Inside ZeroDay Commerce: Tracing Mushr00w’s Webshell Network

Webshells have become a familiar commodity in underground cybercrime communities. Instead of having to compromise a server themselves, buyers can purchase access that is already available and use it for their own purposes. For sellers, the model is simple: find vulnerable or compromised systems, maintain access, and turn that access into something that can be sold repeatedly. Telegram has become one of the places where this market is openly promoted, with sellers advertising everything from individual shell access to higher-value access on specific domains.

This investigation began with activity linked to this wider ecosystem and gradually led toward a Telegram user. What initially appeared to be another account operating within the underground quickly opened into a broader picture involving shell sales, private communities, other operators, and relationships that were not always straightforward.

Using StealthMole, the investigation moved between technical detections, Telegram activity, channel memberships and associated identities to piece together that picture. The findings reveal more than a single seller advertising access. They show how webshells are marketed, how sellers build communities around those services, and how disputes, collaborations and new identities can leave additional traces behind.

The First Signs of Compromise

The first lead came from StealthMole’s Defacement Alert, where Mushr00w was listed in connection with the defacement of the two government websites: Malaysian and Ukrainian.

The defacements themselves provided the first real connection to the actor. The pages were signed “SERVER FUCKED BY MUSHROOW” and, more importantly, included a direct Telegram address:

  • http://t.me/M*****w

The pages also carried the familiar message, “We are Anonymous. We are Legion. We do not forgive. We do not forget. Expect us.” Alongside it were greetings to WebshellSR Famila, MeshSec, Illegalplatform.org and Roween. These names are part of the defacement content, but there is no evidence at this stage to say that they were working with Mushr00w.

The Telegram address gave the investigation its first clear pivot. Rather than following only the defaced websites, the username Mushr00w was directly searched into StealthMole’s Darkweb Tracker to see what was attached to the account behind it.

That search also brought up historical Zone-H records for the two incidents. The Malaysian defacement, where the archived page again carried “HACKED BY MUSHROOW” and the same Telegram address. The Ukrainian incident was similarly linked to Mushr00w in connection with the defacement.

  • http://zone-h.org/mirror/id/42570843
  • http://zone-h.org/mirror/id/42576330

The important part was not simply that the same name appeared twice. The defaced pages had given us a direct identifier that could be followed into Telegram. That was where the investigation moved from the websites themselves to the person operating behind the Mushr00w name.

The Door Marked ZeroDay

The Telegram link on the defaced pages provided the first direct route to Mushr00w. Running Mushr00w through StealthMole’s Telegram Tracker returned an account with the Telegram ID 6775881965 and the username @M*****w. The account had not always used that name. StealthMole’s historical indexing showed the same Telegram ID under several different usernames, giving us a much longer history to work with.

The account had previously appeared as @Lo****e, @Wiz****q, @Sur****a, @Raja_R33, @gh****e and @A*******z before settling on @M*****w. The historical snapshots also showed changes in the account’s display name, biography and profile image over time. For example, the account used the name R33 while operating as @Raja_R33 in October 2025, and later appeared as @Ah*******z before moving to @M*****w. The same Telegram ID ties these different usernames together, making the account history more useful than any single username on its own.

There were also some interesting changes in the account’s bio. On July 25, 2026, while using @M*******w, the bio read “im right here: T.me/Zer*******e”. That short line turned out to be the next important lead in the investigation. It pointed directly to a private Telegram community that was much more closely connected to Mushr00w’s activity.

StealthMole’s historical indexing also gave us a glimpse of activity that predated the current Mushr00w identity. In November 2025, the account was using @Ah*******z and posted a message in Turkish referring to arranging a bank loan of more than one million for a commission, finding people or a network able to get people to Europe, and meeting in Beyoğlu to begin immediately. The message is interesting as a potential language and geographic lead, but it does not by itself establish that the account holder was in Turkey or that they actually carried out any of the activities described.

The account history also contained other signs of underground activity. A September 2024 message under @Wiz*****q warned others about a supposed scammer, while another message from May 2026 asked whether anyone had a free WordPress exploit. These older messages were not enough on their own to explain who Mushr00w was, but they showed that the Telegram account had been active in underground conversations well before the current name appeared.

Inside the ZeroDay Counter

Following the link in Mushr00w’s Telegram bio led to ZeroDay Commerce, a private Telegram community with around 80 members. The group description leaves little doubt about what it is built around: “Digital marketing for SEO's / buy / sell webshells / exploits / No AI coders allowed / Advertising is prohibited here!” Mushr00w is listed in the group information, putting the account directly inside the community rather than simply appearing as another member.

The messages inside the group make the purpose of the community clearer. Webshell access was being advertised for specific websites, including https://petofi10miskolc.edu.hu/ and https://www.rmc.edu.my/, with the latter offered as “Webshell + Admin access.” Other posts advertised “HIGH DA PA DOMAINS AVAILABLE”, along with claims that shells had terminal access and could be used to upload, edit and delete files. Sellers also advertised replacement or refund support and a one-day guarantee after purchase.

One of the posts described the service in more direct terms: “We are more than just a seller”, followed by a claim that the group provided reliable shells, support and solutions to buyers. The contact details attached to these advertisements repeatedly included @M*****w and @boc********9.

The group was not limited to individual shell listings. Another post promoted a “S4LE priv8 WP Checker”, described as a tool capable of live site validation, automated login, plugin installation and user-role detection. Whether every capability advertised actually worked as claimed cannot be established from the posts alone, but the advertisement itself shows the type of tools being offered alongside shell access.

