{
  "version": "https://jsonfeed.org/version/1.1",
  "title": "The Hunter's Ledger",
  "home_page_url": "https://the-hunters-ledger.com/",
  "feed_url": "https://the-hunters-ledger.com/feed.json",
  "description": "Threat Intelligence Reports and Hunting Resources",
  "icon": "https://the-hunters-ledger.com/assets/images/apple-touch-icon.png",
  "favicon": "https://the-hunters-ledger.com/assets/images/favicon.svg",
  "language": "en",
  "authors": [{ "name": "The Hunter's Ledger", "url": "https://the-hunters-ledger.com" }],
  "items": [
    {
      "id": "https://the-hunters-ledger.com/reports/newdouble-clickfix/",
      "url": "https://the-hunters-ledger.com/reports/newdouble-clickfix/",
      "title": "FACEIT ClickFix Pages Point CS2 Players to a Script URL That VirusTotal Ties to a Steam-Focused Executable",
      "summary": "Fake FACEIT verification pages direct CS2 players to run a PowerShell downloader that, as held by VirusTotal on September 25, 2026, downloaded an executable built for Steam account theft.",
      "content_text": "Fake FACEIT verification pages direct CS2 players to run a PowerShell downloader that, as held by VirusTotal on September 25, 2026, downloaded an executable built for Steam account theft.",
      "date_published": "2026-09-28T00:00:00+00:00",
      "date_modified": "2026-09-28T00:00:00+00:00",
      "image": "https://the-hunters-ledger.com/assets/images/cards/newdouble-clickfix.png",
      "tags": ["Loader / Stealer"],
      "authors": [{ "name": "Joseph Harrison", "url": "https://the-hunters-ledger.com/about-me/" }]
    },
    {
      "id": "https://the-hunters-ledger.com/reports/gotenberg-rce-cryptomining-107-175-69-137/",
      "url": "https://the-hunters-ledger.com/reports/gotenberg-rce-cryptomining-107-175-69-137/",
      "title": "Gotenberg CVE-2026-42589 Mass Exploitation and Cryptomining",
      "summary": "One operator confirmed remote code execution on 198 internet-facing Gotenberg instances in 54 minutes and dropped a cryptominer, and the obvious network signature for the attack never fires because the injected newlines are JSON-escaped on the wire.",
      "content_text": "One operator confirmed remote code execution on 198 internet-facing Gotenberg instances in 54 minutes and dropped a cryptominer, and the obvious network signature for the attack never fires because the injected newlines are JSON-escaped on the wire.",
      "date_published": "2026-09-16T00:00:00+00:00",
      "date_modified": "2026-09-16T00:00:00+00:00",
      "image": "https://the-hunters-ledger.com/assets/images/cards/gotenberg-rce-cryptomining-107-175-69-137.png",
      "tags": ["Exploitation Campaign"],
      "authors": [{ "name": "Joseph Harrison", "url": "https://the-hunters-ledger.com/about-me/" }]
    },
    {
      "id": "https://the-hunters-ledger.com/reports/sliver-c2-windows-postex-staging-193-233-202-17/",
      "url": "https://the-hunters-ledger.com/reports/sliver-c2-windows-postex-staging-193-233-202-17/",
      "title": "Sliver C2 Windows Post-Exploitation Staging, 193.233.202.17",
      "summary": "A Sliver C2 and a separate blockchain-resolved Node.js implant, staged from one open directory, reached Domain Admin in a US organisation's Windows estate; the second implant's C2 rotation is logged permanently and publicly on an Ethereum smart contract.",
      "content_text": "A Sliver C2 and a separate blockchain-resolved Node.js implant, staged from one open directory, reached Domain Admin in a US organisation's Windows estate; the second implant's C2 rotation is logged permanently and publicly on an Ethereum smart contract.",
      "date_published": "2026-09-07T00:00:00+00:00",
      "date_modified": "2026-09-07T00:00:00+00:00",
      "image": "https://the-hunters-ledger.com/assets/images/cards/sliver-c2-windows-postex-staging-193-233-202-17.png",
      "tags": ["Post-Exploitation Toolkit"],
      "authors": [{ "name": "Joseph Harrison", "url": "https://the-hunters-ledger.com/about-me/" }]
    },
    {
