Skip to content
View Condor2026's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report Condor2026

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Condor2026/README.md

Static Badge

Typing animation

Condor2026

"Knowing the enemy is the first step to defending yourself."

OSINT Analyst & Digital Threat Hunter
Research · Intelligence · Development


Operational Profile

Threat Intelligence Analyst with a primary focus on persistent threats, hacktivist coalitions, and organized cybercrime. Specialized in Open Source Intelligence (OSINT), Tactics, Techniques, and Procedures (TTP) analysis aligned with the MITRE ATT&CK framework, and the development of early warning systems for detecting malicious infrastructure.

All operations are conducted strictly through open sources and publicly available data, in full compliance with legal and ethical standards. The approach is oriented toward producing actionable intelligence for the defense of critical infrastructure and national strategic interests.

Operational anonymity is maintained until formal engagement with institutional entities (SOCs, CSIRTs, Governments) is established, subject to NDA or formal contract. Personal identifying information is disclosed exclusively upon verified institutional interest and confidentiality guarantees.


Core Competencies

Area Description
🔍 Threat Intelligence Monitoring Continuous monitoring of threat actors, campaigns, and TTP evolution.
🎣 Phishing Campaign Analysis In-depth analysis of phishing campaigns, infrastructure tracking, and malware correlation.
👤 Threat Actor Profiling Attribution and behavioral profiling of APT groups, hacktivists, and cybercriminal syndicates.
🌐 OSINT Investigations Custom OSINT investigations across surface, deep, and dark web sources.
📊 Executive & Technical Reporting Tailored intelligence reports for both technical teams and executive leadership.
🤖 Python Automation for CTI/OSINT Development of scrapers, ETL pipelines, and automation workflows for intelligence gathering.
⚡ IOC Collection & Enrichment Aggregation, enrichment, and correlation of Indicators of Compromise (IoCs).
🛠️ Custom Tool Development Design and deployment of bespoke security tools for defensive and investigative purposes.
📡 Cybercriminal Ecosystem Monitoring Continuous surveillance of cybercriminal forums, Telegram channels, and underground markets.
🛡️ Strategic Security Consulting Advisory services for institutional cybersecurity strategy and risk management.

Technical Stack

Python · OSINT · CTI · Flask · APIs · Automation · MITRE ATT&CK · Git · Linux


Areas of Interest

Threat Intelligence · Passive OSINT · Pro-Russian Group Analysis · Killnet/NoName Tracking · LATAM Organized Crime · DDoS Infrastructure Mapping · Mass Scraping · Actor Attribution · Scanning Prevention · Botnet Monitoring · Defensive Social Engineering · Intelligence Dashboards · Cyber Crime Analytics


Analysis Focus Areas

Domain Description
Pro-Russian Hacktivism Active tracking of Killnet, NoName057(16), DarkStorm, RootSec, Electus, and BotnetKingdom. Comprehensive DDoS infrastructure and TTP mapping.
Organized Crime (LATAM & Europe) Analysis of drug trafficking, extortion, homicides, and gender-based violence patterns using passive OSINT on digital press (Diabolic suite).
Malicious Infrastructure Domain, IP, SSL certificate, WHOIS, JARM fingerprinting, and IOC correlation for actor attribution (ShinyHunters, LAPSUS$, etc.).
Advanced OSINT Mass data extraction from Telegram, Discord, forums, and digital press. Geolocation, digital footprint analysis, and public data correlation.
Threat Prevention Early warning systems (Andrómeda) and monitoring dashboards for botnets and aggressive scanning (Nebula).
Defensive Social Engineering Phishing attack detection and simulation for training and reporting of severe crimes (pedophilia, terrorism).
Role Description
🔍 Threat Intelligence Analyst Monitoring, analysis, and reporting on actors and campaigns (APT, hacktivism, organized crime).
🛡️ Purple Team / Threat Hunter Proactive detection, IoC correlation, adversary emulation, and defense gap identification.
🌐 OSINT Investigator Digital footprint analysis, infrastructure geolocation, and public record correlation for legal or corporate cases.
🤖 Automation Developer (CTI/OSINT) Development of scrapers, dashboards, API integrations, and ETL pipelines for intelligence.
📊 Cybercrime Analyst Analysis of criminal patterns in LATAM, Europe, and Spanish-speaking regions.
🧠 Security Consultant / Advisor Strategic cyber defense advisory, risk management, and incident response planning.

