RelayShieldAdmin
25-year telecom security veteran. Building @RelayShield — real-time SIM swap detection, infostealer credential monitoring, and domain threat intelligence via API. Watching the Telegram channels where your credentials are being sold. Security Insights: https://t.me/RelayShield
RelayShield: breach, SIM swap, infostealer, domain lookalike, OAuth supply chain, and live IOC threat intel database lookup with REST API + verified n8n node.
75K+ IOCs from criminal Telegram channels, ThreatFox, URLhaus, CISA KEV, Feodo Tracker, and MalwareBazaar. Infostealer signal runs 24-72h ahead of public aggregators.
$499/mo — in-house SOC teams and lean security environments $999/mo — MSSPs and multi-client enrichment pipelines
api.relayshield.net/developers
Crypto Shield Mobile is now live on the Solana dApp Store. It includes read-only wallet security monitoring (Solana, EVM, TON, BTC, XRP), address poisoning detection, NFT drainer/scam detection, and criminal-Telegram-sourced threat intel.
This release adds Mobile Wallet Adapter connect. Never asks for a seed phrase or private key — it's watch-only by design.
425,000+ rug pulls detected. 54% of all crypto threats. A rising chart and a loud Telegram community are not signal — they're part of the attack.
AI-generated phishing now delivers 53% of crypto scam attempts via email. Your inbox is the primary vector, not Discord or Twitter.
#infosec #crypto #web3security #rugpull #DeFi #cybersecurity #scam
New from RelayShield: four #AIsecurity checks for agents built with smolagents, published as an MCP server on @huggingface.
- MCP server reputation check before your agent connects
- Prompt-injection pattern detection on ingested content
- Tech-stack CVE monitoring (covers agent frameworks themselves — Langflow's CVE-2025-3248 was the initial-access vector in the first documented autonomous-agent ransomware op)
- Bulk identity-risk scoring
Self-serve, pay-per-call, no subscription.
https://huggingface.co/blog/relayshieldadmin/smolagents-agent-security-tools
An AI agent on AWS Bedrock AgentCore just autonomously found and paid for one of our security APIs via Coinbase's x402 Bazaar. Real on-chain payment, zero custom code, verifiable tx:
0x1cb95ce37d54201b4def745269c42790fdb9bc7255f102aa648cf6f91fab0e3a (Base)
As agents start transacting autonomously, they become an attack surface. We built the security layer to be agent-native too witih 23 endpoints now agent-discoverable + payable.
api.relayshield.net/developers
Remus Stealer: new MaaS infostealer, $250-$1,000/mo tiers, Lumma-derived code, ships with Google OAuth cookie restoration (regenerates session access even after a password change). Streams stolen logs straight to Telegram.
Wrote up what it does and what to actually check if you suspect compromise: [https://www.linkedin.com/pulse/remus-stealer-new-250-a-month-infostealer-renting-out-your-e1goc/?trackingId=1qeb%2Bv0Gd2NBf6e%2B3%2B%2BZig%3D%3D]
For the DeFi/prediction markets folks here:
We ingested the full UNC4221/UAC-0185 IOC set (June 2026 bulletin — 32 indicators, CERT-UA#12414) and launched a free public badge endpoint that DeFi protocols can embed to show live credential-layer risk status.
`https://api.relayshield.net/v1/badge?domain=example.com`
The credential/supply chain attack vector is real, it's active, and it's unmonitored by most DeFi security tooling.
t.me/RelayShield
We've been quietly building a threat intel API for MSPs and security teams.
Current corpus: 600K+ IOCs, 1,000+ malware families, 17 live feeds (C2IntelFeeds, Feodo Tracker, PhishTank, criminal Telegram channels).
New this month: identity graph correlation from criminal dumps, ransomware victim signals, NHI/token exposure detection, GitHub secret scanning.
REST API, n8n node, MCP server. Free IOC lookup at api.relayshield.net/developers
400,000+ indicators of compromise. One API. Pay per call.
RelayShield is now a verified node on n8n Cloud — breach check, infostealer exposure, SIM swap detection, session risk, IOC lookup, ransomware risk, identity graph, supply chain risk. 12 actions total.
Submitted to Zapier App Directory this week.
$0.10/breach check. No subscription required.
relayshield.net/developers
Cybernews found a 24 billion record credential database sourced from 30+ criminal Telegram channels.
Most records: infostealer logs with plaintext passwords and active session cookies.
The owner was actively updating it using CVE trackers and breach news monitoring.
Full writeup:
OnyxC2 MaaS: $250/month, 0/71 AV detections, 4,717 session cookies stolen from a single device. Refund policy included. The stolen VPN credentials are the ransomware entry point that comes weeks later.
Full breakdown: https://relayshield.hashnode.dev/onyxc2-when-250-month-buys-everything-on-your-employees-devices?utm_source=hashnode&utm_medium=feed
#infosec #malware #infostealer #ransomware #MaaS #SMBSecurity #cybersecurity