      "id": "https://the-hunters-ledger.com/reports/opendirectory-13-140-145-210-weblogic-deserialization-telecom-harvester-20260817/",
      "url": "https://the-hunters-ledger.com/reports/opendirectory-13-140-145-210-weblogic-deserialization-telecom-harvester-20260817/",
      "title": "Carrier Credential Harvesting Through a Customer's Router",
      "summary": "An operator reached an Ecuadorian carrier's AAA and provisioning secrets through one small business customer's carrier-managed Cisco router, making the device upload 424,946,514 bytes of its own firmware, crash dumps and configuration files.",
      "content_text": "An operator reached an Ecuadorian carrier's AAA and provisioning secrets through one small business customer's carrier-managed Cisco router, making the device upload 424,946,514 bytes of its own firmware, crash dumps and configuration files.",
      "date_published": "2026-08-18T00:00:00+00:00",
      "date_modified": "2026-08-18T00:00:00+00:00",
      "image": "https://the-hunters-ledger.com/assets/images/cards/opendirectory-13-140-145-210-weblogic-deserialization-telecom-harvester-20260817.png",
      "tags": ["Exploitation Campaign"],
      "authors": [{ "name": "Joseph Harrison", "url": "https://the-hunters-ledger.com/about-me/" }]
    },
    {
      "id": "https://the-hunters-ledger.com/reports/seasia-gov-exploitation-toolkit-144-172-106-236/",
      "url": "https://the-hunters-ledger.com/reports/seasia-gov-exploitation-toolkit-144-172-106-236/",
      "title": "The Middle Tier: A Non-APT Operator's Reach Into Four Southeast Asian Governments",
      "summary": "A hands-on-keyboard operator ran a four-country government exploitation campaign from an exposed open directory. This analysis names the three systems that fell, the far larger set that only got probed, the controls that held, and the hunt anchors for the confirmed activity.",
      "content_text": "A hands-on-keyboard operator ran a four-country government exploitation campaign from an exposed open directory. This analysis names the three systems that fell, the far larger set that only got probed, the controls that held, and the hunt anchors for the confirmed activity.",
      "date_published": "2026-08-13T00:00:00+00:00",
      "date_modified": "2026-08-13T00:00:00+00:00",
      "image": "https://the-hunters-ledger.com/assets/images/cards/seasia-gov-exploitation-toolkit-144-172-106-236.png",
      "tags": ["Exploitation Campaign"],
      "authors": [{ "name": "Joseph Harrison", "url": "https://the-hunters-ledger.com/about-me/" }]
    },
    {
      "id": "https://the-hunters-ledger.com/reports/cloudsync-assembler-toolkit-91-197-98-188/",
      "url": "https://the-hunters-ledger.com/reports/cloudsync-assembler-toolkit-91-197-98-188/",
      "title": "CloudSync: An Assembler's Intrusion Toolkit",
      "summary": "A 22-file intrusion toolkit staged on a live open directory, built almost entirely from other people's tooling. Three named threat actors' tools sit in the kit, and the operator is none of them.",
      "content_text": "A 22-file intrusion toolkit staged on a live open directory, built almost entirely from other people's tooling. Three named threat actors' tools sit in the kit, and the operator is none of them.",
      "date_published": "2026-08-03T00:00:00+00:00",
      "date_modified": "2026-08-03T00:00:00+00:00",
      "image": "https://the-hunters-ledger.com/assets/images/cards/cloudsync-assembler-toolkit-91-197-98-188.png",
      "tags": ["Post-Exploitation Toolkit"],
      "authors": [{ "name": "Joseph Harrison", "url": "https://the-hunters-ledger.com/about-me/" }]
    },
    {
      "id": "https://the-hunters-ledger.com/reports/gocloud-multiservice-cryptojacking-149-28-112-221/",
      "url": "https://the-hunters-ledger.com/reports/gocloud-multiservice-cryptojacking-149-28-112-221/",
      "title": "GOCLOUD: A Commodity Cryptojacking Operation, Captured Whole",
      "summary": "A self-branded, single-operator commodity cryptojacking operation captured across two hosts. Its own ledgers claim roughly 7,145 successes; independent evidence covers seven hosts. The gap between the two is the finding.",
