The QYU Holdings Trail: Mapping the Corporate and Digital Footprint Behind a $100M Forex Ponzi

QYU Holdings presented itself to the world as a professional foreign exchange trading firm. U.S. federal authorities say it was a Ponzi scheme. Between at least 2015 and June 2023 it is alleged to have taken in around $100 million from investors in the United States, Canada, Panama and elsewhere, and its founder, Darren Anthony Robinson, was charged in the Eastern District of Michigan with eleven counts of wire fraud and one count of money laundering. He cut his court ordered GPS tether in November 2023, left the country, and in August 2026 was added to the FBI's Most Wanted Fraudsters list with a reward of up to $150,000.

Investigating through StealthMole's indexed dark web, credential and leaked file sources, this report follows the QYU brand through the infrastructure it left behind: the domains it registered, the mailboxes that leaked, the offshore funds it stood up, an SEC filing it signed, the corporate records it left in Florida, and a broker license it took out in Dubai. Traced this way, a single wanted poster name opened into a corporate structure spread across five jurisdictions, Wyoming, Florida, the Cayman Islands, Panama and the United Arab Emirates, and surfaced several people documented alongside it.

One principle runs through everything that follows. Darren Robinson stands charged, and the allegations against him remain allegations until a court decides. Everyone else named here is documented only as an affiliate or an officer of a QYU entity. A mailbox, a directorship, a signature or a filing shows that a person was connected to the operation. It does not show that they knew it was a fraud, and none of them appears in any charging document. Where the records prove a connection we say so, where they do not prove knowledge or intent we say that too, and the leads that could not be stood up are set out on their own. No information about anyone's current location was developed.

The Starting Point: A Most Wanted Fraudster

The investigation did not begin with an unknown alias. It began with a wanted poster. On 13 August 2026 the FBI's Detroit Field Office added Darren Anthony Robinson to its Most Wanted Fraudsters list and posted a reward of up to $150,000 for information leading to his arrest and conviction. According to the Bureau, Robinson founded and ran QYU Holdings as a purported professional investment company trading foreign currency, and from at least 2015 to June 2023 he raised an estimated $100 million from investors while, it is alleged, running a Ponzi scheme that paid earlier investors with newer money and funded his own lifestyle.

The poster gave a set of identifiers that became the baseline for every record checked afterward:

  • Date of Birth (used): 31 January 1970
  • Place of Birth: Brooklyn, New York
  • Description: Male, 5'11", roughly 180 lbs, brown eyes, bald or shaven head
  • Ties: Panama, the United Arab Emirates and Colombia, with an earlier U.S. footprint in Miami, South Florida, suburban Atlanta and Southern California
  • Photograph: Taken in 2022

Two enforcement tracks anchored the case. A federal arrest warrant was issued on 11 January 2024 in the Eastern District of Michigan after Robinson was charged with eleven counts of wire fraud and one count of money laundering, and he has been a fugitive since November 2023, when he cut his GPS tether while out on bond and left the country.

Separately, the Commodity Futures Trading Commission won a default judgment and permanent injunction in April 2024 against Robinson and The QYU Holdings Inc. (QYUHI), a Wyoming corporation with a claimed principal place of business in Dallas, Texas, ordering $5,923,515.37 in restitution and a matching civil penalty and finding that the firm had taken $7,196,365.37 from 38 pool participants. The distance between the CFTC's $7.2 million and the FBI's $100 million was itself telling. The regulator had captured one slice of a much larger operation.

The charging documents also pointed past Robinson himself. A related CFTC action named Dwight A. Foster, a dual U.S. and Canadian citizen, and K.E.L. Enterprises, Inc. for soliciting not less than $13.2 million from at least 45 investors into a QYU related commodity pool (CFTC v. Foster, No. 2:23-cv-11552, E.D. Mich.). QYU had paid a network of client managers, which meant its footprint was never going to end with one person. That is where the trail into the infrastructure began.

The Brand Footprint: Domains and Web Infrastructure

With the public record in hand, the first pivot ran through StealthMole's Darkweb Tracker into QYU's own web presence. There was not one site but a family of them, and each told a slightly different story to a slightly different audience. Mapping them showed the reach of the operation and gave us a set of infrastructure selectors to carry forward.

The domains and subdomains that surfaced:

  • u**.qyu*****s.com

The investor facing fund site, describing short term intra day forex, "proprietary market research techniques" and a global macro strategy, and naming a specific vehicle, the Vader Fund.

  • t**qyu******scorp.com

A live placeholder branded "The Qyu Holdings Corporation" and pitched around import and export.

  • r***s.qyu*********s.com

A login and password reset portal titled "QYU - Login", the account system that would have served investor statements.

  • qyutech*******s.com

Tied to the Florida entity QYU Technologies Corp, with contact info@qyu****h.com, +1 (786) 6**-2***7 and an address in Miami.

  • qyut******i.com

The site of the UAE broker arm, contact: info@qyut******i.com, +971 5* 6*3 **00

The inconsistency across these properties was itself worth noting. To investors QYU was a professional FX fund. To directories and registries it appeared as a holding company, an import and export firm, an online shopping mall on an abandoned LinkedIn page, and a technology company. An operation said to have raised $100 million wearing several unrelated cover identities is a familiar layering pattern, and here it is documented across five separate web properties.

Each domain went into the file as a selector for passive DNS, historical WHOIS and archive review. So did the marketing language itself, the "Vader Fund" name, the "boutique professional trading firm" self description, and the claim that $100,000 invested in 2014 would have grown past $2 million by 2021 without a single losing month. That kind of copy is distinctive enough to catch again if it were reused under a successor or sibling brand.

Following the Credentials

Pivoting on the first domain qyu*******s.com through StealthMole’s Combo Binder returned 128 credential records. This was a set of real mailboxes with passwords and per record leak dates attached, not addresses guessed from a naming pattern. The distinction mattered. A dataset that carries passwords and timestamps confirms the mailboxes existed and were in use, and it rules out the possibility that any given address is an inference.

Three of them anchored the people side of the investigation:

  • Darren@qyu******s.com

The operator account

  • S.jennings@qyu******s.com

Recurring across leak dates from August 2024 to December 2025, with the password changing over time, which pointed to a mailbox in steady use rather than a one off.

