The Cat Behind the Breach: Tracing TeamPCP’s Digital Trail

TeamPCP has appeared under several identities across underground communities, with activity that has evolved beyond a single criminal service or attack method. Names such as PCPcat, ShellForce, DeadCatx3 and CipherForce appear across different parts of the ecosystem, while the group's presence has also extended into underground forum administration and Telegram communications. Other names associated with the wider ecosystem include Persy, Percy PCP, Persy_PCP and UNC 66780, adding further layers to an already fragmented identity set.

The activity surrounding these names covers several parts of the underground economy. PCPcat has appeared in reporting around exploitation of Next.js and React environments, CipherForce represents the ransomware side of the activity examined here, and TeamPCP itself has claimed a role in managing underground forum infrastructure. At the same time, material surfaced through StealthMole describes activity involving private source code, developer credentials, cloud environments and software supply chains.

The recurring PCP and cat branding offers a visible thread through some of this activity, but the stronger connections come from the infrastructure and account-level artifacts behind it. Following those links provides a different picture of TeamPCP than looking at any single alias in isolation.

The First Signal: CipherForce

The investigation did not begin with a search for TeamPCP. The initial lead came from StealthMole's Ransomware Monitoring module, where the group CipherForce was indexed alongside 19 victims recorded between One of the results that immediately stood out was “BMW Group Internal Documents/Recon”, with a detection date of March 26, 2026.

The victim count provided the initial scale, but the BMW record was more useful for what it revealed about how the operation was presenting stolen material.

The associated CipherForce victim page was:

  • http://22evxpggnkyrxpluewqsrv5j4jtde6hut2peq3w44d6ase676qlkoead.onion/victims/5afc65a1-3eee-4aed-bab5-1415c88e8474

It listed BMW Group Internal Documents/Recon, classified the industry as Automotive, the country as DE, and marked the material FOR SALE. The price was listed as Make an offer, with the contact field pointing to:

  • https://pastebin.com/raw/6********3

The page included the heading “Original Thread by Xpl0itrs” and the following references:

  • https://breached.**/threads/bmw-group********3
  • https://spear.**/Thread-Com-Boss-BMW********s
  • https://rehubcom.**/thre********3/

The listing therefore gave the investigation several ways forward. CipherForce was not only represented through a victim-monitoring record; its page contained an onion infrastructure address, an external contact mechanism and references to several underground platforms.

The CipherForce Infrastructure

The onion address associated with the BMW listing was further investigated in StealthMole’s Darkweb Tracker.

  • 22evxpggnkyrxpluewqsrv5j4jtde6hut2peq3w44d6ase676qlkoead.onion

The current site was no longer live, making StealthMole's historical indexing particularly useful. A historical snapshot dated 2026-08-02 showed the site under the name TeamPCP. However, a further look into the historical snapshots showed that in March 2026, the website operated as CipherForce, making TeamPCP a later re-branding.

That provided the first direct route into the wider TeamPCP investigation. A subsequent Dark Web Tracker pivot on the onion domain produced two identifiers:

Session ID

05a04c*******************************************5823e

TOX ID

BA8***********************************************069F2

Searching the Session ID expanded the investigation beyond the CipherForce onion itself and surfaced material across additional underground services. These identifiers allowed the investigation to follow the same technical thread into places where the name CipherForce did not necessarily appear.

One of the more relevant results was a Breached thread titled “Signs of life amidst rumors”:

  • https://breached.**/threads/signs-of-life-amidst-******1/

The post said TeamPCP would no longer work with Hasan and would instead continue operating on that branch of the forum. It made a number of claims about Hasan's treatment of staff and vetting, alleged that Hasan had been phished for domains and had lost access to his own database, and said that TeamPCP members had remained active despite difficulty reaching the group's public-facing spokesperson.

The same post rejected speculation that the team had been arrested or “fedded.” It also described a contingency in which the TeamPCP alias could be transferred to another operator if the poster was arrested or retired, and directed people requiring forum matters, operational partnerships or access/data toward the “OG tox or session accounts.”

It is also worth mentioning that the post displayed the same Session ID and TOX ID identified during the CipherForce investigation.

TeamPCP Takes a Seat at the Table

The next major finding came from TeamPCP's own activity on Breached.

On 16 May 2026, the account published a thread under the title “TeamPCP Partnership / Forum Co-Ownership.”

  • https://breached.**/threads/teampcp-partnership-forum-co-ownership*****6/

The post announced TeamPCP's new role as co-owners of the platform, with authority over staffing, partnerships and major decisions. The responsibilities described by the account included infrastructure uptime and reliability, staff management, disputes, community guidelines, escrow services, new features, partner vetting, premium resources and databases, contests, community feedback and the verification of databases and tools.

The account also described a role in removing low-quality, fake or malicious content and rewarding verified contributors. It said the platform would provide more frequent updates to premium resources through the Breached CDN and closed with the signature:

“The PCP Cats.”

The same Session ID and TOX ID appear with the post:

  • 05a0**************************************************5823e
  • BA8***************************************************069F2

A StealthMole snapshot dated June 2026 showed the TeamPCP account with the role:

Co-Owner / Staff Member / Co-Owner

This was a notable shift in the investigation. TeamPCP was not simply appearing in material connected to attacks or stolen information. Its own account was presenting the group as part of the infrastructure and administration of an underground platform.

The responsibilities listed in the post also give some indication of the position TeamPCP claimed within that environment. They extended from keeping infrastructure online to managing staff, handling disputes and escrow, vetting partners and deciding what databases or tools should remain on the platform. That is a much broader role than simply maintaining an account on a forum.

The same technical identifiers linking back to the earlier CipherForce investigation were present here as well, giving the developing TeamPCP trail a consistent technical reference point.

What TeamPCP Was Selling

The same TeamPCP identity later advertised something very different.

