The Digital Bloodline: Tracing Blood Tribe’s Network Across Telegram

Blood Tribe is a U.S.-based neo-Nazi and white supremacist organization founded in 2021 by former U.S. Marine and tattoo artist Christopher Pohlhaus, better known as “Hammer.” The group claims chapters across the United States and Canada and has built its identity around an explicitly white-supremacist worldview. Its stated objective is the creation of an all-white ethnostate through the removal of Jews and non-white minorities it considers enemies of the white race. Its ideological influences include Norse Paganism, Odinism or Wotanism, and esoteric Hitlerism.

The group's development has also been closely tied to efforts to build physical and online communities. Before Blood Tribe's wider expansion, Pohlhaus attempted to establish a white-supremacist camp on property he purchased in Springfield, Maine. The project ultimately failed, but Pohlhaus subsequently focused on expanding Blood Tribe's presence across social media and recruiting new members.

Ohio occupies an important place in that history. Blood Tribe's first public appearance took place in Wadsworth, Ohio, in March 2023, followed by further activity around LGBTQ+ events in Ohio and Wisconsin. The group later became prominent in the controversy surrounding Springfield, Ohio, in 2024, where Blood Tribe members participated in spreading racist claims about the city's Haitian community. Christopher Pohlhaus and Blood Tribe second-in-command Drake Berentz subsequently became defendants in a federal civil lawsuit brought by the City of Springfield and others.

The group's name itself, Blutstamm, is German for “Blood Tribe” and reflects the organization's use of German terminology and Nazi symbolism. Its imagery also incorporates Armanen runes, which Blood Tribe uses as part of its wider neo-Nazi and esoteric visual identity.

Against this background, the investigation focused not simply on Blood Tribe's public identity, but on how its digital presence was organized: where its channels led, how regional structures were connected, which identities appeared behind them, and what other forms of activity could be identified from the digital trail.

Christopher Alan Pohlhaus aka Hammer, Leader of Blood Tribe

Where the Investigation Started

The investigation began with a simple keyword search in StealthMole's Telegram Tracker:

  • Blood Tribe Ohio

The search returned a Telegram channel titled:

🩸 BLOOD TRIBE OHIO 🩸

  • Channel URL: https://t.me/bloodtribeohio
  • Channel ID: 1910294769

This became the starting point for the investigation.

Among the historical messages returned by StealthMole was a March 2023 post referring to “Hammer, Blood Tribe Ohio, and White Lives Matter” and celebrating their confrontation with opponents. Other captured material showed the channel being used to publish openly extremist content and to communicate with individuals discussing Blood Tribe's activities in Ohio.

One exchange was particularly revealing. An account identified as @Byehlik stated that they were in the Columbus Ohio chapter and challenged Blood Tribe Ohio to meet publicly. The account representing Blood Tribe Ohio responded that Columbus was “right where we're at” and invited the individual to name a time and place. The exchange provides evidence of an online interaction involving the Blood Tribe Ohio account and an individual claiming affiliation with the Columbus chapter. The claim of chapter membership, however, was made by @Byehlik and was not independently established by the screenshot.

Another historical post from the channel announced an upcoming rally and said that the group intended to gather “as many Nazis as we can.” The accompanying imagery contained Nazi symbolism and violent imagery.

The channel's historical statistics provided another indication of its reach. For the period 26 March–2 April 2023, StealthMole displayed:

  • 4.3K followers
  • +2.7K followers / +181.3%
  • 75.26% enabled notifications
  • 1.1K views per post
  • 11 shares per post

The associated growth chart covered 10 March–2 April 2023 and showed a sharp increase in followers during the period.

The same initial investigation also surfaced a 55-page federal court complaint:

  • gov.uscourts.ohsd.299994.1.0.pdf

The document relates to Case No. 3:25-cv-33 in the U.S. District Court for the Southern District of Ohio, Western Division, and names The Blood Tribe, Christopher Pohlhaus, Drake Berentz and John Does 1–7 as defendants. The plaintiffs include the City of Springfield, Ohio, Mayor Rob Rue, city officials and Springfield residents.

The complaint alleges a campaign of harassment and intimidation directed at people associated with Springfield's Haitian community. As a court complaint, however, these are allegations made by the plaintiffs and not findings established by the court.

The initial search therefore produced two important starting points: a dedicated Ohio Telegram channel with historical activity, and documentation showing that Blood Tribe's Ohio activity had subsequently become the subject of federal litigation.

Following the Messages Trail

Rather than stopping at the channel's public profile, the investigation moved deeper into its historical content using StealthMole’s Telegram Tracker. The search returned 952 messages.

  • Telegram Channel: 1910294769

The expanded dataset provided a much wider collection of identifiers and links.

One of the first important artifacts was:

  • B********M@protonmail.com

A message dated 30 January 2025 invited users who were “curious” to make contact through the address. The message was forwarded into the Blood Tribe Ohio channel from another Telegram source, meaning the email's presence in the channel is directly observable, but the forwarded origin should not automatically be treated as the email's operator.

The same channel history also contained references to Blood Tribe's wider online presence.

Among the identified links were:

  • Blood Tribe Gab: https://gab.com/B******e
  • Hammer Telegram: https://t.me/p********r
  • Hammer Gab: https://gab.com/BL******G
  • Hammer X: https://x.com/b*****g

A September 2024 forwarded post containing the Blood Tribe Gab account claimed that Blood Tribe was closely following events in Springfield, Ohio and claimed to have people on the ground and a network of local informants.

