FBI seizes StarkRDP(and possibly RDP.sh)

edited January 30 in Industry News

Today, the FBI also seized the domains used by:

MySellIX (mysellix.io) and SellIX (sellix.io), two platforms that allowed users to create their own online stores, which threat actors also used to sell stolen data, software keys, and compromised accounts, and
StarkRDP (starkrdp.io), a Windows RDP virtual hosting provider that some threat actors allegedly used for credential stuffing attacks.

https://www.bleepingcomputer.com/news/security/fbi-seizes-domains-for-crackedio-nulledto-hacking-forums/ (archive)

StarkRDP and Sellix was operated by the same group of Germans as RDP.sh who I suspect is next to go.

https://bgp.tools/as/210558 is the network of RDP.sh

Imprints all pointing to Florian Marzahl/1337 Services GmbH


StarkRDP (archive)


RDP.sh (archive)



LinkedIn with Sellix (archive)

Thanked by (1)skhron

Comments

  • MannDudeMannDude Hosting Provider
    edited January 29

    Is the Florian in the screenshot the same as LE*'s Florian M?

    [ IncogNET LLC ] - Privacy By Design
    We believe that privacy and freedom of expression are two very important things, so we offer solutions to accessing and publishing content safely.
    [ USA: Liberty Lake, WA | Kansas City, MO | Allentown, PA ] [EU: Naaldwijk, NL ] [ CL Shared | KVM VPS | VPN | Dedicated Servers | Domain Names ]

  • @MannDude said:
    Is the Florian in the screenshot the same as LE*'s Florian M?

    We are glad that we unbrothered @FlorinMarian last year.

    No hostname left!

  • @MannDude said: Is the Florian in the screenshot the same as LE*'s Florian M?

    Nop, this is Florian Marzahl and our Florian is Florian Meissner.

  • MannDudeMannDude Hosting Provider

    @keklord said:

    @MannDude said: Is the Florian in the screenshot the same as LE*'s Florian M?

    Nop, this is Florian Marzahl and our Florian is Florian Meissner.

    Ahhh, gotcha. I tried to find the user but just knew it was a Florian "M", didn't know his full last name. :)

    Thanked by (1)keklord

    [ IncogNET LLC ] - Privacy By Design
    We believe that privacy and freedom of expression are two very important things, so we offer solutions to accessing and publishing content safely.
    [ USA: Liberty Lake, WA | Kansas City, MO | Allentown, PA ] [EU: Naaldwijk, NL ] [ CL Shared | KVM VPS | VPN | Dedicated Servers | Domain Names ]

  • @MannDude said:

    @keklord said:

    @MannDude said: Is the Florian in the screenshot the same as LE*'s Florian M?

    Nop, this is Florian Marzahl and our Florian is Florian Meissner.

    Ahhh, gotcha. I tried to find the user but just knew it was a Florian "M", didn't know his full last name. :)

    I think our guy is @FlorinMarian

  • edited January 30

    Update from Europol

    Throughout the course of the action day, 12 domains within the platforms Cracked and Nulled were seized. Other associated services were also taken down; including a financial processor named Sellix which was used by Cracked, and a hosting service called StarkRDP, which was promoted on both of the platforms and run by the same suspects.

    https://www.europol.europa.eu/media-press/newsroom/news/law-enforcement-takes-down-two-largest-cybercrime-forums-in-world (archive)

    So apparently they ran Cracked and/or Nulled too.

    Video from arrests.

  • @treesmokah said:
    Video from arrests.

    In video there was a gorgeous lady with a plum bottom! How she could be related to this? :O I think it is a mistake.

    Thanked by (1)marcopolio
  • "1337"!? How dare they misuse such a sacred term for us elite!

  • That Sellix website openly had people selling carding services and "stressers."

    Good riddance.

    Swiftnode.net - Baremetal, virtual machines, VoIP, and DDoS mitigation.

  • AuroraZeroAuroraZero ModeratorHosting ProviderRetired

    @hornet said:
    "1337"!? How dare they misuse such a sacred term for us elite!

    "Hack the Planet!!! They are trashing our rights!! They are trashing!!!! Trashing!!!"

    Thanked by (1)hornet
  • edited February 5

    Brian Krebs has published a piece on the whole shitshow
    https://krebsonsecurity.com/2025/02/whos-behind-the-seized-forums-cracked-nulled/ (archive)

    It confirms what I suspected, however I was not aware shoppy.gg was also involved. Shoppy was pretty much the same like Sellix offering individual "shops" primarily used for selling credentials and other illegal services.
    The idea started with Selly.gg, however they cracked down on illegal use of it, seems like it was not designed for it day one(unlike Shoppy and Sellix).

    0 opsec, its a miracle this shit ran for as long as it did. Feds have ignored it for a very long time, cause it was just skids selling accounts for Netflix etc. Seems like they crossed the line with "e-whoring" and extortion/sextortion of people.

  • edited February 5

    @legendary said:

    @treesmokah said:
    Video from arrests.

    In video there was a gorgeous lady with a plum bottom! How she could be related to this? :O I think it is a mistake.

    Weird way to say morbidly obese. Your typical "E-Girl".

  • the lack of opsec in the Krebs report is just breathtaking, I’m endlessly amazed that people who switch into direct crime just cannot make themselves drop their old kiddie identity first.

  • Given the chaos in the US gov, I am surprised FBI is still business as usual.

    The all seeing eye sees everything...

  • @treesmokah said: Weird way to say morbidly obese. Your typical "E-Girl".

    I like big girls, there is no need to ponder.

  • skorousskorous OGSenpai

    @terrorgen said:
    Given the chaos in the US gov, I am surprised FBI is still business as usual.

    At the point this happened the shit-show hadn't filtered down to the boots on the ground yet.

  • edited February 5

    StarkRDP has rebranded to LakeVPS following their domain seizure and investigation by FBI and Europol. We'll see how it plays out for them long-term.

    https://client.lakevps.io/announcements/2/StarkRDP-is-now-called-LakeVPS.html (archive)

Sign In or Register to comment.