The same activity also appeared outside ZeroDay Commerce. StealthMole’s Telegram Tracker returned messages posted under the Mushr00w identity advertising shell access for edu.co, edu.mx, gov.au and gov.my domains. One post offered random shells for $2 each and stated that escrow was accepted. Another specifically claimed “ALL ROOT DIR / NOT SUBDOMAINS!” and again directed potential buyers to @M****w.

These posts are important because they show that the shell-selling activity was not limited to a single advertisement inside one private group. The same identity was being used to promote access elsewhere on Telegram. At the same time, the domains mentioned in these advertisements should not be mistaken for infrastructure owned by Mushr00w. The evidence shows them as systems for which shell access was being advertised, not proof that Mushr00w owned those domains or personally compromised them.

There was also another community connected to this activity. Rainbow Shell Market had Mushr00w listed as its contact and linked back to ZeroDay Commerce. Its description openly invited users looking for shells to join. Together, the two communities show a small but connected marketplace around the sale and promotion of webshell access, with Mushr00w positioned at the centre of the activity observed in the available evidence.

  • https://t.me/Ra***********t

When Business Turns Personal

The activity around ZeroDay Commerce was not without friction. One of the accounts repeatedly appearing alongside Mushr00w in the shell advertisements was @boc*******9. The two accounts were presented together in posts offering shell access and related services, suggesting that they were working within the same commercial space.

That relationship later broke down publicly.

In a message posted through the ZeroDay Commerce community, the account identified as the owner announced that it was no longer connected with @bo******9 and warned others that any future dealings with the account would be their own responsibility. The message went further, accusing him of being a “liar thief” and claiming that he had stolen a shell. Another member, Yongbe, responded by asking him to be patient, showing that the dispute was taking place in front of other members of the community rather than in a private exchange.

The accusation was later answered by @bo*******9 through D1STR1CT9619, a community project that was also being used to share the dispute. His version of events was very different. He said he had been accused of stealing shells after an RDP he had purchased for Mushr00w developed problems. According to his account, Mushr00w believed that he had changed the RDP password and taken the shells, while he claimed that the RDP had actually been flagged because of misuse. He also denied taking shells for personal use and said he had refused to share proceeds from their sale.

Neither side's account can be independently established from these messages alone. What the evidence does establish is that Mushr00w and @bo********9 had previously been operating in the same shell-selling environment and that their relationship later ended in a public dispute over shell access and an RDP.

StealthMole's profile search on @bo********9 provided little additional information. The account is associated with Telegram ID 6271041627, uses the name “NO NAME”, and has no visible phone number or other identifying information. Its limited profile data therefore does little to resolve the dispute, but the activity surrounding the account gives us a clearer picture of its connection to Mushr00w than the profile itself does.

The fallout is useful for another reason. It gives us a glimpse into how these shell operations appear to function behind the advertisements: access is acquired through RDPs, shells have commercial value, and disagreements over control of that access can quickly become disputes within the same underground community.

The People Around the Seller

The deeper Telegram search showed that Mushr00w’s activity extended beyond ZeroDay Commerce. StealthMole linked Telegram ID 6775881965 to activity across 11 Telegram channels, with additional messages appearing in other groups and channels. This broader footprint made it possible to look at the people appearing around the account rather than treating Mushr00w as a standalone seller.

One of the clearest connections was @be*******u. In the ZeroDay Commerce member list, the account is explicitly marked as “Mate.” Its profile shows the display name X, username @be*******u, and the bio “Lucky 4U Not M3.” The “Mate” designation does not tell us exactly what role the account played, but it does establish that the account held that label within the community.

Another account, VX-encoded, also appeared as a Mate in ZeroDay Commerce. StealthMole identifies the account as @b*******d, Telegram ID 8256413322. Its profile contained a direct reference to the community in its bio: Direction: https://t.me/Zero********e. This provides a separate profile-level connection between VX-encoded and the same community surrounding Mushr00w.

VX-encoded also appeared in a conversation involving shell access. One message, written in Indonesian, questioned why someone would sell their dignity for 20–30 dollars and referred to asking for a “shell” through a backup account. VX-encoded then wrote that he had “lost respect for Indonesians" and questioned why so many of them were “stupid.” The exchange is useful for understanding the conversations taking place around shell access, although it does not identify the person being addressed or establish that VX-encoded was involved in the transaction being discussed.

Together, the Telegram data shows that Mushr00w was operating within a wider group of users rather than in isolation. Some relationships were visible through commercial posts, others through community roles, and others through the conversations taking place around shell access. The network was therefore larger than the Mushr00w account itself, even if the precise role of every person around it cannot be established from the available evidence.

Beyond the Network

The Telegram investigation was not the only place where the same name appeared. A separate OSINT search surfaced a profile:

  • https://gitlab.archlinux.org/M*******w

The username is notably similar to the name used by the Telegram account, but that similarity alone is not enough to connect the two.

At the time of the investigation, the GitLab profile could not be examined further because access to the page was restricted. There was also no additional evidence available from the search that tied the account to Telegram ID 6775881965, ZeroDay Commerce, or any of the other identifiers already associated with Mushr00w.

For that reason, this lead remains separate from the main attribution chain. It is worth recording because the username is distinctive enough to warrant further checking, but there is currently no basis for presenting the GitLab account as belonging to the same person behind @M*****w.

This is also a useful reminder of one of the problems with tracking underground identities. A familiar username can point toward the right person, but it can just as easily belong to someone else. In this case, the Telegram evidence provides a much stronger foundation because several different usernames are tied to the same Telegram ID, while the GitLab account currently has no such link.

Conclusion

The investigation began with two website defacements carrying the Mushr00w name and a Telegram address that opened the door to a much wider footprint. StealthMole’s historical Telegram data then connected Telegram ID 6775881965 to multiple previous usernames and eventually to @M*****w, whose profile pointed directly to ZeroDay Commerce.