The channel also contained a February 2025 post instructing followers to follow Blood Tribe and its leader Chris Pohlhaus, also known as Hammer, across Telegram and X.

The 952-message history therefore changed the direction of the investigation. What initially appeared to be a single Ohio-focused channel was becoming a gateway to a much broader collection of accounts, platforms and regional structures.

When One Channel Points to Another

The next step was to take the known Blood Tribe Ohio URL and search it outside Telegram. It was searched in StealthMole's Dark Web Tracker.

  • https://t.me/bloodtribeohio

That pivot surfaced material hosted on I2P. One of the results was:

  • http://revx7if*************2.i2p/@TexasVet:6/Episode-114:3?nojs=1

The page was titled:

  • “THE FOURTEEN WORDS PODCAST EP. 114 - 6MAY2023 Hammer”

The I2P page provided an important new set of pivots. Under “Hammer's links”, it listed:

  • https://t.me/p***********er
  • https://t.me/bl***********o

The page also identified:

Blood Tribe Merch: D************books.com

Blood Tribe new members: https://t.me/+2B**********E5

Donation: https://givesendgo.com/b*********e

The Telegram invitation was later found to be expired, while the GiveSendGo campaign was unavailable when checked.

The same I2P material also linked to the Odysee account:

  • https://odysee.com/@Te*****6

A second I2P result, associated with @jqrcode, was titled:

  • “The Hammer Interview, BloodTribe - 5/6/2023 - TexasVET”

This result again contained the same links to the Blood Tribe Ohio Telegram channel, Odysee and the GiveSendGo campaign.

These findings were significant because the same Blood Tribe and Hammer identifiers were no longer confined to Telegram. They appeared within I2P-hosted material and associated media content.

The investigation also encountered a commenter using a highly extremist username on one of the I2P pages. The account's comment praised Hammer and invoked the group's ideological beliefs. This was retained as an observed interaction, but not treated as evidence that the commenter was a Blood Tribe member.

The I2P results also provided a potential commercial lead:

  • Di**********s Books

The page explicitly labeled Di*********books.com as “BloodTribe Merch.” This establishes the description used by the I2P content, but the page itself was not treated as independent proof that the site was operated by Blood Tribe.

Building the Map

The expired “Blood Tribe new members” invitation became the next investigative pivot.

  • https://t.me/+2BEbDMSzgMNmMmE5

The invitation appeared in several Blood Tribe-related Telegram channels.

One message from Blood Tribe Dixie directed prospective members toward the invitation and referred to the process of joining the group's wider structure.

From these references, the investigation uncovered a much larger regional network.

United States

Blood Tribe Dixie 

https://t.me/BTDIXIE 

T.me/dixiecamps

Blood Tribe Upper Midwest 

https://t.me/BTUPPERMIDWEST 

T.me/uppermidwestcamps

Blood Tribe Pacific Northwest 

https://t.me/BTPNW 

T.me/pnwcamps

Blood Tribe South Central 

T.me/BTSOUTHCENTRAL 

T.me/btohio

Blood Tribe Ohio 

T.me/BLOODTRIBEOHIO 

T.me/btohio

Blood Tribe New England 

T.me/BTNEWENGLAND 

T.me/necamps

Blood Tribe Southwest 

T.me/BLOODTRIBESW 

T.me/BloodTribeSouthWestCamps

Additional regional artifacts included:

https://t.me/Bl************al

https://t.me/B******W

Canada

Blood Tribe East Canada 

T.me/BTEASTCANADA 

T.me/eastcanadacamps

Blood Tribe West Canada 

T.me/BTWESTCANADA 

T.me/westcanadacamps

The same investigation also identified:

https://t.me/B*************OT

The regional naming pattern was reinforced by a captured map dividing the United States and Canada into Blood Tribe regions. The map displayed areas including PNW, Southwest, South, South Central, Ohio, Upper Midwest, New England, East Canada and West Canada.

The Telegram evidence and the map together provide a picture of an organization attempting to divide its presence geographically.

The distinction between the regional Blood Tribe channels and the associated “Camps” channels is also notable. The evidence does not establish that every regional channel was equally active or operational, but it does show a repeated organizational pattern: a Blood Tribe regional identity paired with a separate Camps-related identifier.

The evidence therefore moved beyond a single Ohio presence. It pointed toward a broader U.S.- and Canada-facing online structure with regional identities and recruitment-oriented spaces.

The People Behind the Addresses

The BL*******M@protonmail.com address provided another investigative pivot.

A search for the address in StealthMole's Telegram Tracker returned a Telegram identity associated with:

Nathaniel Higgers

  • Telegram ID: 5743881965
  • Username: @Y*********Nate
  • Bio: “Forehead Connoisseur”

The significance of the finding was not limited to the current profile.

StealthMole's historical results showed the same Telegram identity appearing under multiple names and usernames over time. The captured historical variants included Nathaniel Higgers, Herzog Higgers, and several different usernames, including @Y*******Nate and other highly extremist handles.

This historical variation is important because the Telegram ID remained the more useful identifier than any individual username.

The investigation also found a direct contextual connection between the email address and Blood Tribe's recruitment process. A HAMMER message dated 20 March 2024 stated that the group's Telegram vetting account had been banned and directed prospective members to:

  • B*********M@protonmail.com

The message instructed people seeking to join the group's “Camps” to use the email address for further instructions.

This was one of the clearest examples in the investigation of the value of historical identity data. A single current username would have provided only a snapshot; the historical Telegram records exposed changes that would otherwise be easy to miss.

