{"id":5342,"date":"2025-08-07T01:25:27","date_gmt":"2025-08-07T01:25:27","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=5342"},"modified":"2025-08-07T01:25:28","modified_gmt":"2025-08-07T01:25:28","slug":"who-bought-arrested-within-the-raid-on-the-xss-crime-discussion-board-krebs-on-safety","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=5342","title":{"rendered":"Who Bought Arrested within the Raid on the XSS Crime Discussion board? \u2013 Krebs on Safety"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p>On July 22, 2025, the European police company <strong>Europol<\/strong> <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.europol.europa.eu\/media-press\/newsroom\/news\/key-figure-behind-major-russian-speaking-cybercrime-forum-targeted-in-ukraine\" target=\"_blank\" rel=\"noopener\">mentioned<\/a> a long-running investigation led by the French Police resulted within the arrest of a 38-year-old administrator of <b>XSS,<\/b>\u00a0a Russian-language cybercrime discussion board with greater than 50,000 members. The motion has triggered an ongoing frenzy of hypothesis and panic amongst XSS denizens concerning the id of the unnamed suspect, however the consensus is that he&#8217;s a pivotal determine within the crime discussion board scene who goes by the hacker deal with \u201c<strong>Toha<\/strong>.\u201d Right here\u2019s a deep dive on what\u2019s knowable about Toha, and a brief stab at who obtained nabbed.<\/p>\n<div id=\"attachment_71827\" style=\"width: 759px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" aria-describedby=\"caption-attachment-71827\" decoding=\"async\" class=\" wp-image-71827\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/08\/xss-sbu.png\" alt=\"\" width=\"749\" height=\"499\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/08\/xss-sbu.png 851w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/08\/xss-sbu-768x512.png 768w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/08\/xss-sbu-782x521.png 782w\" sizes=\"auto, (max-width: 749px) 100vw, 749px\"\/><\/p>\n<p id=\"caption-attachment-71827\" class=\"wp-caption-text\">An unnamed 38-year-old man was arrested in Kiev final month on suspicion of administering the cybercrime discussion board XSS. Picture: ssu.gov.ua.<\/p>\n<\/div>\n<p>Europol didn&#8217;t title the accused, however printed partially obscured images of him from the raid on his residence in Kiev. The police company mentioned the suspect acted as a trusted third get together \u2014 arbitrating disputes between criminals \u2014 and guaranteeing the safety of transactions on XSS. A <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/ssu.gov.ua\/novyny\/sbu-spilno-z-natspolitsiieiu-ta-pravookhorontsiamy-frantsii-vykryla-rozrobnyka-odniiei-z-naividomishykh-u-sviti-khakerskykh-platform\" target=\"_blank\" rel=\"noopener\">assertion<\/a> from Ukraine\u2019s <strong>SBU<\/strong> safety service mentioned XSS counted amongst its members many cybercriminals from varied ransomware teams, together with <strong>REvil<\/strong>, <strong>LockBit<\/strong>, <strong>Conti<\/strong>, and <strong>Qiliin<\/strong>.<\/p>\n<p>For the reason that Europol announcement, the XSS discussion board resurfaced at a brand new deal with on the deep internet (reachable solely through the anonymity community <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/en.wikipedia.org\/wiki\/Tor_(network)\" target=\"_blank\" rel=\"noopener\">Tor<\/a>). However from reviewing the latest posts, there seems to be little consensus amongst longtime members concerning the id of the now-detained XSS administrator.<\/p>\n<p>Probably the most frequent remark concerning the arrest was a message of solidarity and assist for Toha, the deal with chosen by the longtime administrator of XSS and a number of other different main Russian boards. Toha\u2019s accounts on different boards have been silent for the reason that raid.