Back to Blog
initial-access

Dark Web Most Wanted: Miyako

July 24, 2026

Last updated: July 24, 2026 9 min read

Written by: DarkWebSonar Research Team


Threat Actor Icon

Miyako is one of the clearest Initial Access Broker specialists in DarkWebSonar telemetry: 211 of 221 recorded incidents (95%) are access-sale listings rather than data leaks or ransomware victim posts. Since November 2024, DarkWebSonar has tracked 221 forum and marketplace listings attributed to the actor. Nearly two-thirds of that volume (142 incidents) landed in the first 10 weeks of visibility (November 2024–January 2025), followed by a multi-month quiet period, then renewed batch listings through mid-2026. The pattern is not a steady daily drip. It is burst publication of perimeter access, most often framed as root RCE and shell on Linux firewalls, priced in the low hundreds of dollars.

Key findings from DarkWebSonar telemetry (November 2024–July 2026):

  • 221 listings observed; 95% classified as Initial Access, with just 10 listings (5%) offering stolen data rather than access.
  • United States accounts for 93 listings (42%); China (17) and Saudi Arabia (8) rank second and third among named countries.
  • Top industries: Government & Defense (34), Technology & Telecom (32), Financial Services (21).
  • Debut spike: 2024-W47 (47 listings); largest recent week: 2026-W27 (21 listings, late June–early July 2026).
  • Activity classification: Spiked; 22 of 221 listings occurred in the last 30 days.
  • Batch-and-disappear cadence: five silences of three weeks or more (including an eight-month dormancy in 2025); on each return, 95 to 100 percent of every 2026 reactivation posted within the opening week before activity fell back to near zero.

Public reporting identifies the persona under the aliases mommy and Miya, and describes Miyako as a forum-based Initial Access Broker active since 2024. Open-source analysis places Miyako as a primary access supplier to Hellcat ransomware (including the Pinger compromise via F5 BIG-IP CVE-2022-1388) and notes elevated underground forum status. We treat forum listings as intelligence signals: they indicate claimed access and pricing intent, and require corroboration through victim disclosure, infrastructure change, or follow-on reporting before they are treated as confirmed compromise.

By the Numbers (DarkWebSonar Telemetry)

DarkWebSonar monitors Miyako's activity across the underground forums where the actor advertises access. The 221 listings below reflect what the broker chooses to publish; listing volume is a useful proxy for inventory and sales tempo, though it undercounts private deals and overstates unverified claims.

  • Total listings (Nov 2024–Jul 2026): 221 across 38 named countries; United States accounts for 42% of all listings
  • Recent momentum: 22 of 221 listings landed in the last 30 days (June–July 2026 batch cycle)
  • DarkWebSonar risk score: 100 / 100 (Critical)
  • Activity classification: Spiked, meaning recent 30-day volume significantly exceeds the actor's established baseline
  • Where advertised: underground forums reachable without Tor (200 listings, 90%); Tor sites (21 listings, 10%)
  • Attack-type mix: Initial Access 211 (95%); data breach or leak 10 (5%)

Posting cadence and year-week analysis

When DarkWebSonar telemetry is aggregated by ISO year-week, Miyako's activity divides into four observable phases:

  1. Debut surge (2024-W46 through 2025-W04): 142 listings in roughly 10 weeks, peaking at 47 in 2024-W47 (November 21–22, 2024).
  2. Quiet interval (late January–September 2025): No DarkWebSonar-attributed listings for roughly eight months.
  3. Reactivation (2025-W39 through 2025-W50): 25 listings across September–December 2025, including 10 in 2025-W47.
  4. 2026 batch cycles: 54 listings through July 18, 2026, with concentrated weeks in 2026-W06 (12), 2026-W14 (11), and 2026-W27 (21).

Trends

Year-week Listings Notes
2024-W47 47 Debut peak (Nov 21–22)
2024-W48 21 Includes Dec 1 cluster of 18
2026-W27 21 Late June–early July 2026 batch
2024-W50 18 Mid-December 2024
2024-W46 15 First tracked week
2024-W49 12 Early December 2024
2026-W06 12 Early February 2026
2026-W14 11 Early April 2026

The more actionable pattern is not the phases themselves but how Miyako re-emerges from them. Each multi-week silence is followed by a compressed reactivation batch that lands almost entirely in the first days back. The eight-month dormancy broke on September 26, 2025 with six listings in a single day, followed by another two-month silence before the larger November batch; across the four 2026 restarts, 95 to 100 percent of each cycle's volume posted within the opening week before activity fell back to near zero. We assess this reflects a batch-and-disappear rhythm: Miyako accumulates firewall-access inventory while dark, publishes it in a short burst on return, then goes quiet again. Through 2026 the gaps compressed to roughly six to eight weeks (February, April, and late June cycles), which makes the reactivation windows more predictable.