  • Sharrief@qyu******s.com

A third active staff account

Seeing Darren next to S.jennings and Sharrief on the same corporate domain read the way a small staff on shared mail would. The naming was not consistent, first name, then first initial and surname, then first name again, which meant the rest of the roster could not be guessed by permutation.

At this stage the mailboxes established affiliation. People named Jennings and Sharrief held working QYU accounts. They did not yet tell us who those people were, or what they did. Resolving the names came next.

Putting Names to the Mailboxes

When the qyu*******s.com domain was investigated through StealthMole’s Darkweb Tracker, it returned several leaked file records drawn from third party breaches such as MGM Grand Hotels and Apollo.io. These files show where a mailbox was used to sign up for outside services. They do not indicate that QYU itself was breached, but they carry the same weight for our purposes. The address is real, it belongs to the named person, and it was used as a working email.

Two records linked s.jennings@qyu*******s.com to a full name and a location:

  • Stephen, Jennings, PARK CITY, UT, s.jennings@qyu*****s.com
  • a JSON record binding a spelling variant, s.jennns@qyu******s.com, to Stephen Jennings and Sacramento, CA

The first name form and the US geography of these records became the anchor for what we call Cluster A, the Jennings figure hard tied to QYU through the mailbox and a SEC filing along with a set of offshore directorships discussed later in this report.

A record in another leak did the same for the third mailbox, resolving sharrief@qyu*****s.com to a full name and adding a phone number:

  • sharrief@qyu******s.com, Sharrief Shabazz, +1 (404) 5** 3***1

The 404 area code is Atlanta, which lines up with the FBI's stated suburban Atlanta ties for Robinson rather than cutting against them. The number went into the file as a passive selector.

By the end of this stage, we had three names: Robinson, Jennings and Shabazz, each documented on the QYU mail domain, with Jennings and Shabazz now carrying full names and, for Shabazz, a phone. All three were affiliates on the evidence to hand. Role and any knowledge of the scheme were still unestablished.

The Offshore Layer: Cayman Fund Directorships

Further investigation of Jennings led us to an official register. OffshoreAlert holds Cayman Islands General Registry director details, pulled on 26 June 2023 and cross linked to the Robinson criminal complaint, for a cluster of QYU branded funds. Stephen Jennings appears as a director across them.

The entities on which he is listed:

  • QYU Holdings Ltd. (Cayman Islands)
  • QYU CI Fund (Cayman Islands)
  • QYU Guardian Fund (Cayman Islands)
  • Inceptiondx Cayman (Cayman Islands)

Two things stood out. First, a corporate mailbox on the operating domain, combined with a directorship across the associated funds, is difficult to reconcile with a purely arm’s-length nominee arrangement. More importantly, the two records corroborated each other. Second, the footprint extended across three QYU funds and one additional entity, Inceptiondx, which had almost no public presence beyond the same register. The pattern was consistent with the QYU vehicles and made Inceptiondx a probable sibling entity, worth checking against the QYU funds’ registered office and co-directors.

One caution needs to be kept in mind. OffshoreAlert indexes entities linked to its own reporting and does not represent the full Cayman register. The four listings therefore establish four documented directorships, but they do not show that Jennings held no others. Confirming the full extent of his professional director activity would require checking the CIMA registered directors database rather than relying on OffshoreAlert alone.

A Signature on Record: The SEC Loan

Running Jennings through StealthMole against public filings surfaced the strongest document tying him directly to QYU: an SEC filing signed under penalty. Exhibit 10.14, filed by Predictive Technology Group, Inc., contains a revolving loan agreement between The Qyu Holdings, Inc. and Predictive Technology Group, Inc.

The agreement was effective 25 September 2019 and provided up to $3 million at 12 percent interest, with repayment due on 30 September 2021. The lender's notice address lists Stephen Jennings in Miami, Florida.

The signature block is the key piece:

  • THE QYU HOLDINGS, INC. By: Stephen Jennings, Managing Director
  • Predictive Technology Group, Inc. By: Bradley Robinson, CEO

This moved Jennings from a name appearing across QYU-related records to a documented executive of the core QYU entity. The filing also lines up with the QYU mailbox, the Cayman directorships and the LinkedIn profile identifying Jennings as Managing Director at Qyu Technologies in Miami.

The loan opened a second line of investigation. The $3 million went to Predictive Technology Group, a company that was facing SEC scrutiny around the same period and was later the subject of published fraud allegations. The use of QYU funds in that transaction therefore became a separate question, examined further under the Predictive Technology Group section.

The document establishes Jennings' role at QYU, but not his knowledge of or involvement in the alleged fraud. He does not appear in the charging documents reviewed, and the CFTC's findings identify Robinson as controlling the accounts into which investor funds were diverted.

The Corporate Spine: Florida Filings

The U.S. corporate structure was also documented through signed Florida Division of Corporations filings. Two QYU-related entities were registered at the same Miami Beach address.

QYU Holdings Limited LLC, document number L19********137, was filed on 5 April 2019 and later administratively dissolved on 22 September 2023. Its principal address was 1*** C***** Ave, Miami Beach, FL 33139, with earlier filings showing Apt 8C. The filing lists Darren Anthony Robinson and Andrew Anderson as authorized persons.

QYU Technologies Corp, document number P17*******659, EIN 83-2*******75, was filed on 4 December 2017 and dissolved on the same date as the LLC. It used the same Miami address. Across the available annual reports, Darren Anthony Robinson is listed as Director, President, Secretary and Treasurer. The articles describe the company's purpose as a "Commodity Trading Advisor", directly connecting the entity to the forex operation.

Separately, the charged Wyoming entity, The QYU Holdings Inc., surfaces in Austin, TX. A Dun & Bradstreet company profile lists Darren Robinson as Key Principal at the address and gives a Dallas phone number. A StealthMole leaked file independently records the same address as a QYU registration address. Street View shows the property as a single-family residence rather than a commercial premises.

The shared address and dissolution date linked the two Florida entities, with both dissolved on 22 September 2023, the same period as the CFTC complaint and the wider collapse of the scheme. Andrew Anderson also emerged as a new QYU-associated name through the LLC filing.

The physical footprint follows the same pattern. Both the Miami Beach address and the Austin address are residential properties rather than conventional business premises. This is consistent with the QYU entities operating without a clearly identifiable Florida or Texas office.

