Solonik is a cybercriminal persona active on dark web forums and Telegram channels that has been associated with the sale and re-advertisement of large stolen or allegedly stolen datasets. The actor gained broad visibility in January 2026 after promoting a purported Instagram dataset of roughly 17 million users as a fresh “2024 API leak,” but multiple investigations concluded the material was old data that had circulated previously and was likely repackaged and rebranded to increase credibility and sales. Solonik has also been linked to other data-sale claims, including an alleged dataset relating to a major U.S. asset-management firm and additional breach claims affecting numerous organizations over a short period. Operationally, Solonik appears to use a coordinated underground sales ecosystem spanning cybercrime forums, public Telegram vouch channels, and private buyer-negotiation groups. This activity indicates a focus on monetizing exposed personal data and building reputation within criminal marketplaces. Reported tradecraft includes advertising datasets, distributing sample records to entice buyers, and using Telegram-based channels for transaction handling and reputation signaling. The actor has been associated with high-volume leak promotion rather than confirmed bespoke intrusion tooling or malware development. There is reported but unconfirmed overlap between Solonik and earlier aliases including Chucky and Chucky_lucky, based on similarities in datasets, timing, platforms, and Telegram account continuity. Infrastructure-level analysis has also linked Solonik-associated Telegram activity to Persian-speaking communities and Iranian-linked leaked Telegram data, but this does not constitute definitive attribution. Based on currently available high-confidence information, Solonik is best characterized as a financially motivated data broker or breach-data reseller rather than a clearly attributed state actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
10 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Offers for sale an alleged large customer dataset from a US-based asset management firm on DarkForums, including PII that could enable downstream fraud and phishing.
Advertised and monetized a purported 17 million-record Instagram leak, but the investigation indicates the dataset was recycled from earlier years rather than obtained through a new breach. Used dark web forums and Telegram channels for promotion, buyer negotiation, and distribution, while leveraging reputation signaling to appear credible.
A dark-web data seller claiming to have harvested and is selling a dataset of ~17.5M Instagram user records (usernames, emails, phone numbers, partial addresses/geolocations), enabling downstream account takeover attempts (password reset abuse), targeted phishing, and social engineering.
Leaking large-scale datasets of Instagram user information, including usernames, email addresses, and phone numbers, to cybercrime forums. Claimed to have harvested the data using an unspecified API.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.