From there, the evidence became more consistent. ZeroDay Commerce and related Telegram communities were being used to promote and sell webshell access, while Mushr00w appeared repeatedly in those activities. The investigation also identified other accounts around the operation, including @bo******9, @be*****u and VX-encoded, although the exact role of each person is not equally clear. The public dispute with @bo********9 also showed that these relationships could change quickly when access and money were involved.

Overall, the available evidence supports viewing Mushr00w as an active participant in a Telegram-based webshell marketplace, with a history that extends beyond the current username and activity across multiple connected communities. At the same time, some leads remain unresolved, including the real-world identity behind the account and the relationship between Mushr00w and the separate Arch Linux GitLab profile.

Editorial Note

Dark web identities rarely stay consistent for long, and attribution is often built from fragments rather than a single definitive piece of evidence. In this case, usernames changed, relationships shifted, and some claims made by the actors could not be independently verified.

StealthMole helped bring those fragments together, allowing the investigation to follow the same account across historical identities, defacement activity and Telegram communities while keeping the uncertain parts of the picture separate from the findings that could be supported.

To access the unmasked report or full details, please reach out to us separately.

Contact us: support@stealthmole.com




Labels: , ,

Beyond Defacement: Inside 313 Team's Hacktivist and Ransomware Operations

Armed conflicts have long extended beyond conventional battlefields, and in recent years cyberspace has become an increasingly important front in that struggle. Across the Middle East, groups aligned with various resistance movements have embraced cyber operations to amplify political messaging, disrupt perceived adversaries, and project influence beyond geographic borders. Website defacements, coordinated propaganda campaigns, and increasingly sophisticated cyber capabilities have become part of a broader digital strategy, allowing these actors to reach global audiences while demonstrating their presence in an evolving cyber landscape.

Among the groups operating in this space is 313 Team, an Iraqi hacktivist collective that has consistently linked its activities to the broader narrative of the Islamic Resistance. While the group's public image is largely built around high-profile website defacements carrying ideological messages, its online footprint suggests a more structured operation than its defacement campaigns alone might imply. Over time, the group has developed a recognizable digital identity across multiple platforms, maintaining a persistent presence while promoting its operations through coordinated messaging and branded content.

This report examines that wider ecosystem through the lens of StealthMole's intelligence capabilities. Rather than focusing on a single incident, the investigation pieces together the group's digital infrastructure, operational footprint, claimed offensive capabilities, and relationships within the broader hacktivist landscape. By correlating evidence from multiple sources, the report provides a closer look at how 313 Team presents itself, how it operates, and how its activities extend beyond the defacement campaigns that first brought the group into view.

The Digital Face of the Islamic Resistance

Investigations into threat actors often begin with a single indicator that appears routine at first glance but reveals a much larger story when examined more closely. In this case, the investigation began within StealthMole's Defacement Alert module while monitoring website defacement activity linked to hacktivist groups operating in the Middle East.

Among the recorded incidents was a defacement attributed to 313 Team, involving a Russian website. According to StealthMole's records, the incident was detected on 8 September 2023, making it one of the earliest observable activities associated with the group within the platform. While a single website defacement would not normally warrant an extensive investigation, the group's distinctive name and ideological branding suggested that there was likely more to uncover than an isolated attack.

  • http://in*******oy.ru

Rather than treating the defacement as a standalone event, the investigation shifted toward understanding the identity behind 313 Team. The next step was to determine whether the group maintained a broader online presence, particularly on platforms commonly used by hacktivist organizations to claim responsibility for attacks, distribute propaganda, and communicate with supporters. Using StealthMole's Telegram Tracker, a search for "313 Team" quickly revealed an active Telegram channel.

  • https://t.me/**313*****m

The channel immediately provided the first glimpse into the group's public identity. Rather than presenting itself simply as a hacking collective, the operators described themselves as the "Iraqi Cyber Army" and incorporated religious and ideological references throughout their profile, including "جنود الإمام المهدي" ("Soldiers of Imam al-Mahdi") alongside the hashtags #Free_Palestine and #Ya_Mahdi. The channel biography also pointed investigators toward additional Telegram assets, suggesting that the group maintained multiple communication channels to support its operations and preserve its online presence.

  • @**313******k
  • @**313*******up

These initial findings indicated that 313 Team was far more than a name attached to a defacement page. The group's branding, ideological messaging, and interconnected Telegram presence pointed toward a coordinated online ecosystem rather than a collection of isolated attacks. With the primary communication channel identified, the investigation shifted from establishing the group's existence to mapping the infrastructure, operational footprint, and digital assets supporting its activities.

Beyond the Mirror: Mapping 313 Team's Digital Infrastructure

With the group's primary Telegram channel identified, the investigation shifted towards uncovering the digital infrastructure that sustained its operations. Rather than examining individual attack claims, the focus turned to understanding how 313 Team maintained its online presence, communicated with supporters, and preserved continuity despite the risk of account removals and platform enforcement. Using StealthMole's Telegram Tracker as the primary pivot point, a much broader ecosystem began to emerge.

The first indication that 313 Team operated through multiple communication channels came directly from the biography of its primary Telegram channel, https://t.me/**313*****m. Alongside describing itself as the "Iraqi Cyber Army," the channel promoted two additional Telegram assets. While these references initially appeared to be simple backup links, further investigation revealed that each served a distinct operational purpose.

  • @**313*********k
  • @**313*********up

The @**313*********up channel functioned as a resilience mechanism whenever Telegram removed the group's primary presence. One announcement explicitly informed followers that the original 313 Team channel had been taken down for the second time and directed them to migrate to the backup channel so they could continue following future operations. Rather than disrupting the group's activities, platform enforcement had been anticipated, with alternative channels already in place to preserve its audience and maintain operational continuity.

