Skip to content
Hasaan
Technical writing

Threat Hunting Investigation: The Leaks King (CobraEgyLeaks)

A time-bound threat-actor investigation covering public infrastructure, distribution channels, advertised capabilities, activity patterns, and defensive implications.

By Hasaan Muhammed12 min read
  • Threat hunting
  • OSINT
  • Cybercrime
  • Credential exposure

This investigation examined the public footprint of the threat actor using the alias CobraEgyLeaks. The research focused on observable forum activity, distribution channels, advertised tooling, operating patterns, and the likely defensive impact of the actor's credential-leak ecosystem.

The observations are time-bound to March 2025. This revised edition omits direct links to stolen data, private infrastructure, and unverified personal identifiers. Claims about tools and services are described as actor advertising unless independently observable.

Profile summary

The alias appeared on BreachForums in August 2023 and developed a high-volume posting history. By early 2025, the public profile displayed more than 1,100 posts across roughly 1,086 threads. The volume—close to two threads per day across the observed period—made the account unusually visible in credential- leak communities.

The operation was not confined to one platform. Public artifacts connected the same brand across:

  • underground forums used to announce or distribute credential sets;
  • Telegram channels used for leak promotion, customer communication, and vouches;
  • larger combolist-sharing groups where the actor appeared as an administrator; and
  • a small YouTube channel used to demonstrate advertised tools.

This cross-platform pattern matters because it separates functions. Forums create reputation and discovery, messaging channels support distribution and sales, and videos provide demonstrations for less technical buyers.

Observed leak pattern

The actor primarily published email-and-password combinations, often organized by country and described as “fresh” or “UHQ.” Those labels are marketing claims, not proof of freshness, but the cadence and geographic variety showed a repeatable distribution operation rather than one isolated breach.

Public posts included credential sets attributed to Belgium, Spain, Mexico, Egypt, Vietnam, the Czech Republic, Greece, and other locations. Some sets were advertised as containing tens or hundreds of thousands of records. The January 2025 Mexico post, for example, was described as approximately 156,000 accounts and drew attention because government and university addresses appeared in the data.

The apparent targeting pattern was opportunistic. The posts crossed government, education, and private-sector domains and did not indicate one stable industry or regional objective. The more consistent objective was maintaining a steady supply of high-volume credential material for an underground audience.

Advertised tools and services

The actor also advertised custom tools and paid access. Public descriptions of the “CobraEgy BOT 2024” claimed automation for finding web shells, testing hosting control panels, locating cloud and mail accounts, and targeting common content-management systems. A separate reverse-IP tool was promoted for domain enumeration. Video demonstrations were used as marketing evidence, but the claims should not be treated as independently validated capability without executing or reverse-engineering the tooling.

Telegram posts promoted subscription groups that allegedly delivered fresh credential combinations, compromised accounts, server access, and tools. A late-November 2024 promotion advertised lifetime access to three groups for $150. That pricing and the use of dedicated vouch channels suggest a structured service model: public leaks established reputation, while private groups were used to monetize access and maintain repeat customers.

Affiliations and collaboration

No public evidence reviewed for the original investigation established a formal relationship with a known APT or named criminal organization. The actor appeared closer to a solo operator embedded in a collaborative market: administrating shared groups, trading within forums, interacting with other data sellers, and using customer vouches to build trust.

That distinction is operationally important. A threat actor does not need a formal group identity to create large downstream impact. Distribution networks, resellers, tool users, and credential-stuffing operators can multiply the harm of one actor's collection and publication activity.

Activity timeline

2023: Establishing the identity

  • August 2023: the BreachForums account was registered and began building a posting history under the CobraEgyLeaks alias.
  • Late 2023: repeated credential posts and off-platform contact details established the forum-to-Telegram operating pattern. The account later displayed an MVP reputation rank.

2024: Scaling distribution and marketing

  • March 2024: a YouTube channel using the alias was opened to demonstrate private tools and checkers.
  • June 2024: a 500,000-line credential combination list was advertised, marking a visible increase in scale.
  • October 2024: large country-themed releases included a post advertising 317,000 Spanish email/password combinations.
  • November 2024: a post advertised 100,000 Belgian credentials. Later that month, a Black Friday promotion marketed paid lifetime access to private groups.
  • December 2024: posts continued at high frequency, including advertised sets for Vietnam and the Czech Republic. The public profile approached the thousand-thread range by year end.

2025: Continued credential exposure

  • January 2025: the actor advertised approximately 156,000 Mexican accounts, including government and academic addresses, and also posted credential sets attributed to Egypt.
  • February–March 2025: additional country-themed lists appeared and the forum account remained active as of the original research cutoff in March.

This timeline records visible posts and channel activity. It does not prove when the underlying credentials were obtained, whether each set was unique, or whether every advertised record was valid.

Impact analysis

The most direct risk is credential reuse. A leaked username/password pair can be tested against email, remote access, SaaS, and consumer services. Even when only a fraction of a dataset is current, high-volume distribution gives many downstream actors material for credential stuffing, account takeover, phishing, and internal access attempts.

The broader impact is an enablement ecosystem:

  • fresh-looking datasets attract buyers and resellers;
  • automated checkers reduce the skill required to test credentials;
  • paid channels create predictable distribution;
  • vouch groups establish trust between otherwise anonymous parties; and
  • public demonstrations help market tools and services.

For affected organizations, consequences can include forced password resets, incident-response work, fraud investigation, reputational damage, and loss of trust. Government and university addresses can be particularly valuable for phishing and password-reuse attacks because they provide recognizable identity and organizational context.

Defensive implications

Organizations cannot prevent every third-party credential leak, but they can reduce the value of leaked combinations:

  • require phishing-resistant MFA for privileged and externally accessible services;
  • block known-compromised passwords and enforce unique credentials;
  • monitor authentication telemetry for credential stuffing, distributed low- volume guessing, impossible travel, and unusual device changes;
  • rate-limit and risk-score login attempts across account, IP, ASN, device, and campaign dimensions;
  • monitor approved breach-intelligence sources for company domains without downloading or redistributing illicit datasets;
  • expire exposed sessions and credentials using a documented incident workflow; and
  • separate investigation evidence from unverified actor marketing claims.

Methodology and limitations

The investigation used public-source observation of forum profiles, channel membership, public posts, advertised tooling, and mainstream reporting around selected leaks. It deliberately avoided publishing download locations or operational details that would help redistribute stolen material.

Threat-actor research is inherently time-sensitive. Usernames can be copied, channels can change administrators, post counts can be manipulated, and actors can exaggerate the source or quality of data. The strongest conclusions are therefore behavioral: a persistent cross-platform identity, high-volume credential advertising, paid distribution, and tool marketing. Attribution to a real-world person or formal group requires stronger evidence than was available in the public artifacts reviewed here.