Open-source intelligence research has identified the cybercrime forum persona Quake3—described as an XSS moderator—and the alias morgot as the same individual allegedly involved in developing the REvil ransomware source code. The reporting says multiple forum accounts were operated from the same two IP addresses, during matching hours, across three consecutive months, and that one of the linked accounts belonged to a moderator on exploit.in.
The attribution case also cites private correspondence in which the individual allegedly acknowledged being morgot on exploit.in, along with repeated use of the Jabber handle morgot@exploit.im over a six-year period. Additional reporting says a DEF CON 33 persona mapping connected the aliases morgot, Rcode, and Quake3 to the REvil source-code developer, strengthening an OSINT-based attribution built on IP overlap, timing patterns, pseudonym reuse, and cross-platform identity correlations.

TTPs, infrastructure, and targeting history in one profile.
1 event from the most recent confirmed update back to the earliest known activity.
VULONE published an OSINT attribution analysis arguing that a single individual behind the aliases morgot, Rcode, and Quake3 was linked to development of the REvil ransomware source code. The report said the case relied on correlations including shared IP addresses, overlapping usage times, pseudonyms, and private correspondence.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.