The post, titled “Internal Github Source Code,” appeared at:

  • https://breached.**/threads/internal-github-source-c*******5/

The account was displayed as:

[Co-Owner] TeamPCP

The post offered approximately 4,000 private-code repositories and internal organizations. It provided a repository list at:

  • https://limewire.com/d/4HP********b4u

and a sample of two files at:

  • https://limewire.com/d/yMx********sN

The minimum offer was $50,000, while the screenshot showed a current offer of $95K.

The seller also went out of its way to describe the transaction as something other than ransomware. The post explicitly said it was not a ransom and that there was no interest in extorting GitHub. Instead, the buyer would receive the data, after which the seller said the data would be destroyed on their end.

There was another detail that would become relevant later: the account said it was retiring soon and that, if no buyer was found, the material would be leaked for free.

The wording provides a useful look at the group's claimed approach to monetization. The material was being offered as a commodity with a negotiated price, rather than being presented as a ransom demand against the organization whose infrastructure had allegedly been accessed. The $50,000 minimum and $95K current offer also show that the seller was treating the collection as a high-value asset in its own right.

At this point, the investigation had moved from ransomware into another type of underground transaction: the sale of private source code and internal repositories.

One Correlation That Did Not Fit: BulkDMT

The Session ID search also produced a result that looked interesting but could not be safely folded into the TeamPCP story.

The post was:

  • https://breachsta.**/topic/selling-access-to-proprietary-trading-firm-150bl*******xn3

It was dated 2025-09-11 and authored by BulkDMT on Sellers Place.

BulkDMT claimed access to an HFT proprietary trading firm with $150B monthly volume, including root access to cloud infrastructure, workstations and AI clusters, trading bot code, WireGuard profiles, authentication tokens and passwords, private Docker repositories, private PyPI, GitLab keys, Jupyter instances and API keys. The asking price was USD 4.5K in XMR, with the Telegram contact:

  • https://t.me/b*********T

The Session ID was the same:

  • 05a04****************************************95823e

But the TOX ID was not. BulkDMT was associated with the following TOX ID:

  • 8647********************************************E6A5

That difference matters. So does the date, which predates the CipherForce activity examined in this investigation, and the fact that the post was authored by BulkDMT rather than TeamPCP.

The shared Session ID was enough to make the result worth examining, but not enough to attribute the activity to TeamPCP or CipherForce. It remains an unresolved correlation rather than part of the group's established trail.

The GitHub Sale Leads to Telegram

Then the same session ID was further investigated in StealthMole’s telegram tracker, which indexed two messages mentioning the same session ID. The message, originally posted in a channel named “Breaches”, referenced the TeamPCP GitHub source code thread:

  • https://breached.**/threads/internal-github-source*******/

It also contains a telegram user ID, which was labelled as a burner telegram:

  • @TPCP******1

Moreover, the message also mentioned the same Session ID:

  • 05a04**********************************************5823e

together with the same TOX ID:

  • BA8D**********************************************5069F2

The significance of this result lies in what it adds rather than what it repeats. The GitHub thread had already established the source-code sale. The Telegram result provided a new account identifier associated with the communication surrounding that sale.

T-PCP: Following the Account

The newly found telegram account was further investigated using StealthMole’s telegram tracker. The tool indexed an active user account associated with the username.

  • Telegram User ID: 8542877306
  • First name: T-PCP
  • Username: @TPCP********1
  • Profile creation date: 2026-08-08

The account also used the same black-cat image as profile picture, seen on other TeamPCP-related accounts. It should be further noted that this account also appeared in multiple breached related telegram channels, including:

  • https://t.me/Br********zzi

The direct account record was useful because it provided more than a username. T-PCP is itself a TeamPCP-style identifier, and the account could be examined independently after first being surfaced through material referencing the TeamPCP GitHub sale.

That does not establish the real-world identity of the operator. There is no phone number or other direct identity information in the available record. What it does establish is a consistent account-level trail connecting the Telegram identifier to the wider TeamPCP investigation.

The account later appeared in a more contentious discussion.

On 27 August 2026, a message in the Data Hoarder channel stated: “Breachforums owners @hello*******2 and @TPCP*******1 have been arrested.”

The surrounding messages also claimed that bf.** would become a honeypot, discussed previous ownership and warned users against using the site.

Those statements remain third-party Telegram claims. The existence of the messages can be documented, but the available evidence does not independently establish that bf.** became a honeypot.

The Cat Across Platforms

The TeamPCP identity carries a recurring visual marker across the platforms surfaced through StealthMole. A Dark Web Tracker search for Team PCP returned a Spear CX profile:

  • https://spear.**/User-TeamPCP

The profile uses the same black-cat avatar seen on the T-PCP Telegram account. On its own, an avatar would be weak evidence, but its reuse becomes more useful when viewed alongside the other TeamPCP artifacts already identified.

StealthMole also surfaced the TeamPCP-branded image:

  • https://supplychain.breached.st/teampcp.jpg

The image carries TEAM PCP branding and the wording “NOW WITH CIPHERFORCE.” This is more direct than the shared avatar: the graphic itself places TeamPCP and CipherForce together, reinforcing the connection already observed when the historical CipherForce onion was indexed under the title TEAM PCP.

The cat therefore works best as a supporting cross-platform identifier, while the TeamPCP/CipherForce branding provides a stronger link between the two names. Neither should be treated as proof of the real-world identity behind the accounts.

The same StealthMole search also surfaced third-party Telegram discussion linking TeamPCP to another supply-chain attack:

  • “TeamPCP gonna do another large Supply chain attack, be ready for it”

The message also referenced https://t.me/team_pcp and a “+35k stars github repo.” Because this was commentary from another user rather than a TeamPCP-authored post, it is best treated as contextual evidence of how TeamPCP was being discussed, rather than as evidence of a specific operation.

PCPCat: A Different Kind of Operation

The investigation also surfaced earlier activity associated with PCPcat, providing a useful view of the TeamPCP ecosystem before the CipherForce ransomware activity examined in this case.

A 28 December 2025 post in the Telegram channel Slice For Life, carried the title “Operation PCPcat Exploits Next.js and React, Affecting Over 59,000 Servers”.

