CSIDB logo
Threat actor

Raidforums

Attribution profile

Type
Criminal
Location
Portugal
Known incidents
1 incident
First seen
2019-07-01
Last seen
2019-07-01
Updated
2026-07-31 19:27
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Raidforums is a threat actor known by the alias Raidforums and is reported to be based in Portugal. The actor operates a hacking forum that shares content comparable to other underground communities, including cracking tutorials, tools, combolists and a marketplace. Raidforums has been observed targeting rival hacking communities, seeking to expose their internal data. In July 2019 the actor breached the competing forum Cracked.to, which focuses on cracking tutorials, tools and exploit discussions. The breach was carried out through an unspecified exploit against the myBB forum software used by Cracked.to. The actor’s operator, identified as “Omnipotent,” stated the intrusion resulted from an exploit but offered no further technical details. This activity demonstrates a pattern of targeting rival platforms to obtain and disseminate their user information.

The dumped data published on Raidforums.com contained 749,161 unique email addresses, associated IP addresses, usernames and private messages. Passwords were stored as bcrypt hashes using a work factor of 12, a strengthening measure Cracked.to had adopted months before the breach. The file size of the dump was approximately 2.11 gigabytes and included nearly 397,000 private messages in plaintext. Excerpts from those messages revealed discussions about cracking Fortnite accounts, changing email on compromised accounts and selling software exploits. Some messages advertised services for exploiting CVE-2019-20250, a critical WinRAR vulnerability that was being actively used to install malware. The dump also recorded each user’s first and most recent IP address, which could assist in tracking individuals despite possible use of anonymizing networks. Although the bcrypt hashing limited the usefulness of the password data, weaker passwords remained susceptible to cracking. Following the leak, Cracked.to administrators forced a password reset for all users and expressed regret over the exposure of private messages. The forum’s administrator warned that consequences would be pursued against those responsible for distributing the backup and conducting the leak. The incident was cited as a reminder that databases can be compromised and that administrators must remain vigilant against exploits targeting forum software.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB