Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


Shells Virtual Desktop
BMail.ag - Secure Email Service
Server.net
CPLicense.net
VPS Server
Buy VPN
Vultr
VMs for AI
HostDare
ReliableSite White-Label Dedicated Hosting for Resellers
InterServer VPS
BMail.ag - Secure Email Service
Best VPN
High-Performance Bare Metal Server Solutions
Karvl.com
Server Mania Cloud Hosting
DataWagon Hosting
AlphaVPS Hosting
Evoxt.com
Clouvider
VPS Hosting with NVMe
Residential IPs in the US & 4G Mobile Proxies in EU & US with Unlimited Bandwidth
ReliableSite White-Label Dedicated Hosting for Resellers
Rabisu - Hosting Solutions
Shells Virtual Desktop
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

FBI seizes StarkRDP(and possibly RDP.sh)

kaitkait Member
edited January 2025 in News

Today, the FBI also seized the domains used by:

MySellIX (mysellix.io) and SellIX (sellix.io), two platforms that allowed users to create their own online stores, which threat actors also used to sell stolen data, software keys, and compromised accounts, and
StarkRDP (starkrdp.io), a Windows RDP virtual hosting provider that some threat actors allegedly used for credential stuffing attacks.

https://www.bleepingcomputer.com/news/security/fbi-seizes-domains-for-crackedio-nulledto-hacking-forums/ (archive)

cross-post via LES

StarkRDP and Sellix was operated by the same group of Germans as RDP.sh who I suspect is next to go.

https://bgp.tools/as/210558 is the network of RDP.sh

Imprints all pointing to Florian Marzahl/1337 Services GmbH


StarkRDP (archive)


RDP.sh (archive)



LinkedIn with Sellix (archive)

cross-post via LES

Thanked by 3HostSlick emgh oddmario
«13

Comments

  • This could be related with some hacking forums like nulled.to and others giving an error through CF?

    Thanked by 1kait
  • @sandoz said:
    This could be related with some hacking forums like nulled.to and others giving an error through CF?

    It is. Nulled.to, Cracked.io and Sellix.io also got seized at the same time. Looks like one big sweep.

    @kait said: Florian M

    @FlorinMarian What's up?

    Thanked by 3sandoz kait dilroopgill
  • @sandoz said: This could be related with some hacking forums like nulled.to and others giving an error through CF?

    First link in the post crossposted. (https://www.bleepingcomputer.com/news/security/fbi-seizes-domains-for-crackedio-nulledto-hacking-forums/)

    Thanked by 1sandoz
  • They finally seized Sellix?

  • @Obelous said:
    They finally seized Sellix?

    Yeah, just waiting on DNS to propegate the nameserver change XD, taking longer than 4 hours now I think.

  • olokeoloke Member, Host Rep

    Tor relays on RDP.sh remain operational: https://metrics.torproject.org/rs.html#search/as:AS210558

    I didn't realize they host almost 500 relays :open_mouth:

  • @oloke said:
    Tor relays on RDP.sh remain operational: https://metrics.torproject.org/rs.html#search/as:AS210558

    I didn't realize they host almost 500 relays :open_mouth:

    Yes rdp.sh is still working, and all the other stuff (sellix, nulled, cracked, starkrdp) is also working, the domains just got seized afaik.

  • @kait said:

    @oloke said:
    Tor relays on RDP.sh remain operational: https://metrics.torproject.org/rs.html#search/as:AS210558

    I didn't realize they host almost 500 relays :open_mouth:

    Yes rdp.sh is still working, and all the other stuff (sellix, nulled, cracked, starkrdp) is also working, the domains just got seized afaik.

    Because the domains are most likely just their first step.

    It's unclear if rdp.sh is even going to be affected though, the nameservers haven't been updated for the domain.

  • HostSlickHostSlick 🚩 Host Rep Tag Suspended

    Allowed crime on their servers or why?

  • @Obelous said: Because the domains are most likely just their first step.

    I hope so, + this guy is known, its not some anon alias.

  • @HostSlick said: Allowed crime on their servers or why?

    Yeah.

    Nulled/Cracked where hacking and cracking forums.

    Sellix was offering their payment processing services to them.
    MySellix was using Sellix and was an account shop for hacked/cracked/stolen accounts.
    Starkrdp was owned by rdp.sh and allowed/advertised cracking/checking accounts.
    rdp.sh and sellix are owned/ooperated by the same people.

    Thanked by 1loay
  • ObelousObelous Member
    edited January 2025

    Sellix was used for all types of illegal shit, they were one of the most well known places for buying and selling that type of stuff. Stolen accounts, bank accounts, identities, gift cards, booters, illegal tools, if you wanted something, a sellix store probably had it.

    There's a lot of similar sites as well, like shoppy, selly, etc.

