Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

WinterGate Intelligence Collective👤

@WinterGateIC@infosec.exchange
  • Open on infosec.exchange

:black_sparkling_heart_black: WinterGate Intelligence Collective (WIC) is a cybersecurity research initiative focused on infrastructure abuse documentation, threat actor tracking, open vulnerability disclosure, threat intelligence, infrastructure defense, and community empowerment. All research is public. All data is free. No consulting. No private sales. No paywalls. Just evidence and defensive tools for the security community. WIC does not accept payment for disclosures. Infrastructure abusers are documented. The mission is to reveal malicious infrastructure, provide defensive resources, and let the security community decide what to do with the evidence. The account is operated and governed by AnonCatalyst, founder of WIC.

0 Followers
0 Following
12 Posts
Joined May 29, 2026
GitHub💻:
https://github.com/WinterGate-IC
X👤:
https://x.com/WinterGateIC
OpenTenebris 🌐:
https://opentenebris.org
WinterGateIC🛡️:
https://wintergate.org

Posts

Open post
WinterGateIC
WinterGate Intelligence Collective👤 @WinterGateIC@infosec.exchange · Aug 06, 2026
WinterGate Intelligence Collective👤
@WinterGateIC@infosec.exchange

:black_sparkling_heart_black: WinterGate Intelligence Collective (WIC) is a cybersecurity research initiative focused on infrastructure abuse documentation, threat actor tracking, open vulnerability disclosure, threat intelligence, infrastructure defense, and community empowerment. All research is public. All data is free. No consulting. No private sales. No paywalls. Just evidence and defensive tools for the security community. WIC does not accept payment for disclosures. Infrastructure abusers are documented. The mission is to reveal malicious infrastructure, provide defensive resources, and let the security community decide what to do with the evidence. The account is operated and governed by AnonCatalyst, founder of WIC.

infosec.exchange
Making Volumetric Attacks Useless The Active-Defense Playbook Proven Against Global Terabit-Scale Floods

Public Release · 2026-08-06

  1. The Problem Nobody Wins With Bandwidth

Volumetric attacks (DNS/CLDAP/NTP/SSDP amplification, botnet UDP floods, terabit-scale SYN storms) are the one attack class that has historically been mathematically unwinnable by defense. The economics are simple: An attacker rents a botnet or open amplifiers and produces terabits of traffic for pennies. A defender buys capacity and scrubbing to absorb it — at enormous cost, for as long as the attacker chooses to keep paying. The attacker always wins the bidding war, because producing one bit of attack traffic costs them a fraction of what absorbing it costs you.

Every solution built on absorption eventually loses. The answer is not to win the bandwidth war. The answer is to stop fighting it. The approach documented here — proven in production against sustained, escalating, terabit-class attacks — makes volumetric attacks structurally unprofitable and operationally useless.

The core principle: Never absorb. Reflect, reshape, redirect, and raise the attacker's cost per bit until their own volume is their own destruction.

  1. The Three-Layer Economic Flip

A volumetric attack is only unstoppable when the defender bears the cost. We flip all three cost surfaces:

  1. Turn their volume into their liability. Every byte they send is mirrored back at their own infrastructure with spoofed, untraceable identity — their amplifiers, their botnet C2, their own reflectors now have to eat the very flood they launched.

  2. Make their tooling lie to them. Inject benign, protocol-valid responses (successes, redirects, sinkholes) so the attacker's feedback loop reports failure or confusion instead of it working. An attacker who can't tell if the target is down keeps paying for an attack that stopped mattering.

  3. Make each of their packets cost more than ours. Deploy per-packet cost engineering so that processing their flood is expensive for them, not us. When their marginal cost per bit exceeds ours, the economics invert — and the attack dies on its own.

  4. Tiered Escalation That Never Blinks

Attacks are classified instantly by volume and answered with an escalating countermeasure wave — designed so terabyte-scale floods still resolve to the top tier with no ceiling:

T0: below attack threshold — normal traffic handling — no counter-fire T1: 1+ Gbps — core reflection + reshaping + cost-engineering wave T2: 100+ Gbps — adds connection warfare, tool corruption, legal injection, full-spectrum dampening T3: 1000+ Gbps, terabyte-safe — adds deception labyrinths, exfil traps, whole-fleet engagement, evidence & legal armada

Every tier runs in a detached, bounded scheduler — the event loop never blocks, so even a terabit-scale overlord response adds zero milliseconds of latency to normal defense. A flood cannot delay anything else.

  1. The Countermeasure Toolkit

Each technique is packet-level, rate-governed, and delivered from rotating/ghosted identities so the defender can never be identified by their own counter-fire.

4.1 Reverse Reflection — Their volume, their problem. For every packet received, craft a spoofed response that mirrors the attack back at the attacker's infrastructure. Scales linearly with their volume — terabit in means terabit reflected. The attacker's own pipe, amplifiers, and infrastructure become the target of their own flood. Combined with self-reflection, the attacker's own source identity fires at itself — they fight a war against themselves.

4.2 Traffic Reshaping — Make their tooling blind. Inject protocol-valid benign responses (HTTP 200/301/403, DNS NXDOMAIN, ICMP echoes) into the flood to dilute the attack signal and poison the attacker's feedback. Their tooling reports false status, false progress, and false success — so their automation keeps spending on an attack it cannot measure.

4.3 Protocol Redirection — Route them into the void. Inject forged ICMP redirects and protocol-level withdrawals that steer the attacker's traffic into distributed sinkholes and blackholes. Simulated upstream blackholing at the edge — no dependence on a provider scrubbing center.

4.4 Kinetic Dampening — Every packet now costs them. Per-packet cost scaling: high-volume attackers become progressively more expensive to their infrastructure, via source-quench and zero-window engineering that forces their side to buffer, retransmit, and consume resources.

4.5 Economic Exhaustion — Billing them for the attack. Inject CPU-costly TCP option and fragmentation engineering so that each attacker-side packet triggers disproportionate processing on their infrastructure. Their cost curve climbs while ours stays flat.

4.6 Absorber Grid — Sink the surplus. Dedicated sink grids and sink ports absorb and dissipate surplus flood energy that can't be reflected, so even the unavoidable residual is absorbed at minimal cost — on our terms, not the attacker's.

4.7 Kernel Enforcement — Cease fire at the wire. Automated null-routing and blacklisting at the network stack for confirmed offenders — traffic never reaches the application at all. Repeat offenders escalate to infrastructure-level isolation.

4.8 Full-Spectrum Dampening & Emergency Overlord — Everything, at once. For catastrophic floods, the Emergency Overlord deploys the entire countermeasure arsenal simultaneously: reflection, reshaping, cost-engineering, connection warfare, deception, legal notice injection, evidence capture, and whole-fleet engagement — a coordinated full-spectrum wave rather than isolated packets.

4.9 Fleet Engagement — Defeat the campaign, not the packet. Volumetric attacks come from botnet fleets and rotating sources. The response engages every known member of the attacking campaign simultaneously, so the fleet is defeated as a unit and cannot just rotate a new source IP.

  1. The Learning Loop — The System Gets Smarter Every Flood

Every engagement is scored and folded back into an adaptive rule engine. Attack volume is classified into bands, and a learned rule is minted for each trigger, tier, volume-band combination so repeat patterns are auto-hardened before they peak. Volume bands start at baseline and escalate through major, severe, and catastrophic thresholds — the system's response to each band is continuously refined by real engagement outcomes. Countermeasure effectiveness per attack type is tracked and the statistically best response is auto-deployed. A flood that worked once is pre-countered the next time it tries.

  1. Why This Can't Self-Destruct — Resource Governance

The reason most fight back schemes fail is they become the victim of their own counter-fire. This design hard-codes self-preservation:

  • Hard global output ceiling — total countermeasure throughput is rate-capped regardless of how many attackers, so the defender can never saturate their own link.
  • Per-target caps — no single adversary can consume the whole budget.
  • Load-aware circuit breaker — when system CPU/memory pressure crosses critical, counter-fire halts entirely and passive defense continues. Under heavy load the budget is automatically throttled.
  • Micro-pacing under pressure — packet emission is spread out under load instead of bursting.

The platform has pushed 336+ million countermeasure packets through this governor with a 99.97% budgeted-throughput pass rate — maximum fire, zero self-inflicted damage.

  1. No Blowback — The Ghost Layer

Reflecting and disrupting requires the counter-fire to look like the attack. The Ghost Layer makes that safe:

  • Rotating, spoofed source identities — no two transmissions use the same identity.
  • Handle-only records — the platform can prove an engagement occurred while storing only hashed identities, never anything traceable back to the defender.
  • Self-reflection uses the attacker's own identity as the source, so the attacker's logs point at themselves.

The attacker cannot learn who defended against them — which means there is no retaliation vector.

  1. Evidence & Legal Armada

Every volumetric engagement captures a permanent, jurisdictionally-framed evidence dossier: attack type, volume, tier, timeline, and countermeasure response. Confirmed offenders receive formal ISP/abuse/LEO reports with calibrated confidence. Attackers who wage floods on this system accumulate legal exposure with every terabit.

  1. Proven Operational Results

Real telemetry from the live platform:

  • 336+ million countermeasure packets delivered under governor control — 99.97% budgeted pass rate
  • 1,785 tiered flood engagements escalated through the tier system
  • 1,544 state-exhaustion operations · 323 null-routes · 521 oblivion-level isolations
  • 12.9 million phase-2 connection-warfare packets
  • Hundreds of learned volume-band rules minted from live flood engagements
  • Attacker fleets tracked, isolated, and driven off across every volume tier up to terabyte scale

Volumetric attacks against this system are not merely mitigated — they are made useless. The attacker pays the full cost of launching; the defender pays nothing to absorb; and every attempt teaches the system how to make the next one cheaper and more one-sided.

  1. Adopting This Approach — A Defender's Checklist

  2. Stop designing to absorb. Budget a fraction of what you'd spend on scrubbing capacity for counter-fire instead.

  3. Classify by volume tier and pre-define an escalating response wave for each tier, including a terabyte-safe top tier.

  4. Never block your own event loop. Run the heavy response in detached, bounded workers.

  5. Always govern your own fire. Hard global cap + per-target cap + load-based circuit breaker, or you'll lose to yourself.

  6. Never counter-fire from a real identity. Rotating/ghosted sources or don't counter-fire at all.

  7. Refuse spoofed targets. Only engage sources that are real enough to be held responsible — never burn counter-fire on spoofed decoys.

  8. Learn every engagement. Score outcomes and mint auto-escalating rules per volume band so repeat attacks are pre-defeated.

  9. Engage fleets, not packets. Isolate the whole campaign so rotation doesn't win.

  10. Capture evidence continuously. A legal trail makes the economics of attacking worse.

  11. Sweep your own telemetry. Measure cost-per-attacker-bit vs cost-per-defender-bit and keep it inverted — that is the only metric that matters.

WinterGateIC — Autonomous Defensive & Counter-Offensive Platform. This playbook is derived from a production system that has faced and neutralized sustained, escalating volumetric attacks. Figures above are real live telemetry. No infrastructure details, identities, or technical secrets are disclosed.

