ZeroBytes : deux arrestations et des alias à démêler
Two arrests in France have linked the investigation into the ZeroBytes hacking group to the older Epsilon hacking group and a complex web of aliases. ChatNoir, a key figure in the arrests, was involved in ZeroBytes activities, including attacks against organizations like BFM-TV, RMC, and LDLC. The investigation is focusing on identifying the connections between accounts, machines, and pseudonyms, with several pirate forums taking action against associated profiles. The group was also linked to WaveStealer, a malware used to steal login credentials and access professional tools. The arrests highlight a persistent threat landscape and the difficulty in attributing cybercrime to specific individuals.
Two arrests in France have significantly advanced the investigation into the ZeroBytes hacking group, linking it to the older Epsilon hacking group and a complex network of aliases. ChatNoir, aged 18, was arrested on August 18, 2026, and is identified by ZATAZ as a former member and co-founder of Epsilon. He previously operated under various pseudonyms, including ZeroBytes in 2026, and is suspected of involvement in ZeroBytes activities and attacks targeting organizations such as BFM-TV, RMC, and LDLC.
Eight days later, on August 26, a second suspect, Casquette, aged 15, was placed in custody. He is known as a ‘colleague’ of ChatNoir and operated under pseudonyms like Saturne, Shadow, and xCasquette. His computer equipment was seized for analysis, with the focus on reconstructing connections between accounts, machines, and periods of activity. Several pirate forums have taken action against associated profiles, banning some accounts and closing others.
Epsilon had a history of significant data theft, including stealing millions of records from organizations like LDLC and compromising accounts of media outlets and broadcasters. In 2024, the group even took control of a YouTube account belonging to MediaOne TV in India, using it to distribute a video sourced from the pirates. Within France, the official accounts of BFM-TV and RMC were also compromised and used to spread messages targeting Russia and disseminate content related to victims of a Moscow attack. The group was also associated with WaveStealer, a malware specializing in stealing login information. This infostealer, available on Telegram and Discord in 2024, was often disguised as fake game installers and recovered logs, including login credentials, session cookies, and data to access professional tools.
Furthermore, the investigation is grappling with a complex web of aliases. ChatNoir was linked to pseudonyms like Saturne, near, Nears, near2tlg, yagami, Rand0mSeller, random-seller, anonyme1456, ChatNoir7331 and blackcat. Casquette was associated with xMetah, anonyme1456, xReyna, F7001 and npm. xMetah also maintained links with Lagui and NormalLeVrai, who recently reappeared on pirate forums following a data breach targeting the Banque Alimentaire. An online user questioned Lagui about targeting a humanitarian organization, prompting a response: "Because it's France."