We assess the June–July 2026 surge (2026-W27) reflects coordinated multi-listing publication of firewall access inventory rather than simultaneous new compromises on a single day. Same-day or adjacent-day batches across multiple countries and sectors are consistent with a broker clearing or advertising stock, not with a single-campaign ransomware leak-site dump.

Targeting distribution

Miyako's target geography is US-weighted but not US-only:

Countries

  • United States: 93 (42%)
  • China: 17 (8%)
  • Saudi Arabia: 8 (4%)
  • Indonesia: 7 (3%)
  • Canada: 7 (3%)
  • United Kingdom: 6 (3%)
  • South Korea: 6 (3%)
  • Thailand: 5 (2%)
  • France: 4 (2%)
  • United Arab Emirates: 4 (2%)

The United States share is high for an IAB with global inventory, but the long tail across MENA, East Asia, and Southeast Asia means regional SOCs outside North America still see relevant listings. Chinese organizations rarely surface on Western ransomware leak sites, so China ranking second in Miyako's book is a real divergence from the leak-site datasets most teams watch, and it suggests either opportunistic edge exposure in Chinese infrastructure or deliberate inventory diversification.

Sample1

Industry targeting concentrates on high-value perimeter environments:

Industries

  • Government & Defense: 34 (15%)
  • Technology & Telecom: 32 (14%)
  • Financial Services: 21 (10%)
  • Education & Research: 18 (8%)
  • Healthcare & Pharma: 14 (6%)
  • Manufacturing & Construction: 13 (6%)

Government and telecom concentrations align with the actor's advertised product: edge firewall access that can pivot into large enterprise or public-sector networks. Industry labels are blank or Unknown for 30 of 221 listings (roughly 14%), so sector shares among labeled listings are modestly higher than the percentages above.

Notable listing events

  • Nov 21–22, 2024 (47 listings across two days; debut peak)
  • Dec 1, 2024 (18 listings in a single day)
  • Dec 2024 data-breach cluster (Indonesia government financial system, commercial databases in Poland, Philippines, South Korea, Singapore, China, Turkey)
  • Nov 20, 2025 (10 listings; reactivation cluster)
  • Jun 29–Jul 2, 2026 (21 listings in 2026-W27; multi-country firewall root/RCE ads)
  • Jul 18, 2026 (US casino and resort access listing via escrow on an underground forum)

Targeting Profile

Miyako's DarkWebSonar footprint is that of a volume Initial Access Broker with a US-heavy book and secondary presence in China, Gulf states, and East/Southeast Asia. Miyako's signal is the access advertisement itself: country, sector, access type (most often Linux firewall root), and price.

Sample2

We assess that Government & Defense and Technology & Telecom listings deserve elevated triage because perimeter compromise in those sectors enables high-impact follow-on operations (espionage, ransomware, supply-chain pivot). Financial Services and Healthcare listings carry similar downstream risk when the advertised foothold is a network edge device rather than a low-privilege user account.

Attack Profile & Tactics

DarkWebSonar's visibility into Miyako is the forum listing, not the victim network. The platform sees what the actor advertises, not logs, encryptors, or forensic artifacts from a compromised environment, so the MITRE ATT&CK techniques below are inferred from the type of access each listing offers rather than observed during exploitation:

  • T1190 Exploit Public-Facing Application
  • T1133 External Remote Services
  • T1078 Valid Accounts
  • T1005 Data from Local System
  • T1530 Data from Cloud Storage
  • T1041 Exfiltration Over C2 Channel
  • T1048 Exfiltration Over Alternative Protocol
  • T1567 Exfiltration Over Web Service

The dominance of T1190 / T1133 / T1078 reflects what an IAB advertises: public-facing or remote-service access plus privileged credentials on the compromised device. These are the techniques implied by the product on sale, not ones DarkWebSonar has independently confirmed through exploitation evidence. The smaller collection and exfiltration set maps to the minority data breach and leak listings from late 2024.