The Dubai Arm

The FBI's reference to QYU's UAE connections led to a registered entity in Dubai. A company register record lists QYU TECH COMMERCIAL BROKER L.L.C., registration number 941444, established on 15 March 2021 and listed as active.

The record provided four selectors:

  • Website: qyutechdubai.com
  • Email: info@qyutechdubai.com
  • Phone: +971 ** 673 0**0
  • Address: B*****a Heights, 1***8 Al S******r Tower 1, Dubai

WikiFX also carries a profile for the broker and describes it as unregulated. This was treated as supporting context rather than a regulatory finding, since WikiFX is an aggregator rather than a regulator. The profile did, however, provide a useful link. It describes the Dubai broker as running a "Qyu Technologies CTA" platform on MT4.

That description connected back to the U.S. side. QYU Technologies Corp's SunBiz filing lists its corporate purpose as "Commodity Trading Advisor", while the Miami-facing Qyu Technologies profile describes a CTA model where trades are executed through the client's brokerage account using MT4. The Dubai entity was therefore not just using the QYU name. Its advertised product pointed back to the same Qyu Technologies CTA model documented in the U.S.

QYU Tech Dubai - 16 May 2024

QYU Tech Dubai Contact & Address - 16 May 2024

The branding provided another link. The Miami entity uses qyutech.com, while the Dubai company uses qyutechdubai.com. The shared qyutech root is consistent with the Dubai entity being a geographic extension of the same brand rather than an unrelated company using the QYU name.

QYU Technologies - 20 March 2025

QYU Technologies Contact & Address - 13 October 2025

There is also a person-level connection. Stephen Jennings is documented as Managing Director of The Qyu Holdings Inc. in the SEC loan and separately identifies himself as Managing Director of Qyu Technologies in Miami. That is the same Qyu Technologies entity whose CTA model is referenced in the Dubai broker profile.

The Dubai registration therefore added more than another jurisdiction to the QYU footprint. Taken together with the CTA description, shared qyutech branding and Jennings' documented role, it connected the Dubai broker to a specific U.S. entity through the product it advertised.

The Predictive Technology Group Connection

The QYU loan led directly to Predictive Technology Group (PTG) and its CEO, Bradley C. Robinson. The SEC filing identifies Robinson as the person who signed the agreement on behalf of PTG.

The relationship was supported by two additional public records. An SEC Division of Corporation Finance comment letter dated 17 May 2019 addressed Robinson as CEO and raised questions around PTG's consolidation policy, variable interest entities and Juneau ownership figures. A later Hindenburg Research report also examined PTG and its management and alleged fraud.

PTG's own 10-K references the QYU loan. This makes the $3 million transaction a documented financial link between the two entities and provides a clear record to follow through the company's related-party disclosures.

Leads Documented but Excluded

Several records surfaced during the investigation but could not be tied to the QYU individuals with enough confidence to include them in the assessment.

One such lead was the name Stephen William Jennings. StealthMole returned a Bureau van Dijk record identifying a UK national and Company Secretary, a Panjiva record involving a 1979 Chevrolet Corvette shipped from Cayman to Panama, and a Dun & Bradstreet record connected to an Ontario company. The records shared the name and some of the same geography as the QYU Jennings, but no hard selector connected them to the Miami-based individual. They were therefore kept as a separate candidate identity. The idea of a Canadian branch was not supported by the available evidence.

Assessment: Entities and People

The findings are grouped by the strength of the evidence. Tier 1 covers individuals who were charged. Tier 2 covers documented affiliations or roles where the person's involvement or knowledge has not been established and no charges have been brought. Items marked as open are unresolved identity or relationship questions. Items marked as excluded are covered in the previous section, along with the reasons they were not included.

Entities


Entity Name

Jurisdiction

Identifier / Reg #

Documented Officers

Status / Role

The QYU Holdings Inc. (QYUHI)

Wyoming, USA

2013-0*******08

Darren Robinson

The charged forex pool entity

QYU Holdings Limited LLC

Florida, USA

L19******137

Darren Robinson, Andrew Anderson

Dissolved 2023

QYU Technologies Corp

Florida, USA

P17******659, EIN 83-2****075

Darren Robinson (sole)

Purpose "Commodity Trading Advisor"; dissolved 2023

QYU Holdings Ltd, CI Fund, Guardian Fund

Cayman Islands

Cayman registry

Stephen Jennings, Eric Robinson (Guardian)

Offshore funds

Inceptiondx Cayman

Cayman Islands

Cayman registry

Stephen Jennings

Probable sibling entity, to resolve

QYU Tech Commercial Broker LLC

UAE (Dubai)

94****4

Not resolved

Active; flagged unregulated (WikiFX)

QYU Holdings Corporation

Panama

Not on file

Not resolved

Offshore arm

People

Name

Hardest evidence

Status

Darren Anthony Robinson

Federal indictment; CFTC default judgment; signed Florida filings

Tier 1, charged (allegations pending)

Stephen Jennings

SEC Exhibit 10.14 signed as Managing Director of The Qyu Holdings Inc; Cayman directorships; QYU mailbox; self reported LinkedIn MD

Tier 2, documented senior officer; role and knowledge not established; not charged

Andrew Anderson

Signed Florida filing (Treasurer, 2021); Managing Member, QYU Holdings Limited LLC

Tier 2, state filed co officer; role and knowledge not established; not charged

Sharrief Shabazz

QYU mailbox; phone +1 404 5********1

Tier 2, affiliated; role and knowledge not established; not charged

Dwight A. Foster, K.E.L. Enterprises

Named in CFTC v. Foster (feeder pool)

Charged in separate civil action

Eric Robinson

Tagged on QYU Guardian Fund directors; separately named as Bradley Robinson's brother at PTG

Open, same person question unresolved

Bradley C. Robinson

PTG CEO (SEC letter, bio); signed PTG side of the QYU loan

Documented PTG executive; no established QYU fraud role; not a QYU officer

"Stephen William Jennings" (BvD, Panjiva, D&B Ontario)

Name and partial geography match to Cluster A

Open, not confirmed same individual

Conclusion

The investigation started with a single name on a wanted poster and gradually built into a wider QYU network across five jurisdictions. StealthMole's Darkweb Tracker first mapped the related domains and identities. Combo Binder surfaced the mailboxes, while leaked file records reviewed through MoleChat helped connect those mailboxes to real names. From there, each selector opened another part of the structure: offshore records showed the fund directorships, an SEC filing put Stephen Jennings' signature and Managing Director title on The QYU Holdings Inc., Florida filings documented the U.S. entities, and a UAE registration provided a hard corporate record for the Dubai operation.

