I started investigating a database seller on
@stealthmole_int.
A few hours later I was mapping a #Telegram and underground forum ecosystem.
#OSINT has a habit of changing the question you're trying to answer.
https://t.co/R1KgkblsUh
I found #Mindhunter in @stealthmole_int's #SuspectTracker and decided to map his digital footprint.
One username led to forum profiles, #Telegram accounts, historical identities, #BTC wallets and even a group accusing him of #scamming people.
https://t.co/OeSfqzjEzU
Can a threat actor truly hide? ๐ต๏ธโโ๏ธ
We tracked the digital trail of 'Mindhunter,' an underground actor active across multiple forums and Telegram. By correlating reused avatars, crypto wallets, and contact IDs, we uncovered a persistent, cohesive operation behind the shifting aliases.
Read the full investigation:
https://t.co/u0qeEKKE4z
#Cybersecurity #ThreatIntelligence #Infosec #Mindhunter #OSINT #StealthMole
5โญ Rating. Escrow. Affiliate commissions.
#MexicanMafia#DarkWeb marketplace looked like a conventional online business, except for what it claimed to sell.
We uncovered its mirrors, vendors, Bitcoin wallets & Telegram footprint using @stealthmole_int
https://t.co/w8OPRftUbg
Not every interesting finding is hidden.
Sometimes it's sitting on a #ransomware website, waiting for someone to ask, "What happens if I click this?"
That's how this week's #RansomHouse investigation started.
Read the full report on @stealthmole_int
https://t.co/CgCG4YKNiD
๐ StealthMole ร Palantir, D4D Hackathon Seoul has successfully concluded!
The D4D Hackathon Seoul, jointly hosted by StealthMole and Palantir, came to a successful close amid the participantsโ incredible passion and enthusiasm.
๐ July 3 (Fri)โJuly 5 (Sun), 2026
๐ป Intensive Build Session: July 4 (Sat), 09:00โJuly 5 (Sun), 16:00
During the hackathon, Palantirโs FDE team participated on-site, providing technical support and mentoring to the participants. Together with StealthMole, the teams worked on data-driven defense and security challenges using real-world OSINT, dark web, and threat intelligence data.
What stood out most was the participantsโ remarkable focus and dedication. They continued discussing, developing, and solving problems until 4 a.m., and even as the night grew late and fatigue began to set in, they never gave up and continued to do their very best, making the atmosphere even more intense and inspiring. ๐ช
Thanks to the efforts of all the participants, Palantirโs FDE team, and the StealthMole organizing team, this D4D Hackathon was able to conclude safely and successfully.
We sincerely thank everyone who joined us, and we hope that the experiences and ideas developed during this hackathon will lead to new possibilities in AI-driven defense, security, and threat intelligence.
We look forward to seeing you again at the next D4D Hackathon! ๐
๐ Seoul
๐ค StealthMole ร Palantir
๐ก๏ธ Data for Defense, Intelligence for Action
Our 21st OSINT Training program has officially wrapped up successfully ๐
Throughout the sessions, we saw incredible enthusiasm from all participants โ from real-world investigations to hands-on exercises using the StealthMole platform. The curiosity and energy that filled the room made this program even more meaningful ๐
This edition was extra special, as we also hosted our very first OSINT CTF Challenge. From June 22 to July 2, participants put their hard-earned skills to the test in a live, competitive setting.
โ Winners
๐ Overall 1st : leech1996 (Lee Chan-hwi, Cohort 5) โ Apple iPad (2025, A16) Wi-Fi 128GB
๐ฅ Cohort 21 1st (Overall 2nd) : yhseo (Seo Yong-ho, Cohort 21) โ Apple iPad (2025, A16) Wi-Fi 128GB
๐ฅ Cohort 21 2nd (Overall 3rd) : kyimaliaru (Park Tae-jun, Cohort 21) โ Apple Watch SE GPS 40mm
๐ฅ Cohort 21 3rd (Overall 4th) : seojunkim (Kim Seo-jun, Cohort 21) โ Apple AirPods 4
Congratulations to all our winners ๐
A special mention goes to Director Seo Yong-ho โ Cohort 21's 1st place and Overall 2nd โ who visited StealthMole in person to receive his Apple iPad. It was a pleasure to share such a rewarding moment together. Congratulations once again!
We hope the OSINT knowledge and practical skills gained through this program will bring real value to your work. Stay tuned for our upcoming trainings and workshops โ we look forward to seeing you at the next one! ๐ฐ๐ท
One thing that stood out?
The same #Sade โ Promise album artwork kept appearing across different platforms.
It wasn't important because it was @Sade.
It was important cause it became another reusable artifact that helped connect the same identity across multiple platforms.
I started investigating a database seller on
@stealthmole_int.
A few hours later I was mapping a #Telegram and underground forum ecosystem.
#OSINT has a habit of changing the question you're trying to answer.
https://t.co/R1KgkblsUh
@stealthmole_int For those wondering why we chose this image: this threat actor used it as their profile picture across multiple platforms. Itโs more than just an image, itโs a key investigative artifact that helps link activity across accounts.