      "content_text": "A self-branded, single-operator commodity cryptojacking operation captured across two hosts. Its own ledgers claim roughly 7,145 successes; independent evidence covers seven hosts. The gap between the two is the finding.",
      "date_published": "2026-07-26T00:00:00+00:00",
      "date_modified": "2026-07-26T00:00:00+00:00",
      "image": "https://the-hunters-ledger.com/assets/images/cards/gocloud-multiservice-cryptojacking-149-28-112-221.png",
      "tags": ["Cryptojacking"],
      "authors": [{ "name": "Joseph Harrison", "url": "https://the-hunters-ledger.com/about-me/" }]
    },
    {
      "id": "https://the-hunters-ledger.com/reports/multivector-ecommerce-rce-toolkit-192-3-1-116/",
      "url": "https://the-hunters-ledger.com/reports/multivector-ecommerce-rce-toolkit-192-3-1-116/",
      "title": "Enough to Be Dangerous: The Mechanics of an LLM-Assisted Intrusion Campaign",
      "summary": "An exposed staging directory shows how an ordinary operator now runs an intrusion campaign, with scores of probably-generated attack scripts, an off-the-shelf agentic-AI framework wired in as the console, and a defensive lesson in what actually stopped it.",
      "content_text": "An exposed staging directory shows how an ordinary operator now runs an intrusion campaign, with scores of probably-generated attack scripts, an off-the-shelf agentic-AI framework wired in as the console, and a defensive lesson in what actually stopped it.",
      "date_published": "2026-07-21T00:00:00+00:00",
      "date_modified": "2026-07-21T00:00:00+00:00",
      "image": "https://the-hunters-ledger.com/assets/images/cards/multivector-ecommerce-rce-toolkit-192-3-1-116.png",
      "tags": ["Credential and Data Theft"],
      "authors": [{ "name": "Joseph Harrison", "url": "https://the-hunters-ledger.com/about-me/" }]
    },
    {
      "id": "https://the-hunters-ledger.com/reports/evilsoul-engine-stealer-maas-144-172-103-98/",
      "url": "https://the-hunters-ledger.com/reports/evilsoul-engine-stealer-maas-144-172-103-98/",
      "title": "EvilSoul-Engine: A Brazilian Stealer-Builder Malware-as-a-Service",
      "summary": "Server-side teardown of the EvilSoul-Engine stealer-builder, a Brazilian Malware-as-a-Service factory that mass-produces uniquely-packed Discord, browser, and crypto-theft payloads with a working Chrome App-Bound-Encryption bypass and Microsoft Defender timing evasion.",
      "content_text": "Server-side teardown of the EvilSoul-Engine stealer-builder, a Brazilian Malware-as-a-Service factory that mass-produces uniquely-packed Discord, browser, and crypto-theft payloads with a working Chrome App-Bound-Encryption bypass and Microsoft Defender timing evasion.",
      "date_published": "2026-07-03T00:00:00+00:00",
      "date_modified": "2026-07-03T00:00:00+00:00",
      "image": "https://the-hunters-ledger.com/assets/images/cards/evilsoul-engine-stealer-maas-144-172-103-98.png",
      "tags": ["MaaS Operation"],
      "authors": [{ "name": "Joseph Harrison", "url": "https://the-hunters-ledger.com/about-me/" }]
    },
    {
      "id": "https://the-hunters-ledger.com/reports/kaido-quasar-rat-144-172-109-203/",
      "url": "https://the-hunters-ledger.com/reports/kaido-quasar-rat-144-172-109-203/",
      "title": "KAIDO: A Brazilian Quasar-Fork RAT with Hidden-Desktop Session Hijacking",
      "summary": "KAIDO is a rebranded 64-bit Quasar RAT fork operated by a named Brazilian actor. Its Hidden-VNC module clones a victim's browser profile to drive their live, authenticated session on an invisible desktop, defeating device-trust and most 2FA. The C2 was live with May-2026 samples.",
      "content_text": "KAIDO is a rebranded 64-bit Quasar RAT fork operated by a named Brazilian actor. Its Hidden-VNC module clones a victim's browser profile to drive their live, authenticated session on an invisible desktop, defeating device-trust and most 2FA. The C2 was live with May-2026 samples.",
      "date_published": "2026-07-03T00:00:00+00:00",
