764 & Its Offshoots / "com" / Internet Extortion Groups - A decentralized extortion community filled with pedophiles, degenerates and larpers on Discords and Telegram chats

A website named "Statewins" appears to be operating with even greater depravity, offering a blackmailing service - provided by a person (or group) named "NoFear". They have explicitly claimed they will blackmail "anyone except people that are tied to law enforcement and Military".

1783713463366.png

Victim.png

1783713756410.png

1783713778492.png

What are your thoughts on the relationship between StateWins and the author of the Sextortion Guide?
Sorry to dig up the dirt and quote an old post, I was scraping this thread to see whether Statewins had been mentioned. They claim to be in direct collaboration with that Libyan degenerate "Schutz", based on this I'd say the link is incredibly close. The website is open to "content submissions" in exchange for cash, which is of course, directly referenced in the Sextortion Guide. Someone out there with some more knowledge of this region could undoubtedly make a founding link between these two.

This website appears to have been running since 2018, under a variety of different names. Clearly, whoever/ whomever is running this group has been in either close orbit or direct cahoots with COM for a while now.

1783714918012.png
 
offering a blackmailing service - provided by a person (or group) named "NoFear". They have explicitly claimed they will blackmail "anyone except people that are tied to law enforcement and Military".
I was just looking into this last week.

From the way NoFear was described, I assume he has to be the one who wrote the sextortion guide. The guide mentioned how the author has interacted with all of the main sextorters and how he is the greatest out of all of them. He directly mentioned Starkylol, Snapgod, and Ruben, commenting on how they were caught.
A website named "Statewins" appears to be operating with even greater depravity
I have no idea how this website is even operating on the clearnet. Having a ,pk domain apparently makes your website untouchable.
This website appears to have been running since 2018, under a variety of different names. Clearly, whoever/ whomever is running this group has been in either close orbit or direct cahoots with COM for a while now.
I personally think these people only interacted with COM back when 764 was at its peak, considering that they have been doing this pre-764. Not many of them have been caught, so their OPSEC is much better compared to your average retarded edgy extorter.
 
Última edición:
Some more aliases of extorters:
KaharianSchutz
SlimReaper
StarSessions
Luigi Girls
Mr James
God of Godz
XxXstasy
New Dawn
Paul
Hemlock
Ragnar (Apparently watermarks and sells his content for an absurd price)
BigBertha (Either arrested or quit, unknown)


RealGirls (Matthew Falder, arrested)
Oblivion/Snapgod/Snapgodxyz (Lewis Edwards, arrested)
Starkylol (Andrew Venegas, arrested)
DiscreetGent (Philip Sobash, arrested)
MasterMo / Gollum (Apparently caught because they used their real phone number and emails for verifications. Beyond retarded)
 
From the way NoFear was described, I assume he has to be the one who wrote the sextortion guide. The guide mentioned how the author has interacted with all of the main sextorters and how he is the greatest out of all of them. He directly mentioned Starkylol, Snapgod, and Ruben, commenting on how they were caught.
I think this is a completely sensible connection to make. If NoFear (who appears to brand himself as MasterNF or Master No Fear) has been operating for as long as these websites boast, then I can imagine he's enough of a degenerate to write something long-form like the Sextortion Guide, under the illusion that he's completely untouchable.

Clearly, groups or individuals like Statewins are only inflating his ego by offering the sale of his services. That document is for sure full of degenerate ego.
If anyone can link these addresses to "NoFear", "NoFearGod", "MasterNoFear" or "MasterNF", then we have the author confirmed. But this is probably something for the alphabet boys.

The Ethereum address has 289 normal (external) transactions on record. 203 incoming transactions totalling 10.973105 ETH. 86 outgoing transactions totalling 15.267211 ETH - spanning 6 March 2024 to 10 June 2024. It'll be an expensive minefield trying to un-launder that shit, but it's clear they are now operating out of a new wallet - or have "retired".
 
