actors:antilarp

ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP ANTILARP...

Record ID: ANTI-LARP
Handle(s): @skidboss, @compress
Status: Active
First Observed: 2024-08-09 (Based on available records)


Summary

ANTILARP is a highly active and technically proficient cyber threat actor, data broker, and tool developer operating primarily within underground Telegram communities. Operating largely as a “one-man army,” ANTILARP specializes in high-value database exfiltration, cryptocurrency-targeted social engineering, and the automation of exploit chains.

The actor is known for integrating advanced artificial intelligence (including jailbroken LLMs like custom-configured DeepSeek and Mistral models) into his workflow to generate exploits, parse massive datasets, and automate network intrusions. His capabilities span web exploitation (SSRF, RCE, auth-bypass), cloud infrastructure compromise (AWS S3, Azure, GCP metadata endpoints), and telecom social engineering (SIM swapping, 2FA bypass). ANTILARP is a prominent vendor of corporate credentials, KYC (Know Your Customer) documents, and cryptocurrency exchange databases.

While the actor frequently employs highly controversial, hyperbolic, and provocative language as part of a carefully maintained online persona, threat intelligence indicates a sophisticated underlying methodology focused on financial gain.


Aliases

  • @antilarp — Primary Telegram handle
  • @skidboss — Telegram handle used for business and data brokering
  • @compress — Telegram handle used for data brokering and private inquiries
  • dongle / [email protected] — Legacy alias and associated contact email
  • antifart — Satirical/trolling alias used in community chats

Affiliations


Timeline

  • 2024-08-09 — First documented activity within the provided dataset.
  • 2025-02-15 — Claims successful compromise and exfiltration of the Transak and Fractal KYC engine databases.
  • 2025-05-31 — Publicly releases a custom Python-based exploitation tool named “CITRIX_VAMP” for automated Citrix gateway cookie-bleeding.
  • 2026-05-06 — Last known activity, actively communicating in underground group chats.

Evidence

Ref Source Date Notes
[1] Chat Logs 2024-10-02 Actor details his TTPs, including manipulating cloud metadata endpoints (169.254.169.254), DCSync attacks, and payment gateway race conditions.
[2] Chat Logs 2025-01-30 Actor claims to utilize DeepFaceLab and high-quality ID templates to bypass video liveness checks for cryptocurrency exchanges.
[3] Chat Logs 2025-02-15 Actor explicitly claims to have dumped the backend KYC databases for Transak and Fractal.
[4] Chat Logs 2025-05-31 Actor drops functional Python/PyQt5 source code for “CITRIX_VAMP,” a multi-threaded vulnerability scanner and cookie extractor.
[5] Chat Logs 2025-09-17 Actor posts a TruffleHog scan output demonstrating the extraction of Azure Storage Account keys and environment variables.

Notes

  • Automation & AI Use: ANTILARP demonstrates a strong reliance on automation. He frequently discusses utilizing uncensored LLMs (referred to jokingly as “George Droid Giga-nigger Bot II”) to optimize Python scripts, write malicious payloads, and parse complex JSON/SQL database dumps into sellable leads.
  • Social Engineering: The actor claims high proficiency in social engineering (SE), particularly against telecom providers (AT&T, Verizon, T-Mobile) and cryptocurrency exchange support desks. He claims to use voice spoofing and deepfake technology to bypass verification.
  • OpSec Observations: ANTILARP claims to use a highly compartmentalized setup involving offshore VMs, custom Ubuntu builds (“FBI CART OS” jokingly), and layered proxy chains (residential and mobile SOCKS5) tailored to match a victim's exact ZIP code to bypass anti-fraud engines.
  • Behavioral Profile: The actor routinely uses inflammatory language, aggressive posturing, and shock humor. Analysts note this is likely a deliberate obfuscation tactic to blend into the “com” (underground community) subculture and project an unpredictable, intimidating persona.

Record created: 2026-05-06.

actors/antilarp.txt · Last modified: by admin [Admin]