{
	"id": "1283f1e9-c148-479c-898b-dc7660e44a2f",
	"created_at": "2026-04-06T00:06:08.432852Z",
	"updated_at": "2026-04-10T13:12:38.341542Z",
	"deleted_at": null,
	"sha1_hash": "2caf041fed86cab73c8b7aac9643146044012e31",
	"title": "Dark Peep #7: Shadows of Betrayal and Leadership in Flux",
	"llm_title": "",
	"authors": "",
	"file_creation_date": "0001-01-01T00:00:00Z",
	"file_modification_date": "0001-01-01T00:00:00Z",
	"file_size": 66216,
	"plain_text": "Dark Peep #7: Shadows of Betrayal and Leadership in Flux\r\nPublished: 2023-12-22 · Archived: 2026-04-02 10:35:12 UTC\r\n1. Home\r\n2. Blog\r\n3. Dark Web\r\n4. Dark Peep #7: Shadows of Betrayal and Leadership in Flux\r\nShrouded in the mysterious alleys of the dark web, “Dark Peep #7” delves into a world where betrayals happen\r\nas often as tiny secrets, and leadership changes faster than data moves in cyberspace. This issue highlights\r\nsurprising power changes and smart tricks that have upside down the usual order in the digital underworld.\r\nFig. 1. Illustration of a dramatic moment of betrayal with two threat actors in Ancient Rome.\r\n(generated using OpenAI’s DALL-E 3)\r\nWe dive into a story where strong alliances fall apart and new, mysterious leaders rise to power, changing the face\r\nof cyber control. The stories here are more than just digital conflict; they show a deep change in the secret halls of\r\npower. They remind us how weak and short-lived authority can be in the dark web world.\r\nCyber Threat Group vs. Phishing\r\nIn a world where digital shadows loom large, the vigilant watchers of the cyber realm, a hacktivist threat group\r\nknown as Team Insane Pakistan, has issued a crucial warning through their latest Telegram message. The\r\nmessage, stark and urgent, serves as a beacon of caution for the unwary:\r\nFig.2. Team Insane Pakistan’s Telegram Post\r\nThis short but powerful message highlights a dangerous new scam in the digital world: a sophisticated scam\r\ntargeting Facebook pages. \r\nAs the guardians of online sanctity, Team Insane Pakistan’s warning isn’t just a message; it’s a clarion call to\r\nheighten our vigilance. Social media platforms have been playgrounds for digital marauders for too long, but this\r\nnew scam is a reminder that the battle against cyber threats is constantly evolving.\r\nKillSec’s Cyber Crew Quest: Got Skills? They Want ‘Em!\r\nIn the bright, neon-lit back alleys of the cyber world, KillSec, the hacktivist group known as the pirates of this\r\nrealm, is looking for clever recruits. They want you if you’re fluent in computers and see firewalls as just the\r\nbeginning of fun!\r\nFig. 3. KillSec’s Telegram Post\r\nhttps://socradar.io/dark-peep-7-shadows-of-betrayal-and-leadership-in-flux/\r\nPage 1 of 4\n\nKillMilk’s Digital House Cleaning: Rats and Cockroaches Beware!\r\nHold onto your keyboards, folks! KillMilk, the pro-Russian cyber threat group, has just released a video on their\r\nTelegram channel. It’s more surprising than a spy story!\r\nFig. 4. KillMilk’s Telegram Post\r\nKillMilk has uncovered a traitor in their ranks like a scene from a digital detective story. The result? The vigilant\r\nadmin team kicked her out.\r\nWith a playful emoji, KillMilk suggests more excitement is coming. The cyber community is all ears, wondering\r\nwho will be the next to go in this intense online showdown.\r\nHere’s a clear message for everyone in the hidden parts of the internet: trust is even harder to find perfect software\r\nin this secret world.\r\nSiegedSec’s Cat-and-Mouse Game with Telegram Continues!\r\nPeople often say curiosity killed the cat, but SiegedSec, the cyber gang known as the Internet cats, has bounced\r\nback once more. Their Telegram channel has been removed from the platform again. But just like a cat with nine\r\nlives, they’ve landed on their feet, ready to leap into their next digital adventure.\r\nFig. 5. SiegedSec’s X Post\r\nGame Over? Ransomware Wipes Out 17,000 Heroes\r\nIn a situation that feels like it’s straight from a gamer’s worst nightmare, ‘Ethyrial: Echoes of Yore,’ an\r\nMMORPG played by 17,000 adventurers, encountered a digital challenge it couldn’t defeat: a devastating\r\nransomware attack.\r\nFig. 6. Announcement on Discord (Source: BleepingComputer)\r\nThousands experienced a grim reality as cyber saboteurs wiped out their virtual alter egos and treasures in a\r\nswoop of destruction, causing their characters and achievements to vanish into thin air.\r\nAdmin Axed in CsCrew-Ganosec Clash!\r\nA little chaos unfolded when a CsCrew admin spiced up the cyber streets with the phrase “bocil ganos duduk\r\ndiam aja,” which seemed like a jab at Ganosec. Quick to quash the quibble, CsCrew showed that admin the exit in\r\na flash!\r\nFig. 7. CsCrew’s statement\r\nThe phrase “bocil ganos duduk diam aja” is in Indonesian and roughly translates to “The noisy kid just sits\r\nquietly” in English.\r\nhttps://socradar.io/dark-peep-7-shadows-of-betrayal-and-leadership-in-flux/\r\nPage 2 of 4\n\nWith one admin down and tensions hopefully cooled, will CsCrew and Ganosec play nice, or is this just the eye of\r\nthe storm?