Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews
Cybercrime

Quake3 and morgot: tracing REvil’s source-code developer

Dancho DanchevBy Dancho DanchevAugust 10, 2026Updated:August 10, 2026No Comments13 Mins Read49 Views
Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Ransomnews cover: the persona chain Quake3, morgot, Rcode leading to REvil source-code development, named by the BKA in April 2026
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

For most of a decade a Russian-speaking coder posted on the underground forums under the handle Quake3, and later moderated one of them. In August 2025, DEF CON 33 research placed the persona set Morgot, Rcode and Quake3 at the head of REvil‘s source-code development. In April 2026 the German BKA named the men behind REvil and GandCrab in public. This profile does the connective work between those two events: it reads the forum record the moderator left in his own typing, and shows how the handle Quake3 resolves to the persona morgot, and to the developer role the researchers described.

Nothing here rests on a leaked database or a stolen document. It rests on dated messages the subject wrote himself, on public conference research, and on a public law-enforcement statement. Where a step is inference rather than his own words, it is labelled as such. That discipline matters in attribution, and it is the difference between a name and a guess.

Who is Quake3?

Quake3 is a moderator account on XSS.is, the Russian-language cybercrime forum formerly known as DaMaGeLaB. The same account first registered in November 2010 and posted, on and off, until December 2018. Across that run the operator gave a single Jabber contact address again and again: [email protected]. Morgot is a known moderator handle on exploit.in, XSS’s larger sister forum, in its web-coding section. Rcode is the third name in the set. Together, Morgot, Rcode and Quake3 are the personas that Jon DiMaggio and John Fokker placed at REvil’s source-code development in their DEF CON 33 talk, the seventh volume of DiMaggio’s Ransomware Diaries. If you want the wider map of the groups this sits inside, our threat-group catalogue is the place to start.

The interesting thing about this actor is not that he hid well. It is that he did not really hide at all. He assumed the layers of his life would never be laid side by side, and for years he was right. The record below is what happens when they are.

// THE ATTRIBUTION CHAIN chromium evilcore one operator · same two IPs · same hours Quake3XSS.is moderator morgot / Rcodeexploit.in REvil developersource code A. Kravchuknamed by BKA «есть. morgot» DEF CON 33 BKA · Apr 2026 established, from his own words external attribution / assessment
From forum handle to named suspect: Quake3 resolves to morgot and Rcode, the DEF CON 33 REvil source-code developer persona, and the man the BKA named in April 2026. Green links are the subject’s own words; amber links are external attribution.

The self-identification, in his own words

The hinge of the whole case is a single private message from 22 October 2018. A newly appointed section moderator asks the subject whether he is on exploit. The reply is two words: “есть. morgot”, which reads as “yes, morgot.” He offered the name casually, the way a man offers something he assumes everyone already knows. That one line ties the Quake3 moderator seat on XSS directly to the morgot persona on exploit.in.

It is not an isolated slip. He handed out [email protected] as his contact more than a dozen times between 2012 and 2018: on a web-coding job in 2012, on a locker sale in 2013, on a malware-review offer in 2018. In a parallel English-language message the same week in 2018 he wrote it plainly: “me morgot on exploit.in (moderator of web-coding section) and on this one.” Two forums, one man, one contact address, stated openly because he never expected anyone to line up the columns.

One operator, three accounts

The behavioural spine of the case is a multi-account scheme the moderator ran on his own forum, while enforcing that forum’s rules against exactly that. In late 2018 he operated at least three accounts, the primary Quake3 plus two fresh registrations, from the same two IP addresses, at the same hours, with the same maintenance rhythm. All three had their passwords rotated in the same week of October 2018. All three went quiet in the same days of December. Their timezones were set to an unrelated island and to Kaliningrad, chosen for what they do not reveal rather than what they do.

// ONE OPERATOR, THREE ACCOUNTS Quake3moderator, 2010 chromiumalt, reg. Sep 2018 evilcorealt, reg. Oct 2018 2 shared IPs (46.200.195.40 + 1) passwords rotated, same week Oct 2018 last login, same days Dec 2018 masked timezones: Cape Verde / Kaliningrad = one operatorbehavioural match
Three accounts, one operator: Quake3 and its two 2018 alternates share two IP addresses, a single password-rotation week, a common last-login window, and masked timezones.

The cleanest single illustration is a forum logo contest in November 2018. The moderator had closed registration for the voting period, in his own words, to “minimise the risk of votes being stuffed with multis.” On the night of the finale he logged in as Quake3, made a moderator edit to the contest thread, and four minutes later logged in from the same IP as an alternate account and edited it again. The account casting the suspicious block of votes and the moderator policing the complaints were the same person, on the same keyboard. It is a small crime. It is also a perfect fingerprint of the operator’s core habit: pre-positioned masks, clean surfaces, and rules that apply to everyone but him.

