Inside ZeroDay Commerce: Tracing Mushr00w’s Webshell Network
Webshells have become a familiar commodity in underground cybercrime communities. Instead of having to compromise a server themselves, buyers can purchase access that is already available and use it for their own purposes. For sellers, the model is simple: find vulnerable or compromised systems, maintain access, and turn that access into something that can be sold repeatedly. Telegram has become one of the places where this market is openly promoted, with sellers advertising everything from individual shell access to higher-value access on specific domains.
This investigation began with activity linked to this wider ecosystem and gradually led toward a Telegram user. What initially appeared to be another account operating within the underground quickly opened into a broader picture involving shell sales, private communities, other operators, and relationships that were not always straightforward.
Using StealthMole, the investigation moved between technical detections, Telegram activity, channel memberships and associated identities to piece together that picture. The findings reveal more than a single seller advertising access. They show how webshells are marketed, how sellers build communities around those services, and how disputes, collaborations and new identities can leave additional traces behind.
The First Signs of Compromise
The first lead came from StealthMole’s Defacement Alert, where Mushr00w was listed in connection with the defacement of the two government websites: Malaysian and Ukrainian.
The defacements themselves provided the first real connection to the actor. The pages were signed “SERVER FUCKED BY MUSHROOW” and, more importantly, included a direct Telegram address:
- http://t.me/M*****w
The pages also carried the familiar message, “We are Anonymous. We are Legion. We do not forgive. We do not forget. Expect us.” Alongside it were greetings to WebshellSR Famila, MeshSec, Illegalplatform.org and Roween. These names are part of the defacement content, but there is no evidence at this stage to say that they were working with Mushr00w.
The Telegram address gave the investigation its first clear pivot. Rather than following only the defaced websites, the username Mushr00w was directly searched into StealthMole’s Darkweb Tracker to see what was attached to the account behind it.
That search also brought up historical Zone-H records for the two incidents. The Malaysian defacement, where the archived page again carried “HACKED BY MUSHROOW” and the same Telegram address. The Ukrainian incident was similarly linked to Mushr00w in connection with the defacement.
- http://zone-h.org/mirror/id/42570843
- http://zone-h.org/mirror/id/42576330
The important part was not simply that the same name appeared twice. The defaced pages had given us a direct identifier that could be followed into Telegram. That was where the investigation moved from the websites themselves to the person operating behind the Mushr00w name.
The Door Marked ZeroDay
The Telegram link on the defaced pages provided the first direct route to Mushr00w. Running Mushr00w through StealthMole’s Telegram Tracker returned an account with the Telegram ID 6775881965 and the username @M*****w. The account had not always used that name. StealthMole’s historical indexing showed the same Telegram ID under several different usernames, giving us a much longer history to work with.
The account had previously appeared as @Lo****e, @Wiz****q, @Sur****a, @Raja_R33, @gh****e and @A*******z before settling on @M*****w. The historical snapshots also showed changes in the account’s display name, biography and profile image over time. For example, the account used the name R33 while operating as @Raja_R33 in October 2025, and later appeared as @Ah*******z before moving to @M*****w. The same Telegram ID ties these different usernames together, making the account history more useful than any single username on its own.
There were also some interesting changes in the account’s bio. On July 25, 2026, while using @M*******w, the bio read “im right here: T.me/Zer*******e”. That short line turned out to be the next important lead in the investigation. It pointed directly to a private Telegram community that was much more closely connected to Mushr00w’s activity.
StealthMole’s historical indexing also gave us a glimpse of activity that predated the current Mushr00w identity. In November 2025, the account was using @Ah*******z and posted a message in Turkish referring to arranging a bank loan of more than one million for a commission, finding people or a network able to get people to Europe, and meeting in Beyoğlu to begin immediately. The message is interesting as a potential language and geographic lead, but it does not by itself establish that the account holder was in Turkey or that they actually carried out any of the activities described.
The account history also contained other signs of underground activity. A September 2024 message under @Wiz*****q warned others about a supposed scammer, while another message from May 2026 asked whether anyone had a free WordPress exploit. These older messages were not enough on their own to explain who Mushr00w was, but they showed that the Telegram account had been active in underground conversations well before the current name appeared.