The HAMMER Channel

The investigation then moved directly into the Telegram channel associated with HAMMER:

  • https://t.me/p************r
  • Channel ID: 1700136522

The channel became an important central pivot because its posts connected several of the artifacts already discovered.

The channel contained Blood Tribe-related links, recruitment material and references to other parts of the group's online ecosystem.

Among the identified artifacts were:

  • https://t.me/b*******ohio
  • https://t.me/Bl*********al
  • https://t.me/B****W
  • https://t.me/BT*******T

and:

  • https://gab.com/Bl*********Midwest

The channel also contained material directing followers to external platforms and accounts.

A January 2024 post linked to the older X/Twitter account:

  • https://twitter.com/hammer_pohlhaus/

A specific post was captured at:

  • https://twitter.com/hammer_pohlhaus/status/1749888513737359668

The January 2025 material instead showed the X identity:

  • Chris Pohlhaus: @blut_konig

The captured account contained Blood Tribe-related content and references to other far-right figures and accounts.

A separate December 2024 post from the same displayed identity contained explicit praise of Adolf Hitler and rejection of the historical defeat of Nazi Germany.

The investigation also identified another X account, which was suspended when checked.

  • https://x.com/blutstamm

The combination of Telegram links and cross-platform references showed that the HAMMER channel was not operating as an isolated communications point. It repeatedly directed followers toward Blood Tribe regional infrastructure, recruitment-related resources and external social platforms.

Merchandise, Weapons and the Money Trail

The investigation also uncovered evidence of activity extending beyond communication and recruitment.

Merchandise

The I2P material identified: Dissident Minds Books as “BloodTribe Merch.”

A separate HAMMER Telegram post later directed followers toward a Blood Tribe merchandise page:

  • https://www.thesh*******p.com/product/blood-tribe-blutstamm/

The post advertised new Blood Tribe shirts and directed users to the external store.

Weapons

Blood Tribe Ohio promoted content also contained imagery advertising a weapon.

The captured listing described a: “Black oak handle Sæx” with a 7.5-inch blade and a displayed price of $150.

The associated material directed prospective buyers toward and stated that payment was accepted through Cash App.

  • vol***********e@protonmail.com

These artifacts demonstrate the circulation of weapon-related commercial content through the Blood Tribe Ohio ecosystem. They do not, without further evidence, establish who manufactured or operated the associated sales infrastructure.

Fundraising

The previously identified fundraising page was:

  • https://givesendgo.com/bloodtribe

When checked, the page displayed: “This fundraiser is not active.”

The historical I2P material nevertheless preserved the URL as part of the Blood Tribe-related online ecosystem.

More importantly, HAMMER's Telegram channel contained a message providing a Bitcoin address in the context of supporting Blood Tribe.

  • BTC address: 3My2**************************wau

StealthMole's Crypto Tracker was then used to investigate the address. The blockchain displayed an amount of 11.26697765 BTC and a Graylist classification.

  • 4 transactions
  • 2 incoming transactions
  • 2 outgoing transactions
  • 0.039062 BTC received
  • 0.039062 BTC sent
  • Current balance: 0 BTC
  • First transaction: 15 April 2023
  • Last transaction: 3 November 2023

The address-level blockchain view records only 0.039062 BTC received and sent, while the Crypto Tracker displayed the much larger 11.26697765 BTC figure in its transaction visualization. Because the available evidence does not establish exactly what the larger figure represents, it should not be interpreted as the amount transferred by the Blood Tribe-associated address.

The external blockchain view also displayed a BetVIP label associated with the destination. That label was not treated as evidence of any relationship between BetVIP and Blood Tribe.

The strongest conclusion from the financial investigation is therefore narrower: a Bitcoin address was publicly provided through HAMMER's channel in connection with support for Blood Tribe, and StealthMole was able to trace its historical blockchain activity.

The Names Change, the Network Remains

The final stage of the investigation brought together the cross-platform identity artifacts that had appeared throughout the earlier searches.

The older X account was directly referenced from HAMMER's Telegram channel.

  • https://twitter.com/hammer_pohlhaus/

The later X identity appeared in captured material identifying the account as Chris Pohlhaus.

  • https://x.com/blut_konig/

The investigation also identified, which was suspended when checked.

  • https://x.com/blutstamm

On Gab, the investigation found:

  • https://gab.com/Bl*****e
  • https://gab.com/BL*****G
  • https://gab.com/Bl**********Midwest

These accounts appeared through Blood Tribe-related Telegram and I2P content rather than being discovered independently.

The cross-platform evidence also highlighted why historical preservation matters in extremist investigations. Accounts can disappear, usernames can change and channels can become inaccessible. In this case, StealthMole's historical records preserved references to identities and links that were no longer necessarily available when revisited.

The investigation therefore did not depend on any single live account remaining online. Instead, the relationships between the historical artifacts provided the investigative value.

Conclusion

The investigation began with a single search term and an Ohio Telegram channel. By following the artifacts surfaced through that channel, the picture expanded into a network spanning regional Telegram channels, “Camps,” recruitment and vetting mechanisms, historical identities, social-media accounts, I2P-hosted content, merchandise, weapons-related material and financial-support infrastructure.

The most significant finding is not simply that Blood Tribe maintained an online presence. It is that its digital footprint was distributed across multiple interconnected layers.

