Beyond Defacement: Inside 313 Team's Hacktivist and Ransomware Operations

Armed conflicts have long extended beyond conventional battlefields, and in recent years cyberspace has become an increasingly important front in that struggle. Across the Middle East, groups aligned with various resistance movements have embraced cyber operations to amplify political messaging, disrupt perceived adversaries, and project influence beyond geographic borders. Website defacements, coordinated propaganda campaigns, and increasingly sophisticated cyber capabilities have become part of a broader digital strategy, allowing these actors to reach global audiences while demonstrating their presence in an evolving cyber landscape.

Among the groups operating in this space is 313 Team, an Iraqi hacktivist collective that has consistently linked its activities to the broader narrative of the Islamic Resistance. While the group's public image is largely built around high-profile website defacements carrying ideological messages, its online footprint suggests a more structured operation than its defacement campaigns alone might imply. Over time, the group has developed a recognizable digital identity across multiple platforms, maintaining a persistent presence while promoting its operations through coordinated messaging and branded content.

This report examines that wider ecosystem through the lens of StealthMole's intelligence capabilities. Rather than focusing on a single incident, the investigation pieces together the group's digital infrastructure, operational footprint, claimed offensive capabilities, and relationships within the broader hacktivist landscape. By correlating evidence from multiple sources, the report provides a closer look at how 313 Team presents itself, how it operates, and how its activities extend beyond the defacement campaigns that first brought the group into view.

The Digital Face of the Islamic Resistance

Investigations into threat actors often begin with a single indicator that appears routine at first glance but reveals a much larger story when examined more closely. In this case, the investigation began within StealthMole's Defacement Alert module while monitoring website defacement activity linked to hacktivist groups operating in the Middle East.

Among the recorded incidents was a defacement attributed to 313 Team, involving a Russian website. According to StealthMole's records, the incident was detected on 8 September 2023, making it one of the earliest observable activities associated with the group within the platform. While a single website defacement would not normally warrant an extensive investigation, the group's distinctive name and ideological branding suggested that there was likely more to uncover than an isolated attack.

  • http://in*******oy.ru

Rather than treating the defacement as a standalone event, the investigation shifted toward understanding the identity behind 313 Team. The next step was to determine whether the group maintained a broader online presence, particularly on platforms commonly used by hacktivist organizations to claim responsibility for attacks, distribute propaganda, and communicate with supporters. Using StealthMole's Telegram Tracker, a search for "313 Team" quickly revealed an active Telegram channel.

  • https://t.me/**313*****m

The channel immediately provided the first glimpse into the group's public identity. Rather than presenting itself simply as a hacking collective, the operators described themselves as the "Iraqi Cyber Army" and incorporated religious and ideological references throughout their profile, including "جنود الإمام المهدي" ("Soldiers of Imam al-Mahdi") alongside the hashtags #Free_Palestine and #Ya_Mahdi. The channel biography also pointed investigators toward additional Telegram assets, suggesting that the group maintained multiple communication channels to support its operations and preserve its online presence.

  • @**313******k
  • @**313*******up

These initial findings indicated that 313 Team was far more than a name attached to a defacement page. The group's branding, ideological messaging, and interconnected Telegram presence pointed toward a coordinated online ecosystem rather than a collection of isolated attacks. With the primary communication channel identified, the investigation shifted from establishing the group's existence to mapping the infrastructure, operational footprint, and digital assets supporting its activities.

Beyond the Mirror: Mapping 313 Team's Digital Infrastructure

With the group's primary Telegram channel identified, the investigation shifted towards uncovering the digital infrastructure that sustained its operations. Rather than examining individual attack claims, the focus turned to understanding how 313 Team maintained its online presence, communicated with supporters, and preserved continuity despite the risk of account removals and platform enforcement. Using StealthMole's Telegram Tracker as the primary pivot point, a much broader ecosystem began to emerge.

The first indication that 313 Team operated through multiple communication channels came directly from the biography of its primary Telegram channel, https://t.me/**313*****m. Alongside describing itself as the "Iraqi Cyber Army," the channel promoted two additional Telegram assets. While these references initially appeared to be simple backup links, further investigation revealed that each served a distinct operational purpose.

  • @**313*********k
  • @**313*********up

The @**313*********up channel functioned as a resilience mechanism whenever Telegram removed the group's primary presence. One announcement explicitly informed followers that the original 313 Team channel had been taken down for the second time and directed them to migrate to the backup channel so they could continue following future operations. Rather than disrupting the group's activities, platform enforcement had been anticipated, with alternative channels already in place to preserve its audience and maintain operational continuity.

A different role emerged for @**313*********k, which was used to distribute material allegedly obtained during cyber operations. Posts within the channel contained download links, passwords, and references to archived data, while repeatedly directing followers back to the backup channel to ensure continued access if additional channels were removed. The coordinated cross-promotion between these Telegram assets demonstrated a deliberate effort to separate operational announcements from the publication of alleged stolen material while keeping followers connected across multiple platforms.

The investigation uncovered another public-facing channel, https://t.me/Team313******l, which primarily served as a showcase for the group's operations. Unlike the leak channel, posts here focused on announcing newly compromised websites, publishing screenshots of defacements, and highlighting the group's claimed successes. The consistent branding, language, and visual identity closely matched the primary Telegram channel, reinforcing the relationship between these assets.

Beyond Telegram itself, 313 Team maintained a presence across several external platforms that further strengthened attribution. The group's X account, mirrored the same ideological messaging and directed visitors back to its Telegram ecosystem, creating a bridge between mainstream social media and its primary communication platform. The investigation also identified the ProtonMail address, which appeared alongside the group's public messaging and represents a valuable attribution artifact that may assist future investigations involving the same operators.

  • Twitter: https://x.com/**313****m
  • Email: O********m@protonmail.com

Archived defacement records provided another layer of corroboration. Pages preserved on Mirror-H and OwnzYou displayed the same visual identity found throughout the Telegram ecosystem, including the group's logo, ideological slogans, references to the Iraqi Cyber Army, and direct links back to its social media accounts. Rather than existing as isolated mirrors of individual attacks, these archives connected the group's public claims with a consistent digital identity that persisted across multiple platforms.

