Baptiste Robert Profile picture
Feb 21, 2024 19 tweets 10 min read Read on X
Ivan Gennadievich Kondratyev, a.k.a. “Bassterlord” has been added to OFAC's SDN list

It gives us an email address. It's time for an investigation. THREAD ⬇️ ofac.treasury.gov/recent-actions…
Image
Who is Bassterlord ?

According to Jon Di Maggio from @Analyst1:
- Bassterlord is a ransomware affiliate who runs his team, known as the National Hazard Agency. Originally, he was a junior. team member, but as time progressed, he moved up the ranks and is now its leader.

- Bassterlord partnered with at least four ransomware gangs: REvil, RansomEXX, Avadon and LockBit.

- Bassterlord is a Caucasian male around 27 years old, born, raised, and living in Lugansk, Ukraine. He operates on Russian underground forums under the monikers “Fisheye,” “Bassterlord,” “Buster,” and “National Hazard Agency,” which is also the name of his team.

analyst1.com/ransomware-dia…Image
@Analyst1 First things first, I searched the email sinner4iter@gmail.com on . It gives us a lot of online profiles. predictasearch.com
Image
@Analyst1 In the data breaches tab of the report, we can see that his email was in a Twitter leak. It gives us his Twitter handle @It9111 predictasearch.com

Image
Image
@Analyst1 @It9111 A phone number linked to this email can be found in another leak. Time to pivot.
@Analyst1 @It9111 The email is also in the 000webhost leak (2015) and it gives the following location (48.511,38.6722) in Bryanka, Luhansk Oblast, Ukraine
Image
Image
@Analyst1 @It9111 In the report, we can also see the phone hint of the Apple account linked to this email. It's probably the same phone mentioned before (both ends with 38) predictasearch.com

Image
@Analyst1 @It9111 Also, he has a profile linked to this email

It gives a date of birth, location and one of his previous school. ok.ru
ok.ru/profile/594933…
Image
@Analyst1 @It9111 A user with the same name than the profile (Koyerd Uhvwi) leaves a review about a dental clinic in Новомосковск ok.ru
novomoskovsk.fooby.ru/company/stomat…

Image
Image
@Analyst1 @It9111 The profile states that he lives in Алексинский район. The dental clinic address is Россия, Тульская область, Новомосковск, Комсомольская улица, 36/14, 1 этаж.

This is pretty close ok.ru
@Analyst1 @It9111 In multiple leaks his personal address is available: Россия, Тульская обл, Новомосковский р-н, г Новомосковск, 301664, Маяковского ул, д. 10/2, кв. 59

And yes, it's a 12 min walk to go the dental clinic
Image
@Analyst1 @It9111 This is why I love #OSINT. Look that, this is cool af.

In multiple online profiles our guy used the name "Koyerd Uhvwi". If you search this name, you find this Youtube channel : youtube.com/@koyerduhvwi37…
Image
@Analyst1 @It9111 If you go to the playlist tab, you will find an unlisted video. Look who has a nice new Lockbit tatoo!
@Analyst1 @It9111 It's not finished. I have a lot of photos. Trying to confirm before publication
He had a lot of info on his (now deleted) VK profile. The names and dob are identical to what we found in the leaks previously Image
He had a good time during the summer in 2016


Image
Image
Image
Image
Our guy was looking for love. Face, name, age and region are consistent with what we found before за30.рф/page/89977ttxw…
Image
With the help of the @PredictaLabOff relational graph, we mapped (almost) all the info found in this thread Image
@PredictaLabOff I will end the thread here. It was a fun ride. END

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with Baptiste Robert

Baptiste Robert Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @fs0c131y

Jan 19
The IP address of DrugHub, a well-known dark web drug marketplace, has been exposed.

The website owner made a critical OPSEC blunder.

It's OPSEC time!
On the website's /info/market-links page, three links are provided:
- The primary .onion address
- A clearnet link
- A permanent mirror Image
Currently, drughub[.]xx is protected by Cloudflare, but two months ago, it was hosted on the IP address 186.2.171.6. Image
Image
Read 9 tweets
Jan 14
Worried about a TikTok ban? Americans are now flocking to Xiaohongshu (REDnote), another Chinese app.

Spoiler: Yes, it tracks its users.

Time to dive in! ⬇️ Image
When creating an account, you must verify your phone number by entering a code received via SMS.

The request sent to Xiaohongshu's server includes your phone number (of course), along with your IDFA and IDFV. Image
Image
What’s an IDFA? The Identifier for Advertisers (IDFA) is a unique device ID assigned by Apple to every iOS device.

Many actors, like data brokers, use it to profile you, track your location, and more.

Read 13 tweets
Jan 10
Only one country was represented at Kim Jong Un's New Year's Eve party. Can you guess which one?

At the Rungrado Stadium, Kim hosted a grand celebration. Before the fireworks, officials enjoyed a private party near the stadium

One attendee's face stood out 🕵️‍♂️

It’s OSINT time!
South Korean media focused on a 2-second clip of Kim Yo Jong, Kim Jong Un's sister, seen publicly with what seemed to be her children for the first time.

But they missed something important 👀
I came across the official video of the private party before the celebration. It shows key figures stepping out of their cars, mingling, and chatting around tables.

Something immediately caught my eye. Do you see it too?
Read 17 tweets
Jan 8
Hackers claim to have breached Gravy Analytics, a US location data broker selling to government agencies.

They shared 3 samples on a Russian forum, exposing millions of location points across the US, Russia, and Europe.

It's OSINT time! 👇 Image
The samples include tens of millions of location data points worldwide.

They cover sensitive locations like the White House, Kremlin, Vatican, military bases, and more.

Time to dig in! Image
Image
Image
Visualizing such a massive amount of location data is no easy task.

Google Earth Pro crashed at 500k location points, and our OSINT platform hit its limit at 1.5 million. Even if it is "just" a sample, rendering the entire dataset at once is a real challenge. Image
Read 27 tweets
Dec 28, 2024
5 days ago, an Instagram account shared a video from North Korea with the caption: "A brave tourist secretly captures restricted views of downtown North Korea"

Can we geolocate this footage?

It's GEOINT time!
I paused the video to screenshot this pink building. A quick Google Lens search reveals two matching photos of the location:
- alamyimages.fr/un-agent-de-po…
- flickr.com/photos/tobeyfo… Image
Image
Image
Image
The second link includes a street name and points to this location: 39.00493900995318, 125.73642620392643. Image
Image
Read 11 tweets
Dec 23, 2024
On Friday, December 20, 2024, the U.S. DOJ charged Rostislav Panev, a dual Russian-Israeli national, as a LockBit ransomware developer. Arrested in Israel, he awaits extradition to the U.S.

It's OSINT time! Image
You know the drill: with predictasearch.com and predictagraph.com, I traced and mapped Rostislav Panev's complete digital footprint.

Explore the graph here: predictagraph.com/graph/snapshot… Image
First things first, here’s the official information available:
- DOJ Press Release: justice.gov/opa/pr/united-…
- Superseding Complaint: justice.gov/opa/media/1381… Image
Image
Read 14 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us!

:(