ar
Feedback
ᴛʜᴇ ɢʜᴏꜱᴛ ɪɴ ᴛʜᴇ ᴍᴀᴄʜɪɴᴇ

ᴛʜᴇ ɢʜᴏꜱᴛ ɪɴ ᴛʜᴇ ᴍᴀᴄʜɪɴᴇ

الذهاب إلى القناة على Telegram

A coalition focused on cyber resistance.

إظهار المزيد
Israel2 831الفئة غير محددة
325
المشتركون
+124 ساعات
+67 أيام
+830 أيام

جاري تحميل البيانات...

القنوات المماثلة
لا توجد بيانات
هل تواجه مشاكل؟ يرجى تحديث الصفحة أو الاتصال بمدير الدعم الخاص بنا.
الإشارات الواردة والصادرة
---
---
---
---
---
---
جذب المشتركين
سبتمبر '26
سبتمبر '26
+3
في 0 قنوات
أغسطس '26
+12
في 4 قنوات
Get PRO
يوليو '26
+7
في 1 قنوات
Get PRO
يونيو '26
+25
في 3 قنوات
Get PRO
مايو '26
+10
في 2 قنوات
Get PRO
أبريل '26
+149
في 2 قنوات
Get PRO
مارس '26
+82
في 5 قنوات
Get PRO
فبراير '26
+48
في 5 قنوات
Get PRO
يناير '26
+13
في 3 قنوات
التاريخ
نمو المشتركين
الإشارات
القنوات
03 سبتمبر+1
02 سبتمبر+1
01 سبتمبر+1
منشورات القناة
August 31, 1967: Tamara Bunke Bider, better known as “Tania,” was killed in an ambush by the Bolivian army while fighting alo
August 31, 1967: Tamara Bunke Bider, better known as “Tania,” was killed in an ambush by the Bolivian army while fighting alongside Che Guevara’s guerrilla movement in Bolivia. Born in Argentina, Tania lived in East Germany with her family before moving to Cuba in 1961, where she joined the revolutionary struggle following the Cuban Revolution. She later became part of Che Guevara’s guerrilla movement in Bolivia. Tania was only 29 years old when she was killed. She remains a symbol of revolutionary struggle in Latin America to this day.

2
ąղէìʂìօղìʂէą
ąղէìʂìօղìʂէą
27
3
Defense Secretary Pete Hegseth’s driver’s license has leaked. A new dark-web service is selling scans of his and 153M+ U.S. and Canadian driver’s licenses. Timestamps on the scans match victims’ visits to Hertz rental counters and cannabis dispensaries. Evidence points to idscan[.]net, an ID-verification vendor used by Hertz, Target, FedEx and 1,000+ dispensaries. #TGITM
25
4
The Cyber Resistance of Palestine (@OpIsraelTeam). #OpIsrael #FukIsrael
The Cyber Resistance of Palestine (@OpIsraelTeam). #OpIsrael #FukIsrael
33
5
BlackCore's documented interference in Colombia's 2026 presidential election and Argentina's legislative elections establishes a clear pattern of Israeli-linked private intelligence firms operating across South America. The combination of bot infrastructure, shared technical ecosystems (Galacticos Ltd., SNI Digital), connections to senior Israeli cyber officials (Yigal Unna), and the geopolitical framework of the Isaac Agreements points to a sophisticated, well-resourced operation. Colombian President Petro's accusation—that BlackCore deployed half a million bots to manipulate the electorate—may be the most detailed documented case of digital election interference in South American history. The fact that Netanyahu publicly celebrated De la Espriella's victory before electoral disputes were resolved raises further questions about the depth of Israeli involvement in the continent's democratic processes.