I think this is a completely sensible connection to make. If NoFear (who appears to brand himself as MasterNF or Master No Fear) has been operating for as long as these websites boast, then I can imagine he's enough of a degenerate to write something long-form like the Sextortion Guide
The guide was first written near February 20th, 2024, given that the author wrote "Funnily enough, as I write this, just today Binance delisted Monero (XMR) from their platform"

The author states "The truth is, over the course of seven years, I have blackmailed more than 3,000 girls." and also, that "I show my face to every victim"

Statewins talks about his collaboration with sextortionists, and the guide states "There have been notable sextortionists in the past, and people frequently refer to them as sextortionist masterminds, as if they were among the very best sextortionists who have ever lived. However, not a single one of them was even close to being good, and I am able to say this with certainty because I have had direct interaction with each and every one of them."
under the illusion that he's completely untouchable.
His method of being completely untouchable:

Your PC (Real IP) -> Your PC (VPN IP) -> Remote Desktop Connection (Host IP) -> VMWare (Host IP) -> VMWare (VPN IP) -> PuTTy (Website Host IP) / Telegram (VMWare VPN IP)
It'll be an expensive minefield trying to un-launder that shit
The laundering method is as follows:

"Dirty Sextortion Money [BTC or ETH] (Exchanged) -> Intermediate XMR Wallet (Converted)-> XMR Wallet (Transferred & Then Exchanged) -> Clean Sextortion Money [BTC or ETH] (Converted)"

When transferring Monero, "it is crucial to wait between transfers and never transfer the exact or nearly exact amount that you received from exchange."
 
Your PC (Real IP) -> Your PC (VPN IP) -> Remote Desktop Connection (Host IP) -> VMWare (Host IP) -> VMWare (VPN IP) -> PuTTy (Website Host IP) / Telegram (VMWare VPN IP)
I can't imagine how painfully slow his connection must be, especially for video streaming. Might as well use a 56K modem. Not to mention getting capcha checked everywhere you go.
 
I can't imagine how painfully slow his connection must be, especially for video streaming. Might as well use a 56K modem. Not to mention getting capcha checked everywhere you go.
Imagine just not going in purely on naked IP without browser safety check, firewall rules, or antivirus. Go gigachad retard level of OPSec because it's so fucking stupid that no one will expect it.

To further Gigachad retard it, do it publicly, like a library, airport, or directly at the police station.
 
A website named "Statewins" appears to be operating with even greater depravity, offering a blackmailing service - provided by a person (or group) named "NoFear". They have explicitly claimed they will blackmail "anyone except people that are tied to law enforcement and Military".
Where do you report these people's UI, LS to the proper authorities? Which everyone should do. I know when I posted interact with the Lowell Cows, but I think there's an exception when people are hosting actual CP. On the main part of the Internet.
Feel free to write a report. I already wrote one about this website. Disgusting shit.
 
Última edición:
However, not a single one of them was even close to being good, and I am able to say this with certainty because I have had direct interaction with each and every one of them.
This would certainly bridge the gap between the advertisement of the Blackmail Service, noting that their degenerate of choice has worked with other infamous extortionists. Assuming that the author is only referring to those who went by a moniker - and not claiming that they personally have interacted with thousands of perpetrators.
When transferring Monero, "it is crucial to wait between transfers and never transfer the exact or nearly exact amount that you received from exchange."
I had a look through the transactions, and they do appear to be using this exact method. Not being too crypto-savvy myself, I struggle to make sense of the data. If anyone wants the CSV I can drop it.
Where do you report these people's UI, LS to the proper authorities?
I typically opt for the usuals. The domain hosting services, Cloudflare (if applicable), FBI tip line, Europol, and IWF. This website's existence in itself is an outrage, besides it being live on the surface web.

To make matters worse, through a Google dork for "Statewins" - I was suggested an archived Statewins page advertising the sale of "content" including "Gabrielle Nelson" (the crackhead-looking woman who appears in this thread's banner). This was once on the surface web; it's a travesty that it's going undetected to such an extent that it could not only be live at one stage, but archived at another.

