ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP...

Record ID: ANTI-LARP
Handle(s): @skidboss, @compress
Status: Active
First Observed: 2024-08-09 (Based on available records)


Summary

ANTILARP is a highly active and technically proficient cyber threat actor, data broker, and tool developer operating primarily within underground Telegram communities. Operating largely as a “one-man army,” ANTILARP specializes in high-value database exfiltration, cryptocurrency-targeted social engineering, and the automation of exploit chains.

The actor is known for integrating advanced artificial intelligence (including jailbroken LLMs like custom-configured DeepSeek and Mistral models) into his workflow to generate exploits, parse massive datasets, and automate network intrusions. His capabilities span web exploitation (SSRF, RCE, auth-bypass), cloud infrastructure compromise (AWS S3, Azure, GCP metadata endpoints), and telecom social engineering (SIM swapping, 2FA bypass). ANTILARP is a prominent vendor of corporate credentials, KYC (Know Your Customer) documents, and cryptocurrency exchange databases.

While the actor frequently employs highly controversial, hyperbolic, and provocative language as part of a carefully maintained online persona, threat intelligence indicates a sophisticated underlying methodology focused on financial gain.


Aliases


Affiliations


Timeline



Evidence

Ref Source Date Notes
[1] Chat Logs 2024-10-02 Actor details his TTPs, including manipulating cloud metadata endpoints (169.254.169.254), DCSync attacks, and payment gateway race conditions.
[2] Chat Logs 2025-01-30 Actor claims to utilize DeepFaceLab and high-quality ID templates to bypass video liveness checks for cryptocurrency exchanges.
[3] Chat Logs 2025-02-15 Actor explicitly claims to have dumped the backend KYC databases for Transak and Fractal.
[4] Chat Logs 2025-05-31 Actor drops functional Python/PyQt5 source code for “CITRIX_VAMP,” a multi-threaded vulnerability scanner and cookie extractor.
[5] Chat Logs 2025-09-17 Actor posts a TruffleHog scan output demonstrating the extraction of Azure Storage Account keys and environment variables.

Notes


Record created: 2026-05-06.