Skip to main content

Bad Actor #1

immortal/eggy

Placeholder

 

1. Executive Summary

This report documents a Phishing-as-a-Service (PhaaS) cluster targeting Roblox users, operating under at least three linked brands: Shockify, Immortal, and Eggywall. Eggywall functions as shared hosting/WAF infrastructure and nameserver provider for both Shockify and Immortal, which analysis indicates are operated by the same actor(s) or a closely coordinated group. The cluster provides free phishing kits to affiliate users (“panel users”) in exchange for covert secondary harvesting of credentials via a dual-collection mechanism referred to in-community as “dualhooking.” The operation has processed a self-reported volume exceeding 6 million phishing attempts since 2021 and shows evidence of expanding partnerships with adjacent cybercrime groups, including script developers and actors targeting elderly victims via social media.

Overall confidence in the core infrastructure linkage (Shockify – Immortal – Eggywall): High. Confidence in specific actor attribution: Low – sufficient only to name aliases, not to confirm real-world identity.

2. Methodology

All findings below are organized by evidentiary basis, with confidence levels applied per standard analytic tradecraft (High / Moderate / Low).

3. Timeline of Discovery

  1. [URLscan.io flag] Domain roblox.com[.]py (IP: 91.240.21.8) identified as Roblox-impersonating phishing site
  2. [Manual page review] Embedded Telegram link t[.]me/shockifyv5 identified on phishing page
  3. [Telegram OSINT] Shockify Telegram channel led to link directory ( shockify[.]st/status ) and community server
  4. [Controlled account creation] Shockify panel requires Discord/Telegram SSO; registration flow observed directly
  5. [SecurityTrails / DNSDumpster] Shockify’s DNS infrastructure identified as reliant on a third-party WAF, “Eggywall” ( eggywall[.]cc , later eggywall[.]org )
  6. [DNS record review] Shockify’s nameservers confirmed to be operated by Eggywall
  7. [OSINT] Second platform, “Immortal” ( immortal[.]st ), identified via reference in Shockify’s community chat
  8. [Cross-platform comparison] Immortal found to share visual branding, service model, Eggywall NS dependency, and identical onboarding invite persona with Shockify
  9. [Platform monitoring] Immortal’s operational tempo found to exceed Shockify’s (active chat, continuous updates) during a period when Shockify was offline
  10. [Telegram monitoring] Immortal’s public Telegram share link updated to reference “@shockify”; Immortal began promoting Eggywall giveaways
  11. [WHOIS review] WHOIS records across the cluster’s domains returned the aliases “James Eggy” / “James Dogan,” sharing one Gmail address
  12. [Telegram interaction] Immortal’s Telegram admin (“iDom”) found to use an identical sticker/persona element to the shared Discord onboarding account
  13. [On-page/payment flow review] Payment processing identified via NOWPayments, with 300+ rotating cryptocurrency addresses observed
  14. [Favicon pivoting, third-party tooling assist] Favicon hash pivot on Eggywall/Immortal branding surfaced an additional VPS in Ukraine

4. Infrastructure Overview

Core domains/entities identified:

Hosting behavior: The cluster rotates hosting on a multi-day cycle, consistent with evasion of abuse reporting and takedown action. Certificate transparency logs (crt.sh) show a substantial number of test/staging subdomains associated with Eggywall, indicating active infrastructure development rather than a static kit.

Nameserver relationship: DNS records confirm Shockify’s nameservers are operated by Eggywall. This is assessed as high-confidence evidence of operational linkage between the two brands, independent of the branding and personnel overlap discussed in Section 5.

Payment infrastructure: The cluster uses NOWPayments as a cryptocurrency payment processor, generating in excess of 300 distinct wallet addresses observed during the investigation period, with active rotation. This is consistent with an effort to frustrate blockchain-analysis-based tracing and to launder proceeds across many low-value addresses rather than a small number of high-value ones.

5. Actor & Cluster Attribution

5.1 Linkage between Shockify, Immortal, and Eggywall

Assessment: Immortal is likely the current primary operational focus of the group, with Shockify functioning as a dormant or legacy brand. This is supported by comparative activity levels (chat engagement, update cadence) observed directly on both platforms.

5.2 Operator identity

WHOIS records across cluster domains return the aliases “James Eggy” and “James Dogan,” associated with a single Gmail address ( shrturl79@gmail.com ). No further OSINT correlation (name, image, or account reuse) was achieved against these aliases – this line of inquiry is assessed as exhausted with currently available data.

A secondary persona, “iDom,” administers Immortal’s Telegram presence and was observed using the same sticker/branding element used in the shared Discord onboarding flow, supporting a link between iDom and the broader cluster’s onboarding infrastructure. iDom’s real-world identity remains unconfirmed.

Language indicator: A promotional video associated with Immortal’s Discord shows a Dutch-language client interface, suggesting the uploader (iDom or another staff member) has Dutch language proficiency. Confidence: Low – this is a single data point and does not establish nationality, location, or primary operator status.

Infrastructure pivot: Favicon-hash pivoting on Eggywall/Immortal branding surfaced a VPS hosted in Ukraine. Confidence: Low. This technique returns any server hosting a visually identical favicon and does not by itself establish operator control; it is noted as a lead for further validation, not a confirmed attribution point.

5.3 Notable but unverified observations

The following were observed during the investigation and are flagged for awareness but do not meet the bar for an actionable assessment:

These items should be treated as investigative leads, not conclusions.

6. Tactics, Techniques, and Procedures (TTP Summary)

7. Indicators of Compromise (IOCs)

Domains:

Network:

Telegram:

Contact/Financial:

Note: IOCs reflect the state of infrastructure as observed during the investigation period (August 2026) and should be revalidated before operational use, given the cluster’s demonstrated hosting rotation cadence.

8. Diamond Model Summary

Adversary: Eggywall / Shockify / Immortal cluster (aliases: “James Eggy,” “James Dogan,” “iDom”)

Infrastructure: Rotating VPS hosting; Eggywall-provided WAF/NS; Telegram, Discord, and YouTube for C2-adjacent communication and distribution; NOWPayments for monetization

Capability: Turnkey phishing kit deployment; dual-layer credential harvesting; rapid infrastructure re-hosting; low technical barrier to affiliate onboarding

Victim: Roblox account holders; secondarily, affiliate (“panel”) users, whose own harvested credentials are covertly re-harvested by the operator

9. Assessment of Future Activity

The cluster shows no indication of ceasing operations despite sustained abuse reporting and takedown pressure against its hosting. Continued brand consolidation around Immortal, active recruitment of new affiliates, and reported expansion into partnerships with adjacent cybercrime groups (script developers, elder-targeted social engineering operators) suggest the group intends to persist and diversify. Assessed with moderate confidence: identification of the operator(s) is more likely to result from an OPSEC failure on the actors’ part (e.g., persona reuse, as already observed with the shared Discord/Telegram branding) than from infrastructure-based tracing alone, given the group’s demonstrated hosting/payment rotation discipline.

10. Recommendations

11. Analytic Limitations

This assessment relies substantially on OSINT collected via direct interaction with actor-controlled platforms (Discord/Telegram) rather than passive collection, which carries inherent risk of actor awareness and potential deception. Favicon-based pivoting, while methodologically sound, is prone to false positives and should not be treated as attribution-grade evidence on its own. No law-enforcement or subpoena-derived data was available to this investigation; all findings are based on open-source and platform-observable data only