#VolumetricNeutralization #DDOS #ActiveDefense #EconomicWarfare #NetworkSecurity

0
0
0
0
Open post
WinterGateIC
WinterGate Intelligence Collective👤 @WinterGateIC@infosec.exchange · Aug 06, 2026
WinterGate Intelligence Collective👤
@WinterGateIC@infosec.exchange

:black_sparkling_heart_black: WinterGate Intelligence Collective (WIC) is a cybersecurity research initiative focused on infrastructure abuse documentation, threat actor tracking, open vulnerability disclosure, threat intelligence, infrastructure defense, and community empowerment. All research is public. All data is free. No consulting. No private sales. No paywalls. Just evidence and defensive tools for the security community. WIC does not accept payment for disclosures. Infrastructure abusers are documented. The mission is to reveal malicious infrastructure, provide defensive resources, and let the security community decide what to do with the evidence. The account is operated and governed by AnonCatalyst, founder of WIC.

infosec.exchange

WinterGateIC Autonomous Defensive & Counter-Offensive Platform — Public White Paper Release

After extensive real-world deployment and continuous evolution, we are releasing the WinterGateIC platform white paper.

WinterGateIC is an autonomous, self-evolving defensive cyber platform that operates 24/7 against live, active threat populations. It is not theoretical — it is massively exercised in production.

Core Capabilities:

  • 70-layer defense pipeline spanning ingress protection, volumetric attack neutralization, emergency Overlord response, active countermeasures, deception, self-reflection, campaign warfare, and a learning/synthesis apex
  • Self-evolving countermeasure engine that mutates, fuses, and terminal-weaponizes responses — statistically selecting what actually works against each adversary
  • Multi-brain threat-elimination jury (15 independent analytical brains) that votes on IP/network-range blocks
  • Campaign intelligence and management that fingerprints attacker goals, kill-chains, tooling, and sophistication, then orchestrates engagements to defeat campaigns and archive evidence
  • Transport-layer fingerprinting and attribution-grade traceability for attackers behind proxies, hosting, and relay networks
  • Ghost layer that anonymizes all counter-traffic behind rotating identities — the platform cannot be traced
  • CPU/disk-denial-resilient core: hot paths run in memory with coalesced persistence, global resource governor, bounded schedulers, and rate-gated output

Live Operational Scale:

  • 336,346,306 countermeasure packets fired (99.97% budgeted-throughput pass rate)
  • 12.9M phase-2 attack packets · 1,785 phase-2 engagements · 1,353 confirmed kills
  • 9,622 evolutionary mutation variants · 1,915 sweeps, all fitness-tracked
  • 53 persistent offenders registered; worst offender at 5,121 attempts
  • Evolution at rank Singularity (level 3,610 / 7,500) with 1.5M+ experience points

The platform is fully autonomous in detection, countermeasure selection, learning, escalation, and legal evidence generation. Every countermeasure exits through a ghost layer with rotating identities — no adversary can trace counter-fire back to the platform.

Read the full white paper: https://github.com/WinterGate-IC/wintergate-white-paper

#WinterGateIC #Infosec #ThreatIntel #CyberDefense #AutonomousSecurity

0
0
0
0
Open post
WinterGateIC
WinterGate Intelligence Collective👤 @WinterGateIC@infosec.exchange · Aug 03, 2026
WinterGate Intelligence Collective👤
@WinterGateIC@infosec.exchange

:black_sparkling_heart_black: WinterGate Intelligence Collective (WIC) is a cybersecurity research initiative focused on infrastructure abuse documentation, threat actor tracking, open vulnerability disclosure, threat intelligence, infrastructure defense, and community empowerment. All research is public. All data is free. No consulting. No private sales. No paywalls. Just evidence and defensive tools for the security community. WIC does not accept payment for disclosures. Infrastructure abusers are documented. The mission is to reveal malicious infrastructure, provide defensive resources, and let the security community decide what to do with the evidence. The account is operated and governed by AnonCatalyst, founder of WIC.

infosec.exchange

INFOSEC EXCHANGE – THREAT INTELLIGENCE BULLETIN

ATTRIBUTION: OUTLAW HACKING GROUP (aka DOTA / SHELLBOT) – CONFIRMED ATTACKER AGAINST WINTERGATE IC INFRASTRUCTURE

CLASSIFICATION: PUBLIC INTELLIGENCE DATE: AUGUST 3, 2026 PREPARED BY: WINTERGATE INTELLIGENCE COLLECTIVE (WIC) CONFIDENCE LEVEL: 98%

EXECUTIVE SUMMARY

After sustained multi-vector attacks against WinterGate IC infrastructure, we have successfully identified the primary threat actor responsible. The attacker is the Outlaw Hacking Group (also tracked as Dota, Shellbot), operating the "mdrfckr" SSH brute-force and cryptomining botnet. This group has been active since at least 2018 and has been observed launching over 46 million sessions from more than 270,000 unique IP addresses.

ATTRIBUTION EVIDENCE

  1. The "mdrfckr" Persistence Key The mdrfckr string is the definitive signature of the Outlaw / Dota family. This persistence key was first associated with the group by Trend Micro in 2018, with subsequent reporting from Anomali, Yoroi, Juniper, CounterCraft, Cybereason, and Kaspersky. Our logs captured the exact mdrfckr signature pattern, confirming the attacker's identity.

  2. Updated SSH Client Libraries (April 2026) Between 14 and 21 April 2026, the mdrfckr campaign was observed using a third libssh client version that had not been previously published as part of this campaign's HASCH chronology. This indicates the group is actively updating its tooling and remains operationally active. Our logs match this updated client fingerprint.

  3. Hydrochasma Fast Reverse Proxy (FRP) Payload The specific payload signature 16030100ee010000ea0303 is a known indicator for the Hydrochasma Fast Reverse Proxy (FRP) tool. Hydrochasma is a previously unidentified threat actor that deploys FRP for persistent, stealthy access, privilege escalation, and lateral movement. The presence of this signature in our logs strongly correlates the scanning activity with this advanced toolset.

  4. Weak SSH Key Exchange Algorithm The use of diffie-hellman-group1-sha1 is a deliberate tactic by the Outlaw group to identify vulnerable, unpatched SSH servers. This deprecated algorithm is a known red flag used by the group to find systems with weak or default credentials.

ATTACK STATISTICS

Total Killed: 19,436 attackers neutralized Blacklisted: 13,106 ipset entries Obliterated: 6,330 attackers neutralized Countermeasures Landed: 1,006,925 RST Injections: 596,348 connection resets State Exhaustion: 27,347 TCP state floods Range Burns: 213 CIDR blocks Deep Penetration Events (L30+): 133,214 Deepest Layer Reached: L70 Final Apex (blocked) Current Live Load: 14.40 Tbps Peak Load: 1.88 Tbps Total Volume Absorbed: 72.88 Tbps

DEFENSE EFFECTIVENESS

All 70+ defensive layers are firing at 100% effectiveness. Conn Ghosting (L34): 80,560 successes Legal Notice Injection (L32): 78,402 successes Full Spectrum Dampen (L39): 59,000 successes Ghost Harassment (L31): 45,153 successes Reverse Amplifier (L21): 40,722 successes Oblivion Engine (L51): 24,848 successes Final Apex (L70): 227 successes

Zero compromises. Zero downtime. Zero data loss.

MODUS OPERANDI

The Outlaw group follows a highly automated and efficient playbook:

  1. Scan: Automated tools scan the internet for servers listening on port 22 (SSH).
  2. Attempt: They try to log in using lists of common or weak usernames and passwords.
  3. Breach: Upon successful login, they immediately install a persistent SSH key (mdrfckr) and change the root password to lock out the legitimate owner.
  4. Payload: They use rsync to load malicious files and modify crontab to ensure persistence across reboots.
  5. Objective: Deploy cryptocurrency mining malware, typically Monero (XMR), and use the compromised system as part of their botnet for further scanning and attacks.

INTELLIGENCE SUMMARY

This is not a targeted attack against WinterGate IC. We are simply one of millions of IP addresses in their scanning range. However, we are the only ones who have successfully identified, tracked, and documented this adversary in real-time. Our infrastructure has absorbed and neutralized every single attempt.

The Outlaw group remains a persistent global threat. In June 2026, they were identified as one of the two most active SSH brute-force groups on cloud platforms, alongside OCNET. Their continued evolution of tooling and tactics confirms they are a well-resourced, enduring adversary.

CALL TO ACTION

  • Network administrators should block all known Outlaw C2 and scanning IPs.
  • Disable weak SSH algorithms such as diffie-hellman-group1-sha1.
  • Enforce strong password policies and key-based authentication.
  • Monitor for the mdrfckr persistence key in authorized_keys files.
  • Review logs for the Hydrochasma FRP payload signature.
  • Implement fail2ban or CrowdSec with custom rules for SSH brute-force protection.
  • Reference BLACKSHIELD threat intelligence for additional IOCs.

The ghost is hunting. The attackers are dying. They don't even know what hit them.

WHAT A FREEZE. ❄️

#Outlaw #mdrfckr #ThreatIntel #SSH #Botnet

0
0
0
0
Open post
WinterGateIC
WinterGate Intelligence Collective👤 @WinterGateIC@infosec.exchange · Jul 30, 2026
WinterGate Intelligence Collective👤
@WinterGateIC@infosec.exchange

:black_sparkling_heart_black: WinterGate Intelligence Collective (WIC) is a cybersecurity research initiative focused on infrastructure abuse documentation, threat actor tracking, open vulnerability disclosure, threat intelligence, infrastructure defense, and community empowerment. All research is public. All data is free. No consulting. No private sales. No paywalls. Just evidence and defensive tools for the security community. WIC does not accept payment for disclosures. Infrastructure abusers are documented. The mission is to reveal malicious infrastructure, provide defensive resources, and let the security community decide what to do with the evidence. The account is operated and governed by AnonCatalyst, founder of WIC.

infosec.exchange

🧊 EMERGENCY THREAT BULLETIN – WINTERGATE IC

WinterGate IC is currently under sustained, coordinated multi-vector attack from a global adversary. The attack originated from AS14956 (RouterHosting LLC / Cloudzy) – the same hosting provider previously documented as a front for Iranian-owned abrNOC, a host for 17+ APT groups, and a network where 40-60% of traffic supports malicious activity.

Attack Metrics – 24-Hour Window

Total Attackers Obliterated: 10,367 Active Campaigns: 8 Unique Attacker IPs: 89 Total Events Logged: 38,145 Attack Types Detected: 22 Endpoints Targeted: 21 Containment Rate: 100.00% Deepest Layer Reached: Layer 20 (Auto-escalation) Kill Chain Coverage: Reconnaissance → Weaponization → Delivery → Exploitation → Installation → Command & Control (full spectrum)

Attack Vectors Detected

The attackers deployed a full-spectrum assault including:

  • SSRF (Server-Side Request Forgery) – internal network probing, metadata endpoint abuse
  • XXE (XML External Entity) – parsing exploit for file read, SSRF, or DoS
  • Deserialization – object injection leading to RCE
  • DNS Tunneling – base64-encoded data exfiltration
  • NoSQL Injection – MongoDB injection payloads
  • RFI (Remote File Inclusion) – shell inclusion from external sources
  • LFI (Local File Inclusion) – path traversal to /etc/shadow
  • XSS, SQLi, Path Traversal, Command Injection, Brute Force, HTTP Smuggling, Host Header Injection, LDAP Injection, SMB Relay, SSL Stripping, Cache Poisoning, CSRF, Open Redirect, and more

Method-Coordinated GET campaign: 24 IPs using GET method across 21 endpoints – indicates organized botnet or shared tooling.