Access product and pricing (DarkWebSonar + open-source reporting)

Recent DarkWebSonar entries describe a repeatable product: root RCE and shell on Linux-based firewalls, typically priced at $300–$700, with occasional escrow-mediated sales. Late June and early July 2026 listings in telemetry include unnamed US telecom and insurance entities described with multi-billion-dollar revenue claims, a UAE oilfield services contractor, a Saudi logistics firm, a South Korean electronics firm, a US retail pharmacy chain, and a US call-center operation. Public reporting of earlier high-profile offers (including a claimed FBI subdivision firewall listing near $2,000) shows Miyako also prices above that commodity band when the claimed victim raises perceived value.

Sample3

DarkWebSonar visibility begins at the forum listing; exploit chains, recon tooling, and buyer-side follow-on activity below come from public reporting.

That reporting describes Miyako (also tracked as mommy / Miya) building inventory through internet-wide recon of exposed edge devices (Shodan, FOFA, and Leakix are cited), then monetizing privileged footholds on firewalls, VPN gateways, and similar appliances. It links Miyako-supplied access to Hellcat ransomware operations, including the Pinger compromise via the F5 BIG-IP authentication bypass (CVE-2022-1388), and notes PowerShell-based payload download and staging once a foothold is established. Post-purchase tradecraft such as Mimikatz credential dumping, PsExec/RDP lateral movement, and Rclone/MegaSync exfiltration is attributed to Hellcat operators, not to Miyako's listing activity itself.

We assess the firewall-root listing pattern observed in DarkWebSonar is the primary monetization path in 2026, with data-breach posts a secondary, earlier activity mode. Public reporting also describes occasional hybrid offerings that pair network access with sensitive data sales.

Origins & Motivation

Public reporting places Miyako in the underground Initial Access Broker economy that supplies ransomware affiliates and other buyers. It notes self-identification as an Initial Access Broker, prior handles including Miya, and overlapping contact channels across BreachForums-era and successor communities, along with elevated underground status (including a "First Access Broker" relationship with Hellcat) and, at low confidence, ties to East Asian cybercrime ecosystems. Attribution to a specific country of origin remains unconfirmed; DarkWebSonar treats geographic origin as unknown pending stronger evidence.

Commercially, the model is straightforward: compromise or obtain privileged edge access, advertise it with sector and country labels, and sell quickly at modest prices. High listing volume at low unit price suggests a volume business optimized for turnover rather than bespoke, high-dollar private sales alone (though private deals would sit outside DarkWebSonar's public listing telemetry). The Hellcat relationship illustrates why IAB monitoring matters: ransomware crews can outsource scanning and exploitation, so a single prolific broker amplifies risk across many victim organizations. Public reporting on Hellcat's late-2024 activity documented the same pattern from the buyer side, with root access to victims' servers (in many cases the firewall appliances meant to keep attackers out) offered for sale on underground forums, including a major US university and a European energy distributor (Infosecurity Magazine).

Notable Listings

Named or high-signal listings observed in DarkWebSonar telemetry:

Sample4

  • Saudi Post (Saudi Arabia, Government & Defense; June 30, 2026): claimed root RCE and shell on a Linux firewall, priced at $400.

  • US casino and resort (United States, Hospitality; July 18, 2026): claimed initial access advertised at $500 via escrow on an underground forum.

  • US telecom (claimed ~$10B revenue) and US insurance (claimed ~$20B revenue) (Technology & Telecom / Financial Services; June 29, 2026): firewall root access listings at $700 each.

  • Indonesia Regional Financial Management Information System (Government & Defense; December 24, 2024): alleged 82 GB database leak including credentials and financial records.

  • Go Suite Enterprise (Poland, Technology & Telecom; December 23, 2024): alleged 7 GB database sale.

  • Exxel Prime Int'l Trading (Philippines, Retail; December 9, 2024): alleged 2.3 GB customer and logistics data leak.
    High-signal claims from public reporting (intelligence signals, not DarkWebSonar-confirmed compromise outcomes):

  • Claimed root access to a US FBI subdivision firewall (reported near $2,000; covered in Cyber Daily).

  • Claimed firewall access to a major US state university and to an AI cyber threat intelligence company (underground listing monitors, late 2024–early 2025).

  • Pinger compromise path: Miyako-linked F5 BIG-IP access feeding Hellcat ransomware and data theft (open-source technical reporting, January 2025).