The strength of the case came from how these records connected. Credential data, offshore registers, SEC filings, state records and the UAE registration repeatedly pointed back to the same QYU branding, addresses and small group of names. No single record showed the full picture, but taken together they provided a much clearer view of how the network was structured.

At the same time, the investigation did not establish more than the records could support. Darren Robinson is the individual charged in the case. Stephen Jennings, Andrew Anderson and Sharrief Shabazz are documented in QYU-related roles, but their knowledge of or involvement in the alleged fraud was not established in the material reviewed. The Eric Robinson and Stephen William Jennings identity questions remain open, while the Blunt and Montoya address link and the registered agent staff were excluded.

The QYU operation therefore did not resolve through one decisive record. It came together by following the same names, domains, mailboxes, addresses and corporate records across different sources and keeping confirmed links separate from leads that could not be verified. That process is what turned a single name into a documented, multi-jurisdiction picture of the network.

Editorial Note

Dark web and fraud investigations rarely produce a clean attribution from the start. Names can overlap, records can be incomplete, and a shared mailbox or address does not automatically establish a person's role or knowledge. In this case, StealthMole helped move the investigation from surface-level identifiers to deeper records across credentials, infrastructure, registries and corporate filings, while allowing weaker leads to be separated from the findings that could be supported.

To access the unmasked report or full details, please reach out to us separately.

Contact us: support@stealthmole.com






Labels: ,

The Cat Behind the Breach: Tracing TeamPCP’s Digital Trail

TeamPCP has appeared under several identities across underground communities, with activity that has evolved beyond a single criminal service or attack method. Names such as PCPcat, ShellForce, DeadCatx3 and CipherForce appear across different parts of the ecosystem, while the group's presence has also extended into underground forum administration and Telegram communications. Other names associated with the wider ecosystem include Persy, Percy PCP, Persy_PCP and UNC 66780, adding further layers to an already fragmented identity set.

The activity surrounding these names covers several parts of the underground economy. PCPcat has appeared in reporting around exploitation of Next.js and React environments, CipherForce represents the ransomware side of the activity examined here, and TeamPCP itself has claimed a role in managing underground forum infrastructure. At the same time, material surfaced through StealthMole describes activity involving private source code, developer credentials, cloud environments and software supply chains.

The recurring PCP and cat branding offers a visible thread through some of this activity, but the stronger connections come from the infrastructure and account-level artifacts behind it. Following those links provides a different picture of TeamPCP than looking at any single alias in isolation.

The First Signal: CipherForce

The investigation did not begin with a search for TeamPCP. The initial lead came from StealthMole's Ransomware Monitoring module, where the group CipherForce was indexed alongside 19 victims recorded between One of the results that immediately stood out was “BMW Group Internal Documents/Recon”, with a detection date of March 26, 2026.

The victim count provided the initial scale, but the BMW record was more useful for what it revealed about how the operation was presenting stolen material.

The associated CipherForce victim page was:

  • http://22evxpggnkyrxpluewqsrv5j4jtde6hut2peq3w44d6ase676qlkoead.onion/victims/5afc65a1-3eee-4aed-bab5-1415c88e8474

It listed BMW Group Internal Documents/Recon, classified the industry as Automotive, the country as DE, and marked the material FOR SALE. The price was listed as Make an offer, with the contact field pointing to:

  • https://pastebin.com/raw/6********3

The page included the heading “Original Thread by Xpl0itrs” and the following references:

  • https://breached.**/threads/bmw-group********3
  • https://spear.**/Thread-Com-Boss-BMW********s
  • https://rehubcom.**/thre********3/

The listing therefore gave the investigation several ways forward. CipherForce was not only represented through a victim-monitoring record; its page contained an onion infrastructure address, an external contact mechanism and references to several underground platforms.

The CipherForce Infrastructure

The onion address associated with the BMW listing was further investigated in StealthMole’s Darkweb Tracker.

  • 22evxpggnkyrxpluewqsrv5j4jtde6hut2peq3w44d6ase676qlkoead.onion

The current site was no longer live, making StealthMole's historical indexing particularly useful. A historical snapshot dated 2026-08-02 showed the site under the name TeamPCP. However, a further look into the historical snapshots showed that in March 2026, the website operated as CipherForce, making TeamPCP a later re-branding.

That provided the first direct route into the wider TeamPCP investigation. A subsequent Dark Web Tracker pivot on the onion domain produced two identifiers:

Session ID

05a04c*******************************************5823e

TOX ID

BA8***********************************************069F2

Searching the Session ID expanded the investigation beyond the CipherForce onion itself and surfaced material across additional underground services. These identifiers allowed the investigation to follow the same technical thread into places where the name CipherForce did not necessarily appear.

One of the more relevant results was a Breached thread titled “Signs of life amidst rumors”:

  • https://breached.**/threads/signs-of-life-amidst-******1/

The post said TeamPCP would no longer work with Hasan and would instead continue operating on that branch of the forum. It made a number of claims about Hasan's treatment of staff and vetting, alleged that Hasan had been phished for domains and had lost access to his own database, and said that TeamPCP members had remained active despite difficulty reaching the group's public-facing spokesperson.

The same post rejected speculation that the team had been arrested or “fedded.” It also described a contingency in which the TeamPCP alias could be transferred to another operator if the poster was arrested or retired, and directed people requiring forum matters, operational partnerships or access/data toward the “OG tox or session accounts.”

It is also worth mentioning that the post displayed the same Session ID and TOX ID identified during the CipherForce investigation.

TeamPCP Takes a Seat at the Table

The next major finding came from TeamPCP's own activity on Breached.

On 16 May 2026, the account published a thread under the title “TeamPCP Partnership / Forum Co-Ownership.”

  • https://breached.**/threads/teampcp-partnership-forum-co-ownership*****6/

The post announced TeamPCP's new role as co-owners of the platform, with authority over staffing, partnerships and major decisions. The responsibilities described by the account included infrastructure uptime and reliability, staff management, disputes, community guidelines, escrow services, new features, partner vetting, premium resources and databases, contests, community feedback and the verification of databases and tools.

