Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
operation-black-hole — Forensic evidence dossier for Operation Black Hole - Investigating fraudulent Falla app ecosystem (TRON blockchain, admin panel exposure, infrastructure recon). CST regulatory submission portfolio. | Kitploit
Tools/GitLabGitLab/gratech1/operation-black-hole
OSINT (Open Source Intelligence)Vulnerability AnalysisWeb SecurityDigital ForensicsMobile Security
GitLabgratech1/operation-black-hole

operation-black-hole

Forensic evidence dossier for Operation Black Hole - Investigating fraudulent Falla app ecosystem (TRON blockchain, admin panel exposure, infrastructure recon). CST regulatory submission portfolio.

View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
4 months agoNot yet reviewed

Operation Black Hole - Forensic Dossier

Multi-App Fraud Network Investigation

Case ID: OBH-2025-CST-001 Analyst: Sulaiman Alshammari - GraTech Forensic Division Date: April 2026 Methodology: OSINT + Authorized Digital Forensics (ISO 27037, NIST SP 800-86)

DISCLAIMER: This is a public forensic research portfolio. All sensitive values (credentials, wallet addresses, API keys) have been REDACTED. This material is prepared for submission to the Communications, Space & Technology Commission (CST) of Saudi Arabia. No unauthorized access or exploitation was performed. All evidence was collected via OSINT and authorized methods only.


Executive Summary

This repository documents Operation Black Hole, an investigation into a multi-publisher, multi-jurisdiction network of voice chat/gifting applications that share infrastructure, developer identities, and financial pipelines.

The investigation identified 5 applications (high confidence) and 1 additional application (medium confidence) operating as a single coordinated network under different publisher names across Hong Kong, Singapore, and Shenzhen.


Key Findings

Application Attribution (by confidence level)

iOS Publisher (shared): Shenzhen Yinguo Network Technology Co., Ltd. publishes Falla Lite, TooFun, Taeal, and JoyMi under one account.

Attribution Criteria

Apps are linked based on: publisher identity match, package ID prefix patterns (com.iyinguo.*), shared developer email addresses, shared physical addresses, and shared iOS publisher accounts. See analysis/app-attribution-matrix.md for full details.

Infrastructure

  • Operations Triangle: Dubai (financial gateway) → Singapore (legal shell) → China (tech core)
  • Hosting: Tencent Cloud, AS139341 (ACE-SG), Collyer Quay, Singapore
  • Admin Panel: /fallaadmin endpoint discovered via FFUF (47+ hidden endpoints)
  • Blockchain: TRON (TRC-20 USDT) wallet network for fund distribution

Vulnerabilities Documented (6 total)


Repository Structure

root@kitploit:~
operation-black-hole/
├── README.md                              # This file
├── METHODOLOGY.md                         # Investigation methodology & ethical boundaries
├── evidence/
│   ├── admin-panels/
│   │   └── fallaadmin.js                  # Extracted admin panel source (REDACTED)
│   └── forensic-images/
│       └── disk-hashes.sha256             # SHA-256 chain of custody manifest
├── analysis/
│   ├── app-attribution-matrix.md          # App-to-entity mapping with confidence levels
│   ├── infrastructure-map.md              # Network topology (Mermaid diagrams)
│   ├── financial-flow.md                  # Money laundering flow analysis
│   └── technical-report.md                # Full technical analysis
└── presentation/
    └── cst-interview-deck.md              # CST technical presentation

Verified Evidence Hashes

Key evidence files from the forensic workstation (SHA-256):

Note: The fallaadmin.js in this repository is a REDACTED version of the original. The original file (hash above) is preserved in the encrypted evidence archive. Hash difference is expected due to redaction of credentials and API keys.


Legal Framework

  • Saudi Anti-Cybercrime Law (Royal Decree No. M/17)
  • Anti-Money Laundering Law (Royal Decree No. M/31)
  • Personal Data Protection Law (PDPL)
  • SAMA Licensing Requirements (payment gateway compliance)

Methodology

See METHODOLOGY.md for full details on investigation methodology, tools, ethical boundaries, and chain of custody procedures.


Contact

Sulaiman Alshammari GraTech Forensic Division Case ID: OBH-2025-CST-001

Download Tool
AppPlatformPackage IDPublisherConfidence
FallaAndroidcom.juhaoliao.vochatHong Kong Huanyu Interactive Network Technology Co., LtdHigh
Falla LiteAndroidcom.iyinguo.fallaliteHong Kong Huanyu Interactive Network Technology Co., LtdHigh
TooFunAndroidcom.iyinguo.trchatHong Kong Huanyu Network Technology Co., LtdHigh
JoyMiAndroidcom.joymi.sevenFALLA PTE. LTD. (Singapore)High
TaealAndroidcom.taeal.mansurFALLA PTE. LTD. (Singapore)High
BoliAndroidcom.iyinguo.silkroadBoli Technology Ltd / HK Tingyin Network Technology Co., LtdMedium
HiloiOSid1519958782PARTYCOME PTE. LTD.Low (candidate)
IDVulnerabilitySeverityCVSS
V-001Hardcoded Admin CredentialsCritical9.8
V-002SQL Injection in LoginCritical9.1
V-003No Rate Limiting on APIHigh7.5
V-004Exposed MongoDB (No Auth)Critical9.8
V-005Unencrypted Payment DataHigh8.1
V-006Missing CSRF ProtectionMedium6.5
FileSHA-256
falla_admin.js (original)71bf18bf6be88fc7afb4a0d5ae668148d0f75f080ec9e6a6956776bc865ad88d
falla_beautified.js121af874c746a024fad07c42265780668aa3439cbbd6e2d9bb92ec605b69348c
FULL_FORENSIC_REPORT.txt62edf4e153db0956f0594d2b3deb7ee680a53fdccc53d823bc544df7b0a72a0e
FRAUD_FINANCIAL_REPORT.txt9b82b3249535fa1c0f7515420cbb98ca16d36ea2057177aba24c7fc26647d95a
extracted_tron_addresses.jsonf6037e04a9501fe094e70e2b5c5c6459a1cded2faef9422b9f689e102347018f
FORENSIC_CRYPTO_REPORT.json36e16cff90a446e7483ac7ecc20b25c026f4ad41891823074f5f4a8f2d07aa30
final_hilo_falla_clean.txt800e09f3e651274ee63f299a614563a81ef342a81ae3f8c623422ef179111815