6d1c-4f5f-83b8-de85cf760d01_418x257.png 1272w, https://substackcdn.com/image/fetch/$s_!Z0Ff!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37faea74-6d1c-4f5f-83b8-de85cf760d01_418x257.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Z0Ff!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37faea74-6d1c-4f5f-83b8-de85cf760d01_418x257.png" width="418" height="257" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/37faea74-6d1c-4f5f-83b8-de85cf760d01_418x257.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:257,&quot;width&quot;:418,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:12352,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/189742643?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37faea74-6d1c-4f5f-83b8-de85cf760d01_418x257.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Z0Ff!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37faea74-6d1c-4f5f-83b8-de85cf760d01_418x257.png 424w, https://substackcdn.com/image/fetch/$s_!Z0Ff!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37faea74-6d1c-4f5f-83b8-de85cf760d01_418x257.png 848w, https://substackcdn.com/image/fetch/$s_!Z0Ff!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37faea74-6d1c-4f5f-83b8-de85cf760d01_418x257.png 1272w, https://substackcdn.com/image/fetch/$s_!Z0Ff!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37faea74-6d1c-4f5f-83b8-de85cf760d01_418x257.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The deception is further reinforced through functional geographic integration. <br>By leveraging Google Maps alongside a custom polygon overlay system, the malware can render accurate alert zone boundaries. If a user cross-references the app with real-world events, the interface provides a convincing illusion of authentic, live data from the Home Front Command.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ITk1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad79bef9-c59b-4f15-a825-cc4d86bda9d1_335x471.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ITk1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad79bef9-c59b-4f15-a825-cc4d86bda9d1_335x471.png 424w, https://substackcdn.com/image/fetch/$s_!ITk1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad79bef9-c59b-4f15-a825-cc4d86bda9d1_335x471.png 848w, https://substackcdn.com/image/fetch/$s_!ITk1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad79bef9-c59b-4f15-a825-cc4d86bda9d1_335x471.png 1272w, https://substackcdn.com/image/fetch/$s_!ITk1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad79bef9-c59b-4f15-a825-cc4d86bda9d1_335x471.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ITk1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad79bef9-c59b-4f15-a825-cc4d86bda9d1_335x471.png" width="335" height="471" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ad79bef9-c59b-4f15-a825-cc4d86bda9d1_335x471.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:471,&quot;width&quot;:335,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:19014,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/189742643?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad79bef9-c59b-4f15-a825-cc4d86bda9d1_335x471.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ITk1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad79bef9-c59b-4f15-a825-cc4d86bda9d1_335x471.png 424w, https://substackcdn.com/image/fetch/$s_!ITk1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad79bef9-c59b-4f15-a825-cc4d86bda9d1_335x471.png 848w, https://substackcdn.com/image/fetch/$s_!ITk1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad79bef9-c59b-4f15-a825-cc4d86bda9d1_335x471.png 1272w, https://substackcdn.com/image/fetch/$s_!ITk1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad79bef9-c59b-4f15-a825-cc4d86bda9d1_335x471.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Eventually, the auditory component serves as a critical pillar of this social engineering strategy. The application contains a library of 24 sound files, including the actual tzevaadom.mp3 siren used in Israel&#8217;s early-warning infrastructure.</p><p>By providing a spectrum of tones, ranging from the primary alarm to &#8220;calm&#8221; status updates, the malware reinforces a false sense of security, ensuring the user keeps the application active while the spyware silently exfiltrates data in the background.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!JCK4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad3ec76c-cbf5-4947-9f2c-72790eae6c0d_402x713.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!JCK4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad3ec76c-cbf5-4947-9f2c-72790eae6c0d_402x713.png 424w, https://substackcdn.com/image/fetch/$s_!JCK4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad3ec76c-cbf5-4947-9f2c-72790eae6c0d_402x713.png 848w, https://substackcdn.com/image/fetch/$s_!JCK4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad3ec76c-cbf5-4947-9f2c-72790eae6c0d_402x713.png 1272w, https://substackcdn.com/image/fetch/$s_!JCK4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad3ec76c-cbf5-4947-9f2c-72790eae6c0d_402x713.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!JCK4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad3ec76c-cbf5-4947-9f2c-72790eae6c0d_402x713.png" width="402" height="713" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ad3ec76c-cbf5-4947-9f2c-72790eae6c0d_402x713.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:713,&quot;width&quot;:402,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:32646,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/189742643?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad3ec76c-cbf5-4947-9f2c-72790eae6c0d_402x713.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!JCK4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad3ec76c-cbf5-4947-9f2c-72790eae6c0d_402x713.png 424w, https://substackcdn.com/image/fetch/$s_!JCK4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad3ec76c-cbf5-4947-9f2c-72790eae6c0d_402x713.png 848w, https://substackcdn.com/image/fetch/$s_!JCK4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad3ec76c-cbf5-4947-9f2c-72790eae6c0d_402x713.png 1272w, https://substackcdn.com/image/fetch/$s_!JCK4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad3ec76c-cbf5-4947-9f2c-72790eae6c0d_402x713.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h4><strong>Modular Espionage - Spyware Architecture</strong></h4><p>The spyware module is encapsulated entirely within <code>classes2.dex</code> under the <code>androidx.activity.yuma</code> namespace, a deliberate naming convention chosen to blend seamlessly with legitimate AndroidX library components. <br>The malware&#8217;s internal architecture follows a sophisticated, modular Collector &#8594; Queue &#8594; Upload pattern, ensuring efficient data exfiltration while maintaining a low footprint.</p><p>The class hierarchy reveals a highly organized functional division, despite the use of dictionary-word obfuscation to hinder manual analysis.</p><p>The primary execution flow is managed through a series of specialized Runnables, the <code>bestrut </code>class is responsible for harvesting SMS messages, contact lists, and the inventory of installed applications, the <code>border </code>class facilitates continuous GPS tracking via the system&#8217;s <code>LocationManager </code>and <code>LocationListener </code>interfaces, and the <code>unblest </code>class focuses on account theft through <code>AccountManager </code>and unique ID.</p><p>Initialization is triggered through a sequence of executor-dispatched tasks. <br>The primary entry point spawns a dedicated permission-request thread (myopes), which monitors the user&#8217;s responses. Once the requisite permissions are granted, the malware initiates its core data collectors alongside an infinite upload loop managed by the overhot class.</p><p>This loop cyclically iterates through categorized data, packaging and transmitting files to the Command and Control (C2) endpoint.</p><p>The orchestration of these components is handled by functional wrappers such as <code>Bravado()</code> and <code>Wauchle()</code>. These methods encapsulate the <code>Executor.execute(Runnable)</code> logic, dispatching the permission-acquisition flow and the upload loop onto separate thread pool executors.</p><p>This multi-threaded approach ensures that the malicious background activities remain decoupled from the primary UI, allowing the &#8220;Red Alert&#8221; facade to function smoothly while exfiltration occurs in parallel.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!TUxT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3815fb68-55d5-4b9c-a968-d4ab59865784_648x309.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!TUxT!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3815fb68-55d5-4b9c-a968-d4ab59865784_648x309.png 424w, https://substackcdn.com/image/fetch/$s_!TUxT!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3815fb68-55d5-4b9c-a968-d4ab59865784_648x309.png 848w, https://substackcdn.com/image/fetch/$s_!TUxT!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3815fb68-55d5-4b9c-a968-d4ab59865784_648x309.png 1272w, https://substackcdn.com/image/fetch/$s_!TUxT!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3815fb68-55d5-4b9c-a968-d4ab59865784_648x309.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!TUxT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3815fb68-55d5-4b9c-a968-d4ab59865784_648x309.png" width="648" height="309" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3815fb68-55d5-4b9c-a968-d4ab59865784_648x309.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:309,&quot;width&quot;:648,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:33690,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/189742643?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3815fb68-55d5-4b9c-a968-d4ab59865784_648x309.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!TUxT!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3815fb68-55d5-4b9c-a968-d4ab59865784_648x309.png 424w, https://substackcdn.com/image/fetch/$s_!TUxT!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3815fb68-55d5-4b9c-a968-d4ab59865784_648x309.png 848w, https://substackcdn.com/image/fetch/$s_!TUxT!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3815fb68-55d5-4b9c-a968-d4ab59865784_648x309.png 1272w, https://substackcdn.com/image/fetch/$s_!TUxT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3815fb68-55d5-4b9c-a968-d4ab59865784_648x309.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h4><strong>Adversarial Resilience - Encryption &amp; Obfuscation</strong></h4><p>All sensitive strings within the malware, including API endpoints, field names, and internal content URIs, are protected by a consistent, two-stage cryptographic process. This mechanism is designed to thwart static analysis and prevent the discovery of the threat actor&#8217;s infrastructure through simple string-searching tools.</p><p>The decryption pipeline follows a structured sequence:</p><ol><li><p><strong>Base64 Decoding:</strong> The ciphertext, stored as an encoded string, is first processed through the<code> android.util.Base64</code> utility class.</p></li><li><p><strong>Cyclic XOR Transformation:</strong> Each byte of the resulting data is then XOR-encrypted with a character from a static 32-byte key string.</p></li></ol><p>Across the decompiled source code, 281 unique encrypted strings were identified. <br>This extensive use of obfuscation covers every critical operational detail of the spyware, from the specific SMS permissions it requests to the remote server addresses it targets.</p><p>The critical function that decrypts the C2 endpoint URL is <code>Bewailed()</code>, resulting cleartext identifies the central data exfiltration hub: <br><code>https://api[.]ra-backup[.]com/analytics/submit[.]php</code></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!sNo8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe56deb5-e863-4cc1-80b8-1d16dbd42b54_812x226.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!sNo8!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe56deb5-e863-4cc1-80b8-1d16dbd42b54_812x226.png 424w, https://substackcdn.com/image/fetch/$s_!sNo8!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe56deb5-e863-4cc1-80b8-1d16dbd42b54_812x226.png 848w, https://substackcdn.com/image/fetch/$s_!sNo8!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe56deb5-e863-4cc1-80b8-1d16dbd42b54_812x226.png 1272w, https://substackcdn.com/image/fetch/$s_!sNo8!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe56deb5-e863-4cc1-80b8-1d16dbd42b54_812x226.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!sNo8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe56deb5-e863-4cc1-80b8-1d16dbd42b54_812x226.png" width="812" height="226" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/be56deb5-e863-4cc1-80b8-1d16dbd42b54_812x226.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:226,&quot;width&quot;:812,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:27954,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/189742643?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe56deb5-e863-4cc1-80b8-1d16dbd42b54_812x226.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!sNo8!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe56deb5-e863-4cc1-80b8-1d16dbd42b54_812x226.png 424w, https://substackcdn.com/image/fetch/$s_!sNo8!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe56deb5-e863-4cc1-80b8-1d16dbd42b54_812x226.png 848w, https://substackcdn.com/image/fetch/$s_!sNo8!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe56deb5-e863-4cc1-80b8-1d16dbd42b54_812x226.png 1272w, https://substackcdn.com/image/fetch/$s_!sNo8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe56deb5-e863-4cc1-80b8-1d16dbd42b54_812x226.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>The analysis reveals that the identifiers are not the product of standard obfuscators like ProGuard or R8, which typically generate short, sequential strings (a, b, aa, etc...), but a custom obfuscation tool that replaces original identifiers with obscure English dictionary words, such as Bewailed, Cucurbit, and Zyzzyva.</p><p>This specific naming convention serves as a trackable cryptographic fingerprint, allowing to link disparate malware samples to the same development pipeline and infrastructure.</p><h4><strong>Data Collection Capabilities</strong></h4><p>The malware implements five distinct data collection modules, each mapped to an enum value in <code>crisped </code>that categorizes the stolen data for organized exfiltration.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!K1rH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ae01669-941c-4704-ad75-781aea973249_429x144.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!K1rH!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ae01669-941c-4704-ad75-781aea973249_429x144.png 424w, https://substackcdn.com/image/fetch/$s_!K1rH!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ae01669-941c-4704-ad75-781aea973249_429x144.png 848w, https://substackcdn.com/image/fetch/$s_!K1rH!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ae01669-941c-4704-ad75-781aea973249_429x144.png 1272w, https://substackcdn.com/image/fetch/$s_!K1rH!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ae01669-941c-4704-ad75-781aea973249_429x144.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!K1rH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ae01669-941c-4704-ad75-781aea973249_429x144.png" width="429" height="144" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9ae01669-941c-4704-ad75-781aea973249_429x144.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:144,&quot;width&quot;:429,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:9420,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/189742643?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ae01669-941c-4704-ad75-781aea973249_429x144.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!K1rH!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ae01669-941c-4704-ad75-781aea973249_429x144.png 424w, https://substackcdn.com/image/fetch/$s_!K1rH!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ae01669-941c-4704-ad75-781aea973249_429x144.png 848w, https://substackcdn.com/image/fetch/$s_!K1rH!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ae01669-941c-4704-ad75-781aea973249_429x144.png 1272w, https://substackcdn.com/image/fetch/$s_!K1rH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ae01669-941c-4704-ad75-781aea973249_429x144.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Upon SMS permission being granted, the malware queries the system SMS content provider to extract all messages.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1EcE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F034bb2bf-c2b5-4658-85fe-43e9690b554b_632x158.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1EcE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F034bb2bf-c2b5-4658-85fe-43e9690b554b_632x158.png 424w, https://substackcdn.com/image/fetch/$s_!1EcE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F034bb2bf-c2b5-4658-85fe-43e9690b554b_632x158.png 848w, https://substackcdn.com/image/fetch/$s_!1EcE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F034bb2bf-c2b5-4658-85fe-43e9690b554b_632x158.png 1272w, https://substackcdn.com/image/fetch/$s_!1EcE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F034bb2bf-c2b5-4658-85fe-43e9690b554b_632x158.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1EcE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F034bb2bf-c2b5-4658-85fe-43e9690b554b_632x158.png" width="632" height="158" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/034bb2bf-c2b5-4658-85fe-43e9690b554b_632x158.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:158,&quot;width&quot;:632,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:19485,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/189742643?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F034bb2bf-c2b5-4658-85fe-43e9690b554b_632x158.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!1EcE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F034bb2bf-c2b5-4658-85fe-43e9690b554b_632x158.png 424w, https://substackcdn.com/image/fetch/$s_!1EcE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F034bb2bf-c2b5-4658-85fe-43e9690b554b_632x158.png 848w, https://substackcdn.com/image/fetch/$s_!1EcE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F034bb2bf-c2b5-4658-85fe-43e9690b554b_632x158.png 1272w, https://substackcdn.com/image/fetch/$s_!1EcE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F034bb2bf-c2b5-4658-85fe-43e9690b554b_632x158.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>The contacts collector queries three Android content providers to build complete contact profiles. Among the contact harvesting sources queried are primary contact records, phone numbers, and email addresses.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!kh6Y!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26c2fe57-d53f-4e99-983a-69a4c49a6244_558x146.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!kh6Y!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26c2fe57-d53f-4e99-983a-69a4c49a6244_558x146.png 424w, https://substackcdn.com/image/fetch/$s_!kh6Y!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26c2fe57-d53f-4e99-983a-69a4c49a6244_558x146.png 848w, https://substackcdn.com/image/fetch/$s_!kh6Y!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26c2fe57-d53f-4e99-983a-69a4c49a6244_558x146.png 1272w, https://substackcdn.com/image/fetch/$s_!kh6Y!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26c2fe57-d53f-4e99-983a-69a4c49a6244_558x146.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!kh6Y!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26c2fe57-d53f-4e99-983a-69a4c49a6244_558x146.png" width="558" height="146" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/26c2fe57-d53f-4e99-983a-69a4c49a6244_558x146.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:146,&quot;width&quot;:558,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:17094,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/189742643?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26c2fe57-d53f-4e99-983a-69a4c49a6244_558x146.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!kh6Y!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26c2fe57-d53f-4e99-983a-69a4c49a6244_558x146.png 424w, https://substackcdn.com/image/fetch/$s_!kh6Y!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26c2fe57-d53f-4e99-983a-69a4c49a6244_558x146.png 848w, https://substackcdn.com/image/fetch/$s_!kh6Y!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26c2fe57-d53f-4e99-983a-69a4c49a6244_558x146.png 1272w, https://substackcdn.com/image/fetch/$s_!kh6Y!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26c2fe57-d53f-4e99-983a-69a4c49a6244_558x146.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>The <code>border </code>class implements continuous GPS tracking using the Android <code>LocationManager </code>API with a <code>LocationListener </code>callback. Among the captured data are latitude, longitude, speed, accuracy, mock location detection. The listener runs continuously, and each location update is serialized and queued for exfiltration.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!glLJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22fcea8e-3be3-4445-8ccc-24d5c15e7234_597x99.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!glLJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22fcea8e-3be3-4445-8ccc-24d5c15e7234_597x99.png 424w, https://substackcdn.com/image/fetch/$s_!glLJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22fcea8e-3be3-4445-8ccc-24d5c15e7234_597x99.png 848w, https://substackcdn.com/image/fetch/$s_!glLJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22fcea8e-3be3-4445-8ccc-24d5c15e7234_597x99.png 1272w, https://substackcdn.com/image/fetch/$s_!glLJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22fcea8e-3be3-4445-8ccc-24d5c15e7234_597x99.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!glLJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22fcea8e-3be3-4445-8ccc-24d5c15e7234_597x99.png" width="597" height="99" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/22fcea8e-3be3-4445-8ccc-24d5c15e7234_597x99.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:99,&quot;width&quot;:597,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:9463,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/189742643?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22fcea8e-3be3-4445-8ccc-24d5c15e7234_597x99.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!glLJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22fcea8e-3be3-4445-8ccc-24d5c15e7234_597x99.png 424w, https://substackcdn.com/image/fetch/$s_!glLJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22fcea8e-3be3-4445-8ccc-24d5c15e7234_597x99.png 848w, https://substackcdn.com/image/fetch/$s_!glLJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22fcea8e-3be3-4445-8ccc-24d5c15e7234_597x99.png 1272w, https://substackcdn.com/image/fetch/$s_!glLJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22fcea8e-3be3-4445-8ccc-24d5c15e7234_597x99.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>The <code>bestrut </code>class enumerates all installed applications. <br>It uses <code>PackageManager.getInstalledPackages()</code> with <code>QUERY_ALL_PACKAGES</code> permissions to retrieve a complete list. For each package, the malware collects the package name and application label, and builds a JSON array for exfiltration. <br>The resulting data is categorized under<code> crisped.Outports</code> and written to the exfiltration queue.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!yXuu!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f565737-e6c1-4b6b-8b50-17593e7fe351_559x96.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!yXuu!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f565737-e6c1-4b6b-8b50-17593e7fe351_559x96.png 424w, https://substackcdn.com/image/fetch/$s_!yXuu!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f565737-e6c1-4b6b-8b50-17593e7fe351_559x96.png 848w, https://substackcdn.com/image/fetch/$s_!yXuu!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f565737-e6c1-4b6b-8b50-17593e7fe351_559x96.png 1272w, https://substackcdn.com/image/fetch/$s_!yXuu!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f565737-e6c1-4b6b-8b50-17593e7fe351_559x96.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!yXuu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f565737-e6c1-4b6b-8b50-17593e7fe351_559x96.png" width="559" height="96" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6f565737-e6c1-4b6b-8b50-17593e7fe351_559x96.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:96,&quot;width&quot;:559,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:9627,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/189742643?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f565737-e6c1-4b6b-8b50-17593e7fe351_559x96.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!yXuu!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f565737-e6c1-4b6b-8b50-17593e7fe351_559x96.png 424w, https://substackcdn.com/image/fetch/$s_!yXuu!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f565737-e6c1-4b6b-8b50-17593e7fe351_559x96.png 848w, https://substackcdn.com/image/fetch/$s_!yXuu!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f565737-e6c1-4b6b-8b50-17593e7fe351_559x96.png 1272w, https://substackcdn.com/image/fetch/$s_!yXuu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f565737-e6c1-4b6b-8b50-17593e7fe351_559x96.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>The <code>unblest </code>class steals all accounts registered on the device. <br>It uses <code>AccountManager.getAccounts()</code> to iterate all device accounts. <br>For each account, extracts <code>account.type</code> (for example &#8220;com.google&#8221;) and <code>account.name</code> (email address). It also collects the device&#8217;s <code>android_id</code> using <code>Settings.Secure</code>. The Data is serialized as JSON and submitted under the <code>Ploying </code>category.</p><h4><strong>Continuous Exfiltration - The Infinite Upload Loop</strong></h4><p>The overhot class implements an infinite upload loop that continuously polls for queued data files across all stolen categories. The malware iterates through types (SMS, GPS, Contacts), inserting a 500ms delay between categories to maintain a low processing profile.</p><p>To further evade detection by automated analysis tools, the exfiltration logic utilizes Java Reflection within the Plumbers class. By reflectively invoking the HTTP upload handler, the malware decouples the data collection logic from the network transmission layer, making it significantly harder for security products to map the full execution chain from file creation to remote exfiltration.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!jq2e!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F207f6e59-becb-4d5f-97ae-caf1f641bada_673x428.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!jq2e!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F207f6e59-becb-4d5f-97ae-caf1f641bada_673x428.png 424w, https://substackcdn.com/image/fetch/$s_!jq2e!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F207f6e59-becb-4d5f-97ae-caf1f641bada_673x428.png 848w, https://substackcdn.com/image/fetch/$s_!jq2e!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F207f6e59-becb-4d5f-97ae-caf1f641bada_673x428.png 1272w, https://substackcdn.com/image/fetch/$s_!jq2e!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F207f6e59-becb-4d5f-97ae-caf1f641bada_673x428.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!jq2e!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F207f6e59-becb-4d5f-97ae-caf1f641bada_673x428.png" width="673" height="428" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/207f6e59-becb-4d5f-97ae-caf1f641bada_673x428.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:428,&quot;width&quot;:673,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:44079,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/189742643?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F207f6e59-becb-4d5f-97ae-caf1f641bada_673x428.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!jq2e!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F207f6e59-becb-4d5f-97ae-caf1f641bada_673x428.png 424w, https://substackcdn.com/image/fetch/$s_!jq2e!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F207f6e59-becb-4d5f-97ae-caf1f641bada_673x428.png 848w, https://substackcdn.com/image/fetch/$s_!jq2e!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F207f6e59-becb-4d5f-97ae-caf1f641bada_673x428.png 1272w, https://substackcdn.com/image/fetch/$s_!jq2e!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F207f6e59-becb-4d5f-97ae-caf1f641bada_673x428.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>And the Upload call chain:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!TrUB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca18b043-c89c-4d19-a80b-7d042d154bb3_700x249.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!TrUB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca18b043-c89c-4d19-a80b-7d042d154bb3_700x249.png 424w, https://substackcdn.com/image/fetch/$s_!TrUB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca18b043-c89c-4d19-a80b-7d042d154bb3_700x249.png 848w, https://substackcdn.com/image/fetch/$s_!TrUB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca18b043-c89c-4d19-a80b-7d042d154bb3_700x249.png 1272w, https://substackcdn.com/image/fetch/$s_!TrUB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca18b043-c89c-4d19-a80b-7d042d154bb3_700x249.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!TrUB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca18b043-c89c-4d19-a80b-7d042d154bb3_700x249.png" width="700" height="249" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ca18b043-c89c-4d19-a80b-7d042d154bb3_700x249.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:249,&quot;width&quot;:700,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:26743,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/189742643?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca18b043-c89c-4d19-a80b-7d042d154bb3_700x249.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!TrUB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca18b043-c89c-4d19-a80b-7d042d154bb3_700x249.png 424w, https://substackcdn.com/image/fetch/$s_!TrUB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca18b043-c89c-4d19-a80b-7d042d154bb3_700x249.png 848w, https://substackcdn.com/image/fetch/$s_!TrUB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca18b043-c89c-4d19-a80b-7d042d154bb3_700x249.png 1272w, https://substackcdn.com/image/fetch/$s_!TrUB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca18b043-c89c-4d19-a80b-7d042d154bb3_700x249.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h4><strong>Command And Control - Push-Based Surveillance</strong></h4><p>The APK integrates Firebase Cloud Messaging (FCM) to establish a high-efficiency, push-based C2 channel, which allows threat actors to issue real-time operational commands, such as forcing an immediate data collection cycle or waking the device, without the noise of constant polling.</p><p>By embedding these references in <code>firebase_common_keep.xml</code>, the malware maintains a persistent link to the attackers&#8217; infrastructure.</p><p>The core of the spyware&#8217;s power lies in its Invasive Permission Model. <br>Beyond the standard notification and location access expected from a &#8220;Red Alert&#8221; app, it harvests SMS, contacts, and account data. <br>Crucially, the <code>RECEIVE_BOOT_COMPLETED</code> permission ensures long-term persistence, re-launching the malicious background services automatically upon device reboot, effectively turning the phone into a continuous surveillance tool.</p><p>Because the app impersonates a rocket alert system in such tense times, users are highly motivated to grant all permissions immediately. <br>Location access is expected for a regional alert app, notification permission is essential for alerts, but the remaining permissions (SMS, contacts, accounts) are less expected but are likely granted without question by users anxious to enable life-safety alerts quickly.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!LNZL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd572cc65-1c58-425d-9d6d-2d69bd94c8e3_569x403.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!LNZL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd572cc65-1c58-425d-9d6d-2d69bd94c8e3_569x403.png 424w, https://substackcdn.com/image/fetch/$s_!LNZL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd572cc65-1c58-425d-9d6d-2d69bd94c8e3_569x403.png 848w, https://substackcdn.com/image/fetch/$s_!LNZL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd572cc65-1c58-425d-9d6d-2d69bd94c8e3_569x403.png 1272w, https://substackcdn.com/image/fetch/$s_!LNZL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd572cc65-1c58-425d-9d6d-2d69bd94c8e3_569x403.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!LNZL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd572cc65-1c58-425d-9d6d-2d69bd94c8e3_569x403.png" width="569" height="403" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d572cc65-1c58-425d-9d6d-2d69bd94c8e3_569x403.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:403,&quot;width&quot;:569,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:23692,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/189742643?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd572cc65-1c58-425d-9d6d-2d69bd94c8e3_569x403.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!LNZL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd572cc65-1c58-425d-9d6d-2d69bd94c8e3_569x403.png 424w, https://substackcdn.com/image/fetch/$s_!LNZL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd572cc65-1c58-425d-9d6d-2d69bd94c8e3_569x403.png 848w, https://substackcdn.com/image/fetch/$s_!LNZL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd572cc65-1c58-425d-9d6d-2d69bd94c8e3_569x403.png 1272w, https://substackcdn.com/image/fetch/$s_!LNZL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd572cc65-1c58-425d-9d6d-2d69bd94c8e3_569x403.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h4><strong>Siren Song - The Axis of Resistance Spyware Evolution</strong></h4><p>Current analysis reveals a significant operational shift in the &#8220;Red Alert&#8221; malware campaign. While the initial infrastructure originated with the Hamas-affiliated APT-C-23 (Arid Viper), the latest iterations exhibit direct involvement by Iranian-backed threat groups.</p><p>This transition indicates a strategic handover or deep operational synergy within the &#8220;Axis of Resistance,&#8221; aimed at intensifying intelligence collection during the ongoing conflict.</p><p>Operational continuity is maintained through the C2 domain <code>ra-backup[.]com</code>, which leverages the &#8220;Red Alert&#8221; (RA) acronym and a &#8220;cloud backup&#8221; pretext for exfiltration. While the use of api. subdomains and SaaS-like URI paths mirrors Arid Viper&#8217;s historical TTPs, the current versions show higher technical refinement and a broader scope, now targeting Russian and English speakers alongside Hebrew and Arabic users to meet Iranian state-level requirements.</p><p>A critical link between these versions is a unique &#8220;lexical fingerprint&#8221;, a custom obfuscation engine utilizing obscure English and ethnographic terms.</p><p>The persistence of this proprietary tool confirms that Hamas&#8217;s technical assets have been integrated into an Iranian-managed pipeline, upgrading the spyware into a sophisticated state-level espionage tool.</p><p>The convergence of TTPs, from the 2023 patterns to the current technological surge, indicates a coordinated joint venture with Medium-High confidence.</p><p>The shift from a Hamas-led effort to an Iranian-orchestrated operation underscores the systematic weaponization of a life-saving application into a tool for both signals intelligence and psychological warfare.</p><h4><strong>Relevant IOCs</strong></h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!VVMV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8169853-a359-4c68-9e47-9b5ff519aebd_611x766.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!VVMV!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8169853-a359-4c68-9e47-9b5ff519aebd_611x766.png 424w, https://substackcdn.com/image/fetch/$s_!VVMV!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8169853-a359-4c68-9e47-9b5ff519aebd_611x766.png 848w, https://substackcdn.com/image/fetch/$s_!VVMV!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8169853-a359-4c68-9e47-9b5ff519aebd_611x766.png 1272w, https://substackcdn.com/image/fetch/$s_!VVMV!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8169853-a359-4c68-9e47-9b5ff519aebd_611x766.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!VVMV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8169853-a359-4c68-9e47-9b5ff519aebd_611x766.png" width="611" height="766" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e8169853-a359-4c68-9e47-9b5ff519aebd_611x766.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:766,&quot;width&quot;:611,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:32297,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/189742643?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8169853-a359-4c68-9e47-9b5ff519aebd_611x766.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!VVMV!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8169853-a359-4c68-9e47-9b5ff519aebd_611x766.png 424w, https://substackcdn.com/image/fetch/$s_!VVMV!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8169853-a359-4c68-9e47-9b5ff519aebd_611x766.png 848w, https://substackcdn.com/image/fetch/$s_!VVMV!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8169853-a359-4c68-9e47-9b5ff519aebd_611x766.png 1272w, https://substackcdn.com/image/fetch/$s_!VVMV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8169853-a359-4c68-9e47-9b5ff519aebd_611x766.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.darksignal.co/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[
BreachForums - A Comeback Or A Scam?]]></title><description><![CDATA[BreachForums - The Return]]></description><link>https://www.darksignal.co/p/breachforums-a-comeback-or-a-scam</link><guid isPermaLink="false">https://www.darksignal.co/p/breachforums-a-comeback-or-a-scam</guid><dc:creator><![CDATA[DarkSignal]]></dc:creator><pubDate>Mon, 26 Jan 2026 08:20:18 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!YUzk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90040251-d9d0-4a19-a38b-cdd0610f0f18_800x1079.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!YUzk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90040251-d9d0-4a19-a38b-cdd0610f0f18_800x1079.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!YUzk!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90040251-d9d0-4a19-a38b-cdd0610f0f18_800x1079.jpeg 424w, https://substackcdn.com/image/fetch/$s_!YUzk!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90040251-d9d0-4a19-a38b-cdd0610f0f18_800x1079.jpeg 848w, https://substackcdn.com/image/fetch/$s_!YUzk!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90040251-d9d0-4a19-a38b-cdd0610f0f18_800x1079.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!YUzk!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90040251-d9d0-4a19-a38b-cdd0610f0f18_800x1079.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!YUzk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90040251-d9d0-4a19-a38b-cdd0610f0f18_800x1079.jpeg" width="800" height="1079" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/90040251-d9d0-4a19-a38b-cdd0610f0f18_800x1079.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1079,&quot;width&quot;:800,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:331614,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/185280795?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7eb0cabe-f886-449e-864f-d1d486dbd12c_800x1200.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!YUzk!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90040251-d9d0-4a19-a38b-cdd0610f0f18_800x1079.jpeg 424w, https://substackcdn.com/image/fetch/$s_!YUzk!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90040251-d9d0-4a19-a38b-cdd0610f0f18_800x1079.jpeg 848w, https://substackcdn.com/image/fetch/$s_!YUzk!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90040251-d9d0-4a19-a38b-cdd0610f0f18_800x1079.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!YUzk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90040251-d9d0-4a19-a38b-cdd0610f0f18_800x1079.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>BreachForums - The Return</strong></h2><p><strong>BreachForums</strong> is an English-language cybercrime forum that operates as a black-hat marketplace and community, facilitating the exchange of information about data breaches, the sale of stolen databases, hacking tools, and other illicit services. It was created to replace RaidForums, which was seized and taken offline by law enforcement authorities in 2022.</p><p>It was launched in March 2022 by Conor Brian Fitzpatrick, known online as &#8220;pompompurin,&#8221; shortly after the takedown of RaidForums. On March 21, 2023, the forum was shut down following Fitzpatrick&#8217;s arrest. After this takedown, BreachForums re-emerged under new administrators and moderators, including actors associated with <strong>ShinyHunters</strong> and <strong>IntelBroker</strong>.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.darksignal.co/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Since then, the forum has repeatedly resurfaced using dozens of domains and mirrors, operating across both the TOR network and various clearnet domains (current is breachforums[.]bf), many of which were later seized or disrupted by law enforcement, which resulted in several cycles of shutdowns and re-launches over time.</p><p>ShinyHunters, an established cybercrime group active since around 2020, has been publicly linked to BreachForums as a key actor involved in its revival and partial administration following the arrest of its original founder.</p><p>In addition, BreachForums has been repeatedly associated with activity attributed to <strong>Lapsus$</strong> and related clusters. In 2024-2025, an overlap between BreachForums infrastructure and actors described as &#8220;Scattered Lapsus$ Hunters,&#8221; a loose alignment of individuals linked to Lapsus$, Scattered Spider, and ShinyHunters was identified.</p><p>This report is an intelligence-driven analysis that correlates technical infrastructure, threat actors, and exposed data to connect disparate indicators and build a coherent intelligence picture. By linking platforms, domains, operational artifacts, and known groups, the report moves beyond isolated findings and contextualizes them within a broader ecosystem, enabling a deeper understanding of how the infrastructure, actors, and activities interrelate and what they reveal about the underlying narrative behind the observed events.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Ol_v!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80e4864b-0462-4c99-adc3-018a9c7fb503_1083x610.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Ol_v!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80e4864b-0462-4c99-adc3-018a9c7fb503_1083x610.png 424w, https://substackcdn.com/image/fetch/$s_!Ol_v!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80e4864b-0462-4c99-adc3-018a9c7fb503_1083x610.png 848w, https://substackcdn.com/image/fetch/$s_!Ol_v!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80e4864b-0462-4c99-adc3-018a9c7fb503_1083x610.png 1272w, https://substackcdn.com/image/fetch/$s_!Ol_v!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80e4864b-0462-4c99-adc3-018a9c7fb503_1083x610.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Ol_v!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80e4864b-0462-4c99-adc3-018a9c7fb503_1083x610.png" width="1083" height="610" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/80e4864b-0462-4c99-adc3-018a9c7fb503_1083x610.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:610,&quot;width&quot;:1083,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:113466,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/185280795?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80e4864b-0462-4c99-adc3-018a9c7fb503_1083x610.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Ol_v!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80e4864b-0462-4c99-adc3-018a9c7fb503_1083x610.png 424w, https://substackcdn.com/image/fetch/$s_!Ol_v!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80e4864b-0462-4c99-adc3-018a9c7fb503_1083x610.png 848w, https://substackcdn.com/image/fetch/$s_!Ol_v!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80e4864b-0462-4c99-adc3-018a9c7fb503_1083x610.png 1272w, https://substackcdn.com/image/fetch/$s_!Ol_v!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80e4864b-0462-4c99-adc3-018a9c7fb503_1083x610.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>From Dead End to First Exposure</strong></h2><p>First, I started with the given, the domain name (breachforums[.]bf).<br>No WHOIS records, it wasn&#8217;t part of data leaks or any scraped data, and I couldn&#8217;t find any relevant leads based on the official domain name.<br>The IP address that was resolved by the domain is 95[.]129[.]233[.]76, and when I searched for it, I saw it&#8217;s a DDoS protection service and not the real IP of the domain.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!S5Di!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fc75754-a7f3-430c-bae6-54346a97825e_1028x346.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!S5Di!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fc75754-a7f3-430c-bae6-54346a97825e_1028x346.png 424w, https://substackcdn.com/image/fetch/$s_!S5Di!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fc75754-a7f3-430c-bae6-54346a97825e_1028x346.png 848w, https://substackcdn.com/image/fetch/$s_!S5Di!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fc75754-a7f3-430c-bae6-54346a97825e_1028x346.png 1272w, https://substackcdn.com/image/fetch/$s_!S5Di!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fc75754-a7f3-430c-bae6-54346a97825e_1028x346.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!S5Di!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fc75754-a7f3-430c-bae6-54346a97825e_1028x346.png" width="1028" height="346" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3fc75754-a7f3-430c-bae6-54346a97825e_1028x346.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:346,&quot;width&quot;:1028,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:34763,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/185280795?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fc75754-a7f3-430c-bae6-54346a97825e_1028x346.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!S5Di!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fc75754-a7f3-430c-bae6-54346a97825e_1028x346.png 424w, https://substackcdn.com/image/fetch/$s_!S5Di!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fc75754-a7f3-430c-bae6-54346a97825e_1028x346.png 848w, https://substackcdn.com/image/fetch/$s_!S5Di!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fc75754-a7f3-430c-bae6-54346a97825e_1028x346.png 1272w, https://substackcdn.com/image/fetch/$s_!S5Di!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fc75754-a7f3-430c-bae6-54346a97825e_1028x346.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>I ran a custom enumeration script (fuzzer) on the domain and found few misconfigurations that led me to status code 200 (HTTP OK), as most of them were unreliable and just refreshed the page to the home page of Breachforums, few led me to see sensitive details that provided me with further understanding about the infrastructure and the assets related to the operation.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!suzH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F035dc25e-0a28-4c8e-9d44-26c248d3761e_1657x800.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!suzH!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F035dc25e-0a28-4c8e-9d44-26c248d3761e_1657x800.png 424w, https://substackcdn.com/image/fetch/$s_!suzH!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F035dc25e-0a28-4c8e-9d44-26c248d3761e_1657x800.png 848w, https://substackcdn.com/image/fetch/$s_!suzH!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F035dc25e-0a28-4c8e-9d44-26c248d3761e_1657x800.png 1272w, https://substackcdn.com/image/fetch/$s_!suzH!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F035dc25e-0a28-4c8e-9d44-26c248d3761e_1657x800.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!suzH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F035dc25e-0a28-4c8e-9d44-26c248d3761e_1657x800.png" width="1456" height="703" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/035dc25e-0a28-4c8e-9d44-26c248d3761e_1657x800.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:703,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:185739,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/185280795?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F035dc25e-0a28-4c8e-9d44-26c248d3761e_1657x800.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!suzH!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F035dc25e-0a28-4c8e-9d44-26c248d3761e_1657x800.png 424w, https://substackcdn.com/image/fetch/$s_!suzH!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F035dc25e-0a28-4c8e-9d44-26c248d3761e_1657x800.png 848w, https://substackcdn.com/image/fetch/$s_!suzH!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F035dc25e-0a28-4c8e-9d44-26c248d3761e_1657x800.png 1272w, https://substackcdn.com/image/fetch/$s_!suzH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F035dc25e-0a28-4c8e-9d44-26c248d3761e_1657x800.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>I was able to see the php_errors.log page, publicly disclose the PHP error log containing repeated PHP Parse errors indicating a syntax issue (&#8220;Unclosed (&#8221;) within a specific file: <code>/var/www/html/cache/ougc_awards.php</code>.</p><p>This file appears to be an automatically generated cache file, likely associated with a MyBB plugin such as OUGC Awards. The fact that these errors are logged dozens of times within short time intervals indicates that the server repeatedly attempts to load a corrupted or malformed cache file, pointing to poor maintenance, a failed update, or an improper system configuration.</p><p>The log discloses the server&#8217;s full filesystem path, precise technology stack (PHP with MyBB), a specific module, directory structure, activity timestamps, and the frequency of recurring errors, all provides the ability to map infrastructure and operational processes, identifying active components and plugins, and collect other crucial intelligence.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!t7Wi!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a98ecc0-62df-49d4-b935-e563f1a59cb4_1191x318.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!t7Wi!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a98ecc0-62df-49d4-b935-e563f1a59cb4_1191x318.png 424w, https://substackcdn.com/image/fetch/$s_!t7Wi!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a98ecc0-62df-49d4-b935-e563f1a59cb4_1191x318.png 848w, https://substackcdn.com/image/fetch/$s_!t7Wi!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a98ecc0-62df-49d4-b935-e563f1a59cb4_1191x318.png 1272w, https://substackcdn.com/image/fetch/$s_!t7Wi!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a98ecc0-62df-49d4-b935-e563f1a59cb4_1191x318.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!t7Wi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a98ecc0-62df-49d4-b935-e563f1a59cb4_1191x318.png" width="1191" height="318" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7a98ecc0-62df-49d4-b935-e563f1a59cb4_1191x318.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:318,&quot;width&quot;:1191,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:68244,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/185280795?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a98ecc0-62df-49d4-b935-e563f1a59cb4_1191x318.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!t7Wi!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a98ecc0-62df-49d4-b935-e563f1a59cb4_1191x318.png 424w, https://substackcdn.com/image/fetch/$s_!t7Wi!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a98ecc0-62df-49d4-b935-e563f1a59cb4_1191x318.png 848w, https://substackcdn.com/image/fetch/$s_!t7Wi!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a98ecc0-62df-49d4-b935-e563f1a59cb4_1191x318.png 1272w, https://substackcdn.com/image/fetch/$s_!t7Wi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a98ecc0-62df-49d4-b935-e563f1a59cb4_1191x318.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The user enumeration inside the website is not configured correctly and allowed me to view all of the users by their joining date and asses by that who the current admins.</p><p><code>https://www.breachforums[.]bf/ member.php?action=profile&amp;uid=1</code><em> </em>provided the admin of the forum, and all I needed is to change the number to 2, 3, and going to check the other users. Number 2, by the way, revealed that ShinyHunters is the admin as well.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!gPbJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fd8bf83-0560-4600-8ef9-559b2e393ebf_805x731.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gPbJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fd8bf83-0560-4600-8ef9-559b2e393ebf_805x731.png 424w, https://substackcdn.com/image/fetch/$s_!gPbJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fd8bf83-0560-4600-8ef9-559b2e393ebf_805x731.png 848w, https://substackcdn.com/image/fetch/$s_!gPbJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fd8bf83-0560-4600-8ef9-559b2e393ebf_805x731.png 1272w, https://substackcdn.com/image/fetch/$s_!gPbJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fd8bf83-0560-4600-8ef9-559b2e393ebf_805x731.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gPbJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fd8bf83-0560-4600-8ef9-559b2e393ebf_805x731.png" width="805" height="731" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4fd8bf83-0560-4600-8ef9-559b2e393ebf_805x731.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:731,&quot;width&quot;:805,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:122606,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/185280795?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdbb9968d-b741-4094-a18d-aa4311ee9f12_805x1001.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!gPbJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fd8bf83-0560-4600-8ef9-559b2e393ebf_805x731.png 424w, https://substackcdn.com/image/fetch/$s_!gPbJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fd8bf83-0560-4600-8ef9-559b2e393ebf_805x731.png 848w, https://substackcdn.com/image/fetch/$s_!gPbJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fd8bf83-0560-4600-8ef9-559b2e393ebf_805x731.png 1272w, https://substackcdn.com/image/fetch/$s_!gPbJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fd8bf83-0560-4600-8ef9-559b2e393ebf_805x731.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Another misconfiguration that provided me with trustworthy intelligence is the fact that <code>https://breachforums[.]bf/BingSiteAuth[.]xml</code><em> </em>is widely accessible and provided me with the user's one-time hash for SEO purposes.</p><p>The <code>BingSiteAuth.xml</code> file is a standard ownership-verification file used by Microsoft Bing to confirm control over a domain, and its presence indicates that the site operators had (or still have) write access to the web root, reflecting full operational control of the domain at a given point in time.</p><p>Beyond simple verification, it confirms the deliberate use of official SEO and webmaster tools, suggesting that the site was intended for indexing, visibility, and sustained presence in search engines rather than being a short-lived or purely temporary deployment.</p><p>When correlated with server logs (that already been partly exposed), infrastructure changes, and domain activity, the file can help establish a timeline showing when the site reached an operational stage suitable for public indexing.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!N5Kk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F287acbd1-2631-420b-8cdc-eb68e1da1bd0_973x263.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!N5Kk!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F287acbd1-2631-420b-8cdc-eb68e1da1bd0_973x263.png 424w, https://substackcdn.com/image/fetch/$s_!N5Kk!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F287acbd1-2631-420b-8cdc-eb68e1da1bd0_973x263.png 848w, https://substackcdn.com/image/fetch/$s_!N5Kk!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F287acbd1-2631-420b-8cdc-eb68e1da1bd0_973x263.png 1272w, https://substackcdn.com/image/fetch/$s_!N5Kk!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F287acbd1-2631-420b-8cdc-eb68e1da1bd0_973x263.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!N5Kk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F287acbd1-2631-420b-8cdc-eb68e1da1bd0_973x263.png" width="973" height="263" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/287acbd1-2631-420b-8cdc-eb68e1da1bd0_973x263.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:263,&quot;width&quot;:973,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:35050,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/185280795?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F287acbd1-2631-420b-8cdc-eb68e1da1bd0_973x263.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!N5Kk!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F287acbd1-2631-420b-8cdc-eb68e1da1bd0_973x263.png 424w, https://substackcdn.com/image/fetch/$s_!N5Kk!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F287acbd1-2631-420b-8cdc-eb68e1da1bd0_973x263.png 848w, https://substackcdn.com/image/fetch/$s_!N5Kk!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F287acbd1-2631-420b-8cdc-eb68e1da1bd0_973x263.png 1272w, https://substackcdn.com/image/fetch/$s_!N5Kk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F287acbd1-2631-420b-8cdc-eb68e1da1bd0_973x263.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Identifying The Operational Core</strong></h2><p>When searching for the domain name using indexing search engines, I noticed the IP repeated IP address 95[.]129[.]233[.]76 (the DDoS guard) and 104[.]21[.]51[.]126, which is directly related to ShinyHunters and Lapsus&#8217; infrastructure, all say it&#8217;s not the real IP address I&#8217;m searching for.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!nPMu!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7bf5f554-cbf6-4fc2-af48-bf394a1af0d3_1577x478.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!nPMu!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7bf5f554-cbf6-4fc2-af48-bf394a1af0d3_1577x478.png 424w, https://substackcdn.com/image/fetch/$s_!nPMu!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7bf5f554-cbf6-4fc2-af48-bf394a1af0d3_1577x478.png 848w, https://substackcdn.com/image/fetch/$s_!nPMu!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7bf5f554-cbf6-4fc2-af48-bf394a1af0d3_1577x478.png 1272w, https://substackcdn.com/image/fetch/$s_!nPMu!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7bf5f554-cbf6-4fc2-af48-bf394a1af0d3_1577x478.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!nPMu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7bf5f554-cbf6-4fc2-af48-bf394a1af0d3_1577x478.png" width="1456" height="441" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7bf5f554-cbf6-4fc2-af48-bf394a1af0d3_1577x478.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:441,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:77554,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/185280795?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7bf5f554-cbf6-4fc2-af48-bf394a1af0d3_1577x478.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!nPMu!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7bf5f554-cbf6-4fc2-af48-bf394a1af0d3_1577x478.png 424w, https://substackcdn.com/image/fetch/$s_!nPMu!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7bf5f554-cbf6-4fc2-af48-bf394a1af0d3_1577x478.png 848w, https://substackcdn.com/image/fetch/$s_!nPMu!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7bf5f554-cbf6-4fc2-af48-bf394a1af0d3_1577x478.png 1272w, https://substackcdn.com/image/fetch/$s_!nPMu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7bf5f554-cbf6-4fc2-af48-bf394a1af0d3_1577x478.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!aSFj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34c5ff91-a808-486e-928b-de7b41eac49c_1596x483.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!aSFj!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34c5ff91-a808-486e-928b-de7b41eac49c_1596x483.png 424w, https://substackcdn.com/image/fetch/$s_!aSFj!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34c5ff91-a808-486e-928b-de7b41eac49c_1596x483.png 848w, https://substackcdn.com/image/fetch/$s_!aSFj!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34c5ff91-a808-486e-928b-de7b41eac49c_1596x483.png 1272w, https://substackcdn.com/image/fetch/$s_!aSFj!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34c5ff91-a808-486e-928b-de7b41eac49c_1596x483.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!aSFj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34c5ff91-a808-486e-928b-de7b41eac49c_1596x483.png" width="1456" height="441" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/34c5ff91-a808-486e-928b-de7b41eac49c_1596x483.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:441,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:73021,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/185280795?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34c5ff91-a808-486e-928b-de7b41eac49c_1596x483.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!aSFj!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34c5ff91-a808-486e-928b-de7b41eac49c_1596x483.png 424w, https://substackcdn.com/image/fetch/$s_!aSFj!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34c5ff91-a808-486e-928b-de7b41eac49c_1596x483.png 848w, https://substackcdn.com/image/fetch/$s_!aSFj!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34c5ff91-a808-486e-928b-de7b41eac49c_1596x483.png 1272w, https://substackcdn.com/image/fetch/$s_!aSFj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34c5ff91-a808-486e-928b-de7b41eac49c_1596x483.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Rbi4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd7b8333-2dc5-4440-8770-206b92abebf4_1580x474.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Rbi4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd7b8333-2dc5-4440-8770-206b92abebf4_1580x474.png 424w, https://substackcdn.com/image/fetch/$s_!Rbi4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd7b8333-2dc5-4440-8770-206b92abebf4_1580x474.png 848w, https://substackcdn.com/image/fetch/$s_!Rbi4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd7b8333-2dc5-4440-8770-206b92abebf4_1580x474.png 1272w, https://substackcdn.com/image/fetch/$s_!Rbi4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd7b8333-2dc5-4440-8770-206b92abebf4_1580x474.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Rbi4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd7b8333-2dc5-4440-8770-206b92abebf4_1580x474.png" width="1456" height="437" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dd7b8333-2dc5-4440-8770-206b92abebf4_1580x474.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:437,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:73726,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/185280795?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd7b8333-2dc5-4440-8770-206b92abebf4_1580x474.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Rbi4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd7b8333-2dc5-4440-8770-206b92abebf4_1580x474.png 424w, https://substackcdn.com/image/fetch/$s_!Rbi4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd7b8333-2dc5-4440-8770-206b92abebf4_1580x474.png 848w, https://substackcdn.com/image/fetch/$s_!Rbi4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd7b8333-2dc5-4440-8770-206b92abebf4_1580x474.png 1272w, https://substackcdn.com/image/fetch/$s_!Rbi4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd7b8333-2dc5-4440-8770-206b92abebf4_1580x474.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>But one IP address stood out - 45[.]134[.]26[.]22, that leads directly to the domain of breachforums[.]bf.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!8kL8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8949781a-9943-4090-8ce1-ea882d462176_1568x410.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8kL8!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8949781a-9943-4090-8ce1-ea882d462176_1568x410.png 424w, https://substackcdn.com/image/fetch/$s_!8kL8!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8949781a-9943-4090-8ce1-ea882d462176_1568x410.png 848w, https://substackcdn.com/image/fetch/$s_!8kL8!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8949781a-9943-4090-8ce1-ea882d462176_1568x410.png 1272w, https://substackcdn.com/image/fetch/$s_!8kL8!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8949781a-9943-4090-8ce1-ea882d462176_1568x410.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8kL8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8949781a-9943-4090-8ce1-ea882d462176_1568x410.png" width="1456" height="381" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8949781a-9943-4090-8ce1-ea882d462176_1568x410.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:381,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:80384,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/185280795?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8949781a-9943-4090-8ce1-ea882d462176_1568x410.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!8kL8!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8949781a-9943-4090-8ce1-ea882d462176_1568x410.png 424w, https://substackcdn.com/image/fetch/$s_!8kL8!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8949781a-9943-4090-8ce1-ea882d462176_1568x410.png 848w, https://substackcdn.com/image/fetch/$s_!8kL8!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8949781a-9943-4090-8ce1-ea882d462176_1568x410.png 1272w, https://substackcdn.com/image/fetch/$s_!8kL8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8949781a-9943-4090-8ce1-ea882d462176_1568x410.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This IP address was exposed in an RDP handshake scan and reveals the remote desktop service (3389), which indicates a Windows server, probably the one that acts as the main station of operation.</p><p>The banner reveals detailed infrastructure information, from the IP which belongs to <strong>ASN 198953</strong> operated by <strong>Proton66</strong> in <strong>Russia (Saint Petersburg)</strong>, the system is running <strong>Windows Server 2019 / Windows 10 version 1809 (build 17763)</strong>, the authentication uses <strong>NTLM,</strong> and the internal machine identifier (Target Name and NetBIOS name) is <strong>WIN-QCQ1STQOM66</strong>.</p><p>From an intelligence perspective, this constitutes a <strong>full infrastructure fingerprint of a management server</strong>, exposing OS type and version, internal host name, hosting provider, and geolocation, indicating weak hardening, as we already saw before.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!T39p!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3cdd026-961a-4083-a65f-4b2967b72744_907x373.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!T39p!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3cdd026-961a-4083-a65f-4b2967b72744_907x373.png 424w, https://substackcdn.com/image/fetch/$s_!T39p!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3cdd026-961a-4083-a65f-4b2967b72744_907x373.png 848w, https://substackcdn.com/image/fetch/$s_!T39p!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3cdd026-961a-4083-a65f-4b2967b72744_907x373.png 1272w, https://substackcdn.com/image/fetch/$s_!T39p!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3cdd026-961a-4083-a65f-4b2967b72744_907x373.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!T39p!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3cdd026-961a-4083-a65f-4b2967b72744_907x373.png" width="907" height="373" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a3cdd026-961a-4083-a65f-4b2967b72744_907x373.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:373,&quot;width&quot;:907,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:29006,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/185280795?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3cdd026-961a-4083-a65f-4b2967b72744_907x373.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!T39p!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3cdd026-961a-4083-a65f-4b2967b72744_907x373.png 424w, https://substackcdn.com/image/fetch/$s_!T39p!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3cdd026-961a-4083-a65f-4b2967b72744_907x373.png 848w, https://substackcdn.com/image/fetch/$s_!T39p!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3cdd026-961a-4083-a65f-4b2967b72744_907x373.png 1272w, https://substackcdn.com/image/fetch/$s_!T39p!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3cdd026-961a-4083-a65f-4b2967b72744_907x373.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This IP address was shown with port 135 (Endpoint Mapper) and constitutes a strong indicator of a Windows server that is publicly advertising management-related services.</p><p>The IP contains data of other addresses shown in the banner, all of which relate to the single Windows host and represent different network identifiers associated with the same system.</p><p><strong>45[.]134[.]26[.]22</strong> is the primary public IP address exposed to the internet and the endpoint through which the RPC service on port 135 is reachable. <strong>WIN-QCQ1STQOM66</strong> is the internal hostname of the Windows machine, leaked during the RPC/DCERPC handshake, and it serves as the common identifier linking all associated interfaces.