Note
PhishDestroy now lives on GitLab.
On October 7 our GitHub account was blocked. So far we have no understanding of why, and no email β we are looking into it. For now we have deployed here everything that was there.
We don't think it is connected to any investigation concerning elite lawyers or anyone else. We think the cause was the mass update of IOC lists covering the two weeks during which our four registrar repositories and ShortDot were not working. But any ban has a reason β possibly an automatic trigger fired.
Overall, we don't blame or accuse anyone until the real reason is known. It is also possible that the very fact that we maintained a phishing database violates GitHub's rules β but that is not certain. We are not going to make a tragedy out of this or shout that someone got it banned β that is not the case.
github.com with gitlab.com.
βοΈ PhishDestroy
Volunteer-Driven Threat Intelligence β’ Infrastructure Takedowns β’ OSINT Automation
Mission β’ Operations β’ Operational Matrix β’ Repositories β’ Expertise β’ Contact
π― Mission
PhishDestroy is a volunteer-driven threat intelligence initiative focused on large-scale detection, analysis, and elimination of:
- Crypto drainers
- Phishing networks
- Scam infrastructure
- Fraudulent applications
- Threat actor clusters
Since 2019, we have:
- Neutralized 500,000+ malicious domains
- Eliminated 25+ actor-controlled infrastructures
- Investigated 15+ threat actor groups
- Maintained global OSINT feeds and takedown workflows
π Operations Overview
RECONNAISSANCE β ββββββββββββββββββββ β CONTINUOUS
ANALYSIS β ββββββββββββββββββββ β ACTIVE
COORDINATION β ββββββββββββββββββββ β ONGOING
NEUTRALIZATION β ββββββββββββββββββββ β RELENTLESS
π‘οΈ Operational Matrix
|
|
|
|
|
π‘ Repositories
π‘οΈ Blocklists & Threat Intelligence
| Repository | What it is | Site |
|---|---|---|
| destroylist | Real-time phishing & scam domain blocklist β JSON, TXT, hosts, AdBlock, dnsmasq, Unbound, RPZ (wiki) | |
| DestroyScammers | Scam intelligence, phishing attribution, drainer mapping (wiki) | |
| ScamIntelLogs | Telegram dumps of scammer groups preserved as evidence |
π Registrar Evidence β updated daily
| Repository | What it is | Site |
|---|---|---|
| namesilo-evidence | NameSilo, LLC (IANA #1479) β abuse investigation, IOC datasets | |
| nicenic-evidence | NICENIC International Group (IANA #3765) β full zone scan | |
| trustname-evidence | Trustname.com / Fewmoretaps OΓ β zone evidence, IOC datasets | |
| shortdot-evidence | ShortDot SA β .icu .bond .cyou .sbs .cfd .buzz .qpon brand-impersonation domains |
π§ͺ Investigations & Tools
| Repository | What it is | Site |
|---|---|---|
| DO-NOT-USE-xmrwallet-com | xmrwallet.com leaks your private view key on every request β technical proof | |
| taylor-wessing-data-breach-toolkit | PDF redaction auditor & layer decomposer suite | |
| Nigerian-dignity | Catalogue of "inheritance" and "lottery" scam infrastructure | |
| Anti-Phishing-Research | Decoy research tool that feeds scammers millions of fake seeds | |
| Operation-Takedown | Tools and scripts for active phishing campaign disruption |
ποΈ Archives
| Repository | What it is | Site |
|---|---|---|
| medium-archive-phishdestroy | Archive of the PhishDestroy blog after the Medium suspension | |
| x-twitter-archive-CarlyGriggs13 | 138K tweets of phishing takedown reports from @CarlyGriggs13 |
π§ OSINT Detection Methods
- Certificate Transparency API
- DNS anomalies & registrar drift
- Hosting & ASN correlation
- Blockchain scam transaction analysis
- Malware reverse engineering
- AI-enhanced phishing kit detection
- Automated intelligence clustering
π§© Expertise & Stack
- Languages & Frameworks: Python, Go, Rust, PHP, JavaScript, Bash
- Threat Intelligence & Analysis: YARA Rules, Malware RE, Infrastructure Mapping
- Database & Services: MySQL, Redis, Nginx, Cloudflare, Docker, Linux, Git/GitLab
π¬ Contact & Community
Evidence-based threat neutralization since 2019
Personal projects
View allAbout
Pronounced as: phishdestroy Β· he/him
Pronouns: Global / π