The account also described a role in removing low-quality, fake or malicious content and rewarding verified contributors. It said the platform would provide more frequent updates to premium resources through the Breached CDN and closed with the signature:

“The PCP Cats.”

The same Session ID and TOX ID appear with the post:

  • 05a0**************************************************5823e
  • BA8***************************************************069F2

A StealthMole snapshot dated June 2026 showed the TeamPCP account with the role:

Co-Owner / Staff Member / Co-Owner

This was a notable shift in the investigation. TeamPCP was not simply appearing in material connected to attacks or stolen information. Its own account was presenting the group as part of the infrastructure and administration of an underground platform.

The responsibilities listed in the post also give some indication of the position TeamPCP claimed within that environment. They extended from keeping infrastructure online to managing staff, handling disputes and escrow, vetting partners and deciding what databases or tools should remain on the platform. That is a much broader role than simply maintaining an account on a forum.

The same technical identifiers linking back to the earlier CipherForce investigation were present here as well, giving the developing TeamPCP trail a consistent technical reference point.

What TeamPCP Was Selling

The same TeamPCP identity later advertised something very different.

The post, titled “Internal Github Source Code,” appeared at:

  • https://breached.**/threads/internal-github-source-c*******5/

The account was displayed as:

[Co-Owner] TeamPCP

The post offered approximately 4,000 private-code repositories and internal organizations. It provided a repository list at:

  • https://limewire.com/d/4HP********b4u

and a sample of two files at:

  • https://limewire.com/d/yMx********sN

The minimum offer was $50,000, while the screenshot showed a current offer of $95K.

The seller also went out of its way to describe the transaction as something other than ransomware. The post explicitly said it was not a ransom and that there was no interest in extorting GitHub. Instead, the buyer would receive the data, after which the seller said the data would be destroyed on their end.

There was another detail that would become relevant later: the account said it was retiring soon and that, if no buyer was found, the material would be leaked for free.

The wording provides a useful look at the group's claimed approach to monetization. The material was being offered as a commodity with a negotiated price, rather than being presented as a ransom demand against the organization whose infrastructure had allegedly been accessed. The $50,000 minimum and $95K current offer also show that the seller was treating the collection as a high-value asset in its own right.

At this point, the investigation had moved from ransomware into another type of underground transaction: the sale of private source code and internal repositories.

One Correlation That Did Not Fit: BulkDMT

The Session ID search also produced a result that looked interesting but could not be safely folded into the TeamPCP story.

The post was:

  • https://breachsta.**/topic/selling-access-to-proprietary-trading-firm-150bl*******xn3

It was dated 2025-09-11 and authored by BulkDMT on Sellers Place.

BulkDMT claimed access to an HFT proprietary trading firm with $150B monthly volume, including root access to cloud infrastructure, workstations and AI clusters, trading bot code, WireGuard profiles, authentication tokens and passwords, private Docker repositories, private PyPI, GitLab keys, Jupyter instances and API keys. The asking price was USD 4.5K in XMR, with the Telegram contact:

  • https://t.me/b*********T

The Session ID was the same:

  • 05a04****************************************95823e

But the TOX ID was not. BulkDMT was associated with the following TOX ID:

  • 8647********************************************E6A5

That difference matters. So does the date, which predates the CipherForce activity examined in this investigation, and the fact that the post was authored by BulkDMT rather than TeamPCP.

The shared Session ID was enough to make the result worth examining, but not enough to attribute the activity to TeamPCP or CipherForce. It remains an unresolved correlation rather than part of the group's established trail.

The GitHub Sale Leads to Telegram

Then the same session ID was further investigated in StealthMole’s telegram tracker, which indexed two messages mentioning the same session ID. The message, originally posted in a channel named “Breaches”, referenced the TeamPCP GitHub source code thread:

  • https://breached.**/threads/internal-github-source*******/

It also contains a telegram user ID, which was labelled as a burner telegram:

  • @TPCP******1

Moreover, the message also mentioned the same Session ID:

  • 05a04**********************************************5823e

together with the same TOX ID:

  • BA8D**********************************************5069F2

The significance of this result lies in what it adds rather than what it repeats. The GitHub thread had already established the source-code sale. The Telegram result provided a new account identifier associated with the communication surrounding that sale.

T-PCP: Following the Account

The newly found telegram account was further investigated using StealthMole’s telegram tracker. The tool indexed an active user account associated with the username.

  • Telegram User ID: 8542877306
  • First name: T-PCP
  • Username: @TPCP********1
  • Profile creation date: 2026-08-08

The account also used the same black-cat image as profile picture, seen on other TeamPCP-related accounts. It should be further noted that this account also appeared in multiple breached related telegram channels, including:

  • https://t.me/Br********zzi

The direct account record was useful because it provided more than a username. T-PCP is itself a TeamPCP-style identifier, and the account could be examined independently after first being surfaced through material referencing the TeamPCP GitHub sale.

That does not establish the real-world identity of the operator. There is no phone number or other direct identity information in the available record. What it does establish is a consistent account-level trail connecting the Telegram identifier to the wider TeamPCP investigation.

The account later appeared in a more contentious discussion.

On 27 August 2026, a message in the Data Hoarder channel stated: “Breachforums owners @hello*******2 and @TPCP*******1 have been arrested.”

The surrounding messages also claimed that bf.** would become a honeypot, discussed previous ownership and warned users against using the site.

Those statements remain third-party Telegram claims. The existence of the messages can be documented, but the available evidence does not independently establish that bf.** became a honeypot.

The Cat Across Platforms

The TeamPCP identity carries a recurring visual marker across the platforms surfaced through StealthMole. A Dark Web Tracker search for Team PCP returned a Spear CX profile:

  • https://spear.**/User-TeamPCP

The profile uses the same black-cat avatar seen on the T-PCP Telegram account. On its own, an avatar would be weak evidence, but its reuse becomes more useful when viewed alongside the other TeamPCP artifacts already identified.

StealthMole also surfaced the TeamPCP-branded image:

  • https://supplychain.breached.st/teampcp.jpg

The image carries TEAM PCP branding and the wording “NOW WITH CIPHERFORCE.” This is more direct than the shared avatar: the graphic itself places TeamPCP and CipherForce together, reinforcing the connection already observed when the historical CipherForce onion was indexed under the title TEAM PCP.