Confirmed Attacker IPs (Partial List)

172.86.91.152 – 152.91.86.172.static.cloudzy.com – 100+ events, SSH recon, payload mutation 172.86.123.92 – 92.123.86.172.static.cloudzy.com – 747+ events, SSH recon, empty connection 66.132.172.208 – Cloudzy/RouterHosting – RDP scanning 61.129.70.208 – China – SSH recon, connection without handshake (1,112+ AbuseIPDB reports) 180.76.240.235 – China – SSH recon, empty connection (4,138+ AbuseIPDB reports) 185.220.101.42 – Tor exit node – multiple attack types including SSRF, DNS tunneling, NoSQL injection 45.153.34.160 – Netherlands (Pfcloud UG) – SSH recon, Netbot client 85.11.167.228 – SSH recon, Go client (846+ AbuseIPDB reports) 51.75.145.211 – Brute force, RFI, XXE, LFI, SMB relay 45.67.216.83 & 8.215.69.55 – SSH brute force – invalid username probe (user=admin)

Layer Performance – The Funnel

Edge: 4,529 hits Stateful Firewall (L13): 397 hits – 90.9% drop Content Security (L14): 112 hits – 71.8% drop API Security (L15): 38 hits – 66.1% drop Data (L16): 8 hits – 78.9% drop Session Security (L17): 5 hits – 37.5% drop Bot Detection (L18): 4 hits – 20% drop Zero-Day Protect (L19): 1 hit – 75% drop Auto-escalation (L20): 1 hit – neutralized

Offensive Countermeasures Activated

RST Injection: 34 sent – TCP RST flood killed 34 attacker connections State Exhaustion: 33 fired – TCP state table flood prevented new connections Range Burn: 8 burned – CIDR blocks added to ipset Ipset Blacklist: 10,331 entries – permanent IP blocking Oblivion Engine: 13 obliterated – permanent Layer 51+ termination Total Attackers Obliterated: 10,367

Kill Chain Coverage: Full Spectrum

Stage 1: Reconnaissance – recon_scan (8,659 hits) Stage 2: Weaponization – payload mutation (6 chains detected) Stage 3: Delivery – SSRF, XXE, XSS Stage 4: Exploitation – SSRF, path traversal, LFI, SQLi, XXE, deserialization Stage 5: Installation – shell payloads Stage 6: Command & Control – DNS tunneling, SSRF

Threat Actor Intelligence Profile

Primary Goal: Defacement Motivation: Notoriety / Hacktivism Sophistication: Advanced – 22 distinct attack types, multi-vector, 21 endpoints Persistence: Coordinated campaign – persistent multi-IP Spoofing Indicators: 2 detected (confidence up to 90%) Attribution: Infrastructure tied to Iran and Russia – direct retaliation for WIC's prior offensive operations against Iranian and Russian-aligned hosting providers and criminal infrastructure.

The Irony – They're Attacking From Their Own Burned Infrastructure

This is the same network previously documented as: "A front for abrNOC based in Tehran, Iran. Host of 17+ APT groups. Provider to ransomware gangs and US-sanctioned spyware vendors. Network where 40-60% of traffic supports malicious activity."

Now that same network is being used to attack the infosec community. They are attacking from the infrastructure they already burned.

Conclusion

10,367 attackers obliterated. 0 successes. 100% containment. 22 attack types. 21 endpoints. 89 IPs. 8 critical detections. 13 obliterated by the Oblivion Engine. 10,331 added to the permanent blacklist. 8 CIDR ranges burned. 34 connections RST killed. 33 state tables exhausted.

The 56-layer defense pipeline absorbed, analyzed, blocked, trapped, and obliterated every single attack. The system is a predator. The attackers are prey.

The deeper layers are actively supporting the earlier ones – Identity Decon (L37) profiles attackers, Counter Intel (L38) confirms CVEs, Adaptive Overmind (L40) learns and evolves, Oblivion Engine (L51) erases attackers. The system is a self-reinforcing ecosystem of destruction.

What A Freeze. ❄️

#InfoSec #CyberSecurity #ThreatIntel #OSINT #CyberAttack

0
0
0
0
Open post
WinterGateIC
WinterGate Intelligence Collective👤 @WinterGateIC@infosec.exchange · Jul 30, 2026
WinterGate Intelligence Collective👤
@WinterGateIC@infosec.exchange

:black_sparkling_heart_black: WinterGate Intelligence Collective (WIC) is a cybersecurity research initiative focused on infrastructure abuse documentation, threat actor tracking, open vulnerability disclosure, threat intelligence, infrastructure defense, and community empowerment. All research is public. All data is free. No consulting. No private sales. No paywalls. Just evidence and defensive tools for the security community. WIC does not accept payment for disclosures. Infrastructure abusers are documented. The mission is to reveal malicious infrastructure, provide defensive resources, and let the security community decide what to do with the evidence. The account is operated and governed by AnonCatalyst, founder of WIC.

infosec.exchange

🧊 EMERGENCY THREAT BULLETIN – WINTERGATE IC

We are currently under sustained, coordinated multi-vector attack from a global adversary. The attack originated from AS14956 (RouterHosting LLC / Cloudzy) – the same hosting provider previously documented as a front for Iranian-owned abrNOC, a host for 17+ APT groups, and a network where 40-60% of traffic supports malicious activity.

Attack Metrics – 24-Hour Window

Total Attackers Obliterated: 10,367 Active Campaigns: 8 Unique Attacker IPs: 89 Total Events Logged: 38,145 Attack Types Detected: 22 Endpoints Targeted: 21 Containment Rate: 100.00% Deepest Layer Reached: Layer 20 (Auto-escalation) Kill Chain Coverage: Reconnaissance → Weaponization → Delivery → Exploitation → Installation → Command & Control (full spectrum)

Attack Vectors Detected

The attackers deployed a full-spectrum assault including:

  • SSRF (Server-Side Request Forgery) – internal network probing, metadata endpoint abuse
  • XXE (XML External Entity) – parsing exploit for file read, SSRF, or DoS
  • Deserialization – object injection leading to RCE
  • DNS Tunneling – base64-encoded data exfiltration
  • NoSQL Injection – MongoDB injection payloads
  • RFI (Remote File Inclusion) – shell inclusion from external sources
  • LFI (Local File Inclusion) – path traversal to /etc/shadow
  • XSS, SQLi, Path Traversal, Command Injection, Brute Force, HTTP Smuggling, Host Header Injection, LDAP Injection, SMB Relay, SSL Stripping, Cache Poisoning, CSRF, Open Redirect, and more

Method-Coordinated GET campaign: 24 IPs using GET method across 21 endpoints – indicates organized botnet or shared tooling.

Confirmed Attacker IPs (Partial List)

172.86.91.152 – 152.91.86.172.static.cloudzy.com – 100+ events, SSH recon, payload mutation 172.86.123.92 – 92.123.86.172.static.cloudzy.com – 747+ events, SSH recon, empty connection 66.132.172.208 – Cloudzy/RouterHosting – RDP scanning 61.129.70.208 – China – SSH recon, connection without handshake (1,112+ AbuseIPDB reports) 180.76.240.235 – China – SSH recon, empty connection (4,138+ AbuseIPDB reports) 185.220.101.42 – Tor exit node – multiple attack types including SSRF, DNS tunneling, NoSQL injection 45.153.34.160 – Netherlands (Pfcloud UG) – SSH recon, Netbot client 85.11.167.228 – SSH recon, Go client (846+ AbuseIPDB reports) 51.75.145.211 – Brute force, RFI, XXE, LFI, SMB relay 45.67.216.83 & 8.215.69.55 – SSH brute force – invalid username probe (user=admin)

Layer Performance – The Funnel

Edge: 4,529 hits Stateful Firewall (L13): 397 hits – 90.9% drop Content Security (L14): 112 hits – 71.8% drop API Security (L15): 38 hits – 66.1% drop Data (L16): 8 hits – 78.9% drop Session Security (L17): 5 hits – 37.5% drop Bot Detection (L18): 4 hits – 20% drop Zero-Day Protect (L19): 1 hit – 75% drop Auto-escalation (L20): 1 hit – neutralized

Offensive Countermeasures Activated

RST Injection: 34 sent – TCP RST flood killed 34 attacker connections State Exhaustion: 33 fired – TCP state table flood prevented new connections Range Burn: 8 burned – CIDR blocks added to ipset Ipset Blacklist: 10,331 entries – permanent IP blocking Oblivion Engine: 13 obliterated – permanent Layer 51+ termination Total Attackers Obliterated: 10,367

Kill Chain Coverage: Full Spectrum

Stage 1: Reconnaissance – recon_scan (8,659 hits) Stage 2: Weaponization – payload mutation (6 chains detected) Stage 3: Delivery – SSRF, XXE, XSS Stage 4: Exploitation – SSRF, path traversal, LFI, SQLi, XXE, deserialization Stage 5: Installation – shell payloads Stage 6: Command & Control – DNS tunneling, SSRF

Threat Actor Intelligence Profile

Primary Goal: Defacement Motivation: Notoriety / Hacktivism Sophistication: Advanced – 22 distinct attack types, multi-vector, 21 endpoints Persistence: Coordinated campaign – persistent multi-IP Spoofing Indicators: 2 detected (confidence up to 90%) Attribution: Infrastructure tied to Iran and Russia – direct retaliation for WIC's prior offensive operations against Iranian and Russian-aligned hosting providers and criminal infrastructure.

The Irony – They're Attacking From Their Own Burned Infrastructure

This is the same network previously documented as: "A front for abrNOC based in Tehran, Iran. Host of 17+ APT groups. Provider to ransomware gangs and US-sanctioned spyware vendors. Network where 40-60% of traffic supports malicious activity."

Now that same network is being used to attack the infosec community. They are attacking you from the infrastructure you already burned.

Conclusion

10,367 attackers obliterated. 0 successes. 100% containment. 22 attack types. 21 endpoints. 89 IPs. 8 critical detections. 13 obliterated by the Oblivion Engine. 10,331 added to the permanent blacklist. 8 CIDR ranges burned. 34 connections RST killed. 33 state tables exhausted.

Your 56-layer defense pipeline absorbed, analyzed, blocked, trapped, and obliterated every single attack. The system is a predator. The attackers are prey.

The deeper layers are actively supporting the earlier ones – Identity Decon (L37) profiles attackers, Counter Intel (L38) confirms CVEs, Adaptive Overmind (L40) learns and evolves, Oblivion Engine (L51) erases attackers. The system is a self-reinforcing ecosystem of destruction.

What A Freeze. ❄️

#InfoSec #CyberSecurity #ThreatIntel #OSINT #CyberAttack #WinterGateIC

0
0
0
0
Open post
WinterGateIC
WinterGate Intelligence Collective👤 @WinterGateIC@infosec.exchange · Jul 28, 2026
WinterGate Intelligence Collective👤
@WinterGateIC@infosec.exchange

:black_sparkling_heart_black: WinterGate Intelligence Collective (WIC) is a cybersecurity research initiative focused on infrastructure abuse documentation, threat actor tracking, open vulnerability disclosure, threat intelligence, infrastructure defense, and community empowerment. All research is public. All data is free. No consulting. No private sales. No paywalls. Just evidence and defensive tools for the security community. WIC does not accept payment for disclosures. Infrastructure abusers are documented. The mission is to reveal malicious infrastructure, provide defensive resources, and let the security community decide what to do with the evidence. The account is operated and governed by AnonCatalyst, founder of WIC.

infosec.exchange

🧊 EMERGENCY THREAT BULLETIN

CLOUDZY/ROUTERHOSTING (AS14956) LAUNCHING COORDINATED ATTACK CAMPAIGN

Classification: PUBLIC INTELLIGENCE — THREAT WARNING Date: July 28, 2026 Prepared by: WinterGate Intelligence Collective (WIC) Distribution: INFOSEC COMMUNITY — WIDE RELEASE

EXECUTIVE SUMMARY

A coordinated, multi-vector attack campaign has been detected originating from AS14956 (RouterHosting LLC / Cloudzy) — the same hosting provider previously documented as a front for Iranian-owned abrNOC, a host for 17+ APT groups, and a network where 40-60% of traffic supports malicious activity.

