logo

Researchers Detailed r1z Initial Access Broker OPSEC Failures

ID: e817bb0a-0abd-5bdb-9304-facb0ae99730

STIX ID: report--e817bb0a-0abd-5bdb-9304-facb0ae99730

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-01-22

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A prolific initial access broker known as "r1z" marketed stolen VPN credentials, remote enterprise access, and offensive tooling (including EDR-evasion tools and cracked Cobalt Strike) on multiple underground forums, supplying footholds to ransomware operators; undercover law enforcement purchases and OPSEC failures allowed investigators to map his infrastructure and attribute the activity to Feras Albashiti.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.