</p><p><strong>169[.]254[.]71[.]72</strong> is a Windows link-local address, which is not routable on the internet and typically indicates an internal, virtual, or fallback network interface, suggesting the host has additional internal networking configured.</p><p><strong>45[.]134[.]26[.]184</strong> is another public IP within the same ASN and address range, representing an additional interface, a closely related node, or an adjacent system associated with the same infrastructure.</p><p>All of these are identifiers that show the exposed RPC service reveals a mapped view of the host&#8217;s networking, allowing to correlate multiple IP addresses and interfaces back to a single Windows server without any authentication, providing strong infrastructure linkage and insight into the host&#8217;s network layout.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!oYY4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47768695-ae2b-44d6-8ec1-f92a2186ec0b_1037x325.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!oYY4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47768695-ae2b-44d6-8ec1-f92a2186ec0b_1037x325.png 424w, https://substackcdn.com/image/fetch/$s_!oYY4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47768695-ae2b-44d6-8ec1-f92a2186ec0b_1037x325.png 848w, https://substackcdn.com/image/fetch/$s_!oYY4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47768695-ae2b-44d6-8ec1-f92a2186ec0b_1037x325.png 1272w, https://substackcdn.com/image/fetch/$s_!oYY4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47768695-ae2b-44d6-8ec1-f92a2186ec0b_1037x325.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!oYY4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47768695-ae2b-44d6-8ec1-f92a2186ec0b_1037x325.png" width="1037" height="325" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/47768695-ae2b-44d6-8ec1-f92a2186ec0b_1037x325.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:325,&quot;width&quot;:1037,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:20789,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/185280795?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47768695-ae2b-44d6-8ec1-f92a2186ec0b_1037x325.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!oYY4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47768695-ae2b-44d6-8ec1-f92a2186ec0b_1037x325.png 424w, https://substackcdn.com/image/fetch/$s_!oYY4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47768695-ae2b-44d6-8ec1-f92a2186ec0b_1037x325.png 848w, https://substackcdn.com/image/fetch/$s_!oYY4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47768695-ae2b-44d6-8ec1-f92a2186ec0b_1037x325.png 1272w, https://substackcdn.com/image/fetch/$s_!oYY4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47768695-ae2b-44d6-8ec1-f92a2186ec0b_1037x325.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>These three IP addresses were deeply checked, and I found out that all of them host different domains with (.cyou), all unavailable and registered in 2025 by an unknown entity, probably for malware spreading purposes.</p><p>Such domains, for example:</p><ul><li><p>indickensonkas[.]cyou</p></li><li><p>aesacksis[.]cyou</p></li><li><p>sashkra[.]cyou</p></li><li><p>saudkas[.]cyou</p></li><li><p>indaks[.]cyou</p></li><li><p>ilslobas[.]cyou</p></li></ul><p>All pages were deleted, but I managed to find an archive for one of them, verifying it is part of Phishing infrastructure, containing payment request informationn and it seems to be dedicated to Indian citizens.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!KkkW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd69a05e-362e-478f-8062-31efc7b292f7_1893x887.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!KkkW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd69a05e-362e-478f-8062-31efc7b292f7_1893x887.png 424w, https://substackcdn.com/image/fetch/$s_!KkkW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd69a05e-362e-478f-8062-31efc7b292f7_1893x887.png 848w, https://substackcdn.com/image/fetch/$s_!KkkW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd69a05e-362e-478f-8062-31efc7b292f7_1893x887.png 1272w, https://substackcdn.com/image/fetch/$s_!KkkW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd69a05e-362e-478f-8062-31efc7b292f7_1893x887.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!KkkW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd69a05e-362e-478f-8062-31efc7b292f7_1893x887.png" width="1456" height="682" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fd69a05e-362e-478f-8062-31efc7b292f7_1893x887.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:682,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:135080,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/185280795?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd69a05e-362e-478f-8062-31efc7b292f7_1893x887.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!KkkW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd69a05e-362e-478f-8062-31efc7b292f7_1893x887.png 424w, https://substackcdn.com/image/fetch/$s_!KkkW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd69a05e-362e-478f-8062-31efc7b292f7_1893x887.png 848w, https://substackcdn.com/image/fetch/$s_!KkkW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd69a05e-362e-478f-8062-31efc7b292f7_1893x887.png 1272w, https://substackcdn.com/image/fetch/$s_!KkkW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd69a05e-362e-478f-8062-31efc7b292f7_1893x887.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>One Hash, Many Faces</strong></h2><p>When I deep dived into the address 45[.]134[.]26[.]184, I saw it was directly connected to another website by using the same Favicon hash.</p><p>Favicon is an icon a website uses in the browser tab or bookmarks, and the <strong>favicon hash</strong> is a unique digital fingerprint created from that icon file, meaning that if two sites have the same hash, their favicon files are <strong>exactly identical</strong> at the file level.</p><p>When two websites use the same favicon hash, it means they are using the same default icon, the same website template, the same software or control panel, or were deployed from the same setup or infrastructure.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rTb7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6bed10b-a862-4d25-9ea6-4ead6f850492_649x451.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rTb7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6bed10b-a862-4d25-9ea6-4ead6f850492_649x451.png 424w, https://substackcdn.com/image/fetch/$s_!rTb7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6bed10b-a862-4d25-9ea6-4ead6f850492_649x451.png 848w, https://substackcdn.com/image/fetch/$s_!rTb7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6bed10b-a862-4d25-9ea6-4ead6f850492_649x451.png 1272w, https://substackcdn.com/image/fetch/$s_!rTb7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6bed10b-a862-4d25-9ea6-4ead6f850492_649x451.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rTb7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6bed10b-a862-4d25-9ea6-4ead6f850492_649x451.png" width="649" height="451" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c6bed10b-a862-4d25-9ea6-4ead6f850492_649x451.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:451,&quot;width&quot;:649,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:48855,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/185280795?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa58a1f7f-db7c-4869-aba0-b92e9c83426d_649x694.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!rTb7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6bed10b-a862-4d25-9ea6-4ead6f850492_649x451.png 424w, https://substackcdn.com/image/fetch/$s_!rTb7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6bed10b-a862-4d25-9ea6-4ead6f850492_649x451.png 848w, https://substackcdn.com/image/fetch/$s_!rTb7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6bed10b-a862-4d25-9ea6-4ead6f850492_649x451.png 1272w, https://substackcdn.com/image/fetch/$s_!rTb7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6bed10b-a862-4d25-9ea6-4ead6f850492_649x451.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The favicon hash is <strong>1588839859</strong>, and when searching who else uses the exact hash, I found out the website <strong>ncrb-main[.]digitalnightowl[.]shop</strong>, a dedicated phishing infrastructure, impersonating the National Crime Records Bureau of India.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1t1M!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c77892b-d011-466b-a1b7-a94ae7e5d549_1711x727.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1t1M!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c77892b-d011-466b-a1b7-a94ae7e5d549_1711x727.png 424w, https://substackcdn.com/image/fetch/$s_!1t1M!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c77892b-d011-466b-a1b7-a94ae7e5d549_1711x727.png 848w, https://substackcdn.com/image/fetch/$s_!1t1M!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c77892b-d011-466b-a1b7-a94ae7e5d549_1711x727.png 1272w, https://substackcdn.com/image/fetch/$s_!1t1M!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c77892b-d011-466b-a1b7-a94ae7e5d549_1711x727.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1t1M!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c77892b-d011-466b-a1b7-a94ae7e5d549_1711x727.png" width="1456" height="619" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1c77892b-d011-466b-a1b7-a94ae7e5d549_1711x727.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:619,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:918905,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/185280795?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c77892b-d011-466b-a1b7-a94ae7e5d549_1711x727.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!1t1M!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c77892b-d011-466b-a1b7-a94ae7e5d549_1711x727.png 424w, https://substackcdn.com/image/fetch/$s_!1t1M!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c77892b-d011-466b-a1b7-a94ae7e5d549_1711x727.png 848w, https://substackcdn.com/image/fetch/$s_!1t1M!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c77892b-d011-466b-a1b7-a94ae7e5d549_1711x727.png 1272w, https://substackcdn.com/image/fetch/$s_!1t1M!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c77892b-d011-466b-a1b7-a94ae7e5d549_1711x727.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>WHOIS records of the domain show the domain was registered in October 2025, using GoDaddy, exactly as the others.</p><p>The domain of digitalnightowl[.]shop contains dozens of other subdomains as well, for different purposes, from Banks fake pages, real-estate agencies fake pages, government fake pages, and hotel fake pages, all directed at Indian citizens.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rVXJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a616918-bc45-475a-9c69-727a21321bfb_556x63.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rVXJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a616918-bc45-475a-9c69-727a21321bfb_556x63.png 424w, https://substackcdn.com/image/fetch/$s_!rVXJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a616918-bc45-475a-9c69-727a21321bfb_556x63.png 848w, https://substackcdn.com/image/fetch/$s_!rVXJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a616918-bc45-475a-9c69-727a21321bfb_556x63.png 1272w, https://substackcdn.com/image/fetch/$s_!rVXJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a616918-bc45-475a-9c69-727a21321bfb_556x63.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rVXJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a616918-bc45-475a-9c69-727a21321bfb_556x63.png" width="556" height="63" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5a616918-bc45-475a-9c69-727a21321bfb_556x63.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:63,&quot;width&quot;:556,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3961,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/185280795?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a616918-bc45-475a-9c69-727a21321bfb_556x63.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!rVXJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a616918-bc45-475a-9c69-727a21321bfb_556x63.png 424w, https://substackcdn.com/image/fetch/$s_!rVXJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a616918-bc45-475a-9c69-727a21321bfb_556x63.png 848w, https://substackcdn.com/image/fetch/$s_!rVXJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a616918-bc45-475a-9c69-727a21321bfb_556x63.png 1272w, https://substackcdn.com/image/fetch/$s_!rVXJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a616918-bc45-475a-9c69-727a21321bfb_556x63.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!WVsy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5db78e57-e41f-445a-ba22-1427f17e5f87_533x61.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!WVsy!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5db78e57-e41f-445a-ba22-1427f17e5f87_533x61.png 424w, https://substackcdn.com/image/fetch/$s_!WVsy!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5db78e57-e41f-445a-ba22-1427f17e5f87_533x61.png 848w, https://substackcdn.com/image/fetch/$s_!WVsy!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5db78e57-e41f-445a-ba22-1427f17e5f87_533x61.png 1272w, https://substackcdn.com/image/fetch/$s_!WVsy!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5db78e57-e41f-445a-ba22-1427f17e5f87_533x61.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!WVsy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5db78e57-e41f-445a-ba22-1427f17e5f87_533x61.png" width="533" height="61" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5db78e57-e41f-445a-ba22-1427f17e5f87_533x61.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:61,&quot;width&quot;:533,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3838,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/185280795?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5db78e57-e41f-445a-ba22-1427f17e5f87_533x61.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!WVsy!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5db78e57-e41f-445a-ba22-1427f17e5f87_533x61.png 424w, https://substackcdn.com/image/fetch/$s_!WVsy!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5db78e57-e41f-445a-ba22-1427f17e5f87_533x61.png 848w, https://substackcdn.com/image/fetch/$s_!WVsy!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5db78e57-e41f-445a-ba22-1427f17e5f87_533x61.png 1272w, https://substackcdn.com/image/fetch/$s_!WVsy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5db78e57-e41f-445a-ba22-1427f17e5f87_533x61.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rA17!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3e64996-83e2-43db-88a0-48f3b33904f7_494x67.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rA17!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3e64996-83e2-43db-88a0-48f3b33904f7_494x67.png 424w, https://substackcdn.com/image/fetch/$s_!rA17!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3e64996-83e2-43db-88a0-48f3b33904f7_494x67.png 848w, https://substackcdn.com/image/fetch/$s_!rA17!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3e64996-83e2-43db-88a0-48f3b33904f7_494x67.png 1272w, https://substackcdn.com/image/fetch/$s_!rA17!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3e64996-83e2-43db-88a0-48f3b33904f7_494x67.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rA17!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3e64996-83e2-43db-88a0-48f3b33904f7_494x67.png" width="494" height="67" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f3e64996-83e2-43db-88a0-48f3b33904f7_494x67.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:67,&quot;width&quot;:494,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3631,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/185280795?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3e64996-83e2-43db-88a0-48f3b33904f7_494x67.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!rA17!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3e64996-83e2-43db-88a0-48f3b33904f7_494x67.png 424w, https://substackcdn.com/image/fetch/$s_!rA17!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3e64996-83e2-43db-88a0-48f3b33904f7_494x67.png 848w, https://substackcdn.com/image/fetch/$s_!rA17!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3e64996-83e2-43db-88a0-48f3b33904f7_494x67.png 1272w, https://substackcdn.com/image/fetch/$s_!rA17!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3e64996-83e2-43db-88a0-48f3b33904f7_494x67.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5gba!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae8dcf51-625e-4608-b19d-e590fe84cf35_560x73.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5gba!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae8dcf51-625e-4608-b19d-e590fe84cf35_560x73.png 424w, https://substackcdn.com/image/fetch/$s_!5gba!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae8dcf51-625e-4608-b19d-e590fe84cf35_560x73.png 848w, https://substackcdn.com/image/fetch/$s_!5gba!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae8dcf51-625e-4608-b19d-e590fe84cf35_560x73.png 1272w, https://substackcdn.com/image/fetch/$s_!5gba!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae8dcf51-625e-4608-b19d-e590fe84cf35_560x73.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5gba!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae8dcf51-625e-4608-b19d-e590fe84cf35_560x73.png" width="560" height="73" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae8dcf51-625e-4608-b19d-e590fe84cf35_560x73.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:73,&quot;width&quot;:560,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4054,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/185280795?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae8dcf51-625e-4608-b19d-e590fe84cf35_560x73.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!5gba!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae8dcf51-625e-4608-b19d-e590fe84cf35_560x73.png 424w, https://substackcdn.com/image/fetch/$s_!5gba!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae8dcf51-625e-4608-b19d-e590fe84cf35_560x73.png 848w, https://substackcdn.com/image/fetch/$s_!5gba!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae8dcf51-625e-4608-b19d-e590fe84cf35_560x73.png 1272w, https://substackcdn.com/image/fetch/$s_!5gba!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae8dcf51-625e-4608-b19d-e590fe84cf35_560x73.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!bY9L!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe1d8de3-2d64-4560-a5e1-f0f09231db3a_517x73.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!bY9L!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe1d8de3-2d64-4560-a5e1-f0f09231db3a_517x73.png 424w, https://substackcdn.com/image/fetch/$s_!bY9L!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe1d8de3-2d64-4560-a5e1-f0f09231db3a_517x73.png 848w, https://substackcdn.com/image/fetch/$s_!bY9L!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe1d8de3-2d64-4560-a5e1-f0f09231db3a_517x73.png 1272w, https://substackcdn.com/image/fetch/$s_!bY9L!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe1d8de3-2d64-4560-a5e1-f0f09231db3a_517x73.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!bY9L!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe1d8de3-2d64-4560-a5e1-f0f09231db3a_517x73.png" width="517" height="73" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/be1d8de3-2d64-4560-a5e1-f0f09231db3a_517x73.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:73,&quot;width&quot;:517,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3706,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/185280795?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe1d8de3-2d64-4560-a5e1-f0f09231db3a_517x73.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!bY9L!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe1d8de3-2d64-4560-a5e1-f0f09231db3a_517x73.png 424w, https://substackcdn.com/image/fetch/$s_!bY9L!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe1d8de3-2d64-4560-a5e1-f0f09231db3a_517x73.png 848w, https://substackcdn.com/image/fetch/$s_!bY9L!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe1d8de3-2d64-4560-a5e1-f0f09231db3a_517x73.png 1272w, https://substackcdn.com/image/fetch/$s_!bY9L!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe1d8de3-2d64-4560-a5e1-f0f09231db3a_517x73.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>One of the domains had several misconfigurations that led me to see the backend of the website itself, including the JS files, routes, and error logs.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!GUM3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e2f66c8-9e44-4595-a351-d62b2812de56_955x883.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!GUM3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e2f66c8-9e44-4595-a351-d62b2812de56_955x883.png 424w, https://substackcdn.com/image/fetch/$s_!GUM3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e2f66c8-9e44-4595-a351-d62b2812de56_955x883.png 848w, https://substackcdn.com/image/fetch/$s_!GUM3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e2f66c8-9e44-4595-a351-d62b2812de56_955x883.png 1272w, https://substackcdn.com/image/fetch/$s_!GUM3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e2f66c8-9e44-4595-a351-d62b2812de56_955x883.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!GUM3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e2f66c8-9e44-4595-a351-d62b2812de56_955x883.png" width="955" height="883" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8e2f66c8-9e44-4595-a351-d62b2812de56_955x883.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:883,&quot;width&quot;:955,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:56471,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/185280795?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e2f66c8-9e44-4595-a351-d62b2812de56_955x883.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!GUM3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e2f66c8-9e44-4595-a351-d62b2812de56_955x883.png 424w, https://substackcdn.com/image/fetch/$s_!GUM3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e2f66c8-9e44-4595-a351-d62b2812de56_955x883.png 848w, https://substackcdn.com/image/fetch/$s_!GUM3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e2f66c8-9e44-4595-a351-d62b2812de56_955x883.png 1272w, https://substackcdn.com/image/fetch/$s_!GUM3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e2f66c8-9e44-4595-a351-d62b2812de56_955x883.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Beyond The Frontend</strong></h2><p>When I started searching about &#8220;digitalnightowl[.]shop&#8221;, I found references to an Etsy store that wasn&#8217;t very useful but when I logged in to the website itself, I noticed the there is a difference between the name of the website itself and the name in the URL, meaning the site is technically served under one domain but displayed or branded as another, usually due to a server-level redirect or domain alias.</p><p>This commonly occurs when the same operator controls multiple domains for a single website, for branding, redundancy, SEO, or during a domain migration, or when one domain is used as an entry point while another is defined as the primary logical or canonical domain.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3Mo5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb32cfd35-76ea-40ed-9465-ebbc48e7ca8d_1495x848.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3Mo5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb32cfd35-76ea-40ed-9465-ebbc48e7ca8d_1495x848.png 424w, https://substackcdn.com/image/fetch/$s_!3Mo5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb32cfd35-76ea-40ed-9465-ebbc48e7ca8d_1495x848.png 848w, https://substackcdn.com/image/fetch/$s_!3Mo5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb32cfd35-76ea-40ed-9465-ebbc48e7ca8d_1495x848.png 1272w, https://substackcdn.com/image/fetch/$s_!3Mo5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb32cfd35-76ea-40ed-9465-ebbc48e7ca8d_1495x848.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3Mo5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb32cfd35-76ea-40ed-9465-ebbc48e7ca8d_1495x848.png" width="1456" height="826" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b32cfd35-76ea-40ed-9465-ebbc48e7ca8d_1495x848.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:826,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:126423,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/185280795?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb32cfd35-76ea-40ed-9465-ebbc48e7ca8d_1495x848.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3Mo5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb32cfd35-76ea-40ed-9465-ebbc48e7ca8d_1495x848.png 424w, https://substackcdn.com/image/fetch/$s_!3Mo5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb32cfd35-76ea-40ed-9465-ebbc48e7ca8d_1495x848.png 848w, https://substackcdn.com/image/fetch/$s_!3Mo5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb32cfd35-76ea-40ed-9465-ebbc48e7ca8d_1495x848.png 1272w, https://substackcdn.com/image/fetch/$s_!3Mo5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb32cfd35-76ea-40ed-9465-ebbc48e7ca8d_1495x848.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>When searching the phone number that appeared on the website, I saw it belongs to an Indian guy named <strong>Prakhar Abhishek</strong>, probably the owner of Digital Night Owl, a company that seems to be providing service in the areas of IT, Data, and SEO.</p><p>The phone number itself was in a data leak from 2025, revealing three other Indian phone numbers and associated addresses under different names, two of the addresses are identical, meaning there is a close relation between these individuals.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!J_Gt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72c1be27-5cde-4db0-b63a-25a551facd09_553x214.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!J_Gt!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72c1be27-5cde-4db0-b63a-25a551facd09_553x214.png 424w, https://substackcdn.com/image/fetch/$s_!J_Gt!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72c1be27-5cde-4db0-b63a-25a551facd09_553x214.png 848w, https://substackcdn.com/image/fetch/$s_!J_Gt!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72c1be27-5cde-4db0-b63a-25a551facd09_553x214.png 1272w, https://substackcdn.com/image/fetch/$s_!J_Gt!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72c1be27-5cde-4db0-b63a-25a551facd09_553x214.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!J_Gt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72c1be27-5cde-4db0-b63a-25a551facd09_553x214.png" width="553" height="214" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/72c1be27-5cde-4db0-b63a-25a551facd09_553x214.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:214,&quot;width&quot;:553,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:63633,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/185280795?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72c1be27-5cde-4db0-b63a-25a551facd09_553x214.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!J_Gt!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72c1be27-5cde-4db0-b63a-25a551facd09_553x214.png 424w, https://substackcdn.com/image/fetch/$s_!J_Gt!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72c1be27-5cde-4db0-b63a-25a551facd09_553x214.png 848w, https://substackcdn.com/image/fetch/$s_!J_Gt!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72c1be27-5cde-4db0-b63a-25a551facd09_553x214.png 1272w, https://substackcdn.com/image/fetch/$s_!J_Gt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72c1be27-5cde-4db0-b63a-25a551facd09_553x214.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>His email address appears in business registrations in India as the owner of the company, which puts him in charge of the operation as well.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Mk8D!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F122171c3-7739-4eff-a7b8-443012297791_997x233.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Mk8D!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F122171c3-7739-4eff-a7b8-443012297791_997x233.png 424w, https://substackcdn.com/image/fetch/$s_!Mk8D!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F122171c3-7739-4eff-a7b8-443012297791_997x233.png 848w, https://substackcdn.com/image/fetch/$s_!Mk8D!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F122171c3-7739-4eff-a7b8-443012297791_997x233.png 1272w, https://substackcdn.com/image/fetch/$s_!Mk8D!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F122171c3-7739-4eff-a7b8-443012297791_997x233.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Mk8D!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F122171c3-7739-4eff-a7b8-443012297791_997x233.png" width="997" height="233" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/122171c3-7739-4eff-a7b8-443012297791_997x233.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:233,&quot;width&quot;:997,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:26084,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/185280795?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F122171c3-7739-4eff-a7b8-443012297791_997x233.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Mk8D!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F122171c3-7739-4eff-a7b8-443012297791_997x233.png 424w, https://substackcdn.com/image/fetch/$s_!Mk8D!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F122171c3-7739-4eff-a7b8-443012297791_997x233.png 848w, https://substackcdn.com/image/fetch/$s_!Mk8D!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F122171c3-7739-4eff-a7b8-443012297791_997x233.png 1272w, https://substackcdn.com/image/fetch/$s_!Mk8D!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F122171c3-7739-4eff-a7b8-443012297791_997x233.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!KtsJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2e91245-dc2e-41cb-8ed4-26459e24b7fe_1150x100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!KtsJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2e91245-dc2e-41cb-8ed4-26459e24b7fe_1150x100.png 424w, https://substackcdn.com/image/fetch/$s_!KtsJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2e91245-dc2e-41cb-8ed4-26459e24b7fe_1150x100.png 848w, https://substackcdn.com/image/fetch/$s_!KtsJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2e91245-dc2e-41cb-8ed4-26459e24b7fe_1150x100.png 1272w, https://substackcdn.com/image/fetch/$s_!KtsJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2e91245-dc2e-41cb-8ed4-26459e24b7fe_1150x100.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!KtsJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2e91245-dc2e-41cb-8ed4-26459e24b7fe_1150x100.png" width="1150" height="100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d2e91245-dc2e-41cb-8ed4-26459e24b7fe_1150x100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:100,&quot;width&quot;:1150,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:23521,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/185280795?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2e91245-dc2e-41cb-8ed4-26459e24b7fe_1150x100.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!KtsJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2e91245-dc2e-41cb-8ed4-26459e24b7fe_1150x100.png 424w, https://substackcdn.com/image/fetch/$s_!KtsJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2e91245-dc2e-41cb-8ed4-26459e24b7fe_1150x100.png 848w, https://substackcdn.com/image/fetch/$s_!KtsJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2e91245-dc2e-41cb-8ed4-26459e24b7fe_1150x100.png 1272w, https://substackcdn.com/image/fetch/$s_!KtsJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2e91245-dc2e-41cb-8ed4-26459e24b7fe_1150x100.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2><strong>The Revival That Wasn&#8217;t</strong></h2><p>What began as an intelligence investigation into the apparent resurgence of BreachForums ultimately led to the exposure of a broad and coordinated infrastructure of impersonation websites designed to defraud citizens in India on a large scale.</p><p>Correlation of the findings reveals a consistent pattern in which all indicators converge on a single company based in India, operating in the fields of IT services and digital marketing.</p><p>The aggregated evidence suggests that the company&#8217;s owners, Indian nationals residing in the country, are likely responsible for managing the entire operation, including attempts to revive the infamous forum, which itself appears to have been repurposed not as a genuine cybercrime community but as part of a deliberate and organized fraud scheme.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.darksignal.co/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[ SENTAP - An Opportunistic Threat Actor Profile ]]></title><description><![CDATA[Thanks for reading!]]></description><link>https://www.darksignal.co/p/sentap-an-opportunistic-threat-actor</link><guid isPermaLink="false">https://www.darksignal.co/p/sentap-an-opportunistic-threat-actor</guid><dc:creator><![CDATA[DarkSignal]]></dc:creator><pubDate>Mon, 05 Jan 2026 08:15:18 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!s_r1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb722c03a-02b3-4d09-9d4e-7f0432995765_1024x1181.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!s_r1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb722c03a-02b3-4d09-9d4e-7f0432995765_1024x1181.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!s_r1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb722c03a-02b3-4d09-9d4e-7f0432995765_1024x1181.png 424w, https://substackcdn.com/image/fetch/$s_!s_r1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb722c03a-02b3-4d09-9d4e-7f0432995765_1024x1181.png 848w, https://substackcdn.com/image/fetch/$s_!s_r1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb722c03a-02b3-4d09-9d4e-7f0432995765_1024x1181.png 1272w, https://substackcdn.com/image/fetch/$s_!s_r1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb722c03a-02b3-4d09-9d4e-7f0432995765_1024x1181.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!s_r1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb722c03a-02b3-4d09-9d4e-7f0432995765_1024x1181.png" width="1024" height="1181" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b722c03a-02b3-4d09-9d4e-7f0432995765_1024x1181.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1181,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2933256,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/183332412?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a5894c8-c466-4464-aed8-9bc5e3887122_1024x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!s_r1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb722c03a-02b3-4d09-9d4e-7f0432995765_1024x1181.png 424w, https://substackcdn.com/image/fetch/$s_!s_r1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb722c03a-02b3-4d09-9d4e-7f0432995765_1024x1181.png 848w, https://substackcdn.com/image/fetch/$s_!s_r1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb722c03a-02b3-4d09-9d4e-7f0432995765_1024x1181.png 1272w, https://substackcdn.com/image/fetch/$s_!s_r1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb722c03a-02b3-4d09-9d4e-7f0432995765_1024x1181.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.darksignal.co/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h2>Who Is Sentap</h2><p>SENTAP, operating under the alias &#8220;sentap.cyber&#8221;, is a financially motivated threat actor assessed to have been active since at least 2021. The actor primarily operates as an Initial Access Broker (IAB) and data extortion actor, maintaining a persistent presence across underground forums, encrypted messaging platforms, and email-based communication channels.</p><p>His core capability lies in obtaining unauthorized access to organizational environments through compromised credentials, leaked accounts, and abuse of legitimate third-party access. Once access is established, he focuses on identifying centralized file-sharing systems and storage repositories that can be exploited for large-scale data collection.</p><p>During 2024 and 2025, SENTAP significantly increased the scale and visibility of its operations, advertising datasets measured in the hundreds of gigabytes. Notable cases attributed to the actor include the sale of large volumes of infrastructure and personally identifiable information linked to <strong>NBN Co</strong>, as well as a separate dataset attributed to <strong>UrbanX</strong>.</p><p>The data described in these listings reportedly included infrastructure documentation, engineering plans, legal and commercial records, and personal information, highlighting the potential for operational, regulatory, and reputational impact.</p><p>Geographically, SENTAP&#8217;s activity spans multiple regions, with victims and advertised datasets linked to Australia, Europe, North America, the Middle East, and Asia.</p><p>Sector-wise, his operations are cross-industry, reflecting a preference for accessibility and data volume rather than a single vertical focus.</p><p>The following research will assess Sentap&#8217;s actions, digital footprints, and methodologies to identify who this threat actor is and associate him with a specific country (AKA attribution).</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ilW5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8ae4441-7f29-4dda-a6c9-c0c6120982c5_1886x688.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ilW5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8ae4441-7f29-4dda-a6c9-c0c6120982c5_1886x688.png 424w, https://substackcdn.com/image/fetch/$s_!ilW5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8ae4441-7f29-4dda-a6c9-c0c6120982c5_1886x688.png 848w, https://substackcdn.com/image/fetch/$s_!ilW5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8ae4441-7f29-4dda-a6c9-c0c6120982c5_1886x688.png 1272w, https://substackcdn.com/image/fetch/$s_!ilW5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8ae4441-7f29-4dda-a6c9-c0c6120982c5_1886x688.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ilW5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8ae4441-7f29-4dda-a6c9-c0c6120982c5_1886x688.png" width="1456" height="531" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a8ae4441-7f29-4dda-a6c9-c0c6120982c5_1886x688.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:531,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:906681,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/183332412?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8ae4441-7f29-4dda-a6c9-c0c6120982c5_1886x688.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ilW5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8ae4441-7f29-4dda-a6c9-c0c6120982c5_1886x688.png 424w, https://substackcdn.com/image/fetch/$s_!ilW5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8ae4441-7f29-4dda-a6c9-c0c6120982c5_1886x688.png 848w, https://substackcdn.com/image/fetch/$s_!ilW5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8ae4441-7f29-4dda-a6c9-c0c6120982c5_1886x688.png 1272w, https://substackcdn.com/image/fetch/$s_!ilW5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8ae4441-7f29-4dda-a6c9-c0c6120982c5_1886x688.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Modus Operandi - Trust Abuse Model</strong></h2><p>SENTAP&#8217;s activity indicates an opportunistic operating model, focusing on organizations with exposed or weakly protected infrastructure rather than highly targeted, bespoke intrusion campaigns.</p><p>Following data exfiltration, SENTAP engages in extortion-driven activity, leaving ransom or pressure notes within affected environments and initiating direct communication with victims via encrypted channels.</p><p>The actor&#8217;s demands centre on financial payment in exchange for withholding public disclosure or resale of the stolen data. When negotiations fail or are ignored, SENTAP has been observed advertising and selling datasets on underground data-leak and marketplace forums.</p><p>SENTAP operates as a financially motivated threat actor focused on acquiring initial access to organisational environments and converting that access into profit through large-scale data theft and extortion. His operational model is opportunistic in nature, prioritising exploitable exposure, weak identity and access management practices, and over-trusted third-party relationships rather than sophisticated intrusion tooling or highly targeted campaigns.</p><p>Initial access is typically achieved using compromised or leaked credentials, including accounts belonging to internal users and external service providers with legitimate access.</p><p>SENTAP also actively identifies and abuses internet-facing assets with weak or misconfigured security controls, such as cloud services, VPNs, and other externally exposed infrastructure, favouring low-friction entry points that do not require advanced exploitation techniques.</p><p>Once a foothold is established, SENTAP focuses on abusing trusted relationships to maintain access and expand reach within the environment. By operating through valid accounts, particularly those associated with third parties, he can blend into normal user activity, bypass basic security controls, and access sensitive resources with minimal lateral movement or noisy post-exploitation behaviour.</p><p>The core phase of SENTAP&#8217;s operations centres on file-sharing and a centralised storage infrastructure. He performs systematic, high-volume data collection and exfiltration, often over extended periods, using legitimate transfer mechanisms such as SFTP or standard download functionality.</p><p>The objective is bulk data acquisition rather than selective targeting, enabling the extraction of operational documents, business records, technical material, and personally identifiable information at scale.</p><p>Following or during data exfiltration, SENTAP transitions to the pressure and extortion phase. He leaves extortion messages within the affected environment and initiates direct communication with the victim via encrypted and privacy-focused channels. Communications are generally non-aggressive in tone but persistent, emphasising payment to prevent public disclosure or resale of the stolen data.</p><h2><strong>Signals In Plain Sight</strong></h2><p>My starting point is the username &#8220;sentap&#8221;. A lot of details were revealed from different hacking communities under this alias, from BF, to XSS and Leakbase, in all of them he posted dozens of times with different sales offers of stolen data.</p><p>I was able to identify two different services he was registered to, Twitter (X) and Matrix (An open network for secure, decentralised communication), that I was able to cross between them due to his usage with the same profile picture as he uses in the different hacking forums he participates in.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vypQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbccddb9b-a7a1-46c3-ac4b-91b7e6ccfd9d_993x350.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vypQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbccddb9b-a7a1-46c3-ac4b-91b7e6ccfd9d_993x350.png 424w, https://substackcdn.com/image/fetch/$s_!vypQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbccddb9b-a7a1-46c3-ac4b-91b7e6ccfd9d_993x350.png 848w, https://substackcdn.com/image/fetch/$s_!vypQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbccddb9b-a7a1-46c3-ac4b-91b7e6ccfd9d_993x350.png 1272w, https://substackcdn.com/image/fetch/$s_!vypQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbccddb9b-a7a1-46c3-ac4b-91b7e6ccfd9d_993x350.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vypQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbccddb9b-a7a1-46c3-ac4b-91b7e6ccfd9d_993x350.png" width="993" height="350" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bccddb9b-a7a1-46c3-ac4b-91b7e6ccfd9d_993x350.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:350,&quot;width&quot;:993,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:76592,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/183332412?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbccddb9b-a7a1-46c3-ac4b-91b7e6ccfd9d_993x350.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vypQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbccddb9b-a7a1-46c3-ac4b-91b7e6ccfd9d_993x350.png 424w, https://substackcdn.com/image/fetch/$s_!vypQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbccddb9b-a7a1-46c3-ac4b-91b7e6ccfd9d_993x350.png 848w, https://substackcdn.com/image/fetch/$s_!vypQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbccddb9b-a7a1-46c3-ac4b-91b7e6ccfd9d_993x350.png 1272w, https://substackcdn.com/image/fetch/$s_!vypQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbccddb9b-a7a1-46c3-ac4b-91b7e6ccfd9d_993x350.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QmJO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e55dccb-45da-40f1-bebe-3177ec29a695_674x335.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QmJO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e55dccb-45da-40f1-bebe-3177ec29a695_674x335.png 424w, https://substackcdn.com/image/fetch/$s_!QmJO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e55dccb-45da-40f1-bebe-3177ec29a695_674x335.png 848w, https://substackcdn.com/image/fetch/$s_!QmJO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e55dccb-45da-40f1-bebe-3177ec29a695_674x335.png 1272w, https://substackcdn.com/image/fetch/$s_!QmJO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e55dccb-45da-40f1-bebe-3177ec29a695_674x335.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QmJO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e55dccb-45da-40f1-bebe-3177ec29a695_674x335.png" width="674" height="335" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8e55dccb-45da-40f1-bebe-3177ec29a695_674x335.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:335,&quot;width&quot;:674,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:113896,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/183332412?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e55dccb-45da-40f1-bebe-3177ec29a695_674x335.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!QmJO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e55dccb-45da-40f1-bebe-3177ec29a695_674x335.png 424w, https://substackcdn.com/image/fetch/$s_!QmJO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e55dccb-45da-40f1-bebe-3177ec29a695_674x335.png 848w, https://substackcdn.com/image/fetch/$s_!QmJO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e55dccb-45da-40f1-bebe-3177ec29a695_674x335.png 1272w, https://substackcdn.com/image/fetch/$s_!QmJO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e55dccb-45da-40f1-bebe-3177ec29a695_674x335.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The username led to an IP address, 185[.]218[.]3[.]32, that was directly associated with it, probably as a static IP address.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!yiwO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b7bfe1a-2b11-44cb-90d1-cd04c754921c_1106x46.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!yiwO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b7bfe1a-2b11-44cb-90d1-cd04c754921c_1106x46.png 424w, https://substackcdn.com/image/fetch/$s_!yiwO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b7bfe1a-2b11-44cb-90d1-cd04c754921c_1106x46.png 848w, https://substackcdn.com/image/fetch/$s_!yiwO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b7bfe1a-2b11-44cb-90d1-cd04c754921c_1106x46.png 1272w, https://substackcdn.com/image/fetch/$s_!yiwO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b7bfe1a-2b11-44cb-90d1-cd04c754921c_1106x46.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!yiwO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b7bfe1a-2b11-44cb-90d1-cd04c754921c_1106x46.png" width="1106" height="46" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1b7bfe1a-2b11-44cb-90d1-cd04c754921c_1106x46.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:46,&quot;width&quot;:1106,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:8882,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/183332412?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b7bfe1a-2b11-44cb-90d1-cd04c754921c_1106x46.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!yiwO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b7bfe1a-2b11-44cb-90d1-cd04c754921c_1106x46.png 424w, https://substackcdn.com/image/fetch/$s_!yiwO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b7bfe1a-2b11-44cb-90d1-cd04c754921c_1106x46.png 848w, https://substackcdn.com/image/fetch/$s_!yiwO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b7bfe1a-2b11-44cb-90d1-cd04c754921c_1106x46.png 1272w, https://substackcdn.com/image/fetch/$s_!yiwO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b7bfe1a-2b11-44cb-90d1-cd04c754921c_1106x46.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>When searching for this IP address, I was able to find a relevant data breach that contained the IP address, along with the username &#8220;sentap&#8221; and an email address.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!yFan!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb396fc0f-2f23-4fa1-ac71-5c67e381d883_904x31.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!yFan!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb396fc0f-2f23-4fa1-ac71-5c67e381d883_904x31.png 424w, https://substackcdn.com/image/fetch/$s_!yFan!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb396fc0f-2f23-4fa1-ac71-5c67e381d883_904x31.png 848w, https://substackcdn.com/image/fetch/$s_!yFan!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb396fc0f-2f23-4fa1-ac71-5c67e381d883_904x31.png 1272w, https://substackcdn.com/image/fetch/$s_!yFan!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb396fc0f-2f23-4fa1-ac71-5c67e381d883_904x31.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!yFan!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb396fc0f-2f23-4fa1-ac71-5c67e381d883_904x31.png" width="904" height="31" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b396fc0f-2f23-4fa1-ac71-5c67e381d883_904x31.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:31,&quot;width&quot;:904,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2711,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/183332412?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb396fc0f-2f23-4fa1-ac71-5c67e381d883_904x31.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!yFan!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb396fc0f-2f23-4fa1-ac71-5c67e381d883_904x31.png 424w, https://substackcdn.com/image/fetch/$s_!yFan!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb396fc0f-2f23-4fa1-ac71-5c67e381d883_904x31.png 848w, https://substackcdn.com/image/fetch/$s_!yFan!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb396fc0f-2f23-4fa1-ac71-5c67e381d883_904x31.png 1272w, https://substackcdn.com/image/fetch/$s_!yFan!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb396fc0f-2f23-4fa1-ac71-5c67e381d883_904x31.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>That piece of information revealed another username, a part of the email address, under the alias &#8220;hoveylech&#8221;, worth checking as well.</p><p>When searching for clues about this username, I was able to find a Twitter account, opened in 2009 under the name &#8220;<strong>mostafa hoveylech</strong>&#8221;, an empty account, no posts and no actual activity, but he follows a few individuals that located in Iran.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!qLWJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8bb79662-035a-4b74-a3c7-1c7724ebbda5_999x298.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!qLWJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8bb79662-035a-4b74-a3c7-1c7724ebbda5_999x298.png 424w, https://substackcdn.com/image/fetch/$s_!qLWJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8bb79662-035a-4b74-a3c7-1c7724ebbda5_999x298.png 848w, https://substackcdn.com/image/fetch/$s_!qLWJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8bb79662-035a-4b74-a3c7-1c7724ebbda5_999x298.png 1272w, https://substackcdn.com/image/fetch/$s_!qLWJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8bb79662-035a-4b74-a3c7-1c7724ebbda5_999x298.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!qLWJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8bb79662-035a-4b74-a3c7-1c7724ebbda5_999x298.png" width="999" height="298" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8bb79662-035a-4b74-a3c7-1c7724ebbda5_999x298.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:298,&quot;width&quot;:999,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:96159,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/183332412?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8bb79662-035a-4b74-a3c7-1c7724ebbda5_999x298.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!qLWJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8bb79662-035a-4b74-a3c7-1c7724ebbda5_999x298.png 424w, https://substackcdn.com/image/fetch/$s_!qLWJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8bb79662-035a-4b74-a3c7-1c7724ebbda5_999x298.png 848w, https://substackcdn.com/image/fetch/$s_!qLWJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8bb79662-035a-4b74-a3c7-1c7724ebbda5_999x298.png 1272w, https://substackcdn.com/image/fetch/$s_!qLWJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8bb79662-035a-4b74-a3c7-1c7724ebbda5_999x298.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>On top of that, I found an old WordPress site created by him, with no data inside. This is a very old creation from 2010, where the threat actor &#8220;sentap&#8220; started to operate.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_Z4D!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04459861-2960-4a18-8bdc-e27f5f8c0e5e_2152x842.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_Z4D!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04459861-2960-4a18-8bdc-e27f5f8c0e5e_2152x842.png 424w, https://substackcdn.com/image/fetch/$s_!_Z4D!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04459861-2960-4a18-8bdc-e27f5f8c0e5e_2152x842.png 848w, https://substackcdn.com/image/fetch/$s_!_Z4D!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04459861-2960-4a18-8bdc-e27f5f8c0e5e_2152x842.png 1272w, https://substackcdn.com/image/fetch/$s_!_Z4D!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04459861-2960-4a18-8bdc-e27f5f8c0e5e_2152x842.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_Z4D!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04459861-2960-4a18-8bdc-e27f5f8c0e5e_2152x842.png" width="1456" height="570" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/04459861-2960-4a18-8bdc-e27f5f8c0e5e_2152x842.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:570,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:907836,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/183332412?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04459861-2960-4a18-8bdc-e27f5f8c0e5e_2152x842.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!_Z4D!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04459861-2960-4a18-8bdc-e27f5f8c0e5e_2152x842.png 424w, https://substackcdn.com/image/fetch/$s_!_Z4D!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04459861-2960-4a18-8bdc-e27f5f8c0e5e_2152x842.png 848w, https://substackcdn.com/image/fetch/$s_!_Z4D!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04459861-2960-4a18-8bdc-e27f5f8c0e5e_2152x842.png 1272w, https://substackcdn.com/image/fetch/$s_!_Z4D!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04459861-2960-4a18-8bdc-e27f5f8c0e5e_2152x842.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This WordPress website was automatically translated from the  Persian language, another huge clue about the possible origin location of the threat actor - Iran.</p><h2><strong>Names Don&#8217;t Lie</strong></h2><p>Since we have the email address, I started to investigate that lead.<br>The email address was directly associated with another Instagram account that was opened in 2020 under the name &#8220;Reza Hoveylech&#8221;.</p><p>By the ABOUT data section in this account, the username is &#8220;Hoveylech&#8221;, and the origin of the owner is Iran, as suspected.<br>Also, only one photo was published by this account, of a baby with a text in the Farsi language, the official language of Iran.</p><div class="image-gallery-embed" data-attrs="{&quot;gallery&quot;:{&quot;images&quot;:[{&quot;type&quot;:&quot;image/png&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/af495eb6-32f4-41e4-87bc-0bbb93db4654_807x1096.png&quot;},{&quot;type&quot;:&quot;image/png&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fcec3a36-999d-458e-b409-56d9c8a51d5f_560x215.png&quot;}],&quot;caption&quot;:&quot;&quot;,&quot;alt&quot;:&quot;&quot;,&quot;staticGalleryImage&quot;:{&quot;type&quot;:&quot;image/png&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/db300aae-7bb3-4994-885b-8c04e4815254_1456x720.png&quot;}},&quot;isEditorNode&quot;:true}"></div><p>In an archived post of the known hacking forum XSS, I found a post written by him that contains one of his email addresses - sentap@jabber[.]fr, not leads nowhere in terms of data breaches and digital footprint.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!8kai!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70a59ebe-4eed-4147-85f9-33056bc8fc0a_592x254.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8kai!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70a59ebe-4eed-4147-85f9-33056bc8fc0a_592x254.png 424w, https://substackcdn.com/image/fetch/$s_!8kai!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70a59ebe-4eed-4147-85f9-33056bc8fc0a_592x254.png 848w, https://substackcdn.com/image/fetch/$s_!8kai!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70a59ebe-4eed-4147-85f9-33056bc8fc0a_592x254.png 1272w, https://substackcdn.com/image/fetch/$s_!8kai!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70a59ebe-4eed-4147-85f9-33056bc8fc0a_592x254.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8kai!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70a59ebe-4eed-4147-85f9-33056bc8fc0a_592x254.png" width="592" height="254" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/70a59ebe-4eed-4147-85f9-33056bc8fc0a_592x254.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:254,&quot;width&quot;:592,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:19939,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/183332412?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70a59ebe-4eed-4147-85f9-33056bc8fc0a_592x254.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!8kai!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70a59ebe-4eed-4147-85f9-33056bc8fc0a_592x254.png 424w, https://substackcdn.com/image/fetch/$s_!8kai!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70a59ebe-4eed-4147-85f9-33056bc8fc0a_592x254.png 848w, https://substackcdn.com/image/fetch/$s_!8kai!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70a59ebe-4eed-4147-85f9-33056bc8fc0a_592x254.png 1272w, https://substackcdn.com/image/fetch/$s_!8kai!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70a59ebe-4eed-4147-85f9-33056bc8fc0a_592x254.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>But, the first email address I found is hoveylech@yahoo[.]com, and was part of the major Facebook data breach in 2019, which revealed the Facebook 100001020766512, and revealed two different crucial details &#8211; the name &#8220;Mostafa Hoveylech&#8221;, a name that was already mentioned in the Twitter page that was found, and a new detail - <br>+989168155967, a phone number with the Iranian country code.</p><div class="image-gallery-embed" data-attrs="{&quot;gallery&quot;:{&quot;images&quot;:[{&quot;type&quot;:&quot;image/png&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4c727fdf-c4a8-4dba-b9b3-ae06de7eead1_340x176.png&quot;},{&quot;type&quot;:&quot;image/png&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dc279d9f-fceb-45ae-af98-86cb4a5ef48c_602x450.png&quot;}],&quot;caption&quot;:&quot;&quot;,&quot;alt&quot;:&quot;&quot;,&quot;staticGalleryImage&quot;:{&quot;type&quot;:&quot;image/png&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/870bbff4-6234-4a9b-a1b6-e80987a202e9_1456x720.png&quot;}},&quot;isEditorNode&quot;:true}"></div><p>With a deeper dive into the email address, I found a direct association of this data in a database of mcls.gov.ir, the official Iranian government domain belonging to the Ministry of Cooperatives, Labour and Social Welfare, used for public services and administrative systems.</p><p>The appearance of the email address in this DB is valid proof that the attribution of this individual is from Iran.</p><p>More than that, it reveals his date of birth and validates his full name, as previously mentioned, as Mostafa.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!pgPC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32f1a069-e099-4ef7-83d7-2c749e39e7c6_1021x97.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!pgPC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32f1a069-e099-4ef7-83d7-2c749e39e7c6_1021x97.png 424w, https://substackcdn.com/image/fetch/$s_!pgPC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32f1a069-e099-4ef7-83d7-2c749e39e7c6_1021x97.png 848w, https://substackcdn.com/image/fetch/$s_!pgPC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32f1a069-e099-4ef7-83d7-2c749e39e7c6_1021x97.png 1272w, https://substackcdn.com/image/fetch/$s_!pgPC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32f1a069-e099-4ef7-83d7-2c749e39e7c6_1021x97.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!pgPC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32f1a069-e099-4ef7-83d7-2c749e39e7c6_1021x97.png" width="1021" height="97" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/32f1a069-e099-4ef7-83d7-2c749e39e7c6_1021x97.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:97,&quot;width&quot;:1021,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:22400,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/183332412?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32f1a069-e099-4ef7-83d7-2c749e39e7c6_1021x97.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!pgPC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32f1a069-e099-4ef7-83d7-2c749e39e7c6_1021x97.png 424w, https://substackcdn.com/image/fetch/$s_!pgPC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32f1a069-e099-4ef7-83d7-2c749e39e7c6_1021x97.png 848w, https://substackcdn.com/image/fetch/$s_!pgPC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32f1a069-e099-4ef7-83d7-2c749e39e7c6_1021x97.png 1272w, https://substackcdn.com/image/fetch/$s_!pgPC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32f1a069-e099-4ef7-83d7-2c749e39e7c6_1021x97.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2><strong>Financial Infrastructure</strong></h2><p>As the investigation went deeper, by scraping relevant Instagram comments, I found another two profiles of this individual.<br>The Instagram page of his persona (&#8220;sentap&#8221;), followed by the same picture he used in all the other sources, and a reference to his Telegram account.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!x9hy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4342a36f-9b3b-47e9-aaee-0056d233b0f5_619x220.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!x9hy!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4342a36f-9b3b-47e9-aaee-0056d233b0f5_619x220.png 424w, https://substackcdn.com/image/fetch/$s_!x9hy!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4342a36f-9b3b-47e9-aaee-0056d233b0f5_619x220.png 848w, https://substackcdn.com/image/fetch/$s_!x9hy!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4342a36f-9b3b-47e9-aaee-0056d233b0f5_619x220.png 1272w, https://substackcdn.com/image/fetch/$s_!x9hy!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4342a36f-9b3b-47e9-aaee-0056d233b0f5_619x220.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!x9hy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4342a36f-9b3b-47e9-aaee-0056d233b0f5_619x220.png" width="619" height="220" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4342a36f-9b3b-47e9-aaee-0056d233b0f5_619x220.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:220,&quot;width&quot;:619,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:42462,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/183332412?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4342a36f-9b3b-47e9-aaee-0056d233b0f5_619x220.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!x9hy!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4342a36f-9b3b-47e9-aaee-0056d233b0f5_619x220.png 424w, https://substackcdn.com/image/fetch/$s_!x9hy!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4342a36f-9b3b-47e9-aaee-0056d233b0f5_619x220.png 848w, https://substackcdn.com/image/fetch/$s_!x9hy!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4342a36f-9b3b-47e9-aaee-0056d233b0f5_619x220.png 1272w, https://substackcdn.com/image/fetch/$s_!x9hy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4342a36f-9b3b-47e9-aaee-0056d233b0f5_619x220.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>In his old Telegram BIO, he referred to his Keybase profile, where he lists his user, his PGP key, and two crypto addresses.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wrVD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77385445-18a2-4639-a299-e48a459c74e2_912x439.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wrVD!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77385445-18a2-4639-a299-e48a459c74e2_912x439.png 424w, https://substackcdn.com/image/fetch/$s_!wrVD!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77385445-18a2-4639-a299-e48a459c74e2_912x439.png 848w, https://substackcdn.com/image/fetch/$s_!wrVD!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77385445-18a2-4639-a299-e48a459c74e2_912x439.png 1272w, https://substackcdn.com/image/fetch/$s_!wrVD!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77385445-18a2-4639-a299-e48a459c74e2_912x439.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wrVD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77385445-18a2-4639-a299-e48a459c74e2_912x439.png" width="912" height="439" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/77385445-18a2-4639-a299-e48a459c74e2_912x439.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:439,&quot;width&quot;:912,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:77272,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/183332412?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77385445-18a2-4639-a299-e48a459c74e2_912x439.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wrVD!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77385445-18a2-4639-a299-e48a459c74e2_912x439.png 424w, https://substackcdn.com/image/fetch/$s_!wrVD!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77385445-18a2-4639-a299-e48a459c74e2_912x439.png 848w, https://substackcdn.com/image/fetch/$s_!wrVD!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77385445-18a2-4639-a299-e48a459c74e2_912x439.png 1272w, https://substackcdn.com/image/fetch/$s_!wrVD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77385445-18a2-4639-a299-e48a459c74e2_912x439.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>When analysing the addresses, both showed no more than 300$ in their peak, suggesting no massive illegal activities occurred in association with those.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1HTb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4cae7920-4e04-4944-9c6a-90888700aa4c_1702x937.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1HTb!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4cae7920-4e04-4944-9c6a-90888700aa4c_1702x937.png 424w, https://substackcdn.com/image/fetch/$s_!1HTb!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4cae7920-4e04-4944-9c6a-90888700aa4c_1702x937.png 848w, https://substackcdn.com/image/fetch/$s_!1HTb!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4cae7920-4e04-4944-9c6a-90888700aa4c_1702x937.png 1272w, https://substackcdn.com/image/fetch/$s_!1HTb!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4cae7920-4e04-4944-9c6a-90888700aa4c_1702x937.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1HTb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4cae7920-4e04-4944-9c6a-90888700aa4c_1702x937.png" width="1456" height="802" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4cae7920-4e04-4944-9c6a-90888700aa4c_1702x937.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:802,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:94071,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/183332412?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4cae7920-4e04-4944-9c6a-90888700aa4c_1702x937.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!1HTb!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4cae7920-4e04-4944-9c6a-90888700aa4c_1702x937.png 424w, https://substackcdn.com/image/fetch/$s_!1HTb!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4cae7920-4e04-4944-9c6a-90888700aa4c_1702x937.png 848w, https://substackcdn.com/image/fetch/$s_!1HTb!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4cae7920-4e04-4944-9c6a-90888700aa4c_1702x937.png 1272w, https://substackcdn.com/image/fetch/$s_!1HTb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4cae7920-4e04-4944-9c6a-90888700aa4c_1702x937.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Relation With Funksec Group</strong></h2><p>FUNKSEC is a cybercriminal group primarily associated with ransomware operations and digital extortion, which began gaining noticeable visibility mainly during 2024-2025 and operates in a manner resembling the Ransomware-as-a-Service (RaaS) model, combining intrusions into organizational networks with the theft of sensitive data and threats of public disclosure (double extortion).</p><p>The group relies on distributed infrastructure, low-cost VPS hosting, compromised cloud accounts, and anonymization services, and typically targets small to medium-sized organizations, educational institutions, service providers, and occasionally government bodies or subcontractors, with an emphasis not necessarily on extracting high ransom payments but rather on conducting a high volume of fast, opportunistic attacks.</p><p>FUNKSEC has been observed exploiting known (N-day) vulnerabilities, gaining initial access through leaked credentials or exposed RDP services, using common post-exploitation tools (including Cobalt Strike-like loaders or simpler alternatives), and leaking stolen data via shaming portals or underground forums, positioning the group as opportunistic and not particularly technologically &#8220;elite,&#8221; yet operationally efficient in scale, automation, and rapid exploitation of opportunities, making it noisy but dangerous, especially for organizations with weak security hygiene.