I reported the archive through the means above. I've truthfully got no idea whether it's still live - and I honestly don't care to find out. There is absolutely no chance in hell I am clicking on that. But there are two things to take from this: internet reporting means are frustratingly useless and slow at actually resolving these problems at a sufficient pace condusive to the severity of the crimes being committed - and Statewins, in whatever capacity, has a real-time involvement in the com sphere.
I can't imagine how painfully slow his connection must be, especially for video streaming.
"I am your master now"

1784064894136.png
 
There was a school shooting in Tacloban, Philippines influenced by 764.
An online account using the name “Sedykh Ryazanov” might have groomed the students to carry out the attack in Tacloban and potentially had links to 764, according to Hontiveros.
FBI is looking for more victims of Ryan Catello, and released more pictures of the freak:
IMG_0634.webp IMG_0633.png IMG_0632.png
He went by "MorsRium" and "VasylHellerium"
Screenshot_20260714_214601_Chrome.jpg
This channel has chatlogs from Ryan:
 
I can't imagine how painfully slow his connection must be, especially for video streaming. Might as well use a 56K modem. Not to mention getting capcha checked everywhere you go.

I'd like to discern fiction from reality with this. It's highly unlikely that they actually practice the opsec they postulate. It's a common skid power fantasy to posture that you're "invisible" and elusive to authorities because "I'm behind 8 different proxies!" When in reality we all know that most criminals rarely get caught because the VPN, Tor or the technology itself fails, it's always outside factors like sending your face pic to impress a egirl whore on telegram.

Another fairly good indicator of him being full of shit is specifically the last two parts of his procedure:
Remote Desktop Connection (Host IP) -> VMWare (Host IP) -> VMWare (VPN IP) -> PuTTy (Website Host IP) / Telegram (VMWare VPN IP)
I call your bluff. I doubt the cheap VPS/RDP providers, hosted in shit hole countries, that they rent out to you using XMR, offer this feature, I'm even more certain that they're certainly not operating over/on major cloud VPS providers like Digital Ocean, they use offshore hosting or something similar to that. If you've ever used Qubes OS, which is powered by the Xen hypervisor, you'd know they explicitly have this nested virtualization as a feature disabled (whether by choice or technical limitation, I'm not entirely sure.)

1784109878667.png


Is it possible that this person after all does practice what he preaches, yes of course it is. And the author behind it does seem to be opsec conscious, indicated by his awareness of how timing correlation techniques can be used against cryptocurrencies like BTC to establish patterns that can uncover someones identity, and awareness of XMR.

But again, how many times have we heard them espouse this cope/fantasy ad nauseam? "I'm the mastermind," "I'm behind 12 proxies, you can never catch me bro," "bro I run mullvad VPN lol nice try getting my IP," "I'm an undoxable hacker genius god," and then 4 months later they get pinned by the authorities because they sent a photo of their rolex that they obtained with criminal proceeds to brag, or they registered telegram with their personal phone number. It's always like this, seriously. The technology never fails you, it's always you that fails you.

Don't mean to sperg over this, just wanted to cast some doubt over this claim and poke some holes in it.
 
And the author behind it does seem to be opsec conscious
Here are some other OPSEC related things he talks about:

"DEVICE: Samsung Smartphone (OneUI) Samsung phones would be the ideal choice for sextortion activities. Samsung's design and features lend themselves well to such activities, making them highly suitable for those who engage in sextortion."

"As for where to store your physical M-DISCs when the sextortion content is stored, you should never store them anywhere inside your house, even if they are hidden. It is recommended to store your physical M-DISCs in a secure off-site location, such as burying them in a plastic zip bag in your backyard or at a trusted friend or family member's house."

"I personally use Mullvad; it's cheap, anonymous login information; you do not need to use an email or password; it has obsfucation, meaning your ISP cannot even see you are using a VPN, multi-hop, and quantum secure tunnel."