  • Mirror-H: https://mirror-h.org/mirror/5******8/
  • OwnzYou: https://ownzyou.com/mirror/6c5*************896.html

The investigation also identified the public GitHub repository together with its associated GitHub Pages site, both promoting 313 HackBar v1.3. The project described functionality commonly associated with penetration testing, including SQL injection testing, cross-site scripting (XSS), fuzz testing, encoding utilities, and hash generation. While the repository was promoted through the group's Telegram channel, the available evidence does not independently establish that 313 Team developed the project. Nevertheless, its promotion demonstrates that the group's online presence extended beyond propaganda and attack claims to include publicly accessible technical resources.

  • GitHub: https://github.com/313Team/313-HackBar
  • GitHub Pages: https://313team.github.io/313-HackBar/

Another noteworthy discovery was the Telegram channel, operating under the name Team_313_Umar_Al_Khattab. Unlike the group's primary channels, this account predominantly shared cryptocurrency-related tools and blockchain utilities rather than attack announcements. Although the available evidence suggests a relationship with the wider 313 Team ecosystem, it does not conclusively establish that it is operated by the same administrators. As such, it is best regarded as an associated channel pending further corroboration.

  • https://t.me/r****ll

These findings reveal a far more structured digital ecosystem than a single defacement channel. Telegram served as the operational hub, while backup channels, leak channels, social media accounts, archived defacement platforms, public code repositories, and associated communication channels collectively reinforced the group's online resilience.

Each platform fulfilled a specific role, allowing 313 Team to preserve its visibility, distribute content, and maintain continuity even when individual accounts or posts were removed. By correlating these disparate artifacts, StealthMole transformed what initially appeared to be a single Telegram channel into a mapped digital infrastructure supporting the group's broader cyber operations.

More Than Defacement: Following the Ransomware Trail

While mapping the group's digital infrastructure, one recurring term began appearing across multiple Telegram posts and defacement messages: 313 Ransomware. Initially, it appeared to be little more than another piece of branding accompanying the group's propaganda. However, as additional messages were uncovered through StealthMole's Telegram Tracker, it became evident that the name was repeatedly associated with claims of system encryption rather than simple website defacements, suggesting that 313 Team sought to project capabilities beyond those typically associated with hacktivist campaigns.

To better understand this recurring reference, the investigation pivoted by searching "313 Ransomware" within StealthMole's Telegram Tracker. The search led back to the group's own Telegram channel, where a detailed post titled "313 Ransomware" offered the clearest insight yet into the capability the group claimed to possess. Unlike previous announcements celebrating website compromises or service disruptions, this post adopted a distinctly technical tone, describing what it portrayed as the ransomware's encryption process.

According to the Telegram post, the ransomware begins by enumerating every available drive before recursively traversing directories across the compromised system. For each file encountered, it claims to generate a unique ChaCha20 encryption key together with a corresponding nonce. Rather than encrypting files in their entirety, the post describes a partial encryption strategy in which one byte is encrypted followed by two bytes left unencrypted, a technique intended to balance encryption speed with the ability to render files unusable. The generated ChaCha20 keys and nonces are then said to be encrypted using Elliptic Curve Integrated Encryption Scheme (ECIES) before being prepended to each encrypted file.

The group further attempted to justify these design choices by claiming that ChaCha20 enabled efficient stream-based encryption while ECIES provided security comparable to RSA with shorter key lengths and improved performance. Whether these technical claims accurately reflect a functioning ransomware family cannot be determined solely from the Telegram post, and no malware sample was recovered during this investigation. Nevertheless, the level of technical detail distinguishes this announcement from the group's typical ideological messaging and indicates an effort to portray 313Ransomware as a credible operational capability rather than simply a symbolic name.

The ransomware branding was not confined to this single technical post. Earlier artifacts collected during the investigation showed the same name appearing repeatedly across the group's public messaging. An archived defacement warned that targeted organizations would have their databases leaked and website files encrypted using 313 Ransomware. Rather than presenting the operation as a conventional website defacement, the message framed it as part of a broader campaign involving data theft, encryption, and continued attacks against national infrastructure.

Historical Telegram messages further reinforced this narrative. One post describing an attack against the Abha Palace Hotel claimed that the group had not only defaced the website but also copied internal systems, extracted databases, deleted backups, and encrypted affected infrastructure using 313 Ransomware before publishing credentials required to access the allegedly stolen data. While these statements remain claims made by the group and were not independently verified during the investigation, they demonstrate that the ransomware branding had been integrated into the group's public operations well before the technical description was published.

A similar pattern emerged in messages directed toward other organizations. During a claimed attack against Ubuntu, 313 Team asserted that the target's servers and user systems remained completely frozen and instructed the organization to negotiate through the encrypted messaging platform Session, publishing the following identifier:

  • Session ID: 0574b***********************************5f0a

The post concluded by demanding that Ubuntu establish contact to negotiate what it described as a "permanent ceasefire." Another message addressed directly to eBay claimed that the company had already received an email containing the group's Session contact details and warned that attacks would continue until communication was established. Although neither incident could be independently verified through the available evidence, both messages closely resemble the negotiation tactics commonly employed by ransomware operators, where encrypted communication channels are provided for victim contact following an attack.

These findings suggest that 313 Team deliberately cultivated an identity extending beyond ideological defacement campaigns. Through repeated references to 313 Ransomware, technical explanations of its claimed encryption process, public extortion messages, and the publication of a dedicated Session identifier for negotiations, the group consistently portrayed itself as capable of conducting disruptive operations involving data theft, encryption, and victim negotiation.

While the investigation does not independently confirm the existence or effectiveness of the ransomware itself, it demonstrates that 313Ransomware had become a central component of the group's public operational narrative, marking a notable evolution from symbolic defacement activity toward messaging more commonly associated with ransomware operations.

More Than a Hacker Collective: Decoding 313 Team's Narrative

Throughout the investigation, one observation became increasingly clear: 313 Team consistently portrays itself as more than a conventional hacking group. While its activities revolve around cyber operations, the language, symbolism, and messaging surrounding those operations suggest that the group views cyberspace as an extension of a broader ideological struggle rather than simply another domain for conducting attacks.

