Close Menu
TechTost
  • AI
  • Apps
  • Crypto
  • Fintech
  • Hardware
  • Media & Entertainment
  • Security
  • Startups
  • Transportation
  • Venture
  • Recommended Essentials
What's Hot

Spotify now lets you view narrated magazine articles as well

Ghost hackers: the unsolved cybersecurity mystery

Ferrari’s first EV is not for you

Facebook X (Twitter) Instagram
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer
Facebook X (Twitter) Instagram
TechTost
Subscribe Now
  • AI

    The Pope’s encyclical on artificial intelligence is not really about artificial intelligence

    25 May 2026

    Everyone is navigating real-time AI security — even Google

    25 May 2026

    I’ve tried Amazon’s Bee wearable and I’m a bit intrigued

    24 May 2026

    Elon Musk has given up on solar power (on Earth)

    24 May 2026

    Ferrari uses IBM AI to create F1 superfans

    23 May 2026
  • Apps

    Universal Music Group and TikTok renew agreement to combat unauthorized AI music

    26 May 2026

    Google is pitching an ecosystem of AI agents to consumers who might not buy it

    26 May 2026

    Founded by Tony Robbins and Calm alums, The Path hopes to offer safer treatment with artificial intelligence

    25 May 2026

    Spotify will reserve tickets for an artist’s top fans in an effort to fill the engagement

    25 May 2026

    Audio production app Huxe, founded by former NotebookLM developers, is shutting down

    24 May 2026
  • Crypto

    5 days left: Save up to $410 on Disrupt 2026 passes

    25 May 2026

    As crypto cools, a16z crypto raises $2.2 billion in capital

    6 May 2026

    Coinbase to lay off 14% of staff as part of broader restructuring

    5 May 2026

    British cryptographer Adam Back denies NYT report that he is Bitcoin creator Satoshi Nakamoto

    9 April 2026

    Hackers stole over $2.7 billion in crypto in 2025, data shows

    23 December 2025
  • Fintech

    Disrupt 2026 Early Bird ticket prices end May 29

    26 May 2026

    Startup Battlefield 200 applications close before May 27 | TechCrunch

    26 May 2026

    General Catalyst just led a $63 million bet in India’s travel payments market

    21 May 2026

    Startup Battlefield 200 applications close on May 27

    21 May 2026

    Venmo’s biggest makeover in years comes at a very interesting time

    11 May 2026
  • Hardware

    The Dreamie alarm clock made me stop using my phone in bed

    26 May 2026

    6 kitchen gadgets that make adult life easier

    25 May 2026

    Xreal, Google’s smart glasses partner, believes it has finally conquered this extremely difficult industry

    25 May 2026

    We tested Google’s AI glasses and they’re almost there

    23 May 2026

    Finnish phone maker HMD ropes Indian AI chatbot into new smartphone to reach local market

    22 May 2026
  • Media & Entertainment

    Spotify now lets you view narrated magazine articles as well

    26 May 2026

    Spotify launches an audiobook creation tool powered by ElevenLabs

    22 May 2026

    New York City Mayor Zohran Mamdani Takes To Twitch To Chat With New Yorkers

    21 May 2026

    Clouted wants to take the guesswork out of making short videos go viral

    21 May 2026

    ‘Ask YouTube’ Brings AI Chat Search to Video, Adds Gemini Omni to Shorts

    20 May 2026
  • Security

    Ghost hackers: the unsolved cybersecurity mystery

    26 May 2026

    Scammers abuse an internal Microsoft account to send spam links

    22 May 2026

    Law enforcement shuts down VPN service used by two dozen ransomware gangs

    21 May 2026

    GitHub says hackers stole data from thousands of internal repositories

    21 May 2026

    Customers say Trump Mobile is leaking their personal information

    20 May 2026
  • Startups

    What ClickUp’s mass layoff tells us about the future of work

    25 May 2026

    SolarSquare in talks to raise up to $60M as India’s rooftop solar market draws big VC interest

    24 May 2026

    This startup raised $43 million to create a hive mind for ships

    22 May 2026

    Maka Kids redefines kids’ screen time with a streaming app optimized for wellness, not engagement

    22 May 2026

    This new startup is taking on a fragrance industry that hasn’t changed in nearly half a century

    21 May 2026
  • Transportation

    Ferrari’s first EV is not for you

    26 May 2026

    Global EV market becomes K-shaped as US falls behind

    25 May 2026

    Tesla’s Full Self-Driving software is creeping into Europe

    25 May 2026

    TechCrunch Mobility: Robotaxi Reality Check

    24 May 2026

    Wayve’s self-driving technology is heading to US cars made by Stellantis

    24 May 2026
  • Venture

    The pitch trick that helped an eSports startup raise $20 million when VCs only wanted AI

    25 May 2026

    Peec, one of Berlin’s up-and-coming startups, more than doubled annual revenue in months to $10 million, sources say

    23 May 2026

    Convective Capital Raises $85M Fund to Build Disaster Resilience

    22 May 2026

    Sam Altman does a ‘mic drop’ pitch to every Y Combinator startup

    21 May 2026

    Startup Battlefield 200 applications close on May 27

    20 May 2026
  • Recommended Essentials
TechTost
You are at:Home»Security»Ghost hackers: the unsolved cybersecurity mystery
Security

Ghost hackers: the unsolved cybersecurity mystery

techtost.comBy techtost.com26 May 202604 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Email
Ghost Hackers: The Unsolved Cybersecurity Mystery
Share
Facebook Twitter LinkedIn Pinterest Email

In the long history of hacking, there have been numerous data breaches that, years or even decades later, remain unsolved. Countless hackers and the hacker groups behind them have never been exposed.

