- What: Russian-language cybercrime forum XSS.is shut down
- Impact: Criminal activity on the forum has been disrupted
Threat Intelligence Major Russian-language cybercrime forum XSS.is shut down, alleged admin arrested July 1, 2026 Share By SC Staff (Adobe Stock) As detailed in Security Affairs, French and Ukrainian police have arrested a 38-year-old man in Kyiv and shut down XSS.is, a highly influential Russian-language cybercrime forum that operated for nearly two decades. The forum served as a critical hub for the underground economy, facilitating transactions between various cybercriminals. Europol coordinated the operation, dubbed Ratatouille, which dismantled XSS.is, a forum with over 50,000 members. The arrested suspect allegedly earned more than EUR 7 million by acting as a trusted escrow service, a function crucial to the forum's operation. XSS.is facilitated trades for malware authors, exploit sellers, spammers, and ransomware affiliates, providing a secure platform for criminal dealings. Analysis of a leaked database revealed a strong concentration of Cyrillic text and registrations from CIS-region domains, confirming its Russian-speaking user base. The busiest trading sections focused on web-application vulnerabilities, malware, exploit kits, and network access. The forum's activity pattern mirrored a typical workday, peaking between 09:00 and 13:00 UTC, aligning with Moscow working hours. The arrest and seizure of the associated "thesecure.biz" Jabber server represent a significant blow to cybercrime infrastructure, although the forum has since reappeared with diminished trust. The exposure of user data, including nicknames, emails, and IP addresses, poses a lasting threat, enabling the creation of detailed dossiers on forum members. While the takedown removes a central hub, the underlying economy of access brokering and exploit sales continues to migrate to other platforms. Source: Security Affairs SC Staff Related Threat Intelligence US DOJ seizes nearly 400 domains used for illegal World Cup streaming SC Staff July 1, 2026 The US Justice Department's Criminal Division, in coordination with the International Computer Hacking and Intellectual Property (ICHIP) network, took down the domains for violating copyright laws. Threat Intelligence Russian influence operations shift focus to US and Europe, leveraging AI SC Staff June 30, 2026 Google threat hunters report that Russian influence campaigns are increasingly targeting the EU and NATO, aiming to divide Western coalitions and advance Moscow's political and military objectives. Threat Intelligence Gamaredon group expands malware arsenal in ongoing Ukraine cyberattacks SC Staff June 29, 2026 ESET reported that Gamaredon conducted 35 distinct spear-phishing campaigns targeting Ukrainian governmental and military institutions in 2025, primarily in the latter half of the year. Related Events Cybercast Better Threat Intelligence Between Public and Private Sectors On-Demand Event Virtual Conference Nationwide Cybersecurity Summit 2025: Safeguarding America’s Digital Future On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Backdoor Deauthentication Attack Distributed Scans Domain Hijacking Drive-by Download Fault Line Attacks Google Hacking Hybrid Attack Password Cracking Reconnaissance You can skip this ad in 5 seconds