This identity is established from the moment the group introduces itself. Across its Telegram channels, 313 Team repeatedly refers to itself as the "Iraqi Cyber Army" and "The Islamic Cyber Resistance in Iraq", while incorporating religious phrases such as "جنود الإمام المهدي" ("Soldiers of Imam al-Mahdi") and hashtags including #Ya_Mahdi and #Free_Palestine. The group's logo further reinforces this identity, featuring a raised hand holding an assault rifle above a globe alongside the Quranic verse, "Permission [to fight] has been given to those who are fought because they have been wronged" (Quran 22:39). Rather than functioning as decorative imagery, these elements frame the group's cyber operations as part of a larger religious and political narrative centered on resistance.

The significance of the name 313 also appears to support this narrative. Within Shia Islamic tradition, the number is commonly associated with the 313 companions of Imam al-Mahdi, who are believed to stand alongside him before the final establishment of justice. Although the group has not explicitly explained its choice of name, the repeated references to Imam al-Mahdi throughout its public messaging strongly suggest that the branding was chosen deliberately to reinforce this symbolic identity. The result is a consistent image of a cyber collective seeking legitimacy through religious symbolism rather than presenting itself simply as a group of hackers.

The targets highlighted throughout the group's public messaging further illustrate how it seeks to position its operations. Many of the claimed attacks involve organizations that the group associates with its political narrative, including Saudi government services, Israeli entities, and companies perceived as supporting opposing interests. At the same time, the investigation also identified claims involving international technology companies and commercial organizations such as Microsoft 365, Ubuntu, and eBay. This broader range of targets suggests that the group's messaging is not confined solely to government institutions. Instead, its public narrative portrays cyber operations against both public and private organizations as legitimate acts of resistance whenever they are believed to serve the group's broader ideological objectives.

Equally revealing is the language used to describe these operations. Throughout the Telegram posts examined during this investigation, attacks are rarely portrayed as criminal acts or opportunities for financial gain. Instead, they are consistently framed as acts of retaliation, resistance, or justice carried out on behalf of a wider cause. Even messages directed toward alleged victims adopt the language of conflict rather than conventional cybercrime. During the claimed attack against Ubuntu, for example, the group instructed the organization to negotiate a "permanent ceasefire" through an encrypted Session channel, while messages directed at eBay warned that attacks would continue until communication was established. This choice of language mirrors the rhetoric of armed conflict, reinforcing the group's effort to present itself as a participant in an ongoing struggle rather than a traditional ransomware operation.

The investigation also showed that 313 Team's Telegram ecosystem serves purposes extending well beyond announcing cyberattacks. Alongside operational updates, the group distributed technical resources such as the VigilAir drone detection document and the Naem Spy System Mehrdad Rahimi Contacts directory. The presence of these documents within the group's channels suggests an attempt to position Telegram as a broader repository for technical knowledge, operational resources, and intelligence-related material. This combination of propaganda, technical content, and operational announcements helps cultivate an image of an organized movement rather than a collection of isolated actors.

These observations indicate that 313 Team places as much emphasis on shaping perception as it does on claiming cyber operations. Its messaging consistently blends religious symbolism, political narratives, technical content, and cyber activity into a unified public identity. Whether announcing a website defacement, promoting what it describes as 313Ransomware, or distributing technical material through Telegram, every communication reinforces the same overarching message: that the group's cyber activities are intended to be viewed not as isolated hacking incidents, but as contributions to what it describes as the broader Islamic cyber resistance.

Conclusion

What began as the investigation of a single website defacement ultimately revealed a far more structured and deliberate cyber operation. By correlating evidence across StealthMole's Defacement Alert and Telegram Tracker, the investigation uncovered an interconnected ecosystem extending well beyond isolated attack claims. Telegram channels, backup infrastructure, defacement archives, public code repositories, communication identifiers, and ransomware-related messaging collectively paint the picture of a group that has invested considerable effort in building and maintaining a recognizable digital presence.

The investigation also demonstrates that 313 Team actively cultivates an identity that combines ideological messaging with cyber operations. Rather than portraying its activities as ordinary cybercrime, the group consistently frames its operations within the broader narrative of the Islamic Resistance, using religious symbolism, political messaging, and coordinated propaganda to reinforce that identity. Its repeated references to 313Ransomware, public negotiation messages, and technical discussions further suggest an effort to project capabilities extending beyond website defacements, even where those capabilities cannot be independently verified through the available evidence.

Perhaps the most important outcome of this investigation is not the confirmation of any single attack, but the ability to connect fragmented pieces of publicly available information into a coherent operational profile. Viewed individually, a defacement page, a Telegram post, or a GitHub repository may appear insignificant. Examined together, however, they reveal how 313 Team communicates, how it sustains its online presence, and how it seeks to shape perceptions of its own capabilities. That broader understanding provides a stronger foundation for future monitoring than any individual attack claim alone.

Editorial Note

Cyber threat investigations rarely produce absolute answers. Public claims, defacement pages, and online personas often mix verified activity with exaggeration, making careful attribution essential. This investigation demonstrates how StealthMole enables analysts to move beyond isolated indicators by correlating infrastructure, communications, and digital artifacts across multiple sources. While the operational picture surrounding 313 Team will undoubtedly continue to evolve, documenting and connecting these observable elements provides valuable context for understanding both the group's current activities and its future trajectory.

To access the unmasked report or full details, please reach out to us separately.

Contact us: support@stealthmole.com

Labels: ,

Beyond the Leak Site: Uncovering Lynx Ransomware's Infrastructure

Ransomware operations have evolved well beyond encrypting files and demanding payment. Many now function as structured criminal enterprises, maintaining dedicated leak sites, communication portals, and supporting infrastructure designed to pressure victims, manage negotiations, and reinforce their public presence. While these websites often become the most visible part of a ransomware operation, they rarely tell the full story.

Lynx is one such group. Since emerging on the ransomware landscape, it has established an online presence that extends beyond publishing victim information. Like many modern ransomware operations, its infrastructure consists of multiple interconnected components that each serve a distinct purpose, offering valuable insight into how the group presents itself and supports its activities.