44
6
Netanyahu explicitly linked Milei's victory to Israel's broader Latin American strategy, stating that recent political changes in South America mark the return of the alliance of freedom. Argentina's alignment represents a major shift from its historical support for Palestinian rights—the country is home to roughly 700,000 Palestinians and 500,000 Jews. Mexico: The Team Jorge Distinction Mexico has been the subject of Israeli-linked digital interference, but the documented firm is Team Jorge, not BlackCore . Team Jorge—an Israeli private intelligence firm exposed in 2023 by the Forbidden Stories consortium—operated in Mexico to support Tomás Zerón de Lucio, a former Mexican official currently evading extradition in Israel . Zerón is accused of involvement in the forced disappearance, torture, and manipulation of evidence in the 2014 Ayotzinapa case, in which 43 students vanished . The firm's services included creating thousands of fake social media profiles, deploying bot networks, and conducting hacking operations to influence public opinion and pressure decision-makers . Team Jorge boasted of having intervened in 33 presidential-level elections globally, with success in 27 cases. In Mexico, their operations were specifically tied to Zerón's interests . This distinction is significant because Mexico's current president, Claudia Sheinbaum, maintains a pro-Palestinian stance—she has recognized a Palestinian ambassador, condemned the Gaza genocide, and refused full participation in the US-led Board of Peace due to lack of Palestinian representation. The Mexican case is about Team Jorge operating for a specific client (Zerón), not BlackCore running a campaign against the Sheinbaum administration. The Infrastructure: Galacticos Ltd. and SNI Digital Technical investigations by Haaretz and Libération mapped BlackCore's digital footprint . Key findings include: BlackCore shared a London-based server with two Israeli companies: Galacticos Ltd. and SNI Digital. The server hosted subdomains linked to all three entities between March 2025 and May 2026. Galacticos operated a system labeled "Galacticos AI Avatar Generator"—consistent with BlackCore's advertised capability to deploy 1,600 avatars and fake accounts across social media platforms . Within two hours of media inquiries, BlackCore and Galacticos removed all accessible digital infrastructure . Investigators traced connections between BlackCore and Yigal Unna, former head of Israel's National Cyber Directorate and a veteran of IDF Unit 8200 and Shin Bet. The network of Tel Aviv-based firms includes Galacticos Ltd. (formerly Pagecorn Ltd. and Mycelium Intelligence Networks) and SNI (Strategic Network Intelligence)—both registered at the same address . The Broader Israeli Cyber Ecosystem BlackCore is not the only Israeli firm documented in this space: Black Cube, a separate firm founded by Israeli intelligence veterans, intervened in Slovenia before the March 2026 elections, deploying secret recordings to discredit the government of Robert Golob, who had recognized the State of Palestine . Team Jorge operates across Africa, Europe, and Latin America, claiming to have intervened in 33 countries with success in 27. Archimedes Group has been linked to operations in Mexico, Panama, Honduras, and eight African and Asian countries . The consistent pattern: Targets have been leaders, candidates, and governments that have criticized Israel's military offensive in Gaza or supported the Palestinian cause . The Unanswered Question: Who Paid? As Viginum head Marc-Antoine Brillant admitted, investigations have not identified the sponsor or sponsors behind BlackCore's operations : "Our investigations did not make it possible to identify the sponsor or sponsors, if indeed they exist, behind this foreign digital interference." French Prime Minister Sebastien Lecornu has formally requested Israel's diplomatic assistance in identifying those who commissioned the campaign . Conclusion
33
7
BlackCore in South America: Exposing Election Interference in Colombia and Argentina By TGITM Executive Summary Israeli private intelligence firm BlackCore—already under formal investigation by French authorities for global disinformation operations—has been implicated in electoral interference across South America, with documented operations targeting Colombia's 2026 presidential election and Argentina's legislative elections. Mexico, previously cited in connection with Israeli-linked interference, involves a different firm: Team Jorge. The pattern across Colombia and Argentina reveals a coordinated strategy to influence outcomes in favor of candidates aligned with Israeli geopolitical interests, particularly those supportive of the "Isaac Agreements" diplomatic initiative. Colombia: The 500,000-Bot Campaign The most detailed allegations come from Colombia, where outgoing President Gustavo Petro publicly accused BlackCore of orchestrating a massive digital disinformation campaign to manipulate the June 21, 2026 presidential runoff . Petro wrote on X that BlackCore deployed "500,000 bots—fake profiles—to manipulate the Colombian