infomedia

Authors: Audra Campbell and Oscar Presnall
DarkTower identified and investigated the “Ghost Hacker’s Operating System” Telegram channel, operated by user @ghosthackerOS (ID: 848925336), who claims to be the creator of “the world’s most advanced spamming operating system” known as Ghost Hacker OS. Through Telegram-based collection and analysis of a tutorial video uploaded on 26MAR2026, DarkTower…

Maria Harika, James Hubner, Mitchell Riggan, Joseph Green

Introduction

On 09JAN2026, Scattered LAPSUS$ Hunters (SLSH) leaked a BreachForums (BF) user database containing over 320,000 user records on their Dedicated Leak Site (DLS). While the dataset was publicly released in JAN2026, analysis indicates the data originates from a breach that occurred in OCT2025. The JAN2026 leak is a high…

Trevor Wilson

Introduction

A Telegram Emoji Pack is a collection of custom static or animated images that users can add to the messenger to personalize their communication. Telegram Premium users are able to subscribe to exclusive packs with unique designs, while any user can view them in messages. Users can also create and upload their…

Gary Warner & Cameron Stirner

“Pet fraud”

Refers to internet scammers capitalizing on people using online resources to shop for a pet. The scammers will use advertisements that are often too good to be true to attract potential buyers. Once a victim has been lured into purchasing a pet from a fraudulent vendor, the fraudster…

An increasingly prevalent trend being used by fraud actors operating from Indian Call Centers is to send emails claiming that a charge is about to be debited from your account and that to stop the charge, a telephone number should be called.

Hurricane Ian Leads to Predictable FEMA Fraud
Threat Actors (TAs) are ready to take advantage of vulnerabilities as disasters strike and populations become more susceptible to potential fraud. A wave of actors was ready to take advantage of the FEMA disaster assistance program that was released 28SEP2022 after Hurricane Ian hit Florida. Not only have…

17MAY2022 – Gary Warner

This week the US Attorney’s Office in the Middle District of Florida announced that Glib Oleksandr Ivanov-Tolpintsev, a 28 year old hacker from Chernivtsi, Ukraine, would be sentenced to four years in prison for his role as a vendor on the xDedic Marketplace. The court documents don’t actually name xDedic regarding…

INTRODUCTION

DarkTower recently identified and has been monitoring the use of OTP bots, available for purchase in high-traffic Telegram fraud Group Chats.

FINDINGS

DarkTower identified several OTP bots circulating. The bots can be used to circumvent Two-Factor Authentication by sending false requests disguised as legitimate requests. The bots are primarily sold and operated through Telegram.

INTRODUCTION

A list of RedLine Stealer configurations was found on 19SEP2021 on Twitter, showing hashes, C2_proxy, and the encryption key. RedLine Stealer is a MaaS (Malware as a Service) found in forums and markets for sale.

FINDINGS

RedLine Stealer was first seen in 2020 and currently has active subscribers. RedLine Stealer is being sold as…

INTRODUCTION AND RECOMMENDATION

On 14MAY2021, Abidemi Rufai, a pandemic unemployment scammer from Lekki, Nigeria, was arrested at JFK airport as he attempted to leave the country. In the DOJ press release about the event we learned that he had “used variations of a single e-mail address in a manner intended to evade automatic detection by…