DarkWebSonar Insights

  • Specialization scoring flags Miyako as an Initial Access specialist (95%), which separates the actor from ransomware brands that dominate Most Wanted lists and from hacktivists whose primary signal is DDoS or defacement.
  • Year-week cadence tracking surfaces the debut 2024-W47 spike (47 listings) and the 2026-W27 reactivation batch (21 listings), giving CTI teams concrete windows when buyer activity and victim exposure risk were elevated.
  • Venue split (90% non-Tor forums / 10% Tor) shows Miyako advertises mostly on underground forums that do not require Tor, so Tor-only monitoring will miss the majority of listings.
  • Sector-country cross-cuts (for example, US Government & Defense and Gulf-region logistics/energy listings) let SOCs prioritize edge-hardening and watchlists on the access signal itself, well before a foothold is resold and used downstream.

Defender Outlook 2026

Persistent risk: Organizations in Government & Defense, Technology & Telecom, Financial Services, Education, and Healthcare should treat Miyako-style IAB listings as early-warning for perimeter compromise, especially where internet-facing firewalls and remote services lack strong authentication and timely patching. US entities face the highest listing volume, but China, Saudi Arabia, Indonesia, Canada, the UK, South Korea, and the UAE appear often enough to justify global watch.

Tempo: Miyako works in a batch-and-disappear rhythm: weeks of silence, then a compressed reactivation burst in which most of a cycle's listings post within the first days back, then quiet again. The first 48 to 72 hours after Miyako resurfaces is the highest-value monitoring window, because that is when the bulk of new firewall-access inventory appears. Through 2026 these restarts have recurred roughly every six to eight weeks, so a return to silence is better treated as a countdown to the next batch than an all-clear.

Defensive actions:

  • Patch and inventory internet-facing firewalls, VPN concentrators, and load balancers; prioritize known-exploited edge CVEs such as CVE-2022-1388 (an actively exploited F5 BIG-IP authentication bypass flagged in CISA advisory AA22-138A), and reduce public exposure of management interfaces.
  • Enforce MFA and strong credential hygiene on administrative interfaces for perimeter devices; assume valid privileged accounts (T1078) are part of the product Miyako sells.
  • Monitor dark web and forum channels for the aliases Miyako, mommy, and Miya, plus organization-, sector-, or geography-specific ads mentioning root, RCE, or firewall shell.
  • Hunt for suspicious PowerShell download and staging patterns after edge compromise; open-source hunting content tied to this persona treats atypical PowerShell file retrieval as a high-signal IAB staging behavior.
  • Treat a Miyako listing as a trigger for external attack-surface review and incident readiness, not as automatic proof of compromise. Plan for multi-buyer reuse: once access is sold, more than one downstream actor may attempt to use the same foothold.
  • Correlate IAB spikes with ransomware affiliate activity in the following weeks; open-source reporting documents Miyako access feeding Hellcat operations, including the Pinger case.

Data notes: Statistics in this profile are derived from DarkWebSonar telemetry on Miyako-attributed forum and marketplace listings unless attributed to open-source reporting. Listing dates reflect publication, not necessarily compromise date; batch ads can inflate single-week counts. Country and industry fields reflect listing metadata and are incomplete for a minority of listings (industry labels are blank or Unknown for 30 of 221, roughly 14%).

Conclusion

Miyako is a high-volume Initial Access Broker whose DarkWebSonar footprint is defined by specialization, not by leak-site fame: 221 listings since November 2024, 95% Initial Access, and a US-heavy but globally distributed target map. The June–July 2026 batch (21 listings in 2026-W27) shows the actor is still clearing firewall-root inventory into the current cycle.

For CTI and SOC teams, the practical implication is to watch the access market, not only the extortion market. By the time a buyer such as Hellcat deploys ransomware or dumps data, the Miyako listing may already be the earliest public signal that a sector or geography was in play. Edge hardening, PowerShell staging detection, credential control on perimeter devices, and continuous monitoring for the mommy/Miyako/Miya aliases are the controls that map directly to this actor's observable product.


👉 Dark Web Most Wanted profiles are powered by DarkWebSonar's continuous monitoring of dark web forums and threat-actor activity. Want real-time visibility into Initial Access Brokers like Miyako? Contact Sales.

DarkWebSonar

Threat intelligence
without the noise.

Start Free Trial View Pricing

Related articles