At the center of the investigation was the Blood Tribe Ohio channel. From there, historical messages exposed links to HAMMER and other Blood Tribe accounts. The Dark Web Tracker extended those connections into I2P content. The I2P material exposed recruitment and fundraising artifacts, which in turn led back to Telegram. The expired recruitment invitation opened another path into regional channels and Camps. Finally, searches for individual identifiers such as B*********M@protonmail.com produced historical account data that added an identity layer to the network.

The resulting picture is therefore one of a distributed digital ecosystem rather than a single Telegram channel.

StealthMole's historical preservation was particularly important in reconstructing that ecosystem. Several of the artifacts identified during the investigation were no longer fully accessible when revisited, including the expired Telegram recruitment invitation, the inactive GiveSendGo campaign and the suspended @blutstamm X account. The ability to locate historical references allowed those artifacts to remain part of the investigation even after their original availability changed.

Editorial Note

Dark-web and extremist-network investigations rarely provide absolute attribution. Accounts change usernames, content is forwarded between channels, platforms disappear and third-party infrastructure can be referenced without being controlled by the group being investigated. The findings in this report should therefore be understood according to the strength of each individual artifact and the relationships that can be demonstrated between them.

In this case, StealthMole's ability to preserve historical Telegram content and correlate identifiers across Telegram, I2P, social platforms and blockchain data helped turn a single search result into a much broader picture while still leaving room for uncertainty where the evidence does not support a definitive conclusion.

To access the unmasked report or full details, please reach out to us separately.

Contact us: support@stealthmole.com

Labels: ,

“Choices Have Consequences”: Inside The Night Hunters’ Retaliatory Cyber Campaign

The Night Hunters present themselves as more than a typical hacktivist group. Emerging around 2022 and identifying strongly with India, the group has built its online identity around a simple idea: retaliation. Its messaging consistently mixes cyber activity with nationalist language, particularly the recurring use of “Jai Hind” and statements portraying attacks as a response to hostile activity against India. The group is primarily associated with an anti-Pakistan stance, while its public messaging has also shown support for Israel and hostility toward actors it considers opposed to India.

What makes the Night Hunters worth examining is the gap between that straightforward ideological messaging and the range of activity attributed to the group. Their operations have involved claimed breaches, database and document leaks, website compromises and attacks against industrial control systems, while their public channels have been used to publish screenshots, videos and other material presented as proof of access. Their targeting has not remained limited to one country either, with activity linked to Pakistan as well as infrastructure in countries such as Indonesia and Malaysia.

By August 2026, however, the group’s Telegram presence had become fragmented. Several of the channels referenced in its own network were no longer accessible, while replacement and redirection channels continued to circulate its material and connect followers to other hacktivist communities. This raised a more interesting question than simply what the Night Hunters had claimed to breach: how much of the group’s wider online network could still be traced after parts of its original infrastructure disappeared?

The First Signs of Activity

The investigation started with StealthMole's Defacement Alert module. A search for The Night Hunters returned seven victims, giving us the first concrete indication of the group's activity rather than relying on its own descriptions of who it was or what it had done.

The results covered activity between May 2024 and January 2025 and showed that the group had been associated with defacements across several countries. The visible results included targets in Pakistan, Bangladesh, Colombia and the United States.

One example from the results was a defaced Bangladeshi website:

  • http://ha***********school.edu.bd/

What makes this useful is that the StealthMole result gives us something we can actually follow, a specific URL, a named actor and a detection timestamp. Other entries in the same result set pointed to targets in the United States, Colombia, Pakistan and Bangladesh, showing that the group's claimed activity had already crossed borders well before the August 2026 messaging that became the focus of the investigation.

What stood out at this stage was not simply the number of websites. The alerts showed that The Night Hunters was already appearing as a named actor across separate incidents and targets, giving us a starting point from which to investigate the group beyond individual defacement events. But the alerts could only tell us where activity had been observed. They did not explain how the group communicated, how operations were announced, or how different incidents might fit together.

That meant the next step was to follow the group itself.

Following the Telegram Trail

After the defacement search, the next step was to search “The Night Hunters” in StealthMole's Telegram Tracker. This opened up a much broader trail. Rather than finding one clean, permanent channel, the investigation uncovered a collection of channels, groups, redirects and historical references. Some were still available; others had become inaccessible. That fragmentation turned out to be useful in its own way, because surviving references allowed us to follow where the group's audience and communications had moved.

The Telegram identifiers encountered during the investigation included:

  • @op********y
  • @n********op
  • @hack******ic
  • night*******og
  • Night********ic

There was also an important active channel that needs to be distinguished from the expired ones:

  • Telegram: https://t.me/+eS***********U1
  • X account: https://x.com/Th******H

This channel was still active when captured, so it should not be treated as an archived or offline source. At the same time, several other links encountered during the investigation were no longer accessible:

  • https://t.me/+DCO_JVFORXI5ZGQ1
  • https://t.me/+c9c8pNElK21iMWNl

This is where StealthMole's historical visibility becomes particularly useful. Even when individual Telegram destinations were no longer available, references to them remained visible elsewhere.

One example was Night Hunters Main Channel Redirection, where a pinned message directed users toward the group's main channel and chat group. The same material contained another Telegram invite:

  • https://t.me/+vb***********Q1

The messages themselves added another layer to the investigation. Among the surviving material were short operational statements such as:

  • “OP_PRALAY COMING”
  • “Be Ready For Tomorrow”
  • “United We Stand Divided We Fall”

The August 4–15 messaging was particularly notable because the posts moved beyond general slogans and referred to targets and planned activity. The timing also coincided with the group's broader Independence Day messaging, which became more apparent once its other social-media accounts were examined.