This report explores Lynx's publicly accessible infrastructure through a technical investigation conducted using StealthMole. By following infrastructure pivots, examining hidden services, and correlating findings across multiple StealthMole datasets, the investigation moves beyond the group's leak site to build a broader picture of its operational footprint. Rather than focusing on individual attacks or victim disclosures, the report examines the digital infrastructure surrounding the operation and the intelligence that can be uncovered by following those connections.

Behind the Curtain

The investigation began in StealthMole's Government Monitoring module, where a search for "Lynx" returned 8 government-sector organizations that had been listed by the group. The most recent entry was the Talbot County Department of Emergency Services (DES), whose disclosure page included a description of the organization, its reported annual revenue, and the date the listing was published. While the victim itself was not the focus of this investigation, the listing provided an entry point into Lynx's ecosystem and established a starting point for exploring the infrastructure supporting its operations.

  • http://lynxblogoxllth4b46cfwlop5pfj4s7dyv37yuy7qn2ftan6gd72hsad.onion/leaks

To understand the broader scope of the group, the investigation then shifted to StealthMole's Ransomware Monitoring module. A further search of Lynx revealed a significantly larger operational footprint, with 397 victims indexed between July 2024 and August 2026. The volume of disclosures demonstrated that the Talbot County incident was not an isolated event but part of an active ransomware campaign that had persisted for more than two years. More importantly, the historical records offered an opportunity to look beyond recent activity and trace how the group's infrastructure had evolved over time.

Rather than concentrating on the latest disclosures alone, earlier victim listings were examined to identify infrastructure that might no longer be visible through the current leak site. One of the earliest indexed entries, published in August 2024, pointed to a different leak page hosted at:

  • http://lynxblog.******/leaks/66a***********331

This historical listing proved particularly valuable. In addition to the victim information, it exposed several operational artifacts that were absent from more recent disclosures, including the ProtonMail address james*******0@proton.me and a dedicated Tor-based negotiation portal:

  • http://lynxch*********************************qiyqd.onion/login

Victims were also instructed to register using an unique identifier before initiating negotiations. These details suggested that the historical leak page offered far more than a record of a past victim. It provided the first tangible links to the group's operational infrastructure and presented several new avenues for investigation.

  • 66*****************cb4e

Inside the Infrastructure

With historical artifacts pointing towards multiple operational components, the investigation turned to Lynx's current infrastructure to determine how the group maintained its public presence and whether traces of its wider ecosystem remained accessible.

  • lynxblogoxllth4b46cfwlop5pfj4s7dyv37yuy7qn2ftan6gd72hsad.onion

A review of the site confirmed that it remained active at the time of the investigation. Its homepage followed the structure commonly adopted by modern ransomware operations, providing access to sections dedicated to News, Leaks, and Report, while continuing to publish victim disclosures through an actively maintained leak portal. StealthMole's historical records showed that the hidden service was first observed on 20 August 2024 and remained active as of 11 August 2026, demonstrating that the infrastructure had been operational for nearly two years.

The leak portal itself contained the latest victim disclosures. Alongside each victim listing, the site published organizational descriptions, reported revenue, publication dates, and supporting proof files, reflecting the group's continued use of public disclosures as a means of pressuring victims during negotiations.

Rather than stopping at the homepage, the investigation expanded to examine the hidden service itself. Several publicly accessible pages were identified, each providing a clearer picture of how the platform was structured.

Component

URL

Login Portal

http://lynxchat***********knad.onion/main/chat

Registration Portal

http://lynxchat************knad.onion/register

Chat Interface

http://lynxchat***********knad.onion/main/chat

Server Status

http://lynxchat*******knad.onion/server-status

The login interface required registered credentials, while the registration page prompted users to enter a unique identifier and password before creating an account. Combined with the dedicated chat interface, these pages indicate that the platform was designed to support authenticated victim communications rather than relying solely on email exchanges. An attempt to access the /server-status endpoint returned a 404 Page Not Found response, suggesting that the endpoint was either unavailable or intentionally inaccessible during the investigation.

The infrastructure also exposed additional technical metadata through StealthMole. The hidden service was identified as running nginx/1.27.5 While these metadata points do not independently reveal the group's operations, they provide additional artifacts that can be correlated with other datasets during an infrastructure investigation.

Connecting the Dots

With the current leak site confirmed to be active, the investigation shifted from examining the visible infrastructure to exploring the technical artifacts associated with it. Rather than relying solely on what could be observed through the website itself, StealthMole was used to pivot from the hidden service into related malware intelligence, allowing the investigation to uncover connections that would not have been apparent from the leak site alone.

  • lynxblogoxllth4b46cfwlop5pfj4s7dyv37yuy7qn2ftan6gd72hsad.onion


Searching the current leak site, within StealthMole's Dark Web Tracker revealed 37 malware hashes associated with the domain. Rather than treating these as isolated indicators, each hash was investigated individually to determine whether it could provide additional insight into the group's operational infrastructure.

  • 0212*******************************************************7a5eb
  • 71db*******************************************************a0834
  • c587*******************************************************6d633
  • f85e*******************************************************0e619
  • 820e*******************************************************36f8a
  • 582e*******************************************************2fffe
  • 31de*******************************************************d5193
  • 5da4*******************************************************83040
  • bb4e*******************************************************f600a
  • f71f*******************************************************62787
  • 8090*******************************************************0c441
  • 97c8*******************************************************2ba00
  • 8569*******************************************************f5683
  • 432f*******************************************************29c66
  • d20c*******************************************************999f9
  • 468e*******************************************************89d6a
  • 0315*******************************************************21663
  • 589f*******************************************************21a23
  • 571f*******************************************************6cf8b
  • 551e*******************************************************ec386
  • 9a47*******************************************************a3896
  • ecbf*******************************************************f6e49
  • f9bb*******************************************************d56b7
  • 4e5b*******************************************************66412
  • c3b5*******************************************************24a18
  • 4ad4*******************************************************06ac4
  • 90ac*******************************************************cf7b8
  • ac68*******************************************************5b43f
  • dac3*******************************************************c94ed
  • cf7c*******************************************************7ac9c
  • 6486*******************************************************0313a
  • 0fb2*******************************************************1da93
  • ac50*******************************************************e9b60
  • dcba*******************************************************359cc
  • 4fbb*******************************************************4763b
  • 5533*******************************************************a931d
  • 1a01*******************************************************6ced0

One hash, in particular, proved especially valuable:

  • 4fb****************************************************763b

Using this artifact as a pivot uncovered a much broader network of Lynx-associated hidden services. The hash was linked to 14 separate Tor domains, consisting of both leak portals and negotiation portals.

