XARVIS

AI-powered Cybercrime Intelligence Platform. Collects and refines threat data from anonymous channels including Dark web and Telegram. Track cybercrimes with knowledge graph analyzer and user profiling tools.

Product Overview
AI Brief
  • AI Brief
  • XARVIS Overview
  • Key feature
  • Use Cases
XARVIS AI Brief
Malaysia: Asian Football Confederation Suffers Major Data Breach
2025.03.12

The Asian Football Confederation (AFC), headquartered in Kuala Lumpur, Malaysia 🇲🇾, has suffered a cyberattack by the threat actor fesome, exposing sensitive data of over 179,000 individuals across Asia. The breach, announced on BreachForums, includes records of 69,508 players, 24,745 team officials, 81,827 coaches, and 3,200 referees, along with hundreds of high-profile individuals. Additionally, major football clubs, including Al-Sadd, Al-Ahli, Al-Ain, Al-Hilal, Al-Nassr, and Persepolis FC, have had contracts, passports, and contact details leaked. The attacker claims AFC has failed to negotiate and is selling the stolen data for Monero (XMR).

This report is an AI-generated document by XARVIS, which actively monitors the dark web in real-time and automatically extracts key threat information from the data detected each day. If you wish to delve into detailed data, please request a product demo.

XARVIS

XARVIS is a comprehensive deep/dark web monitoring and data collection solution that covers anonymous channels such as the dark web and Telegram. Through integrated web monitoring, it collects data that can be used to track specific cyber incidents and gather information about associated criminals. Additionally, it employs advanced Natural Language Processing (NLP) systems and in-depth analysis to extract meaningful intelligence from the collected data. XARVIS is a powerful tool for monitoring and analyzing online activities in the hidden corners of the internet to enhance cybersecurity and threat intelligence efforts.

DarkCHAT

DarkCHAT is a generative AI-powered chatbot purpose-built for analyzing dark web content. Integrated into XARVIS, it is powered by DarkBERT—the world’s first language model trained specifically on dark web data. By delivering timely and precise insights, DarkCHAT enhances the speed and accuracy of cyber threat investigations, enabling organizations to respond more effectively to emerging threats.

Importance of Dark Web Monitoring
XARVIS Key feature
  • Search Engine
    A purpose-built search engine that enables seamless access to threat intelligence collected from the deep/dark web and Telegram.

    XARVIS applies advanced multi-source data processing to support flexible and precise search based on specific crime types or investigative objectives.
  • Telegram Search
    Explore Telegram channels with real-time access to collected messages, images, and documents.

    Channels are categorized by themes such as hacking, drugs, malware, and hacktivist activities to support targeted analysis.
  • Graph Analyzer
    Reveal hidden relationships across fragmented digital evidence using knowledge graph-based cross-analysis.

    XARVIS connects Bitcoin addresses, Telegram IDs, email accounts, and other identifiers to support rapid and accurate entity correlation.
  • Threat Actor Profiling (Dark Spider)
    Profile threat actors operating on the dark web and Telegram through alias tracking, language patterns, activity timelines, and behavioral insights.

    Dark Spider unifies scattered attributes into comprehensive user profiles for intuitive threat actor analysis.
  • DarkINTEL
    Powered by DarkBERT, a dark web-specialized AI language model, DarkINTEL detects and classifies data leak incidents.

    It automatically identifies associated countries, industries, and risk levels to prioritize critical threats and support rapid response.
  • Crypto Analyzer
    Trace Bitcoin transaction flows to uncover illicit financial activity.

    Equipped with investigation-focused blockchain analysis, Crypto Analyzer provides actionable insights for virtual asset-related crime investigations.
XARVIS Use Cases
Use Case 1
Use Case 2
Use Case 3
Use Case 4
Use Case 5
Use Case 6
Use Case 7
Dark Web Search

XARVIS utilizes 'DarkBERT,' a Dark Web specialized language model developed by S2W's AI team, to classify and provide threat information by category. This technology automatically analyzes the posts uploaded to hacking forums, identifying the targeted countries and industries, making it easier to monitor on a country-by-country and industry-specific basis. S2W's AI calculates threat levels, presenting the most dangerous content in order.