electorate with millions of lies about Ivan and me," referring to ruling-party candidate Iván Cepeda . He described the alleged interference as "the hardest blow to national sovereignty since the Spanish reconquest" and announced he would refuse to recognize the legitimacy of the incoming government . Further claims included allegations that the National Registry's vote-counting software had been "compromised," with detected alterations in IP addresses of core government servers during tabulation . Opposition candidate Abelardo de la Espriella—a criminal defense attorney openly endorsed by US President Donald Trump—won by a razor-thin margin of less than one percentage point (49.66% vs. 48.70%) . Colombia's National Registry and the National Electoral Council issued a joint statement confirming the transparency of the vote-counting software and explicitly denying any unauthorized IP modifications . International observers from the Organization of American States and the European Union validated the election results, stating no evidence of systemic digital manipulation was detected . Israeli Prime Minister Benjamin Netanyahu publicly celebrated De la Espriella's victory on X, stating: "Congratulations to President-elect Abelardo de la Espriella. I look forward to working with you to strengthen the bond between Israel and Colombia. Israel's friends continue to win. Long live the Isaac Agreements!" The Isaac Agreements—a diplomatic initiative inspired by the Abraham Accords—aim to strengthen Israel's ties with Latin American conservative governments. De la Espriella has since declared that "a strategic alliance with the state of Israel and the government of the United States will place us on the right side of history." Shortly after taking office, De la Espriella recognized Syria's Golan Heights as Israeli territory and restored diplomatic relations with Israel, reversing Petro's pro-Palestine stance . Argentina: The Isaac Agreements and Milei's Alignment Argentina's legislative elections saw the victory of President Javier Milei's party, marking a significant geopolitical realignment toward Israel. Milei has described himself as a "fanatic of Israel" and has publicly aligned Argentina with Israeli interests . In April 2026, Milei and Netanyahu formally signed the Isaac Agreements in Jerusalem—described as strategic agreements focusing on security and artificial intelligence. Netanyahu framed the initiative as the return of "the alliance of freedom," stating: "We had Abraham, and now we have Isaac. What will the Jacob Accords be?" Key commitments included direct flights between Buenos Aires and Tel Aviv launching in 2026, joint development of AI models and expert training programs, a commitment to move Argentina's embassy to Jerusalem, and Argentina designating the Islamic Revolutionary Guards Corps and Quds Force as terrorist organizations .
18
8
1. Avatar generators – Software creating fake profile images and personas 2. Agent-maker systems – Tools for managing multiple automated accounts ("sock puppets") 3. Campaign dashboards – Interfaces for coordinating large-scale posting and engagement 4. Bot deployment – Capable of deploying up to 1,600 avatars and fake accounts across social media platforms 5. Shared hosting – A London-based server hosted subdomains linked to BlackCore and two other Israeli firms: Galacticos Ltd. and SNI Digital 6. Rapid takedown – Within two hours of media inquiries, BlackCore and Galacticos removed all accessible digital infrastructure The Unanswered Question: Who Paid? Despite extensive investigation, Viginum could not identify the sponsor or sponsors behind BlackCore's operations . "Our investigations did not make it possible to identify the sponsor or sponsors, if indeed they exist, behind this foreign digital interference." — Marc-Antoine Brillant, Head of Viginum French Prime Minister Sebastien Lecornu stated that Paris has formally requested Israel's diplomatic assistance and cooperation in identifying those who commissioned the campaign . "I do not doubt for a single instant that if a French private group, from French soil moreover, had engaged in foreign digital interference in Israel, they would have done the same to its ambassador on site." — Sebastien Lecornu, French Prime Minister Legal Status BlackCore is currently subject to two French investigations: 1. An investigation by the Paris prosecutor's office 2. An investigation by French intelligence services into who ordered the campaign The case involves potential offenses including espionage, election interference, and online terrorism-related crimes . Broader Context The BlackCore revelations come amid increased scrutiny of Israeli organizations' involvement in European electoral processes . In early May 2026, the Israeli government authorized a $730-million propaganda budget for 2026 – described as a fourfold increase and dubbed the "Eighth Front" by Prime Minister Benjamin Netanyahu . This initiative has been characterized as a "Digital Iron Dome" aimed at suppressing dissenting online content through AI-driven surveillance and mass reporting . Conclusion