<\/p>\n<p>Europol mentioned the suspect has loved a virtually 20-year profession in cybercrime, which roughly traces up with Toha\u2019s historical past. In 2005, Toha was a founding member of the Russian-speaking discussion board <strong>Hack-All. <\/strong>That&#8217;s, till it obtained massively hacked a couple of months after its debut. In 2006, Toha rebranded the discussion board to <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/krebsonsecurity.com\/tag\/exploit-in\/\" target=\"_blank\" rel=\"noopener\"><strong>exploit[.]in<\/strong><\/a>, which might go on to attract tens of hundreds of members, together with an eventual Who\u2019s-Who of needed cybercriminals.<\/p>\n<p>Toha introduced in 2018 that he was promoting the Exploit discussion board, prompting rampant hypothesis on the boards that the customer was secretly a Russian or Ukrainian authorities entity or entrance individual. Nevertheless, these suspicions had been unsupported by proof, and Toha vehemently denied the discussion board had been given over to authorities.<\/p>\n<p>One of many oldest Russian-language cybercrime boards was <strong>DaMaGeLaB<\/strong>, which operated from 2004 to 2017, when its administrator \u201cAr3s\u201d was arrested. In 2018, a partial backup of the DaMaGeLaB discussion board was <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.own.security\/en\/ressources\/blog\/russian-language-cybercriminal-forums---chapter-iii-analyzing-the-most-active-and-renowned-communities-english-only\" target=\"_blank\" rel=\"noopener\">reincarnated as xss[.]is<\/a>, with Toha as its acknowledged administrator.<\/p>\n<h2>CROSS-SITE GRIFTING<\/h2>\n<p>Clues about Toha\u2019s early presence on the Web \u2014 from ~2004 to 2010 \u2014 can be found within the archives of <strong>Intel 471<\/strong>, a cyber intelligence agency that tracks discussion board exercise. Intel 471 exhibits Toha used the identical e-mail deal with throughout a number of discussion board accounts, together with at Exploit, <strong>Antichat<\/strong>, <strong>Carder[.]su<\/strong> and <strong>inattack[.]ru.<\/strong><\/p>\n<p><strong>DomainTools.com<\/strong> finds Toha\u2019s e-mail deal with \u2014 <strong>toschka2003@yandex.ru<\/strong> \u2014 was used to register a minimum of a dozen domains \u2014 most of them from the mid- to late 2000s. Other than exploit[.]in and a website known as <strong>ixyq[.]com<\/strong>, the opposite domains registered to that e-mail deal with finish in .ua, the top-level area for Ukraine (e.g. deleted.org[.]ua, lj.com[.]ua, and blogspot.org[.]ua).<\/p>\n<div id=\"attachment_71853\" style=\"width: 759px\" class=\"wp-caption aligncenter\"><img aria-describedby=\"caption-attachment-71853\" decoding=\"async\" loading=\"lazy\" class=\" wp-image-71853\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/08\/exploit-deleted-ua.png\" alt=\"\" width=\"749\" height=\"702\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/08\/exploit-deleted-ua.png 924w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/08\/exploit-deleted-ua-768x721.png 768w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/08\/exploit-deleted-ua-782x734.png 782w\" sizes=\"auto, (max-width: 749px) 100vw, 749px\"\/><\/p>\n<p id=\"caption-attachment-71853\" class=\"wp-caption-text\">A 2008 snapshot of a website registered to toschka2003@yandex.ru and to Anton Medvedovsky in Kiev. Word the message on the backside left, \u201cProtected by Exploit,in.\u201d Picture: archive.org.<\/p>\n<\/div>\n<p>Practically the entire domains registered to toschka2003@yandex.ru comprise the title <strong>Anton Medvedovskiy<\/strong> within the registration information, apart from the aforementioned ixyq[.]com, which is registered to the title <strong>Yuriy Avdeev<\/strong> in Moscow.<\/p>\n<p>This Avdeev surname got here up in a prolonged dialog with <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/krebsonsecurity.com\/2024\/05\/u-s-charges-russian-man-as-boss-of-lockbit-ransomware-group\/\" target=\"_blank\" rel=\"noopener\">Lockbitsupp<\/a>, the chief of the rapacious and harmful ransomware affiliate group <strong>Lockbit<\/strong>. The dialog befell in February 2024, when Lockbitsupp requested for assist figuring out Toha\u2019s real-life id.