A different role emerged for @**313*********k, which was used to distribute material allegedly obtained during cyber operations. Posts within the channel contained download links, passwords, and references to archived data, while repeatedly directing followers back to the backup channel to ensure continued access if additional channels were removed. The coordinated cross-promotion between these Telegram assets demonstrated a deliberate effort to separate operational announcements from the publication of alleged stolen material while keeping followers connected across multiple platforms.

The investigation uncovered another public-facing channel, https://t.me/Team313******l, which primarily served as a showcase for the group's operations. Unlike the leak channel, posts here focused on announcing newly compromised websites, publishing screenshots of defacements, and highlighting the group's claimed successes. The consistent branding, language, and visual identity closely matched the primary Telegram channel, reinforcing the relationship between these assets.

Beyond Telegram itself, 313 Team maintained a presence across several external platforms that further strengthened attribution. The group's X account, mirrored the same ideological messaging and directed visitors back to its Telegram ecosystem, creating a bridge between mainstream social media and its primary communication platform. The investigation also identified the ProtonMail address, which appeared alongside the group's public messaging and represents a valuable attribution artifact that may assist future investigations involving the same operators.

  • Twitter: https://x.com/**313****m
  • Email: O********m@protonmail.com

Archived defacement records provided another layer of corroboration. Pages preserved on Mirror-H and OwnzYou displayed the same visual identity found throughout the Telegram ecosystem, including the group's logo, ideological slogans, references to the Iraqi Cyber Army, and direct links back to its social media accounts. Rather than existing as isolated mirrors of individual attacks, these archives connected the group's public claims with a consistent digital identity that persisted across multiple platforms.

  • Mirror-H: https://mirror-h.org/mirror/5******8/
  • OwnzYou: https://ownzyou.com/mirror/6c5*************896.html

The investigation also identified the public GitHub repository together with its associated GitHub Pages site, both promoting 313 HackBar v1.3. The project described functionality commonly associated with penetration testing, including SQL injection testing, cross-site scripting (XSS), fuzz testing, encoding utilities, and hash generation. While the repository was promoted through the group's Telegram channel, the available evidence does not independently establish that 313 Team developed the project. Nevertheless, its promotion demonstrates that the group's online presence extended beyond propaganda and attack claims to include publicly accessible technical resources.

  • GitHub: https://github.com/313Team/313-HackBar
  • GitHub Pages: https://313team.github.io/313-HackBar/

Another noteworthy discovery was the Telegram channel, operating under the name Team_313_Umar_Al_Khattab. Unlike the group's primary channels, this account predominantly shared cryptocurrency-related tools and blockchain utilities rather than attack announcements. Although the available evidence suggests a relationship with the wider 313 Team ecosystem, it does not conclusively establish that it is operated by the same administrators. As such, it is best regarded as an associated channel pending further corroboration.

  • https://t.me/r****ll

These findings reveal a far more structured digital ecosystem than a single defacement channel. Telegram served as the operational hub, while backup channels, leak channels, social media accounts, archived defacement platforms, public code repositories, and associated communication channels collectively reinforced the group's online resilience.

Each platform fulfilled a specific role, allowing 313 Team to preserve its visibility, distribute content, and maintain continuity even when individual accounts or posts were removed. By correlating these disparate artifacts, StealthMole transformed what initially appeared to be a single Telegram channel into a mapped digital infrastructure supporting the group's broader cyber operations.

More Than Defacement: Following the Ransomware Trail

While mapping the group's digital infrastructure, one recurring term began appearing across multiple Telegram posts and defacement messages: 313 Ransomware. Initially, it appeared to be little more than another piece of branding accompanying the group's propaganda. However, as additional messages were uncovered through StealthMole's Telegram Tracker, it became evident that the name was repeatedly associated with claims of system encryption rather than simple website defacements, suggesting that 313 Team sought to project capabilities beyond those typically associated with hacktivist campaigns.

To better understand this recurring reference, the investigation pivoted by searching "313 Ransomware" within StealthMole's Telegram Tracker. The search led back to the group's own Telegram channel, where a detailed post titled "313 Ransomware" offered the clearest insight yet into the capability the group claimed to possess. Unlike previous announcements celebrating website compromises or service disruptions, this post adopted a distinctly technical tone, describing what it portrayed as the ransomware's encryption process.

According to the Telegram post, the ransomware begins by enumerating every available drive before recursively traversing directories across the compromised system. For each file encountered, it claims to generate a unique ChaCha20 encryption key together with a corresponding nonce. Rather than encrypting files in their entirety, the post describes a partial encryption strategy in which one byte is encrypted followed by two bytes left unencrypted, a technique intended to balance encryption speed with the ability to render files unusable. The generated ChaCha20 keys and nonces are then said to be encrypted using Elliptic Curve Integrated Encryption Scheme (ECIES) before being prepended to each encrypted file.

The group further attempted to justify these design choices by claiming that ChaCha20 enabled efficient stream-based encryption while ECIES provided security comparable to RSA with shorter key lengths and improved performance. Whether these technical claims accurately reflect a functioning ransomware family cannot be determined solely from the Telegram post, and no malware sample was recovered during this investigation. Nevertheless, the level of technical detail distinguishes this announcement from the group's typical ideological messaging and indicates an effort to portray 313Ransomware as a credible operational capability rather than simply a symbolic name.