The cat therefore works best as a supporting cross-platform identifier, while the TeamPCP/CipherForce branding provides a stronger link between the two names. Neither should be treated as proof of the real-world identity behind the accounts.

The same StealthMole search also surfaced third-party Telegram discussion linking TeamPCP to another supply-chain attack:

  • “TeamPCP gonna do another large Supply chain attack, be ready for it”

The message also referenced https://t.me/team_pcp and a “+35k stars github repo.” Because this was commentary from another user rather than a TeamPCP-authored post, it is best treated as contextual evidence of how TeamPCP was being discussed, rather than as evidence of a specific operation.

PCPCat: A Different Kind of Operation

The investigation also surfaced earlier activity associated with PCPcat, providing a useful view of the TeamPCP ecosystem before the CipherForce ransomware activity examined in this case.

A 28 December 2025 post in the Telegram channel Slice For Life, carried the title “Operation PCPcat Exploits Next.js and React, Affecting Over 59,000 Servers”.

The reported operation involved the exploitation of Next.js and React environments and identified as the distribution infrastructure.

  • 6*.**7.*7.**0:**6

The same reporting was also preserved in a HydraForums thread:

  • https://hydraforums.**/Threads-news-59-000-servers-breached-operation-pcpcat-targets-react-and-next-js*********5

This activity predates the March 2026 CipherForce victim record seen earlier and adds an important layer to the timeline. The material associated with PCPcat describes large-scale exploitation of internet-facing application infrastructure rather than ransomware-based extortion, showing that the activity surrounding the TeamPCP identity set extended into mass exploitation of web technologies before CipherForce appeared in the ransomware monitoring trail.

Conclusion

The investigation ultimately points to a TeamPCP ecosystem that is more interconnected than any single platform or alias would suggest. What makes the trail compelling is not one decisive artifact, but the way CipherForce, TeamPCP, PCPcat and the related accounts repeatedly converge across different environments. The historical CipherForce infrastructure, recurring identifiers, TeamPCP forum activity, Telegram presence and shared branding provide several independent points from which the same ecosystem can be followed.

At the same time, the investigation shows why those connections need to be handled carefully. Some relationships are supported by direct TeamPCP material and repeated technical or visual identifiers, while others remain dependent on third-party claims or incomplete correlations. The available evidence is therefore strong enough to map the digital footprint and operational reach of the TeamPCP ecosystem, but not to turn that footprint into a definitive real-world attribution. In an environment where aliases, accounts and infrastructure can shift quickly, following how those pieces connect is often more useful than relying on a single name or isolated incident.

Editorial Note

Dark-web investigations rarely provide a single piece of evidence that can settle attribution with certainty. Accounts can change, infrastructure can disappear, aliases can be reused, and claims made within underground communities may remain difficult to verify independently. In this case, the investigation demonstrates the value of following those fragments together rather than relying on any one artifact.

StealthMole helped turn an initial ransomware lead into a wider cross-platform trail while allowing stronger evidence, supporting correlations and unresolved claims to remain clearly separated.

To access the unmasked report or full details, please reach out to us separately.

Contact us: support@stealthmole.com






Labels: ,

Where the Trail Leads: Inside Al-Shabaab’s Digital Media Network

Jihadist organizations have adapted to a digital environment in which communication is no longer dependent on a single website, forum or dedicated platform. Messaging applications, social networks and alternative publishing platforms allow extremist groups to distribute propaganda, communicate narratives, publish claims and redirect audiences between different online spaces. This also creates a challenge for investigators: the most useful evidence may not be found on an account that openly identifies with an extremist organization, but somewhere further along the chain of distribution.

Al-Shabaab is a particularly relevant example. The Somali jihadist organization has developed a sustained media presence around its activities in Somalia and the wider region, using digital channels to communicate its narratives and disseminate material associated with the group. Its media activity extends beyond individual posts and can involve multiple platforms, accounts and distribution points.

For an investigator, this creates a more difficult question than simply asking whether Al-Shabaab has an online presence. The more useful question is how that presence can be traced when its content is dispersed across different users and platforms, including spaces that may not appear extremist at first glance.

This investigation was designed around that question.

Additionally, another objective was to test how effectively StealthMole could support investigations into jihadist terrorism and different forms of extremist activity. Rather than beginning with known infrastructure and checking whether the platform could find it, the objective was to start with a basic search and see whether StealthMole could uncover and connect the wider media, communication and distribution ecosystem surrounding the group.

The investigation therefore became a test of the platform's ability to turn a relatively weak initial signal into a more meaningful intelligence picture.


The Ideology Behind the Network

Al-Shabaab's online presence needs to be understood in the context of its broader jihadist identity. The group is not simply an armed actor that happens to use the internet. Its media activity forms part of how it communicates its worldview, presents its activities and maintains an information presence beyond the physical areas in which it operates.

That makes its media infrastructure particularly important from an intelligence perspective. When an extremist group publishes material, the content itself may be only one part of the investigative picture. The more useful question can be how that material moves. Who republishes it? Which accounts repeatedly direct audiences toward the same source? Which platforms are used when another platform becomes difficult to access? Which websites, bots or channels appear repeatedly alongside official material?

These questions matter because extremist communication networks are rarely limited to one account or one website. A single media organization can have several points of distribution, while supporters or other users may reproduce its material elsewhere. As a result, an investigator looking only for an account explicitly identifying itself with the group can miss a substantial amount of the surrounding activity.

The distinction between official media infrastructure and secondary distribution is also important. An account sharing Al-Shabaab material is not automatically an Al-Shabaab operative. Likewise, a Telegram group containing Al-Shabaab-related posts is not necessarily an Al-Shabaab-controlled group. The evidentiary value of each finding depends on what can actually be established about the relationship.

This distinction became particularly important during this investigation. The investigation encountered a mixture of clearly identifiable Al-Shabaab media references, repeated distribution activity by individual users, official communication points and apparently unrelated communities in which the material appeared. Treating all of these entities as one homogeneous network would have overstated the evidence.

Instead, the investigation followed a narrower principle: use confirmed media points as anchors, then examine how those points are referenced and redistributed across the wider digital environment.