The active Night Hunters channel also contained posts discussing alleged compromises of government and infrastructure systems. One visible post referred to Pakistan Metrological Department access credentials, while another discussed .gov.bd infrastructure and DDoS activity.

The Telegram material therefore gave us something the defacement alerts could not: a view into how the group communicated before, during and after its claimed operations.

And because parts of that Telegram presence had already disappeared, the investigation became less about finding a single channel and more about piecing together the surviving trail.

Network Hidden in Plain Sight

The Telegram trail eventually led back to the group's social-media footprint.

The Instagram account identified during the investigation was:

  • Instagram: the*********5
  • Followers shown: 375
  • Following: 9
  • Display name: THE NIGHT HUNTERS 🇮🇳
  • Bio included: “Hunting in the shadows of cyberspace”, “Intelligence • Research • Operations”, and “No noise. No limits”
  • Telegram link in the profile: https://t.me/+DCO_JVFORXI5ZGQ1

The account used the same distinctive green Night Hunters emblem seen across the Telegram material.

The X account provided another direct point of comparison:

  • X: @The*******H
  • Display name: The Night Hunters
  • 18 posts shown in the captured profile
  • 67 followers
  • Telegram link displayed on the profile: https://t.me/+c9c8pNElK21iMWNl

The X profile described itself simply as: “If wanna know us Google us”

Together, the Instagram and X accounts provided an important connection between the group's public-facing identity and the Telegram ecosystem. The Telegram channels were not operating in complete isolation; the same branding, names and links were being used to move users between platforms.

The investigation also encountered a number of other Telegram communities and identities through these links and forwarded material. One example was a channel titled Night Hunters Main Channel Redirection, while another a group profile for FIaxB8M, using the handle @FlA**********nt, with 664 members.

The Night Hunters also listed supposed “allied teams” and “comrades.” The message referenced:

  • 7 Proxies
  • Team UCC
  • SoloAPT
  • Crack Codes
  • GodFather
  • SoLVEIG
  • Teo Miro
  • Mr Anonymous
  • Cryptic@1337
  • ItachiH4X
  • BlurryFace98
  • Odiyan911
  • Krishna404
  • IndixFalcon
  • Mynk
  • King Renger
  • Jeager
  • Red Eagles
  • Kochimona

The important point is that these names were presented by the Night Hunters themselves as allies or comrades. That is evidence of a claimed relationship, not independent confirmation that every named account or group actually collaborated with them.

The same distinction matters when looking at forwarded content. For example, one Night Hunters-related Telegram screenshot contained material forwarded from “TeAm UcC OpErAtIoNs”, alongside logos of several hacktivist groups. Again, this establishes that the material circulated within the ecosystem; it does not by itself establish operational control or direct collaboration.

This distinction becomes increasingly important as we move from the group's communications to its actual attack claims.

From Retaliation to Action

The Telegram material contained a number of claims involving government institutions, databases and industrial infrastructure. These claims provide the clearest picture of what The Night Hunters wanted its audience to believe it had achieved.

One of the most concrete examples concerned Pakistan Railways. A post presented SQL database files and identified the target as Pakistan Railways.

The files shown were:

  • ncs_railway_uat_b_u.sql
  • ncs_railway2.sql

The accompanying text stated that the material included land assets, user accounts, administrative modules and internal workflows.

Another post claimed a breach of a Pakistan Government SQL Server and described the material as office documents. Additional material in the investigation referenced the Pakistan Military Accounts Department, including a claimed 88-page PDF containing stolen data.

A separate post presented an alleged AJ&K Official Portal COVID-19 database leak. The post claimed that the database contained patient-related information and displayed server information alongside the claim.

The group's activity was not limited to conventional databases and websites.

One post claimed access to the Water Consumption Server (PLC) of the Dhaka Water Supply and Sewerage Authority (DWASA). The accompanying screenshot showed a water-management interface containing pump and system readings.

Another post claimed access to Tenaga Nasional Berhad (TNB) infrastructure in Malaysia. The screenshot showed an industrial control interface, while the accompanying statement claimed that the group had gained access to PLC infrastructure associated with the electricity provider.

The group framed the Malaysia operation explicitly as retaliation. Its message stated that the action was carried out in response to attacks by Malaysian actors targeting Indian servers, websites and networks, while insisting that the purpose was to send a warning rather than cause destruction.

The investigation also identified a claimed operation against an Indonesian solar-energy monitoring system, accompanied by a proof-of-concept video.

These incidents show why the Night Hunters' activity cannot be understood purely through its website defacements. Its own posts describe a much broader range of activity, extending from websites and SQL databases to government systems and industrial-control environments.

The important qualification is that these are not all independently verified intrusions. In several cases, the strongest evidence available to us is the group's own publication of screenshots, files or videos claiming successful access.

The Message Behind the Breaches

The technical claims make more sense when read alongside the group's messaging.

The Night Hunters repeatedly presents its activity through an explicitly Indian nationalist lens. “Jai Hind” appears across its Telegram material and social-media branding, while its posts frame attacks as responses to what the group describes as hostile activity against India.

The strongest example came around India's Independence Day.

In one message, the group stated:

  • “On India's Independence Day, we made our move.”

The post then described the claimed TNB operation and linked it directly to what the group portrayed as repeated attacks by Malaysian actors against Indian digital infrastructure.

A similar retaliatory framing appeared in the DWASA claim, where the group connected its alleged access to Bangladeshi cyber activity targeting Indian infrastructure.

