Sable Index
895 subscribers
137 photos
2 videos
6 links
Download Telegram
[EXPLAINED · CRIME] Russia Tops Oxford’s World Cybercrime Index

They assessed the impact, professionalism and technical skill of cybercriminals.

The study covered five areas: malware and access services, attacks and extortion, data and identity theft, scams, and money laundering.

Russia ranked first with a score of 58.39, followed by Ukraine at 36.44, China at 27.84 and the United States at 25.01.

@SableIndex | @SableIndexDiscussion
👀6🤓5
[ANALYSIS · CRIME] How P4x Became a Real-World Mr. Robot

Alejandro Caceres revealed in 2024 that he was P4x, the lone hacker behind North Korea’s week-long internet disruption.

His unauthorized 2022 campaign repeatedly knocked the country’s publicly visible websites offline, affecting government portals and the state airline’s booking site.

The resemblance to Elliot Alderson begins with the double life. Caceres ran cybersecurity company Hyperion Gray while privately testing where defensive expertise ends and vigilantism begins.

North Korean operators had targeted him in a campaign against security researchers, apparently seeking their intrusion tools. Caceres reported the attempt to the FBI and later said the response went nowhere

Months later, working from his Florida home, he used custom scripts and rented cloud servers to overwhelm several routers carrying North Korea’s external traffic.

This was not cinematic keyboard magic. It was patient automation aimed at a small, fragile set of systems, producing an outsized national effect.

WIRED reported that Caceres supplied screen recordings and other evidence while the disruption was unfolding. Independent reporting later interviewed him under his real name.

Like Elliot, P4x cast hacking as a personal answer to institutional paralysis. He decided official channels had failed, selected a target and imposed his own consequence.
But the comparison has limits. Caceres was a public entrepreneur, not an isolated fictional vigilante, and he later pitched his aggressive methods to US defense officials.

No evidence shows that Mr. Robot inspired him. The resemblance lies in the uncomfortable question both stories raise: when expertise becomes power, who authorizes its use?

Caceres feared prosecution but found parts of the US government more interested in his techniques. His Pentagon proposal was never formally adopted.

By revealing his identity, he traded the safety of a pseudonym for a political argument: cyber retaliation should be faster, smaller and less bureaucratic.


That makes P4x a convincing real-world echo of Mr. Robot, and a reminder that a compelling motive does not make an unauthorized attack accountable.

@SableIndex | @SableIndexDiscussion
8🤩2🤓2
[DEVELOPING · MALWARE] Fake Roblox Cheats Turn Discord Into a Spy Trap

A fake “undetected” Xeno cheat spreading through Discord and gaming forums delivers malware to Roblox players.

Bitdefender says the Java-based payload can steal browser cookies, Roblox, Minecraft and Discord accounts, crypto-wallet data and payment tokens.

It can also log keystrokes, activate webcams, stream the desktop, run PowerShell commands and alter files remotely.

@SableIndex | @SableIndexDiscussion
👀75💊3🕊1
[DEVELOPING · FRAUD] Fake IRS Letters Target Crypto Wallets

The IRS warns that scammers are mailing official-looking letters to cryptocurrency holders, directing them to a nonexistent Digital Asset Compliance Portal.

A QR code opens a fake IRS.gov page asking for exchange or wallet details and a phone number.

The IRS says the portal does not exist: follow-up calls may seek access details or transfers.

@SableIndex | @SableIndexDiscussion
💊9🕊31
[FRAUD] ChatGPT Helped Cambodian Scammers Target Workers and Investors

OpenAI banned accounts linked to Cambodian scam centers after WhatsApp flagged them. The operators used ChatGPT to target victims with investment scams and created scam job offers aimed at Indians.

They generated fake personas, translated messages and forged passports, legal notices and stock confirmations. The network ran romance, gambling and police-impersonation schemes.

Recruitment flyers promised free flights, housing and work visas. OpenAI said the operation may have reached hundreds of targets; several conversations referenced losses in the thousands.

@SableIndex | @SableIndexDiscussion
2😴2🤩1
[DEVELOPING · CRIME] Police Probe Dark-Web Drug Deliveries in Kanpur

Law-enforcement agencies in Kanpur, India, opened an inquiry into a suspected dark-web network delivering cannabis and hashish to affluent neighborhoods.

Investigators say sellers used invite-only groups, encrypted messaging and digital payments. Buyers reportedly passed referrals before home deliveries; police are tracing couriers, money flows and communications.

@SableIndex | @SableIndexDiscussion
💊4
[ANALYSIS · CRIME] Rare Telegram gifts raise insider-access questions

GiftChangesUpdates alleges that people linked to Telegram may have received rare collectibles before others. Some rare numbers can later sell for more.

Everyday users pay to upgrade gifts into numbered collectibles with different designs.

The post highlights #5554: Vlad upgraded it and received #5556, while #5555 was missing. Minutes later, #5555 appeared in an account named Tanya.

Similar gaps are cited around #7776-#7778, where #7777 allegedly appeared later.

GiftChangesUpdates links Tanya to Artem, whom the post describes as a Telegram developer, using matching surnames, city and approximate age range. That connection is unverified.

The post speculates that gift attributes are generated in advance, allowing privileged database access to identify and target rare items.

Telegram has not confirmed the allegations; no server logs or independent audit have been published.

@SableIndex | @SableIndexDiscussion
83😴1
[FRAUD] Stolen AI Keys Rack Up Nearly $1 Million in Charges

Cybercriminals are stealing developer access keys and reselling them through gray-market AI services, causing nearly $1m in charges before victims notice.

Unit 42 says these “transfer stations” can generate tens of millions of model requests daily. Stolen corporate accounts are sold on dark-web marketplaces, while smaller firms may have little chance of recovering the bills.

@SableIndex | @SableIndexDiscussion
14🤩4💊4👀3
[CRIME] Ransomware Boss Gets 16 Years After 18-Company Campaign

Maksim Silnikau, 40, creator of the Ransom Cartel ransomware strain, was sentenced in the U.S. to 16 years in prison.

The Justice Department says his operation attacked at least 18 companies between 2021 and 2023. Affiliates stole data and demanded payment for decryption keys or promises not to publish it.

Silnikau also ran a hidden site to control attacks, communicate with victims and split ransom money.

@SableIndex | @SableIndexDiscussion
👀5🕊4