The reported operation involved the exploitation of Next.js and React environments and identified as the distribution infrastructure.

  • 6*.**7.*7.**0:**6

The same reporting was also preserved in a HydraForums thread:

  • https://hydraforums.**/Threads-news-59-000-servers-breached-operation-pcpcat-targets-react-and-next-js*********5

This activity predates the March 2026 CipherForce victim record seen earlier and adds an important layer to the timeline. The material associated with PCPcat describes large-scale exploitation of internet-facing application infrastructure rather than ransomware-based extortion, showing that the activity surrounding the TeamPCP identity set extended into mass exploitation of web technologies before CipherForce appeared in the ransomware monitoring trail.

Conclusion

The investigation ultimately points to a TeamPCP ecosystem that is more interconnected than any single platform or alias would suggest. What makes the trail compelling is not one decisive artifact, but the way CipherForce, TeamPCP, PCPcat and the related accounts repeatedly converge across different environments. The historical CipherForce infrastructure, recurring identifiers, TeamPCP forum activity, Telegram presence and shared branding provide several independent points from which the same ecosystem can be followed.

At the same time, the investigation shows why those connections need to be handled carefully. Some relationships are supported by direct TeamPCP material and repeated technical or visual identifiers, while others remain dependent on third-party claims or incomplete correlations. The available evidence is therefore strong enough to map the digital footprint and operational reach of the TeamPCP ecosystem, but not to turn that footprint into a definitive real-world attribution. In an environment where aliases, accounts and infrastructure can shift quickly, following how those pieces connect is often more useful than relying on a single name or isolated incident.

Editorial Note

Dark-web investigations rarely provide a single piece of evidence that can settle attribution with certainty. Accounts can change, infrastructure can disappear, aliases can be reused, and claims made within underground communities may remain difficult to verify independently. In this case, the investigation demonstrates the value of following those fragments together rather than relying on any one artifact.

StealthMole helped turn an initial ransomware lead into a wider cross-platform trail while allowing stronger evidence, supporting correlations and unresolved claims to remain clearly separated.

To access the unmasked report or full details, please reach out to us separately.

Contact us: support@stealthmole.com






Labels: ,

Where the Trail Leads: Inside Al-Shabaab’s Digital Media Network

Jihadist organizations have adapted to a digital environment in which communication is no longer dependent on a single website, forum or dedicated platform. Messaging applications, social networks and alternative publishing platforms allow extremist groups to distribute propaganda, communicate narratives, publish claims and redirect audiences between different online spaces. This also creates a challenge for investigators: the most useful evidence may not be found on an account that openly identifies with an extremist organization, but somewhere further along the chain of distribution.

Al-Shabaab is a particularly relevant example. The Somali jihadist organization has developed a sustained media presence around its activities in Somalia and the wider region, using digital channels to communicate its narratives and disseminate material associated with the group. Its media activity extends beyond individual posts and can involve multiple platforms, accounts and distribution points.

For an investigator, this creates a more difficult question than simply asking whether Al-Shabaab has an online presence. The more useful question is how that presence can be traced when its content is dispersed across different users and platforms, including spaces that may not appear extremist at first glance.

This investigation was designed around that question.

Additionally, another objective was to test how effectively StealthMole could support investigations into jihadist terrorism and different forms of extremist activity. Rather than beginning with known infrastructure and checking whether the platform could find it, the objective was to start with a basic search and see whether StealthMole could uncover and connect the wider media, communication and distribution ecosystem surrounding the group.

The investigation therefore became a test of the platform's ability to turn a relatively weak initial signal into a more meaningful intelligence picture.


The Ideology Behind the Network

Al-Shabaab's online presence needs to be understood in the context of its broader jihadist identity. The group is not simply an armed actor that happens to use the internet. Its media activity forms part of how it communicates its worldview, presents its activities and maintains an information presence beyond the physical areas in which it operates.

That makes its media infrastructure particularly important from an intelligence perspective. When an extremist group publishes material, the content itself may be only one part of the investigative picture. The more useful question can be how that material moves. Who republishes it? Which accounts repeatedly direct audiences toward the same source? Which platforms are used when another platform becomes difficult to access? Which websites, bots or channels appear repeatedly alongside official material?

These questions matter because extremist communication networks are rarely limited to one account or one website. A single media organization can have several points of distribution, while supporters or other users may reproduce its material elsewhere. As a result, an investigator looking only for an account explicitly identifying itself with the group can miss a substantial amount of the surrounding activity.

The distinction between official media infrastructure and secondary distribution is also important. An account sharing Al-Shabaab material is not automatically an Al-Shabaab operative. Likewise, a Telegram group containing Al-Shabaab-related posts is not necessarily an Al-Shabaab-controlled group. The evidentiary value of each finding depends on what can actually be established about the relationship.

This distinction became particularly important during this investigation. The investigation encountered a mixture of clearly identifiable Al-Shabaab media references, repeated distribution activity by individual users, official communication points and apparently unrelated communities in which the material appeared. Treating all of these entities as one homogeneous network would have overstated the evidence.

Instead, the investigation followed a narrower principle: use confirmed media points as anchors, then examine how those points are referenced and redistributed across the wider digital environment.


One Keyword, One Unexpected Lead

The investigation began in StealthMole's Telegram Tracker with a deliberately broad search for:

  • al-Shabaab

StealthMole returned:

  • 361 Telegram messages
  • 2 Telegram users
  • 20 images
  • 190 documents
  • 43 other files

At first glance, the result did not immediately point toward an obvious Al-Shabaab-operated channel. One of the relevant results came from a Telegram channel titled:

  • ملتقى مهندسي الميكاترونكس

The channel was accessible at:

  • https://t.me/mech*****3

The channel presented itself as a mechatronics engineering community and had 1,180 members. Its visible content included technical material, including a pinned message relating to robotic simulation, robotic arms and agricultural pesticides.

That made the initial discovery more interesting, rather than less.