A decade in the underground coding market

Read forward from 2010, the account is a coherent professional history rather than a scatter of posts. He starts on DDoS botnets, buys aged forum accounts, and by 2012 writes up his own 6,000-node botnet build. He hosts his work on fasm.su, a genuine FASM-assembler tutorial site that doubled as his private file host for a loader builder and a DDoS bot. He offers to code an MBR locker in 2013 and negotiates its safe-mode and payment-screen behaviour in detail, then withdraws on antivirus-evasion grounds. He offers brute-force work, designs botnet admin panels with task and affiliate queues, and returns constantly to one design constraint, stated in Russian as “нельзя чтобы авер орал,” an antivirus must not scream.

Two traits run through all of it. The first is assembly. He asks in 2011 whether serious bots are written in C or MASM, learns assembly the hard way over the following years, and contributes a MASM user-account-control bypass in 2018. The second is a particular kind of honesty. He reviews other people’s malware “as it is,” states his own loader’s antivirus signature to the client’s face, and refuses to claim a tool does more than it does. That honesty is not moral. It is a trade instrument, the thing that keeps a reviewer credible and, at the top of the market, keeps a developer’s affiliates trusting the build.

The prison years, and REvil’s timeline

Between roughly 2016 and 2018 the account goes dark. When it returns in September 2018, the subject and the forum administrator, an old friend who calls him by the affectionate nickname “Кabaka,” a frog, talk in the open about where he has been. He describes a two-and-a-half-year absence, time “fully wasted,” a stretch during which he fought to keep a smuggled smartphone with no internet and wrote code on it. He volunteers a biography in the same window: a medical education by family line, a real job, a family, assembly taken up late and pursued obsessively.

That absence, 2016 into 2018, is the exact window in which the REvil core was assembled. A developer with his documented skillset, offline for the years REvil was being written, returning to the market precisely as ransomware became its centre of gravity, is a timeline that fits without being forced. It is circumstantial on its own. It stops being circumstantial when you lay it next to the code.

The technical match to REvil

REvil’s published internals are specific: pure assembly, RC4 configuration obfuscation, an ECC Curve25519 and Salsa20 encryption scheme, and DLL side-loading. Set those against a decade of the subject’s own dated posts and the rows line up one for one.

REvil internal (from published REvil analysis)The subject’s own documented equivalent
Pure assembly / MASM-style implementationAsks C or MASM in 2011; “I have long written in MASM myself” (2015); MASM UAC-bypass contribution (2018)
RC4 configuration obfuscationDiscusses RC4 and custom crypto in coding threads (2013); walks a peer through decrypting a “known-algorithm” cookie (2012)
ECC Curve25519 / Salsa20 hybridRecurring crypto questions across the decade; analyses RSA versus symmetric on a ransomware thread (2014)
DLL side-loading loaderDiscusses inject and mapping-based loaders (2013); “a loader is two WinAPI functions, I can fit it in 1KB” (2018)
Rebuild from source, avoid third-party cryptors“better to keep it clean from source than to crypt it” (2018)
Affiliate / task queue panelDesigns a bot-gate and task-table admin queue in a client message (2013)
MBR locker heritage (GandCrab lineage)“I can code an MBR locker,” with safe-mode and payment-screen requirements negotiated (2013)
REvil’s published internals against the subject’s own dated forum posts. Compiled by the Ransomnews Research Team from the forum record and public REvil analysis.

The point of the table is not that a skilled coder could have built REvil. Plenty could. The point is that this particular operator wrote down each constituent skill REvil requires, in his own words, dated, years before the world had heard the name REvil. The profile is not reverse-engineered to fit. It was already on the page.

The public attribution: DEF CON 33 and the BKA

Two public sources sit on top of the forum record. At DEF CON 33 in August 2025, DiMaggio and Fokker published a REvil core-operator table that lists Morgot, with aliases Rcode and Quake3, in the source-code-development seat, alongside separate personas for backend development and affiliate management. That is the researchers’ assessment, presented at one of the field’s largest conferences.

Then, in April 2026, the German BKA went public with names. It identified Daniil Maksimovich Shchukin, known on the forums as UNKN, as the public-facing leader who recruited affiliates, and Anatoly Sergeevich Kravchuk, a 43-year-old Russian national born in Makiivka in eastern Ukraine, as the man responsible for the malware and the dark-web panel. The naming was carried by Krebs on Security, The Record, BleepingComputer and others, and Kravchuk was added to the EU Most Wanted listing. The source-code-development slot in the DEF CON table, the Morgot, Rcode and Quake3 row, is the natural fit for the developer the BKA described, and the biography the forum account volunteered, Ukraine-born, medically educated, a late and obsessive assembly coder, roughly 1983, matches on every axis the record contains.

What is established, and what is assessed

Attribution is only as good as its honesty about confidence, so it is worth stating the tiers plainly.

  • Established, from his own words: the Quake3 moderator account and its two alternates are one operator, and that operator is morgot of exploit.in. He wrote “есть. morgot” himself, and gave the same Jabber address for six years.
  • Established, per DEF CON 33: the persona set Morgot, Rcode and Quake3 is REvil’s source-code developer, as assessed by DiMaggio and Fokker.
  • Assessment, moderate confidence: that developer is Anatoly Kravchuk, per the BKA’s public naming and the biographical match. The final step, from a forum persona to a named passport-holder, is one that law enforcement has taken publicly and that this record supports, not one the forum posts prove on their own.