One Keyword, One Unexpected Lead

The investigation began in StealthMole's Telegram Tracker with a deliberately broad search for:

  • al-Shabaab

StealthMole returned:

  • 361 Telegram messages
  • 2 Telegram users
  • 20 images
  • 190 documents
  • 43 other files

At first glance, the result did not immediately point toward an obvious Al-Shabaab-operated channel. One of the relevant results came from a Telegram channel titled:

  • ملتقى مهندسي الميكاترونكس

The channel was accessible at:

  • https://t.me/mech*****3

The channel presented itself as a mechatronics engineering community and had 1,180 members. Its visible content included technical material, including a pinned message relating to robotic simulation, robotic arms and agricultural pesticides.

That made the initial discovery more interesting, rather than less.

The search had not simply returned an obviously extremist channel. Instead, StealthMole had surfaced Al-Shabaab-related material within a community whose visible identity was technical and unrelated to jihadist activity. Rather than assuming the channel itself was connected to Al-Shabaab, the next step was to determine who had posted the relevant material and whether the same activity appeared elsewhere.

A message with the following ID provided the first meaningful pivot.

  • 1307071588_30161

The message was associated with:

  • Telegram user ID: 8008400988
  • First name: سويلم
  • Username: @sal*******6

The account information available through the investigation did not provide a last name, phone number or biography.

The message contained the hashtags:

  • #Somalia
  • #Mogadishu
  • #Alshabaab
  • #AS

It also contained:

  • https://shahadanews.info/?p=27068

Moreover, the accompanying image in the message was identified as an official Al-Shabaab photo.


The Account Behind the Message

Rather than stopping with the single message, the investigation pivoted on @sal******6 inside StealthMole's Telegram Tracker.

This produced four messages from the same user within the Mechatronics channel. The significance of this result was the repetition.

The first finding could have been treated as an isolated instance of a Telegram user sharing extremist material. The additional messages made that explanation less useful. The same account was repeatedly circulating Al-Shabaab-related material and, importantly, repeatedly exposing additional communication points associated with Shahada News, the official media house of al-Shabaab group.

The investigation therefore moved from content identification to pattern identification.

Among the recurring contact points were:

  • @Akh**************bot
  • https://chirpwire.****/Sha***********y
  • https://bsky.app/profile/sh******news.bsky.social

Another message contained:

  • https://shahadanews.info/?p=27054

The value of @sal******46 was consequently not that the available evidence proved the account belonged to Al-Shabaab. It did not. What the evidence did establish was that the account repeatedly circulated Al-Shabaab-related material and, in doing so, exposed several communication points that could be investigated independently.

This distinction is important for attribution. The account could confidently be treated as a distribution point and investigative pivot, but not automatically classified as an Al-Shabaab member or operative.


Following the Media, Not Just the User

The most important pivot in the investigation was the move from @sal******6 to Shahada News.

Shahada News is a known Al-Shabaab media house responsible for official communications. This gave the recurring references to its media points a substantially different evidentiary value from an ordinary social-media account reposting extremist content.

The investigation identified Shahada News across several platforms.

On ChirpWire:

  • https://chirpwire.net/Sha********cy

Its available profile information showed:

  • Handle: @Sha************cy
  • Bio: Press coverage of Somalia, East Africa and the Islamic world.
  • Location: Somalia
  • Member since: July 2024
  • 4,141 Chirps
  • 1,421 Followers
  • 24 Following

The account was actively used to publish Al-Shabaab-related material, including claims, official statements from leaders and videos. Its activity also established that the media presence extended beyond Telegram rather than being confined to a single messaging platform.

A Bluesky presence was also identified:

  • https://bsky.app/profile/sh************s.bsky.social

The significance of this finding was not simply that Shahada News had another social-media account. It showed that the same media operation had identifiable points of presence across different communication environments, giving investigators multiple places from which to observe activity and identify further distribution paths.

The investigation also encountered several Telegram-based contact points associated with the wider media ecosystem, including:

  • @Wakalathhahbot
  • @wakkkalaatshahadabot
  • @akhbaralameslamibot
  • @Akhbaralalamaslambot

Additional bot names surfaced during subsequent searches, including:

  • @ekhbaralambot
  • @Shawanewsagencybot
  • @Ehdathebrazbot
  • @Ekhbarislamworldbot
  • @SHWAEKHBOT
  • @hdathebrazbot

The broader finding was therefore stronger than any individual username: Shahada News appeared to operate within a multi-platform communication environment, with Telegram bots and accounts providing additional routes to material and external platforms providing further distribution.


The Network Starts to Take Shape

The next pivot came from the Bluesky profile:

  • https://bsky.app/profile/sha********s.bsky.social

Searching this identifier in StealthMole's Telegram Tracker surfaced multiple messages that referenced the same media ecosystem.

Clearly identified message IDs included:

  • 1307071588_30046
  • 1307071588_30045
  • 1307071588_30006
  • 1307071588_30001
  • 1307071588_29894

The results also exposed additional Telegram user IDs:

  • 8042389197
  • 6738658884
  • 7760032048

The available evidence did not provide enough information to attribute these users to Al-Shabaab, so they remained unresolved.

More important were the recurring infrastructure and communication references that appeared across the results:

  • https://shahadanews.info
  • @Wakalathhahbot
  • https://chirpwire.***/Sha************cy
  • https://bsky.app/profile/sha*********s.bsky.social

A private Telegram invite was also surfaced:

  • https://t.me/+vLVTo_hNyaU0Mzg0

Other messages exposed additional contact points, including:

  • @wakkkalaatshahadabot
  • @akhbaralameslamibot

A Facebook page was also visible:

  • https://www.facebook.com/News.of.the.World46

The significance of this stage was the cross-platform recurrence.

The investigation was no longer dependent on a single Telegram account. The same media identity was appearing through Telegram, ChirpWire and Bluesky, while Telegram searches were simultaneously revealing bots, private channels and other users connected to the circulation of the material.

This made the digital environment more intelligible. The network did not appear as one clean diagram with a central account and clearly labelled affiliates. Instead, it emerged through repeated references between different platforms.

That is a more realistic picture of extremist online activity: some nodes can be confidently identified, some can be linked through repeated evidence, and others remain unknown until additional information becomes available.


Beyond the Obvious

One of the most useful findings came from returning to the original Telegram community:

  • https://t.me/mech*******3

The purpose of this pivot was straightforward: determine whether the initial result was simply an isolated message from @sal*******6, or whether other Al-Shabaab-related activity existed within the same environment.

The answer was the latter.