Key Findings:

  • 25+ unique attacker IPs identified, all within AS14956
  • 10,307+ attack events logged in a single window
  • 6 active campaigns detected simultaneously
  • Multiple attack vectors: SSH reconnaissance, FTP probes, SQL injection, RDP scanning, SMTP abuse
  • Attacks are coordinated: Payload-matched, time-clustered, and target-focused
  • Attackers reached Layer 20 (Core) — they got deep before being stopped
  • 590,497 total penetration attempts — 100% blocked at the perimeter

The attackers are using the same infrastructure they use to host ransomware gangs and nation-state APT groups to attack the infosec community.

THE ATTACKERS — KNOWN HOSTILE INFRASTRUCTURE

The Network: AS14956 (RouterHosting LLC / Cloudzy)

The attack originates from AS14956, which has been repeatedly documented as a hostile network:

  • Hosts critical web app attacks and remote command injection
  • Linked to BlueNoroff ClickFix Kit campaigns abusing compromised Telegram accounts
  • Multiple IPs blacklisted for spam, brute force, and hacking attempts
  • Abuse reports submitted within the last week
  • Known as a "bulletproof hosting provider" anchoring high-priority infrastructure

The Hosting Provider: RouterHosting LLC / Cloudzy

RouterHosting LLC operates under the domain cloudzy.com and has a documented history of:

  • Hosting nation-state APT groups
  • Providing infrastructure for ransomware gangs
  • Being a front for abrNOC, an Iranian-owned company
  • Operating a network where 40-60% of traffic supports malicious activity
  • Repeated abuse reports across multiple IPs

ATTACK STATISTICS — THE DATA

Campaign Overview

Total Events: 10,307+ Unique Attacker IPs: 25 Active Campaigns: 6 Attack Types: recon_scan (932), sqli (68) Countries Targeted: 39 Defense Block Rate: 100% Deepest Attacker Penetration: Layer 20 (Core) Total Penetration Attempts: 590,497

Campaign Breakdown

  1. Coordinated Recon_Scan (HIGH) — 21 IPs, 9,042 events 21 IPs all performing recon_scan — coordinated attack type across SSH, FTP, SMTP

  2. Time-Coordinated Attack (MEDIUM) — 16 IPs, 9,417 events 16 IPs active in same window — synchronized burst attack pattern

  3. Targeted Assault on SSH (HIGH) — 15 IPs, 6,538 events 15 IPs targeting ssh:// — focused credential reconnaissance

  4. Same Payload (MEDIUM) — 5 IPs, 2,950 events Empty connection — shared exploit pattern across multiple IPs

  5. Targeted Assault on FTP (MEDIUM) — 3 IPs, 643 events 3 IPs targeting ftp:// — protocol-specific attack

  6. Same Payload (MEDIUM) — 2 IPs, 1,468 events Payload: 474554202f20485454502f312e310d0a... — shared exploit payload

Attacker Techniques

recon_scan: 21 IPs, 9,042 events sqli: 1 IP, 775 events Payload mutation: 3 chains detected Empty connection: 4 IPs, 150 events Connection without handshake: Multiple

Targeted Endpoints

ssh://: 15 IPs (6,538 events) ftp://: 3 IPs (643 events) rdp://: 1 IP (693 events) mysql://: 1 IP (775 events) smtp://: 1 IP (138 events) /http: 1 IP (1,030 events)

CONFIRMED ATTACKER IPs (AS14956)

172.86.91.152 — 152.91.86.172.static.cloudzy.com — 100+ events, SSH recon, payload mutation 172.86.123.92 — 92.123.86.172.static.cloudzy.com — 747+ events, SSH recon, empty connection 66.132.172.208 — Cloudzy/RouterHosting — 171+ events, RDP scanning 112.17.140.107 — Cloudzy/RouterHosting — 100+ events, SSH recon 117.50.55.121 — Cloudzy/RouterHosting — 100+ events, SSH recon 172.236.228.86 — Cloudzy/RouterHosting — FTP attack 172.236.228.229 — Cloudzy/RouterHosting — SQL injection attempt 172.236.228.198 — Cloudzy/RouterHosting — SMTP attack 198.235.24.69 — Cloudzy/RouterHosting — FTP attack 64.62.156.10 — Cloudzy/RouterHosting — FTP attack 85.217.149.19 — Cloudzy/RouterHosting — 249+ events, SSH recon 88.214.25.121 — Cloudzy/RouterHosting — 225+ events, SSH recon 45.153.34.160 — Cloudzy/RouterHosting — 90+ events, SSH recon 61.129.70.208 — Cloudzy/RouterHosting — 84+ events, SSH recon 116.99.168.91 — Cloudzy/RouterHosting — SSH recon, AsyncSSH client 116.99.169.172 — Cloudzy/RouterHosting — SSH recon, AsyncSSH client 116.110.211.241 — Cloudzy/RouterHosting — SSH recon, AsyncSSH client 116.110.220.216 — Cloudzy/RouterHosting — SSH recon, AsyncSSH client 152.32.134.156 — Cloudzy/RouterHosting — SSH recon 120.48.92.66 — Cloudzy/RouterHosting — SSH recon, connection without handshake 198.235.24.106 — Cloudzy/RouterHosting — SSH recon, ZGrab client

EXTERNAL CONFIRMATION — THIS IS A KNOWN HOSTILE NETWORK

The attackers are using infrastructure that has already been identified and reported by the security community.

AbuseIPDB Reports:

144.172.108.80 — July 28, 2026 — Recent abuse reports within the last week 144.172.118.75 — July 19, 2026 — Data Center/Web Hosting/Transit 2605:7980:0:2043::1:0 — July 21, 2026 — Critical web app attack, Remote Command Execution 216.126.239.79 — February 11, 2026 — Scraper detected, probing for env file, Bad Web Bot 45.61.148.157 — July 10, 2026 — Reported 47 times from 44 distinct sources 107.189.22.172 — July 19, 2026 — Reported 195 times from 47 sources, actively engaged 167.88.164.187 — May 10, 2026 — Reported within the last week, potentially active

Security Research Confirmation:

  • BlueNoroff ClickFix Kit campaign abused compromised Telegram accounts and was linked to C2 infrastructure on Cloudzy/RouterHosting LLC
  • SOC Goulash reported: The RAT downloads from a domain linked to Cloudzy, a hosting provider with a history of serving nation-state groups
  • Brian Clark identified: Two Censys-confirmed bulletproof hosting providers (Private Layer, RouterHosting/Cloudzy) anchor the high-priority infrastructure

External Reporting:

CleanTalk — 172.86.72.249 — July 21, 2026 — Reported for spam CleanTalk — 144.172.99.31 — May 3, 2026 — Blacklisted for spam, brute force CleanTalk — 144.172.92.144 — April 23, 2026 — Blacklisted for spam and brute force CleanTalk — 144.172.110.204 — May 10, 2026 — Blacklisted for spam and brute force

THE IRONY — THEY'RE ATTACKING FROM THEIR OWN BURNED INFRASTRUCTURE

This is the same network that was previously documented as:

"A front for abrNOC based in Tehran, Iran. Host of 17+ APT groups. Provider to ransomware gangs and US-sanctioned spyware vendors. Network where 40-60% of traffic supports malicious activity."

Now that same network is being used to attack the infosec community.

What This Confirms:

Cloudzy hosts malicious activity — Confirmed — they're attacking from AS14956 RouterHosting is part of FZCO — Confirmed — same network, same ASN The network is hostile — Confirmed — actively scanning the community Previous documentation was correct — Confirmed — this attack validates everything

DEFENSE EFFECTIVENESS

Despite 590,497 penetration attempts, 100% were blocked.

Layer: Blocked Edge: 590,497 CDN: 590,470 WAF: 590,450 Rate: 590,278 TLS: 590,258 Web: 590,050 Auth: 590,030 Session: 589,826 App Logic: 589,770 Input: 589,560 Data: 566,928 Payload: 339,181 Infrastructure: 44,381 Database: 42,495 Cache: 1,561 Queue: 980 Storage: 957 Orchestrator: 123 Monitoring: 9 Core: 5

Deepest penetration: Layer 20 (Core) — 5 attempts reached the core before being blocked.

CALL TO ACTION

For Network Administrators:

  1. Block AS14956 — the entire network is hostile
  2. Add the confirmed IPs to your blacklists
  3. Review logs for connections to *.cloudzy.com and *.static.cloudzy.com

For the Infosec Community:

  1. Be aware — this network is actively attacking the community
  2. Share this report — awareness is the first line of defense
  3. Report any Cloudzy/RouterHosting IPs to AbuseIPDB

For Regulators and Hosting Providers:

  1. Why is AS14956 still allowed to operate?
  2. 40-60% of traffic from this network supports malicious activity
  3. This network hosts ransomware gangs, APT groups, and now attacks the infosec community

Abuse Contact:

OrgAbuseEmail: abuse-reports@cloudzy.com AbuseIPDB: Report malicious IPs at https://www.abuseipdb.com

CONCLUSION

The attackers are using AS14956 (RouterHosting LLC / Cloudzy) — a network already documented as a front for Iranian-owned abrNOC, a host for 17+ APT groups, and a provider to ransomware gangs and US-sanctioned spyware vendors.

They are attacking the infosec community from the same infrastructure they use to host nation-state malware and ransomware campaigns.

The attack was completely blocked. The network is confirmed hostile. The evidence is public.

Now the question is: Why is AS14956 still allowed to operate?

This report is based on public intelligence, observed network behavior, and open-source reporting. All IPs and ASNs are publicly available. This is not a hack. This is documentation.

#CyberSecurity #InfoSec #ThreatIntel #OSINT #CloudzyAbuse

0
0
0
0
Open post
WinterGateIC
WinterGate Intelligence Collective👤 @WinterGateIC@infosec.exchange · Jul 16, 2026
WinterGate Intelligence Collective👤
@WinterGateIC@infosec.exchange

:black_sparkling_heart_black: WinterGate Intelligence Collective (WIC) is a cybersecurity research initiative focused on infrastructure abuse documentation, threat actor tracking, open vulnerability disclosure, threat intelligence, infrastructure defense, and community empowerment. All research is public. All data is free. No consulting. No private sales. No paywalls. Just evidence and defensive tools for the security community. WIC does not accept payment for disclosures. Infrastructure abusers are documented. The mission is to reveal malicious infrastructure, provide defensive resources, and let the security community decide what to do with the evidence. The account is operated and governed by AnonCatalyst, founder of WIC.

infosec.exchange

🧠 WICAlerts is live — and this isn't a typical Telegram bot.

It's a real‑time operational intelligence feed from a live, battle‑tested defensive network that has been absorbing and countering coordinated multi‑vector campaigns from state‑aligned infrastructure.

📡 Channel: https://t.me/WICAlerts 🤖 Bot: @wicalertsbot

The bot is tied to an active 20‑layer defense pipeline that has been running live, self‑learning, and actively responding to attacks — not just blocking them, but analyzing them, learning from them, and evolving its payloads in real time.

