TraceX Labs Uncovers Dark Web Threat Group Demanding $100,000 for Meta Outage

Published:

spot_img

TraceX Labs Uncovers Dark Web Threat Group Demanding $100,000 for Meta Outage

The Dark Web Intelligence Team at TraceX Labs, a cybersecurity firm based in India, has uncovered a dark web portal where a group identifying itself as “ANONYMOUS HOTZ /// APT” claims responsibility for a global outage that impacted Meta platforms, including Facebook and Instagram. This incident raises significant concerns regarding the security of major digital infrastructures and the potential for cyber extortion.

TraceX Labs’ investigation revealed that the portal primarily displays content in Chinese, with an option for English translation accessible via a language switch labeled “切换英文 / ENGLISH.” The onion service associated with this threat actor can be accessed at this link.

Chinese-Language Threat Message Observed

The homepage of the dark web portal features multiple warnings and extortion messages in Chinese. Portions of the text translated by TraceX Labs indicate that the group claims to have executed a Distributed Denial-of-Service (DDoS) attack against Meta’s infrastructure on June 12, 2026. The translated message asserts:

“On 12 June 2026, we executed a Distributed Denial of Service (DDoS) attack against Meta Platforms global infrastructure.”

The portal further alleges that the attack caused Instagram and Facebook services to go offline globally, leading to mobile application crashes and widespread disruptions lasting over six hours.

Ransom Demand and Threats

The dark web portal includes a ransom demand of $100,000 USD, payable in USDT (TRC20) cryptocurrency. A wallet address and QR code for payment are prominently displayed on the page.

Wallet address displayed:
TKjqghf5aYdnpE4ZXFexZd1HYRrYC1EVXa

The site contains aggressive statements threatening another attack within 30 days if the ransom is not paid. One translated section warns:

“Failure to pay equals permanent Meta takedown.”

Another threat claims the next attack would involve:

“Full infrastructure collapse | 14+ days offline | Complete service destruction.”

The portal also threatens retaliation against any legal actions, wallet blacklisting, or countermeasures.

Key Findings from TraceX Labs Investigation

Item Detail
Investigating organization TraceX Labs
Country India
Threat actor alias ANONYMOUS HOTZ /// APT
Portal default language Chinese
English translation available Yes
Claimed attack DDoS on Meta infrastructure
Claimed affected platforms Facebook and Instagram
Claimed outage duration 6+ hours
Ransom amount $100,000 USDT (TRC20)
Wallet address TKjqghf5aYdnpE4ZXFexZd1HYRrYC1EVXa
Onion link Onion link
Technical proof shared None identified

TraceX Labs Assessment

While the outage experienced by Meta was significant and widely reported, TraceX Labs emphasizes that there is currently no verified technical evidence linking the dark web actor to the disruption. The language employed on the portal resembles fear-based extortion tactics often seen in ransomware and intimidation campaigns prevalent in the dark web.

At the time of publication, the following points were noted:

  • Meta has not confirmed any cyberattack.
  • No forensic evidence connecting the outage to the threat actor has been publicly released.
  • No technical indicators, logs, or proof-of-attack data have been provided by the group.

Cybersecurity analysts suggest that the outage may have stemmed from infrastructure issues, routing problems, or configuration failures rather than an external cyberattack.

Meta Yet to Confirm Cause

Meta has publicly acknowledged the service disruption and confirmed that restoration efforts were underway. However, the company has yet to comment on the claims made by the dark web group identified by TraceX Labs. No official root cause analysis has been published as of now.

Advisory from TraceX Labs

TraceX Labs advises the public and media organizations to approach such dark web claims with caution until they are independently verified through technical investigation. The company recommends:

  • Avoiding engagement with extortion demands or cryptocurrency wallets.
  • Not assuming the legitimacy of responsibility claims without evidence.
  • Monitoring verified threat intelligence updates.
  • Exercising caution when accessing Tor hidden services and dark web infrastructure.

At present, the claims made by “ANONYMOUS HOTZ /// APT” remain unverified. Although the timing of the dark web post aligns with the Meta outage, there is no confirmed evidence that the outage was caused by a DDoS attack or by the threat actor behind the portal.

TraceX Labs continues to monitor the hidden service, associated cryptocurrency activity, and any emerging threat intelligence related to this incident.

Source: firstindia.co.in

Keep reading for the latest cybersecurity developments, threat intelligence and breaking updates from across the Middle East.

spot_img

Related articles

Recent articles

Suno Data Breach Exposes 55.3 Million User Accounts, Raising Concerns Over AI Data Governance

A significant data breach at the AI music generation platform Suno has exposed sensitive information belonging to over 55.3 million user accounts. This breach,...

Stadler Rail Rejects Everest’s $12.3 Million Ransom Demand Following Data Breach

Swiss train manufacturer Stadler Rail has announced it will not pay a $12.3 million ransom demanded by the ransomware group Everest, following a data...

Fake Bahrain Alert App Deploys Advanced Android Surveillance Malware Targeting Gulf Region Users

A sophisticated cyber-espionage campaign has been identified involving a fake Bahrain Alert Android application. This malicious app, masquerading as an official civil defense tool,...

Microsoft patches record 622 vulnerabilities, including two actively exploited zero-days

Microsoft has issued a significant security update, addressing a record 622 vulnerabilities in its products, including two actively exploited zero-day vulnerabilities. This update, part...