</p><p>As I managed to find on Sentap&#8217;s Twitter page, he commented to a user in January 2025, as he seems as an individual who was part of the group.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0up8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a99d21d-4247-4a30-93af-ba537c712d37_591x135.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0up8!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a99d21d-4247-4a30-93af-ba537c712d37_591x135.png 424w, https://substackcdn.com/image/fetch/$s_!0up8!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a99d21d-4247-4a30-93af-ba537c712d37_591x135.png 848w, https://substackcdn.com/image/fetch/$s_!0up8!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a99d21d-4247-4a30-93af-ba537c712d37_591x135.png 1272w, https://substackcdn.com/image/fetch/$s_!0up8!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a99d21d-4247-4a30-93af-ba537c712d37_591x135.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0up8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a99d21d-4247-4a30-93af-ba537c712d37_591x135.png" width="591" height="135" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1a99d21d-4247-4a30-93af-ba537c712d37_591x135.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:135,&quot;width&quot;:591,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:12546,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/183332412?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a99d21d-4247-4a30-93af-ba537c712d37_591x135.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!0up8!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a99d21d-4247-4a30-93af-ba537c712d37_591x135.png 424w, https://substackcdn.com/image/fetch/$s_!0up8!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a99d21d-4247-4a30-93af-ba537c712d37_591x135.png 848w, https://substackcdn.com/image/fetch/$s_!0up8!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a99d21d-4247-4a30-93af-ba537c712d37_591x135.png 1272w, https://substackcdn.com/image/fetch/$s_!0up8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a99d21d-4247-4a30-93af-ba537c712d37_591x135.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>And in December 2024, he officially tags Funksec group in a Twitter post, where he claims to perform hacking activities on their behalf.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1XKn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc72f0acf-7771-44a4-b953-479eb3bb8d29_665x154.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1XKn!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc72f0acf-7771-44a4-b953-479eb3bb8d29_665x154.png 424w, https://substackcdn.com/image/fetch/$s_!1XKn!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc72f0acf-7771-44a4-b953-479eb3bb8d29_665x154.png 848w, https://substackcdn.com/image/fetch/$s_!1XKn!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc72f0acf-7771-44a4-b953-479eb3bb8d29_665x154.png 1272w, https://substackcdn.com/image/fetch/$s_!1XKn!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc72f0acf-7771-44a4-b953-479eb3bb8d29_665x154.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1XKn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc72f0acf-7771-44a4-b953-479eb3bb8d29_665x154.png" width="665" height="154" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c72f0acf-7771-44a4-b953-479eb3bb8d29_665x154.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:154,&quot;width&quot;:665,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:17438,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/183332412?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc72f0acf-7771-44a4-b953-479eb3bb8d29_665x154.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!1XKn!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc72f0acf-7771-44a4-b953-479eb3bb8d29_665x154.png 424w, https://substackcdn.com/image/fetch/$s_!1XKn!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc72f0acf-7771-44a4-b953-479eb3bb8d29_665x154.png 848w, https://substackcdn.com/image/fetch/$s_!1XKn!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc72f0acf-7771-44a4-b953-479eb3bb8d29_665x154.png 1272w, https://substackcdn.com/image/fetch/$s_!1XKn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc72f0acf-7771-44a4-b953-479eb3bb8d29_665x154.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Also, when comparing Sentap&#8217;s methods and technical abilities with Funksec&#8217;s, there is a huge similarity, as they both opportunistically engage with small-sized organizations with the same modus operandi.</p><p>On top of that, in a discussion forum, a comment by Sentap was captured, where he goes against those who claim the hacking software of Fucksec was built by AI agents, dismisses the claim, mocks those spreading it, and emphasizes that, in his view, it is baseless chatter rather than anything grounded in real technology.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6j9R!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad1de216-57ab-47c1-a1d2-89a8f78235fe_979x246.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6j9R!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad1de216-57ab-47c1-a1d2-89a8f78235fe_979x246.png 424w, https://substackcdn.com/image/fetch/$s_!6j9R!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad1de216-57ab-47c1-a1d2-89a8f78235fe_979x246.png 848w, https://substackcdn.com/image/fetch/$s_!6j9R!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad1de216-57ab-47c1-a1d2-89a8f78235fe_979x246.png 1272w, https://substackcdn.com/image/fetch/$s_!6j9R!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad1de216-57ab-47c1-a1d2-89a8f78235fe_979x246.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6j9R!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad1de216-57ab-47c1-a1d2-89a8f78235fe_979x246.png" width="979" height="246" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ad1de216-57ab-47c1-a1d2-89a8f78235fe_979x246.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:246,&quot;width&quot;:979,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:139085,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/183332412?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad1de216-57ab-47c1-a1d2-89a8f78235fe_979x246.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6j9R!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad1de216-57ab-47c1-a1d2-89a8f78235fe_979x246.png 424w, https://substackcdn.com/image/fetch/$s_!6j9R!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad1de216-57ab-47c1-a1d2-89a8f78235fe_979x246.png 848w, https://substackcdn.com/image/fetch/$s_!6j9R!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad1de216-57ab-47c1-a1d2-89a8f78235fe_979x246.png 1272w, https://substackcdn.com/image/fetch/$s_!6j9R!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad1de216-57ab-47c1-a1d2-89a8f78235fe_979x246.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.darksignal.co/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Zagros: An Internet Access Solution or Pro Iranian Hacking Operation?]]></title><description><![CDATA[Zagros Platform]]></description><link>https://www.darksignal.co/p/zagros-an-internet-access-solution</link><guid isPermaLink="false">https://www.darksignal.co/p/zagros-an-internet-access-solution</guid><dc:creator><![CDATA[DarkSignal]]></dc:creator><pubDate>Wed, 17 Dec 2025 08:10:17 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!DjuJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf3911f2-7aed-4e06-8b6c-3f62ca8fb13b_1024x1362.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!DjuJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf3911f2-7aed-4e06-8b6c-3f62ca8fb13b_1024x1362.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!DjuJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf3911f2-7aed-4e06-8b6c-3f62ca8fb13b_1024x1362.png 424w, https://substackcdn.com/image/fetch/$s_!DjuJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf3911f2-7aed-4e06-8b6c-3f62ca8fb13b_1024x1362.png 848w, https://substackcdn.com/image/fetch/$s_!DjuJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf3911f2-7aed-4e06-8b6c-3f62ca8fb13b_1024x1362.png 1272w, https://substackcdn.com/image/fetch/$s_!DjuJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf3911f2-7aed-4e06-8b6c-3f62ca8fb13b_1024x1362.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!DjuJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf3911f2-7aed-4e06-8b6c-3f62ca8fb13b_1024x1362.png" width="1024" height="1362" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cf3911f2-7aed-4e06-8b6c-3f62ca8fb13b_1024x1362.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1362,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3090674,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/181577195?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc4fd3a7c-ff41-4771-899d-e10319b47a8f_1024x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!DjuJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf3911f2-7aed-4e06-8b6c-3f62ca8fb13b_1024x1362.png 424w, https://substackcdn.com/image/fetch/$s_!DjuJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf3911f2-7aed-4e06-8b6c-3f62ca8fb13b_1024x1362.png 848w, https://substackcdn.com/image/fetch/$s_!DjuJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf3911f2-7aed-4e06-8b6c-3f62ca8fb13b_1024x1362.png 1272w, https://substackcdn.com/image/fetch/$s_!DjuJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf3911f2-7aed-4e06-8b6c-3f62ca8fb13b_1024x1362.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Zagros Platform</h2><p>The &#8220;Zagros&#8221; service, operated by the Amn Pardaz Nasr Zagros Company, is an officially declared Iranian product designed to provide a domestically controlled solution for accessing the global internet. Its primary purpose is to enable users within the Islamic Republic of Iran to bypass international sanctions and government filtering/blocking of online systems and websites.</p><p>The service is explicitly described as an Iranian product offering &#8220;unrestricted access to sites and systems that are sanctioned or sensitive to the IP address of our country (Islamic Republic of Iran)&#8221;. Technically, it is presented as an alternative to often insecure external tools, aiming to &#8220;eliminate the need for... any filter breakers and insecure VPN services&#8221; and prevent data leakage in sanctioned or sensitive services.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.darksignal.co/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>This strongly suggests its operation as a sophisticated DNS resolver or a similar centralized proxy infrastructure that offers a regulated and monitored channel for external access while being marketed to key demographic sectors such as programmers, graphic designers, gamers, students, and digital currency activists.</p><p>Despite marketing itself with features like &#8220;Sustainable security&#8221; and &#8220;Global END to END encryption&#8221;, Zagros&#8217;s privacy policy contains a critical provision that indicates potential state surveillance and control. While the service claims to protect user privacy, its terms confirm that the service provider has access to users&#8217; personal details, including full name, phone number, and password. Crucially, this sensitive data <strong>&#8220;will be provided upon official request from competent authorities&#8221;</strong>. This policy guarantees that Iranian security or intelligence agencies have a clear, documented path to obtain the identity and activity data of any user, effectively centralizing control over the circumvention process and raising serious concerns about surveillance for political activists or others deemed a risk to the regime.</p><div class="image-gallery-embed" data-attrs="{&quot;gallery&quot;:{&quot;images&quot;:[{&quot;type&quot;:&quot;image/png&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4a7b75eb-9f05-410d-b418-bb83561dbaa6_649x454.png&quot;},{&quot;type&quot;:&quot;image/png&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4ff15e15-6d36-46df-b539-eb0d869bf58f_1285x362.png&quot;}],&quot;caption&quot;:&quot;&quot;,&quot;alt&quot;:&quot;&quot;,&quot;staticGalleryImage&quot;:{&quot;type&quot;:&quot;image/png&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e416256e-f79f-4179-b510-6e66505dc0f3_1456x720.png&quot;}},&quot;isEditorNode&quot;:true}"></div><h2><strong>Infrastructure Doesn&#8217;t Lie</strong></h2><p>The IP address of the website is 185[.]164[.]72[.]226, hosted by Pars Parva System LLC, Iran, a data provided by NSlookup search.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!JPBP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9af541fe-c596-46e5-a5a4-41868c58337d_803x115.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!JPBP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9af541fe-c596-46e5-a5a4-41868c58337d_803x115.png 424w, https://substackcdn.com/image/fetch/$s_!JPBP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9af541fe-c596-46e5-a5a4-41868c58337d_803x115.png 848w, https://substackcdn.com/image/fetch/$s_!JPBP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9af541fe-c596-46e5-a5a4-41868c58337d_803x115.png 1272w, https://substackcdn.com/image/fetch/$s_!JPBP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9af541fe-c596-46e5-a5a4-41868c58337d_803x115.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!JPBP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9af541fe-c596-46e5-a5a4-41868c58337d_803x115.png" width="803" height="115" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9af541fe-c596-46e5-a5a4-41868c58337d_803x115.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:115,&quot;width&quot;:803,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:7329,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/181577195?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9af541fe-c596-46e5-a5a4-41868c58337d_803x115.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!JPBP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9af541fe-c596-46e5-a5a4-41868c58337d_803x115.png 424w, https://substackcdn.com/image/fetch/$s_!JPBP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9af541fe-c596-46e5-a5a4-41868c58337d_803x115.png 848w, https://substackcdn.com/image/fetch/$s_!JPBP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9af541fe-c596-46e5-a5a4-41868c58337d_803x115.png 1272w, https://substackcdn.com/image/fetch/$s_!JPBP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9af541fe-c596-46e5-a5a4-41868c58337d_803x115.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>While searching other entities using the IP address, I found a domain named &#8220;thekitten.ir.zagrosguard.ir&#8221; with the same IP address, the same ASN.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!DnN_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff17ebb9c-6eda-42fb-94d2-a5c8f9a594d5_393x261.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!DnN_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff17ebb9c-6eda-42fb-94d2-a5c8f9a594d5_393x261.png 424w, https://substackcdn.com/image/fetch/$s_!DnN_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff17ebb9c-6eda-42fb-94d2-a5c8f9a594d5_393x261.png 848w, https://substackcdn.com/image/fetch/$s_!DnN_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff17ebb9c-6eda-42fb-94d2-a5c8f9a594d5_393x261.png 1272w, https://substackcdn.com/image/fetch/$s_!DnN_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff17ebb9c-6eda-42fb-94d2-a5c8f9a594d5_393x261.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!DnN_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff17ebb9c-6eda-42fb-94d2-a5c8f9a594d5_393x261.png" width="393" height="261" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f17ebb9c-6eda-42fb-94d2-a5c8f9a594d5_393x261.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:261,&quot;width&quot;:393,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:14750,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/181577195?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff17ebb9c-6eda-42fb-94d2-a5c8f9a594d5_393x261.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!DnN_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff17ebb9c-6eda-42fb-94d2-a5c8f9a594d5_393x261.png 424w, https://substackcdn.com/image/fetch/$s_!DnN_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff17ebb9c-6eda-42fb-94d2-a5c8f9a594d5_393x261.png 848w, https://substackcdn.com/image/fetch/$s_!DnN_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff17ebb9c-6eda-42fb-94d2-a5c8f9a594d5_393x261.png 1272w, https://substackcdn.com/image/fetch/$s_!DnN_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff17ebb9c-6eda-42fb-94d2-a5c8f9a594d5_393x261.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The obvious mention to thekitten[.]ir is a direct link to thekitten[.]group, a <strong>covert pro-Iranian infrastructure</strong> designed to support cyber warfare and espionage against Israeli and other targets. This platform functions as a sophisticated communication hub aimed at coordinating hostile cyber activities by different pro-Iranian groups.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0AzI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F323c4274-7ef9-41ac-b961-ef68e2b1f396_1307x706.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0AzI!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F323c4274-7ef9-41ac-b961-ef68e2b1f396_1307x706.png 424w, https://substackcdn.com/image/fetch/$s_!0AzI!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F323c4274-7ef9-41ac-b961-ef68e2b1f396_1307x706.png 848w, https://substackcdn.com/image/fetch/$s_!0AzI!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F323c4274-7ef9-41ac-b961-ef68e2b1f396_1307x706.png 1272w, https://substackcdn.com/image/fetch/$s_!0AzI!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F323c4274-7ef9-41ac-b961-ef68e2b1f396_1307x706.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0AzI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F323c4274-7ef9-41ac-b961-ef68e2b1f396_1307x706.png" width="1307" height="706" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/323c4274-7ef9-41ac-b961-ef68e2b1f396_1307x706.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:706,&quot;width&quot;:1307,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:16322,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/181577195?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F323c4274-7ef9-41ac-b961-ef68e2b1f396_1307x706.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!0AzI!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F323c4274-7ef9-41ac-b961-ef68e2b1f396_1307x706.png 424w, https://substackcdn.com/image/fetch/$s_!0AzI!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F323c4274-7ef9-41ac-b961-ef68e2b1f396_1307x706.png 848w, https://substackcdn.com/image/fetch/$s_!0AzI!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F323c4274-7ef9-41ac-b961-ef68e2b1f396_1307x706.png 1272w, https://substackcdn.com/image/fetch/$s_!0AzI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F323c4274-7ef9-41ac-b961-ef68e2b1f396_1307x706.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Hi Kitty Kitty</strong></h2><p>The site is built as a <strong>closed and monitored communication platform</strong>, featuring a dark homepage with a form for submitting a <strong>Signal ID and email address</strong>. This design choice indicates an intent to establish a private and ostensibly secure communication channel, operating outside of conventional networks, and requires the <strong>preliminary identification</strong> of its users.</p><p>The inclusion of a validation modal featuring a <strong>64-digit Tracking ID</strong> clarifies that this is not an arbitrary platform, such a long and unique identifier enables the <strong>precise identification, linking, and monitoring</strong> of every single user or &#8220;activist&#8221; accessing or requesting entry to the site.</p><p>Functionally, this setup provides a <strong>secure, internal &#8220;War Room&#8221; infrastructure</strong> for cyber groups operating in service of Iranian objectives, complete with a high capacity for internal surveillance and control.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ByWO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6dc38fa2-7dfd-4f65-9acd-d9cfc9e2cf5a_603x349.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ByWO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6dc38fa2-7dfd-4f65-9acd-d9cfc9e2cf5a_603x349.png 424w, https://substackcdn.com/image/fetch/$s_!ByWO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6dc38fa2-7dfd-4f65-9acd-d9cfc9e2cf5a_603x349.png 848w, https://substackcdn.com/image/fetch/$s_!ByWO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6dc38fa2-7dfd-4f65-9acd-d9cfc9e2cf5a_603x349.png 1272w, https://substackcdn.com/image/fetch/$s_!ByWO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6dc38fa2-7dfd-4f65-9acd-d9cfc9e2cf5a_603x349.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ByWO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6dc38fa2-7dfd-4f65-9acd-d9cfc9e2cf5a_603x349.png" width="603" height="349" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6dc38fa2-7dfd-4f65-9acd-d9cfc9e2cf5a_603x349.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:349,&quot;width&quot;:603,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:8394,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/181577195?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6dc38fa2-7dfd-4f65-9acd-d9cfc9e2cf5a_603x349.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ByWO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6dc38fa2-7dfd-4f65-9acd-d9cfc9e2cf5a_603x349.png 424w, https://substackcdn.com/image/fetch/$s_!ByWO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6dc38fa2-7dfd-4f65-9acd-d9cfc9e2cf5a_603x349.png 848w, https://substackcdn.com/image/fetch/$s_!ByWO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6dc38fa2-7dfd-4f65-9acd-d9cfc9e2cf5a_603x349.png 1272w, https://substackcdn.com/image/fetch/$s_!ByWO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6dc38fa2-7dfd-4f65-9acd-d9cfc9e2cf5a_603x349.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Despite its claims of &#8220;independence&#8221; within the About Us section, the site&#8217;s public declaration is saturated with <strong>explicit pro-Iranian ideological markers</strong>. The use of terminology such as <strong>&#8220;The Front&#8221;</strong>,<strong> &#8220;The Resistance&#8221;</strong>,<strong> and &#8220;Jihad&#8221;</strong> is fundamental terms within the narrative of the Islamic Revolutionary Guard Corps (IRGC) and the Iranian-led Shiite Axis. Furthermore, the explicit call to action, <strong>declaring support for cyber groups operating against the &#8220;Zionist regime,&#8221;</strong> clearly positions the website as an active component of the Iranian non-state actors&#8217; warfare apparatus, even if its institutional affiliation is unofficial or concealed. This makes the platform an ideological front aimed at recruiting and coordinating activists against Israel.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xLTB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e0cbd7f-be0e-41bf-8a81-d920eaf32151_932x786.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xLTB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e0cbd7f-be0e-41bf-8a81-d920eaf32151_932x786.png 424w, https://substackcdn.com/image/fetch/$s_!xLTB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e0cbd7f-be0e-41bf-8a81-d920eaf32151_932x786.png 848w, https://substackcdn.com/image/fetch/$s_!xLTB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e0cbd7f-be0e-41bf-8a81-d920eaf32151_932x786.png 1272w, https://substackcdn.com/image/fetch/$s_!xLTB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e0cbd7f-be0e-41bf-8a81-d920eaf32151_932x786.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xLTB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e0cbd7f-be0e-41bf-8a81-d920eaf32151_932x786.png" width="728" height="613.9570815450644" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3e0cbd7f-be0e-41bf-8a81-d920eaf32151_932x786.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;normal&quot;,&quot;height&quot;:786,&quot;width&quot;:932,&quot;resizeWidth&quot;:728,&quot;bytes&quot;:99278,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/181577195?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e0cbd7f-be0e-41bf-8a81-d920eaf32151_932x786.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:&quot;center&quot;,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!xLTB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e0cbd7f-be0e-41bf-8a81-d920eaf32151_932x786.png 424w, https://substackcdn.com/image/fetch/$s_!xLTB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e0cbd7f-be0e-41bf-8a81-d920eaf32151_932x786.png 848w, https://substackcdn.com/image/fetch/$s_!xLTB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e0cbd7f-be0e-41bf-8a81-d920eaf32151_932x786.png 1272w, https://substackcdn.com/image/fetch/$s_!xLTB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e0cbd7f-be0e-41bf-8a81-d920eaf32151_932x786.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The website directly mentions three known hacking groups that attacked Israel and its allies multiple times, which shows their association with the kitten website.</p><div class="image-gallery-embed" data-attrs="{&quot;gallery&quot;:{&quot;images&quot;:[{&quot;type&quot;:&quot;image/png&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c653fd3b-3a31-4f68-b18c-d43c9cd3c0fc_310x292.png&quot;},{&quot;type&quot;:&quot;image/png&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8afbe108-aeb3-4f19-9c08-03057e276613_269x261.png&quot;},{&quot;type&quot;:&quot;image/png&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e3bb4d69-ed6a-4691-8283-765953f2d2bc_219x250.png&quot;}],&quot;caption&quot;:&quot;&quot;,&quot;alt&quot;:&quot;&quot;,&quot;staticGalleryImage&quot;:{&quot;type&quot;:&quot;image/png&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/51d0f46b-7e48-487a-b95a-dc9ca27a1e5f_1456x474.png&quot;}},&quot;isEditorNode&quot;:true}"></div><h2><strong>Clues of Financial Ties With IRGC</strong></h2><p>The company frames Zagros as far more than just a technical utility, positioning it as a strategic asset with deep ideological ties to the regime. The developers categorise the service as &#8220;The Second Step of the Islamic Revolution and the Social Mission&#8221;, with the intent to provide the necessary infrastructure for Iranian users to access sanctioned content so that it can &#8220;play a small role in realising the statements of the wise and wise Leader of Iran&#8221;. This ideological commitment is also reflected in its financial model, as all funds paid by users for the subscription service are explicitly stated to be spent on <strong>&#8220;jihad and deprivation relief activities&#8221;</strong>, linking the service&#8217;s commercial revenue directly to the IRGC&#8217;s funding and social initiatives.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xqow!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1cfe4cc-3aef-4120-9fbe-599f2b7accf2_549x142.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xqow!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1cfe4cc-3aef-4120-9fbe-599f2b7accf2_549x142.png 424w, https://substackcdn.com/image/fetch/$s_!xqow!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1cfe4cc-3aef-4120-9fbe-599f2b7accf2_549x142.png 848w, https://substackcdn.com/image/fetch/$s_!xqow!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1cfe4cc-3aef-4120-9fbe-599f2b7accf2_549x142.png 1272w, https://substackcdn.com/image/fetch/$s_!xqow!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1cfe4cc-3aef-4120-9fbe-599f2b7accf2_549x142.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xqow!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1cfe4cc-3aef-4120-9fbe-599f2b7accf2_549x142.png" width="549" height="142" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b1cfe4cc-3aef-4120-9fbe-599f2b7accf2_549x142.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:142,&quot;width&quot;:549,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:8017,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/181577195?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1cfe4cc-3aef-4120-9fbe-599f2b7accf2_549x142.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!xqow!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1cfe4cc-3aef-4120-9fbe-599f2b7accf2_549x142.png 424w, https://substackcdn.com/image/fetch/$s_!xqow!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1cfe4cc-3aef-4120-9fbe-599f2b7accf2_549x142.png 848w, https://substackcdn.com/image/fetch/$s_!xqow!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1cfe4cc-3aef-4120-9fbe-599f2b7accf2_549x142.png 1272w, https://substackcdn.com/image/fetch/$s_!xqow!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1cfe4cc-3aef-4120-9fbe-599f2b7accf2_549x142.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2><strong>Hidden Pages, Open Road</strong></h2><p>When trying to understand the different pages I can access in this website, I tried URL fuzzing techniques, a thing that revealed two unrestricted, but yet, very sensitive pages with the status code 200 (OK) &#8211; admin &amp; cPanel.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!JhkU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4ab3f88-c284-4cb6-98a1-044143cbea43_1564x164.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!JhkU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4ab3f88-c284-4cb6-98a1-044143cbea43_1564x164.png 424w, https://substackcdn.com/image/fetch/$s_!JhkU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4ab3f88-c284-4cb6-98a1-044143cbea43_1564x164.png 848w, https://substackcdn.com/image/fetch/$s_!JhkU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4ab3f88-c284-4cb6-98a1-044143cbea43_1564x164.png 1272w, https://substackcdn.com/image/fetch/$s_!JhkU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4ab3f88-c284-4cb6-98a1-044143cbea43_1564x164.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!JhkU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4ab3f88-c284-4cb6-98a1-044143cbea43_1564x164.png" width="1456" height="153" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f4ab3f88-c284-4cb6-98a1-044143cbea43_1564x164.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:153,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:13877,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/181577195?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4ab3f88-c284-4cb6-98a1-044143cbea43_1564x164.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!JhkU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4ab3f88-c284-4cb6-98a1-044143cbea43_1564x164.png 424w, https://substackcdn.com/image/fetch/$s_!JhkU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4ab3f88-c284-4cb6-98a1-044143cbea43_1564x164.png 848w, https://substackcdn.com/image/fetch/$s_!JhkU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4ab3f88-c284-4cb6-98a1-044143cbea43_1564x164.png 1272w, https://substackcdn.com/image/fetch/$s_!JhkU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4ab3f88-c284-4cb6-98a1-044143cbea43_1564x164.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>The cPanel (login page for the control panel) runs on port 2083, requires login credentials that I&#8217;m not sure if configured with OTP that will alert the suspects, so I chose the second-best option.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!WSbJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5166689-2b1c-460f-87d6-da824fc30110_1022x548.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!WSbJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5166689-2b1c-460f-87d6-da824fc30110_1022x548.png 424w, https://substackcdn.com/image/fetch/$s_!WSbJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5166689-2b1c-460f-87d6-da824fc30110_1022x548.png 848w, https://substackcdn.com/image/fetch/$s_!WSbJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5166689-2b1c-460f-87d6-da824fc30110_1022x548.png 1272w, https://substackcdn.com/image/fetch/$s_!WSbJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5166689-2b1c-460f-87d6-da824fc30110_1022x548.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!WSbJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5166689-2b1c-460f-87d6-da824fc30110_1022x548.png" width="1022" height="548" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f5166689-2b1c-460f-87d6-da824fc30110_1022x548.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:548,&quot;width&quot;:1022,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:65633,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/181577195?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5166689-2b1c-460f-87d6-da824fc30110_1022x548.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!WSbJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5166689-2b1c-460f-87d6-da824fc30110_1022x548.png 424w, https://substackcdn.com/image/fetch/$s_!WSbJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5166689-2b1c-460f-87d6-da824fc30110_1022x548.png 848w, https://substackcdn.com/image/fetch/$s_!WSbJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5166689-2b1c-460f-87d6-da824fc30110_1022x548.png 1272w, https://substackcdn.com/image/fetch/$s_!WSbJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5166689-2b1c-460f-87d6-da824fc30110_1022x548.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Inside The System</strong></h2><p>Since the admin page is also accessible, I was able to download the actual admin.zip file and review it for further understanding of the system and architecture of the website.</p><p>The availability of this file for download meant that I was able to obtain a complete production build of the administration interface. The bundle exposed all frontend logic, including business flows, routing structure, and the communication patterns used by the client when interacting with the backend. This constitutes an unintended information disclosure that provides detailed insight into the internal structure of the administration system.</p><p>The file revealed all API endpoints used by the admin panel, including those responsible for viewing, editing, deleting, uploading, and downloading data, as well as additional administrative operations.</p><p>It also exposed the authentication flow, including cookie-based session handling, CSRF mechanisms, and the exact request/response formats the client and server expect.</p><p>This information provided me with the understanding of how login is performed, how the authenticated state is maintained, and which backend interactions are critical to the system&#8217;s operation.</p><p>With these data pieces, if I wanted, I could focus directly on high-value operations such as authorisation checks, potential authentication bypass attempts, IDOR testing, and targeted probing of sensitive actions, including deletions, updates, and file handling.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!sdTC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca19a8f7-35fc-4d4c-8952-6b885fecc0e0_571x189.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!sdTC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca19a8f7-35fc-4d4c-8952-6b885fecc0e0_571x189.png 424w, https://substackcdn.com/image/fetch/$s_!sdTC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca19a8f7-35fc-4d4c-8952-6b885fecc0e0_571x189.png 848w, https://substackcdn.com/image/fetch/$s_!sdTC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca19a8f7-35fc-4d4c-8952-6b885fecc0e0_571x189.png 1272w, https://substackcdn.com/image/fetch/$s_!sdTC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca19a8f7-35fc-4d4c-8952-6b885fecc0e0_571x189.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!sdTC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca19a8f7-35fc-4d4c-8952-6b885fecc0e0_571x189.png" width="571" height="189" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ca19a8f7-35fc-4d4c-8952-6b885fecc0e0_571x189.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:189,&quot;width&quot;:571,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:48735,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/181577195?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca19a8f7-35fc-4d4c-8952-6b885fecc0e0_571x189.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!sdTC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca19a8f7-35fc-4d4c-8952-6b885fecc0e0_571x189.png 424w, https://substackcdn.com/image/fetch/$s_!sdTC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca19a8f7-35fc-4d4c-8952-6b885fecc0e0_571x189.png 848w, https://substackcdn.com/image/fetch/$s_!sdTC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca19a8f7-35fc-4d4c-8952-6b885fecc0e0_571x189.png 1272w, https://substackcdn.com/image/fetch/$s_!sdTC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca19a8f7-35fc-4d4c-8952-6b885fecc0e0_571x189.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2><strong>Technical Analysis of The Code</strong></h2><p>The code exposes the internal admin API through an Axios client configured with <code>baseURL: &#8220;/api/admin/&#8221;</code> and <code>withCredentials: true</code>. Directly visible endpoints include, for example, <code>POST /api/admin/view-client</code> for retrieving client data by <code>tracking_id</code>, and <code>GET /api/admin/view-clients</code> for listing all clients. <br>Additional operations, such as file upload, file deletion, message handling, and project management, are also explicitly mapped <code>(POST /api/admin/upload-files, GET /api/admin/get-projects</code>). The authentication flow is similarly exposed through endpoints such as <code>GET /api/admin/checking</code>, <code>POST /api/admin/login</code>, and <code>POST /api/admin/logout</code>.</p><p>Admin interface routes (React Router) are fully visible in the bundle. Examples include <code>/admin/home</code> for the main dashboard, <code>/admin/pro-iran-projects</code> for project management, and <code>/admin/view-request/:tracking_id</code> for viewing a specific request based on a route parameter. These routes reveal the exact internal structure and navigation logic of the admin panel.</p><p>Client and request data retrieval are handled directly through service functions defined in the code. For instance, <code>POST /api/admin/view-client</code> is used to load a specific client&#8217;s details and <code>GET /api/admin/view-clients</code> returns a list of all clients. The code also exposes how updates are performed, such as <code>POST /api/admin/update-status</code> for modifying a client&#8217;s status. These functions demonstrate the precise request formats and expected backend responses.</p><h2><strong>Online Appearance and Digital Exposure</strong></h2><p>Once I saw the association and connection between the platforms and understood it is no more than a front for cyber-terror activities, I started to map the footprint of these entities, to check if I could find numbers, emails or even a real person associated with this operation.</p><p>Since Zagros platform was the first lead, that was my starting point in this discipline.<br>I was managed to find a Telegram channel of Zagros IP, under the name &#8220;ZAGROS | Channel&#8221;, with their official logo, that counts 31 subscribers. Already claims to be a front shell, with barely any actual activity. The BIO contains direct reference to their website, and two different Telegram bots, one for support and the second for purchasing.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!sQC6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70c2936c-bbb5-4917-9470-ebfbbaf3e089_488x625.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!sQC6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70c2936c-bbb5-4917-9470-ebfbbaf3e089_488x625.png 424w, https://substackcdn.com/image/fetch/$s_!sQC6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70c2936c-bbb5-4917-9470-ebfbbaf3e089_488x625.png 848w, https://substackcdn.com/image/fetch/$s_!sQC6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70c2936c-bbb5-4917-9470-ebfbbaf3e089_488x625.png 1272w, https://substackcdn.com/image/fetch/$s_!sQC6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70c2936c-bbb5-4917-9470-ebfbbaf3e089_488x625.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!sQC6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70c2936c-bbb5-4917-9470-ebfbbaf3e089_488x625.png" width="488" height="625" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/70c2936c-bbb5-4917-9470-ebfbbaf3e089_488x625.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:625,&quot;width&quot;:488,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:37939,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/181577195?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70c2936c-bbb5-4917-9470-ebfbbaf3e089_488x625.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!sQC6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70c2936c-bbb5-4917-9470-ebfbbaf3e089_488x625.png 424w, https://substackcdn.com/image/fetch/$s_!sQC6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70c2936c-bbb5-4917-9470-ebfbbaf3e089_488x625.png 848w, https://substackcdn.com/image/fetch/$s_!sQC6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70c2936c-bbb5-4917-9470-ebfbbaf3e089_488x625.png 1272w, https://substackcdn.com/image/fetch/$s_!sQC6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70c2936c-bbb5-4917-9470-ebfbbaf3e089_488x625.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>While reviewing old messages in their channel, I found one that particularly stood out, containing two different phone numbers for WhatsApp contact, an Instagram account, and an official phone number.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!PTkQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f948f03-045e-48b5-9218-82782e8185ee_368x627.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!PTkQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f948f03-045e-48b5-9218-82782e8185ee_368x627.png 424w, https://substackcdn.com/image/fetch/$s_!PTkQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f948f03-045e-48b5-9218-82782e8185ee_368x627.png 848w, https://substackcdn.com/image/fetch/$s_!PTkQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f948f03-045e-48b5-9218-82782e8185ee_368x627.png 1272w, https://substackcdn.com/image/fetch/$s_!PTkQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f948f03-045e-48b5-9218-82782e8185ee_368x627.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!PTkQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f948f03-045e-48b5-9218-82782e8185ee_368x627.png" width="368" height="627" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6f948f03-045e-48b5-9218-82782e8185ee_368x627.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:627,&quot;width&quot;:368,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:20319,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/181577195?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f948f03-045e-48b5-9218-82782e8185ee_368x627.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!PTkQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f948f03-045e-48b5-9218-82782e8185ee_368x627.png 424w, https://substackcdn.com/image/fetch/$s_!PTkQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f948f03-045e-48b5-9218-82782e8185ee_368x627.png 848w, https://substackcdn.com/image/fetch/$s_!PTkQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f948f03-045e-48b5-9218-82782e8185ee_368x627.png 1272w, https://substackcdn.com/image/fetch/$s_!PTkQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f948f03-045e-48b5-9218-82782e8185ee_368x627.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>All numbers are virtual SIM cards, originating from Turkey and registered to WhatsApp only, with no previous activity of any kind, so this lead wasn&#8217;t very useful. The users also didn&#8217;t provide any relevant information, but then I thought - if Zagros is a front shell for the kitten&#8217;s platform, whoever created Zagros is the owner of the operation, or at least, co-owner. So that&#8217;s what I did.</p><h2><strong>Attribution Begins with a Single Domain</strong></h2><p>The domain zagros-ip[.]com was part of a data leak from 2018, and revealed a person under the name Mohammad Farshidmehr, an Iranian citizen from Shiraz city.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!z-yW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4204ab17-72d4-4643-a403-a2e2d5eba47e_495x203.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!z-yW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4204ab17-72d4-4643-a403-a2e2d5eba47e_495x203.png 424w, https://substackcdn.com/image/fetch/$s_!z-yW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4204ab17-72d4-4643-a403-a2e2d5eba47e_495x203.png 848w, https://substackcdn.com/image/fetch/$s_!z-yW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4204ab17-72d4-4643-a403-a2e2d5eba47e_495x203.png 1272w, https://substackcdn.com/image/fetch/$s_!z-yW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4204ab17-72d4-4643-a403-a2e2d5eba47e_495x203.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!z-yW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4204ab17-72d4-4643-a403-a2e2d5eba47e_495x203.png" width="495" height="203" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4204ab17-72d4-4643-a403-a2e2d5eba47e_495x203.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:203,&quot;width&quot;:495,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:23133,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/181577195?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4204ab17-72d4-4643-a403-a2e2d5eba47e_495x203.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!z-yW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4204ab17-72d4-4643-a403-a2e2d5eba47e_495x203.png 424w, https://substackcdn.com/image/fetch/$s_!z-yW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4204ab17-72d4-4643-a403-a2e2d5eba47e_495x203.png 848w, https://substackcdn.com/image/fetch/$s_!z-yW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4204ab17-72d4-4643-a403-a2e2d5eba47e_495x203.png 1272w, https://substackcdn.com/image/fetch/$s_!z-yW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4204ab17-72d4-4643-a403-a2e2d5eba47e_495x203.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>The individual appears to be a web designer and software developer, living in Australia these days, as appeared on his resume.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!adkZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1dcfe79-e4f8-4965-b396-bb553b12c096_761x396.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!adkZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1dcfe79-e4f8-4965-b396-bb553b12c096_761x396.png 424w, https://substackcdn.com/image/fetch/$s_!adkZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1dcfe79-e4f8-4965-b396-bb553b12c096_761x396.png 848w, https://substackcdn.com/image/fetch/$s_!adkZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1dcfe79-e4f8-4965-b396-bb553b12c096_761x396.png 1272w, https://substackcdn.com/image/fetch/$s_!adkZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1dcfe79-e4f8-4965-b396-bb553b12c096_761x396.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!adkZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1dcfe79-e4f8-4965-b396-bb553b12c096_761x396.png" width="761" height="396" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c1dcfe79-e4f8-4965-b396-bb553b12c096_761x396.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:396,&quot;width&quot;:761,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:50492,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/181577195?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1dcfe79-e4f8-4965-b396-bb553b12c096_761x396.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!adkZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1dcfe79-e4f8-4965-b396-bb553b12c096_761x396.png 424w, https://substackcdn.com/image/fetch/$s_!adkZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1dcfe79-e4f8-4965-b396-bb553b12c096_761x396.png 848w, https://substackcdn.com/image/fetch/$s_!adkZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1dcfe79-e4f8-4965-b396-bb553b12c096_761x396.png 1272w, https://substackcdn.com/image/fetch/$s_!adkZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1dcfe79-e4f8-4965-b396-bb553b12c096_761x396.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>With a deeper search, I was managed to find a website he created himself, as part of self marketing act. The website contained a symbol (logo) created by himself, possibly a kind of hallmark.</p><p>The first symbol, taken from Mohammad&#8217;s website, uses modern Iranian calligraphy identical to the style found in the official emblem of ZAGROS, the Iranian cyber entity operating as a cover for offensive activity and for supporting anti-Israeli proxy groups.</p><div class="image-gallery-embed" data-attrs="{&quot;gallery&quot;:{&quot;images&quot;:[{&quot;type&quot;:&quot;image/png&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b9a9e857-1c44-4a47-be34-ea0c2f19e1ca_538x577.png&quot;},{&quot;type&quot;:&quot;image/png&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e9dfd3cf-59f2-4909-9c12-1fe2889ed5dc_649x840.png&quot;}],&quot;caption&quot;:&quot;&quot;,&quot;alt&quot;:&quot;&quot;,&quot;staticGalleryImage&quot;:{&quot;type&quot;:&quot;image/png&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8da12189-f812-492e-b69a-21d270a13c11_1456x720.png&quot;}},&quot;isEditorNode&quot;:true}"></div><p>Both symbols rely on the same graphic pattern: Persian line flow, three-dimensional volume construction, curved letterforms resembling the &#8220;<code>&#703;ayn / z&#8221;</code> shapes characteristic of Iranian calligraphic design, and colour usage consistent with the same visual school.</p><p>This graphic overlap is not coincidental, but a reflection of design style commonly associated with Iranian studios working for government-affiliated bodies and pro-Iranian cyber organisations.</p><h2><strong>The Facade That Tells the Truth</strong></h2><p>In practice, the zagrosguard[.]ir domain presents as a relatively simple landing page, with a significant lack of robust and independently verifiable commercial identity. Its stated operational complexity and ideological mission appear to heavily outweigh its minimal public-facing corporate infrastructure.</p><p>Based on this observation, it is highly probable that the public-facing Zagros site primarily functions as a <strong>technological front</strong> or a marketing vehicle for an entirely different, perhaps deeper, network or underlying service.</p><p>This approach allows the operating entity, the Amn Pardaz Nasr Zagros Company, to maintain a strategic distance from its core network infrastructure while simultaneously presenting a sanctioned, ideological, and consumer-friendly interface to domestic users.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.darksignal.co/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Unmasking a Unified Criminal Infrastructure]]></title><description><![CDATA[One IP, Three Faces]]></description><link>https://www.darksignal.co/p/unmasking-a-unified-criminal-infrastructure</link><guid isPermaLink="false">https://www.darksignal.co/p/unmasking-a-unified-criminal-infrastructure</guid><dc:creator><![CDATA[DarkSignal]]></dc:creator><pubDate>Mon, 08 Dec 2025 08:15:51 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!u-PY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa40fb36a-0fa1-4312-9784-f2ba12f4f97e_783x671.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!u-PY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa40fb36a-0fa1-4312-9784-f2ba12f4f97e_783x671.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!u-PY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa40fb36a-0fa1-4312-9784-f2ba12f4f97e_783x671.png 424w, https://substackcdn.com/image/fetch/$s_!u-PY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa40fb36a-0fa1-4312-9784-f2ba12f4f97e_783x671.png 848w, https://substackcdn.com/image/fetch/$s_!u-PY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa40fb36a-0fa1-4312-9784-f2ba12f4f97e_783x671.png 1272w, https://substackcdn.com/image/fetch/$s_!u-PY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa40fb36a-0fa1-4312-9784-f2ba12f4f97e_783x671.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!u-PY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa40fb36a-0fa1-4312-9784-f2ba12f4f97e_783x671.png" width="783" height="671" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a40fb36a-0fa1-4312-9784-f2ba12f4f97e_783x671.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:671,&quot;width&quot;:783,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1080891,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/180941192?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70107a20-fe09-462c-b207-f681b1bbe207_792x1188.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!u-PY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa40fb36a-0fa1-4312-9784-f2ba12f4f97e_783x671.png 424w, https://substackcdn.com/image/fetch/$s_!u-PY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa40fb36a-0fa1-4312-9784-f2ba12f4f97e_783x671.png 848w, https://substackcdn.com/image/fetch/$s_!u-PY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa40fb36a-0fa1-4312-9784-f2ba12f4f97e_783x671.png 1272w, https://substackcdn.com/image/fetch/$s_!u-PY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa40fb36a-0fa1-4312-9784-f2ba12f4f97e_783x671.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><h3>One IP, Three Faces</h3><p>Behind an ordinary-looking IP address lies a machinery of logistics, distribution, and anonymity, intertwined with surgical precision. Each service masks itself behind a different facade, yet their trails converge unmistakably at the same destination. What emerges is not coincidence, but the blueprint of a coordinated criminal-grade infrastructure.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.darksignal.co/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Three so-called different services, one illicit and the others controversial, act as one part of a faulty and criminal network.</p><p>The following report examines a tightly connected cluster of services that operate across the same infrastructure layer and share a common operational footprint. Although each brand presents itself as a separate entity with a distinct purpose, all of them resolve to the same IP address, indicating a unified backend, shared operators, or a consolidated management structure.</p><p>By analysing the hosting patterns, network behaviour, and thematic consistencies, the research demonstrates how these services function as interdependent components within the same criminal-grade digital ecosystem, possibly operated by the same owner (s).</p><h3><strong>The IP Address and Its Services</strong></h3><p>Starting with the IP address 155[.]94[.]145[.]211, I found the three different services hosted at the same address.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!8jsc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5442637-a7c6-4320-b398-c1344407ac18_188x188.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8jsc!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5442637-a7c6-4320-b398-c1344407ac18_188x188.png 424w, https://substackcdn.com/image/fetch/$s_!8jsc!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5442637-a7c6-4320-b398-c1344407ac18_188x188.png 848w, https://substackcdn.com/image/fetch/$s_!8jsc!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5442637-a7c6-4320-b398-c1344407ac18_188x188.png 1272w, https://substackcdn.com/image/fetch/$s_!8jsc!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5442637-a7c6-4320-b398-c1344407ac18_188x188.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8jsc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5442637-a7c6-4320-b398-c1344407ac18_188x188.png" width="188" height="188" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c5442637-a7c6-4320-b398-c1344407ac18_188x188.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:188,&quot;width&quot;:188,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:20361,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/180941192?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5442637-a7c6-4320-b398-c1344407ac18_188x188.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!8jsc!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5442637-a7c6-4320-b398-c1344407ac18_188x188.png 424w, https://substackcdn.com/image/fetch/$s_!8jsc!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5442637-a7c6-4320-b398-c1344407ac18_188x188.png 848w, https://substackcdn.com/image/fetch/$s_!8jsc!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5442637-a7c6-4320-b398-c1344407ac18_188x188.png 1272w, https://substackcdn.com/image/fetch/$s_!8jsc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5442637-a7c6-4320-b398-c1344407ac18_188x188.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><ul><li><p><strong>BulletproofServers - Darknet-Grade Infrastructure Layer</strong></p><p>BulletproofServers is the foundational layer of this ecosystem. It&#8217;s a hosting environment designed for resilience, anonymity, and persistence. This type of hosting prioritizes customer privacy over compliance and offers infrastructure that remains online even under governmental pressure, legal complaints, or even takedown attempts.</p><p>The service promotes &#8220;darknet-grade&#8221; capabilities, including anonymous setup, no identity verification, permissive content policies, full port availability, and flexible server locations.</p><p>In practice, it operates as an infrastructure-as-a-service model for actors requiring stable but anonymous digital real estate.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!BwZ9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b8019b0-a3e9-47dc-be36-ec690e9b6d38_367x124.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!BwZ9!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b8019b0-a3e9-47dc-be36-ec690e9b6d38_367x124.png 424w, https://substackcdn.com/image/fetch/$s_!BwZ9!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b8019b0-a3e9-47dc-be36-ec690e9b6d38_367x124.png 848w, https://substackcdn.com/image/fetch/$s_!BwZ9!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b8019b0-a3e9-47dc-be36-ec690e9b6d38_367x124.png 1272w, https://substackcdn.com/image/fetch/$s_!BwZ9!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b8019b0-a3e9-47dc-be36-ec690e9b6d38_367x124.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!BwZ9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b8019b0-a3e9-47dc-be36-ec690e9b6d38_367x124.png" width="367" height="124" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5b8019b0-a3e9-47dc-be36-ec690e9b6d38_367x124.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:124,&quot;width&quot;:367,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:20875,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/180941192?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b8019b0-a3e9-47dc-be36-ec690e9b6d38_367x124.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!BwZ9!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b8019b0-a3e9-47dc-be36-ec690e9b6d38_367x124.png 424w, https://substackcdn.com/image/fetch/$s_!BwZ9!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b8019b0-a3e9-47dc-be36-ec690e9b6d38_367x124.png 848w, https://substackcdn.com/image/fetch/$s_!BwZ9!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b8019b0-a3e9-47dc-be36-ec690e9b6d38_367x124.png 1272w, https://substackcdn.com/image/fetch/$s_!BwZ9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b8019b0-a3e9-47dc-be36-ec690e9b6d38_367x124.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div></li><li><p><strong>NarcoScandinavia - Nordic Underground Logistics Network</strong></p><p>NarcoScandinavia functions as the mid-stream logistical node within this shared infrastructure. It frames itself as a coordinated logistical network operating across the Nordic region, connecting inbound supply routes with last-mile distribution mechanisms. The brand emphasizes structure, reliability, and systematic distribution, qualities associated with organized logistics cells rather than ad-hoc operations.</p><p>This part of the ecosystem bridges international supply flows with domestic demand points, using both physical and digital mechanisms: communication channels, shipment coordination, encrypted operational management, and networked courier elements. Its presence on the same digital infrastructure suggests that logistics management, customer coordination, and backend administration are handled through a centralized system.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2Ank!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d2d1abe-ec2e-4626-bd86-86abff9f0475_410x99.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2Ank!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d2d1abe-ec2e-4626-bd86-86abff9f0475_410x99.png 424w, https://substackcdn.com/image/fetch/$s_!2Ank!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d2d1abe-ec2e-4626-bd86-86abff9f0475_410x99.png 848w, https://substackcdn.com/image/fetch/$s_!2Ank!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d2d1abe-ec2e-4626-bd86-86abff9f0475_410x99.png 1272w, https://substackcdn.com/image/fetch/$s_!2Ank!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d2d1abe-ec2e-4626-bd86-86abff9f0475_410x99.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2Ank!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d2d1abe-ec2e-4626-bd86-86abff9f0475_410x99.png" width="410" height="99" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6d2d1abe-ec2e-4626-bd86-86abff9f0475_410x99.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:99,&quot;width&quot;:410,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:22611,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/180941192?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d2d1abe-ec2e-4626-bd86-86abff9f0475_410x99.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!2Ank!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d2d1abe-ec2e-4626-bd86-86abff9f0475_410x99.png 424w, https://substackcdn.com/image/fetch/$s_!2Ank!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d2d1abe-ec2e-4626-bd86-86abff9f0475_410x99.png 848w, https://substackcdn.com/image/fetch/$s_!2Ank!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d2d1abe-ec2e-4626-bd86-86abff9f0475_410x99.png 1272w, https://substackcdn.com/image/fetch/$s_!2Ank!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d2d1abe-ec2e-4626-bd86-86abff9f0475_410x99.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div></li><li><p><strong>ElMercado - Drogas Express Espa&#241;a</strong></p><p>ElMercado represents the frontend, the actual service. It&#8217;s a consumer-facing layer of the system. An express-delivery model designed for the rapid fulfillment of different illicit drugs across major Spanish cities. The branding aligns with contemporary &#8220;quick-commerce&#8221; aesthetics - fast delivery, urban coverage, and on-demand availability, but applied to illicit products.</p><p>Operating on the same backend IP, ElMercado appears as the retail endpoint of the ecosystem. While BulletproofServers provides the infrastructure and NarcoScandinavia supports regional logistics, ElMercado translates these capabilities into a commercialized street-level distribution model aimed at end users.</p><div class="image-gallery-embed" data-attrs="{&quot;gallery&quot;:{&quot;images&quot;:[{&quot;type&quot;:&quot;image/png&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a3621887-fa9d-4dda-a3c0-9e8dade27682_254x221.png&quot;},{&quot;type&quot;:&quot;image/png&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7c0dfc48-63a6-4f6b-8c30-fbaf18af7797_336x132.png&quot;}],&quot;caption&quot;:&quot;&quot;,&quot;alt&quot;:&quot;&quot;,&quot;staticGalleryImage&quot;:{&quot;type&quot;:&quot;image/png&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d5b5f52c-fd37-4d00-84a8-1da68299f40c_1456x720.png&quot;}},&quot;isEditorNode&quot;:true}"></div><p>While<strong> BulletproofServers</strong> offers the durable, anonymous backbone, <strong>NarcoScandinavia</strong> manages movement, routing, and distribution across northern Europe, and <strong>ElMercado</strong> provides fast, city-level delivery and customer-facing access for illicit drugs.</p></li></ul><h3><strong>Financial Infrastructure</strong></h3><p>Once the customer chooses the product he desires, he adds it to his cart and proceeds to the payment.</p><p>A new tab opens, asking for the contact method the user prefers, for them to contact first via WhatsApp, Signal, Telegram, Viber or a simple phone call.<br>Such a method indicates a good OPSEC behaviour, eliminating the chance of investigators obtaining their main usernames and contact methods until they will decide to do that (probably after they perform a background check to ensure their safety).</p><p>Once the user has completed his contact details, a new BTC address appears in the payment request to deny the possibility of tracing previous transactions associated with the address.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!D0K5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F705f1bb2-74e8-47f5-935a-557330af3c3e_561x447.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!D0K5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F705f1bb2-74e8-47f5-935a-557330af3c3e_561x447.png 424w, https://substackcdn.com/image/fetch/$s_!D0K5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F705f1bb2-74e8-47f5-935a-557330af3c3e_561x447.png 848w, https://substackcdn.com/image/fetch/$s_!D0K5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F705f1bb2-74e8-47f5-935a-557330af3c3e_561x447.png 1272w, https://substackcdn.com/image/fetch/$s_!D0K5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F705f1bb2-74e8-47f5-935a-557330af3c3e_561x447.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!D0K5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F705f1bb2-74e8-47f5-935a-557330af3c3e_561x447.png" width="561" height="447" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/705f1bb2-74e8-47f5-935a-557330af3c3e_561x447.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:447,&quot;width&quot;:561,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:121823,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/180941192?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F705f1bb2-74e8-47f5-935a-557330af3c3e_561x447.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!D0K5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F705f1bb2-74e8-47f5-935a-557330af3c3e_561x447.png 424w, https://substackcdn.com/image/fetch/$s_!D0K5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F705f1bb2-74e8-47f5-935a-557330af3c3e_561x447.png 848w, https://substackcdn.com/image/fetch/$s_!D0K5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F705f1bb2-74e8-47f5-935a-557330af3c3e_561x447.png 1272w, https://substackcdn.com/image/fetch/$s_!D0K5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F705f1bb2-74e8-47f5-935a-557330af3c3e_561x447.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>And Way Down We Go</strong></h3><p>With the known fact that claims the IP address as the backbone of these three services, I started the investigation with the first one, called &#8220;NarcoScandinavia&#8221;.</p><div class="image-gallery-embed" data-attrs="{&quot;gallery&quot;:{&quot;images&quot;:[{&quot;type&quot;:&quot;image/png&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/da6ea798-e9a0-44e7-812c-a246b45da3b3_334x144.png&quot;},{&quot;type&quot;:&quot;image/png&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e6093798-f8a5-4844-b59b-326942424d59_201x199.png&quot;}],&quot;caption&quot;:&quot;&quot;,&quot;alt&quot;:&quot;&quot;,&quot;staticGalleryImage&quot;:{&quot;type&quot;:&quot;image/png&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/366c4cfa-f4f3-4c2f-853c-2f36c1305225_1456x720.png&quot;}},&quot;isEditorNode&quot;:true}"></div><p>I tried to get as many details about the interface of the website, so I gave a try do web directory search enumeration, to check the different optional pages that answer with a positive response (200), just to find out there aren&#8217;t so many of them, and those that do, lead to the same pages I already visited.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!llkA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a7aff5e-979f-47a8-ae83-b8b0f5f69c9d_235x158.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!llkA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a7aff5e-979f-47a8-ae83-b8b0f5f69c9d_235x158.png 424w, https://substackcdn.com/image/fetch/$s_!llkA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a7aff5e-979f-47a8-ae83-b8b0f5f69c9d_235x158.png 848w, https://substackcdn.com/image/fetch/$s_!llkA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a7aff5e-979f-47a8-ae83-b8b0f5f69c9d_235x158.png 1272w, https://substackcdn.com/image/fetch/$s_!llkA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a7aff5e-979f-47a8-ae83-b8b0f5f69c9d_235x158.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!llkA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a7aff5e-979f-47a8-ae83-b8b0f5f69c9d_235x158.png" width="235" height="158" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3a7aff5e-979f-47a8-ae83-b8b0f5f69c9d_235x158.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:158,&quot;width&quot;:235,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:29306,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/180941192?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a7aff5e-979f-47a8-ae83-b8b0f5f69c9d_235x158.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!llkA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a7aff5e-979f-47a8-ae83-b8b0f5f69c9d_235x158.png 424w, https://substackcdn.com/image/fetch/$s_!llkA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a7aff5e-979f-47a8-ae83-b8b0f5f69c9d_235x158.png 848w, https://substackcdn.com/image/fetch/$s_!llkA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a7aff5e-979f-47a8-ae83-b8b0f5f69c9d_235x158.png 1272w, https://substackcdn.com/image/fetch/$s_!llkA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a7aff5e-979f-47a8-ae83-b8b0f5f69c9d_235x158.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>In the &#8220;contact-us&#8221; page, there is a proton email account nrcscandinavia@proton[.]me, which yielded no results. It wasn&#8217;t in any data leaks, any registration, no web mentions of any kind and zero results at all.