\r\nOwnership and Intrigue on BlackForums\r\nThe statement posted on Blackforums’ Telegram channel has us scratching our heads and wondering, “Is this a\r\ncoup, or did someone just win the dark web’s version of a twisted ownership lottery?” A threat actor known as\r\nAstounding has declared themselves the grand overlord of BlackForums and all its cyber-minion groups. It’s like\r\nthey won a sinister version of Monopoly and now have hotels on all the most dangerous digital streets.\r\nFig. 8. Declaration of Astounding\r\nWe can almost picture them in a dark, digital boardroom, twirling a virtual mustache and saying, “I now own it all,\r\nmuahaha!” Their shoutout to supporters adds a touch of dark comedy to this whole affair as if they’re thanking\r\ntheir fans for cheering on their epic digital shopping spree. Who knew ownership could be this entertaining in the\r\nweird world of cyber threats?\r\nEchoes of Absence, the Vanishing of Govadmin\r\nA threat group known as SkidSec Leaks has announced the loss of their leader, Govadmin, after a complete\r\ncommunication blackout. The group memorializes him as a key figure and warns against impostors claiming his\r\nidentity. Despite the setback, SkidSec assures that operations will continue with new leadership already in\r\ndiscussion.\r\nFig. 9. SkidSec Leaks’ Telegram Post\r\nFurthermore, A threat actor known as Soup got all sentimental, calling Govadmin the OG (Original Gangster) of\r\nSkidSec, and even hinted that Govadmin’s ghostly messages might haunt their digital dreams forever.\r\nSkidSec’s Propaganda Print-a-thon\r\nThe clock is ticking! A North Korean threat group, SkidSec, had rallied its followers for a unique mission\r\ntargeting South Korea, urging its followers to spread images of their “glorious leader” across as many printers as\r\nthey could access. The challenge was clear: inundate printers with propaganda posters and provide screenshot\r\nevidence of the efforts to qualify for the bounty.\r\nFig. 10. SkidSec Leaks’ Telegram Post\r\nNavigating the Zero-Day Threat\r\nA recent X platform post noted that hacker ‘thegrugq’ has released critical Indicators of Compromise (IOCs) for a\r\nnew zero-day being leveraged by ransomware gangs. The details include URLs, IP addresses, and checksums\r\ncritical for cybersecurity teams to identify and protect against this emerging threat.\r\nFig. 11. thegrugq’s X post (Source: X)\r\nhttps://socradar.io/dark-peep-7-shadows-of-betrayal-and-leadership-in-flux/\r\nPage 3 of 4\n\nA Web That Never Sleeps\r\nAs we close the pages of “Dark Peep #7,” one truth rings clear: the Dark Web remains a hive of ceaseless activity,\r\nits pulse unfaltering in the face of change and chaos. There’s no hint of a slowdown on this digital frontier, where\r\neach day brings new narratives of intrigue and power shifts.\r\nFor those keen on staying abreast of these ever-evolving developments, Dark Web News within the SOCRadar\r\nXTI Cyber Threat Intelligence module offers an invaluable window. This resource provides the insights and\r\nupdates necessary to navigate and understand the complex, often hidden machinations of the Dark Web. It’s a tool\r\nnot just for observation but for staying one step ahead in a realm where knowledge is as powerful as the codes that\r\nbuild it.\r\nSOCRadar XTI’s Dark Web News page under the CTI Panel (Source: SOCRadar)\r\nSource: https://socradar.io/dark-peep-7-shadows-of-betrayal-and-leadership-in-flux/\r\nhttps://socradar.io/dark-peep-7-shadows-of-betrayal-and-leadership-in-flux/\r\nPage 4 of 4",
	"extraction_quality": 1,
	"language": "EN",
	"sources": [
		"MISPGALAXY",
		"Malpedia"
	],
	"origins": [
		"web"
	],
	"references": [
		"https://socradar.io/dark-peep-7-shadows-of-betrayal-and-leadership-in-flux/"
	],
	"report_names": [
		"dark-peep-7-shadows-of-betrayal-and-leadership-in-flux"
	],
	"threat_actors": [
		{
			"id": "c29ed071-678d-4023-a954-7138fb534056",
			"created_at": "2023-11-05T02:00:08.079228Z",
			"updated_at": "2026-04-10T02:00:03.39948Z",
			"deleted_at": null,
			"main_name": "SiegedSec",
			"aliases": [],
			"source_name": "MISPGALAXY:SiegedSec",
			"tools": [],
			"source_id": "MISPGALAXY",
			"reports": null
		},
		{
			"id": "1ea1bb1c-12f2-4af9-8734-0080c376c02c",
			"created_at": "2024-10-08T02:00:04.457708Z",
			"updated_at": "2026-04-10T02:00:03.720292Z",
			"deleted_at": null,
			"main_name": "SkidSec",
			"aliases": [
				"SkidSec Leaks"
			],
			"source_name": "MISPGALAXY:SkidSec",
			"tools": [],
			"source_id": "MISPGALAXY",
			"reports": null
		}
	],
	"ts_created_at": 1775433968,
	"ts_updated_at": 1775826758,
	"ts_creation_date": 0,
	"ts_modification_date": 0,
	"files": {
		"pdf": "https://archive.orkl.eu/2caf041fed86cab73c8b7aac9643146044012e31.pdf",
		"text": "https://archive.orkl.eu/2caf041fed86cab73c8b7aac9643146044012e31.txt",
		"img": "https://archive.orkl.eu/2caf041fed86cab73c8b7aac9643146044012e31.jpg"
	}
}