This gives the group a consistent narrative: it does not present its attacks as random cybercrime. It presents them as retaliation and national defence.

That narrative is also visible in the group's broader language around Pakistan, Bangladesh and other countries it perceives as adversaries. The messaging repeatedly uses terms such as “anti-India groups”, while slogans such as “Jai Hind” and “Jai Bharat” reinforce the nationalist identity.

The Independence Day material also helps explain the significance of messages such as “OP_PRALAY COMING” and “Be Ready For Tomorrow.” Within the broader sequence of posts, these statements read less like generic promotional messages and more like attempts to build anticipation around upcoming activity.

There is therefore a clear relationship between the group's ideological narrative and its operational messaging: the political message provides the justification, while the breach claims are presented as proof that the group is acting on it.

How the Hunters Operate

Looking across the incidents rather than treating them individually reveals a fairly consistent pattern. The Night Hunters appear to use several different attack types rather than relying on a single technique. The activity documented in the investigation includes:

  • Website defacement
  • SQL/database compromise
  • Data and document leaks
  • Government-system breaches
  • Industrial-control/PLC access claims
  • Proof-of-concept videos
  • Public disclosure of alleged stolen information

The background intelligence associated with the group also identifies the use of tools such as SQLmap, Nikto, Wpseku and Sublist3r, alongside Weevely, GoldenEye, Hulk and Xerxes.

The significance is not that the group possesses an unusually exotic toolkit. The more interesting pattern is how it combines relatively recognizable offensive tools with public-facing hacktivist operations.

A claimed compromise is not simply kept private. It is turned into content: screenshots are published, database files are displayed, videos are released, targets are named, and political messaging is attached to the activity.

That creates a cycle:

target → claimed access → evidence or PoC → public announcement → political/retaliatory narrative.

The Telegram ecosystem appears to be an important part of that cycle. It provides the space for announcements, redirects, audience building and dissemination of claimed results, while Instagram and X extend the group's public identity beyond Telegram.

The group's apparent willingness to move between website defacement, database compromise and claimed ICS access also means that its activity should not be assessed solely through conventional hacktivist defacement metrics.

Conclusion

What began as seven StealthMole defacement alerts developed into a much broader picture of The Night Hunters.

The investigation moved from compromised websites to Telegram channels, from Telegram to Instagram and X, and from surviving channels to historical references left behind by parts of the group's disappearing infrastructure. That trail exposed more than a collection of attack claims. It showed how the group builds an identity, announces operations, mobilizes an audience and frames cyber activity as retaliation.

The group's own material points to a wide target set, including Pakistan, Bangladesh, Indonesia and Malaysia, and to an equally broad range of activity spanning website defacement, database and document leaks and claimed access to industrial-control systems.

At the same time, the investigation shows why hacktivist attribution needs to be handled carefully. Some relationships remain claims, some channels have disappeared, and several of the most serious operations are supported primarily by material published by the actor itself.

The strongest finding is therefore not any single breach claim. It is the consistency of the wider trail: the same identity, branding, platforms, messaging and operational narrative appearing across different sources and different periods of activity.

And that is what makes The Night Hunters worth following. The channel may change, a Telegram invite may expire, or an individual post may disappear but the wider trail can remain.

Editorial Note

Dark-web and cyber investigations rarely produce absolute attribution, and hacktivist groups in particular can blur the line between genuine activity, collaboration and public claims of responsibility. The Night Hunters case is a good example of why individual posts should not be viewed in isolation. Here, StealthMole's ability to connect current findings with historical Telegram activity, defacement records and cross-platform traces helped preserve a fragmented picture even when parts of the group's online presence were no longer accessible.

To access the unmasked report or full details, please reach out to us separately.

Contact us: support@stealthmole.com



Labels: ,

Inside ZeroDay Commerce: Tracing Mushr00w’s Webshell Network

Webshells have become a familiar commodity in underground cybercrime communities. Instead of having to compromise a server themselves, buyers can purchase access that is already available and use it for their own purposes. For sellers, the model is simple: find vulnerable or compromised systems, maintain access, and turn that access into something that can be sold repeatedly. Telegram has become one of the places where this market is openly promoted, with sellers advertising everything from individual shell access to higher-value access on specific domains.

This investigation began with activity linked to this wider ecosystem and gradually led toward a Telegram user. What initially appeared to be another account operating within the underground quickly opened into a broader picture involving shell sales, private communities, other operators, and relationships that were not always straightforward.

Using StealthMole, the investigation moved between technical detections, Telegram activity, channel memberships and associated identities to piece together that picture. The findings reveal more than a single seller advertising access. They show how webshells are marketed, how sellers build communities around those services, and how disputes, collaborations and new identities can leave additional traces behind.

The First Signs of Compromise

The first lead came from StealthMole’s Defacement Alert, where Mushr00w was listed in connection with the defacement of the two government websites: Malaysian and Ukrainian.

The defacements themselves provided the first real connection to the actor. The pages were signed “SERVER FUCKED BY MUSHROOW” and, more importantly, included a direct Telegram address:

  • http://t.me/M*****w

The pages also carried the familiar message, “We are Anonymous. We are Legion. We do not forgive. We do not forget. Expect us.” Alongside it were greetings to WebshellSR Famila, MeshSec, Illegalplatform.org and Roween. These names are part of the defacement content, but there is no evidence at this stage to say that they were working with Mushr00w.

The Telegram address gave the investigation its first clear pivot. Rather than following only the defaced websites, the username Mushr00w was directly searched into StealthMole’s Darkweb Tracker to see what was attached to the account behind it.