The ransomware branding was not confined to this single technical post. Earlier artifacts collected during the investigation showed the same name appearing repeatedly across the group's public messaging. An archived defacement warned that targeted organizations would have their databases leaked and website files encrypted using 313 Ransomware. Rather than presenting the operation as a conventional website defacement, the message framed it as part of a broader campaign involving data theft, encryption, and continued attacks against national infrastructure.

Historical Telegram messages further reinforced this narrative. One post describing an attack against the Abha Palace Hotel claimed that the group had not only defaced the website but also copied internal systems, extracted databases, deleted backups, and encrypted affected infrastructure using 313 Ransomware before publishing credentials required to access the allegedly stolen data. While these statements remain claims made by the group and were not independently verified during the investigation, they demonstrate that the ransomware branding had been integrated into the group's public operations well before the technical description was published.

A similar pattern emerged in messages directed toward other organizations. During a claimed attack against Ubuntu, 313 Team asserted that the target's servers and user systems remained completely frozen and instructed the organization to negotiate through the encrypted messaging platform Session, publishing the following identifier:

  • Session ID: 0574b***********************************5f0a

The post concluded by demanding that Ubuntu establish contact to negotiate what it described as a "permanent ceasefire." Another message addressed directly to eBay claimed that the company had already received an email containing the group's Session contact details and warned that attacks would continue until communication was established. Although neither incident could be independently verified through the available evidence, both messages closely resemble the negotiation tactics commonly employed by ransomware operators, where encrypted communication channels are provided for victim contact following an attack.

These findings suggest that 313 Team deliberately cultivated an identity extending beyond ideological defacement campaigns. Through repeated references to 313 Ransomware, technical explanations of its claimed encryption process, public extortion messages, and the publication of a dedicated Session identifier for negotiations, the group consistently portrayed itself as capable of conducting disruptive operations involving data theft, encryption, and victim negotiation.

While the investigation does not independently confirm the existence or effectiveness of the ransomware itself, it demonstrates that 313Ransomware had become a central component of the group's public operational narrative, marking a notable evolution from symbolic defacement activity toward messaging more commonly associated with ransomware operations.

More Than a Hacker Collective: Decoding 313 Team's Narrative

Throughout the investigation, one observation became increasingly clear: 313 Team consistently portrays itself as more than a conventional hacking group. While its activities revolve around cyber operations, the language, symbolism, and messaging surrounding those operations suggest that the group views cyberspace as an extension of a broader ideological struggle rather than simply another domain for conducting attacks.

This identity is established from the moment the group introduces itself. Across its Telegram channels, 313 Team repeatedly refers to itself as the "Iraqi Cyber Army" and "The Islamic Cyber Resistance in Iraq", while incorporating religious phrases such as "جنود الإمام المهدي" ("Soldiers of Imam al-Mahdi") and hashtags including #Ya_Mahdi and #Free_Palestine. The group's logo further reinforces this identity, featuring a raised hand holding an assault rifle above a globe alongside the Quranic verse, "Permission [to fight] has been given to those who are fought because they have been wronged" (Quran 22:39). Rather than functioning as decorative imagery, these elements frame the group's cyber operations as part of a larger religious and political narrative centered on resistance.

The significance of the name 313 also appears to support this narrative. Within Shia Islamic tradition, the number is commonly associated with the 313 companions of Imam al-Mahdi, who are believed to stand alongside him before the final establishment of justice. Although the group has not explicitly explained its choice of name, the repeated references to Imam al-Mahdi throughout its public messaging strongly suggest that the branding was chosen deliberately to reinforce this symbolic identity. The result is a consistent image of a cyber collective seeking legitimacy through religious symbolism rather than presenting itself simply as a group of hackers.

The targets highlighted throughout the group's public messaging further illustrate how it seeks to position its operations. Many of the claimed attacks involve organizations that the group associates with its political narrative, including Saudi government services, Israeli entities, and companies perceived as supporting opposing interests. At the same time, the investigation also identified claims involving international technology companies and commercial organizations such as Microsoft 365, Ubuntu, and eBay. This broader range of targets suggests that the group's messaging is not confined solely to government institutions. Instead, its public narrative portrays cyber operations against both public and private organizations as legitimate acts of resistance whenever they are believed to serve the group's broader ideological objectives.

Equally revealing is the language used to describe these operations. Throughout the Telegram posts examined during this investigation, attacks are rarely portrayed as criminal acts or opportunities for financial gain. Instead, they are consistently framed as acts of retaliation, resistance, or justice carried out on behalf of a wider cause. Even messages directed toward alleged victims adopt the language of conflict rather than conventional cybercrime. During the claimed attack against Ubuntu, for example, the group instructed the organization to negotiate a "permanent ceasefire" through an encrypted Session channel, while messages directed at eBay warned that attacks would continue until communication was established. This choice of language mirrors the rhetoric of armed conflict, reinforcing the group's effort to present itself as a participant in an ongoing struggle rather than a traditional ransomware operation.

The investigation also showed that 313 Team's Telegram ecosystem serves purposes extending well beyond announcing cyberattacks. Alongside operational updates, the group distributed technical resources such as the VigilAir drone detection document and the Naem Spy System Mehrdad Rahimi Contacts directory. The presence of these documents within the group's channels suggests an attempt to position Telegram as a broader repository for technical knowledge, operational resources, and intelligence-related material. This combination of propaganda, technical content, and operational announcements helps cultivate an image of an organized movement rather than a collection of isolated actors.

These observations indicate that 313 Team places as much emphasis on shaping perception as it does on claiming cyber operations. Its messaging consistently blends religious symbolism, political narratives, technical content, and cyber activity into a unified public identity. Whether announcing a website defacement, promoting what it describes as 313Ransomware, or distributing technical material through Telegram, every communication reinforces the same overarching message: that the group's cyber activities are intended to be viewed not as isolated hacking incidents, but as contributions to what it describes as the broader Islamic cyber resistance.