<\/p>\n<div id=\"attachment_71822\" style=\"width: 759px\" class=\"wp-caption aligncenter\"><img aria-describedby=\"caption-attachment-71822\" decoding=\"async\" loading=\"lazy\" class=\" wp-image-71822\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/08\/lcokbitsupp-convo.png\" alt=\"\" width=\"749\" height=\"938\"\/><\/p>\n<p id=\"caption-attachment-71822\" class=\"wp-caption-text\">In early 2024, the chief of the Lockbit ransomware group \u2014 Lockbitsupp \u2014 requested for assist investigating the id of the XSS administrator Toha, which he claimed was a Russian man named Anton Avdeev.<\/p>\n<\/div>\n<p>Lockbitsupp didn\u2019t share why he needed Toha\u2019s particulars, however he maintained that Toha\u2019s actual title was <strong>Anton Avdeev<\/strong>. I declined to assist Lockbitsupp in no matter revenge he was planning on Toha, however his query made me curious to look deeper.<span id=\"more-71819\"\/><\/p>\n<p>It seems Lockbitsupp\u2019s question was primarily based on a now-deleted Twitter put up from 2022, when a person by the title \u201c<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/x.com\/3xp0rtblog\/status\/1585357689777164288\" target=\"_blank\" rel=\"noopener\">3xp0rt<\/a>\u201d asserted that Toha was a Russian man named <strong>Anton Viktorovich Avdeev<\/strong>, born October 27, 1983.<\/p>\n<p>Looking the net for Toha\u2019s e-mail deal with toschka2003@yandex.ru reveals <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.bmwclub.ru\/threads\/bmw-x5-e70.398405\/\" target=\"_blank\" rel=\"noopener\">a 2010 gross sales thread<\/a> on the discussion board <strong>bmwclub.ru<\/strong> the place a person named Honeypo was promoting a 2007 BMW X5. The advert listed the contact individual as Anton Avdeev and gave the contact telephone quantity <strong>9588693.<\/strong><\/p>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter size-full wp-image-71824\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/08\/bmw-toha.png\" alt=\"\" width=\"878\" height=\"888\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/08\/bmw-toha.png 878w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/08\/bmw-toha-768x777.png 768w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/08\/bmw-toha-782x791.png 782w\" sizes=\"auto, (max-width: 878px) 100vw, 878px\"\/><\/p>\n<p>A search on the telephone quantity 9588693 within the breach monitoring service <strong>Constella Intelligence<\/strong> finds loads of official Russian authorities information with this quantity, date of start and the title Anton Viktorovich Avdeev. For instance, hacked Russian authorities information present this individual has a Russian tax ID and SIN (Social Safety quantity), and that they had been flagged for visitors violations on a number of events by Moscow police; in 2004, 2006, 2009, and 2014.<\/p>\n<p>Astute readers might have observed by now that the ages of Mr. Avdeev (41) and the XSS admin arrested this month (38) are a bit off. This would appear to counsel that the individual arrested is somebody aside from Mr. Avdeev, who didn&#8217;t reply to requests for remark.<\/p>\n<h2>A FLY ON THE WALL<\/h2>\n<p>For additional perception on this query, KrebsOnSecurity sought feedback from <strong>Sergeii Vovnenko<\/strong>, a former cybercriminal from Ukraine who now works on the safety startup <strong>paranoidlab.com<\/strong>. I reached out to Vovnenko as a result of for a number of years starting round 2010 he was the proprietor and operator of <strong>thesecure[.]biz<\/strong>, an encrypted \u201cJabber\u201d instantaneous messaging server that Europol mentioned was operated by the suspect arrested in Kiev. Thesecure[.]biz grew fairly in style amongst most of the high Russian-speaking cybercriminals as a result of it scrupulously saved few information of its customers\u2019 exercise, and its administrator was at all times a trusted member of the group.<\/p>\n<p>The rationale I do know this historic tidbit is that in 2013, Vovnenko \u2014 utilizing the hacker nicknames \u201c<strong>Fly<\/strong>,\u201d and \u201c<strong>Flycracker<\/strong>\u201d \u2014 <a rel=\"nofollow\" target=\"_blank\" href=\"http:\/\/krebsonsecurity.com\/2013\/07\/mail-from-the-velvet-cybercrime-underground\/\" target=\"_blank\" rel=\"noopener\">hatched a plan<\/a> to have a gram of heroin bought off of the Silk Highway darknet market and shipped to our house in Northern Virginia. The scheme was to spoof a name from one among our neighbors to the native police, saying this man Krebs down the road was a druggie who was having narcotics delivered to his house.