Record ID: ACT-1077
Handle(s): AttackLibrarian, @atklib
Status: Active
First Observed: 2024-02-15
AttackLibrarian is an online cyber and OSINT-adjacent actor observed across Telegram-centered hacker, OSINT, shitposting, and private social groups. The logs present her as technically literate, socially embedded, abrasive, funny, hostile to “AI slop,” and comfortable operating in the messy overlap between security talk, trolling, harassment, counter-extremist OSINT, and cyber bravado. Her handle is somewhat literal-adjacent but not literal: she states that she is not a librarian, though she “went to school for library science.”
AttackLibrarian’s strongest documented traits are technical curiosity, OSINT fluency, social confidence, and a sharp sense for adversarial dynamics. She discusses link analysis, data visualization, realistic sockpuppet construction, FCC technical filings, canary tokens, OSINT tooling, and operational security with enough specificity to suggest real familiarity, though not every claim is independently verifiable from the logs.
Her most controversial pattern is not merely offensive speech, although there is plenty of that. More significant is the recurring mix of harassment, humiliation, claimed compromise of adversaries, and self-framing as someone enforcing consequences. In one exchange, she says “we don’t swat,” claims an adversary attempted extortion and swatting, then says she had apologized for harm while also describing “torturing” that person as a “necessary evil.” The logs do not independently confirm the underlying allegations, but they do document AttackLibrarian’s own posture: part grievance, part accountability campaign, part vendetta with a helpdesk ticketing system.
AttackLibrarian is also repeatedly associated with malicious-PDF lore. She states that she has “a reputation for malicious PDF’s,” claims she once rooted a target’s laptop with a poisoned PDF, and later describes GrapheneOS/OS-wipe-resistant access in ways that may be technical boasting, actual compromise, or performative intimidation. The available logs are one-sided, so these should be treated as claims by AttackLibrarian, not confirmed forensic findings.
Her public style is direct to the point of being corrosive. She uses racial, homophobic, ableist, and misogynistic insults repeatedly; some appear as ambient chan-style profanity, others as targeted abuse. At the same time, the logs also show flashes of loyalty, ordinary warmth, self-awareness, and restraint: she thanks friends, tells people to “be nice,” admits discomfort at some bullying, and occasionally demands evidence rather than rumor. The result is not a clean villain or folk hero. It is a competent, volatile, socially influential shitposter with technical chops, a mean streak, and a strong preference for making conflicts everyone else’s problem too.
AttackLibrarian — primary record handle; exact handle not directly shown in the provided log excerpts, but supplied as the article subject.@atklib — self-identified handle in SiegedSec Cult; also referenced as a possible Twitter/X handle.Sava — probable former nickname or handle; AttackLibrarian says people still called her “Sava” by phone, and separately refers to a “Sava original.” Context supports this as an older identity marker, but not enough to treat it as a confirmed platform alias.2024-02-15 — Earliest entry in the provided logs, a low-context command in “я€ďďɨ$h €ąǥℓ€ ƒ๏яµʍ.” This establishes earliest logged activity, not a meaningful profile by itself.2024-08-14 — Early substantive OSINT Kitties activity appears; by this point her trolling style and identity commentary are already visible.2024-08-20 — Discusses constructing a realistic LinkedIn sockpuppet using an AI-generated profile image edited for imperfections.2024-08-26 — Asks about link-analysis tooling and describes data visualization/analysis as a way to chart disparate data points.2024-09-10 — Gives practical advice on locating FCC and CMIIT filings for device radio/technical data.2024-12-11 — Describes a project involving mapping far-right actors, gathering PII, and using the data to explore connections for infiltration and shutdown efforts. This is a self-described activity, not independently verified.2025-01-12 — Provides a narrative of her account history: starting in SiegedSec chat, becoming early in OSINT Kitties, and encountering Epi through discussion of ShadowDragon’s SocialNet software.2025-01-30 — Claims API abuse and account-ban capability, including getting an account banned “in less than 8 minutes.”2025-08-28 — Claims rootkit access against an adversary’s devices and jokes about the target’s paranoia. Treat as AttackLibrarian’s claim, not verified compromise.2025-10-04 — Says she initially rooted a target’s laptop with a poisoned PDF, while denying that her channel’s shared material is tainted.2026-03-26 — In a direct conflict with an adversary, denies swatting, alleges extortion/swatting by the other party, admits causing harm, and frames her conduct as accountability.2026-03-27 — Enforces “No AI slop,” calls it a group rule, and claims past network-engineering experience as authority for the judgment.2026-04-16 — Mentions preparing materials for parallel teams doing “CTF’s, but psyops,” with concepts restated from FM 3-05.301.2026-05-07 — Self-identifies in SiegedSec Cult as “atklib.”2026-05-11 — Last observed logged activity in the provided file.| Ref | Source | Date | Notes |
|---|---|---|---|
| [1] | Telegram log export | 2024-02-15 | Earliest observed entry in the provided logs; low-context command only. |
| [2] | OSINT Kitties | 2024-08-20 | Discusses realistic sockpuppet construction using edited AI-generated profile imagery. |
| [3] | OSINT Kitties | 2024-08-26 | References link analysis, Maltego/i2, data visualization, and disparate-data mapping. |
| [4] | SiegedSec Cult | 2024-09-10 | Advises on FCC ID and CMIIT filings for phone technical data. |
| [5] | GANZIR CITY | 2024-12-11 | Describes mapping far-right actors and connections for infiltration/shutdown efforts. |
| [6] | Heavy Muthafuckin Money | 2025-01-12 | Gives a self-history involving SiegedSec, OSINT Kitties, Epi, and ShadowDragon SocialNet. |
| [7] | Heavy Muthafuckin Money | 2025-01-30 | Claims API abuse and rapid account-ban capability; framed boastfully. |
| [8] | Open Source Idiocy Task Force | 2025-10-04 | Claims poisoned-PDF/rootkit activity against a target while denying that shared channel material is tainted. |
| [9] | Open Source Idiocy Task Force | 2026-03-26 | Conflict exchange showing denial of swatting, claims against an adversary, apology for harm, and “necessary evil” framing. |
| [10] | Open Source Idiocy Task Force | 2026-03-27 | States “My group, my rules,” enforces “No AI slop,” and claims network-engineering background. |
| [11] | Open Source Idiocy Task Force | 2026-04-16 | Discusses psyops-style CTF materials and FM 3-05.301-derived concepts. |
| [12] | SiegedSec Cult | 2026-05-07 | Self-identifies as “atklib.” |
The logs are one-sided and contain AttackLibrarian’s messages, not full conversations. Claims about other people, compromises, motives, extortion, swatting, law-enforcement contact, and technical access should therefore be attributed to AttackLibrarian unless independently corroborated elsewhere.
The clearest supported picture is of a technically literate OSINT/cyber-adjacent operator with real community presence and apparent moderator authority in at least one group. The same record also shows repeated cruelty, slurs, harassment rhetoric, and self-satisfied escalation. Her habit of demanding evidence while casually making severe claims about others is one of the record’s sharper contradictions.
AttackLibrarian’s “malicious PDF” reputation is supported as a reputation she acknowledges and amplifies. The logs do not provide forensic evidence that the claimed payloads, rootkits, or persistence mechanisms worked as described. As demonstrations of tactical restraint go, publicly narrating “white-glove concierge harassment” does not rank among the cleaner specimens.
Private personal details present in the logs are omitted here unless directly relevant to the handle, record identity, or documented public conduct. The article uses she/her pronouns per supplied editorial direction.
Record created: 2026-05-12.