After cleaning his sextortion money, he uses Bitrefill to purchase giftcards, saying it is "the best way to spend your sextortion money, and it is the one I personally use myself."
I call your bluff. I doubt the cheap VPS/RDP providers, hosted in shit hole countries, that they rent out to you using XMR, offer this feature
"When buying RDP service, you will have to make sure to buy an expensive one that has VT-enabled. Once you own an RDP, you cannot use a VPN to mask your RDP IP address. If you try to do so, your RDP PC will continue to work, but you will not be able to connect and use it since the IP address changed due to you using a VPN. This is why VT-enabled RDPs are crucial, because this is where Virtual Machine come in."
 
Here are some other OPSEC related things he talks about:

"DEVICE: Samsung Smartphone (OneUI) Samsung phones would be the ideal choice for sextortion activities. Samsung's design and features lend themselves well to such activities, making them highly suitable for those who engage in sextortion."

"As for where to store your physical M-DISCs when the sextortion content is stored, you should never store them anywhere inside your house, even if they are hidden. It is recommended to store your physical M-DISCs in a secure off-site location, such as burying them in a plastic zip bag in your backyard or at a trusted friend or family member's house."

"I personally use Mullvad; it's cheap, anonymous login information; you do not need to use an email or password; it has obsfucation, meaning your ISP cannot even see you are using a VPN, multi-hop, and quantum secure tunnel."

After cleaning his sextortion money, he uses Bitrefill to purchase giftcards, saying it is "the best way to spend your sextortion money, and it is the one I personally use myself."

"When buying RDP service, you will have to make sure to buy an expensive one that has VT-enabled. Once you own an RDP, you cannot use a VPN to mask your RDP IP address. If you try to do so, your RDP PC will continue to work, but you will not be able to connect and use it since the IP address changed due to you using a VPN. This is why VT-enabled RDPs are crucial, because this is where Virtual Machine come in."

Thank you for providing further details. I don't have access to the sextortion guide myself - something to do with being a normal person and whatnot. (Not to say that those in here who are in possession of it are, when the intent is purely investigative.)

"DEVICE: Samsung Smartphone (OneUI) Samsung phones would be the ideal choice for sextortion activities. Samsung's design and features lend themselves well to such activities, making them highly suitable for those who engage in sextortion."

This is somewhat odd. I'm not entirely sure when this guide came out, but I'm going to guess around ~2020-2021 (?), and I can only assume that around that time GrapheneOS wasn't very known, a simple Google Pixel with GrapheneOS installed easily triumphs over a stock Samsung phone with its restrictive and privacy-evasive ROM, when it comes to its privacy-enhancing features. I don't have that much to add to this, sorry.

"As for where to store your physical M-DISCs when the sextortion content is stored, you should never store them anywhere inside your house, even if they are hidden. It is recommended to store your physical M-DISCs in a secure off-site location, such as burying them in a plastic zip bag in your backyard or at a trusted friend or family member's house."

This is actually quite fascinating, I will say I don't know exactly how inconspicuous ordering, and having mountains of M-DISCs for long term storage is, but I'm going to assume it works for them?


To digress somewhat from the topic at hand, it is fairly interesting to see the different methodologies these different 'COM' groups have when it comes to archiving their stolen or coerced '''data.'''

Members of Lapsus$, another one of these adjacent but defunct hacker com groups, were known to be terrified of storing the data they exfiltrated locally on their machines because of the possibility that the police would discover aforementioned procured data in a police raid. (Which unsurprisingly backfired on them.)

One remarkable aspect of LAPSUS$ was that its members apparently decided not to personally download or store any data they stole from companies they hacked. They were all so paranoid of police raiding their homes that they assiduously kept everything “in the cloud.” That way, when investigators searched their devices, they would find no traces of the stolen information.


But this strategy ultimately backfired: Shortly before the private LAPSUS$ chat was terminated, the group learned it had just lost access to the Amazon AWS server it was using to store months of source code booty and other stolen data.


“RIP FBI seized my server,” Amtrak wrote. “So much illegal shit. It’s filled with illegal shit.”

We also see the opposite approach, with the recent Scattered Spider indicted 'member,' Peter Stokes, we can see that he preferred a more physical approach to storing his purloined data. As when the Finnish police at the Helsinki airport managed to arrest him, they seized two 2TB hard drives he was in possession of, which is most definitely contained the data he was using to victimize companies with (lol).

