π¨ CYBER INTELLIGENCE ALERT: CLANDESTINE INFRASTRUCTURE MIGRATION
[STATUS: OPERATIONAL MIGRATION IN PROGRESS / SUBDOMAIN RESERVATION / ACTIVE MONITORING]
Through telemetry analysis of global SSL/TLS certificate issuance logs, the systematic provisioning and deployment of a new network ecosystem belonging to the illicit leak forum PwnedForums (under the name variant pwnforums(.)sb) has been detected. Timing indicators and hostname structure demonstrate that the platform is preparing or executing a massive migration of its critical services to the Solomon Islands country code top-level domain (ccTLD) (.sb), seeking to inherit the operational capabilities of its former portals.
π― Target Platform: PwnedForums / PwnForums clandestine forum.
π New Base Domain: pwnforums(.)sb (Initially registered on May 14, 2026).
π Identified Subdomain Structure: Logical nodes for CDN, image storage, and escrow services.
π TECHNICAL BREAKDOWN OF THE EXPOSED INFRASTRUCTURE
The detected architecture reveals that the forum is not only trying to create a simple landing page, but also to replicate its entire transactional and operational model in the new extension:
pwnforums(.)sb and *.pwnforums(.)sb (First Seen: 2026-05-14): Initial root domain and wildcard certificate intended to mask the main discussion interface and the forum's backend.
escrow.pwnforums(.)sb (First Seen: 2026-05-17): Critical subdomain dedicated to the Escrow Service (Financial Intermediation). It confirms that the forum maintains active mechanisms to guarantee database purchase/sale transactions, corporate initial access, and exploits between cybercriminals, acting as a guarantor of the funds.
cdn.pwnforums(.)sb and img.pwnforums(.)sb (First Seen: 2026-05-17): Content Delivery Network (CDN) and dedicated image storage server. Designed to optimize platform loading speed and persistently host proof-of-concept (PoC) evidence, samples, and screenshots of auctioned data breaches.
sb.pwnforums(.)sb (First Seen: 2026-05-17): Complementary routing or perimeter load balancing node for the host's new gaming geographic zone.
#CyberSecurity #PwnedForums #InfrastructureMigration #DomainTakedown #DarkWebMarkets #EscrowSecurity #ccTLD_SB #IOC #ThreatIntelligence #CiberAlerta #VECERT #Infosec #PerimeterMonitoring