</p><p>I gave an honest try to the username itself &#8220;nrcscandinavia&#8221;, which also led to no where. This is not the right approach.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!WD0-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d17e5bd-ee4d-442b-bdd0-a7b0b2b3429a_519x124.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!WD0-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d17e5bd-ee4d-442b-bdd0-a7b0b2b3429a_519x124.png 424w, https://substackcdn.com/image/fetch/$s_!WD0-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d17e5bd-ee4d-442b-bdd0-a7b0b2b3429a_519x124.png 848w, https://substackcdn.com/image/fetch/$s_!WD0-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d17e5bd-ee4d-442b-bdd0-a7b0b2b3429a_519x124.png 1272w, https://substackcdn.com/image/fetch/$s_!WD0-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d17e5bd-ee4d-442b-bdd0-a7b0b2b3429a_519x124.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!WD0-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d17e5bd-ee4d-442b-bdd0-a7b0b2b3429a_519x124.png" width="519" height="124" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3d17e5bd-ee4d-442b-bdd0-a7b0b2b3429a_519x124.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:124,&quot;width&quot;:519,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:17495,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/180941192?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d17e5bd-ee4d-442b-bdd0-a7b0b2b3429a_519x124.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!WD0-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d17e5bd-ee4d-442b-bdd0-a7b0b2b3429a_519x124.png 424w, https://substackcdn.com/image/fetch/$s_!WD0-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d17e5bd-ee4d-442b-bdd0-a7b0b2b3429a_519x124.png 848w, https://substackcdn.com/image/fetch/$s_!WD0-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d17e5bd-ee4d-442b-bdd0-a7b0b2b3429a_519x124.png 1272w, https://substackcdn.com/image/fetch/$s_!WD0-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d17e5bd-ee4d-442b-bdd0-a7b0b2b3429a_519x124.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>When trying the second service, called &#8220;bulletproofservers&#8221;, I started with the name itself and combined various user search manipulations and different dorks to find leads, since there is no actual domain name but only an IP address with a specific port.</p><p>The username itself led to an email address (bulletproofservers@protonmail[.]com), and the Telegram user (bulletproofservers), claiming he is the ADMIN in his BIO.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ktep!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9398c82-faeb-4407-9ca0-92777b04914d_203x199.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ktep!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9398c82-faeb-4407-9ca0-92777b04914d_203x199.png 424w, https://substackcdn.com/image/fetch/$s_!ktep!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9398c82-faeb-4407-9ca0-92777b04914d_203x199.png 848w, https://substackcdn.com/image/fetch/$s_!ktep!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9398c82-faeb-4407-9ca0-92777b04914d_203x199.png 1272w, https://substackcdn.com/image/fetch/$s_!ktep!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9398c82-faeb-4407-9ca0-92777b04914d_203x199.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ktep!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9398c82-faeb-4407-9ca0-92777b04914d_203x199.png" width="203" height="199" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f9398c82-faeb-4407-9ca0-92777b04914d_203x199.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:199,&quot;width&quot;:203,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:20500,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/180941192?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9398c82-faeb-4407-9ca0-92777b04914d_203x199.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ktep!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9398c82-faeb-4407-9ca0-92777b04914d_203x199.png 424w, https://substackcdn.com/image/fetch/$s_!ktep!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9398c82-faeb-4407-9ca0-92777b04914d_203x199.png 848w, https://substackcdn.com/image/fetch/$s_!ktep!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9398c82-faeb-4407-9ca0-92777b04914d_203x199.png 1272w, https://substackcdn.com/image/fetch/$s_!ktep!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9398c82-faeb-4407-9ca0-92777b04914d_203x199.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h3><strong>Not So Bulletproof After All</strong></h3><p>The username was part of a known data leak from a famous hacking group in 2014, revealing a GMAIL address with other details such as DOB, IP address and a user handler in this specific forum.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!dILS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb06b5a4-dfc3-4969-91c5-776fc9b9c1a3_265x176.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!dILS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb06b5a4-dfc3-4969-91c5-776fc9b9c1a3_265x176.png 424w, https://substackcdn.com/image/fetch/$s_!dILS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb06b5a4-dfc3-4969-91c5-776fc9b9c1a3_265x176.png 848w, https://substackcdn.com/image/fetch/$s_!dILS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb06b5a4-dfc3-4969-91c5-776fc9b9c1a3_265x176.png 1272w, https://substackcdn.com/image/fetch/$s_!dILS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb06b5a4-dfc3-4969-91c5-776fc9b9c1a3_265x176.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!dILS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb06b5a4-dfc3-4969-91c5-776fc9b9c1a3_265x176.png" width="265" height="176" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fb06b5a4-dfc3-4969-91c5-776fc9b9c1a3_265x176.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:176,&quot;width&quot;:265,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:31378,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/180941192?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb06b5a4-dfc3-4969-91c5-776fc9b9c1a3_265x176.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!dILS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb06b5a4-dfc3-4969-91c5-776fc9b9c1a3_265x176.png 424w, https://substackcdn.com/image/fetch/$s_!dILS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb06b5a4-dfc3-4969-91c5-776fc9b9c1a3_265x176.png 848w, https://substackcdn.com/image/fetch/$s_!dILS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb06b5a4-dfc3-4969-91c5-776fc9b9c1a3_265x176.png 1272w, https://substackcdn.com/image/fetch/$s_!dILS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb06b5a4-dfc3-4969-91c5-776fc9b9c1a3_265x176.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>The email address, associated with a Google ID (114770749765884660059), appears with the photo of the service&#8217;s logo.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Rso3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23636562-8483-44db-a8a9-e75cf01996af_422x150.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Rso3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23636562-8483-44db-a8a9-e75cf01996af_422x150.png 424w, https://substackcdn.com/image/fetch/$s_!Rso3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23636562-8483-44db-a8a9-e75cf01996af_422x150.png 848w, https://substackcdn.com/image/fetch/$s_!Rso3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23636562-8483-44db-a8a9-e75cf01996af_422x150.png 1272w, https://substackcdn.com/image/fetch/$s_!Rso3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23636562-8483-44db-a8a9-e75cf01996af_422x150.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Rso3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23636562-8483-44db-a8a9-e75cf01996af_422x150.png" width="422" height="150" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/23636562-8483-44db-a8a9-e75cf01996af_422x150.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:150,&quot;width&quot;:422,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:64417,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/180941192?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23636562-8483-44db-a8a9-e75cf01996af_422x150.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Rso3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23636562-8483-44db-a8a9-e75cf01996af_422x150.png 424w, https://substackcdn.com/image/fetch/$s_!Rso3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23636562-8483-44db-a8a9-e75cf01996af_422x150.png 848w, https://substackcdn.com/image/fetch/$s_!Rso3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23636562-8483-44db-a8a9-e75cf01996af_422x150.png 1272w, https://substackcdn.com/image/fetch/$s_!Rso3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23636562-8483-44db-a8a9-e75cf01996af_422x150.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>The username appeared in a data leak from 2019 as well, directly connected to another email: bulkhosting@hotmail[.]com, shown with details such as password, address, zip code, city and name of brand called &#8220;GameTsunami&#8221;.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!PW79!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44cf79ad-63c7-46b4-963d-177400d03fe5_267x201.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!PW79!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44cf79ad-63c7-46b4-963d-177400d03fe5_267x201.png 424w, https://substackcdn.com/image/fetch/$s_!PW79!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44cf79ad-63c7-46b4-963d-177400d03fe5_267x201.png 848w, https://substackcdn.com/image/fetch/$s_!PW79!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44cf79ad-63c7-46b4-963d-177400d03fe5_267x201.png 1272w, https://substackcdn.com/image/fetch/$s_!PW79!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44cf79ad-63c7-46b4-963d-177400d03fe5_267x201.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!PW79!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44cf79ad-63c7-46b4-963d-177400d03fe5_267x201.png" width="267" height="201" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/44cf79ad-63c7-46b4-963d-177400d03fe5_267x201.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:201,&quot;width&quot;:267,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:24025,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/180941192?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44cf79ad-63c7-46b4-963d-177400d03fe5_267x201.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!PW79!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44cf79ad-63c7-46b4-963d-177400d03fe5_267x201.png 424w, https://substackcdn.com/image/fetch/$s_!PW79!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44cf79ad-63c7-46b4-963d-177400d03fe5_267x201.png 848w, https://substackcdn.com/image/fetch/$s_!PW79!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44cf79ad-63c7-46b4-963d-177400d03fe5_267x201.png 1272w, https://substackcdn.com/image/fetch/$s_!PW79!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44cf79ad-63c7-46b4-963d-177400d03fe5_267x201.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!duxo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b51856f-d873-486b-b04c-4b4cc19f05d8_689x62.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!duxo!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b51856f-d873-486b-b04c-4b4cc19f05d8_689x62.png 424w, https://substackcdn.com/image/fetch/$s_!duxo!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b51856f-d873-486b-b04c-4b4cc19f05d8_689x62.png 848w, https://substackcdn.com/image/fetch/$s_!duxo!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b51856f-d873-486b-b04c-4b4cc19f05d8_689x62.png 1272w, https://substackcdn.com/image/fetch/$s_!duxo!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b51856f-d873-486b-b04c-4b4cc19f05d8_689x62.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!duxo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b51856f-d873-486b-b04c-4b4cc19f05d8_689x62.png" width="689" height="62" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8b51856f-d873-486b-b04c-4b4cc19f05d8_689x62.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:62,&quot;width&quot;:689,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:35117,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/180941192?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b51856f-d873-486b-b04c-4b4cc19f05d8_689x62.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!duxo!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b51856f-d873-486b-b04c-4b4cc19f05d8_689x62.png 424w, https://substackcdn.com/image/fetch/$s_!duxo!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b51856f-d873-486b-b04c-4b4cc19f05d8_689x62.png 848w, https://substackcdn.com/image/fetch/$s_!duxo!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b51856f-d873-486b-b04c-4b4cc19f05d8_689x62.png 1272w, https://substackcdn.com/image/fetch/$s_!duxo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b51856f-d873-486b-b04c-4b4cc19f05d8_689x62.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>When checking the brand &#8220;GameTsunami&#8221;, it appeared as a kind of hub for video gaming, nothing related to bulletproofservers.</p><p>The email address was the main thing, and the idea was to find other associations with it, from data leaks to registrations, web mentions and social media activity.</p><p>In a leaked database from 2020, I was able to find the above username and the email, in direct association with a name and what seems to be a phone number.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Z2ij!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6474ccb-e0c4-4e0b-a0ed-8ab25e7f8d07_602x94.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Z2ij!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6474ccb-e0c4-4e0b-a0ed-8ab25e7f8d07_602x94.png 424w, https://substackcdn.com/image/fetch/$s_!Z2ij!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6474ccb-e0c4-4e0b-a0ed-8ab25e7f8d07_602x94.png 848w, https://substackcdn.com/image/fetch/$s_!Z2ij!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6474ccb-e0c4-4e0b-a0ed-8ab25e7f8d07_602x94.png 1272w, https://substackcdn.com/image/fetch/$s_!Z2ij!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6474ccb-e0c4-4e0b-a0ed-8ab25e7f8d07_602x94.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Z2ij!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6474ccb-e0c4-4e0b-a0ed-8ab25e7f8d07_602x94.png" width="602" height="94" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a6474ccb-e0c4-4e0b-a0ed-8ab25e7f8d07_602x94.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:94,&quot;width&quot;:602,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:59460,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/180941192?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6474ccb-e0c4-4e0b-a0ed-8ab25e7f8d07_602x94.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Z2ij!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6474ccb-e0c4-4e0b-a0ed-8ab25e7f8d07_602x94.png 424w, https://substackcdn.com/image/fetch/$s_!Z2ij!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6474ccb-e0c4-4e0b-a0ed-8ab25e7f8d07_602x94.png 848w, https://substackcdn.com/image/fetch/$s_!Z2ij!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6474ccb-e0c4-4e0b-a0ed-8ab25e7f8d07_602x94.png 1272w, https://substackcdn.com/image/fetch/$s_!Z2ij!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6474ccb-e0c4-4e0b-a0ed-8ab25e7f8d07_602x94.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h3><strong>Finding The Owner</strong></h3><p>Once we got the name of the person associated with the email address, we already have one more crucial detail: a full address.</p><p>When using web search manipulations, I was able to get a deleted page (not archived unfortunately), that was still partly available due to cache memory.</p><p>In this search, I was able to find the full name of the individual (Christopher Walker, or as he appeared in the data leak by Chris Walker), and to prove he was a resident of this exact address and sold earlier in 2025.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Tznj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91863b98-919d-4d79-aa0d-5b49d6705680_346x115.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Tznj!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91863b98-919d-4d79-aa0d-5b49d6705680_346x115.png 424w, https://substackcdn.com/image/fetch/$s_!Tznj!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91863b98-919d-4d79-aa0d-5b49d6705680_346x115.png 848w, https://substackcdn.com/image/fetch/$s_!Tznj!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91863b98-919d-4d79-aa0d-5b49d6705680_346x115.png 1272w, https://substackcdn.com/image/fetch/$s_!Tznj!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91863b98-919d-4d79-aa0d-5b49d6705680_346x115.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Tznj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91863b98-919d-4d79-aa0d-5b49d6705680_346x115.png" width="346" height="115" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/91863b98-919d-4d79-aa0d-5b49d6705680_346x115.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:115,&quot;width&quot;:346,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:35602,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/180941192?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91863b98-919d-4d79-aa0d-5b49d6705680_346x115.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Tznj!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91863b98-919d-4d79-aa0d-5b49d6705680_346x115.png 424w, https://substackcdn.com/image/fetch/$s_!Tznj!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91863b98-919d-4d79-aa0d-5b49d6705680_346x115.png 848w, https://substackcdn.com/image/fetch/$s_!Tznj!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91863b98-919d-4d79-aa0d-5b49d6705680_346x115.png 1272w, https://substackcdn.com/image/fetch/$s_!Tznj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91863b98-919d-4d79-aa0d-5b49d6705680_346x115.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>And the home itself:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Bk2A!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f52471b-9b94-4328-bb94-c38d4d5f8ce8_425x206.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Bk2A!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f52471b-9b94-4328-bb94-c38d4d5f8ce8_425x206.png 424w, https://substackcdn.com/image/fetch/$s_!Bk2A!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f52471b-9b94-4328-bb94-c38d4d5f8ce8_425x206.png 848w, https://substackcdn.com/image/fetch/$s_!Bk2A!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f52471b-9b94-4328-bb94-c38d4d5f8ce8_425x206.png 1272w, https://substackcdn.com/image/fetch/$s_!Bk2A!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f52471b-9b94-4328-bb94-c38d4d5f8ce8_425x206.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Bk2A!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f52471b-9b94-4328-bb94-c38d4d5f8ce8_425x206.png" width="425" height="206" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3f52471b-9b94-4328-bb94-c38d4d5f8ce8_425x206.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:206,&quot;width&quot;:425,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:168412,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/180941192?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f52471b-9b94-4328-bb94-c38d4d5f8ce8_425x206.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Bk2A!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f52471b-9b94-4328-bb94-c38d4d5f8ce8_425x206.png 424w, https://substackcdn.com/image/fetch/$s_!Bk2A!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f52471b-9b94-4328-bb94-c38d4d5f8ce8_425x206.png 848w, https://substackcdn.com/image/fetch/$s_!Bk2A!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f52471b-9b94-4328-bb94-c38d4d5f8ce8_425x206.png 1272w, https://substackcdn.com/image/fetch/$s_!Bk2A!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f52471b-9b94-4328-bb94-c38d4d5f8ce8_425x206.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h3><strong>Infrastructure Convergence Map</strong></h3><p>This section visualizes the underlying relationship structure connecting all identified entities across the network. By mapping IP addresses, domains, email accounts, social handles, and operational identifiers, the diagram demonstrates that services which appear unrelated on the surface, BulletproofServers, NarcoScandinavia, and ElMercado, are in fact interlinked through shared infrastructure, overlapping contact points, and recurring digital identifiers.</p><p>The graph reveals a consolidated backend ecosystem tied to the same operators, highlighting how infrastructure, logistics, and retail-facing services converge into a single coordinated operation.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!PZuE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a94b2df-257b-4b64-bf12-4680df280889_665x377.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!PZuE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a94b2df-257b-4b64-bf12-4680df280889_665x377.png 424w, https://substackcdn.com/image/fetch/$s_!PZuE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a94b2df-257b-4b64-bf12-4680df280889_665x377.png 848w, https://substackcdn.com/image/fetch/$s_!PZuE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a94b2df-257b-4b64-bf12-4680df280889_665x377.png 1272w, https://substackcdn.com/image/fetch/$s_!PZuE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a94b2df-257b-4b64-bf12-4680df280889_665x377.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!PZuE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a94b2df-257b-4b64-bf12-4680df280889_665x377.png" width="665" height="377" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3a94b2df-257b-4b64-bf12-4680df280889_665x377.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:377,&quot;width&quot;:665,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:132014,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/180941192?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a94b2df-257b-4b64-bf12-4680df280889_665x377.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!PZuE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a94b2df-257b-4b64-bf12-4680df280889_665x377.png 424w, https://substackcdn.com/image/fetch/$s_!PZuE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a94b2df-257b-4b64-bf12-4680df280889_665x377.png 848w, https://substackcdn.com/image/fetch/$s_!PZuE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a94b2df-257b-4b64-bf12-4680df280889_665x377.png 1272w, https://substackcdn.com/image/fetch/$s_!PZuE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a94b2df-257b-4b64-bf12-4680df280889_665x377.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.darksignal.co/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Assam Company and Its Role in Iran’s Digital Media ]]></title><description><![CDATA[Overview and Organisational Profile]]></description><link>https://www.darksignal.co/p/assam-company-and-its-role-in-irans</link><guid isPermaLink="false">https://www.darksignal.co/p/assam-company-and-its-role-in-irans</guid><dc:creator><![CDATA[DarkSignal]]></dc:creator><pubDate>Tue, 02 Dec 2025 08:01:22 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!HBgz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ecf1359-55ab-48c4-bbc9-18c460822f94_761x970.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HBgz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ecf1359-55ab-48c4-bbc9-18c460822f94_761x970.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HBgz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ecf1359-55ab-48c4-bbc9-18c460822f94_761x970.png 424w, https://substackcdn.com/image/fetch/$s_!HBgz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ecf1359-55ab-48c4-bbc9-18c460822f94_761x970.png 848w, https://substackcdn.com/image/fetch/$s_!HBgz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ecf1359-55ab-48c4-bbc9-18c460822f94_761x970.png 1272w, https://substackcdn.com/image/fetch/$s_!HBgz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ecf1359-55ab-48c4-bbc9-18c460822f94_761x970.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HBgz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ecf1359-55ab-48c4-bbc9-18c460822f94_761x970.png" width="761" height="970" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4ecf1359-55ab-48c4-bbc9-18c460822f94_761x970.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:970,&quot;width&quot;:761,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1601991,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/180302713?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c748c88-7f19-43bb-a61e-d1c370e5b266_791x1188.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!HBgz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ecf1359-55ab-48c4-bbc9-18c460822f94_761x970.png 424w, https://substackcdn.com/image/fetch/$s_!HBgz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ecf1359-55ab-48c4-bbc9-18c460822f94_761x970.png 848w, https://substackcdn.com/image/fetch/$s_!HBgz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ecf1359-55ab-48c4-bbc9-18c460822f94_761x970.png 1272w, https://substackcdn.com/image/fetch/$s_!HBgz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ecf1359-55ab-48c4-bbc9-18c460822f94_761x970.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><h3><strong>Overview and Organisational Profile</strong></h3><p>Asam (<strong>asam.company</strong>) is a Tehran-based software and infrastructure provider specialising in high-availability digital platforms for news agencies, broadcasters, and major online media outlets inside Iran.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.darksignal.co/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>The company has been active since approximately 2013, based on its publicly presented operational timeline. <strong>Asam</strong> markets itself as the <strong>technical backbone for &#8220;leading media&#8221;</strong>, managing nearly the entire technological layer of client operations, from content-management systems (<strong>Asam CMS</strong>), <strong>CDN distribution</strong>, <strong>video streaming</strong> platforms, <strong>push-notification systems</strong>, <strong>cloud hosting</strong>, <strong>security monitoring</strong>, and <strong>24/7 operational support</strong>.</p><p>According to their own statements, they absorb the full technical burden of large-scale media publishing, enabling editorial teams to focus exclusively on content.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_-1Q!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc06f686f-f4ec-4d9e-801a-78c209b924ef_669x169.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_-1Q!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc06f686f-f4ec-4d9e-801a-78c209b924ef_669x169.png 424w, https://substackcdn.com/image/fetch/$s_!_-1Q!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc06f686f-f4ec-4d9e-801a-78c209b924ef_669x169.png 848w, https://substackcdn.com/image/fetch/$s_!_-1Q!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc06f686f-f4ec-4d9e-801a-78c209b924ef_669x169.png 1272w, https://substackcdn.com/image/fetch/$s_!_-1Q!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc06f686f-f4ec-4d9e-801a-78c209b924ef_669x169.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_-1Q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc06f686f-f4ec-4d9e-801a-78c209b924ef_669x169.png" width="669" height="169" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c06f686f-f4ec-4d9e-801a-78c209b924ef_669x169.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:169,&quot;width&quot;:669,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:99428,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/180302713?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc06f686f-f4ec-4d9e-801a-78c209b924ef_669x169.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!_-1Q!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc06f686f-f4ec-4d9e-801a-78c209b924ef_669x169.png 424w, https://substackcdn.com/image/fetch/$s_!_-1Q!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc06f686f-f4ec-4d9e-801a-78c209b924ef_669x169.png 848w, https://substackcdn.com/image/fetch/$s_!_-1Q!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc06f686f-f4ec-4d9e-801a-78c209b924ef_669x169.png 1272w, https://substackcdn.com/image/fetch/$s_!_-1Q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc06f686f-f4ec-4d9e-801a-78c209b924ef_669x169.png 1456w" sizes="100vw"></picture><div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!il4E!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe29d1ebf-8374-4146-a2dc-11e1029257aa_430x152.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!il4E!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe29d1ebf-8374-4146-a2dc-11e1029257aa_430x152.png 424w, https://substackcdn.com/image/fetch/$s_!il4E!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe29d1ebf-8374-4146-a2dc-11e1029257aa_430x152.png 848w, https://substackcdn.com/image/fetch/$s_!il4E!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe29d1ebf-8374-4146-a2dc-11e1029257aa_430x152.png 1272w, https://substackcdn.com/image/fetch/$s_!il4E!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe29d1ebf-8374-4146-a2dc-11e1029257aa_430x152.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!il4E!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe29d1ebf-8374-4146-a2dc-11e1029257aa_430x152.png" width="430" height="152" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e29d1ebf-8374-4146-a2dc-11e1029257aa_430x152.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:152,&quot;width&quot;:430,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:41991,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/180302713?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe29d1ebf-8374-4146-a2dc-11e1029257aa_430x152.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!il4E!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe29d1ebf-8374-4146-a2dc-11e1029257aa_430x152.png 424w, https://substackcdn.com/image/fetch/$s_!il4E!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe29d1ebf-8374-4146-a2dc-11e1029257aa_430x152.png 848w, https://substackcdn.com/image/fetch/$s_!il4E!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe29d1ebf-8374-4146-a2dc-11e1029257aa_430x152.png 1272w, https://substackcdn.com/image/fetch/$s_!il4E!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe29d1ebf-8374-4146-a2dc-11e1029257aa_430x152.png 1456w" sizes="100vw"></picture><div></div></div></a></figure></div><h3><strong>Comprehensive Control of Media Infrastructure</strong></h3><p>Multiple <strong>Iranian news organisations</strong>, spanning <strong>economic</strong>, <strong>political</strong>, and <strong>national</strong> <strong>outlets</strong>, <strong>credit Aasaam directly</strong> on their site footers, with phrases such as &#8220;Hosted on Aasaam servers&#8221; or &#8220;Designed and implemented by Aasaam.&#8221;</p><p>This includes major digital properties such as <strong>Donya-ye-Eqtesad</strong>, <strong>Eghtesadnews</strong>, <strong>ILNA</strong>, <strong>Afkarnews</strong>, <strong>MojNews</strong>, <strong>NamehNews</strong>, and <strong>Parsnews</strong>. The company&#8217;s public client list includes over one hundred organizations, all of which operate under Iran&#8217;s national media registry system (&#1587;&#1575;&#1605;&#1575;&#1606;&#1607; &#1580;&#1575;&#1605;&#1593; &#1585;&#1587;&#1575;&#1606;&#1607;&#8204;&#1607;&#1575;&#1740; &#1705;&#1588;&#1608;&#1585;). Functionally, this centralises the digital infrastructure of a large portion of Iranian media within a single private entity, giving Asam operational responsibility for uptime, security, content delivery, user analytics, and technical resilience.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HCTu!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee23aea3-33e3-422f-bbb8-26fdc5201b70_257x382.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HCTu!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee23aea3-33e3-422f-bbb8-26fdc5201b70_257x382.png 424w, https://substackcdn.com/image/fetch/$s_!HCTu!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee23aea3-33e3-422f-bbb8-26fdc5201b70_257x382.png 848w, https://substackcdn.com/image/fetch/$s_!HCTu!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee23aea3-33e3-422f-bbb8-26fdc5201b70_257x382.png 1272w, https://substackcdn.com/image/fetch/$s_!HCTu!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee23aea3-33e3-422f-bbb8-26fdc5201b70_257x382.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HCTu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee23aea3-33e3-422f-bbb8-26fdc5201b70_257x382.png" width="257" height="382" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ee23aea3-33e3-422f-bbb8-26fdc5201b70_257x382.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:382,&quot;width&quot;:257,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:128690,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/180302713?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee23aea3-33e3-422f-bbb8-26fdc5201b70_257x382.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!HCTu!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee23aea3-33e3-422f-bbb8-26fdc5201b70_257x382.png 424w, https://substackcdn.com/image/fetch/$s_!HCTu!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee23aea3-33e3-422f-bbb8-26fdc5201b70_257x382.png 848w, https://substackcdn.com/image/fetch/$s_!HCTu!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee23aea3-33e3-422f-bbb8-26fdc5201b70_257x382.png 1272w, https://substackcdn.com/image/fetch/$s_!HCTu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee23aea3-33e3-422f-bbb8-26fdc5201b70_257x382.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In the picture: logos represent Iranian state-controlled or IRGC-linked media outlets</p><h3><strong>Presence in State-Aligned and IRGC-Narrative Media</strong></h3><p>While Asam does not identify itself as a state-owned or state-affiliated enterprise, a significant portion of <strong>its clients consistently publish content aligned with the Iranian government and IRGC narratives</strong>.</p><p>Outlets such as <strong>Afkarnews</strong> and <strong>Parsnews</strong> are known for <strong>regularly promoting messaging favourable to Iran&#8217;s security establishment</strong>, including <strong>coverage of IRGC military achievements</strong>, regional proxy activity (especially <strong>in the cyber arena</strong>), and Israel-related geopolitical developments.</p><ul><li><p>Donya-ye-Eqtesad:</p><blockquote><p>o &#8220;Unveiling of two Israeli military products in cyber attacks&#8221;</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!mRQZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05bb810c-f6d6-4d51-b605-3560ca8bfc47_336x180.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!mRQZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05bb810c-f6d6-4d51-b605-3560ca8bfc47_336x180.png 424w, https://substackcdn.com/image/fetch/$s_!mRQZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05bb810c-f6d6-4d51-b605-3560ca8bfc47_336x180.png 848w, https://substackcdn.com/image/fetch/$s_!mRQZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05bb810c-f6d6-4d51-b605-3560ca8bfc47_336x180.png 1272w, https://substackcdn.com/image/fetch/$s_!mRQZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05bb810c-f6d6-4d51-b605-3560ca8bfc47_336x180.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!mRQZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05bb810c-f6d6-4d51-b605-3560ca8bfc47_336x180.png" width="336" height="180" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/05bb810c-f6d6-4d51-b605-3560ca8bfc47_336x180.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:180,&quot;width&quot;:336,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:97646,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/180302713?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05bb810c-f6d6-4d51-b605-3560ca8bfc47_336x180.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!mRQZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05bb810c-f6d6-4d51-b605-3560ca8bfc47_336x180.png 424w, https://substackcdn.com/image/fetch/$s_!mRQZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05bb810c-f6d6-4d51-b605-3560ca8bfc47_336x180.png 848w, https://substackcdn.com/image/fetch/$s_!mRQZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05bb810c-f6d6-4d51-b605-3560ca8bfc47_336x180.png 1272w, https://substackcdn.com/image/fetch/$s_!mRQZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05bb810c-f6d6-4d51-b605-3560ca8bfc47_336x180.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div></blockquote></li><li><p>Afkarnews:</p><blockquote><p>o &#8220;Classified Israeli information leaked&#8221;</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Bgu8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59855170-7d43-4b01-9907-9bff6499f2b2_414x124.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Bgu8!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59855170-7d43-4b01-9907-9bff6499f2b2_414x124.png 424w, https://substackcdn.com/image/fetch/$s_!Bgu8!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59855170-7d43-4b01-9907-9bff6499f2b2_414x124.png 848w, https://substackcdn.com/image/fetch/$s_!Bgu8!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59855170-7d43-4b01-9907-9bff6499f2b2_414x124.png 1272w, https://substackcdn.com/image/fetch/$s_!Bgu8!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59855170-7d43-4b01-9907-9bff6499f2b2_414x124.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Bgu8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59855170-7d43-4b01-9907-9bff6499f2b2_414x124.png" width="414" height="124" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/59855170-7d43-4b01-9907-9bff6499f2b2_414x124.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:124,&quot;width&quot;:414,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:37869,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/180302713?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59855170-7d43-4b01-9907-9bff6499f2b2_414x124.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Bgu8!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59855170-7d43-4b01-9907-9bff6499f2b2_414x124.png 424w, https://substackcdn.com/image/fetch/$s_!Bgu8!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59855170-7d43-4b01-9907-9bff6499f2b2_414x124.png 848w, https://substackcdn.com/image/fetch/$s_!Bgu8!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59855170-7d43-4b01-9907-9bff6499f2b2_414x124.png 1272w, https://substackcdn.com/image/fetch/$s_!Bgu8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59855170-7d43-4b01-9907-9bff6499f2b2_414x124.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div></blockquote></li><li><p>Asriran News:</p><blockquote><p>o &#8220;Cyber attack on data from the Israeli regime&#8217;s Iron Beam system&#8221;</p></blockquote></li></ul><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!AyZ-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6b7d525-b803-4ff0-94bb-47bb99adbe47_405x204.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!AyZ-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6b7d525-b803-4ff0-94bb-47bb99adbe47_405x204.png 424w, https://substackcdn.com/image/fetch/$s_!AyZ-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6b7d525-b803-4ff0-94bb-47bb99adbe47_405x204.png 848w, https://substackcdn.com/image/fetch/$s_!AyZ-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6b7d525-b803-4ff0-94bb-47bb99adbe47_405x204.png 1272w, https://substackcdn.com/image/fetch/$s_!AyZ-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6b7d525-b803-4ff0-94bb-47bb99adbe47_405x204.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!AyZ-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6b7d525-b803-4ff0-94bb-47bb99adbe47_405x204.png" width="405" height="204" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a6b7d525-b803-4ff0-94bb-47bb99adbe47_405x204.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:204,&quot;width&quot;:405,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:79170,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/180302713?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6b7d525-b803-4ff0-94bb-47bb99adbe47_405x204.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!AyZ-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6b7d525-b803-4ff0-94bb-47bb99adbe47_405x204.png 424w, https://substackcdn.com/image/fetch/$s_!AyZ-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6b7d525-b803-4ff0-94bb-47bb99adbe47_405x204.png 848w, https://substackcdn.com/image/fetch/$s_!AyZ-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6b7d525-b803-4ff0-94bb-47bb99adbe47_405x204.png 1272w, https://substackcdn.com/image/fetch/$s_!AyZ-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6b7d525-b803-4ff0-94bb-47bb99adbe47_405x204.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h3><strong>Asam as a Structural Enabler of Iran&#8217;s Information Operations</strong></h3><p>Asam company&#8217;s infrastructure <strong>serves many state-licensed, state-regulated, and state-aligned media outlets</strong>, many of which <strong>propagate strategic narratives highly aligned with IRGC objectives</strong>. As such, Asam acts as a structural <strong>enabler</strong> <strong>within Iran&#8217;s broader information and influence</strong> ecosystem.</p><p>Its platforms ensure the resilience, reach, and continuity of media channels that play a central role in broadcasting ideological, political, and cyber-operation messaging in direct support of Iranian state interests.</p><p>This positions Asam as a non-state but deeply embedded node in Iran&#8217;s hybrid media-cyber apparatus, <strong>providing operational backbone to outlets that shape public perception</strong> around Iranian cyber operations, and <strong>sustaining the information environment in which groups</strong> like <strong>Cyber Toufan</strong>, <strong>Handala</strong>, <strong>NetHunt3r</strong>, and the <strong>Cyber Isnaad</strong> <strong>Front</strong> gain legitimacy and psychological impact.</p><h3><strong>Media Amplification of Iran-Aligned Cyber Operations</strong></h3><p>Over the past two years, Iranian and regional reporting has frequently highlighted cyber operations linked by Western intelligence and cybersecurity vendors to Iranian interests. <strong>Outlets hosted or built by Aasaam</strong> have <strong>prominently</strong> <strong>covered</strong> and <strong>supported</strong> <strong>activities</strong> by groups, including:</p><ul><li><p><strong>Cyber Toufan (&#1591;&#1608;&#1601;&#1575;&#1606; &#1587;&#1575;&#1740;&#1576;&#1585;&#1740;): </strong>Linked to destructive attacks targeting Israeli public and private sector entities.</p></li><li><p><strong>Handala Hacking Team (&#1711;&#1585;&#1608;&#1607; &#1607;&#1705;&#1585;&#1740; &#1607;&#1606;&#1583;&#1604;&#1575;): </strong>Known for targeting Israeli infrastructure and exfiltrating sensitive datasets.</p></li><li><p><strong>NetHunt3r: </strong>A group claiming penetration of Israeli commercial and governmental services.</p></li><li><p><strong>Cyber Isnaad Front (&#1580;&#1576;&#1607;&#1607; &#1575;&#1587;&#1606;&#1575;&#1583; &#1587;&#1575;&#1740;&#1576;&#1585;&#1740;): </strong>A rapidly emerging threat actor assessed as Iranian-aligned, credited with breaches of Israeli defence-industry assets, such as the hack of &#8220;Maya&#8221; defence contractor.</p></li></ul><p><strong>Asam supported news organisations</strong> function as the information-distribution layer <strong>of Iranian cyber-influence operations</strong> as they routinely <strong>publish</strong> detailed accounts of <strong>cyberattacks against Israeli entities</strong>, often with technical summaries, <strong>leaked file descriptions</strong>, and commentary <strong>aligning with IRGC-themed narratives</strong> of &#8220;resistance&#8221; and asymmetric retaliation.</p><p>For example, a headline published by Asam supported Donya-ye-Eqtesad:</p><p><em>&#8220;The Maya defence company hacked; classified Israeli documents offered for sale by the Cyber Isnaad Front&#8221;</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!SNPD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7d8316e-901f-4683-b13f-cb133a659fd7_372x328.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!SNPD!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7d8316e-901f-4683-b13f-cb133a659fd7_372x328.png 424w, https://substackcdn.com/image/fetch/$s_!SNPD!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7d8316e-901f-4683-b13f-cb133a659fd7_372x328.png 848w, https://substackcdn.com/image/fetch/$s_!SNPD!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7d8316e-901f-4683-b13f-cb133a659fd7_372x328.png 1272w, https://substackcdn.com/image/fetch/$s_!SNPD!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7d8316e-901f-4683-b13f-cb133a659fd7_372x328.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!SNPD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7d8316e-901f-4683-b13f-cb133a659fd7_372x328.png" width="372" height="328" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e7d8316e-901f-4683-b13f-cb133a659fd7_372x328.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:328,&quot;width&quot;:372,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:189940,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/180302713?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7d8316e-901f-4683-b13f-cb133a659fd7_372x328.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!SNPD!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7d8316e-901f-4683-b13f-cb133a659fd7_372x328.png 424w, https://substackcdn.com/image/fetch/$s_!SNPD!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7d8316e-901f-4683-b13f-cb133a659fd7_372x328.png 848w, https://substackcdn.com/image/fetch/$s_!SNPD!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7d8316e-901f-4683-b13f-cb133a659fd7_372x328.png 1272w, https://substackcdn.com/image/fetch/$s_!SNPD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7d8316e-901f-4683-b13f-cb133a659fd7_372x328.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>Parsnews by Asam Company</strong></h3><p>Parsnews (&#1662;&#1575;&#1585;&#1587; &#1606;&#1740;&#1608;&#1586;) is a <strong>conservative</strong>, <strong>pro-regime Iranian</strong> news website that openly identifies its political and organisational structure.</p><p>On the same page and in every footer on the site, there is a permanent credit: &#8220;&#1591;&#1585;&#1575;&#1581;&#1740; &#1587;&#1575;&#1740;&#1578; &#1582;&#1575;&#1576;&#1585;&#1740; &#1608; &#1570;&#1587;&#1575;&#1605; &#1576;&#1585;&#1705;&#1740;&#1586;&#1740; &#1570;&#1587;&#1575;&#1605;&#8221;, or in a free translation: &#8220;<strong>Design/construction of the news site by ASAM Software Group</strong>&#8221;.</p><p>On its official &#8220;About Us&#8221; page, the site states: <strong>&#8220;&#1589;&#1575;&#1581;&#1576; &#1575;&#1605;&#1578;&#1740;&#1575;&#1586;: &#1605;&#1581;&#1587;&#1606; &#1662;&#1740;&#1585;&#1607;&#1575;&#1583;&#1740;&#8221;</strong>, meaning &#8220;<strong>License holder: Mohsen Pirhadi</strong>.&#8221; Pirhadi is a known <strong>conservative figure</strong> within Iran&#8217;s political landscape, <strong>connected to hardline factions</strong> and <strong>regularly involved in state-aligned media activity</strong>. His <strong>ownership positions</strong> Parsnews not as an independent outlet, but as a <strong>platform that operates within the ideological orbit of Iran&#8217;s</strong> ruling establishment.</p><p>This creates a simple and clear technical-commercial connection: a <strong>political news site controlled by a conservative politician sits on ASAM software</strong>/development infrastructure.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hRs9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69146680-fa29-4d06-ad84-1e474f604fb0_556x163.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hRs9!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69146680-fa29-4d06-ad84-1e474f604fb0_556x163.png 424w, https://substackcdn.com/image/fetch/$s_!hRs9!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69146680-fa29-4d06-ad84-1e474f604fb0_556x163.png 848w, https://substackcdn.com/image/fetch/$s_!hRs9!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69146680-fa29-4d06-ad84-1e474f604fb0_556x163.png 1272w, https://substackcdn.com/image/fetch/$s_!hRs9!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69146680-fa29-4d06-ad84-1e474f604fb0_556x163.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hRs9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69146680-fa29-4d06-ad84-1e474f604fb0_556x163.png" width="556" height="163" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/69146680-fa29-4d06-ad84-1e474f604fb0_556x163.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:163,&quot;width&quot;:556,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:42554,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/180302713?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69146680-fa29-4d06-ad84-1e474f604fb0_556x163.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!hRs9!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69146680-fa29-4d06-ad84-1e474f604fb0_556x163.png 424w, https://substackcdn.com/image/fetch/$s_!hRs9!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69146680-fa29-4d06-ad84-1e474f604fb0_556x163.png 848w, https://substackcdn.com/image/fetch/$s_!hRs9!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69146680-fa29-4d06-ad84-1e474f604fb0_556x163.png 1272w, https://substackcdn.com/image/fetch/$s_!hRs9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69146680-fa29-4d06-ad84-1e474f604fb0_556x163.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h3><strong>Who is Mohsen Pirhadi</strong></h3><p>Mohsen Pirhadi is a <strong>conservative Iranian politician</strong> with a long-standing role <strong>inside the country&#8217;s hardline political establishment</strong>. He previously <strong>served as a member</strong> <strong>of</strong> <strong>parliament</strong>, elected on the &#8220;Revolutionary Unity List&#8221; (&#1604;&#1740;&#1587;&#1578; &#1608;&#1581;&#1583;&#1578;), a coalition representing Iran&#8217;s conservative, pro-regime &#8220;revolutionary&#8221; faction.</p><p>Before that, he <strong>was a member and later the secretary of Tehran&#8217;s City Council</strong>. As of updates published in 2024, Pirhadi <strong>holds a senior government position</strong> as Deputy Minister of Oil for Parliamentary Affairs, marking his integration into Iran&#8217;s upper bureaucratic and executive structures.</p><p>In addition to his political career, Pirhadi serves as the <strong>managing editor </strong>of the conservative daily newspaper <strong>Resalat</strong> (&#1585;&#1587;&#1575;&#1604;&#1578;), one of Iran&#8217;s <strong>well-known ideological newspapers historically aligned with the Islamic-revolutionary camp</strong>. Resalat has consistently represented hardline viewpoints, framing Iranian domestic and regional policies through a pro-system, religious-nationalist lens. <strong>Pirhadi&#8217;s leadership</strong> in the paper <strong>reinforces his position within Iran&#8217;s ideological media</strong> ecosystem.</p><p>A review of Resalat&#8217;s opinion section shows numerous columns written by Pirhadi himself, where he explicitly <strong>praises</strong> <strong>Qassem Soleimani</strong>, depicting him as &#8220;more than a military commander&#8221; and as a central architect of Iran&#8217;s regional &#8220;Axis of Resistance&#8221; strategy. <strong>These writings adhere closely to IRGC and Quds Force narratives</strong>, positioning Soleimani as a visionary and moral figure whose strategic direction shaped Iran&#8217;s regional posture.</p><div class="image-gallery-embed" data-attrs="{&quot;gallery&quot;:{&quot;images&quot;:[{&quot;type&quot;:&quot;image/png&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0843c05c-7319-4c2f-b0c2-d0d55be896f2_299x214.png&quot;},{&quot;type&quot;:&quot;image/png&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f4667513-b93f-4d02-bf64-60f8887338ff_297x275.png&quot;}],&quot;caption&quot;:&quot;&quot;,&quot;alt&quot;:&quot;&quot;,&quot;staticGalleryImage&quot;:{&quot;type&quot;:&quot;image/png&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f7c58060-cb08-4c14-9e8d-095913c6ccc5_1456x720.png&quot;}},&quot;isEditorNode&quot;:true}"></div><p>For four years, <strong>Pirhadi served as the Head of the Basij Organisation</strong> of the Tehran Municipality (&#1585;&#1740;&#1575;&#1587;&#1578; &#1587;&#1575;&#1586;&#1605;&#1575;&#1606; &#1576;&#1587;&#1740;&#1580; &#1588;&#1607;&#1585;&#1583;&#1575;&#1585;&#1740; &#1578;&#1607;&#1585;&#1575;&#1606;). The Basij is a paramilitary <strong>volunteer force operating under the command structure of the Islamic Revolutionary Guard</strong> Corps (IRGC).</p><p>In 2019, the <strong>IRGC</strong> itself was <strong>designated</strong> by the United States as a <strong>Foreign Terrorist Organization</strong> (FTO), while its external operations wing, the <strong>Qods Force</strong> (IRGC&#8211;QF), has been <strong>listed since 2007 as a Specially Designated Global Terrorist</strong> (SDGT) entity.</p><p>He was <strong>directly involved in public propaganda campaigns</strong>, responsible for large-scale <strong>anti-American billboard operations</strong> across the city, describing the high production quality and <strong>coordinated messaging</strong> as indicative of the sophisticated <strong>IRGC/Basij propaganda apparatus</strong>.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!gFVE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0818cd15-011e-42c1-8b94-1f8b05ab5c86_352x174.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gFVE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0818cd15-011e-42c1-8b94-1f8b05ab5c86_352x174.png 424w, https://substackcdn.com/image/fetch/$s_!gFVE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0818cd15-011e-42c1-8b94-1f8b05ab5c86_352x174.png 848w, https://substackcdn.com/image/fetch/$s_!gFVE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0818cd15-011e-42c1-8b94-1f8b05ab5c86_352x174.png 1272w, https://substackcdn.com/image/fetch/$s_!gFVE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0818cd15-011e-42c1-8b94-1f8b05ab5c86_352x174.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gFVE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0818cd15-011e-42c1-8b94-1f8b05ab5c86_352x174.png" width="352" height="174" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0818cd15-011e-42c1-8b94-1f8b05ab5c86_352x174.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:174,&quot;width&quot;:352,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:91330,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/180302713?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0818cd15-011e-42c1-8b94-1f8b05ab5c86_352x174.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!gFVE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0818cd15-011e-42c1-8b94-1f8b05ab5c86_352x174.png 424w, https://substackcdn.com/image/fetch/$s_!gFVE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0818cd15-011e-42c1-8b94-1f8b05ab5c86_352x174.png 848w, https://substackcdn.com/image/fetch/$s_!gFVE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0818cd15-011e-42c1-8b94-1f8b05ab5c86_352x174.png 1272w, https://substackcdn.com/image/fetch/$s_!gFVE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0818cd15-011e-42c1-8b94-1f8b05ab5c86_352x174.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h3><strong>Direct contact with Iranian figures who publicly express terror support</strong></h3><p>In the political-media space where Pirhadi operates, in the hard-line &#8220;revolutionary conservative&#8221; camp, some of the <strong>most visible figures around him</strong> are <strong>senior IRGC</strong> <strong>officers</strong>. One well-documented example is <strong>Mohammad-Hossein Saffar-Harandi</strong>, a long-time IRGC cadre who <strong>served as Iran&#8217;s Minister of Culture and Islamic Guidance</strong> <strong>in Ahmadinejad&#8217;s first cabinet</strong> and then formally returned to the Guards as a cultural <strong>adviser to the IRGC commander</strong>, later becoming a member of the Expediency Council.</p><p>In 2023, in a speech reported by Iran International and echoed in other Iranian outlets, Saffar-Harandi <strong>explicitly described Hamas&#8217;s 7 October attack on Israel as &#8220;&#1602;&#1575;&#1576;&#1604; &#1578;&#1581;&#1587;&#1740;&#1606;&#8221; - &#8220;worthy of praise&#8221;</strong>, and added that &#8220;a <strong>handful of Basij fighters brought the world&#8217;s fourth-strongest army to the point that it was dizzy</strong> and didn&#8217;t know what to do.&#8221;</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!h9MW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b8f5df7-bb09-4ba1-a7d3-b2fa1fec6777_285x249.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!h9MW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b8f5df7-bb09-4ba1-a7d3-b2fa1fec6777_285x249.png 424w, https://substackcdn.com/image/fetch/$s_!h9MW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b8f5df7-bb09-4ba1-a7d3-b2fa1fec6777_285x249.png 848w, https://substackcdn.com/image/fetch/$s_!h9MW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b8f5df7-bb09-4ba1-a7d3-b2fa1fec6777_285x249.png 1272w, https://substackcdn.com/image/fetch/$s_!h9MW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b8f5df7-bb09-4ba1-a7d3-b2fa1fec6777_285x249.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!h9MW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b8f5df7-bb09-4ba1-a7d3-b2fa1fec6777_285x249.png" width="285" height="249" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0b8f5df7-bb09-4ba1-a7d3-b2fa1fec6777_285x249.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:249,&quot;width&quot;:285,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:125539,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/180302713?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b8f5df7-bb09-4ba1-a7d3-b2fa1fec6777_285x249.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!h9MW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b8f5df7-bb09-4ba1-a7d3-b2fa1fec6777_285x249.png 424w, https://substackcdn.com/image/fetch/$s_!h9MW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b8f5df7-bb09-4ba1-a7d3-b2fa1fec6777_285x249.png 848w, https://substackcdn.com/image/fetch/$s_!h9MW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b8f5df7-bb09-4ba1-a7d3-b2fa1fec6777_285x249.png 1272w, https://substackcdn.com/image/fetch/$s_!h9MW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b8f5df7-bb09-4ba1-a7d3-b2fa1fec6777_285x249.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Hamas</strong> itself is <strong>designated</strong> as a <strong>Foreign Terrorist Organisation</strong> by the U.S. State Department and appears on multiple Western terrorist lists, including the USA and EU sanctions regimes. <strong>Pirhadi</strong> is <strong>plugged</strong> directly <strong>into this ecosystem</strong>: <strong>Resalat&#8217;s print and online editions carry Saffar-Harandi&#8217;s speeches</strong> and interviews under a masthead that names &#8220;&#1605;&#1583;&#1740;&#1585; &#1605;&#1587;&#1574;&#1608;&#1604;: &#1605;&#1581;&#1587;&#1606; &#1662;&#1740;&#1585;&#1607;&#1575;&#1583;&#1740;&#8221; (&#8220;Managing Director: Mohsen Pirhadi&#8221;), and multiple conservative events covered by Iranian media, such as a <strong>conference on &#8220;revolutionary media&#8221;</strong> reported by ISNA and mass youth gatherings and cultural events reported by SNN and Borna, <strong>list</strong> both <strong>Saffar-Harandi and Mohsen Pirhadi</strong> <strong>among</strong> the main <strong>participants or guests on the same stage</strong>.</p><h3><strong>Summing Things Up</strong></h3><p>Taken together, <strong>these elements</strong> <strong>form</strong> a <strong>consistent profile of a senior figure from Iran&#8217;s &#8220;revolutionary forces,&#8221;</strong> a <strong>conservative</strong> <strong>newspaper</strong> <strong>manager</strong>, an <strong>ideological</strong> <strong>writer</strong></p><p><strong>promoting IRGC/Quds Force narratives</strong>, and at the same time, the <strong>registered license holder of Parsnews</strong>, A <strong>political news website controlled by a conservative politician</strong> <strong>operating on ASAM&#8217;s software</strong> and development infrastructure.</p><p>This <strong>situates Parsnews</strong> within the <strong>same ideological and political network</strong>, not merely as a neutral news site, but as a <strong>platform under the stewardship of a prominent hardline political actor</strong>.</p><p>It strengthens the argument that <strong>Parsnews operates within Iran&#8217;s state-aligned media ecosystem</strong> and <strong>reinforces</strong> <strong>government messaging through</strong> both <strong>political</strong> and <strong>ideological</strong> channels.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.darksignal.co/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[SPYGAME - A Web of Digital Exploitation Revealed]]></title><description><![CDATA[Introducing SPYGAMES, A Web of Digital Exploitation]]></description><link>https://www.darksignal.co/p/spygame-a-web-of-digital-exploitation</link><guid isPermaLink="false">https://www.darksignal.co/p/spygame-a-web-of-digital-exploitation</guid><dc:creator><![CDATA[DarkSignal]]></dc:creator><pubDate>Wed, 19 Nov 2025 14:01:18 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!CQAL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaeced48-a656-419a-8a18-c5bce0d8df34_665x849.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!CQAL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaeced48-a656-419a-8a18-c5bce0d8df34_665x849.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!CQAL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaeced48-a656-419a-8a18-c5bce0d8df34_665x849.png 424w, https://substackcdn.com/image/fetch/$s_!CQAL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaeced48-a656-419a-8a18-c5bce0d8df34_665x849.png 848w, https://substackcdn.com/image/fetch/$s_!CQAL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaeced48-a656-419a-8a18-c5bce0d8df34_665x849.png 1272w, https://substackcdn.com/image/fetch/$s_!CQAL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaeced48-a656-419a-8a18-c5bce0d8df34_665x849.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!CQAL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaeced48-a656-419a-8a18-c5bce0d8df34_665x849.png" width="665" height="849" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/caeced48-a656-419a-8a18-c5bce0d8df34_665x849.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:849,&quot;width&quot;:665,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1132705,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179352565?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcca8d8de-f7ce-4b3d-a643-2791fdf709ea_792x1188.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!CQAL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaeced48-a656-419a-8a18-c5bce0d8df34_665x849.png 424w, https://substackcdn.com/image/fetch/$s_!CQAL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaeced48-a656-419a-8a18-c5bce0d8df34_665x849.png 848w, https://substackcdn.com/image/fetch/$s_!CQAL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaeced48-a656-419a-8a18-c5bce0d8df34_665x849.png 1272w, https://substackcdn.com/image/fetch/$s_!CQAL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaeced48-a656-419a-8a18-c5bce0d8df34_665x849.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>Introducing SPYGAMES, A Web of Digital Exploitation</strong></h3><p>SPYGAME is a <strong>transnational cyber-extortion network</strong> operating simultaneously <strong>on the clear web and the dark web</strong> (ONION), known for <strong>leaking and monetizing private photos and live camera footage of victims worldwide</strong>. The website was first seen in early 2025 under the domain <em>spygame[.]fans</em>, including an ONION mirror.</p><p>The platform quickly evolved into a hybrid marketplace for intrusive content and blackmail services.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.darksignal.co/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>The SPYGAME ecosystem commodifies the invasion of privacy,&nbsp;<strong>offering &#8220;Leak &amp; Earn&#8221; incentives to contributors, paid &#8220;removal&#8221; options for victims</strong>, and even selling its&nbsp;<strong>entire backend</strong>&nbsp;as the &#8220;SPYGAME PROJECT&#8221; package, which includes the site&#8217;s code, databases, and hacking scripts for IP cameras.</p><p>This report presents a structured OSINT investigation to identify the individuals behind SPYGAME, track its evolution, and document the operational, financial, and technical ecosystem that sustains this cross-platform network.</p><p>By combining domain intelligence, blockchain tracing, infrastructure mapping, and digital-persona correlation, the research seeks to attribute ownership, expose infrastructure overlaps, and provide actionable intelligence for law-enforcement and counter-abuse initiatives.</p><h3><strong>Inside The SPYGAME Network</strong></h3><p>The network has been <strong>active since early 2025</strong>, maintaining a small but persistent presence across <strong>underground forums</strong>, a <strong>Twitter (X)</strong> channel, and a <strong>dark-web community</strong> dedicated to leaks and voyeuristic content.</p><p>The agenda driving SPYGAME is <strong>purely financial</strong>, fuelled by an underlying appeal to personal vengeance, particularly targeting individuals seeking to retaliate against women with whom they have had negative or exploitative relationships.</p><p>The platform monetizes stolen intimate content through subscription access, extortion payments, and affiliate-style &#8220;Leak &amp; Earn&#8221; schemes.</p><p><strong>Promotional traces</strong> of the site have surfaced <strong>on different adult-content subforums</strong>, where the actors advertise <strong>live camera feeds</strong>, <strong>data packages</strong>, and <strong>&#8220;content removal&#8221; services</strong> to attract both paying clients and new collaborators to spread the content across the web.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hpHa!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc413b02-6583-466d-b179-d6beb2560e91_544x237.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hpHa!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc413b02-6583-466d-b179-d6beb2560e91_544x237.png 424w, https://substackcdn.com/image/fetch/$s_!hpHa!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc413b02-6583-466d-b179-d6beb2560e91_544x237.png 848w, https://substackcdn.com/image/fetch/$s_!hpHa!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc413b02-6583-466d-b179-d6beb2560e91_544x237.png 1272w, https://substackcdn.com/image/fetch/$s_!hpHa!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc413b02-6583-466d-b179-d6beb2560e91_544x237.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hpHa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc413b02-6583-466d-b179-d6beb2560e91_544x237.png" width="544" height="237" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cc413b02-6583-466d-b179-d6beb2560e91_544x237.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:237,&quot;width&quot;:544,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:199677,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179352565?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc413b02-6583-466d-b179-d6beb2560e91_544x237.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!hpHa!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc413b02-6583-466d-b179-d6beb2560e91_544x237.png 424w, https://substackcdn.com/image/fetch/$s_!hpHa!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc413b02-6583-466d-b179-d6beb2560e91_544x237.png 848w, https://substackcdn.com/image/fetch/$s_!hpHa!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc413b02-6583-466d-b179-d6beb2560e91_544x237.png 1272w, https://substackcdn.com/image/fetch/$s_!hpHa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc413b02-6583-466d-b179-d6beb2560e91_544x237.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7oWa!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b1f4c74-effc-4bfb-ba32-3046b14112a7_224x300.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7oWa!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b1f4c74-effc-4bfb-ba32-3046b14112a7_224x300.png 424w, https://substackcdn.com/image/fetch/$s_!7oWa!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b1f4c74-effc-4bfb-ba32-3046b14112a7_224x300.png 848w, https://substackcdn.com/image/fetch/$s_!7oWa!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b1f4c74-effc-4bfb-ba32-3046b14112a7_224x300.png 1272w, https://substackcdn.com/image/fetch/$s_!7oWa!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b1f4c74-effc-4bfb-ba32-3046b14112a7_224x300.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7oWa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b1f4c74-effc-4bfb-ba32-3046b14112a7_224x300.png" width="224" height="300" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3b1f4c74-effc-4bfb-ba32-3046b14112a7_224x300.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:300,&quot;width&quot;:224,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:43470,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179352565?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b1f4c74-effc-4bfb-ba32-3046b14112a7_224x300.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!7oWa!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b1f4c74-effc-4bfb-ba32-3046b14112a7_224x300.png 424w, https://substackcdn.com/image/fetch/$s_!7oWa!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b1f4c74-effc-4bfb-ba32-3046b14112a7_224x300.png 848w, https://substackcdn.com/image/fetch/$s_!7oWa!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b1f4c74-effc-4bfb-ba32-3046b14112a7_224x300.png 1272w, https://substackcdn.com/image/fetch/$s_!7oWa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b1f4c74-effc-4bfb-ba32-3046b14112a7_224x300.