Multiple Al-Shabaab-related messages and videos had been posted by users other than Salman1446. This was significant because it changed the interpretation of the original channel.

The channel itself remained a mechatronics community, rather than an Al-Shabaab channel. Its visible identity was technical, it had 1,179 members, and its pinned content concerned engineering-related subjects.

Yet StealthMole surfaced extremist-related material inside that environment.

Among the material identified was a Shahada-branded post from November 2024 containing:

  • https://shahadaagency.net/?p=24056

Another post, dated around November 17, 2024, promoted:

  • @Siham_Al_Khair_04_bot

and

  • https://t.me/Siham_Al_Khair_04_bot

The accompanying Arabic material referred to jihadist and mujahideen-related news and content.

A Somali-language post dated around November 20, 2024 provided another example. Its headline was:

  • WEERAR LAGU QAADAY FARIISIN MALEESHIYAADKA MURTADIINTA AY KU LAHAAYEEN DULEEDKA DEEGAANKA BIRTA DHEER

The post referenced:

  • WILAAYADA ISLAAMIGA EE JUBBADA HOOSE

and contained several external distribution points:

  • https://t.me/+s-fy3YJKuDo5Yml0
  • https://www.facebook.com/News.of.the.World46/videos/1641062710140510
  • https://archive.********/index.php/s/FtrgGns29Lgmf5t
  • https://watch******e.**/h/other/post/247502/deg-deg-daawo-weerar-lagu-qaaday

Another Shahada-branded Arabic post from around November 6, 2024 concerned an alleged attack involving government militias and Al-Shabaab around Kismayo and Lower Juba.

These findings matter for two reasons.

First, they showed that the presence of Al-Shabaab-related material in the mechatronics group was not dependent on Sal*******6 alone. Multiple users were posting or distributing such content.

Second, the finding illustrates why investigations based only on obvious extremist channels can miss relevant activity. The community did not advertise itself as an extremist space. Its primary identity was technical, yet extremist media was nevertheless present within it.

That does not establish that the administrators or members of the channel as a whole were affiliated with Al-Shabaab. There is insufficient evidence for that conclusion.

What it does establish is narrower and more useful: Al-Shabaab-related material was being circulated within a broader Telegram environment that, on its face, was unrelated to jihadist activity.


The Media Trail Goes Further

The investigation then pivoted from the Bluesky reference to the ChirpWire account:

  • https://chirpwire.net/Sha*************cy

Searching for this identifier in StealthMole surfaced a series of Telegram messages spanning several months. The references to Shahada News were not confined to one day or one Telegram user. StealthMole was surfacing repeated references to the media operation across a period extending from November 2024 into February 2025.

The same search also exposed a growing collection of Telegram bot/contact identifiers, including:

  • @wakkkalaatshahadabot
  • @akhbaralameslamibot
  • @ekhbaralambot
  • @Shawanewsagencybot
  • @Ehdathebrazbot
  • @Ekhbarislamworldbot
  • @SHWAEKHBOT
  • @hdathebrazbot

A private Telegram invite was also identified:

  • https://t.me/+zwcrODfjyRESZDkO

The chronology also demonstrated that the media ecosystem had multiple distribution mechanisms operating over time. Telegram posts could point toward external social platforms, while searches for those external identifiers could lead back to Telegram messages containing additional contact points.


When the Trail Changes

One of the more unusual findings concerned the domain:

  • https://shahadanews.info

The domain appeared repeatedly during the investigation and was directly referenced in Al-Shabaab-related Telegram material, including:

  • https://shahadanews.info/?p=27068
  • https://shahadanews.info/?p=27054

Its historical appearance made it relevant to the investigation.

However, when the domain was accessed during the investigation, it no longer presented Al-Shabaab-related material. Instead, it currently hosts Norwegian-language casino content, including references to new casinos and gambling-related reviews.

This creates an important intelligence distinction between historical evidence and present-day infrastructure.

The historical Telegram references establish that shahadanews.info was being used as a destination in Al-Shabaab-related communications at the time those messages were circulated. Its current content, however, does not support describing the domain as an active Al-Shabaab website.

The available evidence does not establish what caused the change. Possible explanations could include later repurposing, transfer, expiration and re-registration, compromise or another change in control, but none of these can be established from the evidence collected in this investigation.

At the same time, the investigation identified a separate currently active website:

  • https://sha*************ws.***

The site presents itself as Shahada News Agency, with Arabic branding and sections covering news, reports, photographs/articles, studies and translations, and opinion-related content. Its current presentation is consistent with the Shahada News media identity encountered through the other investigation pivots.

The distinction between the two domains is important. It prevents the historical shahadanews.info reference from being incorrectly treated as evidence of current infrastructure while preserving its relevance as part of the historical communication trail.


Conclusion

The investigation showed that Al-Shabaab-related media activity extends beyond clearly identifiable extremist channels and can surface within broader online communities through repeated redistribution. Shahada News emerged as the strongest identifiable anchor in the network, with its presence recurring across Telegram, ChirpWire, Bluesky and multiple Telegram-based contact points.

The findings also highlight the importance of separating media infrastructure, distribution activity and attribution. While the evidence establishes a clear connection to Shahada News as an official Al-Shabaab media operation, it does not justify treating every user, channel or bot encountered along the trail as an Al-Shabaab affiliate. The investigation was therefore most useful not for producing a simple list of associated accounts, but for revealing the wider communication environment surrounding the group's media activity.

Most importantly, StealthMole made that environment discoverable from a single broad keyword. By allowing individual messages, users and URLs to become investigative pivots, the platform helped turn an initially isolated Telegram result into a broader view of how Al-Shabaab-related material was being distributed across platforms.


Editorial Note

As with most investigations into cyber and dark-web activity, the available evidence rarely provides absolute attribution or a complete picture of every relationship. Accounts can be repurposed, domains can change hands, content can be redistributed by users with different motivations, and an apparent association does not always establish operational control.

This case demonstrates the value of following those uncertainties rather than forcing premature conclusions: StealthMole helped connect individual pieces of historical and cross-platform evidence while still allowing unresolved entities and attribution gaps to remain unresolved.

To access the unmasked report or full details, please reach out to us separately.

Contact us: support@stealthmole.com


Labels: ,

Learn more about StealthMole

Talk to our team of experts today to learn how you can manage your dark web exposure.
Request demo More Reports

Share this report