Government-Related Dark Web and Deep Web Exposure Activity โ First Week of July 2026
The review identified 60 government-related exposure or disclosure events during the first week of July 2026, including 56 leak/sale postings and 4 ransomware-related disclosures involving government or public-sector entities.
Activity was geographically broad, spanning more than 20 countries/regions. The observed content concentrated in four main themes:
- Government database and document sales
- Public-sector data leak claims with stated record volumes
- Website compromise or โhackedโ claims
- Ransomware disclosure posts naming municipal victims
A small number of actors and posting patterns accounted for a significant share of the activity. Repeated reposting of the same military/intelligence-themed sale titles across multiple forums was a notable pattern, as were multiple Libya- and Indonesia-related listings.
Following #NEETLeak controversy, I used @stealthmole_int to see what was happening beyond the headlines.
I found several #Telegram channels, recurring operators, deleted accounts, and how historical #intelligence helped reconstruct the campaign.
https://t.co/iCxfvFcIFI
One thing I've learned from working on these investigations is that the first finding is rarely the interesting one.
The interesting part is seeing how everything connects.
That was definitely the case with #Anubis.
Read the report on @stealthmole_int
https://t.co/d7a4vWVIjT
You might have heard of #ChatGPT but have you ever heard of #CheatGPT?
Me neither.
I found it by accident on @stealthmole_int. A #Bitcoin wallet led me to a hacker chatbot.
And that wallet led me to a web of unexpected connections.
https://t.co/24XQbRPPXU
I started with a #darkweb platform and ended up mapping an entire ecosystem.
Following #Bitcoin wallets through @stealthmole_int uncovered links between #KidBin, #CheatGPT, and other platforms.
Sometimes the wallets tell a bigger story than the website.
https://t.co/oH9KUB4QkP
Everyone knows ChatGPT.
But have you heard of CheatGPT?
What appeared to be just another dark web AI chatbot turned out to be something much bigger.
By tracing cryptocurrency wallets, payment infrastructure, and contact identifiers, we uncovered unexpected links between CheatGPT, WormGPT, FraudGPT, and several other underground platforms.
Sometimes the most valuable intelligence isn't found on a website's front pageโit's hidden in the infrastructure behind it.
Our latest investigation is now live.
https://t.co/T1Zv9hCiLC
Note: When visiting this blog, you may see a "Sensitive Content" warning from Blogger. This warning is automatically generated by Google's systems based on the topics discussed on the site and does not necessarily indicate the presence of graphic or inappropriate material. Our content is intended for cybersecurity research, threat intelligence, and law enforcement support and reference purposes.
#CyberSecurity #DarkWeb #ThreatIntelligence #OSINT #AI
We traced the threat actor behind the defacement of Malaysia's Ministry of Health (MOH) website.
Our investigation found that the actor has been active on Telegram since 2024, participating in multiple channels related to hacking forums, web shells, spam, hacking tools, and data leaks.
We also observed that the actor changed usernames multiple times before recently adopting the alias "Mushr00w."
In addition, we identified past messages in which the actor used Turkish in a data leak tool channel, providing another potential lead for attribution.
Following the Money: Mapping KidBin's Cryptocurrency Infrastructure Across Darkweb
Note: When visiting this blog, you may see a "Sensitive Content" warning from Blogger. This warning is automatically generated by Google's systems based on the topics discussed on the site and does not necessarily indicate the presence of graphic or inappropriate material. Our content is intended for cybersecurity research, threat intelligence, and law enforcement support and reference purposes.
https://t.co/ZICHpxQpRb
๐ ๐๐ฎ๐ ๐ฎ ๐ถ๐ ๏ฟฝ๏ฟฝ๏ฟฝ๏ฟฝ๐ป ๐ณ๐๐น๐น ๐๐๐ถ๐ป๐ด ๐ฎ๐ ๐๐ป๐๐ฒ๐ฟ๐ป๐ฎ๐๐ถ๐ผ๐ป๐ฎ๐น ๐ฃ๐ผ๐น๐ถ๐ฐ๐ฒ ๐๐ ๐ฝ๐ผ ๐ฎ๐ฌ๐ฎ๐ฒ!
The best part of an event isn't the presentations. It's the conversations happening in between.
Day 2 has been full of great discussions, new connections, and live demos at the StealthMole booth. Thank you to everyone who's stopped by so far! ๐
If you're at the expo today, come visit us at ๐๐ผ๐ผ๐๐ต ๐๐ฎ๐ฏ. There's still plenty of time to connect, exchange ideas, and see StealthMole in action. ๐
See you there! ๐
#StealthMole #ZoomTechnologies #InternationalPoliceExpo #PoliceExpo2026 #CyberSecurity #ThreatIntelligence #OSINT #DigitalInvestigation #DarkWebIntelligence #IndiaCyberSecurity