Inside the ZeroDay Counter
Following the link in Mushr00w’s Telegram bio led to ZeroDay Commerce, a private Telegram community with around 80 members. The group description leaves little doubt about what it is built around: “Digital marketing for SEO's / buy / sell webshells / exploits / No AI coders allowed / Advertising is prohibited here!” Mushr00w is listed in the group information, putting the account directly inside the community rather than simply appearing as another member.
The messages inside the group make the purpose of the community clearer. Webshell access was being advertised for specific websites, including https://petofi10miskolc.edu.hu/ and https://www.rmc.edu.my/, with the latter offered as “Webshell + Admin access.” Other posts advertised “HIGH DA PA DOMAINS AVAILABLE”, along with claims that shells had terminal access and could be used to upload, edit and delete files. Sellers also advertised replacement or refund support and a one-day guarantee after purchase.
One of the posts described the service in more direct terms: “We are more than just a seller”, followed by a claim that the group provided reliable shells, support and solutions to buyers. The contact details attached to these advertisements repeatedly included @M*****w and @boc********9.
The group was not limited to individual shell listings. Another post promoted a “S4LE priv8 WP Checker”, described as a tool capable of live site validation, automated login, plugin installation and user-role detection. Whether every capability advertised actually worked as claimed cannot be established from the posts alone, but the advertisement itself shows the type of tools being offered alongside shell access.
The same activity also appeared outside ZeroDay Commerce. StealthMole’s Telegram Tracker returned messages posted under the Mushr00w identity advertising shell access for edu.co, edu.mx, gov.au and gov.my domains. One post offered random shells for $2 each and stated that escrow was accepted. Another specifically claimed “ALL ROOT DIR / NOT SUBDOMAINS!” and again directed potential buyers to @M****w.
These posts are important because they show that the shell-selling activity was not limited to a single advertisement inside one private group. The same identity was being used to promote access elsewhere on Telegram. At the same time, the domains mentioned in these advertisements should not be mistaken for infrastructure owned by Mushr00w. The evidence shows them as systems for which shell access was being advertised, not proof that Mushr00w owned those domains or personally compromised them.
There was also another community connected to this activity. Rainbow Shell Market had Mushr00w listed as its contact and linked back to ZeroDay Commerce. Its description openly invited users looking for shells to join. Together, the two communities show a small but connected marketplace around the sale and promotion of webshell access, with Mushr00w positioned at the centre of the activity observed in the available evidence.
- https://t.me/Ra***********t
When Business Turns Personal
The activity around ZeroDay Commerce was not without friction. One of the accounts repeatedly appearing alongside Mushr00w in the shell advertisements was @boc*******9. The two accounts were presented together in posts offering shell access and related services, suggesting that they were working within the same commercial space.
That relationship later broke down publicly.
In a message posted through the ZeroDay Commerce community, the account identified as the owner announced that it was no longer connected with @bo******9 and warned others that any future dealings with the account would be their own responsibility. The message went further, accusing him of being a “liar thief” and claiming that he had stolen a shell. Another member, Yongbe, responded by asking him to be patient, showing that the dispute was taking place in front of other members of the community rather than in a private exchange.
The accusation was later answered by @bo*******9 through D1STR1CT9619, a community project that was also being used to share the dispute. His version of events was very different. He said he had been accused of stealing shells after an RDP he had purchased for Mushr00w developed problems. According to his account, Mushr00w believed that he had changed the RDP password and taken the shells, while he claimed that the RDP had actually been flagged because of misuse. He also denied taking shells for personal use and said he had refused to share proceeds from their sale.
Neither side's account can be independently established from these messages alone. What the evidence does establish is that Mushr00w and @bo********9 had previously been operating in the same shell-selling environment and that their relationship later ended in a public dispute over shell access and an RDP.
StealthMole's profile search on @bo********9 provided little additional information. The account is associated with Telegram ID 6271041627, uses the name “NO NAME”, and has no visible phone number or other identifying information. Its limited profile data therefore does little to resolve the dispute, but the activity surrounding the account gives us a clearer picture of its connection to Mushr00w than the profile itself does.
The fallout is useful for another reason. It gives us a glimpse into how these shell operations appear to function behind the advertisements: access is acquired through RDPs, shells have commercial value, and disagreements over control of that access can quickly become disputes within the same underground community.