When a specific country is selected, users can assess the damage distribution across different industries within that country. Furthermore, users can explore the top 5 users targeting that country and the frequency of damage in comparison to neighboring countries.

Telegram Search

Cybercrime is increasingly prevalent not only on the Dark Web but also within Telegram channels. The Telegram search feature is a newly added functionality that allows keyword-based searching of various crime-related Telegram channels collected by S2W.

Telegram channels integrated into the XARVIS platform are typically categorized under hacking, drugs, malware, hactivists’ activities, and more.

By entering drug-related slang terms into the Telegram search bar, users can access actual chat logs containing those keywords. This enables the identification of Telegram channels involved in illegal drug trading and their sellers. This information can be cross-referenced with other data in XARVIS, such as Bitcoin addresses, to track down sellers.

* Please note that this feature is in Beta version, and its public release schedule is currently undefined. Additional features and changes may occur upon public release, expected in the year '24.

* Please note that this feature is in Beta version, and its public release schedule is currently undefined. Additional features and changes may occur upon public release, expected in the year '24.

Tracking Threat Actors #1

XARVIS's cross-analysis tool enables the tracking of threat actors effectively. XARVIS continuously collects real-time identifiers related to threat actors, and users can leverage this collected data for cross-analysis.

In 2022, XARVIS detected the activities of a user named 'Lost_Key' targeting Indonesia on the global hacking forum 'Breached.' XARVIS collected this user's cryptocurrency address and Telegram address. Furthermore, it confirmed that the collected cryptocurrency address was associated with the renowned cryptocurrency exchange 'Binance.'

By utilizing XARVIS's cross-analysis tool, law enforcement agencies and security professionals can identify the identity of threat actors. This powerful tool enhances their ability to uncover and trace the individuals behind cyber threats, ultimately contributing to improved cybersecurity and threat mitigation efforts.

Tracking Threat Actors #2

XARVIS's threat actor analysis tool can effectively track users who operate with multiple identities on the Dark Web and Telegram.

In 2022, XARVIS detected the activity logs of a user named 'okito,' who was continuously targeting Singapore. This user was active on the global hacking forum 'Breached' and left their Telegram address in dozens of posts.

By tracing the Telegram address, XARVIS discovered that the same Telegram address was posted in messages authored by 'ttyper,' who had detected traces of access denial on the hacking forum.

This demonstrates how XARVIS can consistently track users who employ multiple identities on hacking forums, enhancing the ability to monitor and respond to potentially malicious activities effectively.

Identifying New Threat Domains

XARVIS collects approximately 150 new Dark Web domains on a daily basis. It leverages the 'DarkBERT' language model developed by S2W's AI team to automatically classify these collected domains into categories such as drugs, finance, hacking, weapons sales, and more.

This functionality enables organizations in specific sectors to periodically monitor threat websites relevant to their industry. For example, a drugs investigation agency can gather information on newly created drugs trading sites and utilize the data collected from these sites for their investigations.

By using XARVIS's automated classification and monitoring capabilities, organizations can stay vigilant against emerging threats and make informed decisions to bolster their cybersecurity efforts.

Global Issue Monitoring

XARVIS provides the capability to monitor global issues that are gaining attention on the Dark Web.

Following the outbreak of the Russia-Ukraine war, the Dark Web saw a variety of opinions and discussions on this topic. Posts distributing the personal information of major government agencies, businesses, and citizens from both countries were frequently detected.

Similarly, after the outbreak of the Israel-Palestine conflict, XARVIS identified trends similar to those observed during the Russia-Ukraine war.

In this manner, XARVIS can concentrate on monitoring specific topics and detect related illegal transactions and harmful content. This enables organizations to stay informed about emerging issues and potential threats within these discussions on the Dark Web.

Monitoring Server Access Permissions for Sale

XARVIS allows users to monitor the sale and demand for internal network access permissions of specific country-based companies by entering specific keywords.

For example, if a post appears on the Dark Web offering account information that can access the internal servers of a specific institution in South Korea, XARVIS detects this post and sends an alert. Such leaked accounts could be exploited by threat actors to compromise internal servers, leading to potential disruption or ransomware attacks.

In order to respond quickly to such situations and prevent the spread of damage, regular monitoring and detection of account leaks are essential. XARVIS provides the necessary tools to proactively address these security concerns and protect organizations from potential threats.