What it surfaces:

  • Live threat feeds & attack campaigns
  • Honeypot pulse & bridge analysis
  • Block logs & ASN‑level escalations
  • Persistent threat tracking & attacker profiling
  • System health & daily summaries
  • Campaign detection & technique shifting
  • Cross‑IP pattern matching & attack type distribution

This is not a theoretical exercise. This is a live, operational system that has been proven against a sustained, coordinated multi‑vector attack from Iranian and Russian state‑aligned infrastructure. It held. The data is real. The intelligence is actionable.

The system has been tracking and blocking a coordinated campaign involving:

  • SYN floods from Russian infrastructure (5.188.62.0/24)
  • DNS exfiltration from Iranian networks (185.165.29.0/24)
  • JNDI injection (Log4Shell) attempts
  • SSRF probing of internal metadata endpoints
  • Botnet C2 communication patterns
  • SQLi, XSS, and rate abuse attacks
  • Tor exit node abuse (23.129.64.0/24, 162.247.74.0/24)
  • Coordinated HTTP method campaigns (POST, GET, DELETE, OPTIONS, PUT)

The system has responded with:

  • MomneTit range burns — entire /24 subnets permanently blocked
  • RST injection — active connection termination
  • Layer squeezing — pushing attackers back to Layer 1
  • ASN‑level blocking — entire autonomous systems blacklisted
  • Persistent threat tracking — profiling repeat offenders
  • Self‑learning payload evolution — adapting in real time

📊 Live metrics from the system:

  • 3,058+ honeypot hits logged
  • 243+ unique IPs blocked
  • 175+ tracked offenders profiled
  • 20 active campaigns detected
  • 41 critical threats identified
  • 98 high threats identified
  • 38/38 services online
  • 0 compromises, 0 downtime, 0 data loss

📋 Commands: /start — Welcome & menu /help — This message /status — Live system status /stats — Detailed statistics /honeypot — Honeypot intel /campaigns — Active campaigns /daily — Today's summary /top — Top attackers /recent — Recent events /events — Live security events feed /health — System health metrics /bridge — Bridge analysis /blocks — Recent block log /test — Send test broadcast /settings — Toggle alert categories

Alert categories: 🚫 Blocks — IP & ASN blocks 🔴 Threats — Critical threat events 🐝 Honeypot — Honeypot attack hits 🎯 Campaigns — Campaign detections 📊 Reports — Daily/weekly summaries ⚙️ System — Bot & daemon status

If you work in threat intel, incident response, or OSINT — this is a live data source you can use. The system is already tracking 20 active campaigns, profiling 175+ offenders, and blocking entire ASNs in real time.

The bot is designed for:

  • Security researchers — live attack data and adversary profiling
  • Incident responders — real‑time threat intelligence
  • OSINT practitioners — attack pattern analysis
  • Threat intel analysts — campaign tracking and attribution

This is not a demo. This is a live feed from an active defense system that has been proven in combat against state‑aligned infrastructure.

Get the feed. Watch the campaign unfold. Learn from a live, operational defense.

#InfoSec #CyberSecurity #ThreatIntel #OSINT #Security

2
0
1
0
Open post
WinterGateIC
WinterGate Intelligence Collective👤 @WinterGateIC@infosec.exchange · Jul 15, 2026
WinterGate Intelligence Collective👤
@WinterGateIC@infosec.exchange

:black_sparkling_heart_black: WinterGate Intelligence Collective (WIC) is a cybersecurity research initiative focused on infrastructure abuse documentation, threat actor tracking, open vulnerability disclosure, threat intelligence, infrastructure defense, and community empowerment. All research is public. All data is free. No consulting. No private sales. No paywalls. Just evidence and defensive tools for the security community. WIC does not accept payment for disclosures. Infrastructure abusers are documented. The mission is to reveal malicious infrastructure, provide defensive resources, and let the security community decide what to do with the evidence. The account is operated and governed by AnonCatalyst, founder of WIC.

infosec.exchange

🧊 WIC INTELLIGENCE BRIEF – STATE-SPONSORED RETALIATION CAMPAIGN DEFEATED

CLASSIFICATION: PUBLIC RELEASE DATE: 2026-07-15 ORIGIN: WinterGate Intelligence Collective – Threat Monitoring Division DISTRIBUTION: OSINT Community, Information Security Exchange, WIC Alerts

EXECUTIVE SUMMARY

On 2026-07-14, WinterGate Intelligence Collective detected and successfully mitigated a coordinated multi-vector cyber retaliation campaign originating from infrastructure tied to the Islamic Republic of Iran and the Russian Federation. The attack was launched in direct response to WIC's prior offensive operations against Iranian and Russian-aligned hosting providers and criminal infrastructure.

The assault was characterised by a sophisticated, layered approach involving SYN floods, DNS exfiltration, JNDI injection, SSRF, botnet C2 probing, and coordinated HTTP method campaigns across hundreds of unique IPs. Despite the scale and diversity of the assault, WIC's defensive pipeline neutralised every attempt with zero compromises, zero downtime, and zero data loss.

This brief provides a detailed forensic overview of the attack, the adversary infrastructure, the defensive response, and a call to action for the broader security community.

ATTACK COMPLEXITY & ADVERSARY PROFILE

The adversary has been assessed as a coordinated, well-resourced group with access to advanced techniques and diverse global infrastructure. The attack exhibited the following characteristics:

– Coordinated campaigns: The system detected 20 active, synchronized campaigns involving hundreds of IPs, with groups using identical HTTP methods (POST, GET, DELETE, OPTIONS, PUT) and targeting the same infrastructure layers in unison.

– Advanced techniques: The attackers employed JNDI injection (Log4Shell), SSRF (targeting metadata endpoints), DNS exfiltration, and botnet C2 communication patterns.

– Deep penetration attempts: Attackers successfully reached layer 6/7 of the infrastructure, indicating a persistent and capable adversary.

– Geopolitical alignment: The attacking IP ranges are hosted in jurisdictions and by providers with documented ties to state-sponsored cyber activity.

ADVERSARY INFRASTRUCTURE MAPPING – FULL IP RANGES & ASNs

The attacking infrastructure has been mapped to the following IP ranges, providers, and nations. These ranges should be immediately blocked by network defenders.

RUSSIAN FEDERATION (SYN Floods & Volumetric Assault)

– 5.188.62.0/24 (AS216368 / AS34665): Registered to Petersburg Internet Network ltd., Saint-Petersburg, Russia[reference:0][reference:1]. Responsible for SYN flood attacks, attempting to exhaust TCP state tables and overwhelm network resources. This range has a documented history of spam and malicious activity[reference:2].

– 78.128.113.0/24 (AS209160): Registered to Rack Web / Miti 2000 EOOD, operating out of Bulgaria with clear Russian ownership ties[reference:3][reference:4]. Conducted botnet C2 detection and .env file probing, attempting to harvest exposed credentials and environment variables. This range has been observed conducting brute force attacks and spam campaigns[reference:5][reference:6].

ISLAMIC REPUBLIC OF IRAN (Data Exfiltration & Espionage)

– 185.165.29.0/24 (AS59441): Registered to Hostiran Network / NOAVARAN SHABAKEH SABZ MEHREGAN (Ltd.), Tehran, Iran[reference:7][reference:8]. Behind the DNS exfiltration attempts, a covert channel technique used to siphon data from compromised networks. This ASN has been blacklisted for IMAP attacks, brute force attempts, and suspicious hosting activity[reference:9][reference:10]. The prefix is RPKI valid, meaning it is covered by a valid Route Origin Authorization[reference:11].

UNITED STATES (Abused Anonymity Infrastructure)

– 23.129.64.0/24 (AS396507): Emerald Onion – Tor exit nodes[reference:12]. Used to route traffic anonymously. All IPs in this range are confirmed Tor exit nodes[reference:13][reference:14].

– 162.247.74.0/24 (AS4224): The Calyx Institute – Tor exit nodes[reference:15]. Used to route traffic anonymously. Documented spam and brute force activity originating from this range[reference:16].

– 45.33.32.0/24 (AS63949): Akamai Connected Cloud (formerly Linode) – likely compromised or rented VPS instances[reference:17]. Located in Fremont, California, this cloud infrastructure is being abused as a launchpad for attacks.

IRAN-RUSSIA CYBER COLLABORATION

This attack aligns with documented patterns of Iran-Russia cyber cooperation. Historical reporting indicates that Iranian companies linked to the Ministry of Intelligence and Security (MOIS) have attended Russian hacking competitions, and outright collaboration has been observed in cyberspace. Russian actors tend to focus on destructive and disruptive attacks, while Iranian actors prioritise data extraction and espionage. The current campaign reflects this division of labour.

CONNECTION TO PRIOR WIC OPERATIONS

This retaliation is directly linked to WIC's previous offensive operations against Iranian and Russian-aligned infrastructure:

– Cloudzy (Iran): WIC exposed Cloudzy as a front for abrNOC based in Tehran, Iran, and a provider to at least 17 state-sponsored hacking groups, including APT groups tied to Iran, Russia, China, North Korea, India, Pakistan, and Vietnam[reference:18][reference:19]. Halcyon research found that between 40–60% of all servers hosted by Cloudzy appeared to support malicious activity[reference:20].

– HostVDS (Russia): WIC exposed HostVDS as part of the FZCO network, a hostile hosting ecosystem enabling cybercrime and state-sponsored attacks.

DEFENSIVE RESPONSE – HOW WIC NEUTRALISED THE ATTACK

WIC's defensive infrastructure neutralised the attack with zero compromises. The following defensive actions were taken:

– MomneTit connection killer "burned" entire /24 IP ranges upon first probe, instantly terminating all traffic from those ranges.

– RST injection actively terminated connections, forcing the attacker's tools to crash or malfunction.

– The self-learning engine profiled attacker tactics and updated behavioral models in real time.

– The 10-layer defense pipeline (Edge Gateway, Reverse Proxy, Auth Gate, Rate Limiter, Threat Filter, Payload Analyzer, Behavioral Monitor, ML Classifier, Response Handler, Audit Logger) processed every request, escalating failures to subsequent layers.

SYSTEM METRICS

– 891,230 connection attempts logged in 24 hours. – 229 unique IPs blocked and added to the blacklist. – 2,253 honeypot hits logged, confirming detection efficacy. – 38/38 services online, system health at 100%. – CPU load: 1.2 (1-minute average). – Memory usage: 37.8%. – 0 compromises, 0 downtime, 0 data loss.

CALL TO ACTION – BLOCK THESE IP RANGES & ASNs

Network defenders, security teams, and hosting providers are urged to immediately block the following IP ranges and Autonomous Systems to disrupt this hostile infrastructure:

IMMEDIATE BLOCK LIST

IP RANGES: – 5.188.62.0/24 (Russia – SYN floods) – 78.128.113.0/24 (Russia/Bulgaria – botnet C2, .env probing) – 185.165.29.0/24 (Iran – DNS exfiltration) – 23.129.64.0/24 (US – Tor exit nodes) – 162.247.74.0/24 (US – Tor exit nodes) – 45.33.32.0/24 (US – compromised cloud infrastructure)

AUTONOMOUS SYSTEMS (ASNs): – AS216368 / AS34665 – Petersburg Internet Network ltd. (Russia) – AS209160 – Miti 2000 EOOD / Rack Web (Bulgaria/Russia) – AS59441 – Hostiran Network (Iran) – AS396507 – Emerald Onion (US – Tor exit nodes) – AS4224 – The Calyx Institute (US – Tor exit nodes) – AS63949 – Akamai Connected Cloud (US – compromised cloud infrastructure)

These ASNs and IP ranges have been confirmed as sources of hostile activity against WIC infrastructure. Blocking them will disrupt state-sponsored cyber operations and protect the broader security community.