The search had not simply returned an obviously extremist channel. Instead, StealthMole had surfaced Al-Shabaab-related material within a community whose visible identity was technical and unrelated to jihadist activity. Rather than assuming the channel itself was connected to Al-Shabaab, the next step was to determine who had posted the relevant material and whether the same activity appeared elsewhere.

A message with the following ID provided the first meaningful pivot.

  • 1307071588_30161

The message was associated with:

  • Telegram user ID: 8008400988
  • First name: سويلم
  • Username: @sal*******6

The account information available through the investigation did not provide a last name, phone number or biography.

The message contained the hashtags:

  • #Somalia
  • #Mogadishu
  • #Alshabaab
  • #AS

It also contained:

  • https://shahadanews.info/?p=27068

Moreover, the accompanying image in the message was identified as an official Al-Shabaab photo.


The Account Behind the Message

Rather than stopping with the single message, the investigation pivoted on @sal******6 inside StealthMole's Telegram Tracker.

This produced four messages from the same user within the Mechatronics channel. The significance of this result was the repetition.

The first finding could have been treated as an isolated instance of a Telegram user sharing extremist material. The additional messages made that explanation less useful. The same account was repeatedly circulating Al-Shabaab-related material and, importantly, repeatedly exposing additional communication points associated with Shahada News, the official media house of al-Shabaab group.

The investigation therefore moved from content identification to pattern identification.

Among the recurring contact points were:

  • @Akh**************bot
  • https://chirpwire.****/Sha***********y
  • https://bsky.app/profile/sh******news.bsky.social

Another message contained:

  • https://shahadanews.info/?p=27054

The value of @sal******46 was consequently not that the available evidence proved the account belonged to Al-Shabaab. It did not. What the evidence did establish was that the account repeatedly circulated Al-Shabaab-related material and, in doing so, exposed several communication points that could be investigated independently.

This distinction is important for attribution. The account could confidently be treated as a distribution point and investigative pivot, but not automatically classified as an Al-Shabaab member or operative.


Following the Media, Not Just the User

The most important pivot in the investigation was the move from @sal******6 to Shahada News.

Shahada News is a known Al-Shabaab media house responsible for official communications. This gave the recurring references to its media points a substantially different evidentiary value from an ordinary social-media account reposting extremist content.

The investigation identified Shahada News across several platforms.

On ChirpWire:

  • https://chirpwire.net/Sha********cy

Its available profile information showed:

  • Handle: @Sha************cy
  • Bio: Press coverage of Somalia, East Africa and the Islamic world.
  • Location: Somalia
  • Member since: July 2024
  • 4,141 Chirps
  • 1,421 Followers
  • 24 Following

The account was actively used to publish Al-Shabaab-related material, including claims, official statements from leaders and videos. Its activity also established that the media presence extended beyond Telegram rather than being confined to a single messaging platform.

A Bluesky presence was also identified:

  • https://bsky.app/profile/sh************s.bsky.social

The significance of this finding was not simply that Shahada News had another social-media account. It showed that the same media operation had identifiable points of presence across different communication environments, giving investigators multiple places from which to observe activity and identify further distribution paths.

The investigation also encountered several Telegram-based contact points associated with the wider media ecosystem, including:

  • @Wakalathhahbot
  • @wakkkalaatshahadabot
  • @akhbaralameslamibot
  • @Akhbaralalamaslambot

Additional bot names surfaced during subsequent searches, including:

  • @ekhbaralambot
  • @Shawanewsagencybot
  • @Ehdathebrazbot
  • @Ekhbarislamworldbot
  • @SHWAEKHBOT
  • @hdathebrazbot

The broader finding was therefore stronger than any individual username: Shahada News appeared to operate within a multi-platform communication environment, with Telegram bots and accounts providing additional routes to material and external platforms providing further distribution.


The Network Starts to Take Shape

The next pivot came from the Bluesky profile:

  • https://bsky.app/profile/sha********s.bsky.social

Searching this identifier in StealthMole's Telegram Tracker surfaced multiple messages that referenced the same media ecosystem.

Clearly identified message IDs included:

  • 1307071588_30046
  • 1307071588_30045
  • 1307071588_30006
  • 1307071588_30001
  • 1307071588_29894

The results also exposed additional Telegram user IDs:

  • 8042389197
  • 6738658884
  • 7760032048

The available evidence did not provide enough information to attribute these users to Al-Shabaab, so they remained unresolved.

More important were the recurring infrastructure and communication references that appeared across the results:

  • https://shahadanews.info
  • @Wakalathhahbot
  • https://chirpwire.***/Sha************cy
  • https://bsky.app/profile/sha*********s.bsky.social

A private Telegram invite was also surfaced:

  • https://t.me/+vLVTo_hNyaU0Mzg0

Other messages exposed additional contact points, including:

  • @wakkkalaatshahadabot
  • @akhbaralameslamibot

A Facebook page was also visible:

  • https://www.facebook.com/News.of.the.World46

The significance of this stage was the cross-platform recurrence.

The investigation was no longer dependent on a single Telegram account. The same media identity was appearing through Telegram, ChirpWire and Bluesky, while Telegram searches were simultaneously revealing bots, private channels and other users connected to the circulation of the material.

This made the digital environment more intelligible. The network did not appear as one clean diagram with a central account and clearly labelled affiliates. Instead, it emerged through repeated references between different platforms.

That is a more realistic picture of extremist online activity: some nodes can be confidently identified, some can be linked through repeated evidence, and others remain unknown until additional information becomes available.


Beyond the Obvious

One of the most useful findings came from returning to the original Telegram community:

  • https://t.me/mech*******3

The purpose of this pivot was straightforward: determine whether the initial result was simply an isolated message from @sal*******6, or whether other Al-Shabaab-related activity existed within the same environment.

The answer was the latter.

Multiple Al-Shabaab-related messages and videos had been posted by users other than Salman1446. This was significant because it changed the interpretation of the original channel.

The channel itself remained a mechatronics community, rather than an Al-Shabaab channel. Its visible identity was technical, it had 1,179 members, and its pinned content concerned engineering-related subjects.