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>Financial Infrastructure</strong></h3><p>The website <strong>offers a &#8220;free taste</strong>&#8221; with blurred content of random girls, but when accessing the actual content itself, including comprehensive guides on &#8220;how to hack&#8221;, it asks the user to <strong>pay for full VIP access</strong>.</p><p>The requested amount is 249$ for lifetime access, paid via BTC to the following address: <strong>bc1q54p5m9p08fw4xnqywgt3z3l8cu9gk0fwc7t8u3</strong></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tRcK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b06afac-dbdc-4e7a-9300-fb5c38b2fef9_452x225.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tRcK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b06afac-dbdc-4e7a-9300-fb5c38b2fef9_452x225.png 424w, https://substackcdn.com/image/fetch/$s_!tRcK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b06afac-dbdc-4e7a-9300-fb5c38b2fef9_452x225.png 848w, https://substackcdn.com/image/fetch/$s_!tRcK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b06afac-dbdc-4e7a-9300-fb5c38b2fef9_452x225.png 1272w, https://substackcdn.com/image/fetch/$s_!tRcK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b06afac-dbdc-4e7a-9300-fb5c38b2fef9_452x225.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tRcK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b06afac-dbdc-4e7a-9300-fb5c38b2fef9_452x225.png" width="452" height="225" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5b06afac-dbdc-4e7a-9300-fb5c38b2fef9_452x225.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:225,&quot;width&quot;:452,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:35641,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179352565?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b06afac-dbdc-4e7a-9300-fb5c38b2fef9_452x225.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tRcK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b06afac-dbdc-4e7a-9300-fb5c38b2fef9_452x225.png 424w, https://substackcdn.com/image/fetch/$s_!tRcK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b06afac-dbdc-4e7a-9300-fb5c38b2fef9_452x225.png 848w, https://substackcdn.com/image/fetch/$s_!tRcK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b06afac-dbdc-4e7a-9300-fb5c38b2fef9_452x225.png 1272w, https://substackcdn.com/image/fetch/$s_!tRcK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b06afac-dbdc-4e7a-9300-fb5c38b2fef9_452x225.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h3><strong>Deep Diving</strong></h3><p>Each <strong>content leak</strong> of a specific girl <strong>contains her personal details</strong> as well. <br>From <strong>country</strong> to her <strong>province</strong>, <strong>city</strong>, <strong>date of birth</strong>, personal <strong>phone</strong> number, and <strong>email</strong> address, all for full disclosure, and obviously, put pressure on her to pay for data removal. In this way, the threat actor always wins, if he is not paid by the content consumers, he gets paid by the victim who is eager to delete his intimate content from the website.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!XFJj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F945db358-8cd0-4719-9cf7-45732d252491_457x258.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!XFJj!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F945db358-8cd0-4719-9cf7-45732d252491_457x258.png 424w, https://substackcdn.com/image/fetch/$s_!XFJj!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F945db358-8cd0-4719-9cf7-45732d252491_457x258.png 848w, https://substackcdn.com/image/fetch/$s_!XFJj!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F945db358-8cd0-4719-9cf7-45732d252491_457x258.png 1272w, https://substackcdn.com/image/fetch/$s_!XFJj!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F945db358-8cd0-4719-9cf7-45732d252491_457x258.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!XFJj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F945db358-8cd0-4719-9cf7-45732d252491_457x258.png" width="457" height="258" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/945db358-8cd0-4719-9cf7-45732d252491_457x258.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:258,&quot;width&quot;:457,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:116928,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179352565?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F945db358-8cd0-4719-9cf7-45732d252491_457x258.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!XFJj!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F945db358-8cd0-4719-9cf7-45732d252491_457x258.png 424w, https://substackcdn.com/image/fetch/$s_!XFJj!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F945db358-8cd0-4719-9cf7-45732d252491_457x258.png 848w, https://substackcdn.com/image/fetch/$s_!XFJj!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F945db358-8cd0-4719-9cf7-45732d252491_457x258.png 1272w, https://substackcdn.com/image/fetch/$s_!XFJj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F945db358-8cd0-4719-9cf7-45732d252491_457x258.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The old IP address of the Clearnet domain (which already got deleted) is <strong>86.54.42.127</strong>, leading to a <strong>VPS</strong> server <strong>in Bern, Switzerland</strong>. <strong>No VPN/Proxy/Cloudflare</strong> defenders were identified. The only open ports were <strong>80</strong> &amp; <strong>443</strong> (for web browsing) and <strong>22</strong> (to manage the server itself via SSH).</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!9Ysl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F52412db0-9682-4d25-8bc1-ea771bd7bd42_287x263.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9Ysl!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F52412db0-9682-4d25-8bc1-ea771bd7bd42_287x263.png 424w, https://substackcdn.com/image/fetch/$s_!9Ysl!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F52412db0-9682-4d25-8bc1-ea771bd7bd42_287x263.png 848w, https://substackcdn.com/image/fetch/$s_!9Ysl!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F52412db0-9682-4d25-8bc1-ea771bd7bd42_287x263.png 1272w, https://substackcdn.com/image/fetch/$s_!9Ysl!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F52412db0-9682-4d25-8bc1-ea771bd7bd42_287x263.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9Ysl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F52412db0-9682-4d25-8bc1-ea771bd7bd42_287x263.png" width="287" height="263" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/52412db0-9682-4d25-8bc1-ea771bd7bd42_287x263.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:263,&quot;width&quot;:287,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:40957,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179352565?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F52412db0-9682-4d25-8bc1-ea771bd7bd42_287x263.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!9Ysl!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F52412db0-9682-4d25-8bc1-ea771bd7bd42_287x263.png 424w, https://substackcdn.com/image/fetch/$s_!9Ysl!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F52412db0-9682-4d25-8bc1-ea771bd7bd42_287x263.png 848w, https://substackcdn.com/image/fetch/$s_!9Ysl!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F52412db0-9682-4d25-8bc1-ea771bd7bd42_287x263.png 1272w, https://substackcdn.com/image/fetch/$s_!9Ysl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F52412db0-9682-4d25-8bc1-ea771bd7bd42_287x263.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>It&#8217;s All About the Domain</strong></h3><p>When digging in into the old clear web domain of SPYGAMES, 4 different domains were found.</p><p>&#216; <strong>true-leaks[.]com</strong></p><p>&#216; <strong>njalla[.]net</strong></p><p>&#216; <strong>zxc[.]qa</strong></p><p>&#216; <strong>instafansxxx[.]com</strong></p><p><strong>Some</strong> of them with a clear <strong>name indicating the kind of content on those websites</strong>, and some seem like random words. Let&#8217;s check them deeply.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!36-E!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F456e219f-6856-4137-aadc-dbf89d0a0fc6_301x164.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!36-E!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F456e219f-6856-4137-aadc-dbf89d0a0fc6_301x164.png 424w, https://substackcdn.com/image/fetch/$s_!36-E!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F456e219f-6856-4137-aadc-dbf89d0a0fc6_301x164.png 848w, https://substackcdn.com/image/fetch/$s_!36-E!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F456e219f-6856-4137-aadc-dbf89d0a0fc6_301x164.png 1272w, https://substackcdn.com/image/fetch/$s_!36-E!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F456e219f-6856-4137-aadc-dbf89d0a0fc6_301x164.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!36-E!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F456e219f-6856-4137-aadc-dbf89d0a0fc6_301x164.png" width="301" height="164" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/456e219f-6856-4137-aadc-dbf89d0a0fc6_301x164.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:164,&quot;width&quot;:301,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:31446,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179352565?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F456e219f-6856-4137-aadc-dbf89d0a0fc6_301x164.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!36-E!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F456e219f-6856-4137-aadc-dbf89d0a0fc6_301x164.png 424w, https://substackcdn.com/image/fetch/$s_!36-E!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F456e219f-6856-4137-aadc-dbf89d0a0fc6_301x164.png 848w, https://substackcdn.com/image/fetch/$s_!36-E!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F456e219f-6856-4137-aadc-dbf89d0a0fc6_301x164.png 1272w, https://substackcdn.com/image/fetch/$s_!36-E!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F456e219f-6856-4137-aadc-dbf89d0a0fc6_301x164.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>The domain <strong>true-leaks[.]com</strong>, owns a very suspicious name, almost having direct association to the conspiracy just by the name. Most of them are not available anymore, but <strong>older archived versions</strong> of them indeed <strong>revealed a direct connection to the content on SPYGAME</strong> and the <strong>same web design and patterns</strong> (colour, font, and country list).</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!GkxB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38ebe9ee-ab69-4ce6-8d93-49505bc295c9_602x283.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!GkxB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38ebe9ee-ab69-4ce6-8d93-49505bc295c9_602x283.png 424w, https://substackcdn.com/image/fetch/$s_!GkxB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38ebe9ee-ab69-4ce6-8d93-49505bc295c9_602x283.png 848w, https://substackcdn.com/image/fetch/$s_!GkxB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38ebe9ee-ab69-4ce6-8d93-49505bc295c9_602x283.png 1272w, https://substackcdn.com/image/fetch/$s_!GkxB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38ebe9ee-ab69-4ce6-8d93-49505bc295c9_602x283.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!GkxB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38ebe9ee-ab69-4ce6-8d93-49505bc295c9_602x283.png" width="602" height="283" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/38ebe9ee-ab69-4ce6-8d93-49505bc295c9_602x283.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:283,&quot;width&quot;:602,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:105334,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179352565?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38ebe9ee-ab69-4ce6-8d93-49505bc295c9_602x283.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!GkxB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38ebe9ee-ab69-4ce6-8d93-49505bc295c9_602x283.png 424w, https://substackcdn.com/image/fetch/$s_!GkxB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38ebe9ee-ab69-4ce6-8d93-49505bc295c9_602x283.png 848w, https://substackcdn.com/image/fetch/$s_!GkxB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38ebe9ee-ab69-4ce6-8d93-49505bc295c9_602x283.png 1272w, https://substackcdn.com/image/fetch/$s_!GkxB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38ebe9ee-ab69-4ce6-8d93-49505bc295c9_602x283.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In the picture: True-leaks[.]com, SPYGAME and zxc[.]qa websites </p><p></p><p>When checking the domain <strong>njalla[.]net</strong>, it revealed an <strong>anonymous domain name registrar</strong>, <strong>hosting provider and VPN provider</strong>, established by The Pirate Bay co-founder and allows an <strong>encrypted tunnel from the original computer to the Internet</strong>.<br>Also, it&#8217;s the <strong>exact registrar that instafansxxx[.com]</strong> used to register the domain.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!dQ_p!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86a09b51-b403-46ee-9d25-45029a4cb3ac_507x86.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!dQ_p!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86a09b51-b403-46ee-9d25-45029a4cb3ac_507x86.png 424w, https://substackcdn.com/image/fetch/$s_!dQ_p!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86a09b51-b403-46ee-9d25-45029a4cb3ac_507x86.png 848w, https://substackcdn.com/image/fetch/$s_!dQ_p!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86a09b51-b403-46ee-9d25-45029a4cb3ac_507x86.png 1272w, https://substackcdn.com/image/fetch/$s_!dQ_p!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86a09b51-b403-46ee-9d25-45029a4cb3ac_507x86.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!dQ_p!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86a09b51-b403-46ee-9d25-45029a4cb3ac_507x86.png" width="507" height="86" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/86a09b51-b403-46ee-9d25-45029a4cb3ac_507x86.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:86,&quot;width&quot;:507,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:12217,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179352565?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86a09b51-b403-46ee-9d25-45029a4cb3ac_507x86.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!dQ_p!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86a09b51-b403-46ee-9d25-45029a4cb3ac_507x86.png 424w, https://substackcdn.com/image/fetch/$s_!dQ_p!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86a09b51-b403-46ee-9d25-45029a4cb3ac_507x86.png 848w, https://substackcdn.com/image/fetch/$s_!dQ_p!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86a09b51-b403-46ee-9d25-45029a4cb3ac_507x86.png 1272w, https://substackcdn.com/image/fetch/$s_!dQ_p!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86a09b51-b403-46ee-9d25-45029a4cb3ac_507x86.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h3><strong>Revealing the Master of Puppets</strong></h3><p>When understanding that all the domains are associated to another, and of course to SPYGAME, I have dived deeply into them to reveal the individuals associated with to them.</p><p>The domain <strong>zxc[.]qa</strong> was <strong>found in</strong> association to a few <strong>data leak</strong>s and <strong>revealed the password &#8220;zjtxkw2&#8221;</strong> and <strong>&#8220;123456&#8221;,</strong> at least on of them is kind of unique and may be used to reverse search by leaked passwords to find more details. So that is exactly what I did.</p><p>The password <strong>&#8220;zjtxkw2&#8221;</strong> was found numerous times <strong>in direct association with an email address: fasdzc@zxc.qa</strong></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2Zzx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0574c32e-b01e-4fad-958f-b1f30dd0df8b_412x135.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2Zzx!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0574c32e-b01e-4fad-958f-b1f30dd0df8b_412x135.png 424w, https://substackcdn.com/image/fetch/$s_!2Zzx!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0574c32e-b01e-4fad-958f-b1f30dd0df8b_412x135.png 848w, https://substackcdn.com/image/fetch/$s_!2Zzx!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0574c32e-b01e-4fad-958f-b1f30dd0df8b_412x135.png 1272w, https://substackcdn.com/image/fetch/$s_!2Zzx!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0574c32e-b01e-4fad-958f-b1f30dd0df8b_412x135.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2Zzx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0574c32e-b01e-4fad-958f-b1f30dd0df8b_412x135.png" width="412" height="135" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0574c32e-b01e-4fad-958f-b1f30dd0df8b_412x135.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:135,&quot;width&quot;:412,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:43503,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179352565?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0574c32e-b01e-4fad-958f-b1f30dd0df8b_412x135.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!2Zzx!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0574c32e-b01e-4fad-958f-b1f30dd0df8b_412x135.png 424w, https://substackcdn.com/image/fetch/$s_!2Zzx!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0574c32e-b01e-4fad-958f-b1f30dd0df8b_412x135.png 848w, https://substackcdn.com/image/fetch/$s_!2Zzx!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0574c32e-b01e-4fad-958f-b1f30dd0df8b_412x135.png 1272w, https://substackcdn.com/image/fetch/$s_!2Zzx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0574c32e-b01e-4fad-958f-b1f30dd0df8b_412x135.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>The domain <strong>true-leaks[.]com</strong> was deeply investigated, and appears to be <strong>registered by a male</strong>, originally <strong>from the UK,</strong> under the name &#8220;<strong>Artur</strong>&#8221;.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!R_h9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3923c436-5cd8-422e-936e-592d61aad604_543x95.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!R_h9!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3923c436-5cd8-422e-936e-592d61aad604_543x95.png 424w, https://substackcdn.com/image/fetch/$s_!R_h9!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3923c436-5cd8-422e-936e-592d61aad604_543x95.png 848w, https://substackcdn.com/image/fetch/$s_!R_h9!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3923c436-5cd8-422e-936e-592d61aad604_543x95.png 1272w, https://substackcdn.com/image/fetch/$s_!R_h9!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3923c436-5cd8-422e-936e-592d61aad604_543x95.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!R_h9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3923c436-5cd8-422e-936e-592d61aad604_543x95.png" width="543" height="95" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3923c436-5cd8-422e-936e-592d61aad604_543x95.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:95,&quot;width&quot;:543,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:11356,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179352565?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3923c436-5cd8-422e-936e-592d61aad604_543x95.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!R_h9!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3923c436-5cd8-422e-936e-592d61aad604_543x95.png 424w, https://substackcdn.com/image/fetch/$s_!R_h9!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3923c436-5cd8-422e-936e-592d61aad604_543x95.png 848w, https://substackcdn.com/image/fetch/$s_!R_h9!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3923c436-5cd8-422e-936e-592d61aad604_543x95.png 1272w, https://substackcdn.com/image/fetch/$s_!R_h9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3923c436-5cd8-422e-936e-592d61aad604_543x95.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>And as shown in the Domain search engine:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!k0KA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1246139b-a74c-4b37-9736-afe8bc4ff76c_445x81.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!k0KA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1246139b-a74c-4b37-9736-afe8bc4ff76c_445x81.png 424w, https://substackcdn.com/image/fetch/$s_!k0KA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1246139b-a74c-4b37-9736-afe8bc4ff76c_445x81.png 848w, https://substackcdn.com/image/fetch/$s_!k0KA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1246139b-a74c-4b37-9736-afe8bc4ff76c_445x81.png 1272w, https://substackcdn.com/image/fetch/$s_!k0KA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1246139b-a74c-4b37-9736-afe8bc4ff76c_445x81.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!k0KA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1246139b-a74c-4b37-9736-afe8bc4ff76c_445x81.png" width="445" height="81" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1246139b-a74c-4b37-9736-afe8bc4ff76c_445x81.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:81,&quot;width&quot;:445,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:11759,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179352565?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1246139b-a74c-4b37-9736-afe8bc4ff76c_445x81.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!k0KA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1246139b-a74c-4b37-9736-afe8bc4ff76c_445x81.png 424w, https://substackcdn.com/image/fetch/$s_!k0KA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1246139b-a74c-4b37-9736-afe8bc4ff76c_445x81.png 848w, https://substackcdn.com/image/fetch/$s_!k0KA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1246139b-a74c-4b37-9736-afe8bc4ff76c_445x81.png 1272w, https://substackcdn.com/image/fetch/$s_!k0KA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1246139b-a74c-4b37-9736-afe8bc4ff76c_445x81.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h3><strong>Eventually, Anonymity Always Fails</strong></h3><p>What this investigation really shows is simple and chilling. <br>Massive criminal schemes don&#8217;t fail because their code is bad or their planning was amateur. They fail because people slip.</p><p>A reused email at sign-up, an overlooked EXIF tag in a hurried upload, or a careless &#8220;like&#8221; on a social post, each is a tiny, human mistake that leaves a trail.</p><p>When you stitch enough of those crumbs together, domain histories, leaked passwords, blockchain trails and offhand social signals, the mask comes off.</p><p>The takeaway for investigators is hopeful and urgent. <br>Persistent, patient OSINT turns small errors into big breakthroughs, and for those who think anonymity is guaranteed, sloppy OPSEC is not protection, but an open door.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.darksignal.co/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Deepfake Porn Website Revealed]]></title><description><![CDATA[Another AI Misuse]]></description><link>https://www.darksignal.co/p/deepfake-porn-website-revealed</link><guid isPermaLink="false">https://www.darksignal.co/p/deepfake-porn-website-revealed</guid><dc:creator><![CDATA[DarkSignal]]></dc:creator><pubDate>Sun, 16 Nov 2025 13:27:48 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!KrQN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c4de32-e859-4725-9e65-33cbf002d0b5_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!KrQN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c4de32-e859-4725-9e65-33cbf002d0b5_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!KrQN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c4de32-e859-4725-9e65-33cbf002d0b5_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!KrQN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c4de32-e859-4725-9e65-33cbf002d0b5_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!KrQN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c4de32-e859-4725-9e65-33cbf002d0b5_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!KrQN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c4de32-e859-4725-9e65-33cbf002d0b5_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!KrQN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c4de32-e859-4725-9e65-33cbf002d0b5_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e2c4de32-e859-4725-9e65-33cbf002d0b5_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2162667,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179048185?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c4de32-e859-4725-9e65-33cbf002d0b5_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!KrQN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c4de32-e859-4725-9e65-33cbf002d0b5_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!KrQN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c4de32-e859-4725-9e65-33cbf002d0b5_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!KrQN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c4de32-e859-4725-9e65-33cbf002d0b5_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!KrQN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c4de32-e859-4725-9e65-33cbf002d0b5_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>Another AI Misuse </h3><p>It started like most dark corners of the internet do - quietly, anonymously, and with a shiny new tech twist. Deepfucks[.]com, a website offering AI-generated pornographic videos of celebrities, quickly gained traction, drawing tens of thousands of views on each video.</p><p>While the site marketed itself as &#8220;entertainment,&#8221; what it really served was non-consensual deepfake content, hyper-realistic, sexually explicit videos using the faces of real people without their permission.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.darksignal.co/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!zBIR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef376d33-87e7-421f-8ba9-1bcb7bdb7efe_416x285.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!zBIR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef376d33-87e7-421f-8ba9-1bcb7bdb7efe_416x285.png 424w, https://substackcdn.com/image/fetch/$s_!zBIR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef376d33-87e7-421f-8ba9-1bcb7bdb7efe_416x285.png 848w, https://substackcdn.com/image/fetch/$s_!zBIR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef376d33-87e7-421f-8ba9-1bcb7bdb7efe_416x285.png 1272w, https://substackcdn.com/image/fetch/$s_!zBIR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef376d33-87e7-421f-8ba9-1bcb7bdb7efe_416x285.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!zBIR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef376d33-87e7-421f-8ba9-1bcb7bdb7efe_416x285.png" width="416" height="285" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ef376d33-87e7-421f-8ba9-1bcb7bdb7efe_416x285.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:285,&quot;width&quot;:416,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:188065,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179048185?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef376d33-87e7-421f-8ba9-1bcb7bdb7efe_416x285.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!zBIR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef376d33-87e7-421f-8ba9-1bcb7bdb7efe_416x285.png 424w, https://substackcdn.com/image/fetch/$s_!zBIR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef376d33-87e7-421f-8ba9-1bcb7bdb7efe_416x285.png 848w, https://substackcdn.com/image/fetch/$s_!zBIR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef376d33-87e7-421f-8ba9-1bcb7bdb7efe_416x285.png 1272w, https://substackcdn.com/image/fetch/$s_!zBIR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef376d33-87e7-421f-8ba9-1bcb7bdb7efe_416x285.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>But behind the slick interface and synthetic faces was a real person. And after deep digging, I found him.</p><p>Through a detailed OSINT investigation, I traced the site&#8217;s origin back to a single operational security mistake its creator made when the site first launched.</p><p>That error cracked the anonymity he relied on. What followed was the slow, methodical process of connecting dots, emails, domains, and social media breadcrumbs, until the identity of the person behind one disturbing AI porn platform came into focus.</p><p>This is the story of how I found him, what I uncovered, and why it matters.</p><h3>Let the OSINT Begin</h3><p>This is not the first or last misuse of AI for purposes of Deep Fake porn, but one of the known platforms.</p><p>The official website offers direction to social media pages of the &#8220;brand&#8221; &#8211; from Facebook, to Instagram, Twitter, and YouTube, all for the purpose of gaining followers and more views when new users come to the website.</p><p>I started digging into those social media for finding clues or references to contact methods, such as email addresses or phone numbers.</p><p>Only Facebook and YouTube contained a way to engage with the owner, by solving a CAPTCHA and getting an email address, but it was a generic admin email address, which wasn&#8217;t in any data leaks or yielded any results by Google Dorks techniques.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!UckA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F083557a4-e87b-4f75-8e01-6d25c62fc8b3_358x184.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!UckA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F083557a4-e87b-4f75-8e01-6d25c62fc8b3_358x184.png 424w, https://substackcdn.com/image/fetch/$s_!UckA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F083557a4-e87b-4f75-8e01-6d25c62fc8b3_358x184.png 848w, https://substackcdn.com/image/fetch/$s_!UckA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F083557a4-e87b-4f75-8e01-6d25c62fc8b3_358x184.png 1272w, https://substackcdn.com/image/fetch/$s_!UckA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F083557a4-e87b-4f75-8e01-6d25c62fc8b3_358x184.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!UckA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F083557a4-e87b-4f75-8e01-6d25c62fc8b3_358x184.png" width="358" height="184" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/083557a4-e87b-4f75-8e01-6d25c62fc8b3_358x184.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:184,&quot;width&quot;:358,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:28617,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179048185?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F083557a4-e87b-4f75-8e01-6d25c62fc8b3_358x184.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!UckA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F083557a4-e87b-4f75-8e01-6d25c62fc8b3_358x184.png 424w, https://substackcdn.com/image/fetch/$s_!UckA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F083557a4-e87b-4f75-8e01-6d25c62fc8b3_358x184.png 848w, https://substackcdn.com/image/fetch/$s_!UckA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F083557a4-e87b-4f75-8e01-6d25c62fc8b3_358x184.png 1272w, https://substackcdn.com/image/fetch/$s_!UckA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F083557a4-e87b-4f75-8e01-6d25c62fc8b3_358x184.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!pFs9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5321841b-289f-4fbc-8845-e34039f6b5af_288x81.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!pFs9!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5321841b-289f-4fbc-8845-e34039f6b5af_288x81.png 424w, https://substackcdn.com/image/fetch/$s_!pFs9!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5321841b-289f-4fbc-8845-e34039f6b5af_288x81.png 848w, https://substackcdn.com/image/fetch/$s_!pFs9!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5321841b-289f-4fbc-8845-e34039f6b5af_288x81.png 1272w, https://substackcdn.com/image/fetch/$s_!pFs9!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5321841b-289f-4fbc-8845-e34039f6b5af_288x81.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!pFs9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5321841b-289f-4fbc-8845-e34039f6b5af_288x81.png" width="288" height="81" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5321841b-289f-4fbc-8845-e34039f6b5af_288x81.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:81,&quot;width&quot;:288,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:16033,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179048185?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5321841b-289f-4fbc-8845-e34039f6b5af_288x81.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!pFs9!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5321841b-289f-4fbc-8845-e34039f6b5af_288x81.png 424w, https://substackcdn.com/image/fetch/$s_!pFs9!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5321841b-289f-4fbc-8845-e34039f6b5af_288x81.png 848w, https://substackcdn.com/image/fetch/$s_!pFs9!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5321841b-289f-4fbc-8845-e34039f6b5af_288x81.png 1272w, https://substackcdn.com/image/fetch/$s_!pFs9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5321841b-289f-4fbc-8845-e34039f6b5af_288x81.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>The website itself is registered with privacy restrictions, but... What if it wasn&#8217;t always the case?</p><p>I started to look at cached versions of the website by using WayBack machine, a viewed dozens of website changes, just for the chance one of them revealed a  crucial detail, but nothing was found in this department either.</p><h3>It&#8217;s Pivot Time!</h3><p>Not for the first time, deep and dark website owners, cyber-criminals, and others who are doing &#8220;shady stuff&#8221; tend to make mistakes that will lead future investigators to the golden ticket.</p><p>OPSEC, known as Operational Security, is the art of hiding personal details that may reveal our identity and actions. One small slip, like using a real email, can blow their cover, especially when using the email address for other needs (personal ones) as well.</p><p>Olbricht, the founder of the notorious &#8220;SilkRoad&#8221; made this mistake, extremist groups fall for this, and hopefully other criminals will too in the future.</p><p>I started digging into historical WHOIS records of the domain. There were a few, but the last one, and ironically, the oldest record, revealed the first email address used to open this domain. An email address with the domain &#8220;larsersej.dk&#8221;, with direct association to the domain &#8220;deepfucks[.]com&#8221;.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!bEjz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6bf7002-6fda-428c-acb7-4317628cf07b_500x189.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!bEjz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6bf7002-6fda-428c-acb7-4317628cf07b_500x189.png 424w, https://substackcdn.com/image/fetch/$s_!bEjz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6bf7002-6fda-428c-acb7-4317628cf07b_500x189.png 848w, https://substackcdn.com/image/fetch/$s_!bEjz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6bf7002-6fda-428c-acb7-4317628cf07b_500x189.png 1272w, https://substackcdn.com/image/fetch/$s_!bEjz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6bf7002-6fda-428c-acb7-4317628cf07b_500x189.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!bEjz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6bf7002-6fda-428c-acb7-4317628cf07b_500x189.png" width="500" height="189" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b6bf7002-6fda-428c-acb7-4317628cf07b_500x189.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:189,&quot;width&quot;:500,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:67760,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179048185?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6bf7002-6fda-428c-acb7-4317628cf07b_500x189.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!bEjz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6bf7002-6fda-428c-acb7-4317628cf07b_500x189.png 424w, https://substackcdn.com/image/fetch/$s_!bEjz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6bf7002-6fda-428c-acb7-4317628cf07b_500x189.png 848w, https://substackcdn.com/image/fetch/$s_!bEjz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6bf7002-6fda-428c-acb7-4317628cf07b_500x189.png 1272w, https://substackcdn.com/image/fetch/$s_!bEjz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6bf7002-6fda-428c-acb7-4317628cf07b_500x189.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><blockquote><h3><strong>Connecting The Dots</strong></h3><p>Once I got an email address, I started checking where it appears.</p><p>Investors and researchers usually counts on the fact the email address or phone number they found is used for personal usage too, a thing the increases the fact it</p><p>associated with personal social media accounts, password breaches and internet posts that may reveal extra relevant data. It was the case.</p><p>Using Google Dorks queries, I was able to find GitHub page with metadata that reveals the exact email address used to open the domain of deepfucks[.]com, with a full name of a person who claims he owns this email address. It was all in his official GitHub</p><p>profile, which also reveals his photo, his experience and other coding projects.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0n9J!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97bbf350-0a9a-437b-af40-9ad4fff8c372_601x359.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0n9J!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97bbf350-0a9a-437b-af40-9ad4fff8c372_601x359.png 424w, https://substackcdn.com/image/fetch/$s_!0n9J!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97bbf350-0a9a-437b-af40-9ad4fff8c372_601x359.png 848w, https://substackcdn.com/image/fetch/$s_!0n9J!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97bbf350-0a9a-437b-af40-9ad4fff8c372_601x359.png 1272w, https://substackcdn.com/image/fetch/$s_!0n9J!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97bbf350-0a9a-437b-af40-9ad4fff8c372_601x359.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0n9J!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97bbf350-0a9a-437b-af40-9ad4fff8c372_601x359.png" width="601" height="359" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/97bbf350-0a9a-437b-af40-9ad4fff8c372_601x359.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:359,&quot;width&quot;:601,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:112728,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179048185?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97bbf350-0a9a-437b-af40-9ad4fff8c372_601x359.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!0n9J!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97bbf350-0a9a-437b-af40-9ad4fff8c372_601x359.png 424w, https://substackcdn.com/image/fetch/$s_!0n9J!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97bbf350-0a9a-437b-af40-9ad4fff8c372_601x359.png 848w, https://substackcdn.com/image/fetch/$s_!0n9J!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97bbf350-0a9a-437b-af40-9ad4fff8c372_601x359.png 1272w, https://substackcdn.com/image/fetch/$s_!0n9J!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97bbf350-0a9a-437b-af40-9ad4fff8c372_601x359.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In the picture: direct connection between the name on GitHub to the email address he registered with.</p><p>Also, in his GitHub BIO there was a website address with the exact same domain of the email he opened Deepfucks[.] with.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!BYMG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6bcaa77-7bf3-43a9-b2c4-8c609a73ce3d_470x295.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!BYMG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6bcaa77-7bf3-43a9-b2c4-8c609a73ce3d_470x295.png 424w, https://substackcdn.com/image/fetch/$s_!BYMG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6bcaa77-7bf3-43a9-b2c4-8c609a73ce3d_470x295.png 848w, https://substackcdn.com/image/fetch/$s_!BYMG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6bcaa77-7bf3-43a9-b2c4-8c609a73ce3d_470x295.png 1272w, https://substackcdn.com/image/fetch/$s_!BYMG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6bcaa77-7bf3-43a9-b2c4-8c609a73ce3d_470x295.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!BYMG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6bcaa77-7bf3-43a9-b2c4-8c609a73ce3d_470x295.png" width="470" height="295" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c6bcaa77-7bf3-43a9-b2c4-8c609a73ce3d_470x295.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:295,&quot;width&quot;:470,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:112371,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179048185?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6bcaa77-7bf3-43a9-b2c4-8c609a73ce3d_470x295.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!BYMG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6bcaa77-7bf3-43a9-b2c4-8c609a73ce3d_470x295.png 424w, https://substackcdn.com/image/fetch/$s_!BYMG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6bcaa77-7bf3-43a9-b2c4-8c609a73ce3d_470x295.png 848w, https://substackcdn.com/image/fetch/$s_!BYMG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6bcaa77-7bf3-43a9-b2c4-8c609a73ce3d_470x295.png 1272w, https://substackcdn.com/image/fetch/$s_!BYMG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6bcaa77-7bf3-43a9-b2c4-8c609a73ce3d_470x295.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The final stage was to find clues that would claim his current location if the authorities wanted to catch him.</p><p>His Google Maps account was abundant, and no hard techniques were needed here. His recent activity claims exactly where he can be found.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!t7Tx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c82d7c6-d14e-4308-89a8-71090d97cb22_171x346.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!t7Tx!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c82d7c6-d14e-4308-89a8-71090d97cb22_171x346.png 424w, https://substackcdn.com/image/fetch/$s_!t7Tx!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c82d7c6-d14e-4308-89a8-71090d97cb22_171x346.png 848w, https://substackcdn.com/image/fetch/$s_!t7Tx!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c82d7c6-d14e-4308-89a8-71090d97cb22_171x346.png 1272w, https://substackcdn.com/image/fetch/$s_!t7Tx!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c82d7c6-d14e-4308-89a8-71090d97cb22_171x346.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!t7Tx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c82d7c6-d14e-4308-89a8-71090d97cb22_171x346.png" width="171" height="346" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6c82d7c6-d14e-4308-89a8-71090d97cb22_171x346.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:346,&quot;width&quot;:171,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:48756,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179048185?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c82d7c6-d14e-4308-89a8-71090d97cb22_171x346.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!t7Tx!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c82d7c6-d14e-4308-89a8-71090d97cb22_171x346.png 424w, https://substackcdn.com/image/fetch/$s_!t7Tx!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c82d7c6-d14e-4308-89a8-71090d97cb22_171x346.png 848w, https://substackcdn.com/image/fetch/$s_!t7Tx!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c82d7c6-d14e-4308-89a8-71090d97cb22_171x346.png 1272w, https://substackcdn.com/image/fetch/$s_!t7Tx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c82d7c6-d14e-4308-89a8-71090d97cb22_171x346.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>A Complete Intelligence Profile</h3><p>Profiling the person behind the website reveals contact methods and his social</p><p>accounts, a thing that may assist the authorities and other intelligence agencies to engage with him when needed.</p><p>For this purpose and to maintain his privacy, all PIIs (personal identification information) is blurred.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!87wC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b04d740-3415-462d-a1e1-878afeb7a400_591x480.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!87wC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b04d740-3415-462d-a1e1-878afeb7a400_591x480.png 424w, https://substackcdn.com/image/fetch/$s_!87wC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b04d740-3415-462d-a1e1-878afeb7a400_591x480.png 848w, https://substackcdn.com/image/fetch/$s_!87wC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b04d740-3415-462d-a1e1-878afeb7a400_591x480.png 1272w, https://substackcdn.com/image/fetch/$s_!87wC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b04d740-3415-462d-a1e1-878afeb7a400_591x480.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!87wC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b04d740-3415-462d-a1e1-878afeb7a400_591x480.png" width="591" height="480" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9b04d740-3415-462d-a1e1-878afeb7a400_591x480.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:480,&quot;width&quot;:591,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:71951,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179048185?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b04d740-3415-462d-a1e1-878afeb7a400_591x480.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!87wC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b04d740-3415-462d-a1e1-878afeb7a400_591x480.png 424w, https://substackcdn.com/image/fetch/$s_!87wC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b04d740-3415-462d-a1e1-878afeb7a400_591x480.png 848w, https://substackcdn.com/image/fetch/$s_!87wC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b04d740-3415-462d-a1e1-878afeb7a400_591x480.png 1272w, https://substackcdn.com/image/fetch/$s_!87wC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b04d740-3415-462d-a1e1-878afeb7a400_591x480.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p></blockquote><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.darksignal.co/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Introducing PhoSteal - A new Vietnamese Stealer (Malware)]]></title><description><![CDATA[The threat landscape is always renewed and updated, with malicious softwares classified into several categories when the most common ones are Stealers or Ransomwares.]]></description><link>https://www.darksignal.co/p/introducing-phosteal-a-new-vietnamese</link><guid isPermaLink="false">https://www.darksignal.co/p/introducing-phosteal-a-new-vietnamese</guid><dc:creator><![CDATA[DarkSignal]]></dc:creator><pubDate>Sun, 16 Nov 2025 13:01:50 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Dr66!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F65828ff6-13e4-46c6-97a8-d36369ec51c3_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Dr66!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F65828ff6-13e4-46c6-97a8-d36369ec51c3_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Dr66!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F65828ff6-13e4-46c6-97a8-d36369ec51c3_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!Dr66!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F65828ff6-13e4-46c6-97a8-d36369ec51c3_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!Dr66!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F65828ff6-13e4-46c6-97a8-d36369ec51c3_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!Dr66!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F65828ff6-13e4-46c6-97a8-d36369ec51c3_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Dr66!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F65828ff6-13e4-46c6-97a8-d36369ec51c3_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/65828ff6-13e4-46c6-97a8-d36369ec51c3_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3139192,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179046072?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F65828ff6-13e4-46c6-97a8-d36369ec51c3_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Dr66!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F65828ff6-13e4-46c6-97a8-d36369ec51c3_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!Dr66!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F65828ff6-13e4-46c6-97a8-d36369ec51c3_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!Dr66!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F65828ff6-13e4-46c6-97a8-d36369ec51c3_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!Dr66!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F65828ff6-13e4-46c6-97a8-d36369ec51c3_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The threat landscape is always renewed and updated, with malicious softwares classified into several categories when the most common ones are Stealers or Ransomwares.</p><p>In this research, we came across an email sent to victims working in the advertising domain, containing a message prompting action and introducing them to a business cooperation worth significant amounts of money.</p><p>All the victim had to do is answer a few &#8220;questions&#8221; found in the attachment file.</p><p>The delivery method is a phishing email that includes a link to an attachment, intended to be unzipped and opened on the victim&#8217;s system.</p><p>We found evidence that the email message was actually part of a large-scale campaign trying to attack online advertising, SEO and brand growth specialists, with the purpose of stealing their Facebook advertising accounts.</p><h3>Infection chain</h3><p>The attacker created fake Linkedln accounts (AKA &#8220;Sock Puppets&#8221; or &#8220;Burner Accounts&#8221;), all of which shared nearly identical BIOs, email addresses and phone numbers.</p><p>The mail addresses were on newly registered domains (created between August and September 2023), trying to imitate names of famous and large internet fashion retailers such as Furla, O-bag and Pavers.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!gZec!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc6f55e0-9e48-4bb4-8908-8618c2bbdf69_384x378.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gZec!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc6f55e0-9e48-4bb4-8908-8618c2bbdf69_384x378.png 424w, https://substackcdn.com/image/fetch/$s_!gZec!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc6f55e0-9e48-4bb4-8908-8618c2bbdf69_384x378.png 848w, https://substackcdn.com/image/fetch/$s_!gZec!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc6f55e0-9e48-4bb4-8908-8618c2bbdf69_384x378.png 1272w, https://substackcdn.com/image/fetch/$s_!gZec!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc6f55e0-9e48-4bb4-8908-8618c2bbdf69_384x378.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gZec!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc6f55e0-9e48-4bb4-8908-8618c2bbdf69_384x378.png" width="384" height="378" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bc6f55e0-9e48-4bb4-8908-8618c2bbdf69_384x378.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:378,&quot;width&quot;:384,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:33563,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179046072?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc6f55e0-9e48-4bb4-8908-8618c2bbdf69_384x378.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!gZec!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc6f55e0-9e48-4bb4-8908-8618c2bbdf69_384x378.png 424w, https://substackcdn.com/image/fetch/$s_!gZec!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc6f55e0-9e48-4bb4-8908-8618c2bbdf69_384x378.png 848w, https://substackcdn.com/image/fetch/$s_!gZec!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc6f55e0-9e48-4bb4-8908-8618c2bbdf69_384x378.png 1272w, https://substackcdn.com/image/fetch/$s_!gZec!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc6f55e0-9e48-4bb4-8908-8618c2bbdf69_384x378.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>All of the accounts had similar roles as &#8220;Recruitment Specialist&#8221; and were linked by common biographies, WhatsApp numbers and email domains.</p><p>The fake accounts contacted legitimate Linkedln professionals in the areas of marketing, SEO and advertising, and asked them to contact the company&#8217;s marketing managers.</p></blockquote><p>      Checking the phone numbers and domains the attackers used, all of them were  identified as VOIPs from the USA and the UK.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NEov!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F317a230b-d72a-4611-bbb8-cf2e49eaf842_388x291.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NEov!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F317a230b-d72a-4611-bbb8-cf2e49eaf842_388x291.png 424w, https://substackcdn.com/image/fetch/$s_!NEov!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F317a230b-d72a-4611-bbb8-cf2e49eaf842_388x291.png 848w, https://substackcdn.com/image/fetch/$s_!NEov!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F317a230b-d72a-4611-bbb8-cf2e49eaf842_388x291.png 1272w, https://substackcdn.com/image/fetch/$s_!NEov!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F317a230b-d72a-4611-bbb8-cf2e49eaf842_388x291.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NEov!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F317a230b-d72a-4611-bbb8-cf2e49eaf842_388x291.png" width="388" height="291" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/317a230b-d72a-4611-bbb8-cf2e49eaf842_388x291.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:291,&quot;width&quot;:388,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:81223,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179046072?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F317a230b-d72a-4611-bbb8-cf2e49eaf842_388x291.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NEov!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F317a230b-d72a-4611-bbb8-cf2e49eaf842_388x291.png 424w, https://substackcdn.com/image/fetch/$s_!NEov!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F317a230b-d72a-4611-bbb8-cf2e49eaf842_388x291.png 848w, https://substackcdn.com/image/fetch/$s_!NEov!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F317a230b-d72a-4611-bbb8-cf2e49eaf842_388x291.png 1272w, https://substackcdn.com/image/fetch/$s_!NEov!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F317a230b-d72a-4611-bbb8-cf2e49eaf842_388x291.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><blockquote><p>A similar recruitment operation was conducted on Upwork, a freelancer marketplace, in an attempt to reach more potential victims.</p><p>After the initial contact was established on social media, the discussion switched to emails promising a supposedly lucrative offer for business cooperation.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tvVt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b38a1fa-404b-4964-93ec-15cb0c26c3b6_474x265.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tvVt!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b38a1fa-404b-4964-93ec-15cb0c26c3b6_474x265.png 424w, https://substackcdn.com/image/fetch/$s_!tvVt!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b38a1fa-404b-4964-93ec-15cb0c26c3b6_474x265.png 848w, https://substackcdn.com/image/fetch/$s_!tvVt!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b38a1fa-404b-4964-93ec-15cb0c26c3b6_474x265.png 1272w, https://substackcdn.com/image/fetch/$s_!tvVt!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b38a1fa-404b-4964-93ec-15cb0c26c3b6_474x265.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tvVt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b38a1fa-404b-4964-93ec-15cb0c26c3b6_474x265.png" width="474" height="265" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8b38a1fa-404b-4964-93ec-15cb0c26c3b6_474x265.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:265,&quot;width&quot;:474,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:31921,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179046072?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b38a1fa-404b-4964-93ec-15cb0c26c3b6_474x265.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tvVt!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b38a1fa-404b-4964-93ec-15cb0c26c3b6_474x265.png 424w, https://substackcdn.com/image/fetch/$s_!tvVt!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b38a1fa-404b-4964-93ec-15cb0c26c3b6_474x265.png 848w, https://substackcdn.com/image/fetch/$s_!tvVt!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b38a1fa-404b-4964-93ec-15cb0c26c3b6_474x265.png 1272w, https://substackcdn.com/image/fetch/$s_!tvVt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b38a1fa-404b-4964-93ec-15cb0c26c3b6_474x265.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Other emails sent as part of this campaign explicitly mentioned large amounts of money as part of luring into the scheme.</p><p>The email domains observed throughout the investigation were all created on Squarespace (a website builder) in August - September 2023. The majority of them did not have DNS entries (meaning there is no website) and those who had, displayed generic &#8220;Coming Soon&#8221; pages.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!CMe6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b012366-551c-4220-8b14-a71ded84c90c_398x184.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!CMe6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b012366-551c-4220-8b14-a71ded84c90c_398x184.png 424w, https://substackcdn.com/image/fetch/$s_!CMe6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b012366-551c-4220-8b14-a71ded84c90c_398x184.png 848w, https://substackcdn.com/image/fetch/$s_!CMe6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b012366-551c-4220-8b14-a71ded84c90c_398x184.png 1272w, https://substackcdn.com/image/fetch/$s_!CMe6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b012366-551c-4220-8b14-a71ded84c90c_398x184.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!CMe6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b012366-551c-4220-8b14-a71ded84c90c_398x184.png" width="398" height="184" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9b012366-551c-4220-8b14-a71ded84c90c_398x184.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:184,&quot;width&quot;:398,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:56323,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179046072?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b012366-551c-4220-8b14-a71ded84c90c_398x184.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!CMe6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b012366-551c-4220-8b14-a71ded84c90c_398x184.png 424w, https://substackcdn.com/image/fetch/$s_!CMe6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b012366-551c-4220-8b14-a71ded84c90c_398x184.png 848w, https://substackcdn.com/image/fetch/$s_!CMe6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b012366-551c-4220-8b14-a71ded84c90c_398x184.png 1272w, https://substackcdn.com/image/fetch/$s_!CMe6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b012366-551c-4220-8b14-a71ded84c90c_398x184.png 1456w" sizes="100vw"></picture><div></div></div></a></figure></div><p>All emails were written in good business English and contained a link to a Google document with questions to be answered by the candidates in a very short time frame as part of increasing the urgency, a very well-known technique by adversaries.</p><p>The Google Document, stripped of Metadata and styled with brand assets - logos, fonts, links to the brand website (meaning there are different versions for each retailer brand the attacker tried to impersonate) contained a link to a password protected ZIP file hosted on DropBox, which the victim was supposed to download and unzip.</p><p>The file was password protected to prevent scanning by malware detectors on DropBox.</p><h3>Code Analysis</h3><p>The unzipped file contained a list of media assets jpg and mp4 files) and a 1.47GB size of</p><p>.scr file - in fact a Windows executable (.exe file) which would run when double clicked by an unsuspecting victim.</p><p>Whenrunning &#8220;binwalk&#8221; onit(atoolforsearching agivenbinary imageforembedded files and executable code), wefound the code which was written inPython named Iibb1.py.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!mnJa!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2def9e39-b2d6-4d52-a574-cb27919da711_319x206.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!mnJa!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2def9e39-b2d6-4d52-a574-cb27919da711_319x206.png 424w, https://substackcdn.com/image/fetch/$s_!mnJa!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2def9e39-b2d6-4d52-a574-cb27919da711_319x206.png 848w, https://substackcdn.com/image/fetch/$s_!mnJa!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2def9e39-b2d6-4d52-a574-cb27919da711_319x206.png 1272w, https://substackcdn.com/image/fetch/$s_!mnJa!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2def9e39-b2d6-4d52-a574-cb27919da711_319x206.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!mnJa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2def9e39-b2d6-4d52-a574-cb27919da711_319x206.png" width="319" height="206" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2def9e39-b2d6-4d52-a574-cb27919da711_319x206.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:206,&quot;width&quot;:319,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:168036,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179046072?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2def9e39-b2d6-4d52-a574-cb27919da711_319x206.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!mnJa!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2def9e39-b2d6-4d52-a574-cb27919da711_319x206.png 424w, https://substackcdn.com/image/fetch/$s_!mnJa!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2def9e39-b2d6-4d52-a574-cb27919da711_319x206.png 848w, https://substackcdn.com/image/fetch/$s_!mnJa!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2def9e39-b2d6-4d52-a574-cb27919da711_319x206.png 1272w, https://substackcdn.com/image/fetch/$s_!mnJa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2def9e39-b2d6-4d52-a574-cb27919da711_319x206.png 1456w" sizes="100vw"></picture><div></div></div></a></figure></div><p>Extracting the Python file from the executable allowed us to analyze the source code. The file was unknown to VT, however Five vendors identified it as malicious (hash 1cc4759938e647675a55173f96cb7833f6daef641a7da8aa68debc74eaae9795) - either a Python Trojan or a Python Stealer.</p><p>The code performs various tasks related to collecting information from several browsers. Additionally it interacts with Facebook&#8217;s Ads Manager to gather data related to ad accounts. The code operates by the following stages :</p></blockquote><p>      <strong>1.</strong> It imports several Python libraries for tasks such as file operations, cryptography and making HTTP requests.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.darksignal.co/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><blockquote><p><strong>2</strong>. It retrieves information about the computer&#8217;s hostname, username and OS version (probably for additional info to check if there are exploitable CVEs due to the</p><p>non-upgraded version of the OS).</p><p><strong>3</strong>. It takes a snapshot of the screen</p><p><strong>4</strong>. It makes an HTTP request to https://ipinfo[.]com to obtain information about the computer&#8217;s IP address, location and country.</p><p><strong>5.</strong> It creates a timestamp and generates a unique name for a file.</p><p><strong>6</strong>. It defines functions to check if specific web browsers are running and to find user profiles for these very own browsers.</p><p>The specific browsers it tries to look for are Chrome, Edge, Brave, Opera, Chromium, Firefox and CocCoc - a Vietnamese browser.</p></blockquote><p>      <strong>7</strong>. It defines functions to copy browser data files, such as cookies and login data from user profiles, to a destination folder and then deletes the original files (essentially kicking the user out of their account).</p><blockquote><p><strong>8</strong>. It defines functions to decrypt and extract login data (usernames, passwords and cookie information ) from Firefox profiles.</p><p><strong>9</strong>. It defines functions to interact with Facebook Ads Manager, such as obtaining access tokens and retrieving data related to ad accounts.</p><p><strong>10</strong>. It writes the collected data, including login information and cookie data, to human readable text files.</p></blockquote><p>      <strong>11</strong>. It uses a Telegram bot with hard-coded credentials to exfiltrate the data from the local machine to the       malware operator</p><p>     <strong>12</strong>. It appears to keep track of a counter for some purpose, possibly related to the number of times the script has run on the particular machine.</p><blockquote><p>Further analysis of the code reveals messages in Vietnamese, which can hint at the origin of the malware.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5Mky!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff15ba992-972e-4900-a3af-f9a5986f1955_610x35.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5Mky!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff15ba992-972e-4900-a3af-f9a5986f1955_610x35.png 424w, https://substackcdn.com/image/fetch/$s_!5Mky!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff15ba992-972e-4900-a3af-f9a5986f1955_610x35.png 848w, https://substackcdn.com/image/fetch/$s_!5Mky!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff15ba992-972e-4900-a3af-f9a5986f1955_610x35.png 1272w, https://substackcdn.com/image/fetch/$s_!5Mky!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff15ba992-972e-4900-a3af-f9a5986f1955_610x35.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5Mky!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff15ba992-972e-4900-a3af-f9a5986f1955_610x35.png" width="610" height="35" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f15ba992-972e-4900-a3af-f9a5986f1955_610x35.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:35,&quot;width&quot;:610,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:43618,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179046072?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff15ba992-972e-4900-a3af-f9a5986f1955_610x35.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!5Mky!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff15ba992-972e-4900-a3af-f9a5986f1955_610x35.png 424w, https://substackcdn.com/image/fetch/$s_!5Mky!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff15ba992-972e-4900-a3af-f9a5986f1955_610x35.png 848w, https://substackcdn.com/image/fetch/$s_!5Mky!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff15ba992-972e-4900-a3af-f9a5986f1955_610x35.png 1272w, https://substackcdn.com/image/fetch/$s_!5Mky!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff15ba992-972e-4900-a3af-f9a5986f1955_610x35.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>The headers used for the Facebook call provide both more evidence of Vietnamese involvement and a version of Chrome (112) which was the main version in April 2023, so it is likely the malware was written during that period.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_WlU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41555ba3-540c-4418-9562-6dbe1b9ff677_465x134.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_WlU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41555ba3-540c-4418-9562-6dbe1b9ff677_465x134.png 424w, https://substackcdn.com/image/fetch/$s_!_WlU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41555ba3-540c-4418-9562-6dbe1b9ff677_465x134.png 848w, https://substackcdn.com/image/fetch/$s_!_WlU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41555ba3-540c-4418-9562-6dbe1b9ff677_465x134.png 1272w, https://substackcdn.com/image/fetch/$s_!_WlU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41555ba3-540c-4418-9562-6dbe1b9ff677_465x134.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_WlU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41555ba3-540c-4418-9562-6dbe1b9ff677_465x134.png" width="465" height="134" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/41555ba3-540c-4418-9562-6dbe1b9ff677_465x134.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:134,&quot;width&quot;:465,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:77740,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179046072?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41555ba3-540c-4418-9562-6dbe1b9ff677_465x134.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!_WlU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41555ba3-540c-4418-9562-6dbe1b9ff677_465x134.png 424w, https://substackcdn.com/image/fetch/$s_!_WlU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41555ba3-540c-4418-9562-6dbe1b9ff677_465x134.png 848w, https://substackcdn.com/image/fetch/$s_!_WlU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41555ba3-540c-4418-9562-6dbe1b9ff677_465x134.png 1272w, https://substackcdn.com/image/fetch/$s_!_WlU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41555ba3-540c-4418-9562-6dbe1b9ff677_465x134.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>The main() section of the code revealed inisindeedaStealer, tryingtoobtain data stored locally inthe browsers and using a Telegram bot for exfiltration.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!i4l4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2424f8f-2116-4bd2-a9a2-70bcd4881c8b_401x287.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!i4l4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2424f8f-2116-4bd2-a9a2-70bcd4881c8b_401x287.png 424w, https://substackcdn.com/image/fetch/$s_!i4l4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2424f8f-2116-4bd2-a9a2-70bcd4881c8b_401x287.png 848w, https://substackcdn.com/image/fetch/$s_!i4l4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2424f8f-2116-4bd2-a9a2-70bcd4881c8b_401x287.png 1272w, https://substackcdn.com/image/fetch/$s_!i4l4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2424f8f-2116-4bd2-a9a2-70bcd4881c8b_401x287.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!i4l4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2424f8f-2116-4bd2-a9a2-70bcd4881c8b_401x287.png" width="401" height="287" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f2424f8f-2116-4bd2-a9a2-70bcd4881c8b_401x287.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:287,&quot;width&quot;:401,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:99307,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179046072?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2424f8f-2116-4bd2-a9a2-70bcd4881c8b_401x287.