      "date_modified": "2026-07-03T00:00:00+00:00",
      "image": "https://the-hunters-ledger.com/assets/images/cards/kaido-quasar-rat-144-172-109-203.png",
      "tags": ["Remote Access Trojan"],
      "authors": [{ "name": "Joseph Harrison", "url": "https://the-hunters-ledger.com/about-me/" }]
    },
    {
      "id": "https://the-hunters-ledger.com/reports/flaskc2-postex-toolkit-67-215-232-25/",
      "url": "https://the-hunters-ledger.com/reports/flaskc2-postex-toolkit-67-215-232-25/",
      "title": "Flask C2 & MSSQL CLR Backdoor on a Windows Post-Exploitation Staging Host",
      "summary": "A live single-host IIS/MSSQL post-exploitation staging operation pairing a bespoke Flask C2 beacon API with a sandbox-evading custom MSSQL CLR reverse-shell backdoor and a public SeImpersonate-to-Active-Directory escalation kit.",
      "content_text": "A live single-host IIS/MSSQL post-exploitation staging operation pairing a bespoke Flask C2 beacon API with a sandbox-evading custom MSSQL CLR reverse-shell backdoor and a public SeImpersonate-to-Active-Directory escalation kit.",
      "date_published": "2026-06-12T00:00:00+00:00",
      "date_modified": "2026-06-12T00:00:00+00:00",
      "image": "https://the-hunters-ledger.com/assets/images/cards/flaskc2-postex-toolkit-67-215-232-25.png",
      "tags": ["Post-Exploitation Toolkit"],
      "authors": [{ "name": "Joseph Harrison", "url": "https://the-hunters-ledger.com/about-me/" }]
    },
    {
      "id": "https://the-hunters-ledger.com/reports/ai-agent-frameworks-2026-05-23/",
      "url": "https://the-hunters-ledger.com/reports/ai-agent-frameworks-2026-05-23/",
      "title": "Multi-Actor AI-Agent Framework Abuse: 8 Operators Integrating AI CLIs into Offensive Workflows",
      "summary": "Parent report of a six-report series documenting 8 independent threat operators integrating AI-agent CLIs (Gemini CLI, Claude Code, Atlassian Rovodev, OpenClaw, Cursor IDE) into offensive workflows, observed through open-directory exposures. Five novel TTPs, six UTA designations, one named-actor HIGH attribution (Vova75Rus), and a GitHub Trust & Safety Tier-0 disposition outcome.",
      "content_text": "Parent report of a six-report series documenting 8 independent threat operators integrating AI-agent CLIs (Gemini CLI, Claude Code, Atlassian Rovodev, OpenClaw, Cursor IDE) into offensive workflows, observed through open-directory exposures. Five novel TTPs, six UTA designations, one named-actor HIGH attribution (Vova75Rus), and a GitHub Trust & Safety Tier-0 disposition outcome.",
      "date_published": "2026-06-04T00:00:00+00:00",
      "date_modified": "2026-06-04T00:00:00+00:00",
      "image": "https://the-hunters-ledger.com/assets/images/cards/ai-agent-frameworks-2026-05-23.png",
      "tags": ["AI-Augmented Operations"],
      "authors": [{ "name": "Joseph Harrison", "url": "https://the-hunters-ledger.com/about-me/" }]
    },
    {
      "id": "https://the-hunters-ledger.com/reports/korean-claude-openclaw-221.150.15.104/",
      "url": "https://the-hunters-ledger.com/reports/korean-claude-openclaw-221.150.15.104/",
      "title": "Korean Claude Code + OpenClaw Operator (221.150.15.104) - Attacker-Customized AI-Agent Permission Allowlist",
      "summary": "Capsule sub-report (Case 4 of the AI-Agent-Frameworks investigation): a Korean-language operator's attacker-customized ~/.claude/settings.local.json permission allowlist that pre-approves the OpenClaw install-and-run chain, recovered from an open-directory exposure (221.150.15.104, Korea Telecom). UTA-2026-015.",
      "content_text": "Capsule sub-report (Case 4 of the AI-Agent-Frameworks investigation): a Korean-language operator's attacker-customized ~/.claude/settings.local.json permission allowlist that pre-approves the OpenClaw install-and-run chain, recovered from an open-directory exposure (221.150.15.104, Korea Telecom). UTA-2026-015.",
      "date_published": "2026-05-27T00:00:00+00:00",
      "date_modified": "2026-05-27T00:00:00+00:00",