Yet StealthMole surfaced extremist-related material inside that environment.

Among the material identified was a Shahada-branded post from November 2024 containing:

  • https://shahadaagency.net/?p=24056

Another post, dated around November 17, 2024, promoted:

  • @Siham_Al_Khair_04_bot

and

  • https://t.me/Siham_Al_Khair_04_bot

The accompanying Arabic material referred to jihadist and mujahideen-related news and content.

A Somali-language post dated around November 20, 2024 provided another example. Its headline was:

  • WEERAR LAGU QAADAY FARIISIN MALEESHIYAADKA MURTADIINTA AY KU LAHAAYEEN DULEEDKA DEEGAANKA BIRTA DHEER

The post referenced:

  • WILAAYADA ISLAAMIGA EE JUBBADA HOOSE

and contained several external distribution points:

  • https://t.me/+s-fy3YJKuDo5Yml0
  • https://www.facebook.com/News.of.the.World46/videos/1641062710140510
  • https://archive.********/index.php/s/FtrgGns29Lgmf5t
  • https://watch******e.**/h/other/post/247502/deg-deg-daawo-weerar-lagu-qaaday

Another Shahada-branded Arabic post from around November 6, 2024 concerned an alleged attack involving government militias and Al-Shabaab around Kismayo and Lower Juba.

These findings matter for two reasons.

First, they showed that the presence of Al-Shabaab-related material in the mechatronics group was not dependent on Sal*******6 alone. Multiple users were posting or distributing such content.

Second, the finding illustrates why investigations based only on obvious extremist channels can miss relevant activity. The community did not advertise itself as an extremist space. Its primary identity was technical, yet extremist media was nevertheless present within it.

That does not establish that the administrators or members of the channel as a whole were affiliated with Al-Shabaab. There is insufficient evidence for that conclusion.

What it does establish is narrower and more useful: Al-Shabaab-related material was being circulated within a broader Telegram environment that, on its face, was unrelated to jihadist activity.


The Media Trail Goes Further

The investigation then pivoted from the Bluesky reference to the ChirpWire account:

  • https://chirpwire.net/Sha*************cy

Searching for this identifier in StealthMole surfaced a series of Telegram messages spanning several months. The references to Shahada News were not confined to one day or one Telegram user. StealthMole was surfacing repeated references to the media operation across a period extending from November 2024 into February 2025.

The same search also exposed a growing collection of Telegram bot/contact identifiers, including:

  • @wakkkalaatshahadabot
  • @akhbaralameslamibot
  • @ekhbaralambot
  • @Shawanewsagencybot
  • @Ehdathebrazbot
  • @Ekhbarislamworldbot
  • @SHWAEKHBOT
  • @hdathebrazbot

A private Telegram invite was also identified:

  • https://t.me/+zwcrODfjyRESZDkO

The chronology also demonstrated that the media ecosystem had multiple distribution mechanisms operating over time. Telegram posts could point toward external social platforms, while searches for those external identifiers could lead back to Telegram messages containing additional contact points.


When the Trail Changes

One of the more unusual findings concerned the domain:

  • https://shahadanews.info

The domain appeared repeatedly during the investigation and was directly referenced in Al-Shabaab-related Telegram material, including:

  • https://shahadanews.info/?p=27068
  • https://shahadanews.info/?p=27054

Its historical appearance made it relevant to the investigation.

However, when the domain was accessed during the investigation, it no longer presented Al-Shabaab-related material. Instead, it currently hosts Norwegian-language casino content, including references to new casinos and gambling-related reviews.

This creates an important intelligence distinction between historical evidence and present-day infrastructure.

The historical Telegram references establish that shahadanews.info was being used as a destination in Al-Shabaab-related communications at the time those messages were circulated. Its current content, however, does not support describing the domain as an active Al-Shabaab website.

The available evidence does not establish what caused the change. Possible explanations could include later repurposing, transfer, expiration and re-registration, compromise or another change in control, but none of these can be established from the evidence collected in this investigation.

At the same time, the investigation identified a separate currently active website:

  • https://sha*************ws.***

The site presents itself as Shahada News Agency, with Arabic branding and sections covering news, reports, photographs/articles, studies and translations, and opinion-related content. Its current presentation is consistent with the Shahada News media identity encountered through the other investigation pivots.

The distinction between the two domains is important. It prevents the historical shahadanews.info reference from being incorrectly treated as evidence of current infrastructure while preserving its relevance as part of the historical communication trail.


Conclusion

The investigation showed that Al-Shabaab-related media activity extends beyond clearly identifiable extremist channels and can surface within broader online communities through repeated redistribution. Shahada News emerged as the strongest identifiable anchor in the network, with its presence recurring across Telegram, ChirpWire, Bluesky and multiple Telegram-based contact points.

The findings also highlight the importance of separating media infrastructure, distribution activity and attribution. While the evidence establishes a clear connection to Shahada News as an official Al-Shabaab media operation, it does not justify treating every user, channel or bot encountered along the trail as an Al-Shabaab affiliate. The investigation was therefore most useful not for producing a simple list of associated accounts, but for revealing the wider communication environment surrounding the group's media activity.

Most importantly, StealthMole made that environment discoverable from a single broad keyword. By allowing individual messages, users and URLs to become investigative pivots, the platform helped turn an initially isolated Telegram result into a broader view of how Al-Shabaab-related material was being distributed across platforms.


Editorial Note

As with most investigations into cyber and dark-web activity, the available evidence rarely provides absolute attribution or a complete picture of every relationship. Accounts can be repurposed, domains can change hands, content can be redistributed by users with different motivations, and an apparent association does not always establish operational control.

This case demonstrates the value of following those uncertainties rather than forcing premature conclusions: StealthMole helped connect individual pieces of historical and cross-platform evidence while still allowing unresolved entities and attribution gaps to remain unresolved.

To access the unmasked report or full details, please reach out to us separately.