Associated Leak Sites

Domain

Status

lynxblogco7r37jt7p5wrmfxzqze7ghxw6rihzkqc455qluacwotciyd.onion

Inactive

lynxblog************************************2sjyd.onion

Active

lynxblog***********************************2csyad.onion

Active

lynxblogoxllth4b46cfwlop5pfj4s7dyv37yuy7qn2ftan6gd72hsad.onion

Inactive

lynxblog************************************omjad.onion

Active

lynxblog***********************************z3xwqd.onion

Active

lynxblog**********************************ngrfoid.onion

Active

Associated Negotiation Portals

Domain

Status

lynxchat**********************************dbsgmyd.onion

Active

lynxchatde4spv5x6xlwxf47jdo7wtwwgikdoeroxamphu3e7xx5doqd.onion

Inactive

lynxchatdy3tgcuijsqofhssopcepirjfq2f4pvb5qd4un4dhqyxswqd.onion

Inactive

lynxchat***********************************6quxqd.onion

Active

lynxchatfw4rgsclp4567i4llkqjr2kltaumwwobxdik3qa2oorrknad.onion

Inactive

lynxchatly4zludmhmi75jrwhycnoqvkxb4prohxmyzf4euf5gjxroad.onion

Inactive

lynxchatohmppv6au67lloc2vs6chy7nya7dsu2hhs55mcjxp2joglad.onion

Inactive

This single pivot expanded the investigation well beyond the original leak site, revealing multiple generations of Lynx infrastructure that included both active and inactive hidden services. Instead of a standalone website, the findings pointed towards an ecosystem of interconnected domains supporting different aspects of the group's operation.

The investigation continued by exploring additional Lynx-related domains identified through StealthMole, uncovering a further 16 hidden services sharing the group's naming convention. While their specific functions could not be determined from the available evidence, they collectively demonstrated that Lynx maintained a significantly broader Tor footprint than was immediately visible through its public leak site.

Among the additional infrastructure identified were:

  • lynx2*************************************fqiqd.onion
  • lynxa*************************************5daqd.onion
  • lynxo**************************************2oqd.onion
  • lynx2*************************************626yd.onion
  • lynxb************************************z3vvyd.onion
  • lynxk*************************************xc3ad.onion
  • lynxa*************************************whead.onion
  • lynxh*************************************feuid.onion
  • lynxc************************************v2pxyd.onion

while several additional domains were observed in an inactive state, suggesting that portions of the infrastructure had either been retired or replaced over time.

The infrastructure mapping did not end there. A further pivot into the hidden service

  • lynxbllrfr5262yvbgtqoyq76s7mpztcqkv6tjjxgpilpma7nyoeohyd.onion

identified three additional malware samples associated with the domain:

  • 9e565d*****************************************************345da
  • 730f82*****************************************************a753c
  • 2c9f41*****************************************************84e06

One of these malware samples led directly to another operational domain:

  • lynxch2k5xi35j7hlbmwl7d6u2oz4vp2wqp6qkwol624cod3d6iqiyqd.onion

This correlation reinforced the value of using technical artifacts as investigative pivots. Rather than simply cataloguing domains, each malware sample provided another opportunity to uncover infrastructure that was not immediately visible from the group's public-facing services, gradually revealing a far more extensive operational network than the investigation had initially exposed.

The Human Layer

While the infrastructure mapping revealed how Lynx's hidden services were interconnected, the investigation also identified several operational artifacts that offered further insight into how the group communicates with victims and presents itself publicly. Rather than relying on domains alone, these artifacts helped bridge the gap between the group's technical infrastructure and its day-to-day operations.

One of the earliest pivots originated from the historical lynxblog.*** leak page, where the ProtonMail address james*****0@proton.me was first identified. To determine whether additional contact points existed, the domain was further investigated using StealthMole's Dark Web Tracker. This search uncovered two additional email addresses associated with the group's infrastructure:

  • ewik****************8@proton.me
  • martina*************8@proton.me

Unlike standalone contact details, these email addresses appeared repeatedly across multiple artifacts indexed by StealthMole, indicating that they formed part of Lynx's operational communication channels. Their repeated appearance across different records strengthened the association with the group's infrastructure and provided additional indicators for future investigations.

Further examination of these addresses uncovered several copies of the group's ransom note. Beyond outlining payment and negotiation procedures, the note demonstrated how Lynx directs victims toward its communication channels and hidden services. The recovered screenshots also showed martina*******8@proton.me appearing consistently throughout multiple ransom note variants, suggesting that the address was actively used as a victim contact point rather than appearing in a single isolated campaign.

The investigation also revisited several of the group's publicly accessible web pages, including the login and registration portals, to better understand how victims were expected to interact with the platform after initial contact. Combined with the previously identified negotiation portals, these components indicate that Lynx relies on a structured communication workflow in which victims are directed from the leak site to authenticated portals and dedicated contact channels rather than depending exclusively on email correspondence.

To better understand how the group presents itself publicly, a search for "Lynx Ransomware" within StealthMole's Dark Web Tracker uncovered a press release attributed to the operators. In the statement, the group described itself as financially motivated and claimed that it avoids targeting government institutions, hospitals, and non-profit organizations. The release also emphasized negotiation as its preferred method of resolving incidents and portrayed the operation as adhering to its own internal code of conduct.

As with many ransomware groups, however, these statements should be interpreted as self-described messaging rather than independently verified facts. Public declarations of intent often serve to shape perception among victims, affiliates, and the wider cybercriminal ecosystem, and should therefore be considered alongside technical evidence rather than accepted at face value.