BlackCore represents a documented example of what threat intelligence analysts call "disinformation-as-a-service" – a private company selling electoral influence operations to unidentified clients . The combination of fabricated charities, bot infrastructure, shared technical ecosystems, and connections to senior Israeli cyber officials points to a sophisticated, well-resourced operation. The attribution trail – from Let's Encrypt certificates to London-hosted servers to Yigal Unna's ecosystem – provides a rare window into how private intelligence firms operationalize information warfare at scale. The question remains: who is paying for it? This investigation is ongoing. Further analysis of the Galacticos Ltd. and SNI Digital connections will be published in a follow-up report. In our previous article last year, we exposed Israeli firm BlackCore's global disinfo network. Now we can confirm its interference extended to 2026 elections in Colombia, Argentina, and Mexico—with Petro alleging 500,000 bots deployed in Colombia's presidential runoff alone.
22
9
BlackCore – The Private Intelligence Firm Running Global Disinformation Campaigns By TGITM Executive Summary French cyber watchdog Viginum has formally linked Israeli private intelligence firm BlackCore to a coordinated global disinformation network operating across Europe, Africa, Sauth America and the United States. The company, which scrubbed its online presence after media inquiries, targeted elections in France, Scotland, New York City, Angola, and Togo using bot networks, fabricated allegations, and a fake Palestinian charity . The sponsor or client behind these operations remains unidentified . The Company Before vanishing from the internet, BlackCore described itself as "an elite influence, cyber, and technology company built for the modern era of information warfare". It offered governments and political campaigns "cutting-edge strategies to shape narratives" . According to Viginum, BlackCore is part of a "vast ecosystem of Israeli cyber companies" linked to Yigal Unna, former head of Israel's National Cyber Directorate and a veteran of IDF Unit 8200 and Shin Bet. Unna reportedly acted as a liaison to help secure clients for companies within this network . The Operations France (March 2026 Municipal Elections) BlackCore targeted three mayoral candidates from the left-wing, pro-Palestine party La France Insoumise (LFI) in Marseille, Toulouse, and Roubaix. Methods included: · Automated accounts and bot networks amplifying smear content · Fabricated allegations – including false claims of "sexual violence" and pedophilia · Coordinated data leaks targeting candidates Scotland Accounts linked to BlackCore targeted First Minister John Swinney, who publicly described Gaza as a "man-made humanitarian catastrophe" . Viginum identified hundreds of fake accounts generating over 1,400 coordinated comments against Swinney, specifically targeting his statements on Gaza . New York City (2025 Mayoral Election) The same modus operandi was used against the mayoral campaign of Zohran Mamdani, a progressive pro-Palestine candidate who won the election . Mamdani's victory was reportedly unwelcome to traditional pro-Israeli supporters due to his outspoken stance on Palestine. Angola & Togo Viginum confirmed operations in these African nations followed the same pattern, though specific targets remain undisclosed . The Fake Charity: "Sadaqah Palestine" A joint investigation by Libération and Haaretz exposed a sophisticated front operation . Sadaqah Palestine (Arabic for "voluntary charity") presented itself as a non-governmental, nonpolitical humanitarian organization providing aid to Palestinian families in Gaza affected by war and displacement . The reality was very different: · No legal registration – Not registered as a charity in the UK, US, EU, or Israel · Fake social media presence – Maintained accounts on X, Instagram, and Facebook with a paid Meta advertising budget · Inauthentic audience – Of 221 Instagram followers, ~59% were fake; one-third were bots. The follower base included Russian-language accounts, generic Western personas, and empty bios consistent with mass-generated profiles · Coordinated bot engagement – On X, coordinated reply bursts came from recently created accounts split between American-style "fitness coach" personas and Vietnamese-named accounts posting repetitive phrases · Shared infrastructure – The Sadaqah Palestine domain was repeatedly listed with electric-marinade.com in dozens of Let's Encrypt certificates issued between March 2025–March 2026, indicating shared infrastructure · Data harvesting – The site solicited donations via credit card forms, potentially functioning as a "honeypot" to capture donor data and identify pro-Palestinian sympathizers Technical Infrastructure & Tradecraft TTPs (Tactics, Techniques, and Procedures):
21
10
French authorities exposed Mossad-linked Israeli firm BlackCore interfering in elections across Europe, Scotland, Africa, and New York. Fake accounts, AI bots and smear campaigns—used to push voters toward right-wing, pro-Israel candidates.