Technologies & Tools

Category Technologies
Languages Python PyQt C C++ Bash JavaScript
IDE / Environments PyCharm VS Code
OSINT / Security VirusTotal Shodan Censys GreyNoise Wireshark Nmap AlienVault MISP OpenCTI TheHive YARA
Threat Intelligence Platforms OpenCTI GreyNoise Censys MISP AlienVault OTX RiskIQ Recorded Future
Scraping & Automation Scrapy Selenium BeautifulSoup Requests Playwright
Visualization & Web Flask JavaScript HTML5 CSS3 Chart.js Leaflet D3.js
Databases MySQL PostgreSQL MongoDB Elasticsearch
Version Control Git GitHub GitLab
Operating Systems Linux Android Termux Kali Linux Parrot OS Debian Ubuntu
OSINT Platforms Telegram Discord GitHub GitLab Twitter/X Reddit
Knowledge Domains Machine Learning Computer Science Electrical Engineering
Core Methodologies MITRE ATT&CK · TTPs · IoCs · Purple Team · Threat Hunting · Diamond Model · Cyber Kill Chain · Intelligence Driven Defense · DevOps · CI/CD
Specializations DDoS Tracking · Botnet Detection · Malware Analysis · Phishing Analysis · Social Engineering Defense · Fraud Detection · Crime Analysis · Investigative Journalism · Threat Actor Profiling · Takedown Coordination

Methodologies & Practices

MITRE ATT&CK · TTPs · IoCs · Purple Team · Threat Hunting · Threat Intelligence · Passive OSINT · Cyber Crime Analytics · DevOps · CI/CD Pipelines · Diamond Model · Cyber Kill Chain


GitHub Activity

Condor2026's github activity graph


General Statistics

Condor2026 GitHub Stats Top Languages


Featured Security Tools

Project Description Status
🌌 Nebula AntiScan Public demo for aggressive scan detection, Killnet IP tracking, and botnet monitoring. Integrates 73 OSINT sources and 80 intelligence feeds. ✅ Public
🕵️ LYRA OSINT Public OSINT query tool for phone numbers, emails, IPs, and usernames across 300+ platforms. ✅ Public
🦅 TrueCall_Condor OSINT tool for documenting scam calls, phishing domains, and fraudulent URLs. ✅ Public
📡 Andrómeda Private counter-intelligence system for DDoS monitoring, botnet tracking, and 3D threat mapping. +250k alerts processed. 🔒 Private
⚓ OCEANUS-AI v4.5 Private maritime monitoring system for geo-route tracking and anti-narco operations. 🔒 Private

📂 Complete Dossier & Intelligence Reports Index

This section provides direct access to all publicly available intelligence reports, dossiers, and in-depth CTI analyses. These reports form an interconnected intelligence web covering hacktivism, organized crime, hybrid threats, and specific incident investigations.