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!i4l4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2424f8f-2116-4bd2-a9a2-70bcd4881c8b_401x287.png 424w, https://substackcdn.com/image/fetch/$s_!i4l4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2424f8f-2116-4bd2-a9a2-70bcd4881c8b_401x287.png 848w, https://substackcdn.com/image/fetch/$s_!i4l4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2424f8f-2116-4bd2-a9a2-70bcd4881c8b_401x287.png 1272w, https://substackcdn.com/image/fetch/$s_!i4l4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2424f8f-2116-4bd2-a9a2-70bcd4881c8b_401x287.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><blockquote><h3>Attribution</h3><p>We believe the developers of the malware and its operators are Vietnamese, based on the following:</p><ul><li><p>Messages written to the logs:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ai72!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11febd68-3e2a-4fc2-9269-d5e5193fb343_604x35.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ai72!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11febd68-3e2a-4fc2-9269-d5e5193fb343_604x35.png 424w, https://substackcdn.com/image/fetch/$s_!ai72!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11febd68-3e2a-4fc2-9269-d5e5193fb343_604x35.png 848w, https://substackcdn.com/image/fetch/$s_!ai72!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11febd68-3e2a-4fc2-9269-d5e5193fb343_604x35.png 1272w, https://substackcdn.com/image/fetch/$s_!ai72!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11febd68-3e2a-4fc2-9269-d5e5193fb343_604x35.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ai72!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11febd68-3e2a-4fc2-9269-d5e5193fb343_604x35.png" width="604" height="35" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/11febd68-3e2a-4fc2-9269-d5e5193fb343_604x35.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:35,&quot;width&quot;:604,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:43259,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179046072?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11febd68-3e2a-4fc2-9269-d5e5193fb343_604x35.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ai72!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11febd68-3e2a-4fc2-9269-d5e5193fb343_604x35.png 424w, https://substackcdn.com/image/fetch/$s_!ai72!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11febd68-3e2a-4fc2-9269-d5e5193fb343_604x35.png 848w, https://substackcdn.com/image/fetch/$s_!ai72!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11febd68-3e2a-4fc2-9269-d5e5193fb343_604x35.png 1272w, https://substackcdn.com/image/fetch/$s_!ai72!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11febd68-3e2a-4fc2-9269-d5e5193fb343_604x35.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div></li></ul></blockquote></blockquote><ul><li><p>HTTP call headers:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!pYN9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84fae2e0-d1ac-4870-8665-f47e796655ce_602x29.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!pYN9!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84fae2e0-d1ac-4870-8665-f47e796655ce_602x29.png 424w, https://substackcdn.com/image/fetch/$s_!pYN9!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84fae2e0-d1ac-4870-8665-f47e796655ce_602x29.png 848w, https://substackcdn.com/image/fetch/$s_!pYN9!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84fae2e0-d1ac-4870-8665-f47e796655ce_602x29.png 1272w, https://substackcdn.com/image/fetch/$s_!pYN9!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84fae2e0-d1ac-4870-8665-f47e796655ce_602x29.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!pYN9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84fae2e0-d1ac-4870-8665-f47e796655ce_602x29.png" width="602" height="29" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/84fae2e0-d1ac-4870-8665-f47e796655ce_602x29.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:29,&quot;width&quot;:602,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:29302,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179046072?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84fae2e0-d1ac-4870-8665-f47e796655ce_602x29.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!pYN9!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84fae2e0-d1ac-4870-8665-f47e796655ce_602x29.png 424w, https://substackcdn.com/image/fetch/$s_!pYN9!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84fae2e0-d1ac-4870-8665-f47e796655ce_602x29.png 848w, https://substackcdn.com/image/fetch/$s_!pYN9!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84fae2e0-d1ac-4870-8665-f47e796655ce_602x29.png 1272w, https://substackcdn.com/image/fetch/$s_!pYN9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84fae2e0-d1ac-4870-8665-f47e796655ce_602x29.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div></li><li><p>Special handling for CocCoc (Vietnamese browser):</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!zBzf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffff55be2-ec3b-4ec3-a1d6-89949b8b90f6_463x130.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!zBzf!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffff55be2-ec3b-4ec3-a1d6-89949b8b90f6_463x130.png 424w, https://substackcdn.com/image/fetch/$s_!zBzf!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffff55be2-ec3b-4ec3-a1d6-89949b8b90f6_463x130.png 848w, https://substackcdn.com/image/fetch/$s_!zBzf!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffff55be2-ec3b-4ec3-a1d6-89949b8b90f6_463x130.png 1272w, https://substackcdn.com/image/fetch/$s_!zBzf!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffff55be2-ec3b-4ec3-a1d6-89949b8b90f6_463x130.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!zBzf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffff55be2-ec3b-4ec3-a1d6-89949b8b90f6_463x130.png" width="463" height="130" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fff55be2-ec3b-4ec3-a1d6-89949b8b90f6_463x130.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:130,&quot;width&quot;:463,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:54533,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179046072?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffff55be2-ec3b-4ec3-a1d6-89949b8b90f6_463x130.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!zBzf!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffff55be2-ec3b-4ec3-a1d6-89949b8b90f6_463x130.png 424w, https://substackcdn.com/image/fetch/$s_!zBzf!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffff55be2-ec3b-4ec3-a1d6-89949b8b90f6_463x130.png 848w, https://substackcdn.com/image/fetch/$s_!zBzf!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffff55be2-ec3b-4ec3-a1d6-89949b8b90f6_463x130.png 1272w, https://substackcdn.com/image/fetch/$s_!zBzf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffff55be2-ec3b-4ec3-a1d6-89949b8b90f6_463x130.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>We were able to access the Telegram Bot used by the attackers. Using the &#8220;getUpdates&#8221; API returned a list of files as uploaded from victims&#8217; machines, including test runs by the malware operator on their own machine (showing the presentation as a victim would see it), providing valuable insights into their identity.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!b_hn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feedfaf33-014d-4b89-a0fc-6b95fd7e7178_608x342.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!b_hn!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feedfaf33-014d-4b89-a0fc-6b95fd7e7178_608x342.png 424w, https://substackcdn.com/image/fetch/$s_!b_hn!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feedfaf33-014d-4b89-a0fc-6b95fd7e7178_608x342.png 848w, https://substackcdn.com/image/fetch/$s_!b_hn!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feedfaf33-014d-4b89-a0fc-6b95fd7e7178_608x342.png 1272w, https://substackcdn.com/image/fetch/$s_!b_hn!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feedfaf33-014d-4b89-a0fc-6b95fd7e7178_608x342.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!b_hn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feedfaf33-014d-4b89-a0fc-6b95fd7e7178_608x342.png" width="608" height="342" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/eedfaf33-014d-4b89-a0fc-6b95fd7e7178_608x342.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:342,&quot;width&quot;:608,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:167474,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179046072?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feedfaf33-014d-4b89-a0fc-6b95fd7e7178_608x342.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!b_hn!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feedfaf33-014d-4b89-a0fc-6b95fd7e7178_608x342.png 424w, https://substackcdn.com/image/fetch/$s_!b_hn!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feedfaf33-014d-4b89-a0fc-6b95fd7e7178_608x342.png 848w, https://substackcdn.com/image/fetch/$s_!b_hn!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feedfaf33-014d-4b89-a0fc-6b95fd7e7178_608x342.png 1272w, https://substackcdn.com/image/fetch/$s_!b_hn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feedfaf33-014d-4b89-a0fc-6b95fd7e7178_608x342.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In the picture: The screenshot from the attacker&#8217;s machine included text in Vietnamese.</p><p>Calling the Telegram bot&#8217;s &#8220;getChatAdministrators&#8221; API revealed the Telegram username &#8220;iamRioooo&#8221;, and the Ianguage_code &#8220;vi&#8221; (Vietnamese)</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZGgY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61252bf0-2b21-45f4-a4ef-a793fabeb978_598x39.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZGgY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61252bf0-2b21-45f4-a4ef-a793fabeb978_598x39.png 424w, https://substackcdn.com/image/fetch/$s_!ZGgY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61252bf0-2b21-45f4-a4ef-a793fabeb978_598x39.png 848w, https://substackcdn.com/image/fetch/$s_!ZGgY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61252bf0-2b21-45f4-a4ef-a793fabeb978_598x39.png 1272w, https://substackcdn.com/image/fetch/$s_!ZGgY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61252bf0-2b21-45f4-a4ef-a793fabeb978_598x39.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZGgY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61252bf0-2b21-45f4-a4ef-a793fabeb978_598x39.png" width="598" height="39" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/61252bf0-2b21-45f4-a4ef-a793fabeb978_598x39.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:39,&quot;width&quot;:598,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:62779,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179046072?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61252bf0-2b21-45f4-a4ef-a793fabeb978_598x39.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ZGgY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61252bf0-2b21-45f4-a4ef-a793fabeb978_598x39.png 424w, https://substackcdn.com/image/fetch/$s_!ZGgY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61252bf0-2b21-45f4-a4ef-a793fabeb978_598x39.png 848w, https://substackcdn.com/image/fetch/$s_!ZGgY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61252bf0-2b21-45f4-a4ef-a793fabeb978_598x39.png 1272w, https://substackcdn.com/image/fetch/$s_!ZGgY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61252bf0-2b21-45f4-a4ef-a793fabeb978_598x39.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!PW87!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc70464c6-2462-4007-ab1a-57d6d72ac341_696x87.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!PW87!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc70464c6-2462-4007-ab1a-57d6d72ac341_696x87.png 424w, https://substackcdn.com/image/fetch/$s_!PW87!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc70464c6-2462-4007-ab1a-57d6d72ac341_696x87.png 848w, https://substackcdn.com/image/fetch/$s_!PW87!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc70464c6-2462-4007-ab1a-57d6d72ac341_696x87.png 1272w, https://substackcdn.com/image/fetch/$s_!PW87!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc70464c6-2462-4007-ab1a-57d6d72ac341_696x87.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!PW87!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc70464c6-2462-4007-ab1a-57d6d72ac341_696x87.png" width="696" height="87" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c70464c6-2462-4007-ab1a-57d6d72ac341_696x87.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:87,&quot;width&quot;:696,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:58106,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179046072?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc70464c6-2462-4007-ab1a-57d6d72ac341_696x87.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!PW87!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc70464c6-2462-4007-ab1a-57d6d72ac341_696x87.png 424w, https://substackcdn.com/image/fetch/$s_!PW87!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc70464c6-2462-4007-ab1a-57d6d72ac341_696x87.png 848w, https://substackcdn.com/image/fetch/$s_!PW87!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc70464c6-2462-4007-ab1a-57d6d72ac341_696x87.png 1272w, https://substackcdn.com/image/fetch/$s_!PW87!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc70464c6-2462-4007-ab1a-57d6d72ac341_696x87.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wjIL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1807240b-1dc0-41fc-900f-d59b4a079d01_357x238.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wjIL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1807240b-1dc0-41fc-900f-d59b4a079d01_357x238.png 424w, https://substackcdn.com/image/fetch/$s_!wjIL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1807240b-1dc0-41fc-900f-d59b4a079d01_357x238.png 848w, https://substackcdn.com/image/fetch/$s_!wjIL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1807240b-1dc0-41fc-900f-d59b4a079d01_357x238.png 1272w, https://substackcdn.com/image/fetch/$s_!wjIL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1807240b-1dc0-41fc-900f-d59b4a079d01_357x238.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wjIL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1807240b-1dc0-41fc-900f-d59b4a079d01_357x238.png" width="357" height="238" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1807240b-1dc0-41fc-900f-d59b4a079d01_357x238.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:238,&quot;width&quot;:357,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:128980,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179046072?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1807240b-1dc0-41fc-900f-d59b4a079d01_357x238.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wjIL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1807240b-1dc0-41fc-900f-d59b4a079d01_357x238.png 424w, https://substackcdn.com/image/fetch/$s_!wjIL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1807240b-1dc0-41fc-900f-d59b4a079d01_357x238.png 848w, https://substackcdn.com/image/fetch/$s_!wjIL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1807240b-1dc0-41fc-900f-d59b4a079d01_357x238.png 1272w, https://substackcdn.com/image/fetch/$s_!wjIL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1807240b-1dc0-41fc-900f-d59b4a079d01_357x238.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>In the picture: the suspects&#8217; Telegram account</p><blockquote><p>Based on a browser profile grabbed by the malware from the supposed attacker&#8217;s computer, we came across the name &#8220;Tien Oinh Van&#8221; (apparently a very popular name in Vietnam), and a personal email address &#8220;dinhvantien20102000@gmaiI[.]com&#8221; - also, not distinct enough to allow for identification.</p><p>Based on the user names and passwords grabbed by the malware from the supposed attacker&#8217;s computer, we were able to determine with a high degree of confidence the attacker&#8217;s real identity, and that he is, or was, a student at the Dong Nai Institute of Technology.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!h1av!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f8474d2-41e9-4c92-a319-dc29ba5b5567_602x316.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!h1av!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f8474d2-41e9-4c92-a319-dc29ba5b5567_602x316.png 424w, https://substackcdn.com/image/fetch/$s_!h1av!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f8474d2-41e9-4c92-a319-dc29ba5b5567_602x316.png 848w, https://substackcdn.com/image/fetch/$s_!h1av!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f8474d2-41e9-4c92-a319-dc29ba5b5567_602x316.png 1272w, https://substackcdn.com/image/fetch/$s_!h1av!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f8474d2-41e9-4c92-a319-dc29ba5b5567_602x316.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!h1av!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f8474d2-41e9-4c92-a319-dc29ba5b5567_602x316.png" width="602" height="316" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8f8474d2-41e9-4c92-a319-dc29ba5b5567_602x316.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:316,&quot;width&quot;:602,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:58738,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179046072?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f8474d2-41e9-4c92-a319-dc29ba5b5567_602x316.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!h1av!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f8474d2-41e9-4c92-a319-dc29ba5b5567_602x316.png 424w, https://substackcdn.com/image/fetch/$s_!h1av!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f8474d2-41e9-4c92-a319-dc29ba5b5567_602x316.png 848w, https://substackcdn.com/image/fetch/$s_!h1av!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f8474d2-41e9-4c92-a319-dc29ba5b5567_602x316.png 1272w, https://substackcdn.com/image/fetch/$s_!h1av!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f8474d2-41e9-4c92-a319-dc29ba5b5567_602x316.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>Use of AI</h3><p>Throughout our research we were very impressed with the level of written English communication by the attacker. In fact, his phishing emails and recruitment messages were so articulate we suspected we were looking at a team of attackers, one of whom is a native English speaker.</p><p>This mystery was solved when one of the screenshots from the attacker&#8217;s computer showed ChatGPT open on his screen in an attempt to generate recruitment emails for Facebook Advertising Specialists.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZiCS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd9550a0-8757-4383-9c94-49da4b194df1_601x598.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZiCS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd9550a0-8757-4383-9c94-49da4b194df1_601x598.png 424w, https://substackcdn.com/image/fetch/$s_!ZiCS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd9550a0-8757-4383-9c94-49da4b194df1_601x598.png 848w, https://substackcdn.com/image/fetch/$s_!ZiCS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd9550a0-8757-4383-9c94-49da4b194df1_601x598.png 1272w, https://substackcdn.com/image/fetch/$s_!ZiCS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd9550a0-8757-4383-9c94-49da4b194df1_601x598.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZiCS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd9550a0-8757-4383-9c94-49da4b194df1_601x598.png" width="601" height="598" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dd9550a0-8757-4383-9c94-49da4b194df1_601x598.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:598,&quot;width&quot;:601,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:254908,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179046072?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd9550a0-8757-4383-9c94-49da4b194df1_601x598.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ZiCS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd9550a0-8757-4383-9c94-49da4b194df1_601x598.png 424w, https://substackcdn.com/image/fetch/$s_!ZiCS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd9550a0-8757-4383-9c94-49da4b194df1_601x598.png 848w, https://substackcdn.com/image/fetch/$s_!ZiCS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd9550a0-8757-4383-9c94-49da4b194df1_601x598.png 1272w, https://substackcdn.com/image/fetch/$s_!ZiCS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd9550a0-8757-4383-9c94-49da4b194df1_601x598.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>We have long been warned that generative AI services could be used by fraudsters for malicious purposes, such as crafting high quality phishing emails, but this is the first time we have encountered such an example in real life.</p><p>For additional defense, we have created relevant YARA rules -</p><p>1.</p><p><code> rule SuspiciousDomain { strings:</code></p><p><code> $domain1 = &#8220;it-furIa.com&#8221;</code></p><p><code> $domain2 = &#8220;furla-it.com&#8221;</code></p><p><code> $domain3 = &#8220;obag-it.com&#8221;</code></p><p><code> $domain4 = &#8220;pavers-co.uk&#8221;</code></p><p><code> $domain5 = &#8220;falconeri-it.com&#8221;</code></p><p><code> $domain6 = &#8220;colehaan-us.com&#8221;</code></p><p><code> $domain7 = &#8220;us-coIehaan.com&#8221; condition:</code></p><p><code> any of ($domain*)</code></p><p>2.</p><p><code> rule SuspiciousCodelndicator { strings:</code></p><p><code> $idbot1 = &#8220;V34_0110-fur-DI&#8221;</code></p><p><code> $idbot2 = &#8220;NonV45-0910-Cole-N6&#8221;</code></p><p><code> $apibot1 = &#8220;6453235748:AAHa67pMUGuvhmEuR0pIPhzWLQsMd-qAKoU&#8221;</code></p><p><code> $apibot2 = &#8220;6453235748:AAHa67pMUGuvhmEuR0pIPhzWLQsMd-qAKoU&#8221;</code></p><p><code> $newtime = /[0-9]+h[0-9]+m[0-9]+s-[0-9]+-[0-9]+-[0-9]+/</code></p><p><code> $name f = /[A-Za-z]+ [A-Za-z0-9-_]+ [0-9]+h[0-9]+m[0-9]+s-[0-9]+-[0-9]+-[0-9]+/</code></p><p><code>condition:</code></p><p><code> any of ($idbot*, $apibot*, $newtime, $name_f)</code></p><p>3. rule SuspiciousFBTG { strings:</p><p><code> $fburl = &#8220;adsmanager.facebook.com&#8221;</code></p><p><code> $tgurl = &#8220;api.telegram.org&#8221;</code></p><p><code> $import = &#8220;import&#8221; condition:</code></p><p><code>$import at 0 and $fburl and $tgurl</code></p><p><code>4. rule DetectLibb1 InZip { strings:</code></p><p><code>$zip magic = (50 4B 03 04)</code></p><p><code>$Iibb1_fiIename = &#8220;Iibb1.py&#8221;</code></p><p><code>condition:</code></p><p><code>$zip_magic at 0 and $Iibb1_fiIename</code></p></blockquote><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.darksignal.co/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[From Tunisia With Hate - Radio Islam Research]]></title><description><![CDATA[A Broadcast of Hate - The True Agenda of Radio Islam]]></description><link>https://www.darksignal.co/p/from-tunisia-with-hate-radio-islam</link><guid isPermaLink="false">https://www.darksignal.co/p/from-tunisia-with-hate-radio-islam</guid><dc:creator><![CDATA[DarkSignal]]></dc:creator><pubDate>Sun, 16 Nov 2025 12:38:31 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!xKyY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fbd9705-209a-42f1-8fb6-06c4937d4217_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xKyY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fbd9705-209a-42f1-8fb6-06c4937d4217_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xKyY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fbd9705-209a-42f1-8fb6-06c4937d4217_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!xKyY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fbd9705-209a-42f1-8fb6-06c4937d4217_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!xKyY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fbd9705-209a-42f1-8fb6-06c4937d4217_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!xKyY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fbd9705-209a-42f1-8fb6-06c4937d4217_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xKyY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fbd9705-209a-42f1-8fb6-06c4937d4217_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3fbd9705-209a-42f1-8fb6-06c4937d4217_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1993187,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179045233?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fbd9705-209a-42f1-8fb6-06c4937d4217_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!xKyY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fbd9705-209a-42f1-8fb6-06c4937d4217_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!xKyY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fbd9705-209a-42f1-8fb6-06c4937d4217_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!xKyY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fbd9705-209a-42f1-8fb6-06c4937d4217_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!xKyY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fbd9705-209a-42f1-8fb6-06c4937d4217_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><h3><strong>A Broadcast of Hate - The True Agenda of Radio Islam</strong></h3><p>Radio Islam (islam-radio.net) presents itself as an alternative &#8220;truth platform,&#8221; but behind the facade of a cultural or religious outlet lies one of the longest-running antisemitic propaganda hubs on the internet.</p><p>Operating across multiple languages, the site has consistently promoted Holocaust denial, conspiracy narratives about &#8220;Jewish world control&#8221;, revealing personal details of Jewish individuals living in Denmark, and rhetoric framing Jews as a global enemy that must be confronted.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.darksignal.co/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>While originally tied to a Swedish radio broadcast in the late 1980s, the platform has since evolved into a digital archive of ideological extremism, one that blends Neo-Nazi themes, Islamist hostility toward Israel, and calls for &#8220;struggle&#8221; against so-called Jewish domination across the globe.</p><p>This report traces the evolution of islam-radio.net from a local broadcast into a transnational hate ecosystem, examines the role of its founder in shaping its ideology, and documents how the site has functioned as both an online archive and a recruitment asset for broader extremist narratives to find out who really runs the website.</p><h3><strong>Under The Hood of Radicalization</strong></h3><p>An anonymous tip of an Israeli family living in Denmark led me to this website, as I received a phone call from a guy, claiming his wife&#8217;s name and personal details are on the website, all because she has a Jewish name, which makes her a potential target.</p><p>When reviewing this website, I came across proper propaganda against Israelis and Jewish people, extreme antisemite content, pure pro-Palestinian opinions, and significant incitement to violence.</p><p>The website includes graphic content taken from the old Nazi Germany, spreads conspiracy theories about Jews, and publishes content of Holocaust denial.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vod2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1098d19-a317-43da-94c1-56114c06bda7_566x221.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vod2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1098d19-a317-43da-94c1-56114c06bda7_566x221.png 424w, https://substackcdn.com/image/fetch/$s_!vod2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1098d19-a317-43da-94c1-56114c06bda7_566x221.png 848w, https://substackcdn.com/image/fetch/$s_!vod2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1098d19-a317-43da-94c1-56114c06bda7_566x221.png 1272w, https://substackcdn.com/image/fetch/$s_!vod2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1098d19-a317-43da-94c1-56114c06bda7_566x221.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vod2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1098d19-a317-43da-94c1-56114c06bda7_566x221.png" width="566" height="221" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b1098d19-a317-43da-94c1-56114c06bda7_566x221.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:221,&quot;width&quot;:566,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:63935,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179045233?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1098d19-a317-43da-94c1-56114c06bda7_566x221.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vod2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1098d19-a317-43da-94c1-56114c06bda7_566x221.png 424w, https://substackcdn.com/image/fetch/$s_!vod2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1098d19-a317-43da-94c1-56114c06bda7_566x221.png 848w, https://substackcdn.com/image/fetch/$s_!vod2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1098d19-a317-43da-94c1-56114c06bda7_566x221.png 1272w, https://substackcdn.com/image/fetch/$s_!vod2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1098d19-a317-43da-94c1-56114c06bda7_566x221.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!j3gM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd3962e8-1ea8-49a5-ac21-e2c573376556_321x209.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!j3gM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd3962e8-1ea8-49a5-ac21-e2c573376556_321x209.png 424w, https://substackcdn.com/image/fetch/$s_!j3gM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd3962e8-1ea8-49a5-ac21-e2c573376556_321x209.png 848w, https://substackcdn.com/image/fetch/$s_!j3gM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd3962e8-1ea8-49a5-ac21-e2c573376556_321x209.png 1272w, https://substackcdn.com/image/fetch/$s_!j3gM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd3962e8-1ea8-49a5-ac21-e2c573376556_321x209.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!j3gM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd3962e8-1ea8-49a5-ac21-e2c573376556_321x209.png" width="321" height="209" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fd3962e8-1ea8-49a5-ac21-e2c573376556_321x209.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:209,&quot;width&quot;:321,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:49830,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179045233?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd3962e8-1ea8-49a5-ac21-e2c573376556_321x209.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!j3gM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd3962e8-1ea8-49a5-ac21-e2c573376556_321x209.png 424w, https://substackcdn.com/image/fetch/$s_!j3gM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd3962e8-1ea8-49a5-ac21-e2c573376556_321x209.png 848w, https://substackcdn.com/image/fetch/$s_!j3gM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd3962e8-1ea8-49a5-ac21-e2c573376556_321x209.png 1272w, https://substackcdn.com/image/fetch/$s_!j3gM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd3962e8-1ea8-49a5-ac21-e2c573376556_321x209.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!pnpM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03a22356-5efd-426a-a780-a7a2f8fb9e80_253x261.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!pnpM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03a22356-5efd-426a-a780-a7a2f8fb9e80_253x261.png 424w, https://substackcdn.com/image/fetch/$s_!pnpM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03a22356-5efd-426a-a780-a7a2f8fb9e80_253x261.png 848w, https://substackcdn.com/image/fetch/$s_!pnpM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03a22356-5efd-426a-a780-a7a2f8fb9e80_253x261.png 1272w, https://substackcdn.com/image/fetch/$s_!pnpM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03a22356-5efd-426a-a780-a7a2f8fb9e80_253x261.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!pnpM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03a22356-5efd-426a-a780-a7a2f8fb9e80_253x261.png" width="253" height="261" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/03a22356-5efd-426a-a780-a7a2f8fb9e80_253x261.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:261,&quot;width&quot;:253,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:83671,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179045233?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03a22356-5efd-426a-a780-a7a2f8fb9e80_253x261.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!pnpM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03a22356-5efd-426a-a780-a7a2f8fb9e80_253x261.png 424w, https://substackcdn.com/image/fetch/$s_!pnpM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03a22356-5efd-426a-a780-a7a2f8fb9e80_253x261.png 848w, https://substackcdn.com/image/fetch/$s_!pnpM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03a22356-5efd-426a-a780-a7a2f8fb9e80_253x261.png 1272w, https://substackcdn.com/image/fetch/$s_!pnpM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03a22356-5efd-426a-a780-a7a2f8fb9e80_253x261.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The website itself originated in Sweden in the late 1990s as the online continuation of a Stockholm-based radio program founded in 1987 by Ahmed Rami. Although its name suggests a religious or cultural Islamic broadcast, the site is not a mainstream Islamic platform but an openly <strong>antisemitic propaganda hub</strong> that has been repeatedly cited by watchdog organizations, scholars, and legal authorities as one of the most extreme hate-based websites on the internet.</p><p>The website hosts a large multilingual archive of articles, books, and documents whose central purpose is to delegitimize and demonize Jews, Zionism, and Israel.</p><p>The site positions itself as a &#8220;freedom fighter&#8221; platform and uses militant language that portrays Jews as an enemy that must be opposed, turning antisemitic conspiracy theory into a call for action, even a physical one.</p><p>Altough there is no official claim by the owner of Radio Islam, or as it is written in the website - &#8220;<a href="https://www.islam-radio.net/islam/indexab.htm">This</a> Site is owned by a group of Freedom Fighters from different countries in support of <a href="https://www.islam-radio.net/islam/english/index_ri.htm">Ahmed Rami</a>&#8216;s struggle&#8221;, this website runs in the image and insparation of Rami himself.</p><p>Ahmed Rami, who was mentioned, is a Moroccan-Swedish former military officer who fled to Sweden after allegedly taking part in a 1972 coup attempt against King Hassan II, later becoming known as one of Europe&#8217;s most prominent antisemitic propagandists.</p><p>In 1987, he founded <strong>Radio Islam</strong> in Stockholm, originally a community radio program that quickly shifted into broadcasting Holocaust denial, conspiracy theories about &#8220;Jewish/Zionist power,&#8221; and far-right extremist content.</p><p>In 1996, it moved online under the domain <strong>islam-radio.net</strong>, which has since been cited by watchdog groups (ADL, SPLC) as one of the most radical antisemitic sites on the internet.</p><p>Rami was convicted in Sweden in 1990 for &#8220;incitement against an ethnic group&#8221; and served six months in prison, and has been investigated multiple times since for similar offenses, including a 2025 conviction related to antisemitic statements and praise of Hitler.</p><p>His ideology represents a hybrid of Islamist-style anti-Zionism and European Neo-Nazi rhetoric, creating an unusual bridge between far-right and radical Islamist narratives.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!mVdj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4c56443-fc45-4e51-bece-c50d78625d62_602x128.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!mVdj!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4c56443-fc45-4e51-bece-c50d78625d62_602x128.png 424w, https://substackcdn.com/image/fetch/$s_!mVdj!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4c56443-fc45-4e51-bece-c50d78625d62_602x128.png 848w, https://substackcdn.com/image/fetch/$s_!mVdj!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4c56443-fc45-4e51-bece-c50d78625d62_602x128.png 1272w, https://substackcdn.com/image/fetch/$s_!mVdj!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4c56443-fc45-4e51-bece-c50d78625d62_602x128.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!mVdj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4c56443-fc45-4e51-bece-c50d78625d62_602x128.png" width="602" height="128" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b4c56443-fc45-4e51-bece-c50d78625d62_602x128.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:128,&quot;width&quot;:602,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:54491,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179045233?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4c56443-fc45-4e51-bece-c50d78625d62_602x128.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!mVdj!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4c56443-fc45-4e51-bece-c50d78625d62_602x128.png 424w, https://substackcdn.com/image/fetch/$s_!mVdj!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4c56443-fc45-4e51-bece-c50d78625d62_602x128.png 848w, https://substackcdn.com/image/fetch/$s_!mVdj!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4c56443-fc45-4e51-bece-c50d78625d62_602x128.png 1272w, https://substackcdn.com/image/fetch/$s_!mVdj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4c56443-fc45-4e51-bece-c50d78625d62_602x128.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h3><strong>From Tunisia with Hate</strong></h3><p>When checking old domain records, I noticed that the name of the domain was part of a known registrar data leak, occured a few years ago.<br>The leak included not only the dmian name, but an email address and a phone number associated to it.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!XO06!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c8f7ee1-b82c-47ec-831f-5baa3764d976_787x118.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!XO06!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c8f7ee1-b82c-47ec-831f-5baa3764d976_787x118.png 424w, https://substackcdn.com/image/fetch/$s_!XO06!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c8f7ee1-b82c-47ec-831f-5baa3764d976_787x118.png 848w, https://substackcdn.com/image/fetch/$s_!XO06!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c8f7ee1-b82c-47ec-831f-5baa3764d976_787x118.png 1272w, https://substackcdn.com/image/fetch/$s_!XO06!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c8f7ee1-b82c-47ec-831f-5baa3764d976_787x118.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!XO06!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c8f7ee1-b82c-47ec-831f-5baa3764d976_787x118.png" width="787" height="118" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4c8f7ee1-b82c-47ec-831f-5baa3764d976_787x118.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:118,&quot;width&quot;:787,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:23588,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179045233?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c8f7ee1-b82c-47ec-831f-5baa3764d976_787x118.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!XO06!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c8f7ee1-b82c-47ec-831f-5baa3764d976_787x118.png 424w, https://substackcdn.com/image/fetch/$s_!XO06!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c8f7ee1-b82c-47ec-831f-5baa3764d976_787x118.png 848w, https://substackcdn.com/image/fetch/$s_!XO06!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c8f7ee1-b82c-47ec-831f-5baa3764d976_787x118.png 1272w, https://substackcdn.com/image/fetch/$s_!XO06!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c8f7ee1-b82c-47ec-831f-5baa3764d976_787x118.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>When searching the email, I managed to find it in an XLS document from 2014, called &#8220;Selection Events&#8221;, probably a bunch of events around the area of Africa and Tunisia, alongside full names of two individuals and 2 different email addresses, as one of them is the email address that is associated directly with islam-radio.net.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!waqn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe719f8fa-e382-482b-8cf2-577688c4ecd0_507x375.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!waqn!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe719f8fa-e382-482b-8cf2-577688c4ecd0_507x375.png 424w, https://substackcdn.com/image/fetch/$s_!waqn!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe719f8fa-e382-482b-8cf2-577688c4ecd0_507x375.png 848w, https://substackcdn.com/image/fetch/$s_!waqn!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe719f8fa-e382-482b-8cf2-577688c4ecd0_507x375.png 1272w, https://substackcdn.com/image/fetch/$s_!waqn!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe719f8fa-e382-482b-8cf2-577688c4ecd0_507x375.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!waqn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe719f8fa-e382-482b-8cf2-577688c4ecd0_507x375.png" width="507" height="375" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e719f8fa-e382-482b-8cf2-577688c4ecd0_507x375.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:375,&quot;width&quot;:507,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:181903,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179045233?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe719f8fa-e382-482b-8cf2-577688c4ecd0_507x375.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!waqn!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe719f8fa-e382-482b-8cf2-577688c4ecd0_507x375.png 424w, https://substackcdn.com/image/fetch/$s_!waqn!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe719f8fa-e382-482b-8cf2-577688c4ecd0_507x375.png 848w, https://substackcdn.com/image/fetch/$s_!waqn!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe719f8fa-e382-482b-8cf2-577688c4ecd0_507x375.png 1272w, https://substackcdn.com/image/fetch/$s_!waqn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe719f8fa-e382-482b-8cf2-577688c4ecd0_507x375.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The associated names are Jawhara Mohamed Ayoub, Hidoussi Ben, and Hidoussi Ahmed Farouk (who are most likely related by blood).</p><p>The email addresses (one of which is already known and directly associated with Radio Islam are <strong>hmatest@gmail[.]com</strong> and <strong>hidoussifarouk6@gmail[.]com</strong>, a personal email address of one of the individuals.</p><p>Both emails related directly to Hidoussi&#8217;s, but the email hidoussifarouk6@gmail[.]com (belongs to <strong>Farouk Hidoussi </strong>/ <strong>Farouk Hidouci</strong>) found in direct association with an Instagram account of an armed individual with a face mask, standing near a vehicle that seems to be tagged with a car plate of France.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!lHCv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55b4942c-a41b-4e42-a6b6-eff3f55701ea_552x200.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!lHCv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55b4942c-a41b-4e42-a6b6-eff3f55701ea_552x200.png 424w, https://substackcdn.com/image/fetch/$s_!lHCv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55b4942c-a41b-4e42-a6b6-eff3f55701ea_552x200.png 848w, https://substackcdn.com/image/fetch/$s_!lHCv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55b4942c-a41b-4e42-a6b6-eff3f55701ea_552x200.png 1272w, https://substackcdn.com/image/fetch/$s_!lHCv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55b4942c-a41b-4e42-a6b6-eff3f55701ea_552x200.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!lHCv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55b4942c-a41b-4e42-a6b6-eff3f55701ea_552x200.png" width="552" height="200" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/55b4942c-a41b-4e42-a6b6-eff3f55701ea_552x200.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:200,&quot;width&quot;:552,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:106485,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179045233?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55b4942c-a41b-4e42-a6b6-eff3f55701ea_552x200.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!lHCv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55b4942c-a41b-4e42-a6b6-eff3f55701ea_552x200.png 424w, https://substackcdn.com/image/fetch/$s_!lHCv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55b4942c-a41b-4e42-a6b6-eff3f55701ea_552x200.png 848w, https://substackcdn.com/image/fetch/$s_!lHCv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55b4942c-a41b-4e42-a6b6-eff3f55701ea_552x200.png 1272w, https://substackcdn.com/image/fetch/$s_!lHCv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55b4942c-a41b-4e42-a6b6-eff3f55701ea_552x200.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>This account contains only one photo, of Algeria&#8217;s national flag and follows extremists content, such as the account &#8220;s3dosh_officiel&#8221;, that publish photos of radical Islam and owns a profile picture with the Arabic text &#8220;We belong to god, and to him we shall return&#8221;, a very known phrase taken from Quran and mostly used in terms of death and terror.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Cqt2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F033adbaf-d60f-4520-af3a-c16987b473d9_602x379.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Cqt2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F033adbaf-d60f-4520-af3a-c16987b473d9_602x379.png 424w, https://substackcdn.com/image/fetch/$s_!Cqt2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F033adbaf-d60f-4520-af3a-c16987b473d9_602x379.png 848w, https://substackcdn.com/image/fetch/$s_!Cqt2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F033adbaf-d60f-4520-af3a-c16987b473d9_602x379.png 1272w, https://substackcdn.com/image/fetch/$s_!Cqt2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F033adbaf-d60f-4520-af3a-c16987b473d9_602x379.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Cqt2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F033adbaf-d60f-4520-af3a-c16987b473d9_602x379.png" width="602" height="379" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/033adbaf-d60f-4520-af3a-c16987b473d9_602x379.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:379,&quot;width&quot;:602,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:190867,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179045233?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F033adbaf-d60f-4520-af3a-c16987b473d9_602x379.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Cqt2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F033adbaf-d60f-4520-af3a-c16987b473d9_602x379.png 424w, https://substackcdn.com/image/fetch/$s_!Cqt2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F033adbaf-d60f-4520-af3a-c16987b473d9_602x379.png 848w, https://substackcdn.com/image/fetch/$s_!Cqt2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F033adbaf-d60f-4520-af3a-c16987b473d9_602x379.png 1272w, https://substackcdn.com/image/fetch/$s_!Cqt2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F033adbaf-d60f-4520-af3a-c16987b473d9_602x379.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>The Faces Behind Radio Islam</strong></h3><p>The email addresses and names revealed two individuals, their names already been mentioned (<strong>Farouk Hidoussi</strong>, <strong>Hidoussi Ayoub</strong>), Tech Journalists and web designers from Tunisia.</p><p>The email address and phone number that are directly associated to the domain of Radio Islam led to this individual as well, confirming his identity and direct relation and ownership to this matter.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ckJu!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2c7b267d-eb3d-41ec-9b28-71bee4f21cda_514x193.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ckJu!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2c7b267d-eb3d-41ec-9b28-71bee4f21cda_514x193.png 424w, https://substackcdn.com/image/fetch/$s_!ckJu!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2c7b267d-eb3d-41ec-9b28-71bee4f21cda_514x193.png 848w, https://substackcdn.com/image/fetch/$s_!ckJu!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2c7b267d-eb3d-41ec-9b28-71bee4f21cda_514x193.png 1272w, https://substackcdn.com/image/fetch/$s_!ckJu!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2c7b267d-eb3d-41ec-9b28-71bee4f21cda_514x193.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ckJu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2c7b267d-eb3d-41ec-9b28-71bee4f21cda_514x193.png" width="514" height="193" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2c7b267d-eb3d-41ec-9b28-71bee4f21cda_514x193.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:193,&quot;width&quot;:514,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:28733,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179045233?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2c7b267d-eb3d-41ec-9b28-71bee4f21cda_514x193.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ckJu!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2c7b267d-eb3d-41ec-9b28-71bee4f21cda_514x193.png 424w, https://substackcdn.com/image/fetch/$s_!ckJu!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2c7b267d-eb3d-41ec-9b28-71bee4f21cda_514x193.png 848w, https://substackcdn.com/image/fetch/$s_!ckJu!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2c7b267d-eb3d-41ec-9b28-71bee4f21cda_514x193.png 1272w, https://substackcdn.com/image/fetch/$s_!ckJu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2c7b267d-eb3d-41ec-9b28-71bee4f21cda_514x193.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!SxMH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9abd7d93-209f-41b9-9abb-78a8c1e987f5_389x205.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!SxMH!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9abd7d93-209f-41b9-9abb-78a8c1e987f5_389x205.png 424w, https://substackcdn.com/image/fetch/$s_!SxMH!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9abd7d93-209f-41b9-9abb-78a8c1e987f5_389x205.png 848w, https://substackcdn.com/image/fetch/$s_!SxMH!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9abd7d93-209f-41b9-9abb-78a8c1e987f5_389x205.png 1272w, https://substackcdn.com/image/fetch/$s_!SxMH!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9abd7d93-209f-41b9-9abb-78a8c1e987f5_389x205.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!SxMH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9abd7d93-209f-41b9-9abb-78a8c1e987f5_389x205.png" width="389" height="205" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9abd7d93-209f-41b9-9abb-78a8c1e987f5_389x205.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:205,&quot;width&quot;:389,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:21542,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179045233?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9abd7d93-209f-41b9-9abb-78a8c1e987f5_389x205.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!SxMH!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9abd7d93-209f-41b9-9abb-78a8c1e987f5_389x205.png 424w, https://substackcdn.com/image/fetch/$s_!SxMH!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9abd7d93-209f-41b9-9abb-78a8c1e987f5_389x205.png 848w, https://substackcdn.com/image/fetch/$s_!SxMH!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9abd7d93-209f-41b9-9abb-78a8c1e987f5_389x205.png 1272w, https://substackcdn.com/image/fetch/$s_!SxMH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9abd7d93-209f-41b9-9abb-78a8c1e987f5_389x205.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ux5Z!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9186aedf-5948-4c69-b85a-f1712ebf01c5_270x144.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ux5Z!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9186aedf-5948-4c69-b85a-f1712ebf01c5_270x144.png 424w, https://substackcdn.com/image/fetch/$s_!ux5Z!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9186aedf-5948-4c69-b85a-f1712ebf01c5_270x144.png 848w, https://substackcdn.com/image/fetch/$s_!ux5Z!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9186aedf-5948-4c69-b85a-f1712ebf01c5_270x144.png 1272w, https://substackcdn.com/image/fetch/$s_!ux5Z!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9186aedf-5948-4c69-b85a-f1712ebf01c5_270x144.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ux5Z!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9186aedf-5948-4c69-b85a-f1712ebf01c5_270x144.png" width="270" height="144" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9186aedf-5948-4c69-b85a-f1712ebf01c5_270x144.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:144,&quot;width&quot;:270,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:27634,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179045233?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9186aedf-5948-4c69-b85a-f1712ebf01c5_270x144.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ux5Z!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9186aedf-5948-4c69-b85a-f1712ebf01c5_270x144.png 424w, https://substackcdn.com/image/fetch/$s_!ux5Z!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9186aedf-5948-4c69-b85a-f1712ebf01c5_270x144.png 848w, https://substackcdn.com/image/fetch/$s_!ux5Z!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9186aedf-5948-4c69-b85a-f1712ebf01c5_270x144.png 1272w, https://substackcdn.com/image/fetch/$s_!ux5Z!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9186aedf-5948-4c69-b85a-f1712ebf01c5_270x144.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>In the picture: Object 1 Behind the Website (<strong>Hidoussi Ayoub</strong>) </p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vLR6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e6150d6-b98d-4f52-89b2-7226bbb080a0_317x101.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vLR6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e6150d6-b98d-4f52-89b2-7226bbb080a0_317x101.png 424w, https://substackcdn.com/image/fetch/$s_!vLR6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e6150d6-b98d-4f52-89b2-7226bbb080a0_317x101.png 848w, https://substackcdn.com/image/fetch/$s_!vLR6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e6150d6-b98d-4f52-89b2-7226bbb080a0_317x101.png 1272w, https://substackcdn.com/image/fetch/$s_!vLR6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e6150d6-b98d-4f52-89b2-7226bbb080a0_317x101.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vLR6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e6150d6-b98d-4f52-89b2-7226bbb080a0_317x101.png" width="317" height="101" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1e6150d6-b98d-4f52-89b2-7226bbb080a0_317x101.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:101,&quot;width&quot;:317,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:16285,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179045233?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e6150d6-b98d-4f52-89b2-7226bbb080a0_317x101.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vLR6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e6150d6-b98d-4f52-89b2-7226bbb080a0_317x101.png 424w, https://substackcdn.com/image/fetch/$s_!vLR6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e6150d6-b98d-4f52-89b2-7226bbb080a0_317x101.png 848w, https://substackcdn.com/image/fetch/$s_!vLR6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e6150d6-b98d-4f52-89b2-7226bbb080a0_317x101.png 1272w, https://substackcdn.com/image/fetch/$s_!vLR6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e6150d6-b98d-4f52-89b2-7226bbb080a0_317x101.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>In the picture: Object 2 Behind the Website (<strong>Hidoussi Farouk</strong>)</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.darksignal.co/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[INDOHAXSEC - Revealing Threat Actor]]></title><description><![CDATA[INDOHAXSEC - Introduction to Threat Actor]]></description><link>https://www.darksignal.co/p/indohaxsec-revealing-threat-actor</link><guid isPermaLink="false">https://www.darksignal.co/p/indohaxsec-revealing-threat-actor</guid><dc:creator><![CDATA[DarkSignal]]></dc:creator><pubDate>Sun, 16 Nov 2025 12:25:52 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!vbON!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F252a67de-aa21-40aa-80b4-23da579d9d21_1024x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vbON!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F252a67de-aa21-40aa-80b4-23da579d9d21_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vbON!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F252a67de-aa21-40aa-80b4-23da579d9d21_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!vbON!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F252a67de-aa21-40aa-80b4-23da579d9d21_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!vbON!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F252a67de-aa21-40aa-80b4-23da579d9d21_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!vbON!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F252a67de-aa21-40aa-80b4-23da579d9d21_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vbON!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F252a67de-aa21-40aa-80b4-23da579d9d21_1024x1024.png" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/252a67de-aa21-40aa-80b4-23da579d9d21_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1995050,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179044352?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F252a67de-aa21-40aa-80b4-23da579d9d21_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vbON!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F252a67de-aa21-40aa-80b4-23da579d9d21_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!vbON!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F252a67de-aa21-40aa-80b4-23da579d9d21_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!vbON!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F252a67de-aa21-40aa-80b4-23da579d9d21_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!vbON!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F252a67de-aa21-40aa-80b4-23da579d9d21_1024x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><h3><strong>INDOHAXSEC - Introduction to Threat Actor</strong></h3><p>INDOHAXSEC is an Indonesian hacktivist group known for conducting politically motivated cyber operations and opportunistic attacks targeting government entities, corporations, and organizations across Southeast Asia and beyond, mostly Israel, India, and Azerbaijan, who known to be Israel supporters.</p><p>The group went public in early October 2024, a year after the horrific October 7th massacre by the terror organization Hamas, establishing a strong online presence under names such as &#8220;INDOHAXSEC TEAM.&#8221;</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.darksignal.co/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Their campaigns are characterized by large scale website defacements, DDoS attacks, and data-leak announcements often framed as acts of protest pagainst olitical and ideological adversaries. Among their more notable operations is a claimed breach of Nestl&#233;&#8217;s internal systems, where they allegedly accessed and leaked over 28,000 corporate credentials in connection with a boycott campaign against Western-aligned companies.</p><p>INDOHAXSEC has also declared cooperation with other hacktivist entities, including the Pakistani group Team Azrael (&#8220;Angel of Death&#8221;), with stated intentions to conduct cyber operations targeting Indian digital infrastructure.</p><p>Despite self-promoted claims of developing a web-based &#8220;WannaCry-style&#8221; ransomware tool, independent verification of such capabilities remains limited, suggesting the group&#8217;s real-world expertise lies primarily in exploiting poorly secured web servers, CMS vulnerabilities, and weak credentials, their data leak operations also reclaimed.</p><p>INDOHAXSEC maintains multiple Telegram channels and social-media presence through which they publicize supposed successful intrusions, recruit collaborators, and disseminate propaganda aligned with nationalist and anti-Western narratives.</p><p>The following research sheds light on this collective and explores potential affiliations between the group&#8217;s online handles, infrastructure usage, and the broader Southeast-Asian hacktivist ecosystem.</p><h3><strong>Getting To Know INDOHAXSEC</strong></h3><p>The group has been active since October 2024, with a few dozen posts on different hacking forums, Telegram, and even a WhatsApp channel where they boast about recent cyber operations against Israel, India, Azerbaijan, and basically anyone who is &#8220;against Islam&#8221; in their opinion.</p><p>They are monetizing and promoting themselves through social media, from Instagram to TikTo,k to reach new joiners and to gain sympathy by the audience.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hxmf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7820b108-6ca3-40b7-a2b8-38f3c6af6704_529x187.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hxmf!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7820b108-6ca3-40b7-a2b8-38f3c6af6704_529x187.png 424w, https://substackcdn.com/image/fetch/$s_!hxmf!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7820b108-6ca3-40b7-a2b8-38f3c6af6704_529x187.png 848w, https://substackcdn.com/image/fetch/$s_!hxmf!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7820b108-6ca3-40b7-a2b8-38f3c6af6704_529x187.png 1272w, https://substackcdn.com/image/fetch/$s_!hxmf!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7820b108-6ca3-40b7-a2b8-38f3c6af6704_529x187.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hxmf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7820b108-6ca3-40b7-a2b8-38f3c6af6704_529x187.png" width="529" height="187" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7820b108-6ca3-40b7-a2b8-38f3c6af6704_529x187.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:187,&quot;width&quot;:529,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:68581,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179044352?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7820b108-6ca3-40b7-a2b8-38f3c6af6704_529x187.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!hxmf!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7820b108-6ca3-40b7-a2b8-38f3c6af6704_529x187.png 424w, https://substackcdn.com/image/fetch/$s_!hxmf!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7820b108-6ca3-40b7-a2b8-38f3c6af6704_529x187.png 848w, https://substackcdn.com/image/fetch/$s_!hxmf!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7820b108-6ca3-40b7-a2b8-38f3c6af6704_529x187.png 1272w, https://substackcdn.com/image/fetch/$s_!hxmf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7820b108-6ca3-40b7-a2b8-38f3c6af6704_529x187.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2srC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d417fc0-ba83-461e-8935-6fc663cc3e75_220x340.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2srC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d417fc0-ba83-461e-8935-6fc663cc3e75_220x340.png 424w, https://substackcdn.com/image/fetch/$s_!2srC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d417fc0-ba83-461e-8935-6fc663cc3e75_220x340.png 848w, https://substackcdn.com/image/fetch/$s_!2srC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d417fc0-ba83-461e-8935-6fc663cc3e75_220x340.png 1272w, https://substackcdn.com/image/fetch/$s_!2srC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d417fc0-ba83-461e-8935-6fc663cc3e75_220x340.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2srC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d417fc0-ba83-461e-8935-6fc663cc3e75_220x340.png" width="220" height="340" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6d417fc0-ba83-461e-8935-6fc663cc3e75_220x340.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:340,&quot;width&quot;:220,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:64984,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179044352?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d417fc0-ba83-461e-8935-6fc663cc3e75_220x340.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!2srC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d417fc0-ba83-461e-8935-6fc663cc3e75_220x340.png 424w, https://substackcdn.com/image/fetch/$s_!2srC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d417fc0-ba83-461e-8935-6fc663cc3e75_220x340.png 848w, https://substackcdn.com/image/fetch/$s_!2srC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d417fc0-ba83-461e-8935-6fc663cc3e75_220x340.png 1272w, https://substackcdn.com/image/fetch/$s_!2srC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d417fc0-ba83-461e-8935-6fc663cc3e75_220x340.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Bvbq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49a3a5e2-2fee-44f7-8216-a03be3748060_375x236.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Bvbq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49a3a5e2-2fee-44f7-8216-a03be3748060_375x236.png 424w, https://substackcdn.com/image/fetch/$s_!Bvbq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49a3a5e2-2fee-44f7-8216-a03be3748060_375x236.png 848w, https://substackcdn.com/image/fetch/$s_!Bvbq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49a3a5e2-2fee-44f7-8216-a03be3748060_375x236.png 1272w, https://substackcdn.com/image/fetch/$s_!Bvbq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49a3a5e2-2fee-44f7-8216-a03be3748060_375x236.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Bvbq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49a3a5e2-2fee-44f7-8216-a03be3748060_375x236.png" width="375" height="236" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/49a3a5e2-2fee-44f7-8216-a03be3748060_375x236.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:236,&quot;width&quot;:375,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:85908,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179044352?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49a3a5e2-2fee-44f7-8216-a03be3748060_375x236.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Bvbq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49a3a5e2-2fee-44f7-8216-a03be3748060_375x236.png 424w, https://substackcdn.com/image/fetch/$s_!Bvbq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49a3a5e2-2fee-44f7-8216-a03be3748060_375x236.png 848w, https://substackcdn.com/image/fetch/$s_!Bvbq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49a3a5e2-2fee-44f7-8216-a03be3748060_375x236.png 1272w, https://substackcdn.com/image/fetch/$s_!Bvbq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49a3a5e2-2fee-44f7-8216-a03be3748060_375x236.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><ul><li><p>TikTok: https://www.tiktok.com/@indohaxsec</p></li><li><p>Telegram: https://t.me/Indohaxsec_Team</p></li><li><p>Instagram: https://www.instagram.com/indohaxsec</p></li><li><p>GitHub: https://github.com/INDOHAXSEC</p></li></ul><h3><strong>Toolkit &amp; Repositories</strong></h3><p>INDOHAXSEC maintains a <strong>public GitHub presence</strong> tied to the group&#8217;s October-2024 start, the org page and contribution history show most activity concentrated around that timeframe, and the repo README(s) and commits link back to the group&#8217;s Telegram. Their GitHub is essentially a surface-web staging area for scripts, droppers, DDoS tooling, and site-encryption code rather than a polished malware farm.</p><ol><li><p><strong>Ark-Cheat-Detector (modified)</strong> - A game-related repo was repurposed into a web backdoor delivery mechanism. Low sophistication, but an effective way to hide malicious PHP on web hosts. </p></li><li><p><strong>NUKLIR (Python / Node.js DDoS collection)</strong> - a set of DDoS scripts available in Python and Node.js formats that enable volumetric flooding against specified targets. NUKLIR is a functional DDoS tooling (simple to use, widely re-shared) and very useful for hacktivist-style disruption, but not an advanced tradecraft. </p></li><li><p><strong>RUDAL &amp; Rudal-shell (Python / PHP)</strong> - very similar to NUKLIR but missing some external dependencies. The collection contains PHP backdoors and utility scripts for remote control of compromised web servers (file upload/download, command exec, simple web shells). These artifacts indicate a focus on maintaining web footholds and automating defacement/encryption workflows. </p></li><li><p><strong>ExorLock (ransom/site-encryptor)</strong> - ExorLock ransomware project was traced back to earlier group iterations (AnonBlackFlag) via archived README files. <br>ExorLock appears in the repository history and was previously claimed to have been used against an Indian target (unconfirmed). </p></li><li><p><strong>XSS_Fucker (scanner / PoC)</strong> - a compiled Python scanner intended to find XSS vulnerabilities at scale. This sort of tooling automates the discovery of trivial web vulnerabilities that can then be weaponized for defacement, session theft, or initial access.</p></li></ol><p>INDOHAXSEC&#8217;s<strong> </strong>toolkit is <strong>serviceable but generally low-to-moderate sophistication</strong>. The group reuses public code, forks benign projects, and injects PHP droppers/backdoors, packages commonly available DDoS/XSS scanners, and simple encryptors.</p><p>Their public posture (posting repos and demo videos) shows they favour notoriety and ease of reuse over stealth and rigorous OPSEC.</p><h3><strong>Hashtags &amp; Focus Areas</strong></h3><p>An examination of the hashtags appearing in INDOHAXSEC&#8217;s Telegram posts offers additional perspective on their targeting patterns and victim selection. The chart below illustrates the distribution of the group&#8217;s most used hashtags since October 2024.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4kVH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97ce3984-ae9f-4ae3-a489-064deff2399f_863x642.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4kVH!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97ce3984-ae9f-4ae3-a489-064deff2399f_863x642.png 424w, https://substackcdn.com/image/fetch/$s_!4kVH!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97ce3984-ae9f-4ae3-a489-064deff2399f_863x642.png 848w, https://substackcdn.com/image/fetch/$s_!4kVH!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97ce3984-ae9f-4ae3-a489-064deff2399f_863x642.png 1272w, https://substackcdn.com/image/fetch/$s_!4kVH!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97ce3984-ae9f-4ae3-a489-064deff2399f_863x642.