Contact us: support@stealthmole.com


Labels: ,

The Digital Bloodline: Tracing Blood Tribe’s Network Across Telegram

Blood Tribe is a U.S.-based neo-Nazi and white supremacist organization founded in 2021 by former U.S. Marine and tattoo artist Christopher Pohlhaus, better known as “Hammer.” The group claims chapters across the United States and Canada and has built its identity around an explicitly white-supremacist worldview. Its stated objective is the creation of an all-white ethnostate through the removal of Jews and non-white minorities it considers enemies of the white race. Its ideological influences include Norse Paganism, Odinism or Wotanism, and esoteric Hitlerism.

The group's development has also been closely tied to efforts to build physical and online communities. Before Blood Tribe's wider expansion, Pohlhaus attempted to establish a white-supremacist camp on property he purchased in Springfield, Maine. The project ultimately failed, but Pohlhaus subsequently focused on expanding Blood Tribe's presence across social media and recruiting new members.

Ohio occupies an important place in that history. Blood Tribe's first public appearance took place in Wadsworth, Ohio, in March 2023, followed by further activity around LGBTQ+ events in Ohio and Wisconsin. The group later became prominent in the controversy surrounding Springfield, Ohio, in 2024, where Blood Tribe members participated in spreading racist claims about the city's Haitian community. Christopher Pohlhaus and Blood Tribe second-in-command Drake Berentz subsequently became defendants in a federal civil lawsuit brought by the City of Springfield and others.

The group's name itself, Blutstamm, is German for “Blood Tribe” and reflects the organization's use of German terminology and Nazi symbolism. Its imagery also incorporates Armanen runes, which Blood Tribe uses as part of its wider neo-Nazi and esoteric visual identity.

Against this background, the investigation focused not simply on Blood Tribe's public identity, but on how its digital presence was organized: where its channels led, how regional structures were connected, which identities appeared behind them, and what other forms of activity could be identified from the digital trail.

Christopher Alan Pohlhaus aka Hammer, Leader of Blood Tribe

Where the Investigation Started

The investigation began with a simple keyword search in StealthMole's Telegram Tracker:

  • Blood Tribe Ohio

The search returned a Telegram channel titled:

🩸 BLOOD TRIBE OHIO 🩸

  • Channel URL: https://t.me/bloodtribeohio
  • Channel ID: 1910294769

This became the starting point for the investigation.

Among the historical messages returned by StealthMole was a March 2023 post referring to “Hammer, Blood Tribe Ohio, and White Lives Matter” and celebrating their confrontation with opponents. Other captured material showed the channel being used to publish openly extremist content and to communicate with individuals discussing Blood Tribe's activities in Ohio.

One exchange was particularly revealing. An account identified as @Byehlik stated that they were in the Columbus Ohio chapter and challenged Blood Tribe Ohio to meet publicly. The account representing Blood Tribe Ohio responded that Columbus was “right where we're at” and invited the individual to name a time and place. The exchange provides evidence of an online interaction involving the Blood Tribe Ohio account and an individual claiming affiliation with the Columbus chapter. The claim of chapter membership, however, was made by @Byehlik and was not independently established by the screenshot.

Another historical post from the channel announced an upcoming rally and said that the group intended to gather “as many Nazis as we can.” The accompanying imagery contained Nazi symbolism and violent imagery.

The channel's historical statistics provided another indication of its reach. For the period 26 March–2 April 2023, StealthMole displayed:

  • 4.3K followers
  • +2.7K followers / +181.3%
  • 75.26% enabled notifications
  • 1.1K views per post
  • 11 shares per post

The associated growth chart covered 10 March–2 April 2023 and showed a sharp increase in followers during the period.

The same initial investigation also surfaced a 55-page federal court complaint:

  • gov.uscourts.ohsd.299994.1.0.pdf

The document relates to Case No. 3:25-cv-33 in the U.S. District Court for the Southern District of Ohio, Western Division, and names The Blood Tribe, Christopher Pohlhaus, Drake Berentz and John Does 1–7 as defendants. The plaintiffs include the City of Springfield, Ohio, Mayor Rob Rue, city officials and Springfield residents.

The complaint alleges a campaign of harassment and intimidation directed at people associated with Springfield's Haitian community. As a court complaint, however, these are allegations made by the plaintiffs and not findings established by the court.

The initial search therefore produced two important starting points: a dedicated Ohio Telegram channel with historical activity, and documentation showing that Blood Tribe's Ohio activity had subsequently become the subject of federal litigation.

Following the Messages Trail

Rather than stopping at the channel's public profile, the investigation moved deeper into its historical content using StealthMole’s Telegram Tracker. The search returned 952 messages.

  • Telegram Channel: 1910294769

The expanded dataset provided a much wider collection of identifiers and links.

One of the first important artifacts was:

  • B********M@protonmail.com

A message dated 30 January 2025 invited users who were “curious” to make contact through the address. The message was forwarded into the Blood Tribe Ohio channel from another Telegram source, meaning the email's presence in the channel is directly observable, but the forwarded origin should not automatically be treated as the email's operator.

The same channel history also contained references to Blood Tribe's wider online presence.

Among the identified links were:

  • Blood Tribe Gab: https://gab.com/B******e
  • Hammer Telegram: https://t.me/p********r
  • Hammer Gab: https://gab.com/BL******G
  • Hammer X: https://x.com/b*****g

A September 2024 forwarded post containing the Blood Tribe Gab account claimed that Blood Tribe was closely following events in Springfield, Ohio and claimed to have people on the ground and a network of local informants.

The channel also contained a February 2025 post instructing followers to follow Blood Tribe and its leader Chris Pohlhaus, also known as Hammer, across Telegram and X.

The 952-message history therefore changed the direction of the investigation. What initially appeared to be a single Ohio-focused channel was becoming a gateway to a much broader collection of accounts, platforms and regional structures.

When One Channel Points to Another

The next step was to take the known Blood Tribe Ohio URL and search it outside Telegram. It was searched in StealthMole's Dark Web Tracker.

