A Jordanian national, Feras Khalil Ahmad Albashiti (aliases including “r1z,” “Feras/Firas Bashiti”), pleaded guilty in U.S. federal court to fraud and related activity in connection with access devices for acting as an initial access broker who sold unauthorized access to victim networks. Prosecutors said Albashiti used the Russian-language cybercrime forum XSS (XSS.is / XSS.pro) and, in May 2023, sold an undercover law enforcement officer unauthorized access to the networks of at least 50 companies in exchange for cryptocurrency; the charge carries a maximum penalty of 10 years in prison and significant fines, with sentencing scheduled for May 2026.
Court reporting adds that Albashiti’s dealings with an undercover FBI agent included selling a cracked penetration-testing tool, then offering access to dozens of companies via two firewall exploitation methods for about $5,000, and later marketing an “EDR killer” capability; the FBI paid $15,000 for a version of malware described in filings as “novel” and effective at disabling multiple EDR products. Investigators attributed an IP address linked to Albashiti to activity associated with a June 2023 ransomware attack against a U.S. manufacturing firm that reportedly caused roughly $50 million in damage, and they tied the “r1z” account to Albashiti via an email address also used in a prior U.S. visa application; he was residing in Tbilisi, Georgia, and was extradited to the U.S. in July 2024 before reaching a plea deal.

TTPs, infrastructure, and targeting history in one profile.
10 events from the most recent confirmed update back to the earliest known activity.
Following the guilty plea, the court set Albashiti’s sentencing for 2026-05-11, when he will face a maximum penalty of 10 years in prison and financial penalties.
In January 2026, Feras Khalil Ahmad Albashiti pleaded guilty in the District of New Jersey to fraud involving the sale of unauthorized access to computer networks while acting as an initial access broker under the alias “r1z.”
After being located in Tbilisi, Georgia, Albashiti was arrested there and extradited to the United States in July 2024 as part of the U.S. investigation.
Investigators used account-registration data from the now-defunct XSS forum, along with payment-card and identity artifacts, to connect the “r1z” persona to Feras Albashiti.
Authorities determined that the same IP address exposed during the malware test was connected to a June 2023 ransomware attack on an unnamed U.S. manufacturing company that caused about $50 million in damage.
During a demonstration of the EDR-disabling malware against an FBI-controlled server in 2023, investigators captured an IP address that they used to identify and map Albashiti’s infrastructure.
After the initial access sale, the undercover agent paid for additional tooling from r1z, including EDR-disabling malware, a cracked penetration-testing tool, and separate privilege-escalation capabilities.
On 2023-05-19, Albashiti sold an undercover law enforcement officer unauthorized access to the networks of at least 50 companies in exchange for cryptocurrency.
In May 2023, an undercover FBI agent started interacting with the actor using the handle “r1z” on a forum where malware, exploits, and illicit network access were being sold.
Investigators later determined that artifacts from the “r1z” forum account were linked to a Gmail address that had been used in Feras Albashiti’s 2016 U.S. visa application, helping identify the operator behind the alias.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
7 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcehelpnetsecurity.com
Open sourcesecurityaffairs.com
Open sourcego.theregister.com
Open sourcebleepingcomputer.com
Open sourcedatabreaches.net
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.