JustPaste.it

Further Analysis of Rey's Online Footprint

We uncover Rey's address and potential school, further verify that he stole his moms identity, uncover social media accounts and look at Rey's birthday gifts

Introduction

In our last article we discussed the threat actor that stole his own mom's identity. Today we look deeper into the footprint of Saif Al din Khader aka Rey the threat actor behind Hellcat and Scattered LAPSUS$ Hunters, one of the most "notorious" and "sophisticated" threat actor groups operating today.

 

We will uncover Rey's address, his potential school, further verify that he stole his moms identity, uncover social media accounts and look at Rey's birthday gifts. IntelOps will not disclose how this data was obtained but we stand by its authenticity.

 

Rey's Address

 

First we look at the CompuJordan account of Saif and view the Address Book:

reyaddress.png

Translation:

Saif Al-Din Khader

Prince Hassan District, Hamad Al-Qanawi Street, Building 11

 

 

reystreet.png

This matches the dox published on our X Post. We sat on this intel for months until Rey placed a 15 BTC bounty on his own head. Rey's friend Pryx from Hellcat admits the dox are legit

 

reypryxadmitsdeanon.png

 

 

 

saifclown.jpg

Rey is a skid who fails to understand that in his chosen profession integrity means everything and his trust will be gone. How will any ShinySp1d3r RaaS partner trust they will recieve their payments or victims trust they will delete data? How will Scattered LAPSUS$ Shiny Hunters trust Rey's word that he is not snitching on them?

 

Further linking Rey to his mom's stolen identity

 

Next we look at the SMS services that Rey signed up with his mothers stolen identity. It is important for sophisticated threat actors to practice good Operational Security to keep their actions anonymous, so the name Rey chose for this account is: سيف الدين خضر Translated: Saif Al-Din Khader. Curious he provided a fake address for this account:

 

reyreceivesmsonline2.png

Rey uses an Android 12 phone as seen here, with logins as recently as 26 December 2025. Remember that sophisticated threat actors practice good OpSec and don't reuse accounts that have already been burned.

 

reysmscodesandroid.png

Further analysis of these accounts yields no interesting intelligence but is another link in the chain connecting Rey to his mom's identity theft.

 

Rey's Birthday Gifts

 

Rey's father password is saifaldeen912, which we see here courtesy of our friends at Whiteintel.IO monitoring service. With the common date format in Jordan being Day/Month/Year gives Rey a birthday of 9 December.

reyzaidbirthday.png

 

Rey's family is very generous for his birthday. On 9 December they spend JOD 307 (372 Euros or $433 USD) making a computer room for him including a new chair, less blue light monitor and stand for late night hacking, gaming microfone and headset, speakers and the most important part: Redragon LED mouse and keyboard. Sophisticated threat actors only use Green LEDs while commiting cybercrimes.

 

reycitycenter1.pngreycitycenter2.png

 

Wrist Slit

 

Next we look at Rey's social media footprint. The Fut Simple Trader website yields a very important clue, the username vlixero

 

reyvlixero.png

Pivoting on this username vlixero we uncover first a GitHub account with one Repository, a PyGPT chatbot. Some of the Rey stealer logs show use of AI chatbots.

 

reygithub.png

 

Next we uncover a vlixero account on Reddit active in the Jordan SubReddit. The account has low activity.

 

reyreddit.png

 

Next we find Saif Al din Khader's Twitch account lists him as a "Content Creator" without any content. Must be too busy with computer crime. The Twitch lists an Instagram profile for us which we also found using google.

 

reytwitch.png

 

Same story with TikTok, a bare profile with no posts also listing an instagram account.

 

reytiktok.png

We also uncover another X account with a creation date of 2017. This account was likely purchased with the older creation date to give it some credibility. The last username change was September 2023 which is likely the account takeover date.

 

reyvlixerotwitter.png

The last account we uncover belongs to Rey's Instagram. Google is showing us a profile message "discord: wristslit" giving us a username that closely resembles the wristmug username published by our friend Krebs.

 

reyigwristslit.pngreyinstagram.png

Rey's Instagram account has 0 posts or was cleaned up. The account has low activity but we uncover a post on the Modern Arab Academy School announcing the commencement of Tawjihi, this is a General Secondary Education Certificate that is taken after Grade 10.

 

Rey replied to this post "برنلك" which google translate told us "Bartlak" or "Did you mean: Program" however a friend gives us this explanation:

 

"برنلك" is a colloquial Arabic term from Levantine dialects (such as Jordanian or Lebanese), pronounced roughly as "barennlak" or "barenillak." It translates to "I'll call you" in English, derived from "ba-rinn-lak," where "rinn" relates to ringing a phone.

 

reyigschool.pngreyigschooltranslated.png

 

We believe that Rey currently attends this school since 3 August 2025 near Prince Hamza Hospital in Amman, Jordan

 

reyschool.png

 

Following is the area in relation to Rey's House.

 

reyjordan.png

Bonus Youtube

 

If you think back to Rey's accounts o5tdev name and cybero5tdev@proton.me email and o5tswe Microsoft account you might ask yourself what o5t means. o5t mean أخت or sister in Arabic, mostly in north Africa.

 

We uncover with medium confidence a youtube account @SAIFYT-o5t, Saif YT o5t or Saif Youtube Sister. What is your focus on sisters, Rey? Youtube banner shows a potential photo of little Saif

 

There are 2 subscribers, 5 videos and 91 views at time of publishing. Videos show video game scenes focused on a character called SAIF YT.

 

saifyt.png

 

https://www.youtube.com/@SAIFYT-o5t

 

Conclusion

 

There is more intel we have to share but this is a good amount of information for today. We have shown proof that our doxxing of Rey is correct to claim the 15 BTC bounty that Rey has placed on his head. We also shared further showing that Rey stole his mom's identity, uncovered social media accounts, discovered Rey's school and even looked at his birthday gifts and uncoverd his computer equipment.

 

Rey we are having so much fun doing some work like you asked so if you want to hold out a little longer on our bounty its OK. Our next article will dig further into Rey's personal life or show the "sophisticated" skid TTP that Rey employs depending on which article is finished first or what we decide to publish that day. Then we will start publishing about the other Scattered LAPSUS$ Shiny Hunters members. We will stop making fun of you and publishing when the bounty is paid. Its up to you gang.

 

If you have enjoyed these articles or you are Saif, we graciously accept monero donations:

8AVbmNAmWjS9jEHKKr29oxTxrBPgQL2o661egbDb26hxF5NbCwUdq2dFAzKZcYTiZ7jckQE6iiRdTPpmUCT4ohWGAYDxuPS

 

If you like this article you will love our X Account