r57 is a high-volume database/access broker, not a single-campaign actor. Activity spans 40+ countries across ~160 threads dated late 2023 through mid-2026, with a clear tiering:
- Bulk PII/consumer database sales retail, business-leads, education, healthcare records sold as flat files, mostly priced per record count.
- Government and institutional data concentrated heavily in Lebanon (three separate ministries) plus postal services and government portals across several regions.
- Small-business initial-access sales (admin panel/webshell access) overwhelmingly concentrated on Hong Kong SME websites
- Global-brand credential phishing kits Coinbase, Dropbox, Netflix, Office 365
R57 repeatedly advertised databases, compromised administrative access, webshell access, and phishing kits across unrelated sectors and countries. This diversity indicates that the actor’s primary objective was likely the monetization of stolen data and unauthorized access, rather than targeting organizations for a single political, ideological, or strategic purpose.
The volume and variety of the advertisements also suggest that R57 may not have personally compromised every listed victim. Some of the material may have been obtained through partnerships, private trading channels, other threat actors, or resale arrangements.
Targeted Regions and Countries
MENA / Gulf
- UAE (business leads, auction platform, overseas-resident data, influencer/modeling agency, luxury booking)
- Lebanon (Ministry of Justice, Ministry of Labor, Ministry of Health, election-overseas data, telecom operator Ogero, a university)
- Qatar (business leads, POS platform, government-adjacent admin panels)
- Saudi Arabia (brokers, retail stores, business contacts)
- Egypt (retail, GoBus, BlueBus, taxi company breach)
- Palestine, Morocco


Southeast Asia
- Thailand (the single most-targeted country overall alongside Hong Kong ) (covid data, insurance, government portal, cars, education, retail, farmers, general PII)
- Indonesia, Philippines, Vietnam, Malaysia, Myanmar, Singapore
East Asia
- Hong Kong (almost entirely small-business admin-panel/webshell access sales) (jewelry, toys, F&B, manufacturing, education).
- Japan

South Asia
- India (government credentials, teaching platforms, loans, payments, food delivery, general consumer data)
- Pakistan, Bangladesh
Europe
- Norway, Romania, Italy, France, Russia, Poland, Greece, Portugal, Ukraine
Latin America
- Brazil, Argentina, Bolivia, Mexico
Africa
- South Africa, Uganda, Ghana
Oceania
- Australia, New Zealand
North America
- USA
Targeted Sectors
- Retail / E-commerce largest single sector; grocery, jewelry, toys, apparel, luxury goods, general shopping platforms across nearly every region
- Government / Public Sector three Lebanese ministries, postal services (Ghana, Bolivia, South Africa), government portals (Thailand, India, Malaysia, Brazil)
- Business Leads / B2B Contact Data generic corporate contact and “buyer/business” lists, especially Gulf and European entries
- Education universities, teaching platforms, K-12/higher-ed databases across Vietnam, India, Thailand, Lebanon, Singapore, Philippines, Hong Kong
- Healthcare blood donor registry (Philippines), pharmacy (Greece), Covid data and insurance (Thailand), medical shop (Brazil), government medical records (Malaysia)
- Media / Entertainment / Streaming subscription services, news subscribers, entertainment site user data
- Financial Services crypto exchange phishing (Coinbase), loan brokers, payment data, invoicing
- Transportation / Logistics bus and taxi companies (Egypt), dispatch/logistics (USA), ticketing (Mexico)
- Cloud/SaaS Credential Phishing brand-targeted account-takeover kits (Dropbox, Office 365, Netflix, Coinbase)
- Telecom, Agriculture, Hospitality/Travel, Manufacturing, HR/Employment
Is He Alone? Kill3r
Before revealing R57 identity needed to check if he is operating alone or there are multiple threat actors operating with him under the same account or with different accounts
In GoBus data breach, he mentioned that he breached GoBus with his team, it isn’t an indication that he has other teammates, but It worth investigating deeper.

To know if he has other teammates or other accounts he uses, a good pivot point is his contact methods, if there are other accounts has the same contact methods, it is very likely that these accounts belong to him or they are his teammates.
R57 main contact methods are telegram and Tox, he has added them in his BreachForums profile as his contact methods, and added them in his threads

Telegram and Tox identifiers are useful attribution pivots because threat actors frequently reuse the same contact details across multiple forums and marketplaces. Although usernames can be changed easily, a reused messaging account or Tox address can connect otherwise separate forum identities.
However, shared contact information does not automatically prove that two accounts belong to the same individual. The accounts may be operated by teammates, resellers, shared administrators, or members of the same criminal group. For this reason, contact reuse was treated as evidence of an operational relationship and was combined with breach records, email addresses, IP addresses, and other identifying information.
We used the Deep/Dark web search feature in the CCI Portal to search for other threads in dark web forums that contains that TOX address
And There are two threads using it, one with the author is r57, and the other with the author is Kill3r

As this user is registered in BreachForums , so it may have been leaked in the BreachForums breach
BreachForums and its predecessor, Breached.vc, were underground forums used for advertising, trading, and distributing stolen databases and unauthorized access. The forums themselves were compromised on multiple occasions, exposing information associated with registered users.
We searched by the username in the leaked datasets we have, and we have found it is leaked 3 times
BreachForums got breached many times and emails, ip addresses and other details are leaked, so that means that Kill3r is from the old users
The latest breach has his email address and 2 vpn IP addresses

The email address associated with Kill3r was not found in any breach other than the more recent BreachForums leak. However, the same username also appeared in the older Breached.vc database.