<\/p>\n<p>I occurred to be lurking on Flycracker\u2019s non-public cybercrime discussion board when his heroin-framing plan was carried out, and known as the police myself earlier than the smack finally arrived within the U.S. Mail. Vovnenko was later <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/krebsonsecurity.com\/2014\/06\/the-fly-has-been-swatted\/\" target=\"_blank\" rel=\"noopener\">arrested<\/a> for unrelated cybercrime actions, extradited to the US, convicted, and deported after a 16-month keep within the U.S. jail system [on several occasions, he has expressed heartfelt apologies for the incident, and we have since buried the hatchet].<\/p>\n<p>Vovnenko mentioned he bought a tool for cloning bank cards from Toha in 2009, and that Toha shipped the merchandise from Russia. Vovnenko defined that he (Flycracker) was the proprietor and operator of thesecure[.]biz from 2010 till his arrest in 2014.<\/p>\n<p>Vovnenko believes thesecure[.]biz was stolen whereas he was in jail, both by Toha and\/or an XSS administrator who glided by the nicknames <strong>N0klos<\/strong> and <strong>Sonic<\/strong>.<\/p>\n<p>\u201cOnce I was in jail, [the] admin of xss.is stole that area, or most likely N0klos purchased XSS from Toha or vice versa,\u201d Vovnenko mentioned of the Jabber area. \u201cNo one from [the forums] spoke with me after my jailtime, so I can solely guess what actually occurred.\u201d<\/p>\n<p>N0klos was the proprietor and administrator of an early Russian-language cybercrime discussion board referred to as <strong>Darklife[.]ws<\/strong>. Nevertheless, N0kl0s additionally seems to be a lifelong Russian resident, and in any case appears to have vanished from Russian cybercrime boards a number of years in the past.<\/p>\n<p>Requested whether or not he believes Toha was the XSS administrator who was arrested this month in Ukraine, Vovnenko maintained that Toha is Russian, and that \u201cthe French cops took the fallacious man.\u201d<\/p>\n<h2>WHO IS TOHA?<\/h2>\n<p>So who did the Ukrainian police arrest in response to the investigation by the French authorities? It appears believable that the BMW advert invoking Toha\u2019s e-mail deal with and the title and telephone variety of a Russian citizen was merely misdirection on Toha\u2019s half \u2014 supposed to confuse and throw off investigators. Maybe this even explains the Avdeev surname surfacing within the registration information from one among Toha\u2019s domains.<\/p>\n<p>However generally the best reply is the right one. \u201cToha\u201d is a standard Slavic nickname for somebody with the primary title \u201cAnton,\u201d and that matches the title within the registration information for greater than a dozen domains tied to Toha\u2019s toschka2003@yandex.ru e-mail deal with: Anton Medvedovskiy.<\/p>\n<p>Constella Intelligence finds there may be an <strong>Anton Gannadievich Medvedovskiy<\/strong> residing in Kiev who might be 38 years previous in December. This particular person owns the e-mail deal with <strong>itsmail@i.ua<\/strong>, as effectively an <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.airbnb.com\/users\/show\/27040702\" target=\"_blank\" rel=\"noopener\">an Airbnb account<\/a> that includes a profile picture of a person with roughly the identical hairline because the suspect within the blurred images launched by the Ukrainian police. Mr. Medvedovskiy didn&#8217;t reply to a request for remark.<\/p>\n<p>My tackle the takedown is that the Ukrainian authorities seemingly arrested Medvedovskiy. Toha shared on DaMaGeLab in 2005 that he had just lately completed the eleventh grade and was learning at a college \u2014 a time when Mevedovskiy would have been round 18 years previous. On Dec. 11, 2006, fellow Exploit members wished Toha a contented birthday. Information uncovered in a 2022 hack on the Ukrainian public companies portal diia.gov.ua present that Mr. Medvedovskiy\u2019s birthday is Dec. 11, 1987.