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4kVH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97ce3984-ae9f-4ae3-a489-064deff2399f_863x642.png" width="863" height="642" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/97ce3984-ae9f-4ae3-a489-064deff2399f_863x642.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:642,&quot;width&quot;:863,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:124444,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179044352?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97ce3984-ae9f-4ae3-a489-064deff2399f_863x642.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!4kVH!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97ce3984-ae9f-4ae3-a489-064deff2399f_863x642.png 424w, https://substackcdn.com/image/fetch/$s_!4kVH!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97ce3984-ae9f-4ae3-a489-064deff2399f_863x642.png 848w, https://substackcdn.com/image/fetch/$s_!4kVH!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97ce3984-ae9f-4ae3-a489-064deff2399f_863x642.png 1272w, https://substackcdn.com/image/fetch/$s_!4kVH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97ce3984-ae9f-4ae3-a489-064deff2399f_863x642.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>Known Collaborations</strong></h3><p>&#216; <strong>NoName057(16)</strong></p><ul><li><p>Nature of alliance: Publicly declared &#8220;collaboration&#8221; announced via Telegram approximately one month after INDOHAXSEC&#8217;s formation.</p></li><li><p>Profile of partner: Pro-Russian hacktivist collective known for large-scale DDoS operations against Western and NATO-aligned infrastructure.</p></li><li><p>Assessment: Ideological alignment (anti-Western, pro-Palestinian rhetoric) and publicity cooperation rather than formal, coordinated cyber campaigns.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!DW5_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f8f1879-139a-4dfc-beff-564ea592438f_223x235.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!DW5_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f8f1879-139a-4dfc-beff-564ea592438f_223x235.png 424w, https://substackcdn.com/image/fetch/$s_!DW5_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f8f1879-139a-4dfc-beff-564ea592438f_223x235.png 848w, https://substackcdn.com/image/fetch/$s_!DW5_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f8f1879-139a-4dfc-beff-564ea592438f_223x235.png 1272w, https://substackcdn.com/image/fetch/$s_!DW5_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f8f1879-139a-4dfc-beff-564ea592438f_223x235.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!DW5_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f8f1879-139a-4dfc-beff-564ea592438f_223x235.png" width="223" height="235" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5f8f1879-139a-4dfc-beff-564ea592438f_223x235.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:235,&quot;width&quot;:223,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:87999,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179044352?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f8f1879-139a-4dfc-beff-564ea592438f_223x235.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!DW5_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f8f1879-139a-4dfc-beff-564ea592438f_223x235.png 424w, https://substackcdn.com/image/fetch/$s_!DW5_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f8f1879-139a-4dfc-beff-564ea592438f_223x235.png 848w, https://substackcdn.com/image/fetch/$s_!DW5_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f8f1879-139a-4dfc-beff-564ea592438f_223x235.png 1272w, https://substackcdn.com/image/fetch/$s_!DW5_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f8f1879-139a-4dfc-beff-564ea592438f_223x235.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>&#216; <strong>Team Azrael (&#8220;Angel of Death&#8221;)</strong></p></li><li><p>Nature of alliance: Tactical, event-driven collaboration announced during India-Pakistan cyber tensions.</p></li><li><p>Profile of partner: Pakistani hacktivist group linked to politically motivated campaigns targeting Indian entities.</p></li><li><p>Assessment: Typical of hacktivist surge behaviour, a temporary alliance focused on geopolitical flashpoints, with no proof of long-term shared command or infrastructure.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!GX8h!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd4c0fcb-ed24-4662-a3f4-0fdad8497ec0_228x160.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!GX8h!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd4c0fcb-ed24-4662-a3f4-0fdad8497ec0_228x160.png 424w, https://substackcdn.com/image/fetch/$s_!GX8h!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd4c0fcb-ed24-4662-a3f4-0fdad8497ec0_228x160.png 848w, https://substackcdn.com/image/fetch/$s_!GX8h!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd4c0fcb-ed24-4662-a3f4-0fdad8497ec0_228x160.png 1272w, https://substackcdn.com/image/fetch/$s_!GX8h!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd4c0fcb-ed24-4662-a3f4-0fdad8497ec0_228x160.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!GX8h!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd4c0fcb-ed24-4662-a3f4-0fdad8497ec0_228x160.png" width="228" height="160" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cd4c0fcb-ed24-4662-a3f4-0fdad8497ec0_228x160.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:160,&quot;width&quot;:228,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:57460,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179044352?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd4c0fcb-ed24-4662-a3f4-0fdad8497ec0_228x160.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!GX8h!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd4c0fcb-ed24-4662-a3f4-0fdad8497ec0_228x160.png 424w, https://substackcdn.com/image/fetch/$s_!GX8h!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd4c0fcb-ed24-4662-a3f4-0fdad8497ec0_228x160.png 848w, https://substackcdn.com/image/fetch/$s_!GX8h!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd4c0fcb-ed24-4662-a3f4-0fdad8497ec0_228x160.png 1272w, https://substackcdn.com/image/fetch/$s_!GX8h!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd4c0fcb-ed24-4662-a3f4-0fdad8497ec0_228x160.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h3><strong>Deep Diving</strong></h3><p>The username &#8220;<strong>INDOHAXSEC</strong>&#8221; is not common, and it is the official name of the group, so this is the starting point. When searching for that username, their Instagram profile popped up.<br>By using API manipulations, I found the ID of the profile (<strong>68343877461</strong>) and managed to associate the profile with the registered email address (<strong>indohaxsec@gmail.com</strong>) and a new username - &#8220;<strong>K3T0PR4K</strong>&#8221;.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!jLJW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f98b4e6-e26a-478e-9e57-02f0ffb8d6a9_649x45.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!jLJW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f98b4e6-e26a-478e-9e57-02f0ffb8d6a9_649x45.png 424w, https://substackcdn.com/image/fetch/$s_!jLJW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f98b4e6-e26a-478e-9e57-02f0ffb8d6a9_649x45.png 848w, https://substackcdn.com/image/fetch/$s_!jLJW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f98b4e6-e26a-478e-9e57-02f0ffb8d6a9_649x45.png 1272w, https://substackcdn.com/image/fetch/$s_!jLJW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f98b4e6-e26a-478e-9e57-02f0ffb8d6a9_649x45.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!jLJW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f98b4e6-e26a-478e-9e57-02f0ffb8d6a9_649x45.png" width="649" height="45" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0f98b4e6-e26a-478e-9e57-02f0ffb8d6a9_649x45.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:45,&quot;width&quot;:649,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:8771,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179044352?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f98b4e6-e26a-478e-9e57-02f0ffb8d6a9_649x45.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!jLJW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f98b4e6-e26a-478e-9e57-02f0ffb8d6a9_649x45.png 424w, https://substackcdn.com/image/fetch/$s_!jLJW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f98b4e6-e26a-478e-9e57-02f0ffb8d6a9_649x45.png 848w, https://substackcdn.com/image/fetch/$s_!jLJW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f98b4e6-e26a-478e-9e57-02f0ffb8d6a9_649x45.png 1272w, https://substackcdn.com/image/fetch/$s_!jLJW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f98b4e6-e26a-478e-9e57-02f0ffb8d6a9_649x45.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>The email address was also shown on the cached website of the group (that already went off-line), a thing that validates the relation of this email address to the hacking group.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xl7b!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0106c757-8b6a-41fe-b6ed-30a330f26583_612x128.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xl7b!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0106c757-8b6a-41fe-b6ed-30a330f26583_612x128.png 424w, https://substackcdn.com/image/fetch/$s_!xl7b!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0106c757-8b6a-41fe-b6ed-30a330f26583_612x128.png 848w, https://substackcdn.com/image/fetch/$s_!xl7b!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0106c757-8b6a-41fe-b6ed-30a330f26583_612x128.png 1272w, https://substackcdn.com/image/fetch/$s_!xl7b!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0106c757-8b6a-41fe-b6ed-30a330f26583_612x128.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xl7b!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0106c757-8b6a-41fe-b6ed-30a330f26583_612x128.png" width="612" height="128" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0106c757-8b6a-41fe-b6ed-30a330f26583_612x128.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:128,&quot;width&quot;:612,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:46231,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179044352?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0106c757-8b6a-41fe-b6ed-30a330f26583_612x128.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!xl7b!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0106c757-8b6a-41fe-b6ed-30a330f26583_612x128.png 424w, https://substackcdn.com/image/fetch/$s_!xl7b!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0106c757-8b6a-41fe-b6ed-30a330f26583_612x128.png 848w, https://substackcdn.com/image/fetch/$s_!xl7b!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0106c757-8b6a-41fe-b6ed-30a330f26583_612x128.png 1272w, https://substackcdn.com/image/fetch/$s_!xl7b!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0106c757-8b6a-41fe-b6ed-30a330f26583_612x128.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3P7m!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F230a9b9e-26fe-4c8e-acd9-b929dddeac91_614x280.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3P7m!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F230a9b9e-26fe-4c8e-acd9-b929dddeac91_614x280.png 424w, https://substackcdn.com/image/fetch/$s_!3P7m!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F230a9b9e-26fe-4c8e-acd9-b929dddeac91_614x280.png 848w, https://substackcdn.com/image/fetch/$s_!3P7m!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F230a9b9e-26fe-4c8e-acd9-b929dddeac91_614x280.png 1272w, https://substackcdn.com/image/fetch/$s_!3P7m!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F230a9b9e-26fe-4c8e-acd9-b929dddeac91_614x280.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3P7m!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F230a9b9e-26fe-4c8e-acd9-b929dddeac91_614x280.png" width="614" height="280" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/230a9b9e-26fe-4c8e-acd9-b929dddeac91_614x280.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:280,&quot;width&quot;:614,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:75610,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179044352?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F230a9b9e-26fe-4c8e-acd9-b929dddeac91_614x280.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3P7m!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F230a9b9e-26fe-4c8e-acd9-b929dddeac91_614x280.png 424w, https://substackcdn.com/image/fetch/$s_!3P7m!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F230a9b9e-26fe-4c8e-acd9-b929dddeac91_614x280.png 848w, https://substackcdn.com/image/fetch/$s_!3P7m!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F230a9b9e-26fe-4c8e-acd9-b929dddeac91_614x280.png 1272w, https://substackcdn.com/image/fetch/$s_!3P7m!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F230a9b9e-26fe-4c8e-acd9-b929dddeac91_614x280.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The username itself was found several times in relation to previous cyber-attacks (mostly data leaks, defacements, and DDoS attacks) against India and Israel, exactly as the group targets.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-Smp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0de5c5b6-6136-454a-8da3-b50bed5c606a_475x154.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-Smp!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0de5c5b6-6136-454a-8da3-b50bed5c606a_475x154.png 424w, https://substackcdn.com/image/fetch/$s_!-Smp!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0de5c5b6-6136-454a-8da3-b50bed5c606a_475x154.png 848w, https://substackcdn.com/image/fetch/$s_!-Smp!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0de5c5b6-6136-454a-8da3-b50bed5c606a_475x154.png 1272w, https://substackcdn.com/image/fetch/$s_!-Smp!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0de5c5b6-6136-454a-8da3-b50bed5c606a_475x154.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-Smp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0de5c5b6-6136-454a-8da3-b50bed5c606a_475x154.png" width="475" height="154" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0de5c5b6-6136-454a-8da3-b50bed5c606a_475x154.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:154,&quot;width&quot;:475,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:40698,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179044352?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0de5c5b6-6136-454a-8da3-b50bed5c606a_475x154.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-Smp!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0de5c5b6-6136-454a-8da3-b50bed5c606a_475x154.png 424w, https://substackcdn.com/image/fetch/$s_!-Smp!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0de5c5b6-6136-454a-8da3-b50bed5c606a_475x154.png 848w, https://substackcdn.com/image/fetch/$s_!-Smp!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0de5c5b6-6136-454a-8da3-b50bed5c606a_475x154.png 1272w, https://substackcdn.com/image/fetch/$s_!-Smp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0de5c5b6-6136-454a-8da3-b50bed5c606a_475x154.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h3><strong>The Email As a Pivot Point</strong></h3><p>As the username itself provided only superficial evidence, I dug more into the email address itself.</p><p>An active Google account (GMAIL) was found with a photo of two guys, covering their faces with COVID masks, one of them is wearing a hoodie with a code sample on it, and the second wears a hoodie with the logo &#8220;SurabayXploit&#8221;.</p><p>When searing this term, I found that <strong>Surabay(a)Xploit</strong> (often seen as <strong>SurabayaBlackhat / Surabaya Xploit / Barrabravaz</strong>) appears to be an <strong>Indonesian</strong> language <strong>hacking/defacement</strong> persona or small collective that publishes exploit code, web shells, and &#8220;toolbox&#8221; repositories (<strong>PHP shells</strong>, <strong>arbitrary-file-download exploits</strong>, short URL tools, <strong>DDoS</strong>/<strong>scan scripts</strong>) on GitHub and related sites - basically a regional exploit/defacement repo hub rather than a sophisticated APT.<br><br>Also, it came out that it is an annual event held in <strong>Surabaya</strong>, <strong>Indonesia</strong>, that aims to provide a platform for high school and vocational students to channel their interest in information technology.</p><p>The alternative name mentioned above, &#8220;<strong>SurabayaBlackHat</strong>&#8221;, is in the source code of the website (<strong>view-source:https://berkeleyschools.net/B4.html</strong>) that has been hacked, including other related references, such as &#8220;<strong>indonesianblackhat</strong>&#8221;, &#8220;<strong>Jakarta Anonymous,</strong>&#8221; and &#8220;<strong>Indonesia_Hacker</strong>&#8221;</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ciUo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00a0e742-b7c1-4d78-9570-61e97f45834d_439x88.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ciUo!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00a0e742-b7c1-4d78-9570-61e97f45834d_439x88.png 424w, https://substackcdn.com/image/fetch/$s_!ciUo!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00a0e742-b7c1-4d78-9570-61e97f45834d_439x88.png 848w, https://substackcdn.com/image/fetch/$s_!ciUo!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00a0e742-b7c1-4d78-9570-61e97f45834d_439x88.png 1272w, https://substackcdn.com/image/fetch/$s_!ciUo!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00a0e742-b7c1-4d78-9570-61e97f45834d_439x88.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ciUo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00a0e742-b7c1-4d78-9570-61e97f45834d_439x88.png" width="439" height="88" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/00a0e742-b7c1-4d78-9570-61e97f45834d_439x88.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:88,&quot;width&quot;:439,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:71078,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179044352?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00a0e742-b7c1-4d78-9570-61e97f45834d_439x88.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ciUo!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00a0e742-b7c1-4d78-9570-61e97f45834d_439x88.png 424w, https://substackcdn.com/image/fetch/$s_!ciUo!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00a0e742-b7c1-4d78-9570-61e97f45834d_439x88.png 848w, https://substackcdn.com/image/fetch/$s_!ciUo!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00a0e742-b7c1-4d78-9570-61e97f45834d_439x88.png 1272w, https://substackcdn.com/image/fetch/$s_!ciUo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00a0e742-b7c1-4d78-9570-61e97f45834d_439x88.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><div class="image-gallery-embed" data-attrs="{&quot;gallery&quot;:{&quot;images&quot;:[{&quot;type&quot;:&quot;image/png&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c81adb35-055c-42fa-8d1a-2c6603344e95_217x222.png&quot;},{&quot;type&quot;:&quot;image/png&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1788a4ca-2e82-416a-901e-d6283b5b5153_395x72.png&quot;}],&quot;caption&quot;:&quot;&quot;,&quot;alt&quot;:&quot;&quot;,&quot;staticGalleryImage&quot;:{&quot;type&quot;:&quot;image/png&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/40ad7a0d-31a4-4c2e-9285-6272164f996e_1456x720.png&quot;}},&quot;isEditorNode&quot;:true}"></div><p>When searching this term, a LinkedIn profile appeared, under the name &#8220;<strong>M.REIHAN FATAHILLAH</strong>&#8221;, A person from <strong>Surabaya</strong>, Jawa Timur, <strong>Indonesia, </strong>who claims to be an IT Security and Bug Hunting in Surabaya xploit, the only one that was found in this association.</p><p>As shown in his LinkedIn BIO, he &#8220;plays your code with xploit&#8221;, and he owns a Cyber &#8203;&#8203;Security community, namely <strong>SurabayaXploit</strong>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1byN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16e9e768-b1b6-409d-84c4-4f5d87b6f408_425x383.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1byN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16e9e768-b1b6-409d-84c4-4f5d87b6f408_425x383.png 424w, https://substackcdn.com/image/fetch/$s_!1byN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16e9e768-b1b6-409d-84c4-4f5d87b6f408_425x383.png 848w, https://substackcdn.com/image/fetch/$s_!1byN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16e9e768-b1b6-409d-84c4-4f5d87b6f408_425x383.png 1272w, https://substackcdn.com/image/fetch/$s_!1byN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16e9e768-b1b6-409d-84c4-4f5d87b6f408_425x383.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1byN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16e9e768-b1b6-409d-84c4-4f5d87b6f408_425x383.png" width="425" height="383" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/16e9e768-b1b6-409d-84c4-4f5d87b6f408_425x383.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:383,&quot;width&quot;:425,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:83681,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179044352?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16e9e768-b1b6-409d-84c4-4f5d87b6f408_425x383.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!1byN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16e9e768-b1b6-409d-84c4-4f5d87b6f408_425x383.png 424w, https://substackcdn.com/image/fetch/$s_!1byN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16e9e768-b1b6-409d-84c4-4f5d87b6f408_425x383.png 848w, https://substackcdn.com/image/fetch/$s_!1byN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16e9e768-b1b6-409d-84c4-4f5d87b6f408_425x383.png 1272w, https://substackcdn.com/image/fetch/$s_!1byN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16e9e768-b1b6-409d-84c4-4f5d87b6f408_425x383.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.darksignal.co/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[ANTIPODEAN – New Neo-Nazi Member Revealed ]]></title><description><![CDATA[Antipodean Group &#8211; Introduction]]></description><link>https://www.darksignal.co/p/antipodean-new-neo-nazi-member-revealed</link><guid isPermaLink="false">https://www.darksignal.co/p/antipodean-new-neo-nazi-member-revealed</guid><dc:creator><![CDATA[DarkSignal]]></dc:creator><pubDate>Sun, 16 Nov 2025 12:09:32 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!pQzb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cfed5cb-b26c-445d-93eb-a273d45f78cb_453x454.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!pQzb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cfed5cb-b26c-445d-93eb-a273d45f78cb_453x454.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!pQzb!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cfed5cb-b26c-445d-93eb-a273d45f78cb_453x454.png 424w, https://substackcdn.com/image/fetch/$s_!pQzb!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cfed5cb-b26c-445d-93eb-a273d45f78cb_453x454.png 848w, https://substackcdn.com/image/fetch/$s_!pQzb!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cfed5cb-b26c-445d-93eb-a273d45f78cb_453x454.png 1272w, https://substackcdn.com/image/fetch/$s_!pQzb!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cfed5cb-b26c-445d-93eb-a273d45f78cb_453x454.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!pQzb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cfed5cb-b26c-445d-93eb-a273d45f78cb_453x454.png" width="453" height="454" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5cfed5cb-b26c-445d-93eb-a273d45f78cb_453x454.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:454,&quot;width&quot;:453,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:227687,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179041502?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cfed5cb-b26c-445d-93eb-a273d45f78cb_453x454.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!pQzb!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cfed5cb-b26c-445d-93eb-a273d45f78cb_453x454.png 424w, https://substackcdn.com/image/fetch/$s_!pQzb!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cfed5cb-b26c-445d-93eb-a273d45f78cb_453x454.png 848w, https://substackcdn.com/image/fetch/$s_!pQzb!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cfed5cb-b26c-445d-93eb-a273d45f78cb_453x454.png 1272w, https://substackcdn.com/image/fetch/$s_!pQzb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cfed5cb-b26c-445d-93eb-a273d45f78cb_453x454.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><h3>Antipodean Group &#8211; Introduction</h3><p>Antipodean Resistance (Known as &#8220;AR&#8221;) is an Australian neo-Nazi extremist group that was first seen in October 2016. The name &#8220;Antipodean&#8221; refers to Australia&#8217;s geographic location (the Antipodes), underscoring the group&#8217;s aim to establish a National Socialist movement in Australia. <br>AR was founded by young white supremacists who organized via the now-defunct Iron March forum, a notorious international far-right networking site. <br><br>In early 2016, a small cluster of Iron March users discussed forming &#8220;a new group for younger NatSocs (national socialists), 14-25&#8221; that would <em>&#8220;</em>take the fight to the enemy<em>&#8221;</em>, even suggesting actions like attacking a synagogue to show they were serious. <br>By October 2016, the group had a name, a logo, and its own sub-forum on Iron March, where a founding member using the alias &#8220;Xav&#8221; declared AR&#8217;s bold catchphrase: &#8220;We&#8217;re the Hitlers you&#8217;ve been waiting for&#8221;,<em> </em>which still appears on the website.</p><p>Their ideology is a blend of white supremacism, antisemitism, homophobia, and ultra-nationalism. The group explicitly venerates Adolf Hitler and promotes National Socialism (Nazism) as its guiding doctrine. <br>AR&#8217;s propaganda and internal writings reveal a belief that white Australians are in an existential struggle against &#8220;enemies&#8221;, with Jews singled out as the ultimate nemesis. <br><br>In the Nazi worldview AR subscribes to, Jews are blamed for controlling governments, banks, and media, and accused of plotting a &#8220;white genocide&#8221; by means of immigration and multiculturalism. <br>AR members routinely refer to this antisemitic conspiracy theory in their rhetoric, portraying Jews as the primary target of their hatred. One AR poster even called to &#8220;Legalise the execution of Jews&#8221;, illustrating the group&#8217;s genocidal mindset.<br>Australian authorities consider AR a dangerous extremist entity who are willing to use extreme violence.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.darksignal.co/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h3>Known &#8220;AR&#8221; Symbols &amp; Aesthetics</h3><p>The group&#8217;s logo prominently features a Totenkopf (death&#8217;s head skull, as used by Hitler&#8217;s SS) wearing an Australian Akubra-style hat, set against a Black Sun design, with a swastika and laurel wreath included. <br><br>Members often display the swastika flag, AR&#8217;s own flag is blue and white with a black swastika, and they give the Nazi salute in photos. <br>The slogan &#8220;We&#8217;re the Hitlers you&#8217;ve been waiting for&#8221; encapsulates their self-image as a revived Hitler Youth-style vanguard in Australia.</p><p>AR primarily recruits young, white Australian men (teens to mid-20s), insisting on physical fitness and fanatic devotion, as a reference to the known movements of 1940 Germany. <br>The membership is secretive and relatively small, with chapters claimed in most major Australian cities despite an overall headcount likely only in the few members adopt pseudonyms and conceal their faces (often using skull masks or digital blur) in all published images to avoid identification.</p><h3>Known Affiliations</h3><p>Antipodean Resistance (AR) is actively connected with a few other groups, all well-known Neo-Nazi divisions with shared tactics and ideologies, most were classified as terror and violence extremist groups by world-wide authorities, and not for nothing.</p><ol><li><p>National Action [UK] - AR admired NA&#8217;s tactics and adopted similar militant neo-Nazi strategies.</p></li><li><p>Nordic Resistance Movement (NRM) [Scandinavia] - AR maintained direct communication and shared ideological alignment, including an interview with NRM&#8217;s Finnish branch.</p></li><li><p>Atomwaffen Division (AWD) [US] - AR and AWD maintained friendly relations, shared propaganda, and aligned in violent activities and ideology.</p></li><li><p>The Lads Society [Australia] - Many AR members transitioned to the Lads Society, and the groups became so intertwined that they are difficult to separate.</p></li><li><p>National Socialist Network (NSN) [Australia] - AR&#8217;s legacy continued in NSN after a merger with the Lads Society, with key AR figures joining NSN.</p></li></ol><h3>Known Cases of Violence By AR</h3><p>Over the years, Antipodean Resistance (AR) has been involved in different violent incidents and hate crimes. <br>From vandalized schools, universities, and public spaces with neo-Nazi propaganda, including swastikas and racist slogans, causing fear among Jewish, Asian, and LGBT communities between 2016 to 2019, to a violent confrontation with anti-fascist activists when they were caught putting up homophobic posters in Melbourne in 2017. <br><br>AR has also conducted ongoing combat training camps where recruits practiced martial arts and possibly firearms handling, preparing for physical conflict. <br>In 2019, AR expressed support for the Christchurch Mosque shootings and echoed the shooter&#8217;s views, though no direct involvement was confirmed.</p><h3>Known Members of AR</h3><p>Antipodean Resistance was founded by Tim Heibach (known as &#8220;Xav&#8221;) and Jacob Hersant. <br>Tim was the key organizer, shaped AR&#8217;s structure and militant ideology while Jacob, who is active from a young age, became a chief organizer, involved in defacing locations with AR propaganda and later recruiting for AR&#8217;s Victoria branch. <br><br>Other early contributors include &#8220;Kehlsteinhaus&#8221; and Nathaniel Anderson, who handled propaganda and graphic design. <br>The group operated as a decentralized youth network, using small, autonomous cells across Australia. <br><br>While there was no public leader, internal leadership was evident through those managing the website and training camps. In 2019, many AR members transitioned to the National Socialist Network (NSN) under Tom Sewell, who became a key figure in the broader neo-Nazi scene.</p><h3>Exposing New Member of AR</h3><p>Over the years, a few of the AR members were exposed, no one was identified as the owner of the official website &#8220;antipodean-resistance.com&#8221;.<br>So, I took the initiative and started to investigate. In this research, using OSINT techniques and methodologies of intelligence collection and verifications, I present the individual behind the official website of the organization, with cross-references that allegedly validates his interests in a way that frame him as indeed one of the individuals in AR.</p><h2>First, the domain</h2><p>Current WHOIS records aren&#8217;t the solution, as all are restricted for privacy, so I started to figure out &#8220;what general stuff&#8221; I know about the domain?</p><ul><li><p>It&#8217;s an official website of a Neo-Nazi fascist group based in Australia. The suspected individual must be Australian at least, 100% sure a white person, probably, and statistically male. That&#8217;s a start.</p></li><li><p>The official website of &#8220;antipodean-resistance&#8221; shares the same IP address with 5 other domains, no Cloudflare or any other protection usage, meaning the IP address I&#8217;m seeing, is indeed the IP address of the website. <br>All the websites are with the same clear agenda of white-supremacist and Neo-Nazism. IP Address is 23[.]184[.]48[.]187</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Nf_P!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8be3ee49-971d-44ae-927e-260ae70b8822_477x212.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Nf_P!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8be3ee49-971d-44ae-927e-260ae70b8822_477x212.png 424w, https://substackcdn.com/image/fetch/$s_!Nf_P!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8be3ee49-971d-44ae-927e-260ae70b8822_477x212.png 848w, https://substackcdn.com/image/fetch/$s_!Nf_P!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8be3ee49-971d-44ae-927e-260ae70b8822_477x212.png 1272w, https://substackcdn.com/image/fetch/$s_!Nf_P!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8be3ee49-971d-44ae-927e-260ae70b8822_477x212.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Nf_P!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8be3ee49-971d-44ae-927e-260ae70b8822_477x212.png" width="477" height="212" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8be3ee49-971d-44ae-927e-260ae70b8822_477x212.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:212,&quot;width&quot;:477,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:14358,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179041502?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8be3ee49-971d-44ae-927e-260ae70b8822_477x212.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Nf_P!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8be3ee49-971d-44ae-927e-260ae70b8822_477x212.png 424w, https://substackcdn.com/image/fetch/$s_!Nf_P!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8be3ee49-971d-44ae-927e-260ae70b8822_477x212.png 848w, https://substackcdn.com/image/fetch/$s_!Nf_P!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8be3ee49-971d-44ae-927e-260ae70b8822_477x212.png 1272w, https://substackcdn.com/image/fetch/$s_!Nf_P!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8be3ee49-971d-44ae-927e-260ae70b8822_477x212.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>[*] <strong>renegadetribune[.]com</strong> &#8594; </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!9WG5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24031515-8b6d-4028-8dae-2f62f7a90341_452x287.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9WG5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24031515-8b6d-4028-8dae-2f62f7a90341_452x287.png 424w, https://substackcdn.com/image/fetch/$s_!9WG5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24031515-8b6d-4028-8dae-2f62f7a90341_452x287.png 848w, https://substackcdn.com/image/fetch/$s_!9WG5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24031515-8b6d-4028-8dae-2f62f7a90341_452x287.png 1272w, https://substackcdn.com/image/fetch/$s_!9WG5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24031515-8b6d-4028-8dae-2f62f7a90341_452x287.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9WG5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24031515-8b6d-4028-8dae-2f62f7a90341_452x287.png" width="452" height="287" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/24031515-8b6d-4028-8dae-2f62f7a90341_452x287.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:287,&quot;width&quot;:452,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:147383,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179041502?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24031515-8b6d-4028-8dae-2f62f7a90341_452x287.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!9WG5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24031515-8b6d-4028-8dae-2f62f7a90341_452x287.png 424w, https://substackcdn.com/image/fetch/$s_!9WG5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24031515-8b6d-4028-8dae-2f62f7a90341_452x287.png 848w, https://substackcdn.com/image/fetch/$s_!9WG5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24031515-8b6d-4028-8dae-2f62f7a90341_452x287.png 1272w, https://substackcdn.com/image/fetch/$s_!9WG5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24031515-8b6d-4028-8dae-2f62f7a90341_452x287.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>[*] <strong>white-power[.]org</strong> &#8594; </p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xlZw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbead9add-557d-4439-8691-d6b9189a6b93_457x107.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xlZw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbead9add-557d-4439-8691-d6b9189a6b93_457x107.png 424w, https://substackcdn.com/image/fetch/$s_!xlZw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbead9add-557d-4439-8691-d6b9189a6b93_457x107.png 848w, https://substackcdn.com/image/fetch/$s_!xlZw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbead9add-557d-4439-8691-d6b9189a6b93_457x107.png 1272w, https://substackcdn.com/image/fetch/$s_!xlZw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbead9add-557d-4439-8691-d6b9189a6b93_457x107.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xlZw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbead9add-557d-4439-8691-d6b9189a6b93_457x107.png" width="457" height="107" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bead9add-557d-4439-8691-d6b9189a6b93_457x107.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:107,&quot;width&quot;:457,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:40122,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179041502?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbead9add-557d-4439-8691-d6b9189a6b93_457x107.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!xlZw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbead9add-557d-4439-8691-d6b9189a6b93_457x107.png 424w, https://substackcdn.com/image/fetch/$s_!xlZw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbead9add-557d-4439-8691-d6b9189a6b93_457x107.png 848w, https://substackcdn.com/image/fetch/$s_!xlZw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbead9add-557d-4439-8691-d6b9189a6b93_457x107.png 1272w, https://substackcdn.com/image/fetch/$s_!xlZw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbead9add-557d-4439-8691-d6b9189a6b93_457x107.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>[*] <strong>wearswar[.]com</strong> &#8594; </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!sTyo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec5e0cf4-741d-4abf-b85d-915012dc0361_458x290.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!sTyo!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec5e0cf4-741d-4abf-b85d-915012dc0361_458x290.png 424w, https://substackcdn.com/image/fetch/$s_!sTyo!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec5e0cf4-741d-4abf-b85d-915012dc0361_458x290.png 848w, https://substackcdn.com/image/fetch/$s_!sTyo!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec5e0cf4-741d-4abf-b85d-915012dc0361_458x290.png 1272w, https://substackcdn.com/image/fetch/$s_!sTyo!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec5e0cf4-741d-4abf-b85d-915012dc0361_458x290.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!sTyo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec5e0cf4-741d-4abf-b85d-915012dc0361_458x290.png" width="458" height="290" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ec5e0cf4-741d-4abf-b85d-915012dc0361_458x290.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:290,&quot;width&quot;:458,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:204058,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179041502?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec5e0cf4-741d-4abf-b85d-915012dc0361_458x290.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!sTyo!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec5e0cf4-741d-4abf-b85d-915012dc0361_458x290.png 424w, https://substackcdn.com/image/fetch/$s_!sTyo!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec5e0cf4-741d-4abf-b85d-915012dc0361_458x290.png 848w, https://substackcdn.com/image/fetch/$s_!sTyo!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec5e0cf4-741d-4abf-b85d-915012dc0361_458x290.png 1272w, https://substackcdn.com/image/fetch/$s_!sTyo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec5e0cf4-741d-4abf-b85d-915012dc0361_458x290.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>[*] <strong>nsdapao[.]org</strong> &#8594; </p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!G9H1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b3968cc-31dd-49a6-828b-88823bb86921_428x188.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!G9H1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b3968cc-31dd-49a6-828b-88823bb86921_428x188.png 424w, https://substackcdn.com/image/fetch/$s_!G9H1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b3968cc-31dd-49a6-828b-88823bb86921_428x188.png 848w, https://substackcdn.com/image/fetch/$s_!G9H1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b3968cc-31dd-49a6-828b-88823bb86921_428x188.png 1272w, https://substackcdn.com/image/fetch/$s_!G9H1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b3968cc-31dd-49a6-828b-88823bb86921_428x188.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!G9H1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b3968cc-31dd-49a6-828b-88823bb86921_428x188.png" width="428" height="188" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1b3968cc-31dd-49a6-828b-88823bb86921_428x188.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:188,&quot;width&quot;:428,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:51758,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179041502?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b3968cc-31dd-49a6-828b-88823bb86921_428x188.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!G9H1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b3968cc-31dd-49a6-828b-88823bb86921_428x188.png 424w, https://substackcdn.com/image/fetch/$s_!G9H1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b3968cc-31dd-49a6-828b-88823bb86921_428x188.png 848w, https://substackcdn.com/image/fetch/$s_!G9H1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b3968cc-31dd-49a6-828b-88823bb86921_428x188.png 1272w, https://substackcdn.com/image/fetch/$s_!G9H1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b3968cc-31dd-49a6-828b-88823bb86921_428x188.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>[*] <strong>nvu[.]info</strong> &#8594; </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Ejtf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc61aa697-f6d3-4c01-ac99-53b1a82d718e_428x346.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Ejtf!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc61aa697-f6d3-4c01-ac99-53b1a82d718e_428x346.png 424w, https://substackcdn.com/image/fetch/$s_!Ejtf!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc61aa697-f6d3-4c01-ac99-53b1a82d718e_428x346.png 848w, https://substackcdn.com/image/fetch/$s_!Ejtf!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc61aa697-f6d3-4c01-ac99-53b1a82d718e_428x346.png 1272w, https://substackcdn.com/image/fetch/$s_!Ejtf!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc61aa697-f6d3-4c01-ac99-53b1a82d718e_428x346.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Ejtf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc61aa697-f6d3-4c01-ac99-53b1a82d718e_428x346.png" width="428" height="346" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c61aa697-f6d3-4c01-ac99-53b1a82d718e_428x346.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:346,&quot;width&quot;:428,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:171817,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179041502?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc61aa697-f6d3-4c01-ac99-53b1a82d718e_428x346.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Ejtf!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc61aa697-f6d3-4c01-ac99-53b1a82d718e_428x346.png 424w, https://substackcdn.com/image/fetch/$s_!Ejtf!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc61aa697-f6d3-4c01-ac99-53b1a82d718e_428x346.png 848w, https://substackcdn.com/image/fetch/$s_!Ejtf!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc61aa697-f6d3-4c01-ac99-53b1a82d718e_428x346.png 1272w, https://substackcdn.com/image/fetch/$s_!Ejtf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc61aa697-f6d3-4c01-ac99-53b1a82d718e_428x346.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>There is a similar agenda against child abusers appears in the official website of &#8220;antipodean-resistance&#8221; and one of the other domains hosted with the same IP address, &#8220;nvu.info&#8221;. That is a pattern.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-4mj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdff9ff91-a0b2-4fcf-bc06-a74946947a39_515x439.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-4mj!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdff9ff91-a0b2-4fcf-bc06-a74946947a39_515x439.png 424w, https://substackcdn.com/image/fetch/$s_!-4mj!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdff9ff91-a0b2-4fcf-bc06-a74946947a39_515x439.png 848w, https://substackcdn.com/image/fetch/$s_!-4mj!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdff9ff91-a0b2-4fcf-bc06-a74946947a39_515x439.png 1272w, https://substackcdn.com/image/fetch/$s_!-4mj!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdff9ff91-a0b2-4fcf-bc06-a74946947a39_515x439.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-4mj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdff9ff91-a0b2-4fcf-bc06-a74946947a39_515x439.png" width="515" height="439" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dff9ff91-a0b2-4fcf-bc06-a74946947a39_515x439.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:439,&quot;width&quot;:515,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:351815,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179041502?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdff9ff91-a0b2-4fcf-bc06-a74946947a39_515x439.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-4mj!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdff9ff91-a0b2-4fcf-bc06-a74946947a39_515x439.png 424w, https://substackcdn.com/image/fetch/$s_!-4mj!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdff9ff91-a0b2-4fcf-bc06-a74946947a39_515x439.png 848w, https://substackcdn.com/image/fetch/$s_!-4mj!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdff9ff91-a0b2-4fcf-bc06-a74946947a39_515x439.png 1272w, https://substackcdn.com/image/fetch/$s_!-4mj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdff9ff91-a0b2-4fcf-bc06-a74946947a39_515x439.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!CUhp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffcf5efa-580e-40fb-b546-052fb06f4b33_520x358.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!CUhp!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffcf5efa-580e-40fb-b546-052fb06f4b33_520x358.png 424w, https://substackcdn.com/image/fetch/$s_!CUhp!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffcf5efa-580e-40fb-b546-052fb06f4b33_520x358.png 848w, https://substackcdn.com/image/fetch/$s_!CUhp!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffcf5efa-580e-40fb-b546-052fb06f4b33_520x358.png 1272w, https://substackcdn.com/image/fetch/$s_!CUhp!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffcf5efa-580e-40fb-b546-052fb06f4b33_520x358.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!CUhp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffcf5efa-580e-40fb-b546-052fb06f4b33_520x358.png" width="520" height="358" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ffcf5efa-580e-40fb-b546-052fb06f4b33_520x358.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:358,&quot;width&quot;:520,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:95446,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179041502?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffcf5efa-580e-40fb-b546-052fb06f4b33_520x358.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!CUhp!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffcf5efa-580e-40fb-b546-052fb06f4b33_520x358.png 424w, https://substackcdn.com/image/fetch/$s_!CUhp!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffcf5efa-580e-40fb-b546-052fb06f4b33_520x358.png 848w, https://substackcdn.com/image/fetch/$s_!CUhp!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffcf5efa-580e-40fb-b546-052fb06f4b33_520x358.png 1272w, https://substackcdn.com/image/fetch/$s_!CUhp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffcf5efa-580e-40fb-b546-052fb06f4b33_520x358.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>When Past and Present Come Together</h3><p>Since current WHOIS records aren&#8217;t yielding results, let&#8217;s check past records.<br>Though few registrations have been made within this domain, we do know that AR was established at the end of 2016, so the focus should be around the one or two years afterwards.</p><p>99% of the data wasn&#8217;t good enough, until I found one specific result that contained an email address, a full name, phone number ,and a country - Australia. Bingo!</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Ao-g!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d9dea30-b5d4-41e9-ae81-aa6ea9081add_798x80.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Ao-g!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d9dea30-b5d4-41e9-ae81-aa6ea9081add_798x80.png 424w, https://substackcdn.com/image/fetch/$s_!Ao-g!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d9dea30-b5d4-41e9-ae81-aa6ea9081add_798x80.png 848w, https://substackcdn.com/image/fetch/$s_!Ao-g!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d9dea30-b5d4-41e9-ae81-aa6ea9081add_798x80.png 1272w, https://substackcdn.com/image/fetch/$s_!Ao-g!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d9dea30-b5d4-41e9-ae81-aa6ea9081add_798x80.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Ao-g!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d9dea30-b5d4-41e9-ae81-aa6ea9081add_798x80.png" width="798" height="80" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7d9dea30-b5d4-41e9-ae81-aa6ea9081add_798x80.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:80,&quot;width&quot;:798,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:16904,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179041502?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d9dea30-b5d4-41e9-ae81-aa6ea9081add_798x80.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Ao-g!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d9dea30-b5d4-41e9-ae81-aa6ea9081add_798x80.png 424w, https://substackcdn.com/image/fetch/$s_!Ao-g!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d9dea30-b5d4-41e9-ae81-aa6ea9081add_798x80.png 848w, https://substackcdn.com/image/fetch/$s_!Ao-g!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d9dea30-b5d4-41e9-ae81-aa6ea9081add_798x80.png 1272w, https://substackcdn.com/image/fetch/$s_!Ao-g!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d9dea30-b5d4-41e9-ae81-aa6ea9081add_798x80.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>The email address belongs to a person named Paul Kimbell, an Australian citizen, white male, just as assumption.<br>A phone number also found, with the country code of Australia, belongs to Paul as well.</p><h3>Connecting The Dots</h3><ul><li><p> Australianlibertyalliance[.]info: website for the Australian Liberty Alliance, a minor right-wing to far-right political party in Australia that was briefly known as the &#8220;Yellow Vest Australia&#8221;.</p></li><li><p>Sustainabletimbertasmania[.]info: a Tasmanian Government Business Enterprise responsible for sustainably managing public production forests. Paul is from Geilston Bay, Tasmania, Australia.</p></li><li><p>Tarkineaction[.]org: a website dedicated to supporting those who want action against the destruction of Takayna (Australia&#8217;s largest cool-temperate rainforest, located in northwest Tasmania). Australia's rainforests are a known secret training camp for members of Antipodean Resistance.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!r1fj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7020592e-07ba-4a57-8f76-4349e22bf64d_788x140.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!r1fj!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7020592e-07ba-4a57-8f76-4349e22bf64d_788x140.png 424w, https://substackcdn.com/image/fetch/$s_!r1fj!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7020592e-07ba-4a57-8f76-4349e22bf64d_788x140.png 848w, https://substackcdn.com/image/fetch/$s_!r1fj!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7020592e-07ba-4a57-8f76-4349e22bf64d_788x140.png 1272w, https://substackcdn.com/image/fetch/$s_!r1fj!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7020592e-07ba-4a57-8f76-4349e22bf64d_788x140.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!r1fj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7020592e-07ba-4a57-8f76-4349e22bf64d_788x140.png" width="788" height="140" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7020592e-07ba-4a57-8f76-4349e22bf64d_788x140.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:140,&quot;width&quot;:788,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:45544,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179041502?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7020592e-07ba-4a57-8f76-4349e22bf64d_788x140.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!r1fj!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7020592e-07ba-4a57-8f76-4349e22bf64d_788x140.png 424w, https://substackcdn.com/image/fetch/$s_!r1fj!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7020592e-07ba-4a57-8f76-4349e22bf64d_788x140.png 848w, https://substackcdn.com/image/fetch/$s_!r1fj!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7020592e-07ba-4a57-8f76-4349e22bf64d_788x140.png 1272w, https://substackcdn.com/image/fetch/$s_!r1fj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7020592e-07ba-4a57-8f76-4349e22bf64d_788x140.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>When viewing Paul associated profiles, some of them, for example his Flickr account, backed the claim about his agenda of forests saving, exactly as the shown agenda in some of the domains he registered and as pictures shown in the official website of AR, showing Australian forests and the squad training camps.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!k0ay!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4a182a0-1a3b-42b6-9c4c-f75a5bd1c5a6_602x166.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!k0ay!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4a182a0-1a3b-42b6-9c4c-f75a5bd1c5a6_602x166.png 424w, https://substackcdn.com/image/fetch/$s_!k0ay!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4a182a0-1a3b-42b6-9c4c-f75a5bd1c5a6_602x166.png 848w, https://substackcdn.com/image/fetch/$s_!k0ay!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4a182a0-1a3b-42b6-9c4c-f75a5bd1c5a6_602x166.png 1272w, https://substackcdn.com/image/fetch/$s_!k0ay!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4a182a0-1a3b-42b6-9c4c-f75a5bd1c5a6_602x166.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!k0ay!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4a182a0-1a3b-42b6-9c4c-f75a5bd1c5a6_602x166.png" width="602" height="166" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f4a182a0-1a3b-42b6-9c4c-f75a5bd1c5a6_602x166.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:166,&quot;width&quot;:602,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:121819,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179041502?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4a182a0-1a3b-42b6-9c4c-f75a5bd1c5a6_602x166.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!k0ay!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4a182a0-1a3b-42b6-9c4c-f75a5bd1c5a6_602x166.png 424w, https://substackcdn.com/image/fetch/$s_!k0ay!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4a182a0-1a3b-42b6-9c4c-f75a5bd1c5a6_602x166.png 848w, https://substackcdn.com/image/fetch/$s_!k0ay!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4a182a0-1a3b-42b6-9c4c-f75a5bd1c5a6_602x166.png 1272w, https://substackcdn.com/image/fetch/$s_!k0ay!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4a182a0-1a3b-42b6-9c4c-f75a5bd1c5a6_602x166.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Cowe!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e998ae1-b27f-4822-bbf1-6477e81f3bca_602x280.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Cowe!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e998ae1-b27f-4822-bbf1-6477e81f3bca_602x280.png 424w, https://substackcdn.com/image/fetch/$s_!Cowe!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e998ae1-b27f-4822-bbf1-6477e81f3bca_602x280.png 848w, https://substackcdn.com/image/fetch/$s_!Cowe!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e998ae1-b27f-4822-bbf1-6477e81f3bca_602x280.png 1272w, https://substackcdn.com/image/fetch/$s_!Cowe!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e998ae1-b27f-4822-bbf1-6477e81f3bca_602x280.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Cowe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e998ae1-b27f-4822-bbf1-6477e81f3bca_602x280.png" width="602" height="280" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4e998ae1-b27f-4822-bbf1-6477e81f3bca_602x280.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:280,&quot;width&quot;:602,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:272993,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179041502?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e998ae1-b27f-4822-bbf1-6477e81f3bca_602x280.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Cowe!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e998ae1-b27f-4822-bbf1-6477e81f3bca_602x280.png 424w, https://substackcdn.com/image/fetch/$s_!Cowe!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e998ae1-b27f-4822-bbf1-6477e81f3bca_602x280.png 848w, https://substackcdn.com/image/fetch/$s_!Cowe!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e998ae1-b27f-4822-bbf1-6477e81f3bca_602x280.png 1272w, https://substackcdn.com/image/fetch/$s_!Cowe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e998ae1-b27f-4822-bbf1-6477e81f3bca_602x280.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In the picture: Paul&#8217;s Flickr account, with the agenda of defending forests, exactly as the agenda of the domain he registered.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!d0bi!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F526b53ed-4180-4e44-a251-37fbd557ddbe_276x181.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!d0bi!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F526b53ed-4180-4e44-a251-37fbd557ddbe_276x181.png 424w, https://substackcdn.com/image/fetch/$s_!d0bi!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F526b53ed-4180-4e44-a251-37fbd557ddbe_276x181.png 848w, https://substackcdn.com/image/fetch/$s_!d0bi!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F526b53ed-4180-4e44-a251-37fbd557ddbe_276x181.png 1272w, https://substackcdn.com/image/fetch/$s_!d0bi!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F526b53ed-4180-4e44-a251-37fbd557ddbe_276x181.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!d0bi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F526b53ed-4180-4e44-a251-37fbd557ddbe_276x181.png" width="276" height="181" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/526b53ed-4180-4e44-a251-37fbd557ddbe_276x181.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:181,&quot;width&quot;:276,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:94425,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179041502?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F526b53ed-4180-4e44-a251-37fbd557ddbe_276x181.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!d0bi!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F526b53ed-4180-4e44-a251-37fbd557ddbe_276x181.png 424w, https://substackcdn.com/image/fetch/$s_!d0bi!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F526b53ed-4180-4e44-a251-37fbd557ddbe_276x181.png 848w, https://substackcdn.com/image/fetch/$s_!d0bi!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F526b53ed-4180-4e44-a251-37fbd557ddbe_276x181.png 1272w, https://substackcdn.com/image/fetch/$s_!d0bi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F526b53ed-4180-4e44-a251-37fbd557ddbe_276x181.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Weth!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F145de841-c72d-4af9-84bf-c65bd04b3ede_322x131.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Weth!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F145de841-c72d-4af9-84bf-c65bd04b3ede_322x131.png 424w, https://substackcdn.com/image/fetch/$s_!Weth!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F145de841-c72d-4af9-84bf-c65bd04b3ede_322x131.png 848w, https://substackcdn.com/image/fetch/$s_!Weth!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F145de841-c72d-4af9-84bf-c65bd04b3ede_322x131.png 1272w, https://substackcdn.com/image/fetch/$s_!Weth!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F145de841-c72d-4af9-84bf-c65bd04b3ede_322x131.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Weth!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F145de841-c72d-4af9-84bf-c65bd04b3ede_322x131.png" width="322" height="131" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/145de841-c72d-4af9-84bf-c65bd04b3ede_322x131.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:131,&quot;width&quot;:322,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:133100,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179041502?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F145de841-c72d-4af9-84bf-c65bd04b3ede_322x131.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Weth!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F145de841-c72d-4af9-84bf-c65bd04b3ede_322x131.png 424w, https://substackcdn.com/image/fetch/$s_!Weth!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F145de841-c72d-4af9-84bf-c65bd04b3ede_322x131.png 848w, https://substackcdn.com/image/fetch/$s_!Weth!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F145de841-c72d-4af9-84bf-c65bd04b3ede_322x131.png 1272w, https://substackcdn.com/image/fetch/$s_!Weth!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F145de841-c72d-4af9-84bf-c65bd04b3ede_322x131.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p><br>In the picture: Pictures used on the official website of AR, containing known forests in Australia</p></li></ul><h3>Investigation Continues </h3><p>The phone number that was found in association with Paul and the official domain of AR led to a Facebook profile called &#8220;Aves Animalia&#8221;, supposedly with almost no data, but there are two likes by this account.<br>The first is for a Facebook page called &#8220;Radical Art In Nature&#8221;, and the second for another Facebook page called &#8220;Graffiti Research Lab&#8221;, both of them claims of Graffiti as a mean to an end, exactly as AR does in now days for delivering a message.<br>Also, another interesting fact, one of the friends of the Facebook page &#8220;Aves Animalia&#8221; is Paul himself.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Y6Fa!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffd3038b-c965-42eb-b5e5-0e9dadff421e_258x245.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Y6Fa!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffd3038b-c965-42eb-b5e5-0e9dadff421e_258x245.png 424w, https://substackcdn.com/image/fetch/$s_!Y6Fa!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffd3038b-c965-42eb-b5e5-0e9dadff421e_258x245.png 848w, https://substackcdn.com/image/fetch/$s_!Y6Fa!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffd3038b-c965-42eb-b5e5-0e9dadff421e_258x245.png 1272w, https://substackcdn.com/image/fetch/$s_!Y6Fa!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffd3038b-c965-42eb-b5e5-0e9dadff421e_258x245.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Y6Fa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffd3038b-c965-42eb-b5e5-0e9dadff421e_258x245.png" width="258" height="245" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ffd3038b-c965-42eb-b5e5-0e9dadff421e_258x245.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:245,&quot;width&quot;:258,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:26541,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179041502?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffd3038b-c965-42eb-b5e5-0e9dadff421e_258x245.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Y6Fa!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffd3038b-c965-42eb-b5e5-0e9dadff421e_258x245.png 424w, https://substackcdn.com/image/fetch/$s_!Y6Fa!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffd3038b-c965-42eb-b5e5-0e9dadff421e_258x245.png 848w, https://substackcdn.com/image/fetch/$s_!Y6Fa!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffd3038b-c965-42eb-b5e5-0e9dadff421e_258x245.png 1272w, https://substackcdn.com/image/fetch/$s_!Y6Fa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffd3038b-c965-42eb-b5e5-0e9dadff421e_258x245.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5tQm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb99d0d2-8d90-466c-96b1-29717f9baabc_332x242.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5tQm!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb99d0d2-8d90-466c-96b1-29717f9baabc_332x242.png 424w, https://substackcdn.com/image/fetch/$s_!5tQm!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb99d0d2-8d90-466c-96b1-29717f9baabc_332x242.png 848w, https://substackcdn.com/image/fetch/$s_!5tQm!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb99d0d2-8d90-466c-96b1-29717f9baabc_332x242.png 1272w, https://substackcdn.com/image/fetch/$s_!5tQm!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb99d0d2-8d90-466c-96b1-29717f9baabc_332x242.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5tQm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb99d0d2-8d90-466c-96b1-29717f9baabc_332x242.png" width="332" height="242" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fb99d0d2-8d90-466c-96b1-29717f9baabc_332x242.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:242,&quot;width&quot;:332,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:32035,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179041502?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb99d0d2-8d90-466c-96b1-29717f9baabc_332x242.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!5tQm!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb99d0d2-8d90-466c-96b1-29717f9baabc_332x242.png 424w, https://substackcdn.com/image/fetch/$s_!5tQm!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb99d0d2-8d90-466c-96b1-29717f9baabc_332x242.png 848w, https://substackcdn.com/image/fetch/$s_!5tQm!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb99d0d2-8d90-466c-96b1-29717f9baabc_332x242.png 1272w, https://substackcdn.com/image/fetch/$s_!5tQm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb99d0d2-8d90-466c-96b1-29717f9baabc_332x242.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In the picture: Aves Animalia Facebook page, directly associated with the phone number found in the WHOIS records</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ihPk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F359b250f-053b-411a-a5ba-e34e383696dd_602x113.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ihPk!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F359b250f-053b-411a-a5ba-e34e383696dd_602x113.png 424w, https://substackcdn.com/image/fetch/$s_!ihPk!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F359b250f-053b-411a-a5ba-e34e383696dd_602x113.png 848w, https://substackcdn.com/image/fetch/$s_!ihPk!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F359b250f-053b-411a-a5ba-e34e383696dd_602x113.png 1272w, https://substackcdn.com/image/fetch/$s_!ihPk!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F359b250f-053b-411a-a5ba-e34e383696dd_602x113.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ihPk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F359b250f-053b-411a-a5ba-e34e383696dd_602x113.png" width="602" height="113" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/359b250f-053b-411a-a5ba-e34e383696dd_602x113.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:113,&quot;width&quot;:602,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:56121,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179041502?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F359b250f-053b-411a-a5ba-e34e383696dd_602x113.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ihPk!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F359b250f-053b-411a-a5ba-e34e383696dd_602x113.png 424w, https://substackcdn.com/image/fetch/$s_!ihPk!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F359b250f-053b-411a-a5ba-e34e383696dd_602x113.png 848w, https://substackcdn.com/image/fetch/$s_!ihPk!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F359b250f-053b-411a-a5ba-e34e383696dd_602x113.png 1272w, https://substackcdn.com/image/fetch/$s_!ihPk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F359b250f-053b-411a-a5ba-e34e383696dd_602x113.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!o9o5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b3cbc3c-e08a-4b0b-979c-d97967d49a1e_488x264.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!o9o5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b3cbc3c-e08a-4b0b-979c-d97967d49a1e_488x264.png 424w, https://substackcdn.com/image/fetch/$s_!o9o5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b3cbc3c-e08a-4b0b-979c-d97967d49a1e_488x264.png 848w, https://substackcdn.com/image/fetch/$s_!o9o5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b3cbc3c-e08a-4b0b-979c-d97967d49a1e_488x264.png 1272w, https://substackcdn.com/image/fetch/$s_!o9o5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b3cbc3c-e08a-4b0b-979c-d97967d49a1e_488x264.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!o9o5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b3cbc3c-e08a-4b0b-979c-d97967d49a1e_488x264.png" width="488" height="264" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5b3cbc3c-e08a-4b0b-979c-d97967d49a1e_488x264.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:264,&quot;width&quot;:488,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:101750,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179041502?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b3cbc3c-e08a-4b0b-979c-d97967d49a1e_488x264.