Conclusion

What began as the investigation of a single website defacement ultimately revealed a far more structured and deliberate cyber operation. By correlating evidence across StealthMole's Defacement Alert and Telegram Tracker, the investigation uncovered an interconnected ecosystem extending well beyond isolated attack claims. Telegram channels, backup infrastructure, defacement archives, public code repositories, communication identifiers, and ransomware-related messaging collectively paint the picture of a group that has invested considerable effort in building and maintaining a recognizable digital presence.

The investigation also demonstrates that 313 Team actively cultivates an identity that combines ideological messaging with cyber operations. Rather than portraying its activities as ordinary cybercrime, the group consistently frames its operations within the broader narrative of the Islamic Resistance, using religious symbolism, political messaging, and coordinated propaganda to reinforce that identity. Its repeated references to 313Ransomware, public negotiation messages, and technical discussions further suggest an effort to project capabilities extending beyond website defacements, even where those capabilities cannot be independently verified through the available evidence.

Perhaps the most important outcome of this investigation is not the confirmation of any single attack, but the ability to connect fragmented pieces of publicly available information into a coherent operational profile. Viewed individually, a defacement page, a Telegram post, or a GitHub repository may appear insignificant. Examined together, however, they reveal how 313 Team communicates, how it sustains its online presence, and how it seeks to shape perceptions of its own capabilities. That broader understanding provides a stronger foundation for future monitoring than any individual attack claim alone.

Editorial Note

Cyber threat investigations rarely produce absolute answers. Public claims, defacement pages, and online personas often mix verified activity with exaggeration, making careful attribution essential. This investigation demonstrates how StealthMole enables analysts to move beyond isolated indicators by correlating infrastructure, communications, and digital artifacts across multiple sources. While the operational picture surrounding 313 Team will undoubtedly continue to evolve, documenting and connecting these observable elements provides valuable context for understanding both the group's current activities and its future trajectory.

To access the unmasked report or full details, please reach out to us separately.

Contact us: support@stealthmole.com

Labels: ,

Beyond the Leak Site: Uncovering Lynx Ransomware's Infrastructure

Ransomware operations have evolved well beyond encrypting files and demanding payment. Many now function as structured criminal enterprises, maintaining dedicated leak sites, communication portals, and supporting infrastructure designed to pressure victims, manage negotiations, and reinforce their public presence. While these websites often become the most visible part of a ransomware operation, they rarely tell the full story.

Lynx is one such group. Since emerging on the ransomware landscape, it has established an online presence that extends beyond publishing victim information. Like many modern ransomware operations, its infrastructure consists of multiple interconnected components that each serve a distinct purpose, offering valuable insight into how the group presents itself and supports its activities.

This report explores Lynx's publicly accessible infrastructure through a technical investigation conducted using StealthMole. By following infrastructure pivots, examining hidden services, and correlating findings across multiple StealthMole datasets, the investigation moves beyond the group's leak site to build a broader picture of its operational footprint. Rather than focusing on individual attacks or victim disclosures, the report examines the digital infrastructure surrounding the operation and the intelligence that can be uncovered by following those connections.

Behind the Curtain

The investigation began in StealthMole's Government Monitoring module, where a search for "Lynx" returned 8 government-sector organizations that had been listed by the group. The most recent entry was the Talbot County Department of Emergency Services (DES), whose disclosure page included a description of the organization, its reported annual revenue, and the date the listing was published. While the victim itself was not the focus of this investigation, the listing provided an entry point into Lynx's ecosystem and established a starting point for exploring the infrastructure supporting its operations.

  • http://lynxblogoxllth4b46cfwlop5pfj4s7dyv37yuy7qn2ftan6gd72hsad.onion/leaks

To understand the broader scope of the group, the investigation then shifted to StealthMole's Ransomware Monitoring module. A further search of Lynx revealed a significantly larger operational footprint, with 397 victims indexed between July 2024 and August 2026. The volume of disclosures demonstrated that the Talbot County incident was not an isolated event but part of an active ransomware campaign that had persisted for more than two years. More importantly, the historical records offered an opportunity to look beyond recent activity and trace how the group's infrastructure had evolved over time.

Rather than concentrating on the latest disclosures alone, earlier victim listings were examined to identify infrastructure that might no longer be visible through the current leak site. One of the earliest indexed entries, published in August 2024, pointed to a different leak page hosted at:

  • http://lynxblog.******/leaks/66a***********331

This historical listing proved particularly valuable. In addition to the victim information, it exposed several operational artifacts that were absent from more recent disclosures, including the ProtonMail address james*******0@proton.me and a dedicated Tor-based negotiation portal:

  • http://lynxch*********************************qiyqd.onion/login

Victims were also instructed to register using an unique identifier before initiating negotiations. These details suggested that the historical leak page offered far more than a record of a past victim. It provided the first tangible links to the group's operational infrastructure and presented several new avenues for investigation.

  • 66*****************cb4e

Inside the Infrastructure

With historical artifacts pointing towards multiple operational components, the investigation turned to Lynx's current infrastructure to determine how the group maintained its public presence and whether traces of its wider ecosystem remained accessible.

  • lynxblogoxllth4b46cfwlop5pfj4s7dyv37yuy7qn2ftan6gd72hsad.onion

A review of the site confirmed that it remained active at the time of the investigation. Its homepage followed the structure commonly adopted by modern ransomware operations, providing access to sections dedicated to News, Leaks, and Report, while continuing to publish victim disclosures through an actively maintained leak portal. StealthMole's historical records showed that the hidden service was first observed on 20 August 2024 and remained active as of 11 August 2026, demonstrating that the infrastructure had been operational for nearly two years.

