Thursday, January 27, 2022

Exposing a Currently Active "Jabber ZeuS" also known as "Aqua ZeuS" Gang Personal Email Portfolio - An OSINT Analysis


Note: This OSINT analysis has been originally published at my current employer's Web site - https://whoisxmlapi.com where I'm currently acting as a DNS Threat Researcher since January, 2021.

Dear blog readers,

I've decided to share a recently obtained portfolio of personal emails belonging to the "Jabber ZeuS" also known as "Aqua ZeuS" gang members with the idea to assist everyone on their way to track down and monitor the botnet masters behind the botnet including to assist in possible cyber attack campaign attribution including possible cyber threat actor attribution campaigns.

Sample personal emails known to have been currently in use by the "Jabber ZeuS" also known as "Aqua ZeuS" gang:

donsft@hotmail[.]com

johnny@guru[.]bearin[.]donetsk[.]ua

t4ank@ua[.]fm

airlord1988@gmail[.]com

alexeysafin@yahoo[.]com

aqua@incomeet[.]com

bashorg@talking[.]cc

benny@jabber[.]cz

bind@email[.]ru

bx1@hotmail[.]com

bx1_@msn[.]com

cruelintention@email[.]ru

d[.]frank@0nl1ne[.]at

d[.]frank@jabber[.]jp

danibx1@hotmail[.]fr

danieldelcore@hotmail[.]com

demon@jabber[.]ru

duo@jabber[.]cn

fering99@yahoo[.]com

firstmen17@rambler[.]ru

getready@safebox[.]ru

notifier@gajim[.]org

gribodemon@pochta[.]ru

h4x0rdz@hotmail[.]com

hof@headcounter[.]org

i_amhere@hotmail[.]fr

jheto2002@gmail[.]com

john[.]mikle@ymail[.]com

johnlecun@gmail[.]com

kainehabe@hotmail[.]com

lostbuffer@gmail[.]com

lostbuffer@hotmail[.]com

mary[.]j555@hotmail[.]com

miami@jabbluisa[.]com

moscow[.]berlin@yahoo[.]com

mricq@incomeet[.]com

niko@grad[.]com

petr0vich@incomeet[.]com

princedelune@hotmail[.]fr

sector[.]exploits@gmail[.]com

secustar@mail[.]ru

sere[.]bro@hotmail[.]com

shwark[.]power[.]andrew@gmail[.]com

spanishp@hotmail[.]com

susanneon@googlemail[.]com

tank@incomeet[.]com

theklutch@gmail[.]com

um@jabbim[.]com

virus_e_2003@hotmail[.]com

vlad[.]dimitrov@hotmail[.]com

Stay tuned!

No comments:

Post a Comment