The retailer refused to pay, evicted the intruders, and spent at least $2 million cleaning up. According to those records, Finnish officers seized two 2-terabyte hard drives when they stopped Stokes at Helsinki airport as he tried to board a flight to Japan.



"When buying RDP service, you will have to make sure to buy an expensive one that has VT-enabled. Once you own an RDP, you cannot use a VPN to mask your RDP IP address. If you try to do so, your RDP PC will continue to work, but you will not be able to connect and use it since the IP address changed due to you using a VPN. This is why VT-enabled RDPs are crucial, because this is where Virtual Machine come in."

And yeah I guess this proves it then, they really are renting out expensive RDPs with VT-enabled, absolutely bewildering. But I think my point largely stands on its own, most of these extortionists definitely aren't doing this. It costs money and is really inconvenient.

If you try to do so, your RDP PC will continue to work, but you will not be able to connect and use it since the IP address changed due to you using a VPN. This is why VT-enabled RDPs are crucial, because this is where Virtual Machine come in."

This part is particularly funny, because it reveals that his entire reason for performing nested virtualization is because he's too stupid to figure out how to make it so the VPN doesn't traffic ALL RDP through the encrypted tunnel, including services that are listening to or binded to specific ports. You've probably experienced this issue yourself when you tried doing any sort of web scraping from a cheap VPS and decided to use your VPN as a cheap way to circumvent rate limiting. There's tons of workarounds for this on Linux, they mostly involve creating/writing exceptions policies and writing a few iptable rules to prevent you from being disconnected once the VPS connects to the VPN. Admittedly, I don't know exactly how you'd go about doing it on a Windows machine, but I'm confident there's ways around it and his entire approach is super cumbersome, it's not even to there with the intention to prevent a host-based compromise or anything.
 
Última edición:
RealGirls (Matthew Falder, arrested)
Falder in some ways was a standout case, not brown, upper middle class, apparently well-liked, if the little info we have of him is true. I can’t help but to think how common this is among guys like this, they know how wrong what they’re doing is, so they end up telling someone about it in certain ways, direct or indirectly. IMG_9073.jpeg

Falder was active for about 10 years doing this, makes you wonder how many other similar guys are out there. And in typical British fashion, they reduced his sentence by quite a bit. Thank God he was actually British so they didn’t just give him a slap on the wrist.
 
After cleaning his sextortion money, he uses Bitrefill to purchase giftcards, saying it is "the best way to spend your sextortion money, and it is the one I personally use myself."
They arrested some hacker in the UK with millions in his wallet because this exact reason (maybe not the same site, I don't know). The retard bought giftcards connecting him with the hack, and then used them to order food to his own house. It only adds an extra hop, but if you're using the giftcards yourself, it's only a matter of time before they track you down. I am sure there are ways to mitigate this, but they probably include risks. It does not seem like a very scalable method to cash out important sums of money.
 
They arrested some hacker in the UK with millions in his wallet because this exact reason (maybe not the same site, I don't know). The retard bought giftcards connecting him with the hack, and then used them to order food to his own house. It only adds an extra hop, but if you're using the giftcards yourself, it's only a matter of time before they track you down. I am sure there are ways to mitigate this, but they probably include risks. It does not seem like a very scalable method to cash out important sums of money.
I believe you're talking about 'Operator,' otherwise known as Earth2Star, Everlynn, etc. You're correct in that one of the things the feds brought up was the cryptocurrency tx history being used to spend money on takeouts and gift cards, but he was essentially unmasked/doxed as early as the Lapsus$ days by his autistic, low IQ (like clinically), member 'White'.

The leader of LAPSUS$ responded by gleefully posting Asyntax’s real name, phone number, and other hacker handles into a public chat room on Telegram:

1784378986982.png


He was underage at the time, or had just turned 18? Therefore extraditing him, or getting a lengthy sentencing would be difficult. So they chose to sit on the evidence and strike once the time was right.
 
Atrás
Top Abajo