We are naming Kravchuk because law enforcement did, in public, and because the reporting has been carried by every major outlet in the field. We are not publishing the private identifiers that circulate alongside his name in doxing dossiers. Those documents, financial and residential details belong to a fraud kit, not to a threat-intelligence profile, and reproducing them would endanger uninvolved people without adding a single fact that matters to the attribution.

Why it matters

REvil is one of the most consequential ransomware operations in history, the group behind the Kaseya and JBS incidents, and the identity of the person who wrote its core has been an open question for years. What this record shows is not a hack or a leak that unmasked him. It is the opposite. He was unmasked by what he typed, in public and in private, for eight years: the casual “есть. morgot,” the loader on his tutorial site, the locker he offered to build, the panels he designed, the prison years he described to a friend, the country he told everyone he lived in. He assembled his own case file, in his own hand, and filed it somewhere he assumed no one would ever read it back.

That is the operational lesson, and it is the one worth carrying out of this piece. The masks did not fail because someone breached them. They failed because the operator maintained a decade of self-authored records under a handful of handles and trusted that the columns would never be aligned. For defenders and investigators, the takeaway is that persistent, dated, cross-referenced OSINT on forum personas outlasts any single operation. For the operators still posting, it is simpler: the records have a long memory, and the countries that matter have started comparing notes. You can follow how these groups surface and resurface on Ransomtracker.

Press contact for this piece is [email protected].

Frequently asked questions

Who is Quake3?

Quake3 is a long-running moderator account on the XSS.is cybercrime forum, formerly DaMaGeLaB. The operator behind it also used the handle morgot on the sister forum exploit.in. DEF CON 33 research places the Morgot, Rcode and Quake3 persona set at REvil’s source-code development.

Is Quake3 the same person as morgot?

By his own message, yes. In October 2018 he answered a direct question about being on exploit with “есть. morgot,” and he gave the Jabber address [email protected] more than a dozen times across six years.

Did the BKA name REvil’s developer?

In April 2026 the German BKA publicly named Anatoly Sergeevich Kravchuk, a 43-year-old Russian national born in Makiivka, Ukraine, as responsible for REvil’s malware and dark-web panel, alongside Daniil Shchukin (UNKN) as the group’s leader. Kravchuk was added to the EU Most Wanted listing.

How solid is the link between the handle and the person?

The link from Quake3 to morgot, and the multi-account scheme, are established from the subject’s own dated messages. The link from that persona to REvil’s developer is DEF CON 33’s assessment. The final step to the named individual is law enforcement’s public attribution, which the forum record supports at moderate confidence.

What was REvil?

REvil, also known as Sodinokibi, was a Russia-based ransomware-as-a-service operation responsible for major incidents including the Kaseya supply-chain attack and the JBS meatpacking breach before it was disrupted and its personnel began to be identified.

Why does an eight-year-old forum record still matter?

Because attribution of a ransomware core developer is rarely settled by a single event. A decade of dated, self-authored posts under linked handles is durable evidence that outlasts any one operation, and it is what connects a public law-enforcement name to a specific underground persona.

Sources and further reading

  • Ransomnews Research Team analysis of the XSS.is / exploit.in forum record (dated posts and private messages, 2010 to 2018), August 2026
  • Jon DiMaggio and John Fokker, REvil core-operator research, DEF CON 33, August 2025, published as Ransomware Diaries Volume 7 (the persona table placing Morgot / Rcode / Quake3 at source-code development)
  • Krebs on Security: Germany names the head of REvil and GandCrab (April 2026)
  • The Hacker News: BKA identifies REvil leaders behind 130 German attacks
  • The Record: German police unmask suspects linked to REvil and GandCrab
  • Ransomnews: REvil / Sodinokibi, the big-game hunters who hit Kaseya and JBS
  • Ransomnews threat-group catalogue
Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Previous ArticlePokémon Center vending ‘breach’ is old 2016 data
Dancho Danchev
  • LinkedIn

Dancho Danchev is a Bulgarian threat intelligence researcher who has spent more than two decades tracking cybercrime, malware campaigns, and the infrastructure behind the criminal underground. His research covers botnets, including Koobface, exploit kits, blackhat SEO, scareware, and large-scale domain abuse, with a focus on OSINT work that maps campaigns back to the operators running them. He has published through ZDNet Zero Day, Webroot, GroupSense, and WhoisXML API, and has run his own cybercrime research blog since the early 2000s.

Related Posts

Pokémon Center vending ‘breach’ is old 2016 data

August 10, 2026

Israeli population registry for sale, but the data is old

August 10, 2026

Żabka confirms breach via supplier account, data for sale

August 3, 2026

Comments are closed.

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links — when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

// Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker

// Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

// Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.