| Record ID | ACT-0017 |
|---|---|
| Primary name | Yellow King |
| Observed handles | Yellow King, yellowking, @yellowking23, ssyellowking |
| Status | Active / recently observed |
| First observed in export | 2023-10-24 |
| Last observed in export | 2026-06-09 |
| Primary platform | Telegram |
| Primary role assessment | Telegram-native hacktivist organizer / community personality |
| Confidence level | Medium overall; high for identity continuity, lower for operational claims |
Yellow King is a Telegram-based hacker-community personality, organizer, and self-described leader associated with Scisan, Anonymous internationally, and BKB UNION. Across the logs he appears less like a silent advanced operator and more like a persistent social node: rebuilding after account bans, looking for old contacts, moving people into new channels, trying to keep chats active, recruiting coders, invoking Anonymous mythology, and framing hacker communities as a geopolitical force.
The strongest evidence supports describing him as a community builder with amateur-to-intermediate offensive-security exposure. He knows the vocabulary and public tools: Nmap, Dmitry, Burp Suite, Nikto, CVEs, OSINT resources, Shodan-like discovery, Proton/onion-mail discussions, and vulnerability scanning language. But the logs do not prove advanced exploitation capability. What they prove, much more clearly, is persistence, social reach, and a taste for grand narrative.
Yellow King’s operating style is relational and dramatic. He constantly uses brother, sister, friend, citizens, team, leader, mission, war, and betrayer language. This makes him good at keeping loose networks emotionally attached, but it also makes his claims noisy. He is a little bit organizer, a little bit myth-maker, a little bit student, a little bit Telegram mayor, and occasionally a walking OPSEC incident wearing a crown made of screenshots.
Yellow King should be assessed as:
Scisan and BKB UNION.He is not best described as a verified elite threat actor. A fairer read is: self-appointed mayor of a volatile hacker village — persistent, socially sticky, technically curious, overdramatic, occasionally useful, occasionally alarming, and very hard to ignore.
| Alias / Identifier | Type | Evidence / Notes |
|---|---|---|
Yellow King | Primary display name | Directly self-identifies as I am Yellow King in Major Fen Group on 2025-03-06. |
yellowking | Lowercase variant | Uses i am yellowking / I am yellowking brother in multiple chats. |
@yellowking23 | Telegram handle / contact point | Used in channel migration notices: users are told to contact @yellowking23 for the new channel link. |
ssyellowking | Cross-platform ID | On 2024-01-01, gives my id is ssyellowking while arranging a friend request and secret-group invite. |
Team Scisan | Claimed organization | On 2024-01-03, says people are from team scisan. Later claims founder/leader status. |
BKB UNION | Claimed organization / partner team | On 2025-03-06, says Leader of Team Scisan and BKB UNION. |
| Date | Venue | Message Anchor | Why It Matters |
|---|---|---|---|
| 2023-10-24 | Anonymous / Hacked Modz APK Chat | account bans, Kali issues, DDoS support limits | Earliest visible phase: identity recovery after account bans and basic technical setup problems. |
| 2023-10-24 | Hacked Modz APK Chat | ''sab ka name yellowking hi tha'' | Early identity continuity around the yellowking name. |
| 2023-10-30 | Anonymous internationally | ''i am your old friend yellowking'' | Clean early self-identification. |
| 2024-01-01 | Anonymous internationally | ''my id is ssyellowking'' | Cross-platform or alternate identity anchor. |
| 2024-01-03 | Anonymous internationally | ''from team scisan'' | Early Scisan organizational framing. |
| 2024-03-30 | Anonymous internationally | ''sci and san'' / ''san means sanskrit'' | Gives an origin story for the name Scisan. |
| 2024-04-16 | Anonymous internationally | ''I am yellow king'' | Direct identity anchor. |
| 2024-04-18 | Anonymous internationally | ''i am the founder of the team'' | Self-claim of founder status. |
| 2024-04-23 | Anonymous internationally | ''gain control of there systems'' / BIA Nmap output | Shows targeting language and public reconnaissance activity against bia.gov.rs. |
| 2024-04-25 | Anonymous internationally | ''i am founder'' / ''leader not boss'' | Shows preferred leadership framing. |
| 2024-05-24 | Scisan 2.0 | BKB testing/victim comment | Alarming operational rhetoric around BKB. |
| 2024-05-24 | Anonymous internationally | channel shifted to @yellowking23 | Shows continuity management and migration role. |
| 2024-06-02 | Anonymous internationally | channel shifted notice | Repeated migration control via @yellowking23. |
| 2024-06-10 | Anonymous internationally | channel shifted notice | Another migration-control anchor. |
| 2024-06-14 | Scisan 2.0 | anti-CSAM account deletion claim | Claimed anti-abuse action. Treat as self-report. |
| 2024-06-19 | Scisan 2.0 | ''uploaded many big website vuln'' | Self-claim of vulnerability posting in Scisan 1.0. |
| 2024-06-27 | Group Chat | ''i need coders'' / ''just i need coders'' | Recruitment behavior. |
| 2024-07-10 | Scisan 2.0 | Scisan one-year/logo announcement | Brand-building and group continuity. |
| 2025-03-06 | Major Fen Group | ''I am Yellow King'' / ''Leader of Team Scisan and BKB UNION'' | Strongest leadership self-claim. |
| 2025-03-06 | Major Fen Group | ''function mainly on real life'' / compartmented groups claim | Claimed private/offline organizational structure. |
| 2025-06-13 | Keymous Chat | whistleblowing campaign / infiltration rhetoric | Shows escalation beyond simple Telegram chatter. |
| 2026-06-09 | CHX CHATTING GROUP #3 | ''they are attacking us'' / Mossad/CIA claim | Current conspiracy/crackdown narrative. |
These counts are approximate parsed-message counts from the uploaded export. They indicate where this account appears most often, not formal membership rank.
| Venue | Approx. observed records | Notes |
|---|---|---|
Anonymous internationally | 5,859 | Core venue; heavy identity, group, moderation, and Scisan continuity material. |
Scisan 2.0 | 2,533 | Main self-branded venue; leadership, channel management, tool talk, and group maintenance. |
DDoSHome | Scam Expose | 1,025 | DDoS/hacker-adjacent participation and political targeting chatter. |
Group Chat 🙂 | 581 | Recruitment/coder-seeking and project-support discussion. |
LulzSec Chat | 544 | Networking and Anonymous/LulzSec-adjacent presence. |
Chat - Azzasec | 414 | Broader hacker-chat presence. |
CyberVolk. (chat) | 405 | Security-tool discussion and community contact. |
64Gram Chat | 214 | Telegram-client and forwarding/circumvention questions. |
Hacked Modz APK Chat | 198 | Earliest account-recovery/social identity phase. |
Anonymous | 176 | Early Anonymous identity and anti-Israel/pro-Palestine framing. |
CHX CHATTING GROUP #3 | 106 | Latest observed venue; 2026 crackdown/intelligence-agency narrative. |
Major Fen Group | 102 | Strongest leadership and high-risk rhetoric cluster. |
Affiliation here means observed participation, claimed association, or community proximity. It does not prove formal membership, command authority, or successful joint operations. Telegram is a soup. Do not pretend every noodle is a command structure.
The earliest visible phase is not glamorous. Yellow King appears in Hacked Modz APK and Anonymous spaces trying to reconnect with old friends, asking whether they recognize him, and describing multiple Telegram account bans. On 2023-10-24 he says his Telegram situation broke everything, that three accounts were banned, and that Kali/Linux tooling was throwing errors. He also says he cannot help with DDoS at that moment but remains supportive.
This matters because the first observed Yellow King is not presenting as an advanced operator. He is rebuilding identity, infrastructure, and social access after bans. The core pattern starts here: lose account, re-enter chat, find old brothers, restore links, restart the machine.
By 2023-10-29 and 2023-10-30, the language shifts toward revival. He says he wants to restart everything, that people are disappointed or tired, and that he decided to make them active. On 2023-10-30 he directly says i am your old friend yellowking. This is the first clean identity anchor in the export.
On 2024-01-01 he provides ssyellowking as an ID, asks for a friend request, and says he can add someone to a secret group. The same short sequence references multiple secret groups. Two days later, on 2024-01-03, he tells people they are his team people and from team scisan. This is an important transition: the account is no longer only recovering personal identity; it is attaching identity to a group mythology.
The January material also shows a trust-heavy social model. He talks about friends, team people, and trusted chats. That becomes a recurring pattern: Yellow King tries to solve instability by turning social relationships into structure.
On 2024-03-30 he gives an origin story for Scisan, saying it comes from sci and san, with sci meaning science and san meaning Sanskrit. He adds a language-development explanation and then jokes that he is leader. This is not just trivia; it shows how he mythologizes the group. The name is not treated as a random tag. It is given a civilizational explanation, because of course it is. Telegram groups apparently cannot just have names anymore; they require lore.
Around the same period he posts AI-generated explanation of exploit code and notes that ChatGPT was used. The content includes safety warnings from the AI about unauthorized exploitation. This is useful for technical assessment: he is learning, experimenting, and using AI/tooling support, but the logs suggest uneven technical maturity rather than independent advanced capability.
April 2024 is the first major escalation phase.
On 2024-04-16 he states I am yellow king. On 2024-04-18 he says he is the writer of the stories, founder of the story, soul of the team, and founder of the team. This is self-mythology, but it is consistent with later claims: he sees himself as the narrative and emotional center of the group.
The most important April technical/risk cluster is the BIA material. In Anonymous internationally, he discusses plans such as DDoS or information leakage, then says they should gain control of the systems of what he describes as a secret intelligence company. Minutes later he posts Nmap output for bia.gov.rs, the website of Serbia’s Security Intelligence Agency, and comments that bia is secret intelligence agency.
This is evidence of:
It is not evidence of successful compromise. It is evidence of noisy recon and target fixation. There is a difference, and it matters.
On 2024-04-25 he says he is a founder and needs people for his group, then clarifies i am leader not boss. That distinction is revealing. He wants authority, but wants it framed as loyalty/community rather than command hierarchy.
May 2024 shows Scisan becoming more explicit as a managed community. On 2024-05-24, in Scisan 2.0, he tells someone that in the eyes of world they are black hats. In the same cluster, he references BKB and says there are many people in the other team for testing/victim purposes. That line is one of the more alarming cyber-risk markers in the logs.
That same day, Anonymous internationally posts a channel migration notice: CHANNEL IS SHIFTED and users are told to contact @yellowking23 for the new channel link. Similar notices recur on 2024-06-02 and 2024-06-10. This is strong evidence that @yellowking23 functioned as a continuity or routing handle for channel migration.
The boring part is important. Group survival is mostly boring admin work: move the room, pin the link, tell the stragglers, ban spam, repeat. Yellow King appears to do or coordinate that work.
On 2024-05-26 and 2024-05-27 he talks about growing Scisan and says he told everyone in Scisan to study hacking. This supports the view that his strongest role was organizer/encourager, not necessarily lead technician.
June 2024 is dense.
On 2024-06-02 he comments that some groups are not very private and directs people toward private conversation. The logs show recurring tension between wanting secrecy and constantly posting identifying details in public or semi-public chats. Classic Telegram-brain. Worrying about spies while leaving breadcrumbs in every bakery.
On 2024-06-14, he discusses Proton Mail and OnionMail, saying we use proton mail and asking which is safer. The same day he claims Successfully account deleted of cp distributer by YellowKing. That is a self-reported anti-CSAM action and should be treated carefully: the stated target is clearly abusive material, but the export does not independently verify the outcome.
On 2024-06-19 he claims that in Scisan 1.0 he uploaded many big website vulnerabilities. This is another self-report. It supports an image of him wanting to be seen as useful in vulnerability circles, but does not prove high-end capability.
On 2024-06-27 he asks for coders, says he needs legitimate people with dedication, and discusses helping with projects that include ransomware-adjacent language and evasion tooling. Do not overread it as capability. It may simply show he was trying to recruit people who could build what he could not. But it is still a risk marker.
On 2024-07-10, he announces one year since the creation of Scisan 1.0 / Anonymous internationally and introduces a Scisan logo. This is a strong brand-building marker. He is not merely hanging around a chat; he is trying to build continuity and identity. On 2024-07-11, in CyberVolk and Cybersecurity Chat contexts, he asks about Nmap, Nikto, vulnerability scanning, old CVEs, Burp Suite, Nessus, AWVS, and how CVEs help when there are so many records. These questions are valuable because they cut through the pose. They show curiosity and learning, but also confusion about basic tool boundaries and workflow. This is not shameful; everyone starts somewhere. But it is evidence against the “elite operator” reading.
On 2025-03-06, in Major Fen Group, he gives the strongest identity and leadership self-claim in the export: I am Yellow King followed by Leader of Team Scisan and BKB UNION. He then claims the organization functions mainly in real life rather than Telegram, is private, and is divided into groups so one group does not know another. This is classic compartmentation language.
Treat that as self-report. It may reflect real-world structure, aspirational LARP, or a mixture of both. The logs alone do not prove the offline organization exists at the claimed scale.
The same Major Fen cluster includes serious poison-related claims and dosage/quantity talk. Specific details are intentionally omitted here. The important analytical point is that this is a non-cyber violence risk marker and should be documented soberly. It is not “edgy hacker banter” to brush off. If someone is bragging about poison in organizational language, the correct response is not to clap because the lore got spicy.
On 2025-03-08, he again identifies as yellowking in CHAT / Moroccan Soldiers, showing continued handle continuity across communities.
On 2025-06-13, in Keymous Chat, he discusses “modern tactical warfare,” “guerilla warfare in real life,” a social media whistleblowing campaign, and infiltration of an intelligence agency. He also says intelligence agencies are serious issues and that he would hardly get anything from it. This cluster matters because it mixes political grievance, real-world tactics language, intelligence targeting, and activist-media strategy. The safest assessment is not that he had a real operational plan. The safer assessment is that his rhetoric had moved beyond simple chat bravado into a fantasy/planning space where cyber, media, and physical-world conflict blur together. That blur is the risk.
Across late 2025 and early 2026, the Anonymous internationally and Scisan logs include many moderation-like commands such as /ban and /captcha on. These do not prove ownership by themselves, but they support an admin/moderator or trusted-operator role inside the channel ecosystem.
The sheer repetition also reinforces the practical part of the profile: whatever else he claimed, he was present enough to do maintenance. Not glamorous. Still power.
The latest observed cluster is 2026-06-09 in CHX CHATTING GROUP #3. Yellow King argues that Telegram bans and broader hacker-community disruption were not just mass reporting, but a coordinated attack on hackers. He references Pavel Durov’s arrest, channel deletions, hacker arrests, DStat-like infrastructure, CVE availability, intelligence agencies, Interpol, Mossad, CIA, FBI, India, China, and the idea that hackers uniquely challenge governments. The important thing here is not whether his theory is true. The important thing is that he uses it to build a worldview:
That is the clearest ideological snapshot in the export. It is conspiratorial, geopolitical, anti-institutional, and hacker-exceptionalist.
The logs show exposure to:
This is enough to call him security-curious and tool-aware. It is not enough to call him advanced.
| Domain | Assessment |
|---|---|
| Reconnaissance | Basic-to-intermediate familiarity. Posts Nmap/Dmitry output and discusses host discovery, open ports, and vulnerability scanning. |
| Web exploitation | Interest present; capability unproven. Uses AI explanations and asks workflow questions. |
| Vulnerability research | Claims to have posted “big website vuln,” but evidence is self-reported and vague. |
| Malware/ransomware | Mentions and project-adjacent discussion appear, but no verified capability in the logs. |
| OSINT | Familiarity with tools/resources; no proof of advanced tradecraft. |
| OPSEC | Weak. Publicly links handles, roles, targets, ideology, and organizational claims. |
| Community operations | Strongest observed capability. Migration, moderation, recruitment, morale, and group identity are recurring. |
Yellow King’s cyber profile is best summarized as: Public-tool recon + hacker-community literacy + social organizing + overclaiming. He can talk the language, ask the right beginner/intermediate questions, run or repost scans, and keep a crowd moving. But the export does not prove advanced exploitation, malware development, or successful compromise of high-value targets.