The recovered email addresses, ransom notes, negotiation portals, and public statements provide a more complete picture of Lynx's operational identity. While the infrastructure mapping revealed where the group's services reside, these artifacts illustrate how the operators communicate, negotiate, and attempt to define their public image within the ransomware ecosystem.

Conclusion

What began as a review of a single government-sector victim quickly evolved into a broader investigation of Lynx's operational infrastructure. By following a series of technical pivots across StealthMole's Government Monitoring, Ransomware Monitoring, and Dark Web Tracker datasets, the investigation moved beyond the group's public leak site to uncover historical infrastructure, hidden services, malware associations, operational contact channels, and public communications.

Rather than relying on a single source of intelligence, the investigation demonstrated how seemingly unrelated artifacts can be connected to build a more complete picture of a ransomware operation. Historical leak pages provided the first operational pivots, malware intelligence exposed additional hidden services, and recurring communication artifacts revealed how the group manages victim interactions beyond its public-facing website.

Together, these findings highlight the importance of looking beyond victim disclosures when investigating ransomware groups and illustrate how infrastructure-focused analysis can uncover valuable intelligence that may otherwise remain hidden.

Editorial Note

Investigating ransomware groups is rarely a straightforward process. Infrastructure changes over time, hidden services disappear, and public statements often reflect the narrative that threat actors want others to believe rather than independently verifiable facts. Building meaningful intelligence therefore requires careful correlation of historical records, technical artifacts, and operational indicators while maintaining a clear distinction between observed evidence and actor claims.

This investigation demonstrates how StealthMole enables analysts to connect those disparate pieces of information into a coherent picture, allowing investigations to extend well beyond the visible leak site and into the broader infrastructure supporting a ransomware operation.

To access the unmasked report or full details, please reach out to us separately.

Contact us: support@stealthmole.com

Labels: ,

Following the Shells: From Ghost Seoul to PandaChina

A compromised website does not always end with a defacement, a ransom note, or stolen data. Sometimes, the real value is simply keeping the door open and selling the key.

Web shells make that possible. Planted on compromised servers, they can provide attackers with continued remote access, allowing them to interact with files and systems long after the initial intrusion. In underground markets, that access has become a commodity of its own. Sellers advertise compromised websites, administrative panels and webshell access to buyers who may have had no involvement in breaching the target in the first place. Some accesses are sold individually, while others are packaged by the hundreds, turning compromised infrastructure into inventory.

One seller operating in this space is Ghost Seoul, a Telegram-based operation advertising webshell access across a surprisingly broad range of targets. Government agencies, educational institutions, commercial organizations and other websites appeared among its listings, with prices varying according to the access being offered. On the surface, there was little to distinguish Ghost Seoul from the many sellers competing in the same underground economy.

But looking beyond the latest advertisements revealed a different story. Historical Telegram records on StealthMole showed that the identity visible today was only one part of a longer trail. Older usernames, archived messages and connections between seemingly separate accounts and channels gradually pushed the investigation further back, raising questions about how long the operation had really been active and who had been behind it before the name Ghost Seoul appeared.

This report follows that trail, starting with a webshell market active in 2026 and working backward through the digital traces its operator left behind. What emerged was not simply a snapshot of another Telegram seller, but a history that had been hiding behind changing names.

Where the Trail Began

Ghost Seoul first drew attention through a Telegram channel built around a straightforward business: selling access to websites that had already been compromised. Throughout July 2026, the channel advertised webshell and root-shell access across a broad mix of targets, from commercial websites and universities to government and defence-related domains. Alongside individual listings, the operator also offered webshells in bulk, suggesting that compromised access was being treated less as the outcome of individual attacks and more as inventory for resale.

  • https://t.me/web******r

The listings followed a fairly consistent pattern. A domain would be posted alongside a price and, in some cases, details about the level of access being offered. On July 21, for example, the channel advertised 100 “fresh & clean” webshells for $70, an offer that appeared again on July 25, 26 and 27. Individual domains were priced separately, with listings ranging from relatively low-cost website access to several hundred dollars for more notable targets. Some posts were later updated to indicate that the advertised access had been sold.

The targets themselves made the channel difficult to dismiss as just another small webshell shop. South Korean government domains including seoul.go.kr and busan.go.kr appeared alongside Germany's bmvg.de, the UN Food and Agriculture Organization's fao.org, and Singapore's Ministry of Defence domain, mindef.gov.sg. The mindef.gov.sg listing was particularly notable: Ghost Seoul advertised what it described as root shell access for $200 on July 25, before marking the access as sold three days later. These posts document what the seller claimed to possess and sell; they do not, by themselves, independently verify the compromise or transaction.

There were signs that the operation was not limited to simply posting whatever access happened to become available. Listings appeared repeatedly throughout the month, bulk packages were offered alongside individual domains, and the channel included targets spanning multiple countries and sectors. Taken together, the activity presented Ghost Seoul as an active participant in the market for compromised web infrastructure rather than a channel focused on a single campaign or target set.

The listings also provided the first lead beyond the channel itself. Across multiple posts, interested buyers were directed to @c******es to arrange purchases, while @web*****r was repeatedly presented as the channel or proof point for the operation. The same pattern appeared in bulk advertisements, including posts that instructed buyers to “DM @c******es” while pointing them back to Ghost Seoul for proof. Rather than being an occasional mention, @c******es appeared consistently at the point where an advertised shell or access was expected to turn into a transaction.

At that stage, we knew what Ghost Seoul was selling and had a direct contact used by the operation, but very little about the person behind it. That made @c******es the natural next pivot. Instead of looking at another advertised domain, we searched the account itself through StealthMole's historical Telegram records.

One Account, Many Names

The first account worth following was @c******es. Ghost Seoul repeatedly directed interested buyers to this handle, while the account itself left little ambiguity about what it was connected to: its Telegram bio listed “DOMAIN MARKET: Web*****r.” Rather than treating the username as a permanent identity, the investigation pivoted on the account's underlying Telegram identifier, User ID 8423162304.