That search also brought up historical Zone-H records for the two incidents. The Malaysian defacement, where the archived page again carried “HACKED BY MUSHROOW” and the same Telegram address. The Ukrainian incident was similarly linked to Mushr00w in connection with the defacement.

  • http://zone-h.org/mirror/id/42570843
  • http://zone-h.org/mirror/id/42576330

The important part was not simply that the same name appeared twice. The defaced pages had given us a direct identifier that could be followed into Telegram. That was where the investigation moved from the websites themselves to the person operating behind the Mushr00w name.

The Door Marked ZeroDay

The Telegram link on the defaced pages provided the first direct route to Mushr00w. Running Mushr00w through StealthMole’s Telegram Tracker returned an account with the Telegram ID 6775881965 and the username @M*****w. The account had not always used that name. StealthMole’s historical indexing showed the same Telegram ID under several different usernames, giving us a much longer history to work with.

The account had previously appeared as @Lo****e, @Wiz****q, @Sur****a, @Raja_R33, @gh****e and @A*******z before settling on @M*****w. The historical snapshots also showed changes in the account’s display name, biography and profile image over time. For example, the account used the name R33 while operating as @Raja_R33 in October 2025, and later appeared as @Ah*******z before moving to @M*****w. The same Telegram ID ties these different usernames together, making the account history more useful than any single username on its own.

There were also some interesting changes in the account’s bio. On July 25, 2026, while using @M*******w, the bio read “im right here: T.me/Zer*******e”. That short line turned out to be the next important lead in the investigation. It pointed directly to a private Telegram community that was much more closely connected to Mushr00w’s activity.

StealthMole’s historical indexing also gave us a glimpse of activity that predated the current Mushr00w identity. In November 2025, the account was using @Ah*******z and posted a message in Turkish referring to arranging a bank loan of more than one million for a commission, finding people or a network able to get people to Europe, and meeting in Beyoğlu to begin immediately. The message is interesting as a potential language and geographic lead, but it does not by itself establish that the account holder was in Turkey or that they actually carried out any of the activities described.

The account history also contained other signs of underground activity. A September 2024 message under @Wiz*****q warned others about a supposed scammer, while another message from May 2026 asked whether anyone had a free WordPress exploit. These older messages were not enough on their own to explain who Mushr00w was, but they showed that the Telegram account had been active in underground conversations well before the current name appeared.

Inside the ZeroDay Counter

Following the link in Mushr00w’s Telegram bio led to ZeroDay Commerce, a private Telegram community with around 80 members. The group description leaves little doubt about what it is built around: “Digital marketing for SEO's / buy / sell webshells / exploits / No AI coders allowed / Advertising is prohibited here!” Mushr00w is listed in the group information, putting the account directly inside the community rather than simply appearing as another member.

The messages inside the group make the purpose of the community clearer. Webshell access was being advertised for specific websites, including https://petofi10miskolc.edu.hu/ and https://www.rmc.edu.my/, with the latter offered as “Webshell + Admin access.” Other posts advertised “HIGH DA PA DOMAINS AVAILABLE”, along with claims that shells had terminal access and could be used to upload, edit and delete files. Sellers also advertised replacement or refund support and a one-day guarantee after purchase.

One of the posts described the service in more direct terms: “We are more than just a seller”, followed by a claim that the group provided reliable shells, support and solutions to buyers. The contact details attached to these advertisements repeatedly included @M*****w and @boc********9.

The group was not limited to individual shell listings. Another post promoted a “S4LE priv8 WP Checker”, described as a tool capable of live site validation, automated login, plugin installation and user-role detection. Whether every capability advertised actually worked as claimed cannot be established from the posts alone, but the advertisement itself shows the type of tools being offered alongside shell access.

The same activity also appeared outside ZeroDay Commerce. StealthMole’s Telegram Tracker returned messages posted under the Mushr00w identity advertising shell access for edu.co, edu.mx, gov.au and gov.my domains. One post offered random shells for $2 each and stated that escrow was accepted. Another specifically claimed “ALL ROOT DIR / NOT SUBDOMAINS!” and again directed potential buyers to @M****w.

These posts are important because they show that the shell-selling activity was not limited to a single advertisement inside one private group. The same identity was being used to promote access elsewhere on Telegram. At the same time, the domains mentioned in these advertisements should not be mistaken for infrastructure owned by Mushr00w. The evidence shows them as systems for which shell access was being advertised, not proof that Mushr00w owned those domains or personally compromised them.

There was also another community connected to this activity. Rainbow Shell Market had Mushr00w listed as its contact and linked back to ZeroDay Commerce. Its description openly invited users looking for shells to join. Together, the two communities show a small but connected marketplace around the sale and promotion of webshell access, with Mushr00w positioned at the centre of the activity observed in the available evidence.

  • https://t.me/Ra***********t

When Business Turns Personal

The activity around ZeroDay Commerce was not without friction. One of the accounts repeatedly appearing alongside Mushr00w in the shell advertisements was @boc*******9. The two accounts were presented together in posts offering shell access and related services, suggesting that they were working within the same commercial space.

That relationship later broke down publicly.

In a message posted through the ZeroDay Commerce community, the account identified as the owner announced that it was no longer connected with @bo******9 and warned others that any future dealings with the account would be their own responsibility. The message went further, accusing him of being a “liar thief” and claiming that he had stolen a shell. Another member, Yongbe, responded by asking him to be patient, showing that the dispute was taking place in front of other members of the community rather than in a private exchange.