21
11
New Twitter: twitter.now
19
12
A startup in Virginia just launched a social network called Twitter and it has NOTHING to do with Elon Musk. The blue bird is back, tweets and retweets are back, and it costs $20 to get through the door.
19
13
@TheGhostITM
@TheGhostITM
58
14
#TGITM
#TGITM
56
15
Louis Michael Gaebler, 23, of Mandurah, Western Australia, was arrested in Perth in connection with the TeamPCP investigation. Reporting from Australian media said he was one of two West Australian men charged after a joint investigation involving the Australian Federal Police, Western Australia Police, and the FBI. TeamPCP has been linked in reporting to major supply-chain attacks that allegedly spread malicious code through open-source software and affected a large number of organizations worldwide. In this case, the important point is not a single technical failure, but the accumulation of public traces that allowed investigators to connect online identities, platform activity, and real-world records. For a cybersecurity audience, the lesson is straightforward. Attribution in cases like this usually comes from correlation rather than one dramatic breakthrough. Names, usernames, account histories, public profiles, and infrastructure references can all become part of the same investigative picture when they overlap consistently over time. The case also highlights how operational security failures tend to be cumulative. A handle, avatar, social profile, or business record may seem insignificant in isolation, but repeated across services it can create a durable identity trail. That trail becomes more valuable when it is preserved for years and can later be matched against other account activity or public records. Gaebler’s arrest in Perth therefore matters not only as a law-enforcement action, but as a reminder that long-term identity reuse can become an attribution risk. In modern cyber investigations, the strongest cases often do not come from one isolated clue. They come from multiple small clues that point to the same person. #TGITM @TheGhostITM
53
16
Two people linked to TeamPCP were reportedly arrested in Australia today. TeamPCP is believed to be behind a string of major
Two people linked to TeamPCP were reportedly arrested in Australia today. TeamPCP is believed to be behind a string of major supply-chain attacks that sent shockwaves through the cybersecurity community.