Yellow King’s most consistent operational strength is not technical. It is social continuity. He repeatedly:
That is real influence, even if it is not elite hacking. Influence in Telegram scenes often looks like exactly this: being online, being emotional, remembering names, carrying links, making people feel like they are part of something bigger than a chatroom full of stickers and bad decisions.
Yellow King’s ideology is emotional, reactive, and hacker-exceptionalist rather than formally coherent. Recurring motifs:
We are legion, group over individual, mission language.He tends to translate social instability into geopolitical drama. Sometimes that is just Telegram theater. Sometimes it is a warning sign.
| Risk Area | Observed Pattern | Assessment |
|---|---|---|
| Unauthorized access intent | BIA discussion includes language about gaining control of systems, followed by Nmap output. | High concern as intent signal; no proof of compromise. |
| Group testing/victim language | BKB referenced in context of people to test on. | High concern; ambiguous but ugly. |
| Hazardous non-cyber rhetoric | Poison-related claims and dosage/quantity discussion appear in 2025. | Serious warning sign; details intentionally omitted. |
| Physical-world conflict rhetoric | Talks about guerilla warfare, intelligence infiltration, and targeting leaders. | Serious escalation marker, even if likely aspirational. |
| Conspiracy worldview | Frames bans and infrastructure takedowns as intelligence-agency attack on hackers. | Moderate concern; may fuel escalation. |
| OPSEC leakage | Repeated public self-ID, handles, roles, targets, and channels. | High self-exposure; low tradecraft. |
| Recruitment | Seeks coders and helpers for projects. | Moderate concern; capability may depend on recruited talent. |
| Claim | Evidence Status | Notes |
|---|---|---|
| Yellow King / yellowking identity | Strongly supported | Multiple direct self-identifications from 2023 through 2025. |
@yellowking23 as contact handle | Strongly supported | Used in repeated channel migration notices. |
ssyellowking as ID | Supported | Stated directly on 2024-01-01. |
| Founder/leader of Scisan | Medium confidence | Multiple self-claims plus observed maintenance behavior; formal authority not independently verified. |
| Leader of BKB UNION | Low-to-medium confidence | Self-claimed on 2025-03-06; limited corroboration in logs. |
| Advanced technical operator | Low confidence | Tool use and recon visible, but no proof of advanced exploitation. |
| Successful compromise of major targets | Low confidence | Claims are vague/self-reported; no independent proof in export. |
| Anti-CSAM account takedown | Low-to-medium confidence | Claimed directly; outcome not independently verified. |
| Offline compartmented organization | Low confidence | Self-claimed; could be real, aspirational, or performative. |
| Intelligence-agency conspiracy behind hacker bans | Very low confidence | Presented as speculation; not supported by evidence in export. |
@yellowking23 as a continuity contact point.Yellow King communicates like someone trying to turn a friend group into an order of knights. He does not simply say “join the group.” He says people are team, citizens, brothers, leaders, founders, officers, trusted people, betrayers, spies. This is emotionally effective and operationally messy. He appears to need continuity. Bans, dead chats, missing friends, forgotten names, and broken channels bother him. His response is to rebuild: restart everything, make people active, move channels, ask for coders, and retell the story of Scisan. He also projects importance onto events. A ban wave becomes an intelligence operation. A Telegram migration becomes a strategic retreat. A small group becomes an organization. A scan becomes a mission. That is the charisma and the problem in one package.
Yellow King is best understood as a Telegram-native hacktivist organizer with basic-to-intermediate security-tool exposure and strong community-maintenance instincts. He is not a confirmed advanced persistent threat actor. The logs support a more grounded profile: persistent, socially active, politically charged, and technically curious, but noisy and prone to exaggeration. His biggest impact is likely social rather than technical: keeping people connected, keeping groups alive, recruiting helpers, and giving unstable chats a shared story. That said, the risk markers are real. The BIA targeting language, BKB “testing/victim” talk, poison rhetoric, real-world warfare/infiltration language, and conspiratorial crackdown narrative should not be dismissed as harmless roleplay. He may not have the capability he implies, but capability can be borrowed through networks. A dramatic organizer with weak technical skills can still become dangerous if he finds the right coder, the wrong grievance, or enough people willing to follow the story.
Record created: 2026-06-09