  • https://t.me/bloodtribeohio

That pivot surfaced material hosted on I2P. One of the results was:

  • http://revx7if*************2.i2p/@TexasVet:6/Episode-114:3?nojs=1

The page was titled:

  • “THE FOURTEEN WORDS PODCAST EP. 114 - 6MAY2023 Hammer”

The I2P page provided an important new set of pivots. Under “Hammer's links”, it listed:

  • https://t.me/p***********er
  • https://t.me/bl***********o

The page also identified:

Blood Tribe Merch: D************books.com

Blood Tribe new members: https://t.me/+2B**********E5

Donation: https://givesendgo.com/b*********e

The Telegram invitation was later found to be expired, while the GiveSendGo campaign was unavailable when checked.

The same I2P material also linked to the Odysee account:

  • https://odysee.com/@Te*****6

A second I2P result, associated with @jqrcode, was titled:

  • “The Hammer Interview, BloodTribe - 5/6/2023 - TexasVET”

This result again contained the same links to the Blood Tribe Ohio Telegram channel, Odysee and the GiveSendGo campaign.

These findings were significant because the same Blood Tribe and Hammer identifiers were no longer confined to Telegram. They appeared within I2P-hosted material and associated media content.

The investigation also encountered a commenter using a highly extremist username on one of the I2P pages. The account's comment praised Hammer and invoked the group's ideological beliefs. This was retained as an observed interaction, but not treated as evidence that the commenter was a Blood Tribe member.

The I2P results also provided a potential commercial lead:

  • Di**********s Books

The page explicitly labeled Di*********books.com as “BloodTribe Merch.” This establishes the description used by the I2P content, but the page itself was not treated as independent proof that the site was operated by Blood Tribe.

Building the Map

The expired “Blood Tribe new members” invitation became the next investigative pivot.

  • https://t.me/+2BEbDMSzgMNmMmE5

The invitation appeared in several Blood Tribe-related Telegram channels.

One message from Blood Tribe Dixie directed prospective members toward the invitation and referred to the process of joining the group's wider structure.

From these references, the investigation uncovered a much larger regional network.

United States

Blood Tribe Dixie 

https://t.me/BTDIXIE 

T.me/dixiecamps

Blood Tribe Upper Midwest 

https://t.me/BTUPPERMIDWEST 

T.me/uppermidwestcamps

Blood Tribe Pacific Northwest 

https://t.me/BTPNW 

T.me/pnwcamps

Blood Tribe South Central 

T.me/BTSOUTHCENTRAL 

T.me/btohio

Blood Tribe Ohio 

T.me/BLOODTRIBEOHIO 

T.me/btohio

Blood Tribe New England 

T.me/BTNEWENGLAND 

T.me/necamps

Blood Tribe Southwest 

T.me/BLOODTRIBESW 

T.me/BloodTribeSouthWestCamps

Additional regional artifacts included:

https://t.me/Bl************al

https://t.me/B******W

Canada

Blood Tribe East Canada 

T.me/BTEASTCANADA 

T.me/eastcanadacamps

Blood Tribe West Canada 

T.me/BTWESTCANADA 

T.me/westcanadacamps

The same investigation also identified:

https://t.me/B*************OT

The regional naming pattern was reinforced by a captured map dividing the United States and Canada into Blood Tribe regions. The map displayed areas including PNW, Southwest, South, South Central, Ohio, Upper Midwest, New England, East Canada and West Canada.

The Telegram evidence and the map together provide a picture of an organization attempting to divide its presence geographically.

The distinction between the regional Blood Tribe channels and the associated “Camps” channels is also notable. The evidence does not establish that every regional channel was equally active or operational, but it does show a repeated organizational pattern: a Blood Tribe regional identity paired with a separate Camps-related identifier.

The evidence therefore moved beyond a single Ohio presence. It pointed toward a broader U.S.- and Canada-facing online structure with regional identities and recruitment-oriented spaces.

The People Behind the Addresses

The BL*******M@protonmail.com address provided another investigative pivot.

A search for the address in StealthMole's Telegram Tracker returned a Telegram identity associated with:

Nathaniel Higgers

  • Telegram ID: 5743881965
  • Username: @Y*********Nate
  • Bio: “Forehead Connoisseur”

The significance of the finding was not limited to the current profile.

StealthMole's historical results showed the same Telegram identity appearing under multiple names and usernames over time. The captured historical variants included Nathaniel Higgers, Herzog Higgers, and several different usernames, including @Y*******Nate and other highly extremist handles.

This historical variation is important because the Telegram ID remained the more useful identifier than any individual username.

The investigation also found a direct contextual connection between the email address and Blood Tribe's recruitment process. A HAMMER message dated 20 March 2024 stated that the group's Telegram vetting account had been banned and directed prospective members to:

  • B*********M@protonmail.com

The message instructed people seeking to join the group's “Camps” to use the email address for further instructions.

This was one of the clearest examples in the investigation of the value of historical identity data. A single current username would have provided only a snapshot; the historical Telegram records exposed changes that would otherwise be easy to miss.

The HAMMER Channel

The investigation then moved directly into the Telegram channel associated with HAMMER:

  • https://t.me/p************r
  • Channel ID: 1700136522

The channel became an important central pivot because its posts connected several of the artifacts already discovered.

The channel contained Blood Tribe-related links, recruitment material and references to other parts of the group's online ecosystem.

Among the identified artifacts were:

  • https://t.me/b*******ohio
  • https://t.me/Bl*********al
  • https://t.me/B****W
  • https://t.me/BT*******T

and:

  • https://gab.com/Bl*********Midwest

The channel also contained material directing followers to external platforms and accounts.

A January 2024 post linked to the older X/Twitter account:

  • https://twitter.com/hammer_pohlhaus/

A specific post was captured at:

  • https://twitter.com/hammer_pohlhaus/status/1749888513737359668

The January 2025 material instead showed the X identity:

  • Chris Pohlhaus: @blut_konig

The captured account contained Blood Tribe-related content and references to other far-right figures and accounts.

