InstaKilla
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
InstaKilla is the alias used by a Bulgarian hacker who has been publicly linked to a series of data breaches targeting online escort forums. The actor’s location is identified as Bulgaria in the available reporting, and no other aliases or affiliations have been disclosed in the sources provided. The threat actor operates as an individual rather than as part of a known criminal consortium or state‑sponsored group, based on the information that attributes the activity solely to a Bulgarian national.
The actor’s targeting has been confined to adult‑oriented community platforms, specifically escort forums situated in Italy and the Netherlands, with an additional reference to a Zooville forum catering to zoophilia and bestiality enthusiasts. The strategic objective evident from the incidents is financial gain, as the stolen user databases were offered for sale on cybercrime underground markets. No indications of espionage, disruption, or ideological motivation appear in the documented reports, and the actor’s actions are consistently described as motivated by the monetization of compromised data.
Observed tactics, techniques, and procedures involve the exploitation of outdated vBulletin forum software, specifically a critical zero‑day remote code execution flaw identified as CVE‑2019‑16759. The actor leveraged publicly disclosed exploit code to gain remote access to unpatched systems, a method that aligns with the broader botnet activity noted by security researchers at the time. After achieving initial access, the actor extracted user information such as usernames, hashed passwords, IP addresses, and email addresses, and in one case accessed the internal paid subscription system of a Dutch forum, although no financial data was confirmed in the sampled data. The actor’s tooling style appears to rely on using existing proof‑of‑concept exploits rather than developing custom malware families.
The most significant publicly reported operation attributed to InstaKilla is the October 2019 breach of the EscortForumIt.xxx and Hookers.nl platforms, which resulted in the theft of approximately 250,000 Dutch and 33,000 Italian user records. The stolen data were subsequently advertised for sale on hacking forums, with the Dutch database reportedly priced at around $300. This campaign exemplifies the actor’s focus on financially motivated data theft via the exploitation of known vulnerabilities in niche community websites, and it remains the primary incident used to characterize the threat actor’s behavior in open‑source reporting.
Incidents
Attributed incidents are available to members.
2 incidents