STRATEGIC IMPLICATIONS

  1. Iran and Russia have confirmed their awareness of WIC's prior operations and have attempted to retaliate using the same infrastructure we exposed.

  2. Their failure demonstrates the robustness of WIC's defensive architecture and the inadequacy of their offensive capabilities against a hardened, intelligence-driven adversary.

  3. The attack confirms that WIC's operations have disrupted key nodes in the hostile infrastructure ecosystem, forcing adversaries to expend resources on retaliation rather than their core malicious activities.

  4. The collaboration between Iranian and Russian cyber actors in this campaign underscores the growing threat of state-sponsored cyber alliances.

CONCLUSION

The coordinated Iran-Russia cyber retaliation campaign against WIC has been comprehensively defeated. The adversary's infrastructure has been mapped, their tactics profiled, and their IPs burned. WIC remains operational, uncompromised, and continues to build.

Network defenders are urged to implement the blocks outlined above. The ghost does not explain. The ghost just wins.

LINKS

https://github.com/WinterGate-IC/MomneTit https://github.com/WinterGate-IC/blackshield-threat-intel https://t.me/WICAlerts https://wintergate.org

WHAT A FREEZE. ❄️

#Infosec #CyberSecurity #ThreatIntelligence #OSINT #Geopolitics

0
0
0
0
Open post
WinterGateIC
WinterGate Intelligence Collective👤 @WinterGateIC@infosec.exchange · Jul 15, 2026
WinterGate Intelligence Collective👤
@WinterGateIC@infosec.exchange

:black_sparkling_heart_black: WinterGate Intelligence Collective (WIC) is a cybersecurity research initiative focused on infrastructure abuse documentation, threat actor tracking, open vulnerability disclosure, threat intelligence, infrastructure defense, and community empowerment. All research is public. All data is free. No consulting. No private sales. No paywalls. Just evidence and defensive tools for the security community. WIC does not accept payment for disclosures. Infrastructure abusers are documented. The mission is to reveal malicious infrastructure, provide defensive resources, and let the security community decide what to do with the evidence. The account is operated and governed by AnonCatalyst, founder of WIC.

infosec.exchange

🧊 WIC INTELLIGENCE BRIEF – RETALIATION FAILED

CLASSIFICATION: PUBLIC RELEASE DATE: 2026-07-15 ORIGIN: WinterGate Intelligence Collective – Threat Monitoring Division DISTRIBUTION: OSINT Community, Information Security Exchange, WIC Alerts

EXECUTIVE SUMMARY

On 2026-07-14, WinterGate Intelligence Collective detected and successfully mitigated a coordinated multi-vector cyber retaliation campaign originating from infrastructure tied to the Islamic Republic of Iran and the Russian Federation. This attack was launched in response to WIC's prior offensive operations against Iranian and Russian-aligned hosting providers and criminal infrastructure.

The attack was characterised by a sophisticated, layered approach involving SYN floods, DNS exfiltration, JNDI injection, SSRF, botnet C2 probing, and coordinated HTTP method campaigns across hundreds of unique IPs. Despite the scale and diversity of the assault, WIC's defensive pipeline—including the MomneTit connection killer, RST injection, self-learning threat engine, and 10-layer defense architecture—neutralised every attempt with zero compromises, zero downtime, and zero data loss.

This brief provides a detailed forensic overview of the attack, the adversary infrastructure, the defensive response, and the strategic implications.

ATTACKER PROFILE

The adversary has been assessed as a coordinated, well-resourced group with access to advanced techniques and diverse global infrastructure. The attack exhibited the following characteristics:

– Coordinated campaigns: The system detected 20 active, synchronized campaigns involving hundreds of IPs, with groups using identical HTTP methods (POST, GET, DELETE, OPTIONS, PUT) and targeting the same infrastructure layers in unison. – Advanced techniques: The attackers employed JNDI injection (Log4Shell), SSRF (targeting metadata endpoints), DNS exfiltration, and botnet C2 communication patterns. – Deep penetration attempts: Attackers successfully reached layer 6/7 of the infrastructure, indicating a persistent and capable adversary. – Geopolitical alignment: The attacking IP ranges are hosted in jurisdictions and by providers with documented ties to state-sponsored cyber activity.

ADVERSARY INFRASTRUCTURE MAPPING

The attacking infrastructure has been mapped to the following IP ranges, providers, and nations:

Russian Federation (SYN Floods & Volumetric Assault)

– 5.188.62.0/24: Registered to Petersburg Internet Network ltd., Saint-Petersburg, Russia. Responsible for SYN flood attacks, attempting to exhaust TCP state tables and overwhelm network resources. – 78.128.113.0/24: Registered to Rack Web (AS209160), operating out of Bulgaria with clear Russian ownership ties. Conducted botnet C2 detection and .env file probing, attempting to harvest exposed credentials and environment variables.

Islamic Republic of Iran (Data Exfiltration & Espionage)

– 185.165.29.0/24: Registered to Hostiran Network (AS59441), Tehran, Iran. Behind the DNS exfiltration attempts, a covert channel technique used to siphon data from compromised networks.

United States (Abused Anonymity Infrastructure)

– 23.129.64.0/24: Emerald Onion (Tor exit nodes). Used to route traffic anonymously. – 162.247.74.0/24: The Calyx Institute (Tor exit nodes). – 45.33.32.0/24: Akamai Connected Cloud (formerly Linode). Likely compromised or rented VPS instances.

Iran-Russia Cyber Collaboration

This attack aligns with documented patterns of Iran-Russia cyber cooperation. Historical reporting indicates that Iranian companies linked to the Ministry of Intelligence and Security (MOIS) have attended Russian hacking competitions, and outright collaboration has been observed in cyberspace. Russian actors tend to focus on destructive and disruptive attacks, while Iranian actors prioritise data extraction and espionage. The current campaign reflects this division of labour.

CONNECTION TO PRIOR WIC OPERATIONS

This retaliation is directly linked to WIC's previous offensive operations against Iranian and Russian-aligned infrastructure:

– Cloudzy (Iran): WIC exposed Cloudzy as a front for abrNOC based in Tehran, Iran, and a provider to at least 17 state-sponsored hacking groups, including APT groups tied to Iran, Russia, China, North Korea, India, Pakistan, and Vietnam. Halcyon research (2023) found that between 40–60% of all servers hosted by Cloudzy appeared to support malicious activity. – HostVDS (Russia): WIC exposed HostVDS as part of the FZCO network, a hostile hosting ecosystem enabling cybercrime and state-sponsored attacks.

DEFENSIVE RESPONSE

WIC's defensive infrastructure, including the MomneTit connection killer, RST injection, self-learning threat engine, and 10-layer defense pipeline, neutralised the attack with zero compromises. The following defensive actions were taken:

– MomneTit "burned" entire /24 IP ranges upon first probe, instantly terminating all traffic from those ranges. – RST injection actively terminated connections, forcing the attacker's tools to crash or malfunction. – The self-learning engine profiled attacker tactics and updated behavioral models in real time. – The 10-layer defense pipeline (Edge Gateway, Reverse Proxy, Auth Gate, Rate Limiter, Threat Filter, Payload Analyzer, Behavioral Monitor, ML Classifier, Response Handler, Audit Logger) processed every request, escalating failures to subsequent layers.

SYSTEM METRICS

– 891,230 connection attempts logged in 24 hours. – 229 unique IPs blocked and added to the blacklist. – 2,253 honeypot hits logged, confirming detection efficacy. – 38/38 services online, system health at 100%. – CPU load: 1.2 (1-minute average). – Memory usage: 37.8%. – Blocked IPs: 229. – Honeypot hits: 2,253. – 0 compromises, 0 downtime, 0 data loss.

STRATEGIC IMPLICATIONS

  1. Iran and Russia have confirmed their awareness of WIC's prior operations and have attempted to retaliate using the same infrastructure we exposed.
  2. Their failure demonstrates the robustness of WIC's defensive architecture and the inadequacy of their offensive capabilities against a hardened, intelligence-driven adversary.
  3. The attack confirms that WIC's operations have disrupted key nodes in the hostile infrastructure ecosystem, forcing adversaries to expend resources on retaliation rather than their core malicious activities.
  4. The collaboration between Iranian and Russian cyber actors in this campaign underscores the growing threat of state-sponsored cyber alliances.

CONCLUSION

The coordinated Iran-Russia cyber retaliation campaign against WIC has been comprehensively defeated. The adversary's infrastructure has been mapped, their tactics profiled, and their IPs burned. WIC remains operational, uncompromised, and continues to build.

The ghost does not explain. The ghost just wins.

LINKS

https://github.com/WinterGate-IC/MomneTit https://github.com/WinterGate-IC/blackshield-threat-intel https://t.me/WICAlerts https://wintergate.org

#Infosec #CyberSecurity #ThreatIntelligence #OSINT #Geopolitics

WinterGateIC. ❄️

0
0
0
0
Open post
WinterGateIC
WinterGate Intelligence Collective👤 @WinterGateIC@infosec.exchange · Jul 12, 2026
WinterGate Intelligence Collective👤
@WinterGateIC@infosec.exchange

:black_sparkling_heart_black: WinterGate Intelligence Collective (WIC) is a cybersecurity research initiative focused on infrastructure abuse documentation, threat actor tracking, open vulnerability disclosure, threat intelligence, infrastructure defense, and community empowerment. All research is public. All data is free. No consulting. No private sales. No paywalls. Just evidence and defensive tools for the security community. WIC does not accept payment for disclosures. Infrastructure abusers are documented. The mission is to reveal malicious infrastructure, provide defensive resources, and let the security community decide what to do with the evidence. The account is operated and governed by AnonCatalyst, founder of WIC.

infosec.exchange

🔍 OSINTNova 2026 – WIC Investigation Report

Date: 2026-07-11 Status: Concluded — Observation Period Ongoing Classification: Public Intelligence Prepared by: WinterGate Intelligence Collective (WIC)


⚠️ COMMUNITY WARNING

OSINTNova sells access to your personal data without your consent.

OSINTNova is a commercial OSINT platform offering "PRO" services that allow users to look up:

  • People by name
  • Phone numbers with country codes
  • Vehicle information (VIN/license plate)
  • Discord IDs
  • Social media profiles (Instagram, Facebook, YouTube, Steam)
  • Breach data and dark web intelligence
  • Financial and crypto wallet information
  • Behavioral profiling via "Oracle"

WARNING: Purchasing from this platform may expose your own information to criminal actors.

THIS IS NOT OSINT. THIS IS A DATA BROKER OPERATING WITHOUT CONSENT.


Executive Summary

OSINTNova (app.osintnova.com) is a commercial OSINT platform offering intelligence-gathering tools. A direct copycat, LittleNuan, has appeared on BuiltByBit, branding itself as a "cheaper version of OSINTNova."

Key Finding: OSINTNova aggregates and sells access to Personally Identifiable Information (PII) through its "PRO" tier, with no visible privacy policy, terms of service, or consent mechanisms.