That distinction quickly became important. StealthMole's historical Telegram indexing showed that the account visible as COVID77 / @c******es in July 2026 had appeared under a series of different identities during the preceding months. At least eight name and username combinations were captured across the available snapshots, including:

  • Panda / @panda******0x
  • PANDA0X / @panda****0x
  • PANDA/X1ON / @panda****0x
  • Panda/Cod3r / @panda***0x
  • THE/PANDA / @panda****a0x
  • Panda/PANDA / @panda***0x
  • JiuPanda / @x*****panda
  • COVID77 / @c******es

The names changed, but Telegram User ID 8423162304 remained the common identifier. This was significant because @x***npanda and @Panda*****0x had already surfaced elsewhere during searches for Ghost Seoul-related material. Initially, those appearances could have been interpreted as other users circulating or promoting the seller's advertisements. Historical indexing showed otherwise: the Panda, x***npanda and COVID77 identities were different snapshots of the same Telegram account.

The account's activity also remained concentrated around the webshell trade despite the changing names. StealthMole associated User ID 8423162304 with only four observed Telegram communities, one being the Ghost Seoul channel. Three were explicitly centered on the sale or exchange of webshell and server access, while the fourth, Indonesia Defacer, placed the account within another community closely adjacent to that activity.

  • https://t.me/ma***tweb***l
  • https://t.me/WebshellCpan*****S
  • https://t.me/IndonesiaD*****r

This also changed the meaning of earlier messages uncovered during the investigation. In the Webshell / Cpanel / Smtp / Rdp channel, a user appearing as JiuPanda / @x***npanda had circulated Ghost Seoul material. The same Telegram User ID later appeared as Panda / @Panda*****0x in INDONESIA DEFACER | WEBSHELL MARKET. What had initially looked like separate accounts promoting the same seller could now be followed back to User ID 8423162304.

Even the visual identity evolved without completely abandoning the theme. The July @c******es account used imagery closely resembling Ghost Seoul's profile branding, while the channel itself leaned heavily into a South Korean persona through the Korean flag, Seoul imagery and the words “KOREA CYBER UNIT.” The historical records, however, showed that this presentation came after months of Panda-branded identities. The Korean branding therefore provides useful context about how the operation presented itself at that point in time, but it cannot establish where the operator was actually located or their nationality.

That raised a different question: what had PandaChina been doing before Ghost Seoul appeared?

Before Ghost Seoul

Once the historical identities behind Telegram User ID 8423162304 were established, the earlier Panda-era messages could be viewed in a different light. They were no longer references to another seller who happened to circulate Ghost Seoul material. They were part of the same account's earlier activity, and that activity showed that selling compromised web access had begun well before the Ghost Seoul name appeared.

Under @Panda*****0x, the account was already advertising webshells and other forms of server access through Telegram in March 2026. The posts followed a commercial format that would later remain familiar: lists of available domains, prices, payment instructions and direct contact details. Buyers were offered payment through BTC, USDT, Ethereum and DOGE, while advertisements directed them to @Panda*****0x to complete a purchase. Some posts also pointed users toward another contact point, @Pandam******0x, for additional information.

The scale of the inventory was visible in PRICELIST23.txt, a file circulated by the account containing a long list of access points across multiple countries. Many entries included URLs using port 2083, alongside educational and other domains from countries including Peru, Bolivia, Colombia, India, Pakistan, Nepal, Bhutan, Nigeria and Indonesia. Elsewhere, the seller advertised access individually and in bulk, showing that the later Ghost Seoul model of turning compromised infrastructure into priced inventory was already present during the Panda period.

Some of the earlier advertisements also reached government infrastructure. In one March post, @Panda*****0x was listed as the contact for access involving domains such as apd.lacounty.gov, lcc.nebraska.gov, jakarta.bps.go.id, sanjuandelrio.gob.mx, poderjudicialchiapas.gob.mx, dprf.gov.br, and pn-jambi.go.id. Individual prices were attached to the listings, while some entries were subsequently marked as sold. The same message directed users to @Pandam******0x for further information, placing that handle alongside the Panda-era sales activity.

One listing provided a closer look at what was being offered. The account advertised bandungkota.bps.go.id as “shell access” for $100, with @Panda*****0x listed as the contact. An accompanying image showed what appeared to be an active Hidden Shell Version 3.0.2 interface carrying ALFA TEAM branding. The screen displayed server and filesystem information, including the path /datos/www/bandungkota/images/, as well as an Apache/PHP environment and functionality for interacting with files on the host. As with the later Ghost Seoul listings, the screenshot reflects evidence presented by the seller and should not be treated as independent verification that the advertised access remained valid at the time of observation.

The Panda operation also used a separate space for credibility and sales proof. Advertisements from @Panda*****0x directed buyers to the private Telegram invite:

  • https://t.me/+VPB*******NTM1

The link was described as a “Proofs Channel,” and its Telegram preview identified it as Panda Shells. One of the associated messages combined the invite with the seller's payment options and direct contact:

  • DM: @Panda*****0x
  • Proofs Channel: @t.me/+VPB***********NTM1

Another identifier, @panda***x, also appeared in text associated with the Panda Shells channel. At this stage, however, the available evidence does not establish what role that account played, so it remains an associated artifact rather than an attributed identity.

Overall, the Panda-era records push the observable webshell activity back months before the current Ghost Seoul branding. The names and presentation changed, but the underlying business was already recognizable: compromised access was advertised, priced, marked as sold, supported by proof material and promoted through dedicated Telegram channels.

The private Panda Shells link also gave the investigation somewhere new to go. Unlike a username that could change, the same invite began appearing in messages posted by other sellers, opening a path from the history of one account into the wider market operating around it.

Following the Market Around Panda

The Panda Shells invite offered a useful pivot because it was not confined to messages from @Panda*****0x. Searching the same private Telegram link across StealthMole surfaced it in other webshell-related activity, suggesting that the sales infrastructure around Panda extended beyond a single public account.

