The ExtortionLord Trail: How a KakaoTalk Sale Led Back to LockBit's Leaked Infrastructure
The underground data trade rarely revolves around a single forum or marketplace. Sellers and brokers move between dark web communities, encrypted messaging platforms, and private channels, offering everything from compromised databases and source code to network access and internal corporate data. The identities behind these operations can be equally fluid. Usernames change, accounts disappear, and communication shifts from public posts to private messengers, leaving investigators to piece together fragments scattered across different platforms and points in time.
One such figure is ExtortionLord, a threat actor whose activity surfaced through the sale and distribution of compromised data on underground forums. At first glance, the actor appeared to fit a familiar profile: an underground seller advertising access to valuable stolen material. But as we began following the identifiers and traces surrounding ExtortionLord through StealthMole, the investigation started moving beyond individual sales posts and into a wider network of forum activity, aliases, encrypted communication identifiers, Telegram accounts, channels, and leaked files.
This report follows that investigation as it unfolded. Starting with the activity that first brought ExtortionLord into view, we trace the actor's footprint across underground sources and follow each meaningful lead into the next. Along the way, the investigation reaches communication channels connected through shared identifiers, profiles that may offer additional context around the people involved.
The First Trace of ExtortionLord
The investigation began when StealthMole's Leaked Monitoring tool indexed a recent post from a user operating under the name ExtortionLord. The post appeared on DarkForums, where the actor claimed to be selling KakaoTalk's full source code, alongside network access and access to the company's databases.
- https://darkforums.**/Thread-Selling-Kakao-Talk*************96
At this stage, ExtortionLord was simply an unfamiliar name attached to a potentially significant underground sale. There was little indication of who was behind the account or whether the identity had appeared elsewhere. Rather than stopping at the leak itself, we decided to use the information captured by StealthMole as the starting point for a deeper investigation into the seller.
The DarkForums link surfaced through Leaked Monitoring tool was examined further using StealthMole's Dark Web Tracker. Inside the thread, ExtortionLord had left a single direct contact point for anyone interested in reaching them:
- TOX: 4DEBE**********************************************B55A9
Unlike a username, which can easily be copied or reused across unrelated platforms, this long-form identifier offers a much more specific artifact to work with. It gave the investigation two immediate directions: the ExtortionLord identity itself and the Tox ID the actor had chosen as their only listed contact point.
From there, the focus shifted away from the KakaoTalk sale itself. The question was no longer simply what ExtortionLord claimed to possess, but what traces the actor and their contact information might have left elsewhere across the underground ecosystem.
Following the Contact Point
With the Tox ID established as ExtortionLord's only listed contact method on the DarkForums thread, the next step was to determine whether the same identifier had surfaced elsewhere. A search for the full Tox ID through StealthMole produced a much broader trail than the original KakaoTalk listing suggested.
The identifier appeared in a post on XSS, but this time it was not attached to the ExtortionLord name. Instead, the post was associated with the alias Mansoryx. The overlap immediately stood out. The same Tox ID that ExtortionLord had provided as the sole contact point for the KakaoTalk offering was now connected to a different underground identity.
This did not, on its own, establish that ExtortionLord and Mansoryx were the same person. Communication identifiers can potentially be shared, transferred, or used by multiple individuals. However, the exact match provided a concrete connection between the two identities and gave us another lead to follow.
We then searched the Tox ID through StealthMole's Telegram Tracker, looking for any messages or channels where it had previously been mentioned.
That search led us to a telegram channel:
- https://t.me/+NV5**********mI0
Inside the channel, we identified a message containing two encrypted-messaging identifiers. One was the same qTox ID already encountered in the DarkForums and XSS threads:
- 4DEBEB************************************************DB55A9
Another was a Session ID:
- 05a19***********************************************69c74917
At this point, the investigation had moved considerably beyond the original sale post. A Tox identifier first discovered as ExtortionLord's contact point on DarkForums had led to the Mansoryx alias on XSS, which in turn led to a Telegram channel where the same Tox ID appeared alongside a second encrypted communication identifier.
The repeated appearance of the exact Tox ID across these separate sources gave the investigation a more stable thread to follow than the usernames themselves. ExtortionLord and Mansoryx remained identities requiring careful attribution, but the communication infrastructure connecting the activity was beginning to form a clearer trail.
