An investigation tied the underground alias ModernStealer to a cluster of dark web and Telegram accounts advertising alleged military, government, nuclear, and aerospace data, including claims involving Pakistan military procurement, the Pakistan Nuclear Regulatory Authority, the Intelligence Bureau of Pakistan, FIA documents, and a Pakistan-Turkey drone deal. Researchers found that a reused Session contact identifier connected ModernStealer postings with other aliases, including Zu1f1q4r, the Telegram user Sassoon Don, and another seller known as PriorOps, indicating an operational relationship across multiple leak-sale listings.
The reporting stops short of confirming any underlying breach or proving that the linked identities are a single actor rather than a coordinated group or shared contact infrastructure. Analysts said the activity reflects underground sale and extortion-style leak claims rather than a disclosed exploit, and warned that the authenticity of the advertised data remains unverified. The case highlights how persistent contact identifiers can be more reliable than usernames for attribution, while affected organizations are being urged to preserve logs, validate claims with evidence, review unusual access, reset credentials where warranted, and strengthen controls such as phishing-resistant MFA.

See attribution, scope, and your downstream exposure.
11 events from the most recent confirmed update back to the earliest known activity.
StealthMole published an investigation concluding that ModernStealer, Zu1f1q4r, PriorOps, and the Sassoon Don Telegram account were operationally connected through shared contact identifiers, while noting the evidence did not prove whether they were one actor or multiple actors sharing infrastructure. The report also noted at least 30 indexed threads tied to the recurring Session ID.
Researchers found eight ModernStealer-linked government-related listings between March and July 2026. These referenced alleged internal documents from the Bangladesh military, Pakistan's SUPARCO and Ministry of Science and Technology, and material referencing the PLA, CIA, Department of Defense, and DARPA.
Researchers found five listings linked to ModernStealer between March and April 2026, including alleged material tied to the Pakistan Nuclear Regulatory Authority, NUST, Lockheed Martin employees, and the Sri Lanka Air Force. These posts formed part of the broader pattern of military and government-themed leak-sale claims.
A separate Telegram account that historically used the username @Mirage2022 posted asking where to obtain drone leaks and blueprints. Researchers later noted this account used the ModernStealer name but found no direct link to the stronger attribution cluster.
A Breached.live thread titled "PLA OFFICERS AND OTHER RANKS DATABASE" was posted by the user PriorOps. The listing used the same Sassoon Don Telegram username as its contact point, adding another alias to the shared-contact cluster.
ModernStealer later published DarkForums threads advertising alleged classified Pakistani military documents and military documents from various countries that listed both the recurring Session ID and the Sassoon Don Telegram account as contact points. This directly tied the ModernStealer alias to the Telegram identity operationally.
A Telegram message posted by a user identified as Sassoon Don sought classified documents related to Ukraine and five Central Asian countries. The message directed sources to contact the user through the same Session ID seen in the forum listings.
Additional Breached threads by Zu1f1q4r advertised alleged material from Pakistan's Intelligence Bureau and Federal Investigation Agency. These posts again reused the same Session ID and Tox ID, extending the overlap with the ModernStealer-linked activity.
A Breached thread titled "Pakistan Military Procurement and Defense Deals" was posted by the user Zu1f1q4r. The post reused the same Session ID seen in ModernStealer listings and also included a Tox ID contact.
A DarkForums thread attributed to ModernStealer advertised an alleged Pakistan Nuclear Regulatory Authority database. In the post, the seller claimed to have compromised PNRA's mail server and obtained more than 60 databases, offering 17 databases totaling about 3.2 GB.
The investigation began with a DarkForums post by ModernStealer titled "[PK] TUR-PAK DEFENSE DRONE DEAL," advertising a 23-page confidential document on Baykar Teknoloji and Pakistan's National Aerospace Science and Technology Park. The listing included a Session ID used as a contact point.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
cryptika.com
Open sourcecybersecuritynews.com
Open sourcestealthmole-intelligence-hub.blogspot.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.