The People Around the Seller
The deeper Telegram search showed that Mushr00w’s activity extended beyond ZeroDay Commerce. StealthMole linked Telegram ID 6775881965 to activity across 11 Telegram channels, with additional messages appearing in other groups and channels. This broader footprint made it possible to look at the people appearing around the account rather than treating Mushr00w as a standalone seller.
One of the clearest connections was @be*******u. In the ZeroDay Commerce member list, the account is explicitly marked as “Mate.” Its profile shows the display name X, username @be*******u, and the bio “Lucky 4U Not M3.” The “Mate” designation does not tell us exactly what role the account played, but it does establish that the account held that label within the community.
Another account, VX-encoded, also appeared as a Mate in ZeroDay Commerce. StealthMole identifies the account as @b*******d, Telegram ID 8256413322. Its profile contained a direct reference to the community in its bio: Direction: https://t.me/Zero********e. This provides a separate profile-level connection between VX-encoded and the same community surrounding Mushr00w.
VX-encoded also appeared in a conversation involving shell access. One message, written in Indonesian, questioned why someone would sell their dignity for 20–30 dollars and referred to asking for a “shell” through a backup account. VX-encoded then wrote that he had “lost respect for Indonesians" and questioned why so many of them were “stupid.” The exchange is useful for understanding the conversations taking place around shell access, although it does not identify the person being addressed or establish that VX-encoded was involved in the transaction being discussed.
Together, the Telegram data shows that Mushr00w was operating within a wider group of users rather than in isolation. Some relationships were visible through commercial posts, others through community roles, and others through the conversations taking place around shell access. The network was therefore larger than the Mushr00w account itself, even if the precise role of every person around it cannot be established from the available evidence.
Beyond the Network
The Telegram investigation was not the only place where the same name appeared. A separate OSINT search surfaced a profile:
- https://gitlab.archlinux.org/M*******w
The username is notably similar to the name used by the Telegram account, but that similarity alone is not enough to connect the two.
At the time of the investigation, the GitLab profile could not be examined further because access to the page was restricted. There was also no additional evidence available from the search that tied the account to Telegram ID 6775881965, ZeroDay Commerce, or any of the other identifiers already associated with Mushr00w.
For that reason, this lead remains separate from the main attribution chain. It is worth recording because the username is distinctive enough to warrant further checking, but there is currently no basis for presenting the GitLab account as belonging to the same person behind @M*****w.
This is also a useful reminder of one of the problems with tracking underground identities. A familiar username can point toward the right person, but it can just as easily belong to someone else. In this case, the Telegram evidence provides a much stronger foundation because several different usernames are tied to the same Telegram ID, while the GitLab account currently has no such link.
Conclusion
The investigation began with two website defacements carrying the Mushr00w name and a Telegram address that opened the door to a much wider footprint. StealthMole’s historical Telegram data then connected Telegram ID 6775881965 to multiple previous usernames and eventually to @M*****w, whose profile pointed directly to ZeroDay Commerce.
From there, the evidence became more consistent. ZeroDay Commerce and related Telegram communities were being used to promote and sell webshell access, while Mushr00w appeared repeatedly in those activities. The investigation also identified other accounts around the operation, including @bo******9, @be*****u and VX-encoded, although the exact role of each person is not equally clear. The public dispute with @bo********9 also showed that these relationships could change quickly when access and money were involved.
Overall, the available evidence supports viewing Mushr00w as an active participant in a Telegram-based webshell marketplace, with a history that extends beyond the current username and activity across multiple connected communities. At the same time, some leads remain unresolved, including the real-world identity behind the account and the relationship between Mushr00w and the separate Arch Linux GitLab profile.
Editorial Note
Dark web identities rarely stay consistent for long, and attribution is often built from fragments rather than a single definitive piece of evidence. In this case, usernames changed, relationships shifted, and some claims made by the actors could not be independently verified.
StealthMole helped bring those fragments together, allowing the investigation to follow the same account across historical identities, defacement activity and Telegram communities while keeping the uncertain parts of the picture separate from the findings that could be supported.
To access the unmasked report or full details, please reach out to us separately.
Contact us: support@stealthmole.com
Labels: Featured, Threat Actor, Zero Day