The accusation was later answered by @bo*******9 through D1STR1CT9619, a community project that was also being used to share the dispute. His version of events was very different. He said he had been accused of stealing shells after an RDP he had purchased for Mushr00w developed problems. According to his account, Mushr00w believed that he had changed the RDP password and taken the shells, while he claimed that the RDP had actually been flagged because of misuse. He also denied taking shells for personal use and said he had refused to share proceeds from their sale.

Neither side's account can be independently established from these messages alone. What the evidence does establish is that Mushr00w and @bo********9 had previously been operating in the same shell-selling environment and that their relationship later ended in a public dispute over shell access and an RDP.

StealthMole's profile search on @bo********9 provided little additional information. The account is associated with Telegram ID 6271041627, uses the name “NO NAME”, and has no visible phone number or other identifying information. Its limited profile data therefore does little to resolve the dispute, but the activity surrounding the account gives us a clearer picture of its connection to Mushr00w than the profile itself does.

The fallout is useful for another reason. It gives us a glimpse into how these shell operations appear to function behind the advertisements: access is acquired through RDPs, shells have commercial value, and disagreements over control of that access can quickly become disputes within the same underground community.

The People Around the Seller

The deeper Telegram search showed that Mushr00w’s activity extended beyond ZeroDay Commerce. StealthMole linked Telegram ID 6775881965 to activity across 11 Telegram channels, with additional messages appearing in other groups and channels. This broader footprint made it possible to look at the people appearing around the account rather than treating Mushr00w as a standalone seller.

One of the clearest connections was @be*******u. In the ZeroDay Commerce member list, the account is explicitly marked as “Mate.” Its profile shows the display name X, username @be*******u, and the bio “Lucky 4U Not M3.” The “Mate” designation does not tell us exactly what role the account played, but it does establish that the account held that label within the community.

Another account, VX-encoded, also appeared as a Mate in ZeroDay Commerce. StealthMole identifies the account as @b*******d, Telegram ID 8256413322. Its profile contained a direct reference to the community in its bio: Direction: https://t.me/Zero********e. This provides a separate profile-level connection between VX-encoded and the same community surrounding Mushr00w.

VX-encoded also appeared in a conversation involving shell access. One message, written in Indonesian, questioned why someone would sell their dignity for 20–30 dollars and referred to asking for a “shell” through a backup account. VX-encoded then wrote that he had “lost respect for Indonesians" and questioned why so many of them were “stupid.” The exchange is useful for understanding the conversations taking place around shell access, although it does not identify the person being addressed or establish that VX-encoded was involved in the transaction being discussed.

Together, the Telegram data shows that Mushr00w was operating within a wider group of users rather than in isolation. Some relationships were visible through commercial posts, others through community roles, and others through the conversations taking place around shell access. The network was therefore larger than the Mushr00w account itself, even if the precise role of every person around it cannot be established from the available evidence.

Beyond the Network

The Telegram investigation was not the only place where the same name appeared. A separate OSINT search surfaced a profile:

  • https://gitlab.archlinux.org/M*******w

The username is notably similar to the name used by the Telegram account, but that similarity alone is not enough to connect the two.

At the time of the investigation, the GitLab profile could not be examined further because access to the page was restricted. There was also no additional evidence available from the search that tied the account to Telegram ID 6775881965, ZeroDay Commerce, or any of the other identifiers already associated with Mushr00w.

For that reason, this lead remains separate from the main attribution chain. It is worth recording because the username is distinctive enough to warrant further checking, but there is currently no basis for presenting the GitLab account as belonging to the same person behind @M*****w.

This is also a useful reminder of one of the problems with tracking underground identities. A familiar username can point toward the right person, but it can just as easily belong to someone else. In this case, the Telegram evidence provides a much stronger foundation because several different usernames are tied to the same Telegram ID, while the GitLab account currently has no such link.

Conclusion

The investigation began with two website defacements carrying the Mushr00w name and a Telegram address that opened the door to a much wider footprint. StealthMole’s historical Telegram data then connected Telegram ID 6775881965 to multiple previous usernames and eventually to @M*****w, whose profile pointed directly to ZeroDay Commerce.

From there, the evidence became more consistent. ZeroDay Commerce and related Telegram communities were being used to promote and sell webshell access, while Mushr00w appeared repeatedly in those activities. The investigation also identified other accounts around the operation, including @bo******9, @be*****u and VX-encoded, although the exact role of each person is not equally clear. The public dispute with @bo********9 also showed that these relationships could change quickly when access and money were involved.

Overall, the available evidence supports viewing Mushr00w as an active participant in a Telegram-based webshell marketplace, with a history that extends beyond the current username and activity across multiple connected communities. At the same time, some leads remain unresolved, including the real-world identity behind the account and the relationship between Mushr00w and the separate Arch Linux GitLab profile.

Editorial Note

Dark web identities rarely stay consistent for long, and attribution is often built from fragments rather than a single definitive piece of evidence. In this case, usernames changed, relationships shifted, and some claims made by the actors could not be independently verified.

StealthMole helped bring those fragments together, allowing the investigation to follow the same account across historical identities, defacement activity and Telegram communities while keeping the uncertain parts of the picture separate from the findings that could be supported.

To access the unmasked report or full details, please reach out to us separately.

Contact us: support@stealthmole.com




Labels: , ,

Learn more about StealthMole

Talk to our team of experts today to learn how you can manage your dark web exposure.
Request demo More Reports

Share this report