Record ID: ANTI-LARP
Handle(s): @skidboss, @compress
Status: Active
First Observed: 2024-08-09 (Based on available records)
ANTILARP is a highly active and technically proficient cyber threat actor, data broker, and tool developer operating primarily within underground Telegram communities. Operating largely as a “one-man army,” ANTILARP specializes in high-value database exfiltration, cryptocurrency-targeted social engineering, and the automation of exploit chains.
The actor is known for integrating advanced artificial intelligence (including jailbroken LLMs like custom-configured DeepSeek and Mistral models) into his workflow to generate exploits, parse massive datasets, and automate network intrusions. His capabilities span web exploitation (SSRF, RCE, auth-bypass), cloud infrastructure compromise (AWS S3, Azure, GCP metadata endpoints), and telecom social engineering (SIM swapping, 2FA bypass). ANTILARP is a prominent vendor of corporate credentials, KYC (Know Your Customer) documents, and cryptocurrency exchange databases.
While the actor frequently employs highly controversial, hyperbolic, and provocative language as part of a carefully maintained online persona, threat intelligence indicates a sophisticated underlying methodology focused on financial gain.
@antilarp — Primary Telegram handle@skidboss — Telegram handle used for business and data brokering@compress — Telegram handle used for data brokering and private inquiriesdongle / [email protected] — Legacy alias and associated contact emailantifart — Satirical/trolling alias used in community chats2024-08-09 — First documented activity within the provided dataset.2025-02-15 — Claims successful compromise and exfiltration of the Transak and Fractal KYC engine databases.2025-05-31 — Publicly releases a custom Python-based exploitation tool named “CITRIX_VAMP” for automated Citrix gateway cookie-bleeding.2026-05-06 — Last known activity, actively communicating in underground group chats.| Ref | Source | Date | Notes |
|---|---|---|---|
| [1] | Chat Logs | 2024-10-02 | Actor details his TTPs, including manipulating cloud metadata endpoints (169.254.169.254), DCSync attacks, and payment gateway race conditions. |
| [2] | Chat Logs | 2025-01-30 | Actor claims to utilize DeepFaceLab and high-quality ID templates to bypass video liveness checks for cryptocurrency exchanges. |
| [3] | Chat Logs | 2025-02-15 | Actor explicitly claims to have dumped the backend KYC databases for Transak and Fractal. |
| [4] | Chat Logs | 2025-05-31 | Actor drops functional Python/PyQt5 source code for “CITRIX_VAMP,” a multi-threaded vulnerability scanner and cookie extractor. |
| [5] | Chat Logs | 2025-09-17 | Actor posts a TruffleHog scan output demonstrating the extraction of Azure Storage Account keys and environment variables. |
Record created: 2026-05-06.