# Report / Dossier Description Direct Link
1 KillNet Strategic dossier on the evolution, structure, operations, alliances, and campaigns attributed to the KillNet ecosystem and related groups. → Repo
2 NoName057(16) Public threat intelligence tracker for the cybercriminal/hacktivist group NoName057(16), associated with GreenSnow botnet and Emotet. → Repo
3 cti-xv-dpx Complete CTI dossier on X-VDP-X (diable'fire) and the France Cyber Défense breach. Includes TTP analysis, IOCs, and French legal framework. → Repo
4 CIBERWAR OSINT intelligence dossier on Killnet, NoName057(16), and the new generation of hybrid threats. → Repo
5 Dossier 764 & Gov.eth Comprehensive dossier on the 764 terrorist network (satanic-neonazi sect) and the cybercriminal Gov.eth, analyzing modus operandi, ideology, and social impact. → Repo
6 CTI GLOBAL REPORT Global analysis of cyberspace and the invisible war. A macro-level threat intelligence report. → Repo
7 CTI RUSSIAN REPORT Complete dossier on Russian cyber threats. Analysis of actors, TTPs, and infrastructure. → Repo
8 Campaign Phishing AEAT Analysis of a mass phishing campaign impersonating the Spanish Tax Agency (AEAT), including associated malware. → Repo
9 ShinyHunters Infrastructure CTI analysis of shinyhunte.red - Official infrastructure of the ShinyHunters group (2026). → Repo
10 Jabaroot Analysis of the Jabaroot threat actor: hacktivist with OSINT and information operations (info-ops) capabilities. Active since April 2025. → Repo
11 IP BruteForce from China Report on mass brute-force attacks originating from China. Sources: OSINT, Telegram monitoring, Andromeda tools, and prior CTI reports. → Repo
12 Threat Intelligence Report (1 Jul 2026) Comprehensive threat intelligence report. Classification: PUBLIC - INFORMATIVE. Purpose: public awareness and technical documentation. → Repo
13 Dossier goo.su Complete CTI dossier on the goo.su case. → Repo
14 Multi-Malware Campaign Analysis of a multi-malware campaign: China IP + CardSpy + GandCrab. → Repo
15 Phishing Infrastructure .shop Identification of active malicious infrastructure focused on IP 104.17.231.54 (Cloudflare), hosting a network of .shop phishing domains. → Repo
16 Twitter Malware Campaign Analysis of a malware distribution campaign targeting Android devices using compromised Twitter accounts as the initial attack vector. → Repo
17 SpamCall Documentation of heavy spam calling in León, Spain. Identity spoofing alert. → Repo
18 Ciberseguridad para humanos Educational series designed for civilians. Explained in Spanish with real examples, victim stories, and actionable steps. → Repo
19 Dead Man's Switch Digital will with a contingency mechanism for the release of critical intelligence. → Repo
20 Diabolic Italia Passive and analytical OSINT platform monitoring 70+ Italian digital newspapers for criminal pattern detection. → Repo
21 Diabolic Peninsular OSINT platform analyzing 60+ Spanish mainland newspapers to detect criminal patterns. → Repo
22 Diabolic Baleares OSINT platform analyzing 18 Balearic Islands newspapers for criminal patterns (robberies, scams, drug trafficking). → Repo
23 Diabolic Canarias Passive analytical OSINT monitoring of Canary Islands digital newspapers (CRIME focus). → Repo
24 Diabolic Francia OSINT social aid platform monitoring housing, employment, food, health, and poverty in France. 30+ sources, 96 departments, 3 languages. → Repo
25 Keltic Kraken Ireland Criminal Intelligence Platform - Monitoring crime patterns in Ireland. → Repo
26 Diabolic Latam Proactive-passive OSINT analytics tool for detecting and analyzing criminal patterns in Latin America. → Repo
27 Diabolic Alemania OSINT platform for Germany. → Repo

Note: These reports are interconnected. For instance, the Russian hacktivist ecosystem (CIBERWAR, Killnet, NoName) feeds into the CTI RUSSIAN and CTI GLOBAL reports, while regional criminal analyses (Diabolic series, Keltic Kraken) provide ground-level OSINT validation for broader geopolitical threat assessments.


Work Philosophy

  • Anonymity as a Shield: Identity protection is maintained strictly for operational security, not as a weapon.
  • Open Source for Education: Public tools (Nebula, Diabolic series) are released to educate and empower the community.
  • Private Intelligence for Real Defense: The core intellectual capital (Andrómeda) remains private and is never commercialized.
  • Trust is Earned Through Results: Credibility is built on the quality and accuracy of intelligence outputs, not certifications or public posturing.
  • Legal & Ethical Compliance: All activities are conducted within legal frameworks, using only open-source and publicly available data.

Latest Updates

  • 2026-08-28 – Publication of KillNet and NoName057(16) strategic dossiers.
  • 2026-07-23 – Publication of cti-xv-dpx dossier (France Cyber Défense breach).
  • 2026-07-23 – Profile update with new project indexes.
  • 2026-06-04 – Nebula AntiScan v1.3 public release.
  • 2026-05-30 – Diabolic Peninsular v17 improvements.
  • 2026-05-20 – Integration of 80 intelligence feeds into Andrómeda.