      "image": "https://the-hunters-ledger.com/assets/images/cards/korean-claude-openclaw-221.150.15.104.png",
      "tags": ["AI-Augmented Operations"],
      "authors": [{ "name": "Joseph Harrison", "url": "https://the-hunters-ledger.com/about-me/" }]
    },
    {
      "id": "https://the-hunters-ledger.com/reports/rovodev-mirai-matrix-c2-87.106.143.220/",
      "url": "https://the-hunters-ledger.com/reports/rovodev-mirai-matrix-c2-87.106.143.220/",
      "title": "Rovodev AI Co-Authored Mirai Variant + Matrix C2 Framework — UTA-2026-014 (Pandora 11-Arch IoT Botnet + DDoS-as-a-Service)",
      "summary": "Technical analysis of an English-speaking Hybrid AI-augmented operator who combined Atlassian Rovodev AI co-authoring with a downstream Pandora-Mirai 11-architecture IoT botnet and a 13-attack-method Matrix C2 framework, productized as a Discord-fronted DDoS-as-a-Service. First publicly documented Rovodev offensive-use case; AI-Generated Offensive Code Structural Signature confirmed DEFINITE for its universal subset via cross-3-operator validation. UTA-2026-014, first public attribution.",
      "content_text": "Technical analysis of an English-speaking Hybrid AI-augmented operator who combined Atlassian Rovodev AI co-authoring with a downstream Pandora-Mirai 11-architecture IoT botnet and a 13-attack-method Matrix C2 framework, productized as a Discord-fronted DDoS-as-a-Service. First publicly documented Rovodev offensive-use case; AI-Generated Offensive Code Structural Signature confirmed DEFINITE for its universal subset via cross-3-operator validation. UTA-2026-014, first public attribution.",
      "date_published": "2026-05-26T00:00:00+00:00",
      "date_modified": "2026-05-26T00:00:00+00:00",
      "image": "https://the-hunters-ledger.com/assets/images/cards/rovodev-mirai-matrix-c2-87.106.143.220.png",
      "tags": ["AI-Augmented Operations"],
      "authors": [{ "name": "Joseph Harrison", "url": "https://the-hunters-ledger.com/about-me/" }]
    },
    {
      "id": "https://the-hunters-ledger.com/reports/ghost-cryptojacker-vova75rus-77.110.96.200/",
      "url": "https://the-hunters-ledger.com/reports/ghost-cryptojacker-vova75rus-77.110.96.200/",
      "title": "GHOST Cryptojacker Kit Family — Vova75Rus Kit-Author Supply Chain",
      "summary": "End-to-end technical analysis of the GHOST cryptojacker kit, a 4-tier supply chain operation authored by Vova75Rus targeting exposed ComfyUI/GPU-cloud hosts with a userland LD_PRELOAD rootkit, dual-Telegram supply-chain monitoring, and a GitHub Trust & Safety Tier-0 disposition outcome.",
      "content_text": "End-to-end technical analysis of the GHOST cryptojacker kit, a 4-tier supply chain operation authored by Vova75Rus targeting exposed ComfyUI/GPU-cloud hosts with a userland LD_PRELOAD rootkit, dual-Telegram supply-chain monitoring, and a GitHub Trust & Safety Tier-0 disposition outcome.",
      "date_published": "2026-05-25T00:00:00+00:00",
      "date_modified": "2026-05-25T00:00:00+00:00",
      "image": "https://the-hunters-ledger.com/assets/images/cards/ghost-cryptojacker-vova75rus-77.110.96.200.png",
      "tags": ["Cryptojacking"],
      "authors": [{ "name": "Joseph Harrison", "url": "https://the-hunters-ledger.com/about-me/" }]
    },
    {
      "id": "https://the-hunters-ledger.com/reports/turkish-arpa-openclaw-state-insurer-209.38.205.158/",
      "url": "https://the-hunters-ledger.com/reports/turkish-arpa-openclaw-state-insurer-209.38.205.158/",
      "title": "Turkish ARPA Operator — AI-Augmented State-Insurer Observability Compromise + Insider Recruitment Artifact (UTA-2026-013)",
      "summary": "Technical analysis of an active compromise of a state-affiliated Turkish financial-sector organization: a Turkish-speaking operator weaponizes the OpenClaw AI agent platform into a custom analytics platform (ARPA) to harvest the victim's enterprise observability stack across four stolen sources (IBM Instana + SolarWinds Orion + Zabbix + VMware Aria), and authors Turkish-language insider-recruitment documentation to an in-network Windows AD user. UTA-2026-013, first public attribution.",
