Solonik
Solonik is a cybercriminal threat actor active on dark web forums and Telegram channels, primarily observed advertising and selling allegedly stolen datasets. In January 2026, Solonik gained attention for promoting an Instagram dataset described as “17M Global Users - 2024 API Leak,” claiming it contained usernames, email addresses, phone numbers, internal IDs, and partial location data. Multiple reports cited Solonik as highly active and associated with multiple large-scale data dump advertisements, including claims involving approximately 22.5 million records related to a U.S. asset management firm’s customers, offered for sale for $9,500, and separate claims involving VietISO. Supporting infrastructure attributed to Solonik included BreachForums and Dark Forums posts, public Telegram vouch/transaction channels, invite-only Telegram groups used for buyer negotiation and cryptocurrency payment confirmation, and a dedicated domain associated with leaked files. High-confidence reporting in the provided content indicates that Solonik likely repackaged and rebranded older breach or scraped data as new. Investigations found the advertised Instagram dataset was not new and matched materially identical data previously posted in 2023 and 2024, with no evidence of refresh or expansion. The same dataset was linked in prior postings under the aliases Chucky and Chucky_lucky, and the overlap in timing, datasets, platforms, and Telegram channels suggests possible linkage between Chucky, Chucky_lucky, and Solonik, although this was not conclusively proven. Infrastructure analysis also linked a Solonik-associated Telegram account to a phone number beginning with Iran’s +98 country code and to Persian-speaking Telegram activity, but the content explicitly states this is continuity/context only and not definitive attribution. No nation-state attribution is established in the provided content.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Software & Services
- Health Care Equipment & Services
Where they're from
Attributed origin per open-source reporting.
- IR
Tradecraft
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Observables
10 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Offers for sale an alleged large customer dataset from a US-based asset management firm on DarkForums, including PII that could enable downstream fraud and phishing.
Advertised and monetized a purported 17 million-record Instagram leak, but the investigation indicates the dataset was recycled from earlier years rather than obtained through a new breach. Used dark web forums and Telegram channels for promotion, buyer negotiation, and distribution, while leveraging reputation signaling to appear credible.
A dark-web data seller claiming to have harvested and is selling a dataset of ~17.5M Instagram user records (usernames, emails, phone numbers, partial addresses/geolocations), enabling downstream account takeover attempts (password reset abuse), targeted phishing, and social engineering.
Leaking large-scale datasets of Instagram user information, including usernames, email addresses, and phone numbers, to cybercrime forums. Claimed to have harvested the data using an unspecified API.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.