A separate December 2024 post from the same displayed identity contained explicit praise of Adolf Hitler and rejection of the historical defeat of Nazi Germany.

The investigation also identified another X account, which was suspended when checked.

  • https://x.com/blutstamm

The combination of Telegram links and cross-platform references showed that the HAMMER channel was not operating as an isolated communications point. It repeatedly directed followers toward Blood Tribe regional infrastructure, recruitment-related resources and external social platforms.

Merchandise, Weapons and the Money Trail

The investigation also uncovered evidence of activity extending beyond communication and recruitment.

Merchandise

The I2P material identified: Dissident Minds Books as “BloodTribe Merch.”

A separate HAMMER Telegram post later directed followers toward a Blood Tribe merchandise page:

  • https://www.thesh*******p.com/product/blood-tribe-blutstamm/

The post advertised new Blood Tribe shirts and directed users to the external store.

Weapons

Blood Tribe Ohio promoted content also contained imagery advertising a weapon.

The captured listing described a: “Black oak handle Sæx” with a 7.5-inch blade and a displayed price of $150.

The associated material directed prospective buyers toward and stated that payment was accepted through Cash App.

  • vol***********e@protonmail.com

These artifacts demonstrate the circulation of weapon-related commercial content through the Blood Tribe Ohio ecosystem. They do not, without further evidence, establish who manufactured or operated the associated sales infrastructure.

Fundraising

The previously identified fundraising page was:

  • https://givesendgo.com/bloodtribe

When checked, the page displayed: “This fundraiser is not active.”

The historical I2P material nevertheless preserved the URL as part of the Blood Tribe-related online ecosystem.

More importantly, HAMMER's Telegram channel contained a message providing a Bitcoin address in the context of supporting Blood Tribe.

  • BTC address: 3My2**************************wau

StealthMole's Crypto Tracker was then used to investigate the address. The blockchain displayed an amount of 11.26697765 BTC and a Graylist classification.

  • 4 transactions
  • 2 incoming transactions
  • 2 outgoing transactions
  • 0.039062 BTC received
  • 0.039062 BTC sent
  • Current balance: 0 BTC
  • First transaction: 15 April 2023
  • Last transaction: 3 November 2023

The address-level blockchain view records only 0.039062 BTC received and sent, while the Crypto Tracker displayed the much larger 11.26697765 BTC figure in its transaction visualization. Because the available evidence does not establish exactly what the larger figure represents, it should not be interpreted as the amount transferred by the Blood Tribe-associated address.

The external blockchain view also displayed a BetVIP label associated with the destination. That label was not treated as evidence of any relationship between BetVIP and Blood Tribe.

The strongest conclusion from the financial investigation is therefore narrower: a Bitcoin address was publicly provided through HAMMER's channel in connection with support for Blood Tribe, and StealthMole was able to trace its historical blockchain activity.

The Names Change, the Network Remains

The final stage of the investigation brought together the cross-platform identity artifacts that had appeared throughout the earlier searches.

The older X account was directly referenced from HAMMER's Telegram channel.

  • https://twitter.com/hammer_pohlhaus/

The later X identity appeared in captured material identifying the account as Chris Pohlhaus.

  • https://x.com/blut_konig/

The investigation also identified, which was suspended when checked.

  • https://x.com/blutstamm

On Gab, the investigation found:

  • https://gab.com/Bl*****e
  • https://gab.com/BL*****G
  • https://gab.com/Bl**********Midwest

These accounts appeared through Blood Tribe-related Telegram and I2P content rather than being discovered independently.

The cross-platform evidence also highlighted why historical preservation matters in extremist investigations. Accounts can disappear, usernames can change and channels can become inaccessible. In this case, StealthMole's historical records preserved references to identities and links that were no longer necessarily available when revisited.

The investigation therefore did not depend on any single live account remaining online. Instead, the relationships between the historical artifacts provided the investigative value.

Conclusion

The investigation began with a single search term and an Ohio Telegram channel. By following the artifacts surfaced through that channel, the picture expanded into a network spanning regional Telegram channels, “Camps,” recruitment and vetting mechanisms, historical identities, social-media accounts, I2P-hosted content, merchandise, weapons-related material and financial-support infrastructure.

The most significant finding is not simply that Blood Tribe maintained an online presence. It is that its digital footprint was distributed across multiple interconnected layers.

At the center of the investigation was the Blood Tribe Ohio channel. From there, historical messages exposed links to HAMMER and other Blood Tribe accounts. The Dark Web Tracker extended those connections into I2P content. The I2P material exposed recruitment and fundraising artifacts, which in turn led back to Telegram. The expired recruitment invitation opened another path into regional channels and Camps. Finally, searches for individual identifiers such as B*********M@protonmail.com produced historical account data that added an identity layer to the network.

The resulting picture is therefore one of a distributed digital ecosystem rather than a single Telegram channel.

StealthMole's historical preservation was particularly important in reconstructing that ecosystem. Several of the artifacts identified during the investigation were no longer fully accessible when revisited, including the expired Telegram recruitment invitation, the inactive GiveSendGo campaign and the suspended @blutstamm X account. The ability to locate historical references allowed those artifacts to remain part of the investigation even after their original availability changed.

Editorial Note

Dark-web and extremist-network investigations rarely provide absolute attribution. Accounts change usernames, content is forwarded between channels, platforms disappear and third-party infrastructure can be referenced without being controlled by the group being investigated. The findings in this report should therefore be understood according to the strength of each individual artifact and the relationships that can be demonstrated between them.

In this case, StealthMole's ability to preserve historical Telegram content and correlate identifiers across Telegram, I2P, social platforms and blockchain data helped turn a single search result into a much broader picture while still leaving room for uncertainty where the evidence does not support a definitive conclusion.

To access the unmasked report or full details, please reach out to us separately.

Contact us: support@stealthmole.com

Labels: ,

Learn more about StealthMole

Talk to our team of experts today to learn how you can manage your dark web exposure.
Request demo More Reports

Share this report