But productive hacking groups are caught. This is true whether it’s cybercriminals like LAPSUS$, a notorious extortion gang that breached companies like Microsoft and Nvidia and has had many members arrested, or sophisticated government hacking groups from Russia and China, whose members have been named, charged and placed on wanted lists.

Yet some of the most fascinating cases in cybersecurity history remain open — with no culprits, no answers, and in some cases, not even a clear motive. We decided to revisit many of them in a series of articles, starting with one of the strangest episodes in the history of information leaks.

The first installment focuses on the Shadow Brokers – a mysterious group that appeared on the Internet, dropped a trove of hacking tools believed to belong to the NSA, and then disappeared.

In the summer of 2016, amid Russian hacking related to the US presidential election, the group appeared on Twitter. They connected with one Pastebin post and @-mentioned multiple news outlets — a strange, ineffective strategy that meant most of those outlets likely never saw the tweets.

But if someone clicked on the link, they would see a document titled “Equation Group Cyber ​​​​Weapons Auction — Invitation” — a reference to the shadowy hacking operation widely believed to be run by the NSA.

“!!! Beware of Government Sponsors of Cyber ​​War and those who profit from it !!!! How much are you paying for the enemies cyber weapons?” the hackers wrote, claiming to have hacked Equation Group.

A screenshot of the shadow broker’s first tweets.Image Credits:TechCrunch

The document included links to download some hacking tools, as well as a link to download an encrypted file that interested buyers could decrypt by making a bid. “Auction files are better than Stuxnet,” they wrote, referring to the famous malware used against Iran’s nuclear facilities in a 2007 US-Israel cyber attack. They asked for at least 1 million Bitcoins.

The leak quickly attracted press coverage. Once security researchers analyzed the tools, they realized they were highly sophisticated cyber weapons, likely stolen from the NSA – a suspicion reinforced by the fact that some shared names with programs revealed by NSA whistleblower Edward Snowden.

The auction was likely a ruse, as the group eventually dumped many of the tools publicly months later. A lot about Shadow Brokers didn’t make sense. Their broken English was almost comical, as if they were either trying too hard or signaling artificiality on purpose. Despite clearly clamoring for attention—and receiving plenty of press coverage—the team only spoke to a reporter once, giving a short interview to 404 Media’s Joseph Cox, then a reporter at VICE Motherboard.

Ten years later, we know literally nothing about who was behind the Shadow Brokers persona. Cox and me interviewed former NSA officials at the time, who said an undercover or former NSA undercover could be involved. But no one has been arrested or charged – remarkable given that this was arguably one of the worst leaks of US intelligence hacking tools.

One possible suspect was Harold T. Martin III, an NSA contractor arrested for stealing classified information from the agency. But the theory has a problem: while Martin was in custody, the Shadow Brokers remained active online. He has never been formally charged in connection with the leaks. The most widely accepted theory is that the Shadow Brokers were created by a Russian government spy group as a propaganda tool.

The impact was huge. Among the tools released, they published Shadow Brokers EternalBlue — a family of zero-day vulnerabilities targeting Windows that allowed hackers to break into computers on a compromised network, rapidly expand their access, and deploy self-propagating worms. (Zero-day vulnerabilities are flaws unknown to the software manufacturer, meaning there is no patch yet.) North Korean hackers used EternalBlue to release the WannaCry ransomware worm. Russian hackers later created NotPetya, which surpassed its original Ukrainian targets and caused $10 billion in damage worldwide. For businesses, the lesson was stark: Vulnerabilities accumulated by intelligence agencies don’t stay secret forever — and when they leak, the private sector pays the price.

The vault is still yielding discoveries. Among the leaked tools was one that contained a list of project names — including one called Fast16, which was tagged only with “NOTHING TO SEE HERE — CARRY OF.” Last monthresearchers announced that they had located and examined it, finding malware dating back to 2005 designed to tamper with software allegedly used by Iranian nuclear scientists.

When you purchase through links in our articles, we may earn a small commission. This does not affect our editorial independence.

Cybersecurity ghost hacker hackers Mysteries of hacking mystery The Shadow Brokers unsolved
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleFerrari’s first EV is not for you
Next Article Spotify now lets you view narrated magazine articles as well
bhanuprakash.cg
techtost.com
  • Website

Related Posts

Scammers abuse an internal Microsoft account to send spam links

22 May 2026

Flipper unveils a Linux-powered networking gadget designed for hackers and tinkerers

22 May 2026

Law enforcement shuts down VPN service used by two dozen ransomware gangs

21 May 2026
Add A Comment

Leave A Reply Cancel Reply

Don't Miss

Spotify now lets you view narrated magazine articles as well

26 May 2026

Ghost hackers: the unsolved cybersecurity mystery

26 May 2026

Ferrari’s first EV is not for you

26 May 2026
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Fintech

Disrupt 2026 Early Bird ticket prices end May 29

26 May 2026

Startup Battlefield 200 applications close before May 27 | TechCrunch

26 May 2026

General Catalyst just led a $63 million bet in India’s travel payments market

21 May 2026
Startups

What ClickUp’s mass layoff tells us about the future of work

SolarSquare in talks to raise up to $60M as India’s rooftop solar market draws big VC interest

This startup raised $43 million to create a hive mind for ships

© 2026 TechTost. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer

Type above and press Enter to search. Press Esc to cancel.