The leak portal itself contained the latest victim disclosures. Alongside each victim listing, the site published organizational descriptions, reported revenue, publication dates, and supporting proof files, reflecting the group's continued use of public disclosures as a means of pressuring victims during negotiations.

Rather than stopping at the homepage, the investigation expanded to examine the hidden service itself. Several publicly accessible pages were identified, each providing a clearer picture of how the platform was structured.

Component

URL

Login Portal

http://lynxchat***********knad.onion/main/chat

Registration Portal

http://lynxchat************knad.onion/register

Chat Interface

http://lynxchat***********knad.onion/main/chat

Server Status

http://lynxchat*******knad.onion/server-status

The login interface required registered credentials, while the registration page prompted users to enter a unique identifier and password before creating an account. Combined with the dedicated chat interface, these pages indicate that the platform was designed to support authenticated victim communications rather than relying solely on email exchanges. An attempt to access the /server-status endpoint returned a 404 Page Not Found response, suggesting that the endpoint was either unavailable or intentionally inaccessible during the investigation.

The infrastructure also exposed additional technical metadata through StealthMole. The hidden service was identified as running nginx/1.27.5 While these metadata points do not independently reveal the group's operations, they provide additional artifacts that can be correlated with other datasets during an infrastructure investigation.

Connecting the Dots

With the current leak site confirmed to be active, the investigation shifted from examining the visible infrastructure to exploring the technical artifacts associated with it. Rather than relying solely on what could be observed through the website itself, StealthMole was used to pivot from the hidden service into related malware intelligence, allowing the investigation to uncover connections that would not have been apparent from the leak site alone.

  • lynxblogoxllth4b46cfwlop5pfj4s7dyv37yuy7qn2ftan6gd72hsad.onion


Searching the current leak site, within StealthMole's Dark Web Tracker revealed 37 malware hashes associated with the domain. Rather than treating these as isolated indicators, each hash was investigated individually to determine whether it could provide additional insight into the group's operational infrastructure.

  • 0212*******************************************************7a5eb
  • 71db*******************************************************a0834
  • c587*******************************************************6d633
  • f85e*******************************************************0e619
  • 820e*******************************************************36f8a
  • 582e*******************************************************2fffe
  • 31de*******************************************************d5193
  • 5da4*******************************************************83040
  • bb4e*******************************************************f600a
  • f71f*******************************************************62787
  • 8090*******************************************************0c441
  • 97c8*******************************************************2ba00
  • 8569*******************************************************f5683
  • 432f*******************************************************29c66
  • d20c*******************************************************999f9
  • 468e*******************************************************89d6a
  • 0315*******************************************************21663
  • 589f*******************************************************21a23
  • 571f*******************************************************6cf8b
  • 551e*******************************************************ec386
  • 9a47*******************************************************a3896
  • ecbf*******************************************************f6e49
  • f9bb*******************************************************d56b7
  • 4e5b*******************************************************66412
  • c3b5*******************************************************24a18
  • 4ad4*******************************************************06ac4
  • 90ac*******************************************************cf7b8
  • ac68*******************************************************5b43f
  • dac3*******************************************************c94ed
  • cf7c*******************************************************7ac9c
  • 6486*******************************************************0313a
  • 0fb2*******************************************************1da93
  • ac50*******************************************************e9b60
  • dcba*******************************************************359cc
  • 4fbb*******************************************************4763b
  • 5533*******************************************************a931d
  • 1a01*******************************************************6ced0

One hash, in particular, proved especially valuable:

  • 4fb****************************************************763b

Using this artifact as a pivot uncovered a much broader network of Lynx-associated hidden services. The hash was linked to 14 separate Tor domains, consisting of both leak portals and negotiation portals.

Associated Leak Sites

Domain

Status

lynxblogco7r37jt7p5wrmfxzqze7ghxw6rihzkqc455qluacwotciyd.onion

Inactive

lynxblog************************************2sjyd.onion

Active

lynxblog***********************************2csyad.onion

Active

lynxblogoxllth4b46cfwlop5pfj4s7dyv37yuy7qn2ftan6gd72hsad.onion

Inactive

lynxblog************************************omjad.onion

Active

lynxblog***********************************z3xwqd.onion

Active

lynxblog**********************************ngrfoid.onion

Active

Associated Negotiation Portals

Domain

Status

lynxchat**********************************dbsgmyd.onion

Active

lynxchatde4spv5x6xlwxf47jdo7wtwwgikdoeroxamphu3e7xx5doqd.onion

Inactive

lynxchatdy3tgcuijsqofhssopcepirjfq2f4pvb5qd4un4dhqyxswqd.onion

Inactive

lynxchat***********************************6quxqd.onion

Active

lynxchatfw4rgsclp4567i4llkqjr2kltaumwwobxdik3qa2oorrknad.onion

Inactive

lynxchatly4zludmhmi75jrwhycnoqvkxb4prohxmyzf4euf5gjxroad.onion

Inactive

lynxchatohmppv6au67lloc2vs6chy7nya7dsu2hhs55mcjxp2joglad.onion

Inactive

This single pivot expanded the investigation well beyond the original leak site, revealing multiple generations of Lynx infrastructure that included both active and inactive hidden services. Instead of a standalone website, the findings pointed towards an ecosystem of interconnected domains supporting different aspects of the group's operation.

The investigation continued by exploring additional Lynx-related domains identified through StealthMole, uncovering a further 16 hidden services sharing the group's naming convention. While their specific functions could not be determined from the available evidence, they collectively demonstrated that Lynx maintained a significantly broader Tor footprint than was immediately visible through its public leak site.