<\/p>\n<p>The regulation enforcement motion and ensuing confusion concerning the id of the detained has thrown the Russian cybercrime discussion board scene into disarray in latest weeks, with prolonged and heated arguments about XSS\u2019s future spooling out throughout the boards.<\/p>\n<p>XSS relaunched on a brand new Tor deal with shortly after the authorities plastered their seizure discover on the discussion board\u2019s\u00a0 homepage, however the entire trusted moderators from the previous discussion board had been dismissed with out rationalization. Present members noticed their discussion board account balances drop to zero, and had been requested to plunk down a deposit to register on the new discussion board. The brand new XSS \u201cadmin\u201d mentioned they had been involved with the earlier homeowners and that the adjustments had been to assist rebuild safety and belief inside the group.<\/p>\n<p>Nevertheless, the brand new admin\u2019s assurances seem to have executed little to assuage the worst fears of the discussion board\u2019s erstwhile members, most of whom appear to be protecting their distance from the relaunched web site for now.<\/p>\n<p>Certainly, if there may be one widespread understanding amid all of those discussions concerning the seizure of XSS, it&#8217;s that Ukrainian and French authorities now have a number of years value of personal messages between XSS discussion board customers, in addition to contact rosters and different person knowledge linked to the seized Jabber server.<\/p>\n<p>\u201cThe parable of the \u2018trusted individual\u2019 is shattered,\u201d the person \u201cGordonBellford\u201d cautioned on Aug. 3 in an Exploit discussion board thread that spans dozens of pages. \u201cThe discussion board is run by strangers. They obtained all the things. Two years of Jabber server logs. Full backup and discussion board database.\u201d<\/p>\n<p>GordonBellford continued:<\/p>\n<blockquote>\n<p>And the scariest factor is: this knowledge array is not only an archive. It&#8217;s materials for evaluation that has ALREADY BEEN DONE . With the assistance of recent instruments, they see all the things:<\/p>\n<p>Graphs of your contacts and exercise.<br \/>Relationships between nicknames, emails, password hashes and Jabber ID.<br \/>Timestamps, IP addresses and digital fingerprints.<br \/>Your distinctive writing fashion, phrasing, punctuation, consistency of grammatical errors, and even typical typos that may hyperlink your accounts on completely different platforms.<\/p>\n<p>They don&#8217;t seem to be searching for a needle in a haystack. They merely sifted the haystack via the AI sieve and obtained ready-made dossiers.<\/p>\n<\/blockquote><\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>On July 22, 2025, the European police company Europol mentioned a long-running investigation led by the French Police resulted within the arrest of a 38-year-old administrator of XSS,\u00a0a Russian-language cybercrime discussion board with greater than 50,000 members. The motion has triggered an ongoing frenzy of hypothesis and panic amongst XSS denizens concerning the id of [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":5344,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[3361,2782,4530,262,4529,211,2456],"class_list":["post-5342","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-arrested","tag-crime","tag-forum","tag-krebs","tag-raid","tag-security","tag-xss"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/5342","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=5342"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/5342\/revisions"}],"predecessor-version":[{"id":5343,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/5342\/revisions\/5343"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/5344"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=5342"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=5342"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=5342"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-06-13 15:21:42 UTC -->