People are asking how the OSINT nerds found the guy that drained the cancer bro.
Well, it's very shrimple
The shitty malware sent all the stolen data to a Telegram the scammers made.
We connected to the Telegram channel using the same credentials that were inside of the shitty malware
Inside the channel was the scammer(s)
We got their Telegram IDs
OSINT nerds used their Telegram IDs to see if they were in any other public facing chatrooms.
One of the scammers in there was in several fraud chatrooms. He advertised looking for a video game programmer to make a basic 2D game. He also advertised needing help with some malware stuff.
In a different chatroom he talked about how much he likes skateboarding.
In a different channel he shared his Instagram and was sharing photos of himself next to expensive cars
Then, OSINT nerds looked at his Instagram which had a LinkTree. His LinkTree linked to literally everything about the guy including his YouTube, PayPal, Kick, Twitter, etc.
So either he is a master of disguise, and ran a year long detrace campaign to throw off OSINT nerds in the event he's caught scamming
Or alternatively, he wasn't aware public Telegram chatrooms are public and could be searched easily.