
Keitaro TDS: 1,500 Panels Exposed and Zero Legitimate Uses Found
50,000+ sites scanned, 1,565 admin panels discovered, 0% legitimate use rate. Criminal clients include EvilCorp, LockBit, and VexTrio. Open-source detection tools released.
Real-time threat intelligence, active investigations, and takedown operations from our detection systems.
Investigations, research, and takedown operations

50,000+ sites scanned, 1,565 admin panels discovered, 0% legitimate use rate. Criminal clients include EvilCorp, LockBit, and VexTrio. Open-source detection tools released.

The "middle class" of fraud exposed. Three teams, shared Google Spreadsheets, and proof that OSINT disruption works — 717Team archived after intelligence operations.

Not a scam tool — a scam university. $10M+ claimed, 5,000+ members trained since 2021. 730+ scammer usernames leaked. The upstream producer behind casino and drainer operations.

Technical breakdown of wallet-draining phishing kits behind $1.93B stolen in H1 2025. Kill-chain, real exploits, DaaS economy, and recovery steps.

Code-level deep-dive into TRXDrop (50 forced signing retries, AI-generated code) and NiceCrypto (80% affiliate commission, 4-chain expansion). Full 9-step attack chain deconstructed.

383 verified victims across 30+ countries. Celebrity deepfakes, AI chatbots, and a meta-scam that steals from its own scammers. Four casino PaaS operations dissected.

Follow-up investigation: 24.7 MB dataset reviewed, 5,000+ abuse tickets ignored, all NiceNIC domains now flagged as unsafe. Challenge: find a legitimate domain.

Investigation into IANA 3765 with phishing score 1,141.74, $8.5M Trust Wallet heist, and open confession: "we are not against scamming."

The dashboard proving that scammers are frightened mice. We expose crypto scammer infrastructure, collect evidence, and help victims fight back by refusing to stay silent.

We detected a Russian malvertising operation using stealer malware, restored wallet access, and returned $100K to the victim.

How major domain registrars enable global phishing scams through weak abuse policies and slow response times.

150+ malicious Mozilla extensions sharing a single C2 backend on Nigerian infrastructure, all controlled by one operator.

How Valve enabled BlockBlasters to deploy crypto-drainer malware on Steam, stealing hundreds of thousands from gamers.

Comprehensive breakdown of PhishDestroy operations: domains tracked, abuse reports filed, takedowns coordinated, and response times measured.

Visual report on phishing domain registration patterns across top registrars: where scam domains cluster and which registrars enable them.
Analyze domains, check wallets, scan URLs — all free, no registration.