KELA Cybercrime Threat Intelligence
kela-cyber · B · active
https://www.kelacyber.com/blog/
Israeli CTI firm specialising in dark-web / cybercrime forum monitoring; ransomware + initial-access broker tracking (added 2026-05-08). 2026-05-08 audit: WebFetch returned 5 dated articles Mar 21 - Apr 29 2026. Candidate — promote to active after 3 runs. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → webfetch (listing) https://www.kelacyber.com/blog/ for titles+dates+URLs; then bridge: python3 tools/fetch_source.py url <article_url> for body (article pages are media-heavy, >10MB). AVOID: Do NOT WebFetch the per-article page — pages exceed WebFetch's 10MB cap (maxContentLength exceeded). Drill the article via the bridge instead.. | 2026-07-05 admiralty audit: B — original dark-web/cybercrime research lab, first-hand collection; usually reliable. Reliability HIGH->B, status stays active.
Cited in 4 entries
Citation cadence
Citation days per ISO week (11 weeks of coverage span, total 4).
- ByteToBreach hits Hungary's State Treasury after Romania's land registry — the reported entry point is an Oracle WebLogic server left unpatched since a 2017 patch cycle2026-08-05
- ANCPI (Romania cadastre): agency says core databases were NOT compromised, contradicting ByteToBreach's destruction claim; Gov Cloud migration to complete 22 July2026-07-21
- Romania's national cadastre agency ANCPI hit by a multi-day cyberattack; ByteToBreach claims citizen-data and e-Terra source-code theft plus ransomware2026-07-19
- The Gentlemen / Storm-2697 — internal "Rocket" backend leaked by a rival; KELA and Check Point dissect the operator inner circle2026-05-25