One of those appearances came from jacky27 / @ja*****7, Telegram User ID 7595948503. Messages associated with the account advertised webshell and cPanel access while pointing buyers toward the same private channel previously promoted by @Panda*****0x:

  • https://t.me/+VP************NTM1

This was a more meaningful overlap than two sellers simply appearing in the same Telegram group. During the Panda period, User ID 8423162304 had explicitly described the invite as its “Proofs Channel.” Finding @ja*****7 directing users toward that same destination connected the account to infrastructure already associated with Panda's sales activity.

The overlap, however, does not tell us exactly what that relationship was. @ja*****7 could have been another seller using a shared proof channel, a reseller working from the same inventory, someone cooperating with Panda, or simply a user republishing existing advertisements. The available evidence does not establish common ownership of the two Telegram accounts, so User ID 7595948503 remains a separate actor rather than another Panda alias.

Another contact surfaced repeatedly as the investigation moved through these webshell communities: @os*******e. Earlier searches for web*****r had already captured posts from an account appearing as C0L1N / @os*******e, Telegram User ID 6767763093. In one message, buyers were instructed:

  • Pm: @os*******e
  • Channels & Support: @web*****r

Other material placed the same account around Panda-era sales. A message attributed to Os/M1d / @os*******e, for example, advertised access to carnalprime.cl, quaorealty.com, carverdentallab.dev.tqnia.me and vermione.cz, but ended by directing buyers to:

  • PM: @Panda*****0x
  • CH: @Pandam******0x

The relationship also appeared in the opposite direction. On March 19, StealthMole captured C0L1N forwarding material originating from Ghost Seoul channel ID 3512450200, while the resulting advertisement used @os*******e as the direct contact and @web*****r as the channel. Rather than two completely separate sales footprints, the records showed C0L1N appearing around both the earlier Panda infrastructure and the later Ghost Seoul operation.

That pattern is significant, but it has limits. Nothing found so far establishes that User IDs 6767763093 and 8423162304 were controlled by the same person, nor does the overlap prove that C0L1N was formally part of Ghost Seoul. What the records do show is repeated commercial crossover: advertisements, contact points and channels associated with one seller appearing in activity involving the other.

Keeping those distinctions mattered, particularly with @os*******e, because unlike most of the surrounding accounts, his Telegram profile exposed an artifact that could be followed outside Telegram altogether: a phone number.

The C0L1N Pivot

The phone number attached to @os*******e offered something the other Telegram artifacts had not: a lead that could be followed outside the webshell channels themselves. Searching the account in StealthMole showed that C0L1N was no longer active under its observed identity, with the Telegram account currently deleted, but historical snapshots preserved enough information to continue tracing it.

The account was anchored to Telegram User ID 6767763093. In a March 8, 2026 snapshot, StealthMole recorded it as:

  • Name: C0L1N
  • Username: @os*******e
  • Telegram User ID: 6767763093
  • Phone: 18**********90
  • Bio: col1n has return

Like the primary Ghost Seoul account, C0L1N's Telegram identity had not remained static. Historical records captured at least three username or profile-name changes during March 2026 alone, while hundreds of messages associated with the account revolved around webshells and related access sales. The profile itself used Brazilian-themed imagery, including the country's flag, but there was no evidence to treat that branding as an indication of the operator's actual location or nationality.

The more useful artifact was 18**********90. Rather than stopping at the Telegram profile, the number was searched against StealthMole's compromised-data holdings, where it appeared across seven leaked files. This shifted the investigation away from what C0L1N chose to publish on Telegram and toward identifiers that had appeared alongside the same number elsewhere.

Several of those records were then examined through MoleChat to identify useful correlations without manually working through each dataset. One recurring association linked the phone number to the numeric identifier 30*****61 and the corresponding QQ email address:

  • 30********1@qq.com

The finding was useful, but it was not enough to put a real-world name behind C0L1N. The leaked records establish an association between 18**********90 and 30********1@qq.com; they do not establish who was controlling either identifier during the webshell activity observed in 2026.

Conclusion

Ghost Seoul initially appeared to be a relatively straightforward Telegram operation selling webshell and server access. Following the account behind those listings, however, showed that the identity visible in July 2026 was only the latest part of a longer history.

The most important thread throughout the investigation was not a username, but the underlying Telegram User ID. While names shifted from Panda and x***npanda identities to @c******es, User ID 8423162304 allowed activity separated by months, different handles and different Telegram communities to be connected back to the same account. That history showed that the commercial activity associated with Ghost Seoul had roots in an earlier Panda-branded webshell operation, where compromised access was already being priced, advertised and supported through dedicated sales and proof channels.

Following those older artifacts also exposed a wider marketplace around the account. The private Panda Shells channel, @Pandam******0x, @ja*****7 and @os*******e showed how advertisements and contact points moved between sellers and webshell-focused communities. Those overlaps do not establish a single organized group behind the accounts, but they do show that Ghost Seoul operated within an interconnected trading environment rather than in isolation. The C0L1N branch pushed that trail beyond Telegram altogether, linking User ID 6767763093 to phone number 18**********90 and, through leaked records, to QQ identifier 30*****61 and 30********1@qq.com. The trail ended there, without enough evidence to identify the person behind the account.

There are still important questions the available data cannot answer. The investigation does not establish the real-world identity or location of the Ghost Seoul operator, despite the operation's prominent Korean branding. It also does not reveal how the advertised systems were initially compromised, who purchased the access, or what buyers subsequently did with it. Likewise, listings marked as sold remain claims made by the seller rather than independent confirmation of successful transactions.

What the investigation does establish is a traceable history behind an identity that, viewed only in its current form, would have appeared much newer and more isolated. Ghost Seoul was where the trail began, but the account's earlier footprints showed that it was not where the story started.

Editorial Note

Attribution in underground ecosystems is rarely absolute. Usernames change, infrastructure is shared, and associations do not always imply common ownership. This investigation shows how StealthMole's historical records and cross-source pivots can help navigate that uncertainty, connecting activity across changing identities while keeping the line between what the evidence establishes and what remains unknown.

To access the unmasked report or full details, please reach out to us separately.

Contact us: support@stealthmole.com




Labels: ,

Learn more about StealthMole

Talk to our team of experts today to learn how you can manage your dark web exposure.
Request demo More Reports

Share this report