New Names Begin to Surface
With the Tox and Session identifiers now appearing together in the same Telegram message, we continued investigating the Tox ID beyond the underground sources already uncovered. This led us to a security research report published by Trellix examining the leak of LockBit's administrative panel.
The report contained the same Tox ID we had been following since the original ExtortionLord post. More importantly, it provided additional context around the communication trail that had started to emerge through our own investigation.
Among the information documented in the research was a Telegram account:
- https://t.me/INFO********l
The report also referenced activity involving the moniker flex, which had reportedly been used in connection with efforts to recruit pentesters on the XSS forum.
These findings introduced new names into the investigation, but they also required caution. The presence of the same Tox ID created a reason to examine the surrounding accounts and aliases, but it was not enough to conclude that ExtortionLord, flex, or the operator behind @INFO*******l were necessarily the same individual. Each would need to be investigated independently before any stronger connection could be made.
The Telegram account provided the most immediate next step. We searched @INFO*********l through StealthMole's Telegram Tracker, where the account surfaced under the name Molot.
The profile contained a particularly interesting detail. In its bio, Molot had included the following message:
Не ответил? проигнорировал? продублируй https://t.me/+NV51*********mI0
The link pointed to the same Telegram channel we had already reached by tracing ExtortionLord's Tox ID, the channel where the Tox and Session identifiers had appeared together.
This created a more meaningful connection than a shared username or alias. The investigation had reached the channel independently through ExtortionLord's Tox identifier, while the @INFO*********l account surfaced through a separate research trail and directly referenced that same channel in its profile.
We then examined Molot's wider Telegram activity through StealthMole. The account was found participating in another Telegram community:
- https://t.me/user****forum
StealthMole's indexed data showed at least 24 messages associated with Molot in the channel, opening another avenue for examining the account's historical activity.
By this stage, the investigation had begun to move from isolated identifiers toward a more interconnected picture. Yet the relationships between the names remained unresolved. ExtortionLord, Mansoryx, flex, and Molot had now surfaced at different points along the same broader investigative trail, but the available evidence did not justify treating them as a single actor. What it did provide was a growing collection of connections that could now be examined against another source of evidence waiting in StealthMole's indexed data.
A Familiar Name Inside a Leaked Database
With the communication trail beginning to take shape, we returned to the other investigative direction created at the start of the case: the ExtortionLord username itself.
Searching ExtortionLord through StealthMole's Dark Web Tracker produced a result inside a leaked SQL file labelled Panel_DB. Unlike the earlier forum posts, this was not another public appearance of the alias. The username appeared as a record within a database dump.
To understand what the result contained, we analyzed the file using StealthMole's MoleChat. The analysis surfaced several values associated with the ExtortionLord record:
Username: ExtortionLord
Password/value: gRh************i5
Token/session-like value: eqnd*******************6ik2
At this point, however, the presence of the username raised more questions than it answered. A record labelled ExtortionLord inside an unidentified panel database did not tell us who operated the panel, what purpose it served, or what the actor's presence within the database actually represented. Even the additional values associated with the record could not be assigned a definitive function without understanding the underlying database structure.
The name of the file provided the next clue. We searched for references to paneldb_dump through StealthMole's Telegram Tracker and found the term appearing across several messages and shared files. One of those results came from a private Telegram channel, where copies of paneldb_dump and a corresponding torrent file had been circulated.
The accompanying message provided crucial context around what we had found. The material was described as originating from a compromise of LockBit's administrative infrastructure, with the leak attributed in the circulated material to an actor referred to as "xoxo from Prague."
This also brought the earlier Trellix report back into focus. The report we had initially reached while tracing ExtortionLord's Tox ID was examining the same broader event: the leak of LockBit's admin panel. What had previously served as a source of additional identifiers now provided context for understanding the unexplained SQL record surfaced through StealthMole.
The Panel_DB result was therefore not evidence of a database operated by ExtortionLord. Instead, the investigation indicated that the record had surfaced within data associated with the leaked LockBit admin panel.
That distinction was critical. It prevented an unrelated infrastructure attribution while opening a much more important question: why did a record carrying the ExtortionLord identity appear inside data from LockBit's leaked panel?
The answer could not be established from the username alone. But the database itself offered considerably more material to examine. Additional searches through StealthMole surfaced three more files associated with paneldb_dump, giving us an opportunity to look beyond a single ExtortionLord record and examine the structure and contents of the leaked panel in greater detail.