Among the additional infrastructure identified were:

  • lynx2*************************************fqiqd.onion
  • lynxa*************************************5daqd.onion
  • lynxo**************************************2oqd.onion
  • lynx2*************************************626yd.onion
  • lynxb************************************z3vvyd.onion
  • lynxk*************************************xc3ad.onion
  • lynxa*************************************whead.onion
  • lynxh*************************************feuid.onion
  • lynxc************************************v2pxyd.onion

while several additional domains were observed in an inactive state, suggesting that portions of the infrastructure had either been retired or replaced over time.

The infrastructure mapping did not end there. A further pivot into the hidden service

  • lynxbllrfr5262yvbgtqoyq76s7mpztcqkv6tjjxgpilpma7nyoeohyd.onion

identified three additional malware samples associated with the domain:

  • 9e565d*****************************************************345da
  • 730f82*****************************************************a753c
  • 2c9f41*****************************************************84e06

One of these malware samples led directly to another operational domain:

  • lynxch2k5xi35j7hlbmwl7d6u2oz4vp2wqp6qkwol624cod3d6iqiyqd.onion

This correlation reinforced the value of using technical artifacts as investigative pivots. Rather than simply cataloguing domains, each malware sample provided another opportunity to uncover infrastructure that was not immediately visible from the group's public-facing services, gradually revealing a far more extensive operational network than the investigation had initially exposed.

The Human Layer

While the infrastructure mapping revealed how Lynx's hidden services were interconnected, the investigation also identified several operational artifacts that offered further insight into how the group communicates with victims and presents itself publicly. Rather than relying on domains alone, these artifacts helped bridge the gap between the group's technical infrastructure and its day-to-day operations.

One of the earliest pivots originated from the historical lynxblog.*** leak page, where the ProtonMail address james*****0@proton.me was first identified. To determine whether additional contact points existed, the domain was further investigated using StealthMole's Dark Web Tracker. This search uncovered two additional email addresses associated with the group's infrastructure:

  • ewik****************8@proton.me
  • martina*************8@proton.me

Unlike standalone contact details, these email addresses appeared repeatedly across multiple artifacts indexed by StealthMole, indicating that they formed part of Lynx's operational communication channels. Their repeated appearance across different records strengthened the association with the group's infrastructure and provided additional indicators for future investigations.

Further examination of these addresses uncovered several copies of the group's ransom note. Beyond outlining payment and negotiation procedures, the note demonstrated how Lynx directs victims toward its communication channels and hidden services. The recovered screenshots also showed martina*******8@proton.me appearing consistently throughout multiple ransom note variants, suggesting that the address was actively used as a victim contact point rather than appearing in a single isolated campaign.

The investigation also revisited several of the group's publicly accessible web pages, including the login and registration portals, to better understand how victims were expected to interact with the platform after initial contact. Combined with the previously identified negotiation portals, these components indicate that Lynx relies on a structured communication workflow in which victims are directed from the leak site to authenticated portals and dedicated contact channels rather than depending exclusively on email correspondence.

To better understand how the group presents itself publicly, a search for "Lynx Ransomware" within StealthMole's Dark Web Tracker uncovered a press release attributed to the operators. In the statement, the group described itself as financially motivated and claimed that it avoids targeting government institutions, hospitals, and non-profit organizations. The release also emphasized negotiation as its preferred method of resolving incidents and portrayed the operation as adhering to its own internal code of conduct.

As with many ransomware groups, however, these statements should be interpreted as self-described messaging rather than independently verified facts. Public declarations of intent often serve to shape perception among victims, affiliates, and the wider cybercriminal ecosystem, and should therefore be considered alongside technical evidence rather than accepted at face value.

The recovered email addresses, ransom notes, negotiation portals, and public statements provide a more complete picture of Lynx's operational identity. While the infrastructure mapping revealed where the group's services reside, these artifacts illustrate how the operators communicate, negotiate, and attempt to define their public image within the ransomware ecosystem.

Conclusion

What began as a review of a single government-sector victim quickly evolved into a broader investigation of Lynx's operational infrastructure. By following a series of technical pivots across StealthMole's Government Monitoring, Ransomware Monitoring, and Dark Web Tracker datasets, the investigation moved beyond the group's public leak site to uncover historical infrastructure, hidden services, malware associations, operational contact channels, and public communications.

Rather than relying on a single source of intelligence, the investigation demonstrated how seemingly unrelated artifacts can be connected to build a more complete picture of a ransomware operation. Historical leak pages provided the first operational pivots, malware intelligence exposed additional hidden services, and recurring communication artifacts revealed how the group manages victim interactions beyond its public-facing website.

Together, these findings highlight the importance of looking beyond victim disclosures when investigating ransomware groups and illustrate how infrastructure-focused analysis can uncover valuable intelligence that may otherwise remain hidden.

Editorial Note

Investigating ransomware groups is rarely a straightforward process. Infrastructure changes over time, hidden services disappear, and public statements often reflect the narrative that threat actors want others to believe rather than independently verifiable facts. Building meaningful intelligence therefore requires careful correlation of historical records, technical artifacts, and operational indicators while maintaining a clear distinction between observed evidence and actor claims.

This investigation demonstrates how StealthMole enables analysts to connect those disparate pieces of information into a coherent picture, allowing investigations to extend well beyond the visible leak site and into the broader infrastructure supporting a ransomware operation.

To access the unmasked report or full details, please reach out to us separately.

Contact us: support@stealthmole.com

Labels: ,

Learn more about StealthMole

Talk to our team of experts today to learn how you can manage your dark web exposure.
Request demo More Reports

Share this report