80
17
- Cross-platform alias persistence: Handles and identity fragments were reportedly retained across HackerOne, GitHub, Hugging Face, TikTok, Steam, and Telegram. - Infrastructure exposure: A domain reportedly associated with malicious command-and-control activity was publicly linked from developer-facing profiles. - Weak identity separation: A possible real name, initials, aliases, and related account data were sufficiently connected to enable further OSINT pivots. - Historical timeline overlap: Steam VAC-ban dates and account interactions reportedly aligned across multiple identities. - Visual-identity reuse: The same distinctive cat avatar reportedly appeared on Steam and Telegram accounts associated with the wider TeamPCP ecosystem. - Public-record exposure: A business reportedly operated under the name OPSEC EXPRESS created an additional real-world attribution surface. Corporate records are routinely useful when they can be correlated with online identifiers, financial activity, communications, or infrastructure evidence. Analytical Takeaway This case demonstrates that operational security fails cumulatively. An individual does not need to expose a home address, leave a real IP address in a server log, or publish a direct confession to become attributable. Small artifacts—an old Steam ban, a contact comment, a reused profile image, a domain on a public developer profile, or a social-media video—can persist for years and later become critical evidence. The central mistake was treating individual accounts as isolated identities. They were not isolated. The reported evidence indicates that each platform preserved a fragment of the same operational history. Once one fragment was linked to a real-world identity, the remaining artifacts could be examined as part of a single pattern. For cyber-intelligence teams, the lesson is equally practical: prioritize pivots that establish independent corroboration. A username is a lead, not a conclusion. Confidence grows when a handle is supported by shared infrastructure, time-based correlations, platform relationships, visual markers, and verifiable public records. #TGITM @TheGhostITM
63
18
Case Study: How Reused Digital Identity Exposed an Alleged TeamPCP Member By Yara Tabet (The Ghost In The Machine) Executive Assessment The reported arrest of Ruben Thomson in Western Australia illustrates a common failure in hacking OPSEC: identity reuse across platforms with radically different levels of visibility. The reported attribution was not built around a zero-day, a covert implant, or a single leaked identifier. It emerged from publicly accessible traces that, when correlated, connected a long-standing online persona to an alleged TeamPCP member. The core failure was poor compartmentalization. Handles, infrastructure references, historical account activity, profile imagery, and social-media content allegedly overlapped for years. Any one artifact would have been weak evidence. Together, they created an attribution chain that was difficult to dismiss. Scope and Attribution Caveat This assessment is based on publicly reported material and open-source observations. It does not independently establish guilt or validate all claims of group membership. The reference to Thomson’s reported arrest and alleged connection to TeamPCP should be read as an attribution assessment pending the outcome of judicial proceedings. Initial Identity Pivot The investigation reportedly began with the handle DeadCatx3, which was associated with a HackerOne profile connected to the name Ruben Thomson. The account was significant because it created an initial bridge between a real-world identity and an established online alias. Researchers then identified what appeared to be an associated Hugging Face account using initials consistent with the same name. That profile reportedly referenced masscan[.]cloud. The domain had been identified publicly as command-and-control infrastructure associated with the Mini Shai-Hulud npm worm activity. The same domain was also reportedly present on the DeadCatx3 GitHub profile. This overlap mattered because it was not merely a reused username. It connected a named identity, developer-platform profiles, and infrastructure allegedly tied to a malware campaign. The evidentiary value came from convergence: distinct services independently pointing toward the same operational ecosystem. Social-Media and Steam Correlation Once Ruben Thomson became a working lead, investigators and researchers reportedly pivoted through account-linked data and open-source records. This led to a TikTok account using the name yolosolo17. The account reportedly contained a single video, published in March 2017, showing a Steam profile named YolocrownZ. The footage showed that the account had received a VAC ban $$175$$ days earlier. This places the likely ban date at approximately September 13, 2016. Further Steam research reportedly identified an account called Ellis that had also received a VAC ban on September 13, 2016. Public Steam-profile interactions and comments reportedly established a relationship between the Ellis and YolocrownZ identities. This is a valuable example of timestamp-based correlation. A shared ban date does not identify a person on its own, but it becomes meaningful when aligned with connected accounts, relationships, alias reuse, and the wider attribution record. The Avatar Link The strongest and most memorable pivot was visual rather than technical. A distinctive cat avatar appeared on a Steam profile associated with the identity chain. The same image was reportedly reused by the PCPsh Telegram account linked publicly to TeamPCP. Reverse-image searches reportedly produced few or no unrelated uses of the image. This gave the avatar limited but useful attribution value. Profile pictures are generally weak indicators because they can be copied, but their value rises when they appear consistently across accounts that also share timelines, contacts, aliases, and operational context. The cat image did not prove identity. It corroborated an identity chain that was already supported by multiple independent sources. OPSEC Failures Identified
55
19
Proton is currently experiencing a major outage affecting Proton's services due to a cooling failure in their Frankfurt datacenter.
29
20
The Uwais al-Qarani Hacker Group claims responsibility for a cyberattack on Israel's power grid, targeting critical infrastructure and sending a message of resistance. #TGITM @TheGhostITM
27