      "content_text": "Technical analysis of an active compromise of a state-affiliated Turkish financial-sector organization: a Turkish-speaking operator weaponizes the OpenClaw AI agent platform into a custom analytics platform (ARPA) to harvest the victim's enterprise observability stack across four stolen sources (IBM Instana + SolarWinds Orion + Zabbix + VMware Aria), and authors Turkish-language insider-recruitment documentation to an in-network Windows AD user. UTA-2026-013, first public attribution.",
      "date_published": "2026-05-25T00:00:00+00:00",
      "date_modified": "2026-05-25T00:00:00+00:00",
      "image": "https://the-hunters-ledger.com/assets/images/cards/turkish-arpa-openclaw-state-insurer-209.38.205.158.png",
      "tags": ["AI-Augmented Operations"],
      "authors": [{ "name": "Joseph Harrison", "url": "https://the-hunters-ledger.com/about-me/" }]
    },
    {
      "id": "https://the-hunters-ledger.com/reports/russian-gemini-credential-mill-213.165.51.115/",
      "url": "https://the-hunters-ledger.com/reports/russian-gemini-credential-mill-213.165.51.115/",
      "title": "Russian Gemini CLI Credential Mill — UTA-2026-012 / US Healthcare Provider Compromise",
      "summary": "End-to-end technical analysis of a Russian-native AI-augmented cybercrime operator (UTA-2026-012 / Trend Micro 'bandcampro') running a Gemini-CLI-orchestrated credential mill against a US healthcare victim, with three novel TTP anchors: AI Operator Handoff Documents, LLM-Personalized Credential Mutation, and an operator-built unauthenticated Python-stdlib C2.",
      "content_text": "End-to-end technical analysis of a Russian-native AI-augmented cybercrime operator (UTA-2026-012 / Trend Micro 'bandcampro') running a Gemini-CLI-orchestrated credential mill against a US healthcare victim, with three novel TTP anchors: AI Operator Handoff Documents, LLM-Personalized Credential Mutation, and an operator-built unauthenticated Python-stdlib C2.",
      "date_published": "2026-05-25T00:00:00+00:00",
      "date_modified": "2026-05-25T00:00:00+00:00",
      "image": "https://the-hunters-ledger.com/assets/images/cards/russian-gemini-credential-mill-213.165.51.115.png",
      "tags": ["AI-Augmented Operations"],
      "authors": [{ "name": "Joseph Harrison", "url": "https://the-hunters-ledger.com/about-me/" }]
    },
    {
      "id": "https://the-hunters-ledger.com/reports/opendirectory-216-126-227-49-cve-2026-41940-cpanel-harvester-20260517/",
      "url": "https://the-hunters-ledger.com/reports/opendirectory-216-126-227-49-cve-2026-41940-cpanel-harvester-20260517/",
      "title": "CVE-2026-41940 cPanel Harvester Toolkit — 216.126.227.49",
      "summary": "Detailed profile of a financially-motivated operator weaponizing CVE-2026-41940 (cPanel CRLF auth bypass, CVSS 9.8) with a 45-file custom Python/Bash credential-harvesting toolkit, a live Flask C2 dashboard, and a Parklogic TDS monetization layer spanning 17+ operator-controlled domains.",
      "content_text": "Detailed profile of a financially-motivated operator weaponizing CVE-2026-41940 (cPanel CRLF auth bypass, CVSS 9.8) with a 45-file custom Python/Bash credential-harvesting toolkit, a live Flask C2 dashboard, and a Parklogic TDS monetization layer spanning 17+ operator-controlled domains.",
      "date_published": "2026-05-17T00:00:00+00:00",
      "date_modified": "2026-05-17T00:00:00+00:00",
      "image": "https://the-hunters-ledger.com/assets/images/cards/opendirectory-216-126-227-49-cve-2026-41940-cpanel-harvester-20260517.png",
      "tags": ["Exploitation Campaign"],
      "authors": [{ "name": "Joseph Harrison", "url": "https://the-hunters-ledger.com/about-me/" }]
    },
    {
      "id": "https://the-hunters-ledger.com/reports/inkognito-russian-vpn-phishing-185-221-196-118-20260516/",
      "url": "https://the-hunters-ledger.com/reports/inkognito-russian-vpn-phishing-185-221-196-118-20260516/",