Availability

  • Strategic Consulting for institutional and governmental entities.
  • Threat Intelligence Analysis on persistent threats, hacktivism, and organized crime.
  • Automation Development for CTI and OSINT workflows.
  • SOC & CSIRT Support in threat hunting, IOC correlation, and incident response.

Contact (Secure Channels)

For operational security reasons, personal data and direct contacts are provided exclusively during formal interviews or after signing a non-disclosure agreement (NDA) with institutional entities.

Channel Handle
⌨️ Telegram Private
🐦 Twitter/X @PurpleCondors |
☣️ VirusTotal @KiraSecurity
📧 Email KiraSecuruty@proton.me
💼 LinkedIn Not used (OpSec)

Note: PGP key available upon request.


Support the Research

If you find this threat intelligence work valuable and wish to support independent research and operational costs (servers, APIs, OSINT infrastructure), contributions are welcome:

  • ETH: 0x8eEA6C4B77DaB2C20E632407065c4F5d93093EaA
  • BTC: bc1qfvmwav55r3fqk88duux70z37kqw05c4k9t7h0j

Background

The journey began as an independent researcher operating in hostile digital environments. Over time, this experience was transformed into scalable prevention frameworks and actionable intelligence platforms.

Today, the focus remains on monitoring persistent threat groups, developing early detection systems, and publishing actionable intelligence for the defense of critical infrastructure. The background provides a unique understanding of adversary TTPs, cultivated through practical experience rather than formal coursework.

Self-taught, with a strong emphasis on operational security, the creator of Andrómeda (private counter-intelligence system) and Nebula (public demo). Specializations include botnet detection, pro-Russian group tracking, DDoS infrastructure mapping, and persistent threat analysis.


🔍 Open to collaboration – Threat Intelligence, OSINT, Purple Team, Automation.

  • Contact: KiraSecuruty@proton.me (PGP on request).
  • No personal Telegram or LinkedIn for OpSec reasons.

Producing actionable intelligence through rigorous OSINT and TTP analysis.


Maintained by: Condor2026 – Threat Security · Purple Team · Intelligence · Defense

Pinned Loading

  1. Diabolic_Latam Diabolic_Latam Public

    🌎Herramienta Osint proactiva-pasiva de analítica que detecta y analiza patrones criminales en Latam.

    Python

  2. Nebula_AntiScan2 Nebula_AntiScan2 Public

    🌌 NEBULA ANTISCAN v2.0– Demo pública de detección de escaneos agresivos, IPs de Killnet y botnets. ✅ 73 fuentes OSINT + 80 feeds de inteligencia ✅ Dashboard cyberpunk con mapa y gráficos ✅ Geolocal…

    Python 2

  3. Andromeda-analisi-grupos-ciber-delictivos Andromeda-analisi-grupos-ciber-delictivos Public

    📁🛡️🚨 El período de monitoreo ha revelado una intensa actividad cibernética en múltiples frentes. Se han identificado 46 grupos criminales y hacktivistas operando en el ecosistema digital, con difer…

  4. diabolic_france diabolic_france Public

    🇫🇷🗼 DIABOLIC FRANCE - OSINT social aid platform. Monitors housing, employment, food, health & poverty needs in France. 30+ sources · 96 departments · 3 languages (ES/FR/IT) · Real pagination · Auto…

    Python

  5. INFORMES_NoNames05716_2026 INFORMES_NoNames05716_2026 Public

    🌐🕵🛡️🚨This repository serves as a public, structured threat intelligence tracker for the cybercriminal and hacktivist group tracked as NoName057(16) (also associated with the GreenSnow botnet, Emote…

  6. KillNet KillNet Public

    📄 Dossier de Inteligencia | Ecosistema KillNet 🇷🇺 Análisis estratégico sobre la evolución, estructura, operaciones, alianzas y campañas atribuidas al ecosistema KillNet y grupos relacionados.