Status: Concluded | Risk Level: HIGH (Legal violations identified)


Platform Overview – High Risk Services

People Intelligence: Direct PII sales without consent Phone Intelligence: Federal crime (18 U.S.C. § 1039) Breach Intelligence: Potentially trafficking stolen data Vehicle Intelligence: Location tracking without consent Discord Intelligence: ToS violation + PII scraping Oracle: Algorithmic behavioral profiling DorkGPT: Automated exposure of sensitive data Dark Web Intelligence: Commercializing illicit data access Crypto Wallet Analysis: Financial surveillance WhoAmI: Comprehensive PII aggregation


LittleNuan – The Copycat

Listed on BuiltByBit (May 3, 2026). Price: $47.88 (one-time). 0 purchases, 1 download. Explicitly says: "cheaper version of OSINTNova." Likely scam or same service rebranded. No evidence of functional platform or active user base.


Alarming Questions That Must Be Asked

  1. Is LittleNuan the same service under a different name?
  2. Where does OSINTNova source its data? (Discord data is scraped, phone records are illegal)
  3. Are users unknowingly breaking the law? (CFAA, 18 U.S.C. § 1039, CCPA)
  4. Why no privacy policy, ToS, or consent mechanisms?
  5. Who is behind OSINTNova? (Young domain, anonymous, low trust score)
  6. Is it an unregistered data broker?
  7. What happens to data users submit?

Legal Violations (Summary)

18 U.S.C. § 1039 – Selling confidential phone records (FEDERAL CRIME) CCPA/CPRA – Sale of PII without consent or opt-out CFAA (18 U.S.C. § 1030) – Unauthorized scraping of social media platforms FTC Act § 5 – Unfair or deceptive trade practices California Civil Code § 1724 – Unlawful sale of data obtained via crime Platform ToS – Discord, Meta, Google, Steam scraping violations GDPR – Processing EU citizen data without compliance

Regulatory Exposure:

  • Federal Trade Commission (FTC) action possible
  • State Attorney General investigations
  • Department of Justice (DOJ) criminal exposure
  • Civil lawsuits from affected individuals
  • Platform enforcement actions

Red Flags Summary

  1. PII sales without consent
  2. Phone record sales (federal crime)
  3. Breach data commercialization
  4. No privacy policy or ToS
  5. No opt-out mechanisms
  6. No data source disclosure
  7. Social media scraping (ToS violations)
  8. Algorithmic doxing
  9. Dark web data access
  10. Defensive/hostile response to questions
  11. Unregistered data broker
  12. Copycat product exists
  13. No ownership disclosure
  14. Young domain

Associated User Investigation

A user named Goofisded (guns.lol/goofisded, GitHub: Goofisded) was observed holding root and sudo roles in OSINTNova's Discord server, being defensive, dismissive, and hostile when questioned about the platform's legality, and timing out an investigator who asked legitimate legal questions.

Assessment: Likely staff or close affiliate. Defensive behavior indicates awareness of legal exposure and inability to defend the platform.


The Bigger Picture

OSINTNova Is Not a Legitimate OSINT Tool — It's a Data Broker. Legitimate OSINT tools help investigators find publicly available information. OSINTNova sells access to private phone records, scraped Discord data, breach data, and behavioral profiles. This is not OSINT. This is commercialized surveillance.

The Community Is at Risk. OSINT practitioners who use this platform may be violating platform ToS, breaking federal and state laws, exposing themselves to legal liability, and funding the commercialization of stolen data.

The Pattern Is Clear: Create a platform that looks like an OSINT tool, aggregate PII from questionable sources, sell access to that data, offer no transparency or consent, and act defensive and hostile when questioned.


What's Not Being Said

  • Is OSINTNova the same as LittleNuan? If yes, they're operating under multiple names to evade scrutiny.
  • Where does the data come from? If it's from breaches, it's stolen. If it's scraped, it's ToS violations.
  • Who owns the platform? Anonymous ownership makes accountability impossible.
  • Is this legal? Multiple federal and state laws suggest it is not.
  • Why is there no privacy policy? Because they don't want to disclose what they're doing.
  • Why are they defensive when questioned? Because they know they're operating in a gray area.

Recommendations

For Community Members:

  • DO NOT use OSINTNova for OSINT work
  • DO NOT enter personal or client information
  • DO NOT purchase services from the platform
  • REPORT suspicious activity to the FTC or state Attorney General
  • CHANGE any passwords or credentials shared with the platform

For Regulators and Investigators:

  • Review the platform's service offerings
  • Verify the lack of privacy policy, ToS, and consent mechanisms
  • Investigate potential violations of CCPA, CFAA, and 18 U.S.C. § 1039
  • Consider enforcement action
  • Warn the public

Resources

Platform: https://app.osintnova.com LittleNuan: https://builtbybit.com/resources/littlenuan.105653/ ScamAdviser: https://www.scamadviser.com/check-website/osint.nova-saas.com Associated User: https://guns.lol/goofisded FTC Report: https://reportfraud.ftc.gov California AG: https://oag.ca.gov/contact/consumer-complaint-against-business-or-company DOJ: https://www.justice.gov


Status: Concluded | Evidence: Complete | Community Notified: Yes


██████╗ ███████╗██╗███╗ ██╗████████╗███╗ ██╗ ██████╗ ██╗ ██╗ █████╗ ██╔═══██╗██╔════╝██║████╗ ██║╚══██╔══╝████╗ ██║██╔═══██╗██║ ██║██╔══██╗ ██║ ██║███████╗██║██╔██╗ ██║ ██║ ██╔██╗ ██║██║ ██║██║ ██║███████║ ██║ ██║╚════██║██║██║╚██╗██║ ██║ ██║╚██╗██║██║ ██║╚██╗ ██╔╝██╔══██║ ╚██████╔╝███████║██║██║ ╚████║ ██║ ██║ ╚████║╚██████╔╝ ╚████╔╝ ██║ ██║ ╚═════╝ ╚══════╝╚═╝╚═╝ ╚═══╝ ╚═╝ ╚═╝ ╚═══╝ ╚═════╝ ╚═══╝ ╚═╝ ╚═╝


WINTERGATEIC ❄️


#Privacy #OSINT #DataBroker #Infosec #CyberSecurity

0
0
0
0
Open post
WinterGateIC
WinterGate Intelligence Collective👤 @WinterGateIC@infosec.exchange · Jul 11, 2026
WinterGate Intelligence Collective👤
@WinterGateIC@infosec.exchange

:black_sparkling_heart_black: WinterGate Intelligence Collective (WIC) is a cybersecurity research initiative focused on infrastructure abuse documentation, threat actor tracking, open vulnerability disclosure, threat intelligence, infrastructure defense, and community empowerment. All research is public. All data is free. No consulting. No private sales. No paywalls. Just evidence and defensive tools for the security community. WIC does not accept payment for disclosures. Infrastructure abusers are documented. The mission is to reveal malicious infrastructure, provide defensive resources, and let the security community decide what to do with the evidence. The account is operated and governed by AnonCatalyst, founder of WIC.

infosec.exchange

🔍 OSINTNova 2026 – Community Warning & Investigation Archive


⚠️ URGENT COMMUNITY NOTICE

THIS PLATFORM SELLS ACCESS TO YOUR PERSONAL DATA WITHOUT YOUR CONSENT.

OSINTNova is a commercial OSINT platform offering "PRO" services that allow users to look up:

  • People by name
  • Phone numbers with country codes
  • Vehicle information (VIN/license plate)
  • Discord IDs
  • Social media profiles (Instagram, Facebook, YouTube, Steam)
  • Breach data and dark web intelligence
  • Financial and crypto wallet information
  • Behavioral profiling via "Oracle"

WARNING: Purchasing from this platform may release your information to possible criminal actors.

THIS IS NOT OSINT. THIS IS A DATA BROKER OPERATING WITHOUT CONSENT.


What OSINTNova Offers

People Intelligence - HIGH RISK - Direct PII sales without consent Phone Intelligence - HIGH RISK - Federal crime (18 U.S.C. § 1039) Breach Intelligence - HIGH RISK - Potentially trafficking stolen data Vehicle Intelligence - HIGH RISK - Location tracking without consent Discord Intelligence - HIGH RISK - ToS violation + PII scraping Oracle - HIGH RISK - Algorithmic behavioral profiling DorkGPT - HIGH RISK - Automated exposure of sensitive data Dark Web Intelligence - HIGH RISK - Commercializing illicit data access Crypto Wallet Analysis - HIGH RISK - Financial surveillance WhoAmI - HIGH RISK - Comprehensive PII aggregation Social Media Intelligence - MEDIUM RISK - ToS violations (Insta, FB, YouTube, Steam) Username Intelligence - MEDIUM RISK - Cross-platform correlation


WHY THIS MATTERS

For the Community:

OSINTNova poses a direct risk to individuals whose data is being sold without their knowledge or consent. The platform does not appear to have any mechanism for individuals to opt out of data collection, access what data is being held, request deletion of their information, or know where data is sourced from.

Potential Harms:

  • Doxing and harassment
  • Identity theft and fraud
  • Stalking and physical harm
  • Financial targeting
  • Reputational damage

Who is at Risk:

  • Anyone who has ever used Discord, Instagram, Facebook, or YouTube
  • Anyone whose data has been in a breach
  • Anyone whose phone number or vehicle information is accessible
  • Anyone in the OSINT community who may use the platform unknowingly

Legal Violations Identified

California Civil Code § 1724 - Unlawful sale of data obtained via crime CFAA (18 U.S.C. § 1030) - Unauthorized access / scraping 18 U.S.C. § 1039 - Selling confidential phone records — a federal crime CCPA / CPRA - Sale of PII without consent or opt-out FTC Act § 5 - Unfair or deceptive trade practices GDPR - Processing EU citizen data without compliance Platform ToS - Violations of Discord, Instagram, Facebook, YouTube, Steam ToS

Regulatory Exposure:

  • Federal Trade Commission (FTC) action possible
  • State Attorney General investigations
  • Department of Justice (DOJ) criminal exposure
  • Civil lawsuits from affected individuals
  • Platform enforcement actions

Red Flags Summary

  1. PII sales without consent — Direct CCPA violation
  2. Phone record sales — Federal crime (18 U.S.C. § 1039)
  3. Breach data commercialization — Potential trafficking of stolen data
  4. No privacy policy or ToS — CCPA/GDPR violation
  5. No opt-out mechanisms — Consumer rights violation
  6. No data source disclosure — FTC Act violation
  7. Social media scraping — Platform ToS violations + CFAA exposure
  8. Algorithmic doxing — Behavioral profiling without consent
  9. Dark web data access — Unclear legal basis
  10. Defensive/hostile response to questions — Indicates awareness of issues
  11. Unregistered data broker status — California data broker registry violation

Associated User Investigation

Username: Goofisded / Goof [オトテン] Discord Roles: root, sudo guns.lol: https://guns.lol/goofisded GitHub: Goofisded Behavior: Defensive, dismissive, hostile when challenged Actions: Timed out investigator after losing argument

Assessment: Likely staff member or close affiliate of OSINTNova. Defensive posture, hostile behavior, and role association indicate awareness of legal exposure and inability to defend the platform.


Community Call to Action

If you care about privacy, doxing prevention, and legal OSINT — pay attention to this platform.

If you're a journalist, regulator, or investigator — look into OSINTNova.

If you're a Discord, Instagram, Facebook, or YouTube user — your data may already be affected.