    Thanked by 2kait oloke
  • olokeoloke Member, Host Rep

    @Obelous said:
    Sellix was used for all types of illegal shit, they were one of the most well known places for buying and selling that type of stuff. Stolen accounts, bank accounts, identities, gift cards, booters, illegal tools, if you wanted something, a sellix store probably had it.

    There's a lot of similar sites as well, like shoppy, selly, etc.

    I even thought about buying server from RDP.sh at one point. I believe their servers are located mostly in Poland, they have (/had) pretty clean website and rather affordable pricing.

    Didn't know they were affiliated with those kind of stuff.

  • Nice, waiting for krebs article.

    Thanked by 1kait
  • @Levi said:
    Nice, waiting for krebs article.

    Would be epik, haven't followed krebs in a while.

  • HostSlickHostSlick 🚩 Host Rep Tag Suspended


    REGUARDS

    i guess

    Thanked by 2kait suyadi92
  • LeviLevi Member
    edited January 2025

    Actually omnisia is in legal trouble, he just play hide and seek with feds. Hehe…

    Here is archive https://krebsonsecurity.com/tag/omniscient/

    Thanked by 2kait Blembim
  • Waiting for Mutahar from SomeOrdinaryGamers and Mental Outlaw videos on this lol

    Thanked by 2oloke giang
  • emghemgh Member, Megathread Squad

    @kait said:

    @Obelous said:
    They finally seized Sellix?

    Yeah, just waiting on DNS to propegate the nameserver change XD, taking longer than 4 hours now I think.

    Wasn't this the guys that looked for hosting here on LET where I shared some examples in their request thread to providers on the kind of stuff they actually host :D

    Thanked by 1ethanblake87
  • @emgh said: Wasn't this the guys that looked for hosting here on LET where I shared some examples in their request thread to providers on the kind of stuff they actually host :D

    If you can find that, that would be lovely, can't recall that.

    Thanked by 1emgh
  • emghemgh Member, Megathread Squad

    @kait said:

    @emgh said: Wasn't this the guys that looked for hosting here on LET where I shared some examples in their request thread to providers on the kind of stuff they actually host :D

    If you can find that, that would be lovely, can't recall that.

    I can't, already tried.

    Either it's been hidden/removed or I'm just confusing Sellix with one of those similar ones, there's been quite a few of them.

    Anyway, exciting stuff.

    Honestly suprised it took the FBI what feels like forever to shut some of those forums down. They've been around since forever. With that power and budget they don't seem very effective :D

    Thanked by 2kait ethanblake87
  • wadhahwadhah Member, Host Rep
    edited January 2025

    @emgh said:

    @kait said:

    @emgh said: Wasn't this the guys that looked for hosting here on LET where I shared some examples in their request thread to providers on the kind of stuff they actually host :D

    Honestly suprised it took the FBI what feels like forever to shut some of those forums down. They've been around since forever. With that power and budget they don't seem very effective :D

    I doubt they will shutdown for long if at all, they will just move domains

    Thanked by 1emgh
  • jarjar Patron Provider, Top Host, Veteran

    @HostSlick said:
    Allowed crime on their servers or why?

    Criminal activity and "RDP" in a hosting provider name go together like peanut butter and jelly.

  • @jar said: go together like peanut butter and jelly

    We as well I assume.

    Thanked by 1jar
  • “RDP” hmmm

  • @HostSlick said: REGUARDS

    Allegedly, HF complies with the feds. But both of the seized forums did the same (at least partially), so who knows.

  • emghemgh Member, Megathread Squad

    @wadhah said:

    @emgh said:

    @kait said:

    @emgh said: Wasn't this the guys that looked for hosting here on LET where I shared some examples in their request thread to providers on the kind of stuff they actually host :D

    Honestly suprised it took the FBI what feels like forever to shut some of those forums down. They've been around since forever. With that power and budget they don't seem very effective :D

    I doubt they will shutdown for long if at all, they will just move domains

    Don’t worry, the FBI will shut down the new domains in another 10 years

    Thanked by 1jsg
  • @emgh said: Honestly suprised it took the FBI what feels like forever to shut some of those forums down

    why take down a cybercrime forum when they know a replacement will take its place within days? better to keep it up and let skids incriminate themselves

    Thanked by 2emgh tentor
  • naphthanaphtha Member
    edited January 2025

    @jar said:

    @HostSlick said:
    Allowed crime on their servers or why?

    Criminal activity and "RDP" in a hosting provider name go together like peanut butter and jelly.

    this is why we don't have windows server images (besides legal concerns and me not wanting to have anything to do with m$)

    it filters out 99% of abusers because skids cant into linux

  • SwiftnodeSwiftnode Member, Patron Provider, LIR

    Sellix had a ton of "DDoS for Hire" and carding services operating blatantly, and their "abuse contact" was notified and did nothing for months.

    Not surprised.

Sign In or Register to comment.