      "title": "Inkognito — Russian-Speaking Multi-Product Fraud Operator (INK VPN, INK Lens 467+ Brand-Impersonation Phishing Library, BEC Burn Domains, CryptOne Fake Exchange)",
      "summary": "Inkognito is a Russian-speaking multi-product fraud operator that has run continuously for nearly three years. The operator pairs a real commercially-billed VPN service with a 467+ brand-impersonation phishing subdomain library targeting US banking, enterprise SaaS, Chinese internet giants, and Russian telecom. Apex chameleon-decoy tradecraft, an 11-minute domain-to-live deployment pipeline, and infrastructure spanning two sanctioned bulletproof hosters (Aeza, Stark/Worktitans) define the operator footprint. This is the first public cross-brand documentation of the Inkognito portfolio.",
      "content_text": "Inkognito is a Russian-speaking multi-product fraud operator that has run continuously for nearly three years. The operator pairs a real commercially-billed VPN service with a 467+ brand-impersonation phishing subdomain library targeting US banking, enterprise SaaS, Chinese internet giants, and Russian telecom. Apex chameleon-decoy tradecraft, an 11-minute domain-to-live deployment pipeline, and infrastructure spanning two sanctioned bulletproof hosters (Aeza, Stark/Worktitans) define the operator footprint. This is the first public cross-brand documentation of the Inkognito portfolio.",
      "date_published": "2026-05-16T00:00:00+00:00",
      "date_modified": "2026-05-16T00:00:00+00:00",
      "image": "https://the-hunters-ledger.com/assets/images/cards/inkognito-russian-vpn-phishing-185-221-196-118-20260516.png",
      "tags": ["Phishing and Fraud"],
      "authors": [{ "name": "Joseph Harrison", "url": "https://the-hunters-ledger.com/about-me/" }]
    },
    {
      "id": "https://the-hunters-ledger.com/reports/bellamain-turkish-phaas-79-137-192-3-20260516/",
      "url": "https://the-hunters-ledger.com/reports/bellamain-turkish-phaas-79-137-192-3-20260516/",
      "title": "BellaMain — Turkish Phishing-as-a-Service Panel with USOM Self-Monitor, Four-Bot Telegram C2, On-Demand TRUNCATE Anti-Forensics, and Wadanz Code-Author Signature",
      "summary": "BellaMain is an operator-developed Turkish Phishing-as-a-Service panel and matched seven-kit brand-impersonation bundle, recovered in full PHP source from an open directory on Aeza Group OFAC-sanctioned hosting. The panel ships first-class operator tradecraft rarely visible at the source layer: USOM (Turkey CERT) blocklist self-monitoring, four-bot Telegram C2 with identity-vs-card role separation, three Telegram-triggered TRUNCATE evidence-destruction commands, mysqldump-to-Telegram backup-as-exfil, a 70/30 TRX/TRON revenue split via live Binance TRXTRY rate conversion, invite-only operator gating with one-time-consume referral codes, and a code-level Wadanz developer signature. First public source-code disclosure for this PhaaS family. Tracked under UTA-2026-008.",
      "content_text": "BellaMain is an operator-developed Turkish Phishing-as-a-Service panel and matched seven-kit brand-impersonation bundle, recovered in full PHP source from an open directory on Aeza Group OFAC-sanctioned hosting. The panel ships first-class operator tradecraft rarely visible at the source layer: USOM (Turkey CERT) blocklist self-monitoring, four-bot Telegram C2 with identity-vs-card role separation, three Telegram-triggered TRUNCATE evidence-destruction commands, mysqldump-to-Telegram backup-as-exfil, a 70/30 TRX/TRON revenue split via live Binance TRXTRY rate conversion, invite-only operator gating with one-time-consume referral codes, and a code-level Wadanz developer signature. First public source-code disclosure for this PhaaS family. Tracked under UTA-2026-008.",
      "date_published": "2026-05-16T00:00:00+00:00",
      "date_modified": "2026-05-16T00:00:00+00:00",
      "image": "https://the-hunters-ledger.com/assets/images/cards/bellamain-turkish-phaas-79-137-192-3-20260516.png",
      "tags": ["Phishing and Fraud"],
      "authors": [{ "name": "Joseph Harrison", "url": "https://the-hunters-ledger.com/about-me/" }]
    }
  ]
}