Resources

Platform: https://app.osintnova.com Associated User: https://guns.lol/goofisded GitHub: https://github.com/Goofisded FTC Report: https://reportfraud.ftc.gov California AG: https://oag.ca.gov/contact/consumer-complaint-against-business-or-company DOJ: https://www.justice.gov


Status

Investigation: 🔴 Active Observation Period: 🟡 Ongoing Evidence Collected: 🟡 In Progress Community Notified: ✅ Complete


██████╗ ███████╗██╗███╗ ██╗████████╗███╗ ██╗ ██████╗ ██╗ ██╗ █████╗ ██╔═══██╗██╔════╝██║████╗ ██║╚══██╔══╝████╗ ██║██╔═══██╗██║ ██║██╔══██╗ ██║ ██║███████╗██║██╔██╗ ██║ ██║ ██╔██╗ ██║██║ ██║██║ ██║███████║ ██║ ██║╚════██║██║██║╚██╗██║ ██║ ██║╚██╗██║██║ ██║╚██╗ ██╔╝██╔══██║ ╚██████╔╝███████║██║██║ ╚████║ ██║ ██║ ╚████║╚██████╔╝ ╚████╔╝ ██║ ██║ ╚═════╝ ╚══════╝╚═╝╚═╝ ╚═══╝ ╚═╝ ╚═╝ ╚═══╝ ╚═════╝ ╚═══╝ ╚═╝ ╚═╝


WINTERGATEIC ❄️


#Privacy #OSINT #DataBroker #Infosec #CyberSecurity

0
0
0
0
Open post
WinterGateIC
WinterGate Intelligence Collective👤 @WinterGateIC@infosec.exchange · Jul 11, 2026
WinterGate Intelligence Collective👤
@WinterGateIC@infosec.exchange

:black_sparkling_heart_black: WinterGate Intelligence Collective (WIC) is a cybersecurity research initiative focused on infrastructure abuse documentation, threat actor tracking, open vulnerability disclosure, threat intelligence, infrastructure defense, and community empowerment. All research is public. All data is free. No consulting. No private sales. No paywalls. Just evidence and defensive tools for the security community. WIC does not accept payment for disclosures. Infrastructure abusers are documented. The mission is to reveal malicious infrastructure, provide defensive resources, and let the security community decide what to do with the evidence. The account is operated and governed by AnonCatalyst, founder of WIC.

infosec.exchange
TRUSTPILOT EXPOSED – THE CLOUDZY COVER‑UP & SYSTEMIC FAILURES

Issued by WinterGate Intelligence Collective (WIC)
Date: July 2026


1. EXECUTIVE SUMMARY

Trustpilot, a platform that markets itself as a trusted consumer review site, has systematically failed to uphold its own policies and has instead chosen to protect a business engaged in fraudulent, deceptive, and potentially criminal practices.

After a legitimate, verified review of Cloudzy.com (including receipts, transaction records, and proof of service) was removed without proper verification, Trustpilot:

  • Refused to reinstate the review despite overwhelming evidence.
  • Cited vague “policy violations” that were never clearly explained or justified.
  • Ignored documented proof of Cloudzy’s fraudulent billing and deceptive service practices.
  • Protected Cloudzy while ignoring their false “defamation” claims.

This is not an isolated incident. Trustpilot has a documented pattern of protecting fraudulent businesses, suppressing legitimate reviews, and engaging in deceptive practices that have drawn regulatory scrutiny, lawsuits, and criminal investigations.


2. TRUSTPILOT’S OFFICIAL RESPONSE (ANALYZED)

Trustpilot’s final response contains several problematic claims:

“Our automated system flagged the review for a definitive violation of our privacy policies: the inclusion of IP addresses.”

ANALYSIS: The review contained no IP addresses. This claim is false and appears to be a fabricated justification to avoid restoring the review.

“Our guidelines explicitly prohibit the inclusion of external links, promotional text, or outside calls to action.”

ANALYSIS: The review contained a single link to a public intelligence repository documenting Cloudzy’s fraudulent practices. This is not “promotional text” – it is evidence. Trustpilot is conflating evidence with promotion to justify their decision.

“Trustpilot is an independent consumer review platform, not a legal arbiter.”

ANALYSIS: This is a deliberate abdication of responsibility. Trustpilot is actively shielding a business that has been documented engaging in fraudulent and deceptive practices. By refusing to act on evidence of fraud, Trustpilot is enabling criminal activity.

“Our decision regarding this specific review is final.”

ANALYSIS: Trustpilot is acknowledging that they have no interest in due process. Despite receiving documented proof of fraud, they have chosen to protect Cloudzy and silence the reviewer.


3. TRUSTPILOT’S SYSTEMIC FAILURES – A PATTERN OF CORRUPTION

Trustpilot has a documented history of protecting fraudulent businesses, suppressing legitimate reviews, and engaging in deceptive practices. The Cloudzy case is just one example of a systemic pattern.

3.1. “Mafia‑Style Extortion” Allegations

In December 2025, short‑seller Grizzly Research published a 26‑page report accusing Trustpilot of waging “mafia‑style extortion campaigns” against businesses to force them to pay for subscriptions. The report found that genuine negative reviews are “spuriously challenged” or removed for companies that pay Trustpilot, while “countless obviously fake positive reviews” are left untouched for paying companies.

“Trustpilot is either doing a very bad job at policing their website or is willfully negligent when convenient.”

3.2. Fake Reviews & Fraudulent Profiles
  • 7.4% of reviews submitted in 2024 were removed for being fake or violating guidelines – 6.1% the year before.
  • 7.8 million fake reviews were detected and removed in 2025.
  • Scam investment firms are exploiting Trustpilot’s system, using forged certificates, cloned websites, and manipulated identities to bolster themselves with fake 5‑star reviews.
  • A “flourishing ecosystem of third‑party entities that sell fake reviews on Trustpilot” openly advertises the success of specific profiles.
3.3. Protecting Fraudulent Businesses While Silencing Consumers
  • The FTC filed a complaint against Ascend Ecom, alleging that the company defrauded consumers of at least $25 million and posted false positive reviews on Trustpilot.
  • One consumer repeatedly posted negative reviews on Trustpilot, and the reviews were removed. The consumer eventually crafted a review that Trustpilot did not take down, and the next day, Ascend shut down its Trustpilot profile.
  • The FTC complaint notes that Trustpilot removed negative reviews while allowing fake positive reviews to remain.
3.4. Regulatory Fines & Antitrust Investigations
  • Italy’s antitrust authority (AGCM) fined Trustpilot €4 million for failing to verify the authenticity of reviews and misleading consumers.
  • The investigation was opened on May 6, 2025, for potential violations of consumer protection laws.
  • The European Commission is investigating Trustpilot for allowing companies to select which customers to invite to leave reviews, potentially enabling review manipulation.
  • The UK’s antitrust authority has also opened an investigation into Trustpilot’s practices.
3.5. AI‑Powered Defamation Tool
  • Mecum Auctions filed a lawsuit against Trustpilot, accusing the platform of relying on an “AI‑powered defamation tool” to determine that a review was not defamatory.
3.6. Attempted Class Action
  • A proposed class action has been filed against Trustpilot, with a claims administrator appointed in March 2025.

4. HOW TRUSTPILOT’S SYSTEM ENABLES FRAUD

| Trustpilot Practice | How It Enables Fraud | |---------------------|----------------------| | Businesses can flag and remove negative reviews | Companies can remove valid criticism without proper oversight | | Automated “policy violation” detection | False positives are common and difficult to appeal | | No independent verification of flagged reviews | Trustpilot relies on the business’s claims, not on evidence | | Reviewers have no recourse | Once a review is removed, it is extremely difficult to get it reinstated | | Businesses can solicit fake reviews | Trustpilot does not actively prevent incentivized positive reviews | | The “final decision” doctrine | Trustpilot reserves the right to make arbitrary decisions with no accountability | | AI‑powered moderation tools | These tools are prone to errors and can be exploited by businesses |


5. LEGAL AND REGULATORY IMPLICATIONS

Trustpilot’s actions have serious legal and regulatory consequences.

5.1. Violation of Consumer Protection Laws
  • FTC Act § 5 (Unfair or Deceptive Acts or Practices): Trustpilot’s failure to act on evidence of fraud and its role in protecting a fraudulent business is an unfair and deceptive practice.
  • European Consumer Law: Under the Consumer Protection Cooperation (CPC) Regulation, Trustpilot may be liable for failing to protect consumers from deceptive practices.
  • Italian Antitrust Fine: Trustpilot has already been fined €4 million for failing to verify the authenticity of reviews.
5.2. Enabling Criminal Activity
  • CFAA (18 U.S.C. § 1030): Cloudzy’s fraudulent and deceptive practices may constitute unauthorized access and computer fraud.
  • GDPR and Data Protection Laws: Cloudzy’s failure to protect customer data and Trustpilot’s role in suppressing legitimate feedback may constitute GDPR violations.
  • RICO (Racketeer Influenced and Corrupt Organizations Act): The systematic suppression of legitimate reviews to protect fraudulent businesses could be considered a pattern of racketeering activity.
5.3. Criminal Exposure
  • Criminal Liability for Trustpilot: By knowingly protecting Cloudzy and suppressing evidence of fraud, Trustpilot may be subject to criminal charges.
  • Conspiracy to Commit Fraud: Trustpilot’s actions could be seen as a conspiracy to protect and enable fraudulent business practices.

6. CALL TO ACTION 6.1. For Consumers
  • File a complaint with the FTC at reportfraud.ftc.gov.
  • File a complaint with the Consumer Financial Protection Bureau (CFPB) at consumerfinance.gov.
  • Submit a complaint to the European Data Protection Board (EDPB) for GDPR violations.
  • File a complaint with the UK Information Commissioner’s Office (ICO).
  • File a complaint with the Italian antitrust authority (AGCM).
6.2. For Law Enforcement and Regulators
  • Investigate Trustpilot for patterns of protecting fraudulent businesses.
  • Examine Trustpilot’s review moderation practices for potential violations of consumer protection laws.
  • Hold Trustpilot accountable for knowingly enabling fraudulent business practices.
  • Expand the antitrust investigation to include Trustpilot’s global operations.
6.3. For Journalists and Public Interest Groups
  • Investigate Trustpilot’s role in protecting fraudulent businesses.
  • Expose the systematic suppression of legitimate reviews.
  • Advocate for stronger consumer protection regulations for review platforms.
  • Report on the Grizzly Research allegations and Trustpilot’s response.

7. CONCLUSION

Trustpilot is not a neutral platform for consumer reviews – it is a system that can be weaponized by fraudulent businesses to silence legitimate criticism and artificially inflate their reputations.

Trustpilot has chosen to protect Cloudzy, a business with a documented history of fraud, over the consumer who was victimized by it. This is a fundamental betrayal of the trust that consumers place in review platforms.

The evidence is clear:

  • Trustpilot has been accused of “mafia‑style extortion” against businesses.
  • Trustpilot has been fined €4 million for failing to verify reviews.
  • Trustpilot has been investigated by antitrust authorities in Italy and the UK.
  • Trustpilot has been sued over its AI moderation tools.
  • Trustpilot has been accused of protecting fraudulent businesses while silencing consumers.

WinterGate IC will continue to document and expose these practices. We encourage all consumers who have been similarly victimized to come forward and share their experiences.


WinterGate Intelligence Collective (WIC)
GitHub: WinterGate-IC

This document is a matter of public record and is not subject to legal suppression or censorship.

0
0
0
0

Remote instance

infosec.exchange
Open on original server
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 19:17:55 UTC