In the older breach, Kill3r was linked to a different email address that appeared to be personal, along with a non-VPN Indonesian IP address.
This suggests that Kill3r may have replaced the personal email address with a more privacy-focused account and adopted VPN services to improve his operational security following earlier forum breaches.
Using Live OSINT Scan feature in CCI portal, we ran an OSINT scan on his personal email address to see if it is registered on any platform.
A Live OSINT Scan checks whether a supplied identifier, such as an email address or phone number, is associated with publicly accessible accounts, profile metadata, registration indicators, or other online services. The results can help identify reused names, profile photographs, social-media accounts, and additional identifiers connected to the same person.
His email address is registered in Google services with his name and his personal photo

So till now we revealed the identity of r57 teammate (Kill3r), next we will investigate if there are other teammates or accounts.
Is He Alone? RealThreat & STEPBRO
From R57 profiles in forums and his threads/replies, we retrieved his telegram accounts he uses for contact.
@thehunt3rs
@FortiLayers
@xlixaxorr
We searched with each telegram account in dark web forums, to see if there are other accounts who use it, and it can be r57 teammate or other account.
We found 2 other accounts using @thehunt3rs and @xlixaxorr as their contact methods, which are STEPBRO and RealThreat

So the relationship between the new two dark web usernames and the telegram accounts of r57 will be:

R57 Telegram Accounts
CCI Portal offers revealing the phone number behind the telegram account (whenever it is possible)
CCI Portal succeed in revealing the phone number used by the telegram account @xlixaxorr, it is a Lebanese phone number.

Using Live OSINT Scan feature in CCI portal, we ran OSINT scan on the Lebanese phone number to see if it is registered on any platform, and to see the caller id results.
The phone is registered in Facebook with email m *** t@gmail.com, Also its caller id is Elie do██eth

R57 Identity Reveal
The name we identified from the phone number is good, but we can’t rely on it for attribution because the phone number may be fake or reused. We need to go deeper.
We searched for the username r57 in the data breaches, we found it leaked in the BreachForums breach, with a personal email, and VPN IP address.

This personal email address was found in a malware logs, malware logs are a collection of data stolen from an infected device by information-stealing malware, which may include saved credentials, browser data, system information, and account details.
A malware log normally represents information collected from a specific compromised device at a particular point in time. Email addresses and passwords appearing in the same machine record may belong to the device owner, another user of the machine, a family member, a customer, or accounts temporarily accessed from the device.
We searched the email address in the CCI Portal and retrieved the associated compromised machine record, including additional email addresses and passwords collected from the device.
We then searched the first retrieved email address, eliedo██@gmail.com, across data breach databases and found that it had been exposed in both the BreachForums and Altenen forum data breaches.
The email address was associated with the username STEPBRO in the BreachForums breach and with the username tsolerig24 in the Altenen breach.
We previously identified STEPBRO as a username linked to R57. Based on the combined evidence, we assess with high confidence that STEPBRO is an account operated by R57.
The BreachForums data breach also contained Lebanese IP addresses associated with this account.

We then did an OSINT analysis on the email to find if it is registered with any platform, we found that it was registered in a lot of platforms, with the most important platform is linkedin, we got from it his first and last name and his address.

Linkedin Profile:

We searched with another email address retrieved from malware logs, eliedo██ethmafia@hotmail.com against data breach databases.
We found it was leaked in many breaches, one of them in Altenen forum breach, with username tsoler

From another databreach we got his address and his date of birth

And from another breach we got another phone number.

Attribution Assessment
The investigation identified a Lebanese individual assessed to operate the R57 account and several associated aliases. The attribution is based on multiple independent correlations, including reused Telegram identifiers, underground-forum breach records, personal and operational email addresses, Lebanese IP addresses, information-stealer logs, phone-number data, and a LinkedIn profile containing matching personal information.
The strongest evidence is the connection between an email address recovered from the compromised-machine record, the STEPBRO account in the BreachForums breach, and the tsolerig24 account in the Altenen breach. STEPBRO was independently linked to R57 through Telegram contact reuse. Additional personal details, including the subject’s name, address, date of birth, phone numbers, and LinkedIn profile, were identified through separate sources.
The attribution is assessed with high confidence because the conclusion is supported by several distinct data sources rather than a single username, IP address, or caller-identification result.
Identified Personal Information and Associated Digital Footprint
| Field | Details |
|---|---|
| Assessed Full Name | Elie Do██eth |
| Known Aliases | R57, STEPBRO, tsoler, tsolerig24 |
| Date of Birth | 1996-08-03 |
| Nationality | Lebanese |
| Country of Residence | Lebanon |
| Address | G███ir, Kfa███ab, Keserwan-Jbeil Governorate, Beirut, Lebanon |
| Email Address | eliedo██96@gmail.com, eliedo██ethmafia@hotmail.com, eliedo██@gmail.com |
| Primary Phone Number | +9617187████ |
| Additional Phone Number | +9617049████ |
| LinkedIn Profile | https://linkedin.com/in/elie-do██eth-248███2a9 |
| Telegram Accounts | @thehunt3rs, @FortiLayers, @xlixaxorr |
| Dark-Web Accounts | R57, STEPBRO, tsoler, tsolerig24 |
| Associated IP Addresses | 212.30.██.███, 185.97.███.███ |
| Attribution Confidence | High |