Looking Inside the LockBit Panel Leak
With the origin of paneldb_dump now clearer, the investigation shifted from identifying the database to understanding what it actually contained. StealthMole had surfaced three additional leaked files associated with paneldb_dump, which we analyzed using MoleChat to examine their structure and contents without manually navigating thousands of database records.
The files appeared to contain data from the backend of a ransomware operation. MoleChat identified records associated with victim and operator negotiations, including messages exchanged during ransom discussions and corresponding timestamps. Other records related to Bitcoin payment addresses, providing insight into how cryptocurrency addresses were managed within the panel.
The database also contained traces of the operational processes surrounding an extortion case. These included references to uploaded files and attachments, as well as records associated with test-decryption workflows, a process commonly used during ransomware negotiations to demonstrate that encrypted files can be recovered.
Additional tables and entries pointed to API-related activity and operational identifiers, while the records visible in the analyzed material covered activity from at least December 2024 through April 2025. Taken together, the files provided a glimpse into the administrative machinery behind the panel rather than simply a collection of leaked usernames.
This context helped us better understand the significance, and the limitations, of the earlier ExtortionLord record. Finding a username inside such a database could indicate that the identity existed somewhere within the panel's operational environment, but it did not, by itself, explain the individual's role. Without establishing precisely what table the record originated from and what that table represented, it would be premature to label ExtortionLord as a LockBit affiliate, administrator, or operator.
What made the finding more difficult to dismiss as a simple username collision, however, was the wider trail already uncovered during the investigation. The ExtortionLord identity found in the leaked panel data was being examined alongside a highly specific Tox identifier that had independently surfaced across the actor's 2026 DarkForums activity, XSS, Telegram, and external research connected to the LockBit panel leak.
The database therefore added an important historical layer to the investigation, but not a definitive attribution. Rather than providing a simple answer to who ExtortionLord was, it placed the identity within a much larger operational dataset and raised a more focused question about the nature of that connection.
With the LockBit panel data examined, one unresolved lead remained particularly interesting: Mansoryx, the alias encountered earlier on XSS using the same Tox contact point as ExtortionLord. We therefore returned to that identity to see whether StealthMole could uncover a historical footprint beyond the forum post where the name first appeared.
Conclusion
What began with StealthMole detecting an underground offer involving KakaoTalk ultimately became an investigation into the digital footprint surrounding the seller behind it. ExtortionLord initially appeared as a newly surfaced actor with little context beyond a DarkForums account and a Tox contact point. It was that contact point, rather than the username, that proved to be the most valuable lead.
Following the identifier across different sources uncovered traces that predated the KakaoTalk offering and crossed several corners of the underground ecosystem. The investigation encountered Mansoryx on XSS, a corresponding Session identifier in historical Telegram data, and the @INFO*********l account associated with Molot, whose profile pointed back to the same Telegram channel already uncovered through the Tox search. Separately, the ExtortionLord username surfaced within the leaked LockBit panel data, adding another potentially significant connection while leaving the actor's precise role within that environment unresolved.
Not every lead produced a definitive identity, and the investigation does not establish that ExtortionLord, Mansoryx, Molot, or flex are necessarily the same individual. The evidence instead shows how a single communication identifier can persist across platforms and over time, connecting activity that would otherwise appear unrelated. In this case, a Tox ID attached to a 2026 data sale opened a window into a much older and more complex trail.
The identity behind ExtortionLord therefore remains an open question. But the actor who appeared on DarkForums was not surrounded by an entirely new digital footprint. The identifiers attached to that identity had a history, and by following those traces across StealthMole's indexed dark web, leaked-data, and Telegram sources, it became possible to reconstruct parts of that history without forcing uncertain correlations into definitive attribution.
Editorial Note
Attribution in cybercrime and underground investigations is rarely absolute. Aliases can be reused, accounts can change hands, and communication identifiers may connect individuals without proving they are the same person.
The case also demonstrates the value of StealthMole in navigating these fragmented environments, allowing investigators to move between current activity and historical records, follow persistent identifiers across different sources, and distinguish meaningful connections from coincidences without overstating what the available evidence can prove.
To access the unmasked report or full details, please reach out to us separately.
Contact us: support@stealthmole.com
Labels: Breach, Featured, Ransomware, Threat Actor