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!o9o5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b3cbc3c-e08a-4b0b-979c-d97967d49a1e_488x264.png 424w, https://substackcdn.com/image/fetch/$s_!o9o5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b3cbc3c-e08a-4b0b-979c-d97967d49a1e_488x264.png 848w, https://substackcdn.com/image/fetch/$s_!o9o5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b3cbc3c-e08a-4b0b-979c-d97967d49a1e_488x264.png 1272w, https://substackcdn.com/image/fetch/$s_!o9o5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b3cbc3c-e08a-4b0b-979c-d97967d49a1e_488x264.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>A Complete Intelligence Profile</h3><p>Profiling the person behind the website reveals contact methods and his social accounts, a thing that may assist to the authorities and other intelligence agencies to engage with him when needed.</p><p>For this purpose and to maintain his privacy, all PIIs (personal identification information) and associated online accounts are blurred.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!R5Tk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa32369dd-5dfa-44d4-a8eb-0f6d7cff5157_500x709.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!R5Tk!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa32369dd-5dfa-44d4-a8eb-0f6d7cff5157_500x709.png 424w, https://substackcdn.com/image/fetch/$s_!R5Tk!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa32369dd-5dfa-44d4-a8eb-0f6d7cff5157_500x709.png 848w, https://substackcdn.com/image/fetch/$s_!R5Tk!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa32369dd-5dfa-44d4-a8eb-0f6d7cff5157_500x709.png 1272w, https://substackcdn.com/image/fetch/$s_!R5Tk!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa32369dd-5dfa-44d4-a8eb-0f6d7cff5157_500x709.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!R5Tk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa32369dd-5dfa-44d4-a8eb-0f6d7cff5157_500x709.png" width="500" height="709" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a32369dd-5dfa-44d4-a8eb-0f6d7cff5157_500x709.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:709,&quot;width&quot;:500,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:245385,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179041502?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa32369dd-5dfa-44d4-a8eb-0f6d7cff5157_500x709.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!R5Tk!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa32369dd-5dfa-44d4-a8eb-0f6d7cff5157_500x709.png 424w, https://substackcdn.com/image/fetch/$s_!R5Tk!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa32369dd-5dfa-44d4-a8eb-0f6d7cff5157_500x709.png 848w, https://substackcdn.com/image/fetch/$s_!R5Tk!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa32369dd-5dfa-44d4-a8eb-0f6d7cff5157_500x709.png 1272w, https://substackcdn.com/image/fetch/$s_!R5Tk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa32369dd-5dfa-44d4-a8eb-0f6d7cff5157_500x709.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.darksignal.co/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[ByteToBreach - A Threat Actor Revealed]]></title><description><![CDATA[A Threat Actor Revealed]]></description><link>https://www.darksignal.co/p/bytetobreach-a-threat-actor-revealed</link><guid isPermaLink="false">https://www.darksignal.co/p/bytetobreach-a-threat-actor-revealed</guid><dc:creator><![CDATA[DarkSignal]]></dc:creator><pubDate>Sun, 16 Nov 2025 10:42:39 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!yQua!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda25de0b-81a6-455b-bbaa-1b3b598109c4_850x900.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!yQua!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda25de0b-81a6-455b-bbaa-1b3b598109c4_850x900.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!yQua!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda25de0b-81a6-455b-bbaa-1b3b598109c4_850x900.png 424w, https://substackcdn.com/image/fetch/$s_!yQua!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda25de0b-81a6-455b-bbaa-1b3b598109c4_850x900.png 848w, https://substackcdn.com/image/fetch/$s_!yQua!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda25de0b-81a6-455b-bbaa-1b3b598109c4_850x900.png 1272w, https://substackcdn.com/image/fetch/$s_!yQua!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda25de0b-81a6-455b-bbaa-1b3b598109c4_850x900.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!yQua!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda25de0b-81a6-455b-bbaa-1b3b598109c4_850x900.png" width="728" height="770.8235294117648" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/da25de0b-81a6-455b-bbaa-1b3b598109c4_850x900.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;normal&quot;,&quot;height&quot;:900,&quot;width&quot;:850,&quot;resizeWidth&quot;:728,&quot;bytes&quot;:1737782,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179039157?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe913433d-974a-4feb-b4b2-1ba5ecb9ae96_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:&quot;center&quot;,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!yQua!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda25de0b-81a6-455b-bbaa-1b3b598109c4_850x900.png 424w, https://substackcdn.com/image/fetch/$s_!yQua!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda25de0b-81a6-455b-bbaa-1b3b598109c4_850x900.png 848w, https://substackcdn.com/image/fetch/$s_!yQua!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda25de0b-81a6-455b-bbaa-1b3b598109c4_850x900.png 1272w, https://substackcdn.com/image/fetch/$s_!yQua!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda25de0b-81a6-455b-bbaa-1b3b598109c4_850x900.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><h3>A Threat Actor Revealed</h3><p>ByteToBreach is a well-known cyber threat actor active, known primarily for carrying out opportunistic but high-impact breaches against financial institutions, airlines, and corporations across multiple regions. His attacks have been documented against Uzbekistan Airways, where he leaked passenger data, including records of U.S. government employees; Seychelles Commercial Bank, where he exfiltrated customer banking data and attempted extortion by decrypting files, and BTS Group Holdings. In this major Thai conglomerate, they stole internal LMS (Learning Management System) data and advertised ongoing network access. Additional chatter links them to breaches of academic institutions in the United States, though attribution in those cases remains less certain.</p><p>The following research sheds light on this individual and reveals connections between the threat actor and the persona behind it.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.darksignal.co/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>*The personal details (PII &amp; usernames) are blurred for security and privacy*.</p><h3>So, Who Are You, ByteToBreach?</h3><p>A recent post in a known hacking forum by him offers reverse shell access to 2 huge corporations (Nokia &amp; Atos), while he publishes contact methods to reach him.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!dA4T!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41e71b09-42eb-4a71-945e-69cad4a29eaa_782x194.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!dA4T!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41e71b09-42eb-4a71-945e-69cad4a29eaa_782x194.png 424w, https://substackcdn.com/image/fetch/$s_!dA4T!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41e71b09-42eb-4a71-945e-69cad4a29eaa_782x194.png 848w, https://substackcdn.com/image/fetch/$s_!dA4T!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41e71b09-42eb-4a71-945e-69cad4a29eaa_782x194.png 1272w, https://substackcdn.com/image/fetch/$s_!dA4T!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41e71b09-42eb-4a71-945e-69cad4a29eaa_782x194.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!dA4T!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41e71b09-42eb-4a71-945e-69cad4a29eaa_782x194.png" width="782" height="194" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/41e71b09-42eb-4a71-945e-69cad4a29eaa_782x194.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:194,&quot;width&quot;:782,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:62387,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179039157?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41e71b09-42eb-4a71-945e-69cad4a29eaa_782x194.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!dA4T!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41e71b09-42eb-4a71-945e-69cad4a29eaa_782x194.png 424w, https://substackcdn.com/image/fetch/$s_!dA4T!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41e71b09-42eb-4a71-945e-69cad4a29eaa_782x194.png 848w, https://substackcdn.com/image/fetch/$s_!dA4T!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41e71b09-42eb-4a71-945e-69cad4a29eaa_782x194.png 1272w, https://substackcdn.com/image/fetch/$s_!dA4T!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41e71b09-42eb-4a71-945e-69cad4a29eaa_782x194.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><ul><li><p>Session: 05c2db4775cb46350f16814dfe3bfa856664f315585653e4c368af08ce50b0Signalc31b</p></li><li><p>Signal: Bytetobreach</p></li><li><p>Email: Bytetobreach@tuta.com</p></li></ul><p>All are very secure and known to be in use by cybercriminals, terrorists, investigators, and super privacy-oriented individuals.</p><h3><strong>The Investigation Starts</strong></h3><p>The user &#8220;Bytetobreach&#8221; leads to an active Telegram user with this alias. By search manipulations, the current username revealed 2 other usernames: <strong>CvHNWwEG</strong>, and <strong>i&#951;e&#1109;slop&#1077;z</strong> (the &#8216;&#951;&#8217; is a Latino/Greek letter).</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Qi6t!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f162881-e632-4e22-afae-b77ee99857d2_320x170.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Qi6t!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f162881-e632-4e22-afae-b77ee99857d2_320x170.png 424w, https://substackcdn.com/image/fetch/$s_!Qi6t!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f162881-e632-4e22-afae-b77ee99857d2_320x170.png 848w, https://substackcdn.com/image/fetch/$s_!Qi6t!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f162881-e632-4e22-afae-b77ee99857d2_320x170.png 1272w, https://substackcdn.com/image/fetch/$s_!Qi6t!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f162881-e632-4e22-afae-b77ee99857d2_320x170.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Qi6t!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f162881-e632-4e22-afae-b77ee99857d2_320x170.png" width="320" height="170" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1f162881-e632-4e22-afae-b77ee99857d2_320x170.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:170,&quot;width&quot;:320,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:35309,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179039157?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f162881-e632-4e22-afae-b77ee99857d2_320x170.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Qi6t!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f162881-e632-4e22-afae-b77ee99857d2_320x170.png 424w, https://substackcdn.com/image/fetch/$s_!Qi6t!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f162881-e632-4e22-afae-b77ee99857d2_320x170.png 848w, https://substackcdn.com/image/fetch/$s_!Qi6t!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f162881-e632-4e22-afae-b77ee99857d2_320x170.png 1272w, https://substackcdn.com/image/fetch/$s_!Qi6t!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f162881-e632-4e22-afae-b77ee99857d2_320x170.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>The user Bytetobreach leads to an active Instagram account, which publishes evidence of hacking and breaches he performs (SQL Injection, ransomware, and phishing scams, including live recording from the victim&#8217;s screen).</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Ee3y!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30f0373b-8da1-4205-91a3-56cccc1c0508_247x229.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Ee3y!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30f0373b-8da1-4205-91a3-56cccc1c0508_247x229.png 424w, https://substackcdn.com/image/fetch/$s_!Ee3y!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30f0373b-8da1-4205-91a3-56cccc1c0508_247x229.png 848w, https://substackcdn.com/image/fetch/$s_!Ee3y!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30f0373b-8da1-4205-91a3-56cccc1c0508_247x229.png 1272w, https://substackcdn.com/image/fetch/$s_!Ee3y!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30f0373b-8da1-4205-91a3-56cccc1c0508_247x229.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Ee3y!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30f0373b-8da1-4205-91a3-56cccc1c0508_247x229.png" width="247" height="229" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/30f0373b-8da1-4205-91a3-56cccc1c0508_247x229.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:229,&quot;width&quot;:247,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:108480,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179039157?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30f0373b-8da1-4205-91a3-56cccc1c0508_247x229.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Ee3y!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30f0373b-8da1-4205-91a3-56cccc1c0508_247x229.png 424w, https://substackcdn.com/image/fetch/$s_!Ee3y!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30f0373b-8da1-4205-91a3-56cccc1c0508_247x229.png 848w, https://substackcdn.com/image/fetch/$s_!Ee3y!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30f0373b-8da1-4205-91a3-56cccc1c0508_247x229.png 1272w, https://substackcdn.com/image/fetch/$s_!Ee3y!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30f0373b-8da1-4205-91a3-56cccc1c0508_247x229.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!x2h1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb127e6f6-f608-4961-8cce-b4b48019c74f_131x227.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!x2h1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb127e6f6-f608-4961-8cce-b4b48019c74f_131x227.png 424w, https://substackcdn.com/image/fetch/$s_!x2h1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb127e6f6-f608-4961-8cce-b4b48019c74f_131x227.png 848w, https://substackcdn.com/image/fetch/$s_!x2h1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb127e6f6-f608-4961-8cce-b4b48019c74f_131x227.png 1272w, https://substackcdn.com/image/fetch/$s_!x2h1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb127e6f6-f608-4961-8cce-b4b48019c74f_131x227.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!x2h1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb127e6f6-f608-4961-8cce-b4b48019c74f_131x227.png" width="131" height="227" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b127e6f6-f608-4961-8cce-b4b48019c74f_131x227.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:227,&quot;width&quot;:131,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:35176,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179039157?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb127e6f6-f608-4961-8cce-b4b48019c74f_131x227.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!x2h1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb127e6f6-f608-4961-8cce-b4b48019c74f_131x227.png 424w, https://substackcdn.com/image/fetch/$s_!x2h1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb127e6f6-f608-4961-8cce-b4b48019c74f_131x227.png 848w, https://substackcdn.com/image/fetch/$s_!x2h1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb127e6f6-f608-4961-8cce-b4b48019c74f_131x227.png 1272w, https://substackcdn.com/image/fetch/$s_!x2h1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb127e6f6-f608-4961-8cce-b4b48019c74f_131x227.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Z4JJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35c29b0e-6e9d-45b8-8ec9-a0db63190de9_278x314.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Z4JJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35c29b0e-6e9d-45b8-8ec9-a0db63190de9_278x314.png 424w, https://substackcdn.com/image/fetch/$s_!Z4JJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35c29b0e-6e9d-45b8-8ec9-a0db63190de9_278x314.png 848w, https://substackcdn.com/image/fetch/$s_!Z4JJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35c29b0e-6e9d-45b8-8ec9-a0db63190de9_278x314.png 1272w, https://substackcdn.com/image/fetch/$s_!Z4JJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35c29b0e-6e9d-45b8-8ec9-a0db63190de9_278x314.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Z4JJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35c29b0e-6e9d-45b8-8ec9-a0db63190de9_278x314.png" width="278" height="314" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/35c29b0e-6e9d-45b8-8ec9-a0db63190de9_278x314.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:314,&quot;width&quot;:278,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:31612,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179039157?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35c29b0e-6e9d-45b8-8ec9-a0db63190de9_278x314.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Z4JJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35c29b0e-6e9d-45b8-8ec9-a0db63190de9_278x314.png 424w, https://substackcdn.com/image/fetch/$s_!Z4JJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35c29b0e-6e9d-45b8-8ec9-a0db63190de9_278x314.png 848w, https://substackcdn.com/image/fetch/$s_!Z4JJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35c29b0e-6e9d-45b8-8ec9-a0db63190de9_278x314.png 1272w, https://substackcdn.com/image/fetch/$s_!Z4JJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35c29b0e-6e9d-45b8-8ec9-a0db63190de9_278x314.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>While the users &#8220;<strong>CvHNWwEG</strong>&#8221; and &#8220;<strong>i&#951;e&#1109;slop&#1077;z</strong>&#8221; did not yield any results as themselves but the letter &#8216;<strong>&#951;</strong>&#8217; suggests a hint regarding the source of the language, thus the source of the individual behind the operation.</p><p>Through searching the Tuta mail, TOX address, and username provided by the attacker, a website called &#8220;<strong>bytetobreach.com</strong>&#8221; was revealed, where these contact methods are posted. He claims to &#8220;protect&#8221; others&#8217; data from hackers, while he is the de facto attacker. A known method by criminals.</p><p>The website is full of victims that he has already attacked, and even reviews by those &#8220;clients&#8221;, saying how aggressive he was in his attacks, but after he rented his services for protecting them, he became a whole different person.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!K0Bx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cc1a96f-f3a8-4887-9352-b8f0d4c52e3b_425x273.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!K0Bx!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cc1a96f-f3a8-4887-9352-b8f0d4c52e3b_425x273.png 424w, https://substackcdn.com/image/fetch/$s_!K0Bx!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cc1a96f-f3a8-4887-9352-b8f0d4c52e3b_425x273.png 848w, https://substackcdn.com/image/fetch/$s_!K0Bx!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cc1a96f-f3a8-4887-9352-b8f0d4c52e3b_425x273.png 1272w, https://substackcdn.com/image/fetch/$s_!K0Bx!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cc1a96f-f3a8-4887-9352-b8f0d4c52e3b_425x273.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!K0Bx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cc1a96f-f3a8-4887-9352-b8f0d4c52e3b_425x273.png" width="425" height="273" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1cc1a96f-f3a8-4887-9352-b8f0d4c52e3b_425x273.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:273,&quot;width&quot;:425,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:29608,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179039157?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cc1a96f-f3a8-4887-9352-b8f0d4c52e3b_425x273.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!K0Bx!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cc1a96f-f3a8-4887-9352-b8f0d4c52e3b_425x273.png 424w, https://substackcdn.com/image/fetch/$s_!K0Bx!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cc1a96f-f3a8-4887-9352-b8f0d4c52e3b_425x273.png 848w, https://substackcdn.com/image/fetch/$s_!K0Bx!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cc1a96f-f3a8-4887-9352-b8f0d4c52e3b_425x273.png 1272w, https://substackcdn.com/image/fetch/$s_!K0Bx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cc1a96f-f3a8-4887-9352-b8f0d4c52e3b_425x273.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!t23D!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ed2f8e6-df97-4a72-ac4a-9bac213fe6fe_425x166.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!t23D!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ed2f8e6-df97-4a72-ac4a-9bac213fe6fe_425x166.png 424w, https://substackcdn.com/image/fetch/$s_!t23D!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ed2f8e6-df97-4a72-ac4a-9bac213fe6fe_425x166.png 848w, https://substackcdn.com/image/fetch/$s_!t23D!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ed2f8e6-df97-4a72-ac4a-9bac213fe6fe_425x166.png 1272w, https://substackcdn.com/image/fetch/$s_!t23D!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ed2f8e6-df97-4a72-ac4a-9bac213fe6fe_425x166.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!t23D!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ed2f8e6-df97-4a72-ac4a-9bac213fe6fe_425x166.png" width="425" height="166" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4ed2f8e6-df97-4a72-ac4a-9bac213fe6fe_425x166.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:166,&quot;width&quot;:425,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:21190,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179039157?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ed2f8e6-df97-4a72-ac4a-9bac213fe6fe_425x166.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!t23D!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ed2f8e6-df97-4a72-ac4a-9bac213fe6fe_425x166.png 424w, https://substackcdn.com/image/fetch/$s_!t23D!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ed2f8e6-df97-4a72-ac4a-9bac213fe6fe_425x166.png 848w, https://substackcdn.com/image/fetch/$s_!t23D!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ed2f8e6-df97-4a72-ac4a-9bac213fe6fe_425x166.png 1272w, https://substackcdn.com/image/fetch/$s_!t23D!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ed2f8e6-df97-4a72-ac4a-9bac213fe6fe_425x166.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!TsUC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95431b8d-06c2-430f-9c74-1882eca5ee03_443x156.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!TsUC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95431b8d-06c2-430f-9c74-1882eca5ee03_443x156.png 424w, https://substackcdn.com/image/fetch/$s_!TsUC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95431b8d-06c2-430f-9c74-1882eca5ee03_443x156.png 848w, https://substackcdn.com/image/fetch/$s_!TsUC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95431b8d-06c2-430f-9c74-1882eca5ee03_443x156.png 1272w, https://substackcdn.com/image/fetch/$s_!TsUC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95431b8d-06c2-430f-9c74-1882eca5ee03_443x156.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!TsUC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95431b8d-06c2-430f-9c74-1882eca5ee03_443x156.png" width="443" height="156" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/95431b8d-06c2-430f-9c74-1882eca5ee03_443x156.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:156,&quot;width&quot;:443,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:97115,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179039157?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95431b8d-06c2-430f-9c74-1882eca5ee03_443x156.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!TsUC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95431b8d-06c2-430f-9c74-1882eca5ee03_443x156.png 424w, https://substackcdn.com/image/fetch/$s_!TsUC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95431b8d-06c2-430f-9c74-1882eca5ee03_443x156.png 848w, https://substackcdn.com/image/fetch/$s_!TsUC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95431b8d-06c2-430f-9c74-1882eca5ee03_443x156.png 1272w, https://substackcdn.com/image/fetch/$s_!TsUC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95431b8d-06c2-430f-9c74-1882eca5ee03_443x156.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Among his victims are well-known organizations, such as banks, airways, and universities across the globe. He is well proud of his achievements, claiming to hack over 200 clients in 26 different countries.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ptgL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8fa68843-fc96-41a6-a78c-a2c65504b5cb_602x168.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ptgL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8fa68843-fc96-41a6-a78c-a2c65504b5cb_602x168.png 424w, https://substackcdn.com/image/fetch/$s_!ptgL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8fa68843-fc96-41a6-a78c-a2c65504b5cb_602x168.png 848w, https://substackcdn.com/image/fetch/$s_!ptgL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8fa68843-fc96-41a6-a78c-a2c65504b5cb_602x168.png 1272w, https://substackcdn.com/image/fetch/$s_!ptgL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8fa68843-fc96-41a6-a78c-a2c65504b5cb_602x168.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ptgL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8fa68843-fc96-41a6-a78c-a2c65504b5cb_602x168.png" width="602" height="168" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8fa68843-fc96-41a6-a78c-a2c65504b5cb_602x168.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:168,&quot;width&quot;:602,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:32668,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179039157?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8fa68843-fc96-41a6-a78c-a2c65504b5cb_602x168.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ptgL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8fa68843-fc96-41a6-a78c-a2c65504b5cb_602x168.png 424w, https://substackcdn.com/image/fetch/$s_!ptgL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8fa68843-fc96-41a6-a78c-a2c65504b5cb_602x168.png 848w, https://substackcdn.com/image/fetch/$s_!ptgL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8fa68843-fc96-41a6-a78c-a2c65504b5cb_602x168.png 1272w, https://substackcdn.com/image/fetch/$s_!ptgL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8fa68843-fc96-41a6-a78c-a2c65504b5cb_602x168.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>The contact methods he provided were already mentioned, but he chose to add another revealing sentence that can hint at his way of thinking, a thing that represents him potentially in other places and can be used to cross-reference to locate the individual.</p><p>He specifically says, &#8220;<strong>Do not contact me if you are a t3rr0r!st3, or if you are into ch!ldr3n$</strong>&#8221;, meaning he owns a very straightforward mindset about child sexual abusers (CSAM) and terror-related entities.</p><p>Also, the website he operates is using <strong>WordPress</strong> as a host, another clue that may reveal useful associations.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!cYQ5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9025eed-f26e-4760-b26f-75f75b1411d5_602x344.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!cYQ5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9025eed-f26e-4760-b26f-75f75b1411d5_602x344.png 424w, https://substackcdn.com/image/fetch/$s_!cYQ5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9025eed-f26e-4760-b26f-75f75b1411d5_602x344.png 848w, https://substackcdn.com/image/fetch/$s_!cYQ5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9025eed-f26e-4760-b26f-75f75b1411d5_602x344.png 1272w, https://substackcdn.com/image/fetch/$s_!cYQ5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9025eed-f26e-4760-b26f-75f75b1411d5_602x344.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!cYQ5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9025eed-f26e-4760-b26f-75f75b1411d5_602x344.png" width="602" height="344" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c9025eed-f26e-4760-b26f-75f75b1411d5_602x344.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:344,&quot;width&quot;:602,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:74802,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179039157?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9025eed-f26e-4760-b26f-75f75b1411d5_602x344.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!cYQ5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9025eed-f26e-4760-b26f-75f75b1411d5_602x344.png 424w, https://substackcdn.com/image/fetch/$s_!cYQ5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9025eed-f26e-4760-b26f-75f75b1411d5_602x344.png 848w, https://substackcdn.com/image/fetch/$s_!cYQ5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9025eed-f26e-4760-b26f-75f75b1411d5_602x344.png 1272w, https://substackcdn.com/image/fetch/$s_!cYQ5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9025eed-f26e-4760-b26f-75f75b1411d5_602x344.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>The Domain As a Pivot Point</h3><p>The domain itself wasn&#8217;t part of any data breaches or mentions around the web, and no WHOIS records were found associated with it.<br>When checking the IP address of the website, it led to Frankfurt, Germany, where the WordPress servers are. But&#8230; What if one of the interacting users with the IP address is associated with it?</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rJ5Y!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F788bd85f-3d96-4fa2-8caa-c15457aafb42_417x328.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rJ5Y!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F788bd85f-3d96-4fa2-8caa-c15457aafb42_417x328.png 424w, https://substackcdn.com/image/fetch/$s_!rJ5Y!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F788bd85f-3d96-4fa2-8caa-c15457aafb42_417x328.png 848w, https://substackcdn.com/image/fetch/$s_!rJ5Y!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F788bd85f-3d96-4fa2-8caa-c15457aafb42_417x328.png 1272w, https://substackcdn.com/image/fetch/$s_!rJ5Y!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F788bd85f-3d96-4fa2-8caa-c15457aafb42_417x328.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rJ5Y!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F788bd85f-3d96-4fa2-8caa-c15457aafb42_417x328.png" width="417" height="328" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/788bd85f-3d96-4fa2-8caa-c15457aafb42_417x328.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:328,&quot;width&quot;:417,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:103501,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179039157?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F788bd85f-3d96-4fa2-8caa-c15457aafb42_417x328.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!rJ5Y!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F788bd85f-3d96-4fa2-8caa-c15457aafb42_417x328.png 424w, https://substackcdn.com/image/fetch/$s_!rJ5Y!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F788bd85f-3d96-4fa2-8caa-c15457aafb42_417x328.png 848w, https://substackcdn.com/image/fetch/$s_!rJ5Y!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F788bd85f-3d96-4fa2-8caa-c15457aafb42_417x328.png 1272w, https://substackcdn.com/image/fetch/$s_!rJ5Y!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F788bd85f-3d96-4fa2-8caa-c15457aafb42_417x328.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>After researching the IP address in data breaches, and an automated script with a dictionary of relevant words (such as &#8216;hack&#8217;, &#8216;dark&#8217;, &#8216;tuta&#8217; [the anonymous mail provider], and others), one user came up. This is the lead.</p><p>Also, important to add - this <strong>IP address is used to host over 300+ different websites</strong>, <strong>none</strong> of them <strong>was found in the history of the following suspected</strong> user, which backs the claim that the only reason for associating with this IP address is <strong>directly related to</strong> <strong>&#8220;ByteToBreach&#8221;</strong>.</p><p>While going deeper into this user&#8217;s data, I found other relevant associations to hacking skills, privacy software, and operating systems, and of course, many usages with the letter &#8216;<strong>&#951;</strong>&#8217;, as he is located in Greece.</p><div class="image-gallery-embed" data-attrs="{&quot;gallery&quot;:{&quot;images&quot;:[{&quot;type&quot;:&quot;image/png&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/92ecd9ae-76ea-4525-a12e-2b8b6274e4be_291x78.png&quot;},{&quot;type&quot;:&quot;image/png&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fe4d2204-e573-487d-98e6-9c9635b07445_290x61.png&quot;},{&quot;type&quot;:&quot;image/png&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ff929864-4f49-47e5-bb67-79bc37075c57_532x74.png&quot;},{&quot;type&quot;:&quot;image/png&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/12ed5a17-f94a-42bf-8d66-25dadc39d3ed_360x147.png&quot;},{&quot;type&quot;:&quot;image/png&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bee35c94-a2cb-424c-a044-2e693409aafc_417x93.png&quot;},{&quot;type&quot;:&quot;image/png&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1dbc9b33-5078-4734-a0d1-c55c207dbfac_272x151.png&quot;}],&quot;caption&quot;:&quot;&quot;,&quot;alt&quot;:&quot;&quot;,&quot;staticGalleryImage&quot;:{&quot;type&quot;:&quot;image/png&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4c29a3e1-ad7b-4af0-856d-43af9a63ec1c_1456x964.png&quot;}},&quot;isEditorNode&quot;:true}"></div><p>By this data, we can understand that he is well familiar with privacy-oriented solutions (<strong>Tails OS, Tuta mail, Kali Linux</strong>, etc), that he speaks <strong>Greek</strong>, is involved with hacking tools and associated GitHub repos (such as Wi-Fi stealers), and even searched for guidance on <strong>hosting his own Darkweb site</strong>.</p><p>Also, a lot of mentions for <strong>WordPress</strong> services were found, including https://***di*.staging.wpengine.com, a staging site (private test version of WP, like a SandBox that is designed to be private and hidden from the public&#8217;s site).</p><h3>New Clue Sheds Light</h3><p>After reviewing thousands of lines of data, one username repeated again and again, &#8220;<strong>**uru_gr</strong>&#8221; (username blurred for privacy matters), which opened a whole new door for this investigation.</p><p>The username is directly associated with a website called &#8220;<strong>**uru.gr</strong>&#8221;, where the owner posts dozens of materials on stealers, exploits, privacy-oriented tools, and hacking materials.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Hzhn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfb1e442-72f2-40e5-afac-503586efd9ac_602x338.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Hzhn!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfb1e442-72f2-40e5-afac-503586efd9ac_602x338.png 424w, https://substackcdn.com/image/fetch/$s_!Hzhn!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfb1e442-72f2-40e5-afac-503586efd9ac_602x338.png 848w, https://substackcdn.com/image/fetch/$s_!Hzhn!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfb1e442-72f2-40e5-afac-503586efd9ac_602x338.png 1272w, https://substackcdn.com/image/fetch/$s_!Hzhn!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfb1e442-72f2-40e5-afac-503586efd9ac_602x338.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Hzhn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfb1e442-72f2-40e5-afac-503586efd9ac_602x338.png" width="602" height="338" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dfb1e442-72f2-40e5-afac-503586efd9ac_602x338.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:338,&quot;width&quot;:602,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:100744,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179039157?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfb1e442-72f2-40e5-afac-503586efd9ac_602x338.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Hzhn!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfb1e442-72f2-40e5-afac-503586efd9ac_602x338.png 424w, https://substackcdn.com/image/fetch/$s_!Hzhn!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfb1e442-72f2-40e5-afac-503586efd9ac_602x338.png 848w, https://substackcdn.com/image/fetch/$s_!Hzhn!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfb1e442-72f2-40e5-afac-503586efd9ac_602x338.png 1272w, https://substackcdn.com/image/fetch/$s_!Hzhn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfb1e442-72f2-40e5-afac-503586efd9ac_602x338.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Also, by the username &#8220;<strong>**uru</strong>&#8221;, in his associated data found, an <strong>ONION url</strong> was found (Darknet) <strong>with his name</strong>, meaning he used to be the admin of a website on the Darknet.<br>The server has already been deleted, and no archives were found.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!x6I0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1a34433-e8a9-44cd-914c-f44959f863ff_602x68.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!x6I0!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1a34433-e8a9-44cd-914c-f44959f863ff_602x68.png 424w, https://substackcdn.com/image/fetch/$s_!x6I0!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1a34433-e8a9-44cd-914c-f44959f863ff_602x68.png 848w, https://substackcdn.com/image/fetch/$s_!x6I0!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1a34433-e8a9-44cd-914c-f44959f863ff_602x68.png 1272w, https://substackcdn.com/image/fetch/$s_!x6I0!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1a34433-e8a9-44cd-914c-f44959f863ff_602x68.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!x6I0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1a34433-e8a9-44cd-914c-f44959f863ff_602x68.png" width="602" height="68" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b1a34433-e8a9-44cd-914c-f44959f863ff_602x68.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:68,&quot;width&quot;:602,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:17000,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179039157?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1a34433-e8a9-44cd-914c-f44959f863ff_602x68.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!x6I0!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1a34433-e8a9-44cd-914c-f44959f863ff_602x68.png 424w, https://substackcdn.com/image/fetch/$s_!x6I0!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1a34433-e8a9-44cd-914c-f44959f863ff_602x68.png 848w, https://substackcdn.com/image/fetch/$s_!x6I0!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1a34433-e8a9-44cd-914c-f44959f863ff_602x68.png 1272w, https://substackcdn.com/image/fetch/$s_!x6I0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1a34433-e8a9-44cd-914c-f44959f863ff_602x68.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>When using the Wayback Archive Machine to check the past versions of the website, I found it was part of a Mashable leak that occurred in 2020 and revealed personal information, including usernames. His username is to be more straightforward.</p><p>In the archived version of his website, he claims to be part of <strong>Anonymous hackers</strong>, and <strong>expressed direct against child abusers</strong>, exactly as the official hacker&#8217;s website.</p><p>The <strong>http://t[.]co/HaIX****</strong> is a direct link to <strong>**uru.GR</strong> website.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!WLVX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ae133a9-68eb-4b99-9ce7-7b26a11aa2ab_440x239.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!WLVX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ae133a9-68eb-4b99-9ce7-7b26a11aa2ab_440x239.png 424w, https://substackcdn.com/image/fetch/$s_!WLVX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ae133a9-68eb-4b99-9ce7-7b26a11aa2ab_440x239.png 848w, https://substackcdn.com/image/fetch/$s_!WLVX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ae133a9-68eb-4b99-9ce7-7b26a11aa2ab_440x239.png 1272w, https://substackcdn.com/image/fetch/$s_!WLVX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ae133a9-68eb-4b99-9ce7-7b26a11aa2ab_440x239.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!WLVX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ae133a9-68eb-4b99-9ce7-7b26a11aa2ab_440x239.png" width="440" height="239" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4ae133a9-68eb-4b99-9ce7-7b26a11aa2ab_440x239.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:239,&quot;width&quot;:440,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:62507,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179039157?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ae133a9-68eb-4b99-9ce7-7b26a11aa2ab_440x239.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!WLVX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ae133a9-68eb-4b99-9ce7-7b26a11aa2ab_440x239.png 424w, https://substackcdn.com/image/fetch/$s_!WLVX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ae133a9-68eb-4b99-9ce7-7b26a11aa2ab_440x239.png 848w, https://substackcdn.com/image/fetch/$s_!WLVX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ae133a9-68eb-4b99-9ce7-7b26a11aa2ab_440x239.png 1272w, https://substackcdn.com/image/fetch/$s_!WLVX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ae133a9-68eb-4b99-9ce7-7b26a11aa2ab_440x239.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h3>Username To Social Life</h3><p>With this username revealed, tons of other data came out. From email addresses to passwords, associated accounts, and a lot more.<br>The Twitter (X) account with this name appears to be in direct association with <strong>cybersecurity</strong> and <strong>technology</strong>, and refers to the website with this username, Facebook account, and approves the location of <strong>Greece</strong>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QZax!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a26654a-c3a8-4454-accf-3748e2f4f895_333x260.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QZax!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a26654a-c3a8-4454-accf-3748e2f4f895_333x260.png 424w, https://substackcdn.com/image/fetch/$s_!QZax!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a26654a-c3a8-4454-accf-3748e2f4f895_333x260.png 848w, https://substackcdn.com/image/fetch/$s_!QZax!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a26654a-c3a8-4454-accf-3748e2f4f895_333x260.png 1272w, https://substackcdn.com/image/fetch/$s_!QZax!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a26654a-c3a8-4454-accf-3748e2f4f895_333x260.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QZax!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a26654a-c3a8-4454-accf-3748e2f4f895_333x260.png" width="333" height="260" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1a26654a-c3a8-4454-accf-3748e2f4f895_333x260.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:260,&quot;width&quot;:333,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:58425,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179039157?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a26654a-c3a8-4454-accf-3748e2f4f895_333x260.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!QZax!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a26654a-c3a8-4454-accf-3748e2f4f895_333x260.png 424w, https://substackcdn.com/image/fetch/$s_!QZax!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a26654a-c3a8-4454-accf-3748e2f4f895_333x260.png 848w, https://substackcdn.com/image/fetch/$s_!QZax!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a26654a-c3a8-4454-accf-3748e2f4f895_333x260.png 1272w, https://substackcdn.com/image/fetch/$s_!QZax!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1a26654a-c3a8-4454-accf-3748e2f4f895_333x260.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>On this Twitter account, there are a lot of old posts about individuals who <strong>got arrested for child abuse and child pornography</strong> (again, repeating the strong mindset and agenda against CSAM users), and references to <strong>Anonymous</strong> <strong>hackers</strong>, a user named &#8220;<strong>TheAnon0ne</strong>&#8221;, a known hacker with a strong agenda <strong>against child abusers</strong>.</p><div class="image-gallery-embed" data-attrs="{&quot;gallery&quot;:{&quot;images&quot;:[{&quot;type&quot;:&quot;image/png&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/53fba651-5ba7-460a-9a01-5aa166bccb48_496x115.png&quot;},{&quot;type&quot;:&quot;image/png&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6e3cc124-d6a7-42e4-a619-b72ea38cab99_390x279.png&quot;},{&quot;type&quot;:&quot;image/png&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dbf98b16-344e-4ec3-a40a-60c9fb18ed20_318x414.png&quot;}],&quot;caption&quot;:&quot;&quot;,&quot;alt&quot;:&quot;&quot;,&quot;staticGalleryImage&quot;:{&quot;type&quot;:&quot;image/png&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c663a5cf-8891-411e-a509-4543742558ba_1456x474.png&quot;}},&quot;isEditorNode&quot;:true}"></div><p>As shown previously in the archived version of his website <strong>**uru.GR</strong>, the hashtags <strong>#Anonymous</strong>, <strong>#OpPedoChat</strong>, and the <strong>user @TheAnon0ne</strong>, repeated on his Twitter as well.</p><h3>Let&#8217;s understand who this **uru</h3><p>More than 20 different emails were found with his nickname, including tuta email provider, but none of them yielded any significant results.<br>Though the nick by itself didn&#8217;t help, the website &#8220;<strong>**uRu.gr</strong>&#8221;, based on that very same nick, gave the official LinkedIn page of this entity.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!j2Uc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feef275de-f6ad-4d79-be30-9ed5934876c0_602x373.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!j2Uc!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feef275de-f6ad-4d79-be30-9ed5934876c0_602x373.png 424w, https://substackcdn.com/image/fetch/$s_!j2Uc!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feef275de-f6ad-4d79-be30-9ed5934876c0_602x373.png 848w, https://substackcdn.com/image/fetch/$s_!j2Uc!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feef275de-f6ad-4d79-be30-9ed5934876c0_602x373.png 1272w, https://substackcdn.com/image/fetch/$s_!j2Uc!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feef275de-f6ad-4d79-be30-9ed5934876c0_602x373.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!j2Uc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feef275de-f6ad-4d79-be30-9ed5934876c0_602x373.png" width="602" height="373" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/eef275de-f6ad-4d79-be30-9ed5934876c0_602x373.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:373,&quot;width&quot;:602,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:79276,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179039157?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feef275de-f6ad-4d79-be30-9ed5934876c0_602x373.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!j2Uc!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feef275de-f6ad-4d79-be30-9ed5934876c0_602x373.png 424w, https://substackcdn.com/image/fetch/$s_!j2Uc!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feef275de-f6ad-4d79-be30-9ed5934876c0_602x373.png 848w, https://substackcdn.com/image/fetch/$s_!j2Uc!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feef275de-f6ad-4d79-be30-9ed5934876c0_602x373.png 1272w, https://substackcdn.com/image/fetch/$s_!j2Uc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feef275de-f6ad-4d79-be30-9ed5934876c0_602x373.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The most interesting result here is the fact that there is <strong>only one employee in this company</strong>.<br>When checking the page to see who is the person involved with it, one name came up &#8211; Anastasis ******, from <strong>Thessalon&#237;ki, Greece</strong>.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xA0T!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63580766-c132-4f90-a218-a1a459760be2_408x159.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xA0T!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63580766-c132-4f90-a218-a1a459760be2_408x159.png 424w, https://substackcdn.com/image/fetch/$s_!xA0T!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63580766-c132-4f90-a218-a1a459760be2_408x159.png 848w, https://substackcdn.com/image/fetch/$s_!xA0T!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63580766-c132-4f90-a218-a1a459760be2_408x159.png 1272w, https://substackcdn.com/image/fetch/$s_!xA0T!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63580766-c132-4f90-a218-a1a459760be2_408x159.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xA0T!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63580766-c132-4f90-a218-a1a459760be2_408x159.png" width="408" height="159" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/63580766-c132-4f90-a218-a1a459760be2_408x159.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:159,&quot;width&quot;:408,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:28630,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179039157?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63580766-c132-4f90-a218-a1a459760be2_408x159.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!xA0T!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63580766-c132-4f90-a218-a1a459760be2_408x159.png 424w, https://substackcdn.com/image/fetch/$s_!xA0T!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63580766-c132-4f90-a218-a1a459760be2_408x159.png 848w, https://substackcdn.com/image/fetch/$s_!xA0T!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63580766-c132-4f90-a218-a1a459760be2_408x159.png 1272w, https://substackcdn.com/image/fetch/$s_!xA0T!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63580766-c132-4f90-a218-a1a459760be2_408x159.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Checking on this individual led to phone numbers and email addresses associated directly with him, and from there, to a Facebook page with 121K likes and 3.8K followers.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!OZKE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1f92475-1e52-46fa-b1c4-39b62070dda8_437x351.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!OZKE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1f92475-1e52-46fa-b1c4-39b62070dda8_437x351.png 424w, https://substackcdn.com/image/fetch/$s_!OZKE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1f92475-1e52-46fa-b1c4-39b62070dda8_437x351.png 848w, https://substackcdn.com/image/fetch/$s_!OZKE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1f92475-1e52-46fa-b1c4-39b62070dda8_437x351.png 1272w, https://substackcdn.com/image/fetch/$s_!OZKE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1f92475-1e52-46fa-b1c4-39b62070dda8_437x351.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!OZKE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1f92475-1e52-46fa-b1c4-39b62070dda8_437x351.png" width="437" height="351" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a1f92475-1e52-46fa-b1c4-39b62070dda8_437x351.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:351,&quot;width&quot;:437,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:138022,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179039157?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1f92475-1e52-46fa-b1c4-39b62070dda8_437x351.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!OZKE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1f92475-1e52-46fa-b1c4-39b62070dda8_437x351.png 424w, https://substackcdn.com/image/fetch/$s_!OZKE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1f92475-1e52-46fa-b1c4-39b62070dda8_437x351.png 848w, https://substackcdn.com/image/fetch/$s_!OZKE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1f92475-1e52-46fa-b1c4-39b62070dda8_437x351.png 1272w, https://substackcdn.com/image/fetch/$s_!OZKE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1f92475-1e52-46fa-b1c4-39b62070dda8_437x351.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>By the account, it appears that this individual is <strong>well familiar with hacking materials</strong>. He claims to be a cybersecurity expert (<strong>penetration testing</strong>, <strong>malware analysis</strong>, <strong>developer</strong>, <strong>red teamer</strong>), and is associated <strong>directly with **uRu</strong>.<br>Also, the first post his on his Facebook page includes a manual of FlipperZero, a known hacking tool that can read, copy, and emulate RFID and NFC tags, radio remotes, iButtons, and digital access keys.</p><p>In this Facebook page, older posts, one specific post came up, <strong>regarding child safety on the internet</strong>, directly connected to the &#8220;anti-pedophile&#8221; mindset, appears on the official website of the threat actor &#8220;<strong>Bytetobreach</strong>&#8221;. This post is tagged with another Facebook account under his name, with the same photo and nickname (<strong>Cyber***</strong>).</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!aOcb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffb3f38e-ea69-4bb6-bf54-98d4965826dc_318x263.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!aOcb!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffb3f38e-ea69-4bb6-bf54-98d4965826dc_318x263.png 424w, https://substackcdn.com/image/fetch/$s_!aOcb!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffb3f38e-ea69-4bb6-bf54-98d4965826dc_318x263.png 848w, https://substackcdn.com/image/fetch/$s_!aOcb!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffb3f38e-ea69-4bb6-bf54-98d4965826dc_318x263.png 1272w, https://substackcdn.com/image/fetch/$s_!aOcb!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffb3f38e-ea69-4bb6-bf54-98d4965826dc_318x263.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!aOcb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffb3f38e-ea69-4bb6-bf54-98d4965826dc_318x263.png" width="318" height="263" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ffb3f38e-ea69-4bb6-bf54-98d4965826dc_318x263.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:263,&quot;width&quot;:318,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:172888,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179039157?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffb3f38e-ea69-4bb6-bf54-98d4965826dc_318x263.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!aOcb!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffb3f38e-ea69-4bb6-bf54-98d4965826dc_318x263.png 424w, https://substackcdn.com/image/fetch/$s_!aOcb!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffb3f38e-ea69-4bb6-bf54-98d4965826dc_318x263.png 848w, https://substackcdn.com/image/fetch/$s_!aOcb!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffb3f38e-ea69-4bb6-bf54-98d4965826dc_318x263.png 1272w, https://substackcdn.com/image/fetch/$s_!aOcb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffb3f38e-ea69-4bb6-bf54-98d4965826dc_318x263.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>When exploring this second Facebook page's posts, <strong>more relevant posts on child safety</strong> strengthen the claim of his mindset, similar to the threat actor &#8220;<strong>Bytetobreach</strong>&#8221; that spoke directly against pedophiles on his official website.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!lpOn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39cfded9-db34-487b-9964-9e408d57b74e_300x431.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!lpOn!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39cfded9-db34-487b-9964-9e408d57b74e_300x431.png 424w, https://substackcdn.com/image/fetch/$s_!lpOn!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39cfded9-db34-487b-9964-9e408d57b74e_300x431.png 848w, https://substackcdn.com/image/fetch/$s_!lpOn!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39cfded9-db34-487b-9964-9e408d57b74e_300x431.png 1272w, https://substackcdn.com/image/fetch/$s_!lpOn!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39cfded9-db34-487b-9964-9e408d57b74e_300x431.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!lpOn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39cfded9-db34-487b-9964-9e408d57b74e_300x431.png" width="300" height="431" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/39cfded9-db34-487b-9964-9e408d57b74e_300x431.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:431,&quot;width&quot;:300,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:184317,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179039157?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39cfded9-db34-487b-9964-9e408d57b74e_300x431.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!lpOn!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39cfded9-db34-487b-9964-9e408d57b74e_300x431.png 424w, https://substackcdn.com/image/fetch/$s_!lpOn!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39cfded9-db34-487b-9964-9e408d57b74e_300x431.png 848w, https://substackcdn.com/image/fetch/$s_!lpOn!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39cfded9-db34-487b-9964-9e408d57b74e_300x431.png 1272w, https://substackcdn.com/image/fetch/$s_!lpOn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39cfded9-db34-487b-9964-9e408d57b74e_300x431.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>On top of that, the username he uses on his official Facebook pages (<strong>Cyber***</strong>) is the username for <strong>**uru.news website</strong> on his behalf.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-qSF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc53d614b-4e14-42d8-be93-940b6f061d90_284x93.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-qSF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc53d614b-4e14-42d8-be93-940b6f061d90_284x93.png 424w, https://substackcdn.com/image/fetch/$s_!-qSF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc53d614b-4e14-42d8-be93-940b6f061d90_284x93.png 848w, https://substackcdn.com/image/fetch/$s_!-qSF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc53d614b-4e14-42d8-be93-940b6f061d90_284x93.png 1272w, https://substackcdn.com/image/fetch/$s_!-qSF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc53d614b-4e14-42d8-be93-940b6f061d90_284x93.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-qSF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc53d614b-4e14-42d8-be93-940b6f061d90_284x93.png" width="284" height="93" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c53d614b-4e14-42d8-be93-940b6f061d90_284x93.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:93,&quot;width&quot;:284,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:14737,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179039157?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc53d614b-4e14-42d8-be93-940b6f061d90_284x93.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-qSF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc53d614b-4e14-42d8-be93-940b6f061d90_284x93.png 424w, https://substackcdn.com/image/fetch/$s_!-qSF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc53d614b-4e14-42d8-be93-940b6f061d90_284x93.png 848w, https://substackcdn.com/image/fetch/$s_!-qSF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc53d614b-4e14-42d8-be93-940b6f061d90_284x93.png 1272w, https://substackcdn.com/image/fetch/$s_!-qSF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc53d614b-4e14-42d8-be93-940b6f061d90_284x93.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>With a deeper dive into his profiles and mentions, his appearence in a freelancers website came out, specifiying his email address, phone number and some details about him <strong>owning the relevant skills that &#8220;Byetobreach&#8221;</strong> owns, that he have <strong>16 years of expirienc</strong>e (which perfectly alligns with the fact that in the official website of the threat actor, that created 1 year ago, it says <strong>&#8220;15 years of expirience&#8221;</strong>), and the fact he mentions <strong>WorPress</strong> (the infrastracture of &#8220;Bytetobreach&#8217;s&#8221; website) as main skill.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!IrMg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8afee0d0-686e-42c8-b83d-8ecacd6b4d0a_571x332.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!IrMg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8afee0d0-686e-42c8-b83d-8ecacd6b4d0a_571x332.png 424w, https://substackcdn.com/image/fetch/$s_!IrMg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8afee0d0-686e-42c8-b83d-8ecacd6b4d0a_571x332.png 848w, https://substackcdn.com/image/fetch/$s_!IrMg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8afee0d0-686e-42c8-b83d-8ecacd6b4d0a_571x332.png 1272w, https://substackcdn.com/image/fetch/$s_!IrMg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8afee0d0-686e-42c8-b83d-8ecacd6b4d0a_571x332.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!IrMg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8afee0d0-686e-42c8-b83d-8ecacd6b4d0a_571x332.png" width="571" height="332" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8afee0d0-686e-42c8-b83d-8ecacd6b4d0a_571x332.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:332,&quot;width&quot;:571,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:96601,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179039157?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8afee0d0-686e-42c8-b83d-8ecacd6b4d0a_571x332.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!IrMg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8afee0d0-686e-42c8-b83d-8ecacd6b4d0a_571x332.png 424w, https://substackcdn.com/image/fetch/$s_!IrMg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8afee0d0-686e-42c8-b83d-8ecacd6b4d0a_571x332.png 848w, https://substackcdn.com/image/fetch/$s_!IrMg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8afee0d0-686e-42c8-b83d-8ecacd6b4d0a_571x332.png 1272w, https://substackcdn.com/image/fetch/$s_!IrMg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8afee0d0-686e-42c8-b83d-8ecacd6b4d0a_571x332.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>A Complete Intelligence Review - Digital Footprints</h3><p>Profiling the person behind the website reveals contact methods and their social accounts, a thing that may assist the authorities and other intelligence agencies to engage with them when needed.</p><p>For this purpose and to maintain his privacy, all PIIs (personal identification information) and associated online accounts are blurred.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Af3m!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3af9e1d7-548f-497f-9351-82783d15c47d_602x470.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Af3m!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3af9e1d7-548f-497f-9351-82783d15c47d_602x470.png 424w, https://substackcdn.com/image/fetch/$s_!Af3m!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3af9e1d7-548f-497f-9351-82783d15c47d_602x470.png 848w, https://substackcdn.com/image/fetch/$s_!Af3m!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3af9e1d7-548f-497f-9351-82783d15c47d_602x470.png 1272w, https://substackcdn.com/image/fetch/$s_!Af3m!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3af9e1d7-548f-497f-9351-82783d15c47d_602x470.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Af3m!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3af9e1d7-548f-497f-9351-82783d15c47d_602x470.png" width="602" height="470" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3af9e1d7-548f-497f-9351-82783d15c47d_602x470.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:470,&quot;width&quot;:602,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:135930,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179039157?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3af9e1d7-548f-497f-9351-82783d15c47d_602x470.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Af3m!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3af9e1d7-548f-497f-9351-82783d15c47d_602x470.png 424w, https://substackcdn.com/image/fetch/$s_!Af3m!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3af9e1d7-548f-497f-9351-82783d15c47d_602x470.png 848w, https://substackcdn.com/image/fetch/$s_!Af3m!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3af9e1d7-548f-497f-9351-82783d15c47d_602x470.png 1272w, https://substackcdn.com/image/fetch/$s_!Af3m!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3af9e1d7-548f-497f-9351-82783d15c47d_602x470.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tEnX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc5d11c8-a5b7-42c7-b3f1-bd0343078576_484x132.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tEnX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc5d11c8-a5b7-42c7-b3f1-bd0343078576_484x132.png 424w, https://substackcdn.com/image/fetch/$s_!tEnX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc5d11c8-a5b7-42c7-b3f1-bd0343078576_484x132.png 848w, https://substackcdn.com/image/fetch/$s_!tEnX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc5d11c8-a5b7-42c7-b3f1-bd0343078576_484x132.png 1272w, https://substackcdn.com/image/fetch/$s_!tEnX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc5d11c8-a5b7-42c7-b3f1-bd0343078576_484x132.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tEnX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc5d11c8-a5b7-42c7-b3f1-bd0343078576_484x132.png" width="484" height="132" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cc5d11c8-a5b7-42c7-b3f1-bd0343078576_484x132.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:132,&quot;width&quot;:484,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:19625,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179039157?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc5d11c8-a5b7-42c7-b3f1-bd0343078576_484x132.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tEnX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc5d11c8-a5b7-42c7-b3f1-bd0343078576_484x132.png 424w, https://substackcdn.com/image/fetch/$s_!tEnX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc5d11c8-a5b7-42c7-b3f1-bd0343078576_484x132.png 848w, https://substackcdn.com/image/fetch/$s_!tEnX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc5d11c8-a5b7-42c7-b3f1-bd0343078576_484x132.png 1272w, https://substackcdn.com/image/fetch/$s_!tEnX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc5d11c8-a5b7-42c7-b3f1-bd0343078576_484x132.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!pXwd!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99b3726f-7d66-4b1d-af56-1c727b1a26ec_485x114.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!pXwd!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99b3726f-7d66-4b1d-af56-1c727b1a26ec_485x114.png 424w, https://substackcdn.com/image/fetch/$s_!pXwd!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99b3726f-7d66-4b1d-af56-1c727b1a26ec_485x114.png 848w, https://substackcdn.com/image/fetch/$s_!pXwd!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99b3726f-7d66-4b1d-af56-1c727b1a26ec_485x114.png 1272w, https://substackcdn.com/image/fetch/$s_!pXwd!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99b3726f-7d66-4b1d-af56-1c727b1a26ec_485x114.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!pXwd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99b3726f-7d66-4b1d-af56-1c727b1a26ec_485x114.png" width="485" height="114" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/99b3726f-7d66-4b1d-af56-1c727b1a26ec_485x114.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:114,&quot;width&quot;:485,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:18589,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179039157?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99b3726f-7d66-4b1d-af56-1c727b1a26ec_485x114.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!pXwd!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99b3726f-7d66-4b1d-af56-1c727b1a26ec_485x114.png 424w, https://substackcdn.com/image/fetch/$s_!pXwd!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99b3726f-7d66-4b1d-af56-1c727b1a26ec_485x114.png 848w, https://substackcdn.com/image/fetch/$s_!pXwd!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99b3726f-7d66-4b1d-af56-1c727b1a26ec_485x114.png 1272w, https://substackcdn.com/image/fetch/$s_!pXwd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99b3726f-7d66-4b1d-af56-1c727b1a26ec_485x114.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!luh3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd7a8fd4-e9f8-46f2-b92d-15343be4ae49_485x491.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!luh3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd7a8fd4-e9f8-46f2-b92d-15343be4ae49_485x491.png 424w, https://substackcdn.com/image/fetch/$s_!luh3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd7a8fd4-e9f8-46f2-b92d-15343be4ae49_485x491.png 848w, https://substackcdn.com/image/fetch/$s_!luh3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd7a8fd4-e9f8-46f2-b92d-15343be4ae49_485x491.png 1272w, https://substackcdn.com/image/fetch/$s_!luh3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd7a8fd4-e9f8-46f2-b92d-15343be4ae49_485x491.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!luh3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd7a8fd4-e9f8-46f2-b92d-15343be4ae49_485x491.png" width="485" height="491" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dd7a8fd4-e9f8-46f2-b92d-15343be4ae49_485x491.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:491,&quot;width&quot;:485,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:116725,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.darksignal.co/i/179039157?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd7a8fd4-e9f8-46f2-b92d-15343be4ae49_485x491.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!luh3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd7a8fd4-e9f8-46f2-b92d-15343be4ae49_485x491.png 424w, https://substackcdn.com/image/fetch/$s_!luh3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd7a8fd4-e9f8-46f2-b92d-15343be4ae49_485x491.png 848w, https://substackcdn.com/image/fetch/$s_!luh3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd7a8fd4-e9f8-46f2-b92d-15343be4ae49_485x491.png 1272w, https://substackcdn.com/image/fetch/$s_!luh3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd7a8fd4-